Workforce Risk · Redacted Case Study
ACS Approved. Still Exposed.
A Tier 2 security contractor held SIA Approved Contractor Scheme status. Evidence-led audit uncovered serious payroll, employment and corporate warning signs that regulatory approval alone had not exposed.
A Tier 2 security contractor held SIA Approved Contractor Scheme status. Evidence-led audit uncovered serious payroll, employment and corporate warning signs that regulatory approval alone had not exposed.
Case Summary — Redacted
- Sector
- UK Private Security
- Supplier Position
- Tier 2
- Regulatory Status
- SIA Approved Contractor Scheme (ACS)
- Audit Type
- Evidence-led Workforce Assurance
- Outcome
- Multiple interconnected assurance concerns requiring investigation
The supplier looked credible
It operated in a regulated UK industry.
It held Security Industry Authority Approved Contractor Scheme status.
It was a Tier 2 supplier operating within an established commercial supply chain.
- Workers attended sites.
- Services were delivered.
- Invoices were submitted.
From the perspective of an enterprise relying upon conventional supplier controls, there was little obvious reason to assume that the workforce beneath the contract required substantially deeper investigation.
Then the audit moved beyond accreditation and supplier declarations.
What emerged was not one isolated compliance issue.
It was a series of interconnected questions across employment, payroll, corporate structure, payment evidence, subcontracting and audit cooperation.
Individually, each anomaly required investigation.
Together, they demonstrated why regulatory approval and workforce assurance are fundamentally different things.
The supplier was ACS Approved
This point matters.
The case did not involve an obviously questionable business operating outside a regulated market.
The supplier operated within the UK private security industry and held SIA Approved Contractor Scheme status.
ACS approval is an important component of security-industry procurement and provides customers with independent assurance against the requirements of the scheme.
HMRC itself recognises SIA and ACS status as relevant controls when considering labour supply-chain assurance within the security industry.
But HMRC recommends something else as well:
Audit the underlying workforce.
Current HMRC labour supply-chain guidance identifies security workforces as potentially exposed to risks including employment-status non-compliance, organised labour payroll fraud, cash-in-hand arrangements, complex tax-avoidance arrangements and disguised or offshore payment structures.
Its recommended controls therefore extend beyond accreditation to checking subcontractors, employment arrangements and payslips and conducting regular audits against contractual requirements.
This case illustrates why.
ACS approval provided an important control. It did not answer every question sitting underneath the workforce.
The contract said one thing. The workforce evidence raised questions about another.
The contractual model required the contracted supplier to provide appropriately employed and compliant labour.
As the audit progressed, evidence emerged indicating that some workers associated with delivery of the contracted services may have been connected with another company rather than the contracted Tier 2 supplier itself.
That immediately changed the nature of the audit.
The question was no longer simply:
“Is our ACS Approved supplier compliant?”
It became:
“Who actually employs these people?”
That question is fundamental.
Because once another legal entity appears between the contracted supplier and the worker, a series of further questions follows.
- Who operates PAYE?
- Who pays the worker?
- Who holds the employment contract?
- Who carries Employers' Liability insurance?
- Who accounts to HMRC?
- Was the use of that entity permitted under the principal contract?
- Was the entity disclosed?
- Was it itself subject to appropriate due diligence?
And ultimately:
Did the enterprise actually know who was supplying its workforce?
Finding 01
The declared employer required verification
Worker and employment information obtained during the audit raised questions about whether all individuals delivering services were employed by the organisation the customer believed was supplying them.
Evidence pointed towards involvement by another corporate entity in elements of the workforce arrangement.
That is not an administrative detail.
The identity of the legal employer determines or affects:
- employment obligations;
- payroll responsibility;
- PAYE;
- National Insurance;
- pension obligations;
- employment rights;
- insurance;
- right-to-work controls; and
- accountability for the workforce.
A workforce can look identical operationally while being completely different legally.
The same officers arrive at the same sites. They perform the same duties. They wear the same uniforms. The service continues uninterrupted.
But underneath them, the legal and financial structure may be materially different from the one the enterprise believes it has contracted with.
Finding 02
Payroll documents raised verification concerns
The audit examined payroll evidence associated with workers delivering the service.
Questions arose regarding the consistency and provenance of some of the documentation presented.
That created a need to move beyond the document itself.
A payslip is evidence.
But it is not necessarily proof that the worker received the money stated.
And it is not, by itself, proof that the associated deductions reached HMRC.
This creates an essential audit principle:
Never verify a document only against itself.
A meaningful payroll audit seeks independent corroboration.
Audit Principle
A document is evidence. Corroboration provides assurance.
A payslip is a starting point — not a conclusion.
Assurance comes from reconciling the evidence across the entire sequence.
