Frequently Asked Questions

Frequently Asked Questions

This page collects the questions construction contractors, finance directors, and advisers most frequently ask us about the new CIS regime taking effect from 6 April 2026, and about Tax Radar CIS Defence.

The April 2026 changes

What changed for CIS on 6 April 2026?

The Finance Act 2026 introduced new sections 62A and 62B into the CIS legislation. From 6 April 2026, HMRC can hold principal contractors liable for tax lost through fraud committed elsewhere in their subcontractor supply chain, where the contractor “knew or should have known” that fraud was occurring. This is a significant expansion of HMRC’s existing CIS enforcement powers. See the Finance Act 2026 and its Explanatory Notes for the statutory wording.

What are Sections 62A and 62B of the Finance Act 2004 (inserted by the Finance Act 2026)?

Section 62A creates a power for HMRC to recover lost tax from principal contractors where fraud has occurred in the supply chain and the contractor knew or should have known about it. Section 62B sets out the mechanism for immediate removal of Gross Payment Status from contractors connected to such fraud, without the usual review or appeal window. The two provisions together significantly raise the consequence of inadequate due diligence.

Who is affected by the April 2026 CIS changes?

Any business that engages subcontractors under the Construction Industry Scheme is affected. This includes Tier 1 principal contractors, sub-contractors who themselves engage labour, and deemed contractors whose construction spend brings them into scope. The legislation does not distinguish by size: a regional builder engaging twenty subbies is exposed in the same way as a national contractor engaging two thousand.

What is the “knew or should have known” standard?

It is the evidential threshold that determines whether you can be held liable for tax lost through fraud elsewhere in your supply chain. “Knew” covers actual knowledge. “Should have known” is the harder test: it asks whether a reasonable person in your position, exercising reasonable due diligence, would have spotted the warning signs. The test is fact-specific and judged on the evidence available at the time of the transaction, not with hindsight.

Where does the “knew or should have known” standard come from?

It is not a new statutory test. It is borrowed directly from VAT case law, where it is known as the Kittel principle, after the 2006 European Court of Justice judgment in Axel Kittel v Belgian State. Nearly twenty years of UK case law (Mobilx, Davis & Dann, Fonecomp, and others) has developed the principle. Construction will now be judged against the same body of case law. See our Kittel Countdown article and the case law section of our references page.

Can HMRC remove Gross Payment Status immediately under the new rules?

Yes. Under section 62B, HMRC can withdraw Gross Payment Status with immediate effect where the contractor is connected to supply chain fraud. The previous review and appeal window does not apply. Loss of GPS shifts the contractor to 20% (or 30% if unverified) deductions at source, which has immediate cash flow consequences for the business.

Am I liable for fraud committed by a sub-subcontractor I have never met?

Potentially yes. The new regime extends contractor liability beyond the immediate supplier relationship. If fraud is found further down the supply chain, the question becomes whether you knew, or should have known, that something was wrong. This is why mapping the supply chain and continuously monitoring counterparties matters: liability does not stop at your direct subcontractor.

What is the maximum personal liability I face as a director under the new rules?

Director personal liability for penalties under the new regime is capped at 30% of the tax loss attributable to the fraud, not the full underlying tax liability. This is a meaningful but real exposure: on a £500,000 fraud, the director-level penalty could be up to £150,000. This is in addition to the corporate-level liability and any GPS consequence. The exact amount depends on HMRC’s assessment of culpability and cooperation.

Does the new regime apply to deemed contractors?

Yes. A deemed contractor (a business that is not a construction business but whose construction spend exceeds the threshold) is subject to the same obligations as a principal contractor for the purposes of the new rules. Property developers, large landlords, and businesses with significant fit-out programmes should review their position.

Are the new rules retrospective?

The new rules apply to construction operations carried out on or after 6 April 2026. They are not retrospective in the strict legal sense. However, evidence of historic patterns (for example, repeated use of phoenix subcontractors over years) may be relevant to whether a contractor “should have known” about fraud occurring after April 2026. Historic conduct is part of the factual matrix; it does not create liability in itself.

Reasonable care and due diligence

What does “reasonable care” mean under the new CIS regime?

Reasonable care is the standard of due diligence a contractor must demonstrate to defend against a “should have known” allegation. It is not defined in the legislation. In practice it means: verifying subcontractor identities and tax status, monitoring for changes, investigating warning signs, benchmarking rates against market, and keeping a contemporaneous, timestamped record of all of the above. See our guidance on what reasonable care looks like in practice.

