Labour hire operators are the overlooked risk carrier when a fraudulent RSA certificate slips through onboarding. Under state liquor acts, the venue holding the licence bears the primary penalty. But the labour hire company that placed the uncertified worker carries parallel liability through a separate legal pathway, and the combined exposure is far more serious than most operators appreciate.
Why RSA verification matters for labour hire operators
RSA (Responsible Service of Alcohol) certification is a legal requirement for anyone serving or selling alcohol in a licensed venue across Australia. The unit of competency is SITHFAB021 (Provide Responsible Service of Alcohol), delivered by Registered Training Organisations (RTOs) approved by state regulators. Workers who complete the course receive a Statement of Attainment from the RTO. In NSW and VIC, they also receive a state-issued competency card with a unique number and expiry date.
The compliance chain looks simple. A worker gets trained, gets certified, presents their certificate to the employer, and goes to work. But the verification link in that chain is almost entirely visual. Someone checks the document, notes the expiry date, and moves on. For labour hire operators placing casual staff across multiple venues and multiple states, that visual check is often done under pressure, by coordinators who are not trained document examiners, and for workers they may be placing on their first shift.
That is where the problem lives.
Who is legally responsible when an RSA certificate is fake?
This is the question nobody asks until something goes wrong. The answer is not what most operators expect, and it varies by jurisdiction.
The licensee (venue) carries primary statutory liability.
Under s.149 of the Liquor Act 2007 (NSW), licensees are liable for the acts of their employees and agents as if they committed the act themselves. This is near-strict vicarious liability. A limited "reasonable precautions" defence exists under s.149A, but it applies specifically to club managers, not to licensees generally.
Queensland's approach under s.229 of the Liquor Act 1992 (Qld) creates a rebuttable presumption of employer liability: if an employee commits a relevant offence, the employer is presumed to have participated. The employer can rebut that by proving they had no knowledge and could not reasonably have known, but the burden sits with them.
Victoria goes further. Section 53B of the Liquor Control Reform Act 1998 creates personal criminal liability for officers of corporate licensees who fail to exercise due diligence to prevent liquor offences.
Western Australia has the harshest position of all. Section 165 of the Liquor Control Act 1988 (WA) makes licensees liable for the acts of their employees and agents in the same terms as the other states. But subsection (3) goes further than any other jurisdiction: it explicitly provides that it is not a defence to show the licensee did not know, could not reasonably have been aware of, or had taken reasonable steps to prevent the employee's offence. In WA, where there is no central RSA register and no employer-facing verification tool, the liability is fully strict and the usual defences simply do not exist.
South Australia takes a similar approach. Under the Liquor Licensing Act 1997 (SA), the licensee and manager of licensed premises are each liable when liquor is sold or supplied in breach of the Act by any person on those premises. Good faith is not a blanket defence to the primary offence.
Labour hire operators face a parallel exposure.
When a labour hire company places a worker at a licensed venue, the venue is the licensee and holds primary liability under the liquor acts. But the labour hire company is still exposed through its own obligations: the Labour Hire Licensing Act 2018 (Vic) and equivalent legislation in other states impose separate compliance obligations on the placing entity. Work Health and Safety obligations create a further layer.
A fraudulent certificate presented by the worker does not transfer liability away from either party. It creates separate pathways: the venue faces regulatory exposure under its liquor licence, and the labour hire company faces compliance exposure under its own licensing obligations and civil liability for placing an unqualified worker.
The incident liability framing matters more than the fine.
An infringement notice is one thing. A fake RSA at the time of a serious incident is another. An overservice injury, a minor served, or a patron assault will trigger civil liability, liquor licence review, and potentially criminal charges for the licensee. Courts and regulators treat the absence of a valid RSA at the time of an incident as directly relevant to culpability: it removes the primary compliance defence and opens the door to the full range of penalties under the relevant liquor act. A fraudulent RSA, one that was never valid at all, is worse than an expired one.
Does good faith provide a defence?
Partially. "We checked and it looked genuine" is not a complete defence to the regulatory offence itself. The statutory obligation is to ensure staff actually hold valid certification, not merely that they present a document claiming to evidence it. Good faith and documented reasonable steps are relevant to prosecutorial discretion and to sentencing, but they do not extinguish the infringement.
