Skip to main content

Current Regulatory Pressures

HMRC and the Self-Employed Officer

In the last month every security business in the UK has been written to by HMRC (His Majesty’s Revenue and Customs) reminding us that:

•  “The typical arrangements for security workers are such that HMRC expects they will be employed for tax purposes. As such, security workers should ordinarily be on the payroll.”

•  All of us should check to ensure that all security workers are correctly registered for PAYE and NIC.

•  Make sure their pay fully accounts for income Tax and NIC’s.

•  This letter on its own, should give us all pause to think and consider the potential outcomes.

Operationally, it could not be clearer that HMRC is going to require compliance and enforce the law.

Interestingly the law has always been clear and HMRC is simply telling us what it can do. The factsheet (CC/FS7a) makes it clear that if your return is inaccurate and results in results in “tax being unpaid, understated or overclaimed”, then you will be liable. There will be a debate about this, but it is a safe assumption that if you keep records then they can form part of an evidence chain, against you. To put it simply it will no longer be enough to state, that they are self-employed and not to record accurately what was paid.

It would be reasonable to expect a similar challenge from security operatives to employment status, as with UBER 5 in our industry and whilst that ruling was complex it did cement the idea that UBER drivers are not self-employed. We should learn the lesson and use it as a map for our own industry.

This makes it clear that security businesses must take steps to ensure that they have accurate records that clearly show what and to who they have made payment, the employment status of the person that has delivered the service and any other compliance data needed. This cannot be done, with any certainty, on a spreadsheet.

Current Regulatory Pressures
The British Standards 7858 & 7499

Along with the HMRC taking an active interest in the security industry, we already have our own regulatory and legal. These two areas are then backed by British Standards and whilst it is not generally possible to be prosecuted for non-compliance with a British Standard, standards can be used in Court as evidence to prove non-compliance with relevant acts or regulations.

BS 7858
While BS 7858 is not a legal requirement for all employers, it becomes mandatory for organisations seeking or maintaining approval under the Security Industry Authority’s (SIA) Approved Contractor Scheme (ACS). SIA-approved contractors must comply with BS 7858 as a condition of their ACS status. This is a regulatory, not statutory, requirement—meaning it is enforced by the SIA as part of its scheme, not by criminal or civil law for all employers.

As Operators we succeed through attaining ACS status, indeed as a pacesetter, you are stating proudly that you are setting your business out as one of the best. BS 7858 makes it clear for us how we vet and screen our employees’ and that alone begs questions about the status of the people we deploy. If we link the actions to be taken by HMRC and the current need to provide sufficient evidence to show that we are taking such steps to ensure that we are compliant, how many of us can truly say we are not simply ticking boxes but are embracing the standards as a necessary part of the industry codes of practice.

BS 7499
Whilst BS 7499 is not legally enforceable in itself, it is a code of practice and serves as a guideline for best practices in static site guarding and mobile patrol services. Organisations may choose to adopt it voluntarily or be required to follow it by clients, insurers or as part of contractual obligations, but there is no general statutory requirement to comply unless:

• Required by a regulator (e.g., SIA for ACS membership).
• Mandated by a client or as a condition of an insurance policy.
• Included as a contractual obligation between parties.

Conclusion
It is easy to conclude that the Security Industry Authority (SIA) and HMRC will continue to work together to reduce poor practice and ensure that we, as operators, deliver to the letter of the law. We must acknowledge that we, as an industry, are the architects of this outcome. As an industry, there is not one of us, as leaders, that cannot give examples of where workers have been exploited by a minority section of businesses in the sector. Whilst a minority, it has become an increasingly discussed area and the exposure of the use of “self-employed” and “un-screened” security personnel has required the SIA to commence a process that will inevitably cause some pain and cost for us all.

Recommendations
Our recommendations are simple and, with the right system-based approach, will ensure that the majority of our industry can remain compliant to current and future regulations:

•  Employ a single system-based approach to your vetting and screening. Make sure the people you use are qualified and have a right to work in the UK.

•  Audit and full audit trails, will increasingly be needed. Simple Spreadsheets can be altered and are not fully auditable. Think about a system-based solution that can show who did what and when.

•  Control access to your and your team’s data. It not just GDPR but a secure system-based solution will make the retention and recall of compliance data easier for you when the regulator asks

•  A Centralised policy management and regulatory system-based framework that declares your business rules will show any regulators that you are aware and working to their needs.