Payroll is no longer just an operational function. It is part of your compliance evidence.
Joint and several liability moves the risk of an umbrella company’s payroll onto the agency and the end client that engaged the worker. This page explains what that changes, in plain English.
The liability travels up the chain
Historically, if an umbrella company failed to operate PAYE correctly, the exposure sat largely with the umbrella company. Under joint and several liability, that exposure can attach to other parties in the supply chain - typically the recruitment agency, and in some circumstances the end client.
The practical consequence is straightforward. An agency that places a worker through an umbrella now carries a financial interest in whether that umbrella actually operated payroll correctly and actually paid over what it owed. It is no longer a question of contractual comfort. It is a question about somebody else’s money becoming their problem.
What agencies will start asking for
Agencies will not ask to see your payroll software. They will ask for evidence about specific pay runs, and they will ask repeatedly, because they need it for their own position rather than yours.
- Which controls ran on a given pay run, and what each one produced.
- Who approved anything that did not pass cleanly, when, and on what basis.
- Whether the FPS was submitted and what HMRC returned.
- What the PAYE and NIC liability was, and whether the funds to meet it were held.
- That the evidence covers only their workers, without exposing your other commercial relationships.
Compliance should happen during payroll - not be reconstructed afterwards.
Why reconstruction fails
Most umbrella operations can produce a payslip and an FPS on request. Far fewer can produce all of the above at once, for a run that closed months ago, without a person spending days on it.
That is not a competence problem. It is an architecture problem: a system records decisions only if it was built to record them while the work was happening. Afterwards, the decision is gone and only its outcome remains - and an outcome is not evidence of a process.
Detection versus protection
Several platforms address this by adding detection: reports that surface a problem after the run, or an integration with a third-party checking service. That is genuinely useful, and it is better than nothing.
It is not the same as prevention. A control that identifies an incorrect holiday-pay calculation after payday has told you about a liability you now have. A control that blocks the run until the calculation is corrected means you never acquired it.
What a payroll operation should do now
Three things are worth establishing before any system decision:
- Where your current evidence actually lives, and how long it takes to assemble a full picture of one pay run.
- Which of your controls run during the pay run, and which only run after it.
- What you would send an agency tomorrow if it asked, and how much of it you would have to build by hand.
If the answer to the last one involves an export and a spreadsheet, that is the gap. It is a gap that closes by moving the evidence into the process, not by adding another report on top of it.
This page is a plain-English summary written for payroll and compliance teams. It is not legal advice, and it does not replace guidance from your own advisers.
Four expectations that moved.
Each of these was a reasonable definition of “running payroll well” five years ago. None of them is sufficient now.