FAQs · Labour Supply Chain Assurance · OPRaaS VCD

This page answers the questions OPRaaS hears most often from end-hirers, recruitment agencies, umbrella companies, managed service providers, public-sector buyers and Statement of Work programme owners. The answers are written for the Director, Tax, HR, Procurement, Recruitment and Payroll professionals who carry the labour supply chain risk inside those organisations.

Each answer references the operating model OPRaaS uses on customer engagements: labour supply chain assurance (LSCA) built on the OPRaaS Map, Train, Audit and Evidence discipline, delivered through the OPRaaS Virtual Compliance Director (OPRaaS VCD) platform. Where a question touches material taught in the OPRaaS LSCA Self-Certification Course, the relevant module is named so readers can locate the deeper treatment without the full course content being reproduced here.

Compliance is your asset. Evidenced daily.

About OPRaaS and labour supply chain assurance

What is OPRaaS?

OPRaaS, On-Pay-Roll-as-a-Service, is a systemised governance and workforce management partner for organisations that rely on temporary, contractor and contingent labour. We design and run labour supply chain assurance (LSCA 2.0) frameworks that keep end-hirers, recruitment agencies, umbrella companies and managed service providers compliant with fast-moving tax, employment and labour supply regulation, while optimising the use of temps, freelancers, contractors, interims and consultants.

What does On-Pay-Roll-as-a-Service mean?

It captures what OPRaaS does as a service: keep every worker who should be on a payroll on the right payroll, with documented controls evidencing that decision through the engagement lifecycle. The name signals that compliance with PAYE, IR35, CIS, GLAA, Modern Slavery and the wider HMRC labour supply chain expectations is delivered as an ongoing service, not as an annual audit or a one-off implementation.

What is the OPRaaS Virtual Compliance Director (OPRaaS VCD)?

The OPRaaS VCD is a retained governance function. Through OPRaaS’s Virtual Compliance Director solutions, senior governance leadership is embedded into the client organisation without the cost of a full-time director, building audit-ready controls across JSL, IR35, CIS, GLAA, Modern Slavery and HMRC’s wider labour supply chain expectations. The OPRaaS VCD platform captures the work as it happens, so the controls produce a continuous evidence record rather than a point-in-time report.

What is Labour Supply Chain Assurance (LSCA)?

LSCA is the assurance discipline that proves an end-hirer, recruitment agency, umbrella or MSP knows who is in its labour supply chain at every tier, how each tier is paid, and that the engagements are compliant with UK tax, employment and labour supply law. It is the buyer’s discipline, because the buyer chooses who enters the chain. The OPRaaS LSCA Self-Certification Course Module 3 sets out the five LSCA pillars and the five practical steps that make the discipline operable.

What is the OPRaaS LSCA 2.0 methodology?

LSCA 2.0 is OPRaaS’s current generation of the LSCA framework, designed for the April 2026 Joint and Several Liability (JSL) regime and the wider tightening of labour supply chain expectations. It is built around four operating stages: Map, Train, Audit and Evidence. Each stage produces an artefact that feeds the next, so the assurance record compounds month over month rather than being rebuilt at each audit cycle.

What does “Map, Train, Audit and Evidence” mean?

Map: identify every tier in the labour supply chain, every supplier, every flow of pay. Train: equip the named accountable owners to operate the controls. Audit: test the controls on a defined cadence against a documented standard. Evidence: capture the results in a continuous, dated, retrievable form inside the OPRaaS online platform and audit dashboards. From those four stages the platform can produce a Defence File on demand, the artefact a regulator, auditor or buyer can ask for on the day they ask for it.

What does OPRaaS mean by a Defence File?

The OPRaaS online platform and audit dashboards can produce a continuous, dated, hash-stamped evidence record on demand. They capture supplier checks, payroll samples, contract reviews, training completions, status determinations and incident logs in one retrievable place. When HMRC, the Fair Work Agency, the UK Government Commercial Agency or an internal audit team asks for evidence, the Defence File is the artefact that answers them. It is the operational form of the OPRaaS proposition that compliance is an asset.

What does “Compliance is your asset. Evidenced daily.” mean?

It is the OPRaaS proposition in two lines. Compliance work, when it is evidenced as it happens, becomes a documented control record that supports board confidence, customer due diligence, regulator engagement and procurement scoring. Without that evidence record, the same effort becomes a recurring cost. Continuous evidencing is what turns the spend into the asset, and the Own Your Compliance as an Asset page sets out the underlying argument.

Which UK Government frameworks is OPRaaS approved on?

OPRaaS is approved on the UK Government Commercial Agency (formerly Crown Commercial Service) frameworks including: RM6310 Audit & Assurance Services (Lots 2 and 4), RM6219 Learning & Training Services DPS, and RM6237 Learning & Training Services DPS. Central Government and the wider public sector can call off specialist labour supply chain assurance, training and implementation support through these routes.

Who does OPRaaS work with?

OPRaaS works with five audience groups: end-hirers that engage temporary or contingent labour at scale, recruitment agencies, umbrella companies, managed service providers (MSPs), and public-sector buyers. Statement of Work (SoW) programmes are treated as a service overlay across those audiences, not as a sixth audience, because an SoW engagement still sits inside one of the five buyer types.

How is OPRaaS different from an umbrella, an MSP, or an audit firm?

An umbrella employs workers and runs payroll. An MSP manages a programme of suppliers on behalf of an end-hirer. An audit firm reviews controls at a point in time. OPRaaS is none of those. OPRaaS is the buyer’s retained labour supply chain assurance partner, sitting outside the supply chain so that its assurance work is independent of the parties being assured. The OPRaaS VCD platform and audit dashboards deliver and capture the controls; a Defence File can be produced on demand to evidence them.

Does OPRaaS provide legal advice?

No. OPRaaS provides a governance and assurance service. The OPRaaS VCD operates the labour supply chain assurance discipline and produces the evidence record. Where a question of legal interpretation arises, OPRaaS works alongside the client’s own legal, tax and employment advisors and references published HMRC and statutory guidance directly. Anything OPRaaS publishes that reads a piece of HMRC guidance analytically is presented as an OPRaaS interpretation, not as HMRC’s position.

End-hirers

What is an end-hirer in UK labour supply chain terms?

An end-hirer is the organisation for which the temporary, contractor or contingent worker actually performs work. The end-hirer typically engages workers through one or more intermediaries, a recruitment agency, an umbrella company, a managed service provider, or an SoW supplier. Under the April 2026 JSL regime the end-hirer’s position in the chain matters because liability for unpaid PAYE can move up to it where intermediaries default. The OPRaaS LSCA Self-Certification Course Module 1 sets out the end-hirer’s position in the four exposure families.

Why does an end-hirer need labour supply chain assurance?

Because the end-hirer chooses the suppliers that enter its labour supply chain. From April 2026, unpaid PAYE liability can move up the chain under the Joint and Several Liability regime, and HMRC guidance is read as expecting buyers to assure the integrity of the chain rather than only perform point-in-time checks. Labour supply chain assurance gives the end-hirer a continuous, documented control record that shows what was checked, when, and by whom.

What is Joint and Several Liability (JSL) and when does it apply?

