Frequently Asked Questions
This page collects the questions construction contractors, finance directors, and advisers most frequently ask us about the new CIS regime taking effect from 6 April 2026, and about Tax Radar CIS Defence.
This page collects the questions construction contractors, finance directors, and advisers most frequently ask us about the new CIS regime taking effect from 6 April 2026, and about Tax Radar CIS Defence.
The Finance Act 2026 introduced new sections 62A and 62B into the CIS legislation. From 6 April 2026, HMRC can hold principal contractors liable for tax lost through fraud committed elsewhere in their subcontractor supply chain, where the contractor “knew or should have known” that fraud was occurring. This is a significant expansion of HMRC’s existing CIS enforcement powers. See the Finance Act 2026 and its Explanatory Notes for the statutory wording.
Section 62A creates a power for HMRC to recover lost tax from principal contractors where fraud has occurred in the supply chain and the contractor knew or should have known about it. Section 62B sets out the mechanism for immediate removal of Gross Payment Status from contractors connected to such fraud, without the usual review or appeal window. The two provisions together significantly raise the consequence of inadequate due diligence.
Any business that engages subcontractors under the Construction Industry Scheme is affected. This includes Tier 1 principal contractors, sub-contractors who themselves engage labour, and deemed contractors whose construction spend brings them into scope. The legislation does not distinguish by size: a regional builder engaging twenty subbies is exposed in the same way as a national contractor engaging two thousand.
It is the evidential threshold that determines whether you can be held liable for tax lost through fraud elsewhere in your supply chain. “Knew” covers actual knowledge. “Should have known” is the harder test: it asks whether a reasonable person in your position, exercising reasonable due diligence, would have spotted the warning signs. The test is fact-specific and judged on the evidence available at the time of the transaction, not with hindsight.
It is not a new statutory test. It is borrowed directly from VAT case law, where it is known as the Kittel principle, after the 2006 European Court of Justice judgment in Axel Kittel v Belgian State. Nearly twenty years of UK case law (Mobilx, Davis & Dann, Fonecomp, and others) has developed the principle. Construction will now be judged against the same body of case law. See our Kittel Countdown article and the case law section of our references page.
Yes. Under section 62B, HMRC can withdraw Gross Payment Status with immediate effect where the contractor is connected to supply chain fraud. The previous review and appeal window does not apply. Loss of GPS shifts the contractor to 20% (or 30% if unverified) deductions at source, which has immediate cash flow consequences for the business.
Potentially yes. The new regime extends contractor liability beyond the immediate supplier relationship. If fraud is found further down the supply chain, the question becomes whether you knew, or should have known, that something was wrong. This is why mapping the supply chain and continuously monitoring counterparties matters: liability does not stop at your direct subcontractor.
Director personal liability for penalties under the new regime is capped at 30% of the tax loss attributable to the fraud, not the full underlying tax liability. This is a meaningful but real exposure: on a £500,000 fraud, the director-level penalty could be up to £150,000. This is in addition to the corporate-level liability and any GPS consequence. The exact amount depends on HMRC’s assessment of culpability and cooperation.
Yes. A deemed contractor (a business that is not a construction business but whose construction spend exceeds the threshold) is subject to the same obligations as a principal contractor for the purposes of the new rules. Property developers, large landlords, and businesses with significant fit-out programmes should review their position.
The new rules apply to construction operations carried out on or after 6 April 2026. They are not retrospective in the strict legal sense. However, evidence of historic patterns (for example, repeated use of phoenix subcontractors over years) may be relevant to whether a contractor “should have known” about fraud occurring after April 2026. Historic conduct is part of the factual matrix; it does not create liability in itself.
Reasonable care is the standard of due diligence a contractor must demonstrate to defend against a “should have known” allegation. It is not defined in the legislation. In practice it means: verifying subcontractor identities and tax status, monitoring for changes, investigating warning signs, benchmarking rates against market, and keeping a contemporaneous, timestamped record of all of the above. See our guidance on what reasonable care looks like in practice.
A documented, contemporaneous record of the checks you carried out, when, what they returned, and what you did about anything they flagged. HMRC’s Guidelines for Compliance GfC12 on labour supply chains sets out the framework. A Compliance Passport (see below) is designed to produce exactly this record in HMRC-ready form. Verbal assurances, expired CHAS certificates, and one-off checks are unlikely to be sufficient on their own.
No. The new regime is built on the premise that supply chain risk evolves. A subcontractor who passed verification in January may have been deregistered, dissolved, or substituted by July. Reasonable care implies ongoing monitoring rather than a single check at onboarding. This is the gap that continuous monitoring tools are designed to fill.
The right answer depends on the size and risk profile of your supply chain, but the principle is “at least as often as something material could have changed”. For active subcontractors that typically means monthly verification with HMRC, continuous monitoring of Companies House data, and immediate flags on changes (deregistration, dissolution, director changes). Tax Radar CIS Defence runs these checks automatically.
A Compliance Passport is the monthly evidence pack produced by Tax Radar CIS Defence. It contains a timestamped snapshot of every check carried out on every active subcontractor, the result of each check, and the action taken in response. It is designed to be the artefact a contractor produces in response to an HMRC enquiry to demonstrate that reasonable care was exercised. It is exportable as a PDF and shareable with advisers and auditors.
No tool can guarantee that. The “should have known” test is fact-specific and applied case by case. What a Compliance Passport does is produce the contemporaneous, structured evidence trail that the test requires. The alternative (reconstructing your due diligence after the fact from emails, spreadsheets, and memory) is materially weaker. Reasonable care is shown by what you did at the time, not what you can piece together later.