The Evidential Sequence
- 1Worker
- 2Shift / Attendance
- 3Legal Employer
- 4Payroll Record
- 5Payslip
- 6Bank / BACS Payment
- 7PAYE / NI Record
- 8HMRC
If the evidence cannot be reconciled across those points, the payslip becomes the beginning of the audit rather than the end of it.
This is particularly significant because HMRC warns that fraudulent documentation can be used by non-compliant businesses to conceal organised labour fraud and recommends direct sampling of worker payslips as part of supply-chain assurance.
Finding 03
Evidence of wage payment became critical
Questions around payroll led naturally to the next evidential test:
Did the money actually reach the worker?
Assertions concerning payment cannot provide the same level of assurance as independent payment evidence.
Where proportionate, lawful and contractually available, an effective audit may therefore seek evidence capable of reconciling the net pay on the payslip with payment to the worker.
That might involve appropriate bank or BACS evidence or other independently verifiable payment records.
Where cash payment is asserted, the evidential challenge becomes greater.
Cash itself does not establish non-compliance. But it reduces the independent transaction trail available to corroborate the payroll record.
That should increase rather than decrease the level of assurance required.
Finding 04
Another company appeared in the workforce chain
The investigation identified the involvement of another corporate entity associated with elements of workforce provision.
That matters because an enterprise's assurance is only as complete as its understanding of the businesses actually operating within its chain.
Once another entity appears, the audit needs to establish:
- its legal identity;
- directors;
- ownership;
- trading history;
- financial status;
- VAT status;
- PAYE arrangements;
- insurance;
- relationship with the Tier 2 supplier;
- relationship with the workers;
- contractual authority to participate; and
- whether the customer knew it existed.
Corporate status also matters.
Where entities within a labour chain experience insolvency, failure or replacement while substantially the same workforce continues operating, that is a recognised risk indicator requiring investigation.
HMRC specifically identifies supplier insolvency followed by a new supplier continuing to provide substantially the same workforce as a potential labour supply-chain risk indicator.
Finding 05
Corporate changes mattered
Corporate due diligence cannot be performed once and forgotten.
Companies House information and related corporate records can reveal changes in:
- directors;
- ownership;
- registered addresses;
- company names;
- financial condition;
- insolvency history; and
- relationships with other businesses.
None of these changes individually establishes wrongdoing.
But patterns matter.
HMRC's current guidance identifies matters including changes in directorship, multiple directorships, previous business failures, bankruptcies, subtle changes in business names and limited trading histories as information capable of contributing to a labour supply-chain risk assessment.
The lesson is not that changing a director is suspicious.
It is that:
Corporate change within a labour supply chain should trigger reassessment rather than simply disappear into Companies House history.
Finding 06
Audit resistance became a risk indicator in itself
Perhaps one of the most important lessons arose not from the information provided, but from the information that proved difficult to obtain.
The contractual arrangements provided audit and information rights.
Yet obtaining the records necessary to complete the reconciliation became a material part of the exercise.
That matters.
A supplier may have a perfectly legitimate explanation for a missing document.
But repeated inability or reluctance to provide information necessary to verify the workforce changes the risk profile.
HMRC itself identifies a supplier being reluctant or unable to provide information as a potential supply-chain risk indicator.
The practical lesson is simple:
An audit right has little value if the enterprise is unwilling or unable to enforce it.
The pattern matters more than any individual anomaly
None of these indicators should automatically be treated as proof of fraud.
- A changed director is not proof of fraud.
- A failed company is not proof of fraud.
- A payroll discrepancy is not proof of fraud.
- A missing document is not proof of fraud.
- Use of another company is not necessarily improper.
- A cash payment is not automatically unlawful.
But effective assurance does not examine each event in isolation.
It asks whether the events form a pattern.
In this case, the audit raised interconnected questions involving:
- 1Who employed the workers
- 2Who paid them
- 3Which company appeared on the records
- 4Whether payroll evidence could be corroborated
- 5Whether other corporate entities were involved
- 6What happened to those entities
- 7Whether the supplier provided the information required
At that point, the issue is no longer ordinary supplier administration.
It is an enterprise assurance problem.
What if nobody had looked?
This is perhaps the most important part of the case.
- The security officers would still have attended work.
- The customer would still have received its security service.
- The Tier 1 contractor would still have received invoices.
- The Tier 2 contractor would still have appeared within the approved supply chain.
- And its SIA Approved Contractor Scheme status could have provided additional comfort.
Without an evidence-led audit, there may have been no obvious operational event requiring the enterprise to look underneath the arrangement.
That is precisely the vulnerability.
A labour supply chain does not have to fail operationally to be failing underneath.
The Question This Case Left Behind
What would we have known if nobody had looked?
A supplier can be established. It can operate in a regulated industry.
It can hold recognised accreditation. It can deliver the service every day.
And the enterprise can still have a material assurance gap underneath it.
