From 1st October 2026, Section 48 of the Border Security, Asylum and Immigration Act widens right to work checks beyond direct employees.
We brought together Amiqus clients, partners and a Home Office representative to explore:
- What the changes mean for immigration and employment considerations
- The Home Office view shared during the session
- How technology can support a stronger right to work process
The session raised more questions than we could answer live. Here are the ten points we think matter most.
This article summarises a discussion and is not legal advice. Formal Home Office guidance was still in draft when the session took place on 15th September 2026.
1. The 1st October date is not moving
The clearest answer of the session was on timing: it’s not changing.
The regulations are already in place. The expectation shared during the session was that they will come into force on 1st October without delay. The draft guidance has been updated following stakeholder feedback and isn’t expected to change substantially. It may still add a checklist and an annex covering common questions.
The practical takeaway is clear: plan against the published draft now. Waiting for the final version isn’t a strategy, and nothing suggests a grace period is coming.
2. Liability no longer stops at direct employees
The old shorthand, “that person isn’t my employee, so it isn’t my liability”, no longer holds.
The new rules reach into subcontracting, agency supply, and gig or platform arrangements. The panel flagged sectors where contracts permit worker substitution as higher risk, along with online matching services and contracts for services an individual delivers personally.
If you engage labour through anything other than a straightforward employment contract, start by identifying which of your arrangements now sit within your risk perimeter.
3. Existing contracts are safe, but rolling engagements need careful thought
A question that came up repeatedly was whether the rules apply retrospectively. The answer: they don’t.
If you had a contract in place before 1 October 2026, you don’t need to carry out a retrospective check. Contracts starting on or after 1 October are in scope.
Repeat engagements are less straightforward. Say someone completes a six-month assignment, leaves, then returns, is that a new engagement or a continuation? On a simple reading of the guidance, one check is enough. In practice, it depends on whether you’re working under an overarching contract or service agreement, or a series of separate instructions. Time-limited permission to work adds another layer.
4. Scope is a judgement call, not a checklist
The guidance sets out factors the Home Office will weigh up.
Who’s contractually responsible for providing the service? Who engages or supplies the individual? Is the work carried out personally? Is the relationship genuinely business to business?
The panel described this repeatedly as an overall assessment, not a test with a definitive answer.
The label attached to an arrangement doesn’t decide what it is. The panel compared this with the introduction of IR35, where the label mattered less than who held direction, supervision, and control in practice. Review your contracts, then look at what happens on the ground.
5. End users are usually outside the scope, but risk sits in the middle of the chain
A recurring scenario involved outsourced services on your premises, such as catering, cleaning, or security.
On a basic reading, if you’re receiving a business-to-business service, you sit outside the liability chain. Personal service companies contracting with other businesses and invoicing for work were also described as out of scope. What happens when they subcontract further down the chain remains an open question.
If you sit in the middle of the chain, having contracted with an end customer and subcontracted part of the delivery, you may fall within extended liability.
Even when you are clearly the end user, reputational risk and duties such as modern slavery obligations remain. Building a right to carry out spot checks into your supplier contracts is a sensible control.
6. A written statement supports the statutory excuse, but it doesn’t replace it
The panel corrected a common misconception about written statements.
In an extended liability scenario, the written statement is one of several prescribed requirements you need to establish a statutory excuse. It doesn’t replace the rest of the process. Treat it as one part of your evidence pack, not a shortcut.
7. You can outsource the process, not the liability
This was the line of the day.
You can use a provider to run and evidence your checks. But if a check turns out to be wrong, liability still rests with you as the employer, under the broader definition the new rules introduce.
From 1st October, the rules also change who you can work with to establish a statutory excuse. For digital right to work checks on UK and Irish passports you must use a certified Digital Verification Service provider (DVSP). It needs to appear on the GOV.UK Digital verification services register of digital verification service providers. The relevant role is now described as a right to work digital verification service provider.
The Home Office doesn’t endorse a single provider, so the register is your source of truth. If your current provider isn’t on it, speak to them now.
If your provider relies on another organisation to meet the technology requirements, ask what’s behind it: the underlying technology, the data processing, and whether the service can keep pace as the regulations evolve.
Some digital verification service providers, including Amiqus, support more of the compliance onboarding journey. This can include vetting, re-verification, and biometric checks to reduce day-one imposter risk. Digital source documents and holder services are also on the horizon as the regulations develop.
8. Imposter risk is the quiet failure point
Hiring fraud is real, and remote