I think an easier approach would be some sort of mandatory indemnity. Rather than trying to impose specific practices which very well may vary greatly depending on the domain, just levy automatic penalties for breaches and set them high enough to encourage action.