What the worker faces
Presenting a fake RSA certificate is a criminal offence under fraud and forgery law in every state.
Under s.192E of the Crimes Act 1900 (NSW), obtaining financial advantage by deception (wages from employment obtained by presenting a forged certificate) carries up to 10 years imprisonment. Making or using a false document under the forgery provisions carries the same maximum. In Victoria, s.83A of the Crimes Act 1958 covers making false documents with intent to have them accepted as genuine: up to 15 years. Commonwealth provisions under the Criminal Code Act 1995 can also apply, given SITHFAB021 is a nationally recognised VET unit.
The individual is not off the hook. But that does not help the venue or the operator after an incident.
What the penalties actually look like by state
Current penalty unit values and the corresponding penalties for RSA non-compliance:
NSW (Liquor Regulation 2018, Clause 63): a licensee who permits a staff member to work without a current RSA competency card faces an infringement notice of $1,100. The maximum court penalty is $5,500 (50 penalty units at $110 each). The staff member faces $220, or $440 in a prescribed precinct.
VIC (LCRA 1998, s.108AC): a licensee who fails to ensure staff complete an approved RSA program faces a maximum court penalty of 60 penalty units. At the 2025-26 value of $203.51 per unit, that is $12,211. For a body corporate, the maximum rises to 500 penalty units: $101,755. Victoria also operates a demerit point system; serious or repeat breaches can trigger licence suspension or cancellation.
QLD (Liquor Act 1992): licence condition breaches attract penalties up to 40 penalty units ($6,908 at the current rate of $172.70). Serious irresponsible service offences carry up to 500 penalty units ($86,350) for licensees. In Queensland, workers must complete RSA within 30 days of starting employment, and licensees must keep copies of all Statements of Attainment on premises for inspection by OLGR and police.
WA (Liquor Control Regulations 1989, Reg 14AG): if a staff member has not completed RSA within 28 days of commencing employment, the licensee faces a $5,000 penalty. Licensees must maintain a training register recording each staff member's certificate details, available for inspection at all times.
Why the verification system is structurally fragile
Even operators who want to verify properly run into a fundamental problem: the system itself is not designed for verification at scale.
RSA certification is state-by-state. Each jurisdiction has its own regulator, its own document format, its own validity period, and its own verification mechanism. There is no single national RSA verification database. There is no employer-facing API. A labour hire operator placing staff across NSW, VIC, and QLD in the same week is navigating three separate regulatory regimes with three different document types and three different verification tools.
NSW issues a competency card via Service NSW (the CCH card), valid 5 years. The digital version can be verified in real time via the Service NSW app.
VIC issues a certificate through Liquor Control Victoria (LCV), now valid for 3 years following the introduction of mandatory SHARPR module renewal from December 2025. Certificates can be verified via the VCGLR (Victorian Commission for Gambling and Liquor Regulation) status check tool.
QLD issues nothing centrally. The Statement of Attainment from the RTO is the only evidence. There is no Queensland database of RSA holders. Verification relies on contacting the issuing RTO directly, which takes days and is entirely manual.
WA is the same. No central card, no central database. The Statement of Attainment from the training provider is what a worker presents, and approximately 1,000 DLGSC-approved RTOs are authorised to issue them, each in a different format.
WA and QLD have no central RSA register and no employer-facing verification tool. Yet WA has the strictest liability in the country (s.165 Liquor Control Act 1988 explicitly removes the "reasonable steps" defence). Operators placing staff in these states carry the highest verification burden with the least infrastructure to support it.
This is not an oversight. It is how each state built its own regime independently over several decades. But it means the verification burden falls entirely on employers and platforms, with no infrastructure to support it.
How to verify an RSA certificate in each state
Practical verification steps, by jurisdiction:
NSW: Require the digital competency card viewed live in the Service NSW app, not a screenshot or a photo of the physical card. The live app pulls from the L&GNSW database in real time. Record the CCH number, expiry date, and date of verification in your training register.
VIC: Cross-reference the certificate number against the VCGLR status check tool before the worker's first shift. From December 2025, also confirm completion of the SHARPR module, which is a mandatory additional requirement for VIC certification.
