Workforce Risk · Board Briefing

Is Organised Crime Sitting Inside Your Supply Chain?

Your risk may sit only one tier below you. Even regulated, accredited Tier 2 contractors can conceal serious payroll, tax and workforce failures — and the consequences still travel back to the enterprise.

Your risk may sit only one tier below you. Even regulated, accredited Tier 2 contractors can conceal serious payroll, tax and workforce failures — and the consequences still travel back to the enterprise.

Large organisations increasingly depend on people they do not directly employ. Security officers, facilities staff, construction workers, cleaners, engineers, drivers, agency workers and temporary labour may all be supplied through contractors, subcontractors, agencies, umbrella companies and other intermediaries.

Operationally, that model is normal. But it creates a fundamental risk-management problem:

You may know who you contracted with without knowing who actually employs, pays or controls the people delivering your service.

And critically, the risk does not have to be buried five or seven tiers down an opaque supply chain. It can exist at Tier 2. It can exist within a contractor that is regulated. It can exist within a contractor that holds recognised industry accreditation. It can exist within an organisation that has passed supplier onboarding and appears compliant on paper.

Regulation and accreditation are important controls. They are not substitutes for continuing assurance.

HMRC explicitly recognises that labour supply chains are targeted by non-compliant individuals and groups seeking to exploit outsourced labour arrangements. The workers can continue turning up. The service can continue being delivered. The invoices can continue being approved. From the corporate customer's perspective, everything can appear normal. Underneath, something very different may be happening.

This is not a theoretical risk

HMRC has investigated precisely this type of supply chain. In one construction-sector case:

7

Tiers between end-user and visible worker

£3.5m

VAT fraudulently diverted from HMRC

Multiple

Businesses defaulting on VAT

There was also evidence of illegal workers and multiple businesses defaulting on VAT. When businesses disappeared following HMRC intervention, replacement businesses appeared and the fraud continued. The criminality was buried inside an apparently functioning commercial supply chain.

But the consequences did not remain there. HMRC issued tax-loss letters to businesses above the defaulting companies, including end-users. Multiple companies were denied VAT Input Tax and received penalties. Further enforcement action was taken lower down the chain.

The larger organisation at the top was not necessarily participating in the fraud. But it was connected to a supply chain through which serious fraud was taking place. That distinction matters.

You do not need to be committing the fraud for fraud inside your supply chain to become your problem.

Regulated does not mean risk-free

There is a dangerous assumption in supply-chain governance: if a supplier is regulated or accredited, somebody else has already checked it. Regulation, licensing and accreditation can provide valuable independent controls. But they do not remove the enterprise's need to understand what is happening within its own supply chain.

A supplier can hold the required licence, maintain an industry accreditation, have appropriate policies, provide insurance certificates and satisfy procurement requirements — and serious compliance failures can still occur.

The issue is particularly important where an accredited Tier 2 contractor itself employs the workforce. At that point, the enterprise is relying upon the integrity of the contractor's:

  • employment records;
  • payroll;
  • worker identity information;
  • tax treatment;
  • wage payments;
  • right-to-work controls;
  • insurance;
  • subcontracting arrangements; and
  • underlying compliance evidence.

The presence of a regulator or accreditation scheme should therefore form part of the assurance framework. It should not replace it. Accreditation tells you a supplier has met the requirements of a scheme. Assurance tells you whether the evidence in your supply chain stands up today.

How can organised crime sit inside a legitimate supply chain?

The mechanics can be surprisingly simple.

  1. 1Your organisation
  2. 2Tier 1 — Principal contractor
  3. 3Tier 2 — Regulated / accredited contractor
  4. 4Workforce

Or the chain can continue:

  1. 1Labour provider
  2. 2Payroll / umbrella company
  3. 3Another intermediary
  4. 4Employing company
  5. 5Worker

The risk can therefore arise in a relatively short chain or a highly complex one. Further businesses can be inserted to receive payments, operate payroll or supposedly employ workers. Payroll responsibilities and tax liabilities can move through those entities. At the bottom of a fraudulent structure, an entity can default on its liabilities, disappear or be replaced. The workforce continues working. Another company takes its place. And the process can begin again.