What could the enterprise have been exposed to?
The precise legal and tax consequences always depend upon the facts and applicable law.
But inadequately controlled labour arrangements can create potential exposure across several areas.
Tax
Where tax obligations are not correctly discharged within labour chains, HMRC can investigate not only the defaulting business but transactions and businesses associated with the non-compliance. Current HMRC guidance expressly warns businesses about potential financial consequences arising from association with fraud within their supply chains.
Employment
Where the true employer or engagement model is unclear, questions can arise concerning employment status, minimum wage, holiday pay, pensions and other worker rights.
Insurance
If the entity actually employing or supplying the workforce differs from the entity represented within the contractual structure, the enterprise needs to understand whether appropriate insurance applies to the actual arrangement.
Regulatory
In a regulated workforce, the enterprise needs to understand not merely whether its supplier holds ACS status, but whether the workforce arrangement operating beneath it remains consistent with the contractual and regulatory framework upon which the enterprise is relying.
Operational
Regulatory intervention, insolvency, tax enforcement or sudden removal of a supplier can disrupt the availability of labour required to deliver critical services.
Reputational
The public distinction between “your employee” and “an employee of your contractor's subcontractor” can disappear rapidly when allegations concern worker exploitation, tax fraud or serious labour abuse occurring while those individuals are delivering services for a recognised corporate brand.
ACS approval was a control. Audit provided the assurance.
This is the central lesson from the case.
The supplier's SIA Approved Contractor Scheme status mattered. It formed part of the control environment.
But it could not answer every question the enterprise needed answered.
It could not replace:
- workforce sampling;
- payroll reconciliation;
- corporate due diligence;
- payment verification;
- subcontractor disclosure;
- contractual audit rights;
- evidence gathering;
- exception management; or
- enforcement.
That distinction is fundamental.
ACS Approval Asks
Has the contractor satisfied the requirements of the scheme?
Enterprise Assurance Asks
Can we evidence what is actually happening in our supply chain today?
Both matter. They perform different functions.
The Central Lesson
ACS Approved. Still Exposed.
ACS approval provides an important control.
Enterprise assurance tests the underlying evidence.
The Tutandos approach
The methodology developed from cases such as this is deliberately evidence-led.
01
Identify
Establish every material business and workforce relationship between the enterprise and the worker.
02
Verify
Do not rely upon a single document where independent corroboration is available.
03
Reconcile
Connect deployment → worker → employer → payroll → payment → tax and identify where information does not align.
04
Investigate
Treat anomalies as questions requiring evidence rather than jumping immediately to conclusions.
05
Enforce
Use contractual information and audit rights where suppliers fail to provide the evidence necessary for assurance. Work alongside legal advisers where formal enforcement is required.
06
Monitor
Continue assurance after the initial audit. Companies, directors, workers, payroll structures, financial circumstances and subcontractors change. The risk assessment needs to change with them.
07
Assure
Translate detailed audit activity into meaningful board-level information. Leadership should understand what was tested, what evidence was obtained, what could not be verified, what anomalies were identified, what further investigation occurred, what remediation was required and what residual risk remains.
The question this case left behind
The most important question was not:
“How did an ACS Approved supplier generate these audit concerns?”
It was:
“What would we have known if nobody had audited beneath the ACS approval?”
For boards relying upon outsourced workforces, that question extends far beyond the security industry.
- A supplier can be established.
- It can operate in a regulated industry.
- It can hold recognised accreditation.
- It can deliver the service successfully every day.
And the enterprise can still have a material assurance gap underneath it.
The Board Test
For every material outsourced workforce, ask:
Visibility. Evidence. Control.
Regulation provides a control. Evidence provides assurance.
Tutandos provides enterprises with the audit capability, contractual framework and continuing monitoring required to understand what is actually happening within outsourced workforces.
Because sometimes the most important question is not whether your supplier has been approved.
It is whether anybody has looked underneath it.
Sources & Further Reading
Authoritative HMRC material on labour supply-chain assurance
The guidance below is published by HMRC and is independent of the anonymised Tutandos case study above. It informed the audit principles described in this article.
- HMRC — Help with Labour Supply Chain Assurance (GfC12)
- HMRC — GfC12 security workforce examples
- HMRC — Organised Labour Fraud
- HMRC — Recommended Approach to Assurance
- HMRC — Contractual Process and Recommended Steps
The case study above is based on a real UK labour supply-chain audit and has been fully anonymised. It does not identify the supplier, the principal contractor, the corporate end customer, individual employees, directors, specific sites or any commercially identifying information. References to HMRC guidance describe publicly available HMRC material and do not imply that the SIA or ACS endorsed any of the individual practices or circumstances identified by the audit.
Assess Your Workforce Risk
If this could exist beneath an ACS Approved supplier, what are you relying upon elsewhere in your own outsourced workforce?