JSL is the regime under which more than one party in a labour supply chain may be liable for the same unpaid PAYE and National Insurance. From April 2026, where an umbrella in the chain fails to operate PAYE correctly, HMRC may collect from the recruitment agency or, where applicable, from the end-hirer. The statutory location is Chapter 11 of Part 2 of the Income Tax (Earnings and Pensions) Act 2003 (ITEPA 2003) as amended by the Finance Act 2026 supporting clauses.

From when does end-hirer JSL exposure for unpaid PAYE start?

From 6 April 2026, in line with the commencement provisions of the relevant Finance Act 2026 clauses inserting JSL into ITEPA 2003 Chapter 11. The regime applies to PAYE and NIC obligations arising from that date onward. Earlier engagements remain subject to the rules that applied at the time. The OPRaaS LSCA Self-Certification Course Module 11 covers the 2026 regime in detail across six topics.

Which statute governs the 2026 JSL regime?

Chapter 11 of Part 2 of ITEPA 2003, inserted and extended by the relevant Finance Act 2026 clauses. The chapter sets out who in the chain is treated as the deemed employer for PAYE purposes when the actual umbrella defaults, and the procedural route HMRC uses to collect. OPRaaS reads the chapter alongside HMRC’s published guidance on applying supply chain due diligence principles to assure labour supply chains.

What is HMRC Regulation 80 and how does it relate to JSL?

Regulation 80 of the Income Tax (Pay As You Earn) Regulations 2003 is HMRC’s procedural tool for crystallising unpaid PAYE against a specific person. Under JSL, HMRC may issue Reg 80 determinations against the umbrella, the agency or the end-hirer depending on where the law allocates the liability. OPRaaS includes a Reg 80 incident response playbook in its OPRaaS VCD operating model so that any notice received is met with a structured evidence and engagement response.

Does an indemnity clause in a supplier contract protect us from JSL?

An indemnity supports a contractual claim against the supplier; it does not displace a statutory tax liability that HMRC has the power to collect from the end-hirer or agency. If the supplier is insolvent, has phoenixed or is otherwise unable to pay, the indemnity has nothing to attach to. OPRaaS treats indemnities as a useful, but secondary, control. The primary control is continuous evidence that the supplier was operating compliantly through the engagement, captured by the OPRaaS VCD platform and retrievable as a Defence File on demand.

What evidence do HMRC, the Fair Work Agency, or the UK Government Commercial Agency want to see?

A continuous, dated, retrievable record showing what was checked, by whom, when, against which standard, with the source documents attached. The OPRaaS online platform and audit dashboards capture that record continuously and produce it as a Defence File on demand. The output covers supplier due diligence, identity and right-to-work checks, payroll samples, contract reviews, training completions, IR35 status determinations, incident logs and renewal cycles. The point is to show the assurance pattern over time, not to produce a snapshot.

What is a “purported umbrella” and why does the term matter?

“Purported umbrella” is the term HMRC uses for an entity holding itself out as an umbrella company while not operating as a compliant employer for PAYE purposes. Whether the entity is formally an umbrella in name is not the test. JSL treats the substance, not the label. OPRaaS Module 11 covers purported umbrella patterns alongside high-take-home claims, disguised remuneration, loan and advance structures and phoenix chain anatomy, so that a buyer’s due diligence is targeted on the patterns that matter.

What checks should an end-hirer expect on its umbrella suppliers?

At a minimum: company and director verification, PAYE registration confirmation, sample payslip analysis, holiday pay treatment, NMW and NLW arithmetic, contract review, RTI submission sampling, ownership-change monitoring, beneficial-owner check, sanction-and-PEP screening, GLAA position check where applicable, and a documented onboarding and re-audit cycle. The OPRaaS approach groups the checks into the CAR Principles, Credibility, Assurance and Risk, as set out in OPRaaS LSCA Module 4.

How often should we re-audit Preferred Supplier List (PSL) umbrellas?

OPRaaS recommends a re-audit cadence built around the supplier’s risk rating, not a fixed annual cycle. Higher-risk suppliers and those with recent ownership changes, RTI anomalies or worker complaints are re-audited more frequently. Lower-risk suppliers operating on a stable footprint are re-audited at defined intervals against the same standard, so trend is visible. The OPRaaS LSCA Module 3 topic on PSL frequency and scope sets the framework.

What is the role of a Senior Responsible Owner (SRO) in LSCA?

The SRO is the named individual inside the end-hirer who is accountable for the labour supply chain assurance programme. The role exists so that the discipline has a single owner whose remit is documented, whose decisions are captured and who is the point of escalation when an incident requires a coordinated response. OPRaaS LSCA Module 3 sets out the SRO position alongside the “Know Your Estate” concept and the Take Control / Assign Responsibility steps of the framework.

How does Modern Slavery Act 2015 s.54 connect to labour supply chain assurance?

Section 54 of the Modern Slavery Act 2015 requires qualifying businesses to publish an annual statement setting out the steps taken to ensure modern slavery is not occurring in their business or supply chains. Labour supply chains are the highest-risk area for many end-hirers, so the s.54 statement and the LSCA evidence record share the same source data. OPRaaS LSCA Module 5 covers worker exploitation risk management, incident response and the operational signs to look for in the chain.

What is the Corporate Criminal Offence under CFA 2017?

Sections 45 and 46 of the Criminal Finances Act 2017 create a corporate offence where a business fails to prevent the facilitation of UK tax evasion (s.45) or overseas tax evasion (s.46) by an associated person. The statutory defence is “reasonable prevention procedures”. OPRaaS LSCA Module 6 maps the six guiding principles HMRC has published for those procedures, alongside the risk assessment, communication, training and monitoring activities that evidence the defence.

How does GDPR affect labour supply chain assurance?

UK GDPR and the Data Protection Act 2018 set the rules for handling worker data inside the assurance programme. Lawful basis, purpose limitation, data minimisation and accountability all apply. OPRaaS LSCA Module 10 sets out the seven principles of data processing alongside worker rights such as subject access, rectification, erasure, restriction and objection, and explains how data-protection abuse can itself be a Modern Slavery indicator inside a labour supply chain.

What are the four exposure families in labour supply chain risk?

OPRaaS LSCA Module 1 names them: financial penalties (PAYE, CIS, NIC, VAT), reputational damage (Modern Slavery, exploitation), criminal liability (CFA 2017 corporate offence) and operational disruption (frozen contracts, lost framework places, executive time absorbed by enquiry response). The four families are useful at board level because they map labour supply chain assurance to risks the board already governs through other functions.

What is the one-page JSL board report?

It is OPRaaS’s standard board reporting format for labour supply chain assurance, structured around six fixed sections: Executive snapshot, Exposure, Control maturity, Key incidents, Action plan and Forward look. The format is short, repeatable and comparable cycle on cycle. Board directors get the same shape of report every quarter, so trend in control maturity and exposure becomes visible rather than buried inside changing narrative. OPRaaS LSCA Module 11 sets out the format.

Recruitment agencies

What is a recruitment agency’s exposure under April 2026 JSL?

The recruitment agency sits in the middle of the chain between the worker, the umbrella and the end-hirer, so unpaid PAYE arising from an umbrella default may be collected from the agency before, or instead of, the end-hirer. The agency’s assurance work, especially its PSL management, supplier onboarding and ongoing monitoring, is therefore directly relevant to its own balance sheet, not only to its clients’. The OPRaaS LSCA Module 11 covers the agency position in detail.