The worker may be the first victim

Tax fraud is only part of the exposure. The same lack of visibility that allows financial crime to remain hidden can conceal exploitation of the workforce itself. Potential risks within poorly controlled labour chains include:

  • illegal working;
  • wages being withheld or diverted;
  • unlawful deductions;
  • workers being paid below statutory minimums;
  • false employment arrangements;
  • tax deductions not reaching HMRC;
  • loss of employment rights;
  • exploitative recruitment;
  • coercion;
  • forced criminality;
  • debt bondage; and
  • modern slavery.

Workers themselves may not even know that they are part of a fraudulent labour structure. The enterprise purchasing their labour can be even further removed from what is happening. This produces one of the most uncomfortable characteristics of outsourced workforce risk:

The exploitation may be several tiers away. The newspaper headline won't be.

Organised crime can also move up the chain

The risk is not confined to unknown companies at the bottom. Individuals within legitimate organisations can themselves become part of supply-chain fraud. The mechanisms can include:

  • bribery;
  • corruption;
  • money laundering;
  • falsification of due diligence;
  • deliberately bypassing supplier controls;
  • introducing connected companies into procurement processes; and
  • facilitating contracts with businesses involved in fraudulent structures.

This changes the nature of the risk. It is no longer simply:

"Is one of our suppliers dishonest?"

It becomes:

"Does our control environment make it possible for a dishonest supplier — potentially assisted by somebody inside our own organisation — to enter and remain within our labour supply chain?"

That is an enterprise governance question.

Operational distance does not create risk distance

A fraudulent business might be four contractual tiers below the enterprise. Or a serious compliance failure could sit within the regulated Tier 2 contractor actually employing the workforce. A worker may be employed by a company the enterprise has never heard of. A payroll company may never appear on the approved supplier list. An exploitative intermediary may have no contractual relationship whatsoever with the corporate customer.

Yet the labour ultimately delivers the corporate customer's service. And the consequences can travel upwards. These can include:

  • tax exposure;
  • denied VAT recovery;
  • penalties;
  • supply-chain disruption;
  • loss of workforce;
  • regulatory investigation;
  • operational failure;
  • association with tax fraud;
  • association with modern slavery or worker exploitation;
  • adverse media coverage;
  • customer concern;
  • investor concern; and
  • questions about the adequacy of corporate governance.

The critical question is therefore not "Is our supplier regulated?" nor simply "Did we appoint a reputable supplier?" It is:

"What evidence do we have that the workforce operating within our supply chain is actually compliant?"

The greatest risk may be the supplier you think has already been checked

Most sophisticated organisations already conduct supplier due diligence. They may obtain company information, accounts, insurance, regulatory licences, accreditations, policies, tax registrations, Modern Slavery statements, right-to-work procedures, employment policies and contractual warranties. These are all legitimate controls.

But they primarily tell you about the supplier at a particular point in time. They do not necessarily establish what is actually happening within that supplier's workforce today. The enterprise therefore needs to understand:

  • Who actually employs the workers?
  • Who operates payroll?
  • Who pays them?
  • Who accounts for PAYE and National Insurance?
  • Who holds the relevant insurance?
  • Do the people on the operational roster correspond with the people on the payroll?
  • Does the payslip correspond with an actual wage payment?
  • Do tax and payroll records support the employment position being represented?
  • Are other businesses involved that have not been disclosed?

The greatest supply-chain risks are often not the risks recorded in supplier questionnaires. They are the organisations, workers, employment arrangements and payment flows the enterprise has never independently verified.

Supplier approval is not supply-chain assurance

Due diligence at procurement is important. Regulatory approval is important. Accreditation is important. But none answers the continuing question: what is actually happening now?

