Beyond the SafeRec Certification

SafeRec Team
2 September 2026
The Story Behind the Number of Certified Umbrella Companies, an Extensive Undercover Investigation and a Wave of Umbrella Acquisitions.
Over the past several months, SafeRec has experienced one of the most unusual periods since our certification was created. The story takes us from a wave of umbrella acquisitions and questions around payroll and ownership, through an extensive undercover investigation, to additional controls, significant pressure and threats against our team, and ultimately circumstances that led SafeRec to contact the police.
It has been one of the most challenging periods we have experienced since creating SafeRec, but also one of the most important.
When we built SafeRec, we knew that operating a robust certification and real-time audit framework would sometimes require us to ask difficult questions and make difficult decisions. What we perhaps did not anticipate was the level of pressure that could follow when those questions challenged the interests of certain operators, or how strongly some businesses would resist additional controls and verification we considered necessary.
Our processes have never been static. As legislation changes, new intelligence becomes available and different structures or practices emerge, we develop our controls accordingly. Much of that work happens quietly behind the scenes, because continuously improving the certification is part of our responsibility rather than something we feel the need to announce every time it happens.
Over the coming weeks, we are going to tell the story of what we experienced, what we observed, the undercover investigation that followed and how the events of this period shaped the additional controls and verification we introduced. We will do so as transparently as we responsibly can, while respecting the legal, contractual and confidentiality obligations that inevitably limit some of what we can share.
The story starts at the beginning of 2026, when we noticed something unusual happening in the acquisition market for umbrella companies.
An unusual start to the year
Acquisitions are nothing new in the umbrella market. Successful businesses are bought and sold, investors enter the industry and owners eventually decide to exit. There was therefore nothing remarkable about hearing that umbrella companies were changing hands.
What caught our attention was the volume of activity and, increasingly, the valuations being discussed.
At almost exactly the same time, demand from umbrella companies wanting to understand SafeRec Certification increased at a level we had never experienced before. During one period in Q1, 42 umbrella companies approached us about starting the process. On the face of it, that was positive. SafeRec was growing quickly and recruitment agencies were increasingly asking their umbrella partners about certification.
But SafeRec occupies a slightly unusual position in the market. For years, recruitment agencies have been uploading payslips from umbrella companies across the industry to our Platform. Consequently, when an umbrella company approaches SafeRec for certification, there are often occasions where we have already seen payroll information relating to that business through agencies using SafeRec.
Some of the companies approaching us were therefore businesses about which we already held relevant payroll intelligence, meaning that in some cases our understanding of the business did not begin with the certification demo.
At the same time, we were hearing that some businesses which had already achieved SafeRec Certification were attracting significant acquisition interest. Experienced operators looking to make acquisitions themselves told us that commercially reasonable offers were being rejected because other prospective buyers were prepared to pay considerably more. In some cases, the valuations being discussed were several multiples higher than those buyers believed the businesses would ordinarily command.
None of this, by itself, demonstrated wrongdoing. A buyer can place a premium on a business for many commercial reasons, and we were careful not to draw conclusions simply from an acquisition or valuation.
But then another signal started appearing for some Umbrella Companies through the SafeRec Platform.
What agencies could see, and what they couldn't
SafeRec was built differently from a traditional accreditation model precisely because these risks were already known to us.
From the beginning, we understood that assessing payroll at a particular moment, awarding a certification and returning months later could not provide the ongoing visibility we wanted to give the recruitment supply chain. An umbrella could operate more than one PAYE reference, workers could potentially be moved between payrolls, or funds could be transferred to another entity which then engaged and paid those workers.
That is why SafeRec was built around continuous controls.
All PAYE reference numbers operated by a certified umbrella company must be disclosed and included within the relevant SafeRec audit controls. Payslips are audited continuously and compared with RTI information submitted to HMRC, additional verification takes place throughout the certification period, and recruitment agencies receive monthly reporting as well as direct access to real-time audit information relating to their workers through the SafeRec Platform. We made the Platform free from the beginning because transparency is one of our core principles and has always been an integral part of how our framework was designed.