What does HMRC expect to see as evidence of due diligence?

A documented, contemporaneous record of the checks you carried out, when, what they returned, and what you did about anything they flagged. HMRC’s Guidelines for Compliance GfC12 on labour supply chains sets out the framework. A Compliance Passport (see below) is designed to produce exactly this record in HMRC-ready form. Verbal assurances, expired CHAS certificates, and one-off checks are unlikely to be sufficient on their own.

Is a one-off CIS verification at the start of a relationship enough?

No. The new regime is built on the premise that supply chain risk evolves. A subcontractor who passed verification in January may have been deregistered, dissolved, or substituted by July. Reasonable care implies ongoing monitoring rather than a single check at onboarding. This is the gap that continuous monitoring tools are designed to fill.

How often should I check my subcontractors?

The right answer depends on the size and risk profile of your supply chain, but the principle is “at least as often as something material could have changed”. For active subcontractors that typically means monthly verification with HMRC, continuous monitoring of Companies House data, and immediate flags on changes (deregistration, dissolution, director changes). Tax Radar CIS Defence runs these checks automatically.

What is a Compliance Passport?

A Compliance Passport is the monthly evidence pack produced by Tax Radar CIS Defence. It contains a timestamped snapshot of every check carried out on every active subcontractor, the result of each check, and the action taken in response. It is designed to be the artefact a contractor produces in response to an HMRC enquiry to demonstrate that reasonable care was exercised. It is exportable as a PDF and shareable with advisers and auditors.

Will a Compliance Passport definitely protect me from HMRC enforcement?

No tool can guarantee that. The “should have known” test is fact-specific and applied case by case. What a Compliance Passport does is produce the contemporaneous, structured evidence trail that the test requires. The alternative (reconstructing your due diligence after the fact from emails, spreadsheets, and memory) is materially weaker. Reasonable care is shown by what you did at the time, not what you can piece together later.

Is CHAS or Constructionline accreditation enough?

No. Accreditation schemes verify a subcontractor’s status at a single point in time and do not address tax fraud risk. A subcontractor can be CHAS-accredited and still be part of a phoenix fraud scheme. Accreditations are useful as part of a broader due diligence package; they are not a substitute for ongoing tax-specific verification and forensic monitoring.

Do I need to verify every subcontractor or just new ones?

Every active subcontractor. The legislation does not draw a distinction between new and existing relationships. A subcontractor you have engaged for ten years can be deregistered, dissolved, or implicated in fraud just as easily as a new one. Some long-standing relationships are the highest risk precisely because they are taken for granted.

What records do I need to keep, and for how long?

HMRC’s general record-keeping rule for tax records is six years. For CIS records specifically, three years is the statutory minimum but six is the practical standard given the longer enquiry windows in fraud cases. We recommend retaining the full Compliance Passport history for at least six years. Records should be tamper-evident and timestamped.

What is the safest defensive position to be in by April 2026?

A documented, repeatable, monthly due diligence process covering every active subcontractor, with immediate alerts on material changes, benchmarked pricing data, and on-site verification of who is actually working. The process should produce a contemporaneous evidence pack each month that could be handed to HMRC tomorrow. That is what Tax Radar CIS Defence is built to deliver.

Subcontractor verification and detection

How does Tax Radar verify subcontractors with HMRC?

Tax Radar CIS Defence connects directly to HMRC’s CIS API to verify subcontractor registration and tax status in real time. We are HMRC CIS Internet Recognised (Vendor ID 9328), which means our software meets HMRC’s technical and security standards for direct integration. Verifications are not cached: every check is live.

What is phoenixism and why does it matter?

Phoenixism is the practice of deliberately liquidating a company to escape tax liabilities, then re-forming a similar business under a new name with the same directors. It is a common fraud pattern in construction. Engaging a phoenix subcontractor is one of the clearest “should have known” red flags, because the public Companies House data showing the linkage is available to anyone who looks. CIS Defence detects phoenix patterns automatically.

How do you detect phoenixism?

By cross-referencing director appointments, registered addresses, and incorporation histories across Companies House data. A new company with directors recently dissolved on a prior company in the same trade, at the same or a nearby address, is a strong phoenix signal. CIS Defence runs this analysis automatically on every subcontractor and updates as new appointments are filed.