Companies change. Directors change. Bank accounts change. Subcontractors change. Workers change. Employment models change. Payroll providers change. Financial pressure changes behaviour. And compliance itself can deteriorate after a supplier has been approved.

HMRC's current Guidelines for Compliance — Help with Labour Supply Chain Assurance (GfC12) therefore treat assurance as an ongoing process. Organisations should understand their supply chains and workforce, identify risk, verify information, monitor change and act when indicators of fraud or non-compliance emerge.

A supplier questionnaire asks:

"Do you comply?"

A regulator or accreditation scheme asks:

"Do you meet our requirements?"

An assurance programme asks:

"Can we evidence what is actually happening?"

That distinction is fundamental. A supplier can provide a policy; an assurance programme tests whether it is being followed. A supplier can provide an accreditation; an assurance programme tests the underlying workforce. A supplier can provide a payslip; an assurance programme can establish whether the worker exists, actually delivered the service, is genuinely employed by the declared business, with payroll records that correspond, money received matching the stated amount, and statutory records supporting the transaction.

The evidential chain can therefore move from:

  1. 1Shift worked
  2. 2Worker identified
  3. 3Legal employer
  4. 4Payroll record
  5. 5Payslip
  6. 6Net wage payment
  7. 7PAYE / NI liability
  8. 8HMRC payment

Each dataset provides another opportunity to corroborate the others. Where the evidence aligns, assurance increases. Where it does not, the discrepancy becomes a risk indicator.

Contractual rights determine how far you can see

An organisation cannot meaningfully audit a labour supply chain if it does not have the right to obtain the necessary information. That means assurance begins before the audit. Appropriate contractual architecture, developed with legal advisers where required, can establish:

  • rights of audit;
  • access to relevant records;
  • workforce-information requirements;
  • payroll evidence requirements;
  • tax-compliance obligations;
  • insurance obligations;
  • requirements to disclose subcontractors;
  • restrictions on onward subcontracting;
  • approval requirements for new suppliers;
  • record-retention requirements;
  • cooperation with investigations;
  • remediation requirements;
  • suspension provisions; and
  • termination rights.

Crucially, these requirements need to travel down the supply chain. An audit right against Tier 1 is of limited value if the workforce and the evidence sit at Tier 2. And an audit right against Tier 2 is of limited value if Tier 2 has itself moved labour provision further down the chain. The objective is to establish an enforceable route from the enterprise to the underlying evidence.

What does effective workforce assurance test?

The precise scope should be proportionate to risk. But a meaningful programme should be capable of testing four connected areas.

01

The Supply Chain

  • every material entity
  • contractual relationships between them
  • corporate ownership & directorship
  • trading history, VAT & PAYE status
  • relevant licences, accreditations & insurance
  • authority to subcontract

02

The Workforce

  • who is actually delivering the service
  • who employs or engages them
  • right-to-work evidence
  • required licences or qualifications
  • assignment & deployment records
  • attendance

03

Employment, Payroll & Tax

  • employment arrangements & payroll records
  • payslips & gross-to-net calculations
  • minimum-wage compliance
  • PAYE, NI & pension deductions
  • RTI information & HMRC payment evidence
  • VAT, CIS where relevant, and BACS wage evidence

04

Insurance

  • the insured legal entity
  • policy type, limits & exclusions
  • activities covered & validity dates
  • whether the employing entity benefits from the required cover

Fraud often reveals itself through inconsistency

No single anomaly necessarily proves wrongdoing. But effective assurance looks for inconsistencies between datasets. Potential indicators can include:

  • undisclosed subcontractors;
  • workers attached to unexpected employing entities;
  • unexplained changes of employer;
  • newly incorporated companies;
  • repeated changes of directors;
  • unusual numbers of small employing businesses;
  • workers absent from payroll;
  • differences between rosters and payroll;
  • payslips unsupported by payment evidence;
  • unusual cash-payment arrangements;
  • missing tax evidence;
  • unexplained changes of bank account;
  • discrepancies between invoices and worker numbers;
  • insurance belonging to a different entity;
  • businesses repeatedly disappearing and being replaced;
  • retrospective or inconsistent records; and
  • reluctance to provide information required under the contract.

