Every day, people who aren’t your employees perform work inside your facility: device representatives in the OR, service engineers on your equipment, couriers moving specimens and implants, pharmaceutical reps on the floor. CMS still holds the hospital’s governing body responsible for them — 42 CFR §482.12(e) makes services furnished under contract the hospital’s duty.
NBWCV gives the hospital a way to discharge that duty without adding staff or building another binder. For every non-hospital worker and vendor, it attaches a verifiable answer to the four questions a surveyor would ask — and it does so inside the hospital’s own chain of command, anchored to the contract.
Every person who enters to perform work should be able to answer four questions. NBWCV attaches a verifiable answer to each — three numbers and a competency.
The individual, certified to ISO/IEC 17024 for job-task competency in the hospital environment — a portable credential that travels with the person, not the badge at one facility.
The company that stands behind the person, certified to ISO/IEC 17065 for product competency — plus its screening, health, sanctions, and chain-of-command obligations, carried as a surveilled responsibility.
The engagement under the hospital’s contract — the scope, the reason for access, and the tie into the facility’s chain of command and §482.12(e) responsibility.
Not a signed attestation — verified ability to perform the specific task, certified by an accredited third party and kept under surveillance.
Competence on the device or product the rep supports — verified at the company level.
Competence to perform the job task safely where care happens — verified at the person level.
Together they answer question 4: product competency sits with the company; job-task competency sits with the person.
The four questions don’t only apply to the device rep in the OR. They apply to anyone the hospital brings in under contract — biomedical and equipment servicers, HVAC and construction trades working in occupied clinical space, couriers and logistics moving through restricted areas — every bit as much as the clinical or device representative at the table.
The regulatory tests are identical for all of them: verified qualifications (HR.11.02.01), accountable oversight of contracted work (LD.13.03.03), and controlled access to security-sensitive areas (NPG.11.01.01). The rep number and company certificate answer the same four questions for each of them, wherever they enter.
Credentialing platforms treat everyone the same — badge in, badge out. That is a Visit. But a rep guiding a procedure, an engineer servicing a sterilizer, or a courier handling an implant is doing a Job: a task that touches patient care and carries accountability. The four questions matter only because it is a Job, not a Visit.
Vendor credentialing collects attestations — a rep clicks “I completed training,” uploads a certificate, signs a policy. An attestation is a claim. Competency is verified ability to perform the specific job task, certified by an accredited third party and kept under surveillance. The fourth question — are you competent? — is the one credentialing can’t answer, and the one certification is built to.
The Contract Number is what ties the person and the company into the hospital’s own chain of command. CMS §482.12(e) makes the governing body responsible for contracted services — and the contract is where that responsibility lives. NBWCV does not sit beside the contract as one more vendor portal; it plugs the rep number and company number into the contract, so the accountability structure the hospital already runs now carries the non-hospital workforce too.
The rep number rolls up to the company number — the certified entity that stands behind the individual.
The company number is engaged through the contract number — defining scope, access, and reason.
The contract sits under §482.12(e) — the governing body’s standing responsibility for contracted services.
This is not a new mechanism to learn. It extends the two delegated-assurance models a hospital already relies on to meet its CMS Conditions of Participation for the non-employees in its care environment — the CVO for the person, and Joint Commission HCSS certification for the company. The registry is the source of truth, queried the way a hospital already queries its medical staff — see the Source of Truth Directory.
Vendor credentialing today reverses the HCSS direction: the hospital must monitor many independent third parties and carries the audit burden itself. The company number restores it — a certified entity monitors itself, and the burden moves off the hospital. It is the same delegated assurance hospitals already use for clinicians, extended to the workforce HCSS never covered.
NBWCV's programs are built on the international conformity-assessment standards ISO/IEC 17065 (certification of organizations and their programs) and ISO/IEC 17024 (certification of persons) — the same family of principles trusted across regulated industries.
Both are in process: organizational certification under ISO/IEC 17065 is being established now, with personnel certification under ISO/IEC 17024 planned, and accreditation by the ANSI National Accreditation Board (ANAB) is being pursued. Accreditation is the independent assurance that the verifier, too, is held to a standard.
The four answers resolve in one place, and the case for accrediting bodies is laid out for surveyors.