No. Accreditation schemes verify a subcontractor’s status at a single point in time and do not address tax fraud risk. A subcontractor can be CHAS-accredited and still be part of a phoenix fraud scheme. Accreditations are useful as part of a broader due diligence package; they are not a substitute for ongoing tax-specific verification and forensic monitoring.
Every active subcontractor. The legislation does not draw a distinction between new and existing relationships. A subcontractor you have engaged for ten years can be deregistered, dissolved, or implicated in fraud just as easily as a new one. Some long-standing relationships are the highest risk precisely because they are taken for granted.
HMRC’s general record-keeping rule for tax records is six years. For CIS records specifically, three years is the statutory minimum but six is the practical standard given the longer enquiry windows in fraud cases. We recommend retaining the full Compliance Passport history for at least six years. Records should be tamper-evident and timestamped.
A documented, repeatable, monthly due diligence process covering every active subcontractor, with immediate alerts on material changes, benchmarked pricing data, and on-site verification of who is actually working. The process should produce a contemporaneous evidence pack each month that could be handed to HMRC tomorrow. That is what Tax Radar CIS Defence is built to deliver.
Tax Radar CIS Defence connects directly to HMRC’s CIS API to verify subcontractor registration and tax status in real time. We are HMRC CIS Internet Recognised (Vendor ID 9328), which means our software meets HMRC’s technical and security standards for direct integration. Verifications are not cached: every check is live.
Phoenixism is the practice of deliberately liquidating a company to escape tax liabilities, then re-forming a similar business under a new name with the same directors. It is a common fraud pattern in construction. Engaging a phoenix subcontractor is one of the clearest “should have known” red flags, because the public Companies House data showing the linkage is available to anyone who looks. CIS Defence detects phoenix patterns automatically.
By cross-referencing director appointments, registered addresses, and incorporation histories across Companies House data. A new company with directors recently dissolved on a prior company in the same trade, at the same or a nearby address, is a strong phoenix signal. CIS Defence runs this analysis automatically on every subcontractor and updates as new appointments are filed.
Boots on the Ground is a site-level identity check. CIS Defence sends a verification request to a named project manager on site, asking them to confirm who is actually working on a given day. The response is timestamped and stored as part of the Compliance Passport. It is the only mechanism that addresses the gap between “who is on the paperwork” and “who is on site”. This is increasingly relevant in identity fraud and labour substitution cases.
Uncommercially low pricing is one of HMRC’s stated red flags for tax fraud, because subcontractors evading tax can undercut compliant competitors. A subcontractor pricing 30% below market for a given trade and region is signalling something. CIS Defence benchmarks every subcontractor’s rate against current industry data (Spon’s 2026 validated rates for most trades) and flags anomalies for review.
A verification check confirms current status: is the subcontractor registered for CIS, what is their deduction rate, are they active at Companies House. A forensic check looks at the history: prior dissolved companies, director linkages, phoenix patterns, address overlaps, and other structural signals. The new regime requires both: status at the time of the transaction, and historic pattern as evidence of what you should have known.
Yes. VAT verification is live. CIS Defence checks each subcontractor’s VAT registration status against HMRC’s records alongside the CIS verification, so VAT and CIS status are captured in a single dated record on the Compliance Passport. The VAT check uses HMRC’s REST API and is independent of the CIS GovTalk XML integration, so a change in one does not affect the other.
CIS Defence monitors continuously and flags status changes immediately. A deregistration, dissolution, or director change mid-engagement is one of the highest-priority alerts the platform generates. The Compliance Passport records the date of the change and the action taken, so the response is part of the evidence trail.
£12.50 per active subcontractor per month, VAT-exclusive. Pricing is by active subcontractor, not by user seat or by company size, so it scales with your actual exposure.
We do not require long-term lock-in. Specifics of contract terms are confirmed during onboarding.
By written notice to your account contact. We hold your Compliance Passport history available for export for the standard record-retention period after cancellation.
Yes. The active subcontractor list updates continuously. Charging is based on the count of active subcontractors in the billing month, so additions and removals are reflected in the next invoice.
We offer live demos where we run your own current subcontractor list through the platform so you can see exactly what CIS Defence would have flagged. Contact us to arrange one.
Data is held on AWS infrastructure in the EU (Frankfurt region), encrypted at rest and in transit. Access is restricted to authorised Tax Radar personnel for the purpose of providing the service. We are ICO registered. Our Security page sets out the full position.
Yes. Tax Radar acts as a data processor for the subcontractor data you upload, with the contractor as data controller. Our processing terms, sub-processor list, and Record of Processing Activities are available on request. We are ICO registered.
Accounting software records transactions. It does not verify counterparty tax status against HMRC, it does not detect phoenix patterns across Companies House data, and it does not benchmark pricing for fraud signals. Xero and Sage are essential bookkeeping tools. They are not designed to defend a “should have known” allegation. Tax Radar CIS Defence is.
Accreditation schemes verify health and safety, insurance, and basic financial standing at a single point in time, usually annually. They do not perform live tax verification, they do not detect phoenix patterns, and they do not produce a contemporaneous tax-focused evidence pack. The two approaches are complementary: accreditations cover one part of the diligence picture, CIS Defence covers the tax fraud and supply chain integrity part.
An annual review is a point-in-time audit. The new regime is continuous: fraud occurring in October is not addressed by a review carried out in February. An external review also produces a written report rather than a structured, exportable, monthly evidence trail of the kind HMRC’s investigators are trained to interrogate. The two are not mutually exclusive, but an annual review alone leaves continuous-monitoring gaps that the legislation now penalises.
Book a demo and we will run your own subcontractors through CIS Defence so you can see exactly what it flags.