An anomaly creates a question. Multiple anomalies create a pattern. A pattern requires investigation.

Finding the problem is not enough

Audit without action does not manage risk. An effective assurance framework therefore needs an escalation process:

  1. 1Identify
  2. 2Evidence
  3. 3Assess
  4. 4Remediate
  5. 5Escalate
  6. 6Assure

Depending upon severity, this can include:

  • additional evidence requests;
  • expanded workforce sampling;
  • forensic payroll reconciliation;
  • corrective-action plans;
  • enhanced monitoring;
  • removal of unapproved subcontractors;
  • restriction of further subcontracting;
  • suspension;
  • contractual enforcement;
  • involvement of legal advisers;
  • termination where appropriate; and
  • reporting to relevant authorities where required.

The objective is not simply to discover risk. It is to control it.

The board does not need to audit payslips. It needs evidence that somebody competent does.

What the board should be able to answer

For organisations with material outsourced workforces, leadership should be able to answer:

Do we know who is actually delivering services on our behalf?
Do we know every material organisation between us and those workers?
Do we know who employs and pays them?
Do we understand where the relevant tax responsibilities sit?
Are we relying on accreditation as evidence of current compliance — or independently assuring it?
Do our contracts provide meaningful audit and information rights?
Do those rights flow down the chain?
Do we test the underlying evidence?
Can operational deployment be reconciled with employment and payroll?
Do we independently verify information supplied to us?
Do we know which supply chains present elevated risk?
Do we have procedures for investigating anomalies?
Can we demonstrate what action we took?

If those questions cannot be answered confidently, the organisation has a workforce assurance gap.

Tutandos Workforce Assurance

Tutandos helps enterprises close that gap

We combine supply-chain visibility, contractual control, evidence-led audit, continuous monitoring and board-level assurance.

01

Assess

Map the labour supply chain from the enterprise through contractors, subcontractors and intermediaries to the actual workforce. Understand where employment, payroll, tax, regulatory and insurance responsibilities sit. Identify vulnerabilities and risk indicators.

02

Govern

Establish the control environment. Determine what suppliers must disclose, what evidence must be retained, what contractual rights are required, who owns assurance, how frequently testing occurs, how subcontracting is controlled and what happens when suppliers fail to comply. Where appropriate, Tutandos works alongside the enterprise's legal advisers.

03

Protect

Conduct risk-based, evidence-led audits. Move beyond declarations, regulatory status and accreditation certificates to reconcile operational workforce information against employment, payroll, payment, tax, insurance and regulatory evidence.

04

Monitor

Continue assurance throughout the commercial relationship. Monitor suppliers, subcontractors, workforce structures, corporate changes, insurance, employment models, identified exceptions, remediation and emerging risk indicators. Higher-risk chains receive greater scrutiny.

05

Assure

Translate detailed compliance activity into meaningful board-level information — material supply-chain exposure, high-risk suppliers, unidentified entities, audit status, evidence outstanding, material exceptions, remediation, overdue actions and residual risk.

The result is more than supplier due diligence. It is an evidential record of active governance and control.

The Board Test

If serious fraud were discovered in your labour supply chain tomorrow, could the organisation demonstrate…

We understood the risk.

We knew who was in the chain.

We established the controls.

We obtained the evidence.

We tested it.

We challenged what didn't add up.

We acted.

If not, the problem may extend beyond the criminality or non-compliance within the supplier. It may expose a weakness in the organisation's own assurance framework.

Visibility. Evidence. Control.

How far through your workforce can you see?

Assess Your Workforce Risk

A short conversation is usually enough to see how far through your supply chain you can actually evidence compliance.

Talk to Tutandos