QLD and WA: Check the RTO number on the Statement of Attainment against training.gov.au. This confirms whether the organisation exists, holds current scope to deliver SITHFAB021, and held that scope at the date the certificate was issued. An RTO that lost its scope after issuing a certificate may still have issued a valid certificate at the time; date-bounding that check matters. Record the RTO number and certificate number in your training register.
All states: Consider requesting the worker's USI (Unique Student Identifier) VET transcript through usi.gov.au with their consent. The USI system records all nationally recognised VET completions reported by RTOs. It is the closest thing to a government-backed verification tool available to employers.
USI only covers completions from January 2015 onward, and this will not change. Workers who trained before that date have no USI record at all. A transcript pull returns nothing — not because they are unqualified, but because the system predates them. For experienced casual workers in their 30s or 40s, this gap is the rule rather than the exception. It is also the scenario most likely to involve a forged document, because there is nothing to cross-check it against.
USI also requires the worker's consent to access, and it records the underlying training completion, not the state-issued card status. A worker whose NSW competency card has lapsed still shows a completion on USI.
What "reasonable steps" looks like in practice
Documenting your verification process is the difference between a compliance matter handled administratively and one that results in prosecution. Based on the statutory frameworks across all four states, the following constitutes a documented reasonable steps defence:
- Sight the original document, not a copy or photo (interim certificate or competency card)
- Verify the certificate using the relevant state tool (Service NSW app, VCGLR portal, or training.gov.au RTO check)
- Record the certificate number, RTO name and number, issue date, expiry date, and the date and method of verification
- Store those records in a training register accessible to inspectors on request (this is a legal requirement in WA and QLD)
- Set expiry alerts: NSW cards expire at 5 years, VIC certificates at 3 years, other states have no expiry on the original cert but renewal requirements apply
- For QLD and WA specifically: confirm the issuing RTO appears on the state-approved provider list (QLD OLGR approved providers, WA DLGSC approved RTOs) in addition to the training.gov.au national register
The difference between a compliance field (a place to upload a PDF) and a compliance gate (a system that blocks rostering until verification passes) is the operational distinction that separates operators who are protected from operators who are exposed.
What we found building for this problem
At TwoStreams, we have processed over 3,400 real RSA certificates through our own automated verification pipeline, and WA is the hardest case in the country. Not because it is the largest state, but because the verification problem is most acute there: roughly 1,000 RTOs are approved to issue RSA certificates in WA, each producing their own document in their own format, with no central register to check them against.
The first approach we tried was training a fraud classifier to distinguish genuine certificates from fakes. It failed for a structural reason: you cannot train a fraud classifier when you cannot legally obtain examples of the negative class. Real forged RSA certificates are rare. Legitimate organisations do not manufacture convincing fakes at volume. The negative class simply does not exist in usable form.
What works instead is reading the document and checking what it claims against the national register. The training.gov.au API exposes the full register of RTOs and their scope of registration. For any given RTO number, it is possible to confirm the organisation exists, holds RSA delivery scope, that the unit codes on the certificate are legitimate SITHFAB021 units, and that the RTO held that scope on the date the certificate claims to have been issued. That last check, bounding the validity window to the issue date rather than today, catches a failure mode that is otherwise easy to miss: an organisation that has since lost its RSA scope may still have issued perfectly valid certificates while it was registered.
This approach does not substitute for a live government register lookup where one exists. In NSW and VIC, the digital card and VCGLR portal remain the gold standard. But for QLD and WA, issuer validation against the national register is the most reliable automated verification available.
The structural problem
The verification gap is a symptom of a deeper issue. Australia's compliance obligations for casual and gig workforces are genuinely complex, genuinely fragmented, and genuinely consequential. But the tooling has not kept pace with how work actually happens.
Events do not run on permanent staff. Venues staff up from casual pools at short notice. Labour hire operators place workers across multiple clients and jurisdictions in the same week. The compliance infrastructure was built for a world where an employer hired someone, checked their credentials once at onboarding, and kept them for years. It was not designed for the operational reality of modern shift-based labour hire.
Fixing it properly requires better data sharing between state regulators, a clearer employer access path to the USI system, and platforms that treat verification as a compliance gate rather than a compliance field. Until then, operators who build rigorous verification processes and document them carefully carry a material legal and competitive advantage over those who do not.
TwoStreams is workforce management software built for gig-economy and casual labour-hire businesses in Australia. Join the waitlist to be first in line.