How does JSL interact with IR35 for an agency?

IR35 (the off-payroll rules in ITEPA 2003 Chapter 10) governs status determination for workers operating through their own intermediary. JSL (Chapter 11) governs liability for unpaid PAYE in umbrella chains. The two chapters address different fact patterns but often live inside the same agency book of business. OPRaaS LSCA Module 9 covers the contract compliance angle and Module 11 covers the JSL angle, so the agency’s controls cover both without gaps.

What is a Key Information Document (KID)?

The Key Information Document is the written summary an employment business must provide to a work-seeker before contractual terms are agreed, under the Conduct of Employment Agencies and Employment Businesses Regulations 2003 (as amended). It sets out pay rates, deductions, holiday entitlement, who pays the worker and any intermediaries involved. KID compliance and consistency with the actual payslip is a routine OPRaaS audit check, covered in Module 7.

What payslip checks should agencies expect at audit?

OPRaaS audits a sample of payslips against the KID, the worker’s contract, the engagement’s assignment rate and RTI submissions. The audit looks at gross pay, deductions, holiday pay accrual and treatment, employer-side costs, NMW and NLW arithmetic, pension contributions and the consistency of bank details and National Insurance numbers across the sample. OPRaaS LSCA Module 8 sets out the step-by-step verification procedure.

CIS vs PAYE for agencies, what is the difference?

PAYE is the income tax and NIC operating system for employees and deemed employees. CIS is the Construction Industry Scheme, a separate set of deduction rules that applies where the engagement is construction operations within the meaning of the Finance Act 2004. The two routes carry different evidencing obligations. OPRaaS LSCA Module 7 sets out the side-by-side comparison and Module 8 covers the CIS Remittance Checklist.

What is the Construction Industry Scheme (CIS) and where does it bite for an agency?

CIS is HMRC’s set of rules for tax deductions from payments made by contractors to subcontractors in construction. An agency placing workers into construction operations needs to determine the right route (PAYE, CIS or off-payroll) for every engagement, hold the right verification status with HMRC, and apply deductions correctly. CIS errors compound quickly across a large book of placements. OPRaaS LSCA Module 8 covers CIS remittance compliance and contract structure.

How does Conduct Regulations 2003 affect agency contracts?

The Conduct of Employment Agencies and Employment Businesses Regulations 2003 set the baseline for what an agency must disclose, document and put in writing with both work-seekers and hirers. KID requirements, opt-out mechanics for limited-company contractors, written terms of business and prohibited fees all sit inside the regulations. OPRaaS LSCA Module 9 covers the contract compliance angle, including how the regulations interact with ERA 1996 s.1 written-particulars obligations.

What contracts must agencies have with workers, end-hirers and umbrellas?

At a minimum: terms of business with the end-hirer, a contract with the umbrella covering payment terms and compliance representations, an assignment schedule covering every placement, and worker-facing documents that meet the Conduct Regulations and ERA 1996 written-particulars obligations. OPRaaS LSCA Module 9 covers the contract content requirements; the OPRaaS VCD platform stores executed copies so they can be drawn into a Defence File on demand.

How does AWR (Agency Workers Regulations) sit alongside LSCA?

The Agency Workers Regulations 2010 give agency workers the right to equal treatment on basic working and employment conditions after a 12-week qualifying period. Compliance turns on accurate tracking of qualifying weeks, comparable-employee benchmarking and pay-and-conditions parity. OPRaaS LSCA Module 4 covers the AWR 12-week parity point inside the broader supply chain mapping discipline, so AWR is treated as one element of the same evidence record rather than as a separate spreadsheet.

What is a phoenix chain in an umbrella supply chain?

A phoenix chain is a sequence in which an umbrella or related entity is dissolved and a successor company picks up the same workers, the same controlling minds and similar operating patterns. The structure can be used to leave PAYE arrears behind in the dissolved entity. OPRaaS LSCA Module 11 covers phoenix chain anatomy alongside purported umbrella patterns, so the supplier onboarding and re-audit cycle is targeted on the patterns that matter.

How does OPRaaS audit an agency’s umbrella PSL?

OPRaaS reviews each PSL umbrella against the CAR Principles (Credibility, Assurance, Risk) covered in Module 4, with sampled payroll data, contract documents, RTI submissions, ownership-change records and incident logs feeding the result. The output is a per-supplier rating that drives onboarding decisions, re-audit cadence and de-listing where required. Findings are captured by the OPRaaS VCD platform and surface in a Defence File on demand, so the agency’s clients can see the assurance pattern over time.

What is the Fair Work Agency and when is it expected to start regulating umbrellas?

The Fair Work Agency (FWA) is the proposed single labour-market enforcement body that consolidates HMRC’s NMW enforcement, the GLAA and EAS functions, alongside an extended remit covering umbrella companies. The umbrella-regulation remit is expected to commence in 2027, subject to secondary legislation and the relevant commencement orders. Until commencement, the existing enforcement bodies retain their current powers.

How does the OPRaaS VCD reduce my insurance and client due-diligence work?

Insurers, end-hirer procurement teams and framework reviewers ask the same questions about controls in different formats. The OPRaaS VCD platform holds a single, dated record from which a Defence File can be produced on demand, so each due diligence exercise becomes a controlled extract rather than a fresh data-gathering project. The agency’s named OPRaaS VCD owns the response process and the evidence trail.

What is an agency’s incident response if HMRC issues a Reg 80 notice on a supplier?

OPRaaS’s incident-response playbook for Reg 80 events covers immediate evidence preservation, internal escalation, worker impact assessment, legal and tax review, supplier engagement and a structured response to HMRC. The objective is to draw the evidence record already captured by the OPRaaS VCD platform into a Defence File response within a defined window, rather than starting evidence collection at the point of the notice. Module 11 covers the playbook.

Are accreditations and warranties enough to evidence assurance?

OPRaaS reads HMRC’s guidance on labour supply chain due diligence as treating accreditations and contractual warranties as supporting controls, not as standalone assurance. The reading is OPRaaS’s, drawn from the guidance’s use of the verb “assure”, but it is reflected in the way OPRaaS LSCA Module 11 frames the controls that support JSL readiness. Continuous operational evidence sits above accreditations and warranties in the OPRaaS hierarchy of controls.

Umbrella companies and MSPs

What does compliant umbrella payroll actually look like?

A compliant umbrella operates PAYE as the employer, pays at or above NMW and NLW on the worked hours rather than the assignment rate, accounts for holiday pay correctly, applies employer-side costs transparently, issues a KID and a contract before work starts, submits RTI on time and keeps a clear audit trail between the assignment rate, the payslip and the bank payment. OPRaaS LSCA Module 7 covers the side-by-side PAYE and CIS positions.

What is disguised remuneration and how do you spot it?

Disguised remuneration is any structure that pays workers in a form designed to look like something other than employment income for tax purposes, often as loans, advances, credits, capital payments or third-party transfers. Tells include payments not routed through PAYE, pay rates significantly above the market for a given role, and a contract structure that introduces a separate paying entity. OPRaaS LSCA Module 11 covers disguised remuneration alongside high take-home claims.

What is mini umbrella company (MUC) fraud?