SafeRec can audit every PAYE reference disclosed to us, but if a business were deliberately to use an undisclosed PAYE reference, or transfer funds to another entity which then engaged and paid part of the worker population, those workers could potentially sit outside the payroll being presented.
This is where the recruitment agency becomes an important additional control, because it knows how many workers it has placed with an umbrella. Imagine an agency has 100 workers with an umbrella company but can only see the expected SafeRec audit information for 70. It should not simply take comfort from the fact that those 70 payslips have passed the audit. It should ask a very simple question: Where are the other 30?
If those workers were being processed through an undisclosed PAYE reference or paid through another entity, the payroll visible to SafeRec could continue to reconcile with the RTI relating to that payroll while another population remained outside the audit. If PAYE liabilities associated with that separate population were then not paid to HMRC, significant liabilities could potentially accumulate elsewhere.
This was not a risk we discovered in 2026. It is one of the reasons SafeRec was built this way from the beginning, why agencies receive ongoing reporting and why access to the Platform is free.
What changed was the scale at which that transparency was being used.
More than 5,000 recruitment agencies created SafeRec accounts and, as agencies increasingly checked their workers, a few began reporting that workers and payslips they expected to see were missing. Each time an agency raised the issue directly with the umbrella, the situation was rectified. What made those reports particularly significant was the pattern behind them: the cases being brought to our attention related to umbrella companies that had undergone changes in ownership from December 2025 onwards.
This was happening at the same time as the acquisition activity we were already watching.
We weren't discovering a new risk. We were seeing controls built to identify that risk produce signals that warranted further investigation. We did not want to make assumptions or conclude that the acquisition activity was connected. The Board decided we needed to understand more.
An extensive SafeRec undercover investigation
There was an obvious difficulty. If SafeRec approached brokers or operators and directly asked whether they knew of arrangements through which payroll could sit outside the controls we were applying, we were unlikely to learn very much.
We needed to understand what would be presented when the person on the other side believed they were speaking to a potential customer rather than a compliance organisation.
We therefore created several fictitious healthcare recruitment agencies, established the infrastructure necessary for them to operate credibly and began developing relationships with brokers. We presented ourselves as recruitment businesses interested in whether there were opportunities to improve the commercial return from our payroll supply chain.
The investigation was deliberately structured to gather as much reliable information as possible.
At the beginning, our objective was not to obtain evidence at all. It was to build trust and listen. The people involved in the investigation were instructed not to appear overly curious, not to ask leading questions and not to push conversations towards conclusions we might expect.
If somebody had a proposition they wanted to sell, we wanted them to explain it themselves.
We were prepared for the investigation to produce very little. Repeatedly prompting someone to tell you what you want to hear has limited value; understanding what they voluntarily present to a recruitment business they believe they can work with is very different.
Over several weeks, the picture became clearer.
We were presented with different payroll arrangements and heard discussions involving workers being processed through different entities or PAYE references. We were presented with financial incentives connected with payroll and, eventually, arrangements described to us as involving Bills of Exchange.
We will cover those conversations properly later in this series. Where it is appropriate and lawful to do so, we also intend to show evidence rather than simply asking the industry to accept SafeRec's interpretation of what was said.
The investigation provided additional intelligence and context for the activity we had been observing. That intelligence also had practical consequences.
When new controls meet resistance
SafeRec continuously develops its controls. During Q2, we introduced additional requirements around ownership and changes of control, further verification, and additional requirements where information or access was necessary for us to remain satisfied that a certified business continued to meet the required standards.
The overwhelming majority of SafeRec Certified umbrella companies (over 90%) worked with us. When additional information or verification was required, nearly all engaged constructively and provided what was necessary.
In a smaller number of cases, the position became considerably more difficult. Necessary information or verification was not provided, concerns could not be resolved, circumstances surrounding a business had materially changed, or a business was unwilling to continue under controls we considered necessary. Certification could not simply remain in place because removing it might be difficult or commercially uncomfortable. Over the following weeks, several umbrella companies ceased to be SafeRec Certified.
Nor should the matters described throughout this introduction be taken as applying to any of those businesses; the circumstances, concerns and reasons for cessation differed from company to company.
During this wider period, some decisions also resulted in significant pressure being placed on SafeRec and members of our team. Our processes and authority were challenged, lawyers became involved and, on occasions, communications crossed a line that we considered threatening. Certain information and communications arising from particular matters became sufficiently concerning that we contacted the police and shared relevant material.
We do not mention this to dramatise what happened or portray SafeRec as a victim. A compliance organisation making decisions that materially affect businesses should expect its decisions to be challenged and should be prepared to explain and defend the evidence on which it has acted. Equally, we have a responsibility to challenge our own conclusions, consider alternative explanations and distinguish evidence from suspicion.
But there is another side to that responsibility. A certification has limited value if the organisation behind it is only prepared to enforce its standards when doing so is easy.
There will inevitably be occasions when protecting the integrity of a certification means making an uncomfortable decision, attracting criticism or facing significant pressure. Over the past several months, we have had to make several of those decisions.
What this period reinforced for us
The events of 2026 reinforced many of the principles on which SafeRec was built.
Businesses change after certification. Ownership can change, new PAYE references can be introduced, payroll arrangements can evolve and different entities can become involved. This is precisely why continuous auditing, ongoing verification, monthly reporting and direct agency visibility via the SafeRec platform have always formed part of our model.
What changed was not our understanding that these risks existed, but the circumstances we were seeing and the intelligence available to us. As that intelligence developed, we continued doing what SafeRec has always done: adapting our processes and introducing additional controls and verification in response.
The experience also reinforced another principle: a control only has value if you are prepared to enforce it.
The systems and transparency already in place gave us signals to look further, the investigation provided additional intelligence, and our certification framework allowed us to respond as circumstances developed. Throughout that period, we continued developing our controls, expanding the intelligence available to us and standing behind the standards on which SafeRec Certification was built.
That is ultimately what this series is about: what happens when the controls designed to identify a risk produce a signal, how we investigate it and what we are prepared to do when the evidence requires us to act.
The story we will tell over the coming weeks
We are sharing this story because its relevance extends well beyond SafeRec.
Recruitment agencies, MSPs and end clients increasingly need meaningful visibility over their payroll supply chains, and we believe there is value in explaining what we encountered during this period and the practical controls available to businesses.
We will begin with Part One: The Acquisition Wave, examining the extraordinary acquisition activity we observed during Q1, the increase in demand for SafeRec Certification demonstrations and the significant interest being shown in already-certified umbrella companies.
Part Two: The Missing Payslips will examine what agencies began identifying through the Platform, how workers can potentially be processed through another PAYE reference or entity and why agencies must compare the workers visible through SafeRec with the population they expect to see.
Part Three: Going Undercover will take readers inside our extensive investigation: how the fictitious recruitment agencies were established, how relationships developed and what happened as people began presenting opportunities to us in their own words.
Part Four: When Controls Are Challenged will examine what happened as additional controls were introduced, how businesses responded to those requirements and what followed when some of our decisions and processes were challenged, including the wider pressure we experienced during this period.
Finally, Part Five: Transparency, Not Trust will look forward: at ownership and changes of control, PAYE visibility, payroll populations and the practical information recruitment businesses should be using to understand their supply chains.
There will inevitably be limits to what we can publish. We will respect our contractual and confidentiality obligations, and there are matters involving third parties and authorities where disclosure would not be appropriate. Throughout the series, we will distinguish between facts we can establish, information presented to us and assessments reached by SafeRec.
This is not intended as a victory lap, nor to suggest that every acquisition, additional entity or second PAYE reference indicates wrongdoing. It is the story of an extraordinary period for our business and the market in which we operate: what we saw, how the controls SafeRec had been built around responded, and what we did when the information in front of us required action.
Some of the decisions we made during this period were among the most significant we have faced since SafeRec was created, and at times they brought considerable pressure and challenge. Throughout it, however, we continued to develop our controls, expand the intelligence available to us and, above all, stand behind the standards and transparency on which SafeRec Certification was built.
Over the coming weeks, we are going to share that story properly.
Next, we start at the beginning with Part One: The Acquisition Wave.