For UK construction principal contractors / FA 2004 ss.62A–62B / in force since 6 April 2026
CIS Defence
CIS Defence is monitoring software for UK construction supply chains. It verifies every subcontractor continuously with HMRC and Companies House, works in the background, and tells you the day something changes. This page sets out exactly what it checks, how often, and what the record looks like when HMRC asks.
What it checks
Six checks. Every subcontractor. Every month.
Each check exists because of one test. Where you knew or should have known that a payment was connected to a deliberate CIS or PAYE failure, HMRC has a chain of powers against you, and the "knew or should have known" principle turns on what was visible and what you did about it. These are the signals CIS Defence looks for, and the cadence it looks at them on.
HMRC Gateway
CIS registration and Gross Payment Status verified live with HMRC through the GovTalk API, using your own contractor credentials, at source rather than against a cached copy. CIS Defence verifies continuously with HMRC and re-screens every month, so a status change is caught in days rather than at your next manual check.
Forensic History
Phoenix company detection across Companies House: serial dissolution and re-registration, director histories, and the linkages between them. What it finds feeds each subcontractor's dynamic risk score, alongside company age, payment patterns and position in the chain.
Benchmarking
Labour rates tested against National Minimum Wage floors, CIJC, JIB and JIB-PMES agreed trade rates, and ASHE regional earnings data. Rates that sit below what the work can lawfully be done for are one of HMRC's clearest red flags, and the analysis behind each rating is kept with it.
Boots on the Ground
Timestamped confirmation from your own project managers of who is actually working, matched against who is being paid. The section below sets out why this check exists and what it is for.
Manager Override
A flagged risk does not always reflect the real position, and CIS Defence does not pretend your judgement away. Manager Override records that judgement formally: what was found, what was done about it, who took the decision and for how long it stands. When an override expires the risk wakes up and has to be looked at again.
HMRC Compliance Passport
The monthly evidence pack: every check above, every flag raised and every decision taken, timestamped in one PDF for each subcontractor. The record section below sets out what it contains and how it comes out.
CIS Defence works in the background. You hear from it the day something changes, and only when it matters: an alert when a rating changes, a site verification falls due or an override nears expiry, and a monthly digest that summarises everything else.
How far it looks
Depth changes what a check has to prove.
CIS Defence tracks supply chain depth and escalates due diligence proportionally. HMRC's GfC12 guidance treats long supply chains as a red flag, so a subcontractor five tiers down is not checked the same way as a direct engagement.
GfC12
Field verification
Who you paid, and who was actually working.
Paper-based due diligence cannot tell you who is actually on site. HMRC knows this, and so do fraudsters. Identity substitution, where a verified entity is paid but unverified labour is actually working, is one of the most common and difficult-to-detect patterns of CIS fraud.
The "knew or should have known" test is not limited to paperwork. Boots on the Ground puts on the record, timestamped, that you verified not just who you were paying, but who was actually working.
The record
One PDF. Every check, every decision, every sign-off.
The HMRC Compliance Passport is where the six checks end up. One document per subcontractor, rebuilt every month, holding the findings and the reasoning together rather than in separate systems.
What the Passport contains
- Data sources checked, and the date each was verified
- Risk factors identified, and how each was addressed
- Decisions made, and the rationale behind them
- Sign-off records, with timestamps
Export is one action per subcontractor: the complete audit trail as a PDF, with every verification record and a chronological history of what happened and when. It is exportable the day an enquiry letter arrives, not assembled after it.
Evidence that you followed a system
Standardised onboarding, documented verification of CIS registration, Gross Payment Status confirmation and VAT cross-reference, applied the same way to every subcontractor rather than case by case.
Evidence that you kept looking
Verification cycles that continue past onboarding, alerts triggered and the actions taken on them, and changes in subcontractor status tracked over the life of the engagement.
If HMRC opens an enquiry, you have a complete, timestamped record of what you checked, when, and what you decided.
Let's look at your exposure.
Twenty minutes on a call. We put your actual subcontractors through the six checks above and show you what the record would say today, including anything you would rather find before HMRC does.