What is “Boots on the Ground” verification?

Boots on the Ground is a site-level identity check. CIS Defence sends a verification request to a named project manager on site, asking them to confirm who is actually working on a given day. The response is timestamped and stored as part of the Compliance Passport. It is the only mechanism that addresses the gap between “who is on the paperwork” and “who is on site”. This is increasingly relevant in identity fraud and labour substitution cases.

Why does pricing benchmarking matter for CIS fraud?

Uncommercially low pricing is one of HMRC’s stated red flags for tax fraud, because subcontractors evading tax can undercut compliant competitors. A subcontractor pricing 30% below market for a given trade and region is signalling something. CIS Defence benchmarks every subcontractor’s rate against current industry data (Spon’s 2026 validated rates for most trades) and flags anomalies for review.

What is the difference between a verification check and a forensic check?

A verification check confirms current status: is the subcontractor registered for CIS, what is their deduction rate, are they active at Companies House. A forensic check looks at the history: prior dissolved companies, director linkages, phoenix patterns, address overlaps, and other structural signals. The new regime requires both: status at the time of the transaction, and historic pattern as evidence of what you should have known.

Can Tax Radar check VAT status as well as CIS?

Yes. VAT verification is live. CIS Defence checks each subcontractor’s VAT registration status against HMRC’s records alongside the CIS verification, so VAT and CIS status are captured in a single dated record on the Compliance Passport. The VAT check uses HMRC’s REST API and is independent of the CIS GovTalk XML integration, so a change in one does not affect the other.

What if a subcontractor’s CIS status changes mid-project?

CIS Defence monitors continuously and flags status changes immediately. A deregistration, dissolution, or director change mid-engagement is one of the highest-priority alerts the platform generates. The Compliance Passport records the date of the change and the action taken, so the response is part of the evidence trail.

Commercial and contractual

How is Tax Radar CIS Defence priced?

£12.50 per active subcontractor per month, VAT-exclusive. Pricing is by active subcontractor, not by user seat or by company size, so it scales with your actual exposure.

Is there a minimum contract length?

We do not require long-term lock-in. Specifics of contract terms are confirmed during onboarding.

How do I cancel?

By written notice to your account contact. We hold your Compliance Passport history available for export for the standard record-retention period after cancellation.

Can I add or remove subcontractors mid-month?

Yes. The active subcontractor list updates continuously. Charging is based on the count of active subcontractors in the billing month, so additions and removals are reflected in the next invoice.

Is there a free trial or pilot?

We offer live demos where we run your own current subcontractor list through the platform so you can see exactly what CIS Defence would have flagged. Contact us to arrange one.

Where is my data stored, and who can access it?

Data is held on AWS infrastructure in the EU (Frankfurt region), encrypted at rest and in transit. Access is restricted to authorised Tax Radar personnel for the purpose of providing the service. We are ICO registered. Our Security page sets out the full position.

Is Tax Radar GDPR compliant?

Yes. Tax Radar acts as a data processor for the subcontractor data you upload, with the contractor as data controller. Our processing terms, sub-processor list, and Record of Processing Activities are available on request. We are ICO registered.

Comparisons

How is Tax Radar different from Xero or Sage?

Accounting software records transactions. It does not verify counterparty tax status against HMRC, it does not detect phoenix patterns across Companies House data, and it does not benchmark pricing for fraud signals. Xero and Sage are essential bookkeeping tools. They are not designed to defend a “should have known” allegation. Tax Radar CIS Defence is.

How is Tax Radar different from CHAS, SafeContractor, or Constructionline?

Accreditation schemes verify health and safety, insurance, and basic financial standing at a single point in time, usually annually. They do not perform live tax verification, they do not detect phoenix patterns, and they do not produce a contemporaneous tax-focused evidence pack. The two approaches are complementary: accreditations cover one part of the diligence picture, CIS Defence covers the tax fraud and supply chain integrity part.

Why not just engage an accountant to do an annual review?

An annual review is a point-in-time audit. The new regime is continuous: fraud occurring in October is not addressed by a review carried out in February. An external review also produces a written report rather than a structured, exportable, monthly evidence trail of the kind HMRC’s investigators are trained to interrogate. The two are not mutually exclusive, but an annual review alone leaves continuous-monitoring gaps that the legislation now penalises.

Still have a question?

Book a demo and we will run your own subcontractors through CIS Defence so you can see exactly what it flags.