MUC fraud uses chains of small umbrella companies to abuse the Employment Allowance and the VAT Flat Rate Scheme. Workers are spread thinly across many micro-employers, the Employment Allowance is claimed multiple times, and the structure phoenixes regularly. HMRC has classified MUC as a tax fraud pattern. OPRaaS LSCA Module 2 covers the VAT fraud taxonomy, of which MUC fraud is one named pattern alongside Missing Trader fraud, Input VAT fraud and contrived subcontracting.

What is the difference between an umbrella, a PEO, and an MSP?

An umbrella is the employer of record for the worker. A PEO (Professional Employer Organisation) usually co-employs the worker with the client and shares HR responsibilities. An MSP (Managed Service Provider) sits one level up, managing the supplier programme on behalf of the end-hirer, often including a Vendor Management System. The three roles are sometimes confused, but the OPRaaS assurance discipline applies to each differently because each holds different parts of the supply chain risk.

Does OPRaaS audit umbrellas?

Yes. OPRaaS audits umbrellas on behalf of end-hirers, recruitment agencies and MSPs, against the OPRaaS LSCA standard. The audit covers payroll, contracts, RTI, ownership, beneficial owners, sanctions screening and supplier-side incident records. The output feeds the buyer’s evidence record on the OPRaaS VCD platform, where a Defence File can be produced on demand, gives the umbrella a structured improvement path, and provides the buyer’s SRO with a defensible PSL decision record.

Why do high-take-home models fail OPRaaS audit standards?

Models advertising take-home percentages materially above the achievable PAYE arithmetic for a given assignment rate are almost always achieving the headline through a non-PAYE route. Once the non-PAYE element is identified, the structure usually maps to disguised remuneration, loan and advance schemes or contrived subcontracting. The OPRaaS audit standard tests the arithmetic against the payslip, not the marketing.

What is the Kittel Principle and how does it relate to umbrella supply chains?

The Kittel Principle, from Axel Kittel v Belgian State, allows a tax authority to deny input VAT recovery where the taxpayer knew or should have known that the transaction was connected with fraud. Although Kittel is a VAT doctrine, the “knew or should have known” logic is widely applied across HMRC’s labour supply chain expectations. OPRaaS LSCA Module 2 sets out the principle and its connection to the wider due-diligence standard.

What is Employer of Record (EoR) and where does it fit?

EoR is a model in which a third party becomes the legal employer of a worker placed at an end-hirer’s site, often used for international hires or where the end-hirer does not have a local employing entity. EoR moves the employment relationship; it does not move the assurance obligation off the end-hirer’s labour supply chain. OPRaaS LSCA Module 11 covers EoR as one of the four operating-model choices alongside umbrella, in-house PAYE and PSC.

How does an MSP demonstrate continuous compliance to end-hirer clients?

An MSP can use the OPRaaS VCD platform to operate the labour supply chain assurance discipline across its end-hirer book of business, with the Defence File output covering the suppliers in scope. The end-hirer sees a documented control record covering its tier of the chain rather than a programme-level marketing claim. The same record supports the MSP’s own framework retention, client renewal and audit cycles.

What does an audit-ready umbrella evidence file contain?

Director and beneficial-owner records, statutory filings, PAYE scheme registration, sample payslips matched to KIDs and contracts, RTI submission records, holiday pay calculations, NMW and NLW arithmetic, complaint logs, supplier insurance, GLAA position where applicable, sanctions screening, training completions for compliance roles, and a documented incident response history. OPRaaS LSCA Module 8 covers the audit content; Module 11 covers the operating-model dimension.

How are RTI submissions used as an audit signal?

RTI (Real Time Information) submissions are the live record of pay and tax flowing through the umbrella to HMRC. OPRaaS samples RTI submissions to detect patterns such as duplicate National Insurance numbers, mismatched bank details, late-month NMW corrections, holiday-pay backfills and worker movements between phoenix-linked entities. The samples feed the evidence record for the buyer in scope, from which a Defence File can be produced on demand.

How does GLAA enforcement connect to umbrella compliance?

The Gangmasters and Labour Abuse Authority (GLAA) regulates labour providers in agriculture, shellfish gathering and food processing under the Gangmasters (Licensing) Act 2004, and has wider labour-abuse powers across other sectors. Where an umbrella supplies workers into a GLAA-regulated sector, the umbrella’s licence position is a control point. OPRaaS LSCA Module 5 covers the GLAA dimension inside Modern Slavery and labour exploitation risk management.

How does CFA 2017 apply to umbrella senior management?

An umbrella is a corporate body that engages associated persons (employees, agents, intermediaries). If any associated person facilitates UK or overseas tax evasion in the course of business, the corporate offence under CFA 2017 s.45 or s.46 may apply, subject to the “reasonable prevention procedures” defence. OPRaaS LSCA Module 6 covers the six guiding principles HMRC has published for prevention procedures and how to evidence them.

How does the Senior Accounting Officer regime overlap with LSCA?

The Senior Accounting Officer (SAO) regime under Schedule 46 to the Finance Act 2009 requires the named SAO of a qualifying company to certify that the company has appropriate tax accounting arrangements. Labour supply chain controls feed PAYE and NIC accuracy, so labour supply chain assurance evidence supports the SAO’s annual certificate. OPRaaS work routinely contributes to the SAO control framework rather than sitting alongside it.

How does OPRaaS support MSPs running a multi-tier supply chain?

OPRaaS maps each tier of the chain, sets the assurance standard for each tier, runs the audits, captures the evidence in the OPRaaS VCD platform for retrieval as a Defence File on demand, and stays in scope as suppliers change. The MSP retains responsibility for programme commercials and supplier orchestration; OPRaaS provides the independent assurance function that sits outside the supplier relationships so that the assurance work is, and is seen to be, independent.

Labour supply chain assurance for the public sector

Which public-sector buyers does OPRaaS work with?

OPRaaS works with Central Government departments, arm’s-length bodies, NHS Trusts and ICBs, local authorities, blue-light services, higher education institutions and other contracting authorities that engage temporary, contractor or contingent labour. OPRaaS’s position on the UK Government Commercial Agency frameworks makes call-off straightforward where the buyer wishes to procure through an existing route.

What does the UK Government Commercial Agency framework approval allow public-sector buyers to do?

Public-sector buyers can call off specialist labour supply chain assurance, training and implementation support from OPRaaS through the relevant UK Government Commercial Agency (formerly Crown Commercial Service) frameworks without running a separate full procurement, subject to the buyer’s own internal governance. The framework route reduces procurement lead time and gives the buyer a pre-assessed supplier.

What are RM6310 Lots 2 and 4?

RM6310 is the UK Government Commercial Agency’s Audit & Assurance Services framework. OPRaaS is approved on Lots 2 and 4, covering internal audit and specialist assurance services applicable to labour supply chain assurance work. Buyers can call off through direct award or further competition depending on the lot rules and the buyer’s internal procedures.

What is the RM6219 DPS?

RM6219 is the UK Government Commercial Agency’s Learning & Training Services Dynamic Purchasing System. OPRaaS is approved on RM6219, allowing public-sector buyers to commission OPRaaS LSCA training, including the OPRaaS LSCA Self-Certification Course content tailored to the buyer’s sector, through the DPS route.

What is the RM6237 DPS?

RM6237 is a further Learning & Training Services DPS on which OPRaaS is approved. It offers buyers a second compliant route to commission OPRaaS training and capability-building work, supporting situations where RM6219 is not the right fit for the buyer’s scope or timing.

How does NHS workforce procurement intersect with LSCA?

NHS Trusts engage substantial volumes of temporary labour through agency frameworks and direct engagements. The four exposure families apply with sector-specific intensity, particularly Modern Slavery and CFA 2017 risk in extended chains. OPRaaS LSCA Module 11 covers the NHS sector lens as one of three, alongside Construction and Security and Logistics, so the assurance work is targeted on the patterns common to the sector.

How does the OPRaaS LSCA approach apply to local authority placements?

Local authorities engage temporary labour for adult social care, children’s services, planning, environmental health, building control and many other specialisms. The OPRaaS LSCA discipline applies to those engagements in the same way it applies to a Central Government department, mapped against the authority’s own procurement rules and standing orders. OPRaaS works with the authority’s SRO to set the assurance cadence.

How does the OPRaaS approach work with public-sector governance expectations?

Public-sector buyers operate within the Cabinet Office Sourcing Playbook, the Procurement Act 2023 regime, Managing Public Money, and their own departmental or corporate governance manuals. The Defence File the OPRaaS VCD platform produces on demand is constructed to satisfy those expectations alongside HMRC’s, so the same evidence supports internal audit, external audit and accounting officer assurance without rework.

What does an LSCA audit look like for a Central Government department?

The audit maps the department’s labour supply chains, tests a representative sample of suppliers, payroll engagements and status determinations against the OPRaaS LSCA standard, and produces a control-maturity report alongside on-demand Defence File extracts from the OPRaaS VCD platform. Reporting lines run to the department’s named SRO and to internal audit. OPRaaS LSCA Module 4 covers the audit methodology.

How does HMRC’s “perform vs assure” guidance affect public-sector buyers?

HMRC’s guidance on applying supply chain due diligence principles is titled around the verb “assure”. OPRaaS reads that choice as drawing a working distinction between performing a check at a moment in time and assuring the integrity of the chain through continuous operation. The reading is OPRaaS’s interpretation, not a HMRC-stated dichotomy, and it shapes the way OPRaaS designs continuous-evidence controls for public-sector buyers.

How is value for money evidenced under continuous compliance?

Continuous evidence produces a cumulative control record that supports value-for-money assertions at internal audit, NAO review and parliamentary committee. The same record is used to demonstrate progress against the public-sector buyer’s social value commitments, particularly on Modern Slavery and worker treatment in the supply chain. The Defence File produced on demand from the OPRaaS VCD platform is the artefact value-for-money assessors examine.

What is the timeline to onboard a public-sector engagement?

Through the existing UK Government Commercial Agency frameworks, scoping and mobilisation typically run on a four to eight week cycle depending on the buyer’s internal governance, the size of the labour estate and the data-access arrangements needed. OPRaaS supplies a standard mobilisation pack covering data protection, security and access controls so that internal information governance reviews can run in parallel with the scoping work.

How is OPRaaS work documented for National Audit Office or internal-audit review?

The Defence File the OPRaaS VCD platform produces on demand is the primary artefact, supported by audit working papers, sample selection notes, supplier correspondence and incident logs. The structure mirrors the evidence framework that NAO and internal audit teams already use, so review is a controlled extract rather than a fresh data-gathering exercise. OPRaaS’s position on RM6310 Lots 2 and 4 reflects the same evidencing discipline.

Statement of Work (SoW) compliance services

What is a Statement of Work (SoW) engagement?

An SoW engagement is a contract for the delivery of a defined output, deliverable or service, rather than for the supply of labour by the hour or day. The end-hirer buys the outcome; the supplier organises the resources, methods and risk to deliver it. SoW is a legitimate engagement model where the substance matches the form. It is misused where in practice the workers are operating as if they were temporary labour under the end-hirer’s control.

How does an SoW engagement differ from PAYE temporary labour?

In PAYE temporary labour, the end-hirer directs how, when and where the work is done; the supplier provides workers. In SoW, the supplier owns the outcome, sets the method, manages the team and carries the delivery risk. The contract is the start, but it is the operational substance that determines the classification. The OPRaaS SoW audit tests substance, not labels.

What makes an SoW arrangement at risk of being recharacterised?

The common patterns are: end-hirer direction over day-to-day task allocation, end-hirer line management of supplier personnel, mixed teams where supplier and end-hirer staff are interchangeable, time-based billing dressed as deliverables, lack of supplier risk and lack of meaningful supplier methodology. Where the substance reads as labour supply, HMRC, an employment tribunal or an internal audit team may recharacterise the engagement.

What are the five UK-law tests for genuine SoW?

OPRaaS applies five tests drawn from common-law employment status, the IR35 framework and the wider labour-supply jurisprudence: mutuality of obligation, control over how the work is done, substitution and resourcing freedom, financial risk and integration with the end-hirer’s organisation. A genuine SoW reads as a delivery contract on all five. The detailed application sits inside the OPRaaS SoW audit; the principles are visible at first review.

What is the six-domain SoW audit?

The OPRaaS SoW audit examines six domains: contract construction, commercial structure, delivery methodology, governance and reporting, personnel and management practice, and evidence trail. Each domain is scored against an OPRaaS standard, with findings consolidated into a single audit report and a remediation plan where required. The audit covers individual SoW engagements and SoW supplier panels.

How does ITEPA 2003 Chapter 11 JSL apply to SoW arrangements?

JSL bites where the engagement is, in substance, labour supply, regardless of the SoW label. A recharacterised SoW can therefore expose the end-hirer and any agency in the chain to JSL alongside the misclassification consequences. OPRaaS LSCA Module 11 covers the JSL position; the SoW audit identifies the recharacterisation risk before the regulator does.

When should an end-hirer convert an SoW to PAYE temporary labour?

Where the audit shows the substance is labour supply, the right route is to engage the workers through PAYE temporary labour and document the change in arrangements. Persisting with an SoW label after substance has been identified compounds risk across IR35, JSL and AWR at the same time. OPRaaS supports the conversion as part of the SoW remediation plan.

Can an SoW be used to engage a single contractor?

A single-contractor SoW is possible but fragile. Most of the five UK-law tests are harder to satisfy at single-person scale, particularly substitution, financial risk and integration. OPRaaS’s view is that single-contractor SoW arrangements should be the exception rather than the default, and that the audit standard for them is higher than for team-based delivery.

What evidence is gathered during an OPRaaS SoW audit?

Contract documents, change orders, governance minutes, delivery plans, status reports, deliverable acceptance records, time and expense data, line-management evidence, supplier methodology artefacts, and personnel records on the supplier side. The evidence feeds the OPRaaS VCD platform, where a Defence File can be produced on demand to demonstrate, on a continuous basis, that the SoW is operating as an SoW.

How does OPRaaS support agencies offering SoW services?

Agencies offering SoW alongside temporary labour can use OPRaaS to set the assurance standard for the SoW line, audit the engagements against that standard and capture the evidence in the OPRaaS VCD platform so a Defence File can be produced on demand. The standard sits alongside, not on top of, the agency’s own commercial controls. Agencies present a credible SoW capability to end-hirers when the substance, the contract and the evidence all line up.

Working with OPRaaS

How does an OPRaaS engagement start?

Engagements start with a thirty-minute scoping call to set the boundaries: the audience type, the labour estate in scope, the relevant statutory framework, the assurance cadence and the data-access arrangements. From the call, OPRaaS issues a scoping pack and a proposed mobilisation plan. Where the engagement is being procured through a UK Government Commercial Agency framework, the framework call-off route is followed in parallel.

What does an OPRaaS Virtual Compliance Director engagement actually deliver?

A named OPRaaS VCD lead with senior governance experience, embedded into the client’s management routine. The OPRaaS VCD platform captures supplier checks, payroll samples, contract reviews, training completions and incident logs as they happen. A Defence File can be produced from those captures on demand to support board reporting, regulator engagement and customer due diligence. A documented remediation programme closes the gaps identified at audit.

How is OPRaaS work priced?

Engagements are priced as retained services with a fixed monthly fee covering the OPRaaS VCD platform access, the named OPRaaS VCD lead and the agreed assurance cadence. Audit volumes, supplier counts and training delivery scope drive the fee. Public-sector buyers procuring through the relevant UK Government Commercial Agency framework follow the framework’s pricing structure for the lot in use.

Is the OPRaaS LSCA Self-Certification Course included?

Yes. Course access for the agreed user group is included in the OPRaaS VCD engagement, with completion records captured by the OPRaaS VCD platform and available in a Defence File on demand alongside the audit and evidence work. The course supports the buyer’s training obligations under the “Communication and Training” limb of the CFA 2017 prevention-procedures framework covered in Module 6.

How does OPRaaS handle data protection inside the engagement?

OPRaaS operates as a data processor or joint controller, as the engagement requires, under a written data processing agreement aligned to UK GDPR and the Data Protection Act 2018. Worker data is processed under documented lawful bases, with minimisation and retention applied. The OPRaaS LSCA Module 10 framework on the seven data-processing principles applies internally as well as in audit content.

How does OPRaaS keep its own knowledge current?

The OPRaaS team tracks HMRC guidance updates, Finance Act commencement orders, secondary legislation, employment tribunal and tax tribunal outputs, ICO enforcement notices, GLAA enforcement updates and the published reports of NAO, OBR and the National Crime Agency. Where a change affects the assurance standard, the OPRaaS LSCA course content and the OPRaaS VCD platform configuration are updated together.

Where can I read about OPRaaS’s view on current developments?

OPRaaS publishes regular analysis at the News section of opraas.co.uk, covering JSL implementation, HMRC enforcement, sector vignettes and the practical operation of labour supply chain assurance. Each post names a specific OPRaaS LSCA module so readers can see where the analysis sits against the wider methodology.

How do I contact OPRaaS?

Use the contact form on the OPRaaS website, or email info@opraas.co.uk. Public-sector buyers procuring through a UK Government Commercial Agency framework can also reach OPRaaS through the relevant framework contact route.

Compliance is your asset. Evidenced daily.

Talk to OPRaaS about your supply chain.

Use the contact form in the sidebar to the right of this page, or email info@opraas.co.uk.

This page is published for general information and educational purposes only. It is believed to be accurate at the time of publication and reflects the legislation, HMRC guidance, and market practice referenced. It is not legal, tax, employment, accounting, or regulatory advice and should not be relied upon as such. Compliance obligations vary by organisation, supply chain, and engagement type; please consult your own qualified legal, tax, or compliance advisor before acting on any point covered here. Any images, screenshots, dashboards, or platform displays shown are for illustration and reference purposes only and do not necessarily depict the live OPRaaS platform, live customer data, or actual on-screen output. Trademarks, framework names, and statutory references remain the property of their respective owners. While we take every care, errors can occur; if you spot an inaccuracy, please let us know at info@opraas.co.uk.

LSCA Glossary of Terms

Glossary of Terms

Comprehensive definitions for Labour Supply Chain Assurance compliance terminology

No matching terms found. Try a different search.
Acronym Full Term Definition
CFA 2017 Criminal Finances Act 2017 UK legislation introducing Corporate Criminal Offence (sections 45/46): failure to prevent the facilitation of tax evasion. Requires businesses to implement 'reasonable prevention procedures' (RPP). The only defence is having adequate RPP or showing it was not reasonable to expect such procedures.
MSA 2015 Modern Slavery Act 2015 UK legislation mandating supply chain transparency and worker safeguarding. Section 54 requires commercial organisations with ≥£36m turnover to publish annual modern slavery statements (board-approved, signed by director, published on website with prominent homepage link).
IR35 Off-Payroll Working Rules Tax legislation determining whether a contractor should be treated as employed or self-employed for tax purposes. Since April 2021, medium and large private sector clients must determine contractor status and deduct employment taxes if inside IR35. Requires Status Determination Statement (SDS).
JSL Joint & Several Liability 2026 legislation imposing strict liability on agencies and end-hirers for umbrella company tax debts, even where due diligence checks have been undertaken. Makes supply chain participants jointly responsible for unpaid PAYE taxes.
AWR Agency Workers Regulations 2010 UK regulations giving agency workers the right to the same basic working and employment conditions as permanent employees after 12 weeks in a qualifying assignment (12-week parity rule).
Good Work Plan Good Work Plan 2020 UK employment law reforms requiring written 'section 1 statement' of employment particulars to be given to employees and workers on or before day 1 of engagement (effective 6 April 2020). Sets out key terms but is not itself the contract.
Construction Act Housing Grants, Construction and Regeneration Act 1996 UK legislation governing payment practices in construction contracts. Section 113 renders "pay when paid" clauses ineffective (except where upstream payer is insolvent). Requires clear due dates, final dates for payment, and compliant payment/pay less notices.
Pensions Act 2008 Pensions Act 2008 UK legislation establishing workplace pension auto-enrolment requirements. Employers must automatically enrol eligible workers into qualifying pension schemes and make minimum contributions.
Acronym Full Term Definition
HMRC HM Revenue & Customs UK government department responsible for tax collection, payment of tax credits and benefits, and enforcement of tax law. Operates PAYE, CIS, RTI systems and conducts compliance audits. Business Tax Account provides reconciliation data.
GLAA Gangmasters and Labour Abuse Authority UK government body regulating labour providers in certain sectors (agriculture, horticulture, shellfish gathering, food processing/packaging) and investigating worker exploitation. Operates licensing regime and has criminal investigation powers. Hotline: 0800 432 0804 (03000 718234 out of hours).
ICO Information Commissioner's Office UK independent authority upholding information rights. Enforces UK GDPR and Data Protection Act 2018. Personal data breaches must be reported to ICO within 72 hours where there's risk to individuals' rights. Provides guidance on lawful bases, DSARs, and data-sharing.
CITB Construction Industry Training Board Industry body that collects levy from construction employers (payroll ≥£80k in PAYE in last tax year, or ≥£80k net CIS payments) and provides training grants. CITB levy compliance is audited in construction-focused compliance audits.
Acronym Full Term Definition
PAYE Pay As You Earn HMRC's system for collecting Income Tax and National Insurance Contributions from employees' wages. Employers deduct tax before paying employees, then remit to HMRC. Operates under Real Time Information (RTI) reporting requirements.
CIS Construction Industry Scheme Tax deduction scheme for payments to subcontractors in construction industry. Contractors must verify subcontractors with HMRC before first payment and make deductions (20% for verified, 30% for unverified) on labour element only (excluding VAT and allowable materials). CIS300 returns due by 19th following tax month.
GPS Gross Payment Status CIS status allowing subcontractors to be paid without deductions. Must apply to HMRC and meet compliance tests (business test, turnover test, compliance test). Contractors must verify GPS and keep evidence; continue to file CIS300 but make no deduction.
CIS300 CIS Monthly Return HMRC return submitted by contractors detailing total payments made to each subcontractor and CIS tax deductions applied. Must be filed by the 19th following the tax month (6th–5th). Should reconcile to subcontractor statements and bank payments.
CIS340 CIS340 Guidance HMRC's official guidance document defining what constitutes 'construction operations' for CIS purposes. Only work qualifying under CIS340 can legitimately be paid through the Construction Industry Scheme. Includes site preparation, construction, alteration, repairs, demolition.
RTI Real Time Information HMRC system requiring employers to report PAYE information at or before each pay run. Consists of Full Payment Submission (FPS) for regular pay data and Employer Payment Summary (EPS) for adjustments/recoveries. Must reconcile to payslips and Business Tax Account.
FPS Full Payment Submission RTI submission reporting gross taxable pay, Income Tax, and NICs for each employee on each payday. FPS values must match payslips. Should not be used to mask under-deductions.
EPS Employer Payment Summary RTI submission used only for adjustments, such as recoveries, statutory payments, employment allowance claims, or apprenticeship levy. Should not be used to mask PAYE under-deductions.
Bacs Bankers' Automated Clearing Services UK electronic payment system used for direct debits and credits, including salary payments. Net pay on payslip must match Bacs transfer to worker's bank account. Never use "BACS" (incorrect).
UTR Unique Taxpayer Reference 10-digit number issued by HMRC to identify individuals and businesses for tax purposes. Required for CIS verification and self-assessment tax returns. Note: UTR alone isn't proof of CIS verification; contractor must verify with HMRC before first payment.
NIC / NICs National Insurance Contributions UK social security tax paid by employees (via PAYE), employers (as on-costs), and the self-employed (Class 2/4 via self-assessment). Funds state benefits including state pension, statutory sick pay, and maternity allowance. CIS deductions are payments on account of Income Tax and Class 4 NICs.
NMW National Minimum Wage Legal minimum hourly rate employers must pay workers in the UK. Rates vary by age band. Post-deduction pay (after deductions for employer's own use/benefit) must not fall below NMW. Records must be kept for 6 years.
NLW National Living Wage Higher rate of National Minimum Wage for workers aged 21 and over. Often referred to together as "NMW/NLW". Different from voluntary Real Living Wage calculated by Living Wage Foundation.
AE Auto-Enrolment (Pensions) Workplace pension scheme where employers must automatically enrol eligible workers (aged 22+ to state pension age, earning ≥£10k annually) into a qualifying pension. Minimum contributions, opt-out rights, and re-enrolment (every 3 years) required.
P45 P45 (Leaving Employment) HMRC form given to employees when they leave employment, showing pay and tax details for the year to date. New employer uses P45 to operate correct tax code. Emergency codes (e.g., 1257L W1/M1) apply without P45/P6.
Acronym Full Term Definition
DRC Domestic Reverse Charge (VAT) VAT mechanism for construction services where the customer accounts for VAT instead of the supplier. Applies to most construction services under CIS340. Designed to combat missing trader fraud in construction supply chains.
Kittel Kittel Principle EU/UK legal principle that a taxpayer who knew or should have known their transaction was connected to VAT fraud may be denied the right to deduct input VAT. Creates due diligence obligations for supply chain participants.
DR Disguised Remuneration Tax avoidance arrangements designed to pay individuals while avoiding income tax and NICs, often involving loans, offshore entities, or trusts. HMRC actively targets such schemes. Loan charge applies to outstanding loans.
Acronym Full Term Definition
SDC Supervision, Direction or Control Key factor in determining employment status under agency rules (ITEPA 2003 s44). If a worker is under supervision, direction or control by any person (client, agency, end-hirer) over how they work, PAYE must be operated. SDC alone is not the general CIS status test—apply usual status tests (control, substitution, mutuality).
MOO Mutuality of Obligation Employment status indicator examining whether the employer is obliged to provide work and the worker is obliged to accept it. Absence of MOO suggests self-employment; presence suggests employment.
SDS Status Determination Statement Document required under IR35 reforms (April 2021) where medium/large clients must provide written reasons for their determination of a contractor's employment status for tax purposes. Must be given before contract starts or worker begins work.
CEST Check Employment Status for Tax HMRC's online tool for determining whether a worker should be classified as employed or self-employed for tax purposes. Results are binding on HMRC if information provided is accurate and not relating to highly complex arrangements.
PSC Personal Service Company Limited company through which a contractor provides their services. Often used by contractors working outside IR35, but subject to IR35 rules if the underlying relationship is one of employment. Requires SDS from medium/large clients.
KID Key Information Document Plain-English factsheet (not a contract) that agencies must give to workers before they agree to an assignment (Conduct of Employment Agencies and Employment Businesses Regulations 2003). Includes worked pay illustration, deductions, who pays the worker, benefits. Must be updated within 5 working days of any change.
ITEPA 2003 Income Tax (Earnings and Pensions) Act 2003 UK tax legislation governing employment income. Section 44 contains agency rules requiring PAYE where worker is under SDC. Section 61N–61R cover off-payroll working (IR35) for public sector and (from 2021) medium/large private sector.
DBS Disclosure and Barring Service UK government service providing criminal record checks for employment purposes (particularly roles working with children or vulnerable adults). Processing DBS data requires DPA 2018 Schedule 1 condition and appropriate policy document.
Acronym Full Term Definition
Umbrella Umbrella Company Employment intermediary that employs agency workers and contractors. Handles PAYE, pension, and employment administration while the worker performs assignments for end-clients arranged through agencies. Employer NICs/apprenticeship levy must be funded from assignment rate, not charged to workers as deductions.
MUC Mini Umbrella Company Fraudulent scheme where multiple small umbrella companies are created to exploit employment allowances and avoid tax obligations. Often phoenixing after accumulating tax debt. A significant compliance risk that supply chain audits help detect.
Phoenix Phoenix Company Scheme Fraudulent practice where a company accumulates tax debts, is dissolved, and re-emerges as a new entity to escape liabilities. A key risk factor in supply chain due diligence. Tolerance of phoenix suppliers by end users enables fraud cycle.
Purported Purported Umbrella Company Entity presenting itself as a legitimate umbrella company but failing to meet compliance standards, potentially operating tax avoidance schemes or misclassifying workers.
Hybrid Hybrid Payment Model Pay arrangement combining different payment methods (e.g., PAYE + CIS, or PAYE + PSC). Requires careful status assessment to avoid disguised remuneration or employment status breaches.
Acronym Full Term Definition
UK GDPR UK General Data Protection Regulation UK data protection law (retained EU law post-Brexit) governing processing of personal data. Requires lawful basis (Art 6), data minimisation, security, transparency (Arts 13-14), and respect for data subject rights. Works alongside Data Protection Act 2018.
DPA 2018 Data Protection Act 2018 UK legislation supplementing UK GDPR. Schedule 1 sets conditions for processing special category data (health, biometric, union membership) and criminal offence data (e.g., DBS checks). Provides exemptions (crime prevention, tax collection, legal professional privilege).
DSAR Data Subject Access Request Individual's right under Art 15 UK GDPR to obtain copy of their personal data. Must respond within one month (extendable by 2 months for complex requests). Usually no fee. Must verify identity proportionately.
DPO Data Protection Officer Required role for public authorities or organisations conducting large-scale systematic monitoring or processing special category data (Art 37). Oversees data protection compliance, advises on DPIAs, and acts as contact point for ICO and data subjects.
LIA Legitimate Interests Assessment Assessment required when relying on legitimate interests (Art 6(1)(f)) as lawful basis. Three-part test: identify legitimate interest → demonstrate necessity → balancing test (interests vs individual rights). Appropriate for audit/assurance; avoid consent for audits.
DPIA Data Protection Impact Assessment Required assessment where processing is likely to result in high risk to individuals (Art 35). Must complete for large-scale, systematic monitoring or extensive special category data processing. Documents risks, mitigation measures, and necessity/proportionality.
RoPA Records of Processing Activities GDPR requirement (Art 30) documenting all personal data processing activities. Must include purposes, lawful bases, data categories, recipients, retention periods, security measures, and international transfers. Must be available to ICO on request.
IDTA International Data Transfer Agreement UK mechanism for lawfully transferring personal data outside the UK (replacing EU Standard Contractual Clauses post-Brexit). Required unless recipient country has adequacy decision or other derogation applies. Alternative: UK Addendum to EU SCCs.
SCCs Standard Contractual Clauses EU Commission-approved contract templates for international data transfers. For UK data exports, use UK Addendum to EU SCCs or UK IDTA.
Art 28 DPA Article 28 Data Processing Agreement Mandatory contract between controller and processor (Art 28 UK GDPR). Must cover: subject matter, duration, data types, processing instructions, confidentiality, security, sub-processors, data subject rights assistance, breach notification, data deletion/return, audit rights.
Art 26 Article 26 (Joint Controllers) UK GDPR provision for parties who jointly determine purposes and means of processing. Requires arrangement setting out respective responsibilities, data subject rights, and contact points. Different from controller-processor (Art 28) or controller-controller data-sharing.
Controller Data Controller Organisation that determines the purposes and means of processing personal data. Bears primary GDPR obligations. Agencies, umbrellas, and end-hirers usually act as independent controllers for their own audit/compliance purposes.
Acronym Full Term Definition
LSCA Labour Supply Chain Assurance Due diligence framework ensuring compliance with tax, employment, and ethical standards throughout the labour supply chain. Covers PAYE/CIS compliance, modern slavery, CFA 2017, worker rights, and IR35. Aims to detect exploitation, fraud, and phoenixism.
PSL Preferred Supplier List Vetted list of approved suppliers (typically umbrella companies or agencies) that meet compliance standards. Key governance control for managing supply chain risk. Should be reviewed regularly and require re-certification.
End-Hirer End-Hirer / End Client The organisation where agency or contract workers ultimately perform their work. Under current regulations, medium/large end-hirers have IR35 status determination responsibilities and supply chain due diligence obligations.
CCO Corporate Criminal Offence CFA 2017 offence: failure to prevent facilitation of tax evasion by an associated person. Three-stage liability: (1) taxpayer evades tax, (2) associated person criminally facilitates it, (3) organisation failed to prevent. Only defence: reasonable prevention procedures (RPP).
RPP Reasonable Prevention Procedures The only defence to Corporate Criminal Offence under CFA 2017. HMRC's six principles: risk assessment, proportionate procedures, top-level commitment, due diligence, communication (training), monitoring & review. Must be risk-based and documented.
SRO Senior Responsible Owner Senior person accountable for CFA 2017 compliance, risk assessments, and implementation of reasonable prevention procedures. Provides top-level commitment and board oversight.
MSAT Modern Slavery Assessment Tool UK Government tool (Home Office/Cabinet Office) for assessing modern slavery risks in supply chains. Free to organisations registered on UK Government Supplier Registration Service.
Acronym Full Term Definition
ASCA Agency Self-Certification Audit Most comprehensive audit form with 174 questions across 18 sections. Enables recruitment agencies to self-assess compliance with tax, employment, and supply chain obligations including PAYE, CIS, Modern Slavery, CFA 2017.
AUCIS Agency Umbrella CIS Audit Audit evaluating recruitment agencies' compliance with CIS requirements when engaging umbrella companies, ensuring proper tax treatment and supply chain integrity.
AUPAYE Agency Umbrella PAYE Audit Audit assessing recruitment agencies' oversight of umbrella companies' PAYE compliance, including tax deductions, National Insurance contributions, and payroll accuracy.
EHUCIS End-Hirer Umbrella CIS Audit Audit evaluating end-hirers' due diligence when engaging umbrella companies under CIS, ensuring supply chain compliance and proper contractor treatment.
EHUPAYE End-Hirer Umbrella PAYE Audit Audit assessing end-hirers' oversight of umbrella PAYE arrangements, covering payroll transparency and worker rights compliance.
EHSA End-Hirer Self-Assessment Audit Audit enabling end-hirers to self-assess their compliance with supply chain, tax, and employment obligations.
EHAA End-Hirer Assurance Audit Audit providing end-hirers with an independent assessment of their supply chain compliance, risk management, and due diligence practices.
UMBCIS Umbrella CIS Audit Audit evaluating umbrella companies' compliance with CIS requirements, including proper contractor treatment, tax deductions, and verification processes.
UMBPAYE Umbrella PAYE Audit Audit assessing umbrella companies' PAYE compliance, payroll integrity, and worker protection standards. Contains 21 sections (Section 1 info-only, Sections 2-20 audit, Section 21 declaration) vs 18 for most other audits.
Self-Cert Self-Certification Audit Generic term for labour supply chain compliance audits where organisations self-assess against tax, employment, and ethical standards. Provides documented evidence of due diligence for HMRC inspections.
Acronym Full Term Definition
Instance Audit Form Instance Individual audit submission. Users can create unlimited instances, each stored as WordPress custom post type with responses in wp_opraas_audit_responses table. Assigned to logged-in user via post_author field.
Completion Completion Score Frontend metric showing percentage of questions answered (any answer counts). Includes ALL sections: Section 1 checkbox, Section 2 (8 fields), Declaration (7 fields), and all audit questions. N/A responses count as answered.
Compliance Compliance Score Backend metric measuring quality of compliance. Scoring: Yes=5 points, No=0 points, N/A=0 points (excluded from maximum), Don't Know=1 point. EXCLUDES Sections 1, 2, and Declaration entirely. ≥80% = Compliant, 60-79% = Partially Compliant, <60% = Non-Compliant.
Evidence Evidence Files Supporting documents uploaded to substantiate audit responses. Stored in AWS S3 via WP Offload Media plugin, with Evidence Table providing S3-aware ZIP downloads that temporarily download from cloud before adding to archives.
Red Flags Red Flags Warning indicators in audit questions identifying practices that may indicate non-compliance, fraud risk (phoenixism, MUCs, disguised remuneration), or regulatory breaches requiring immediate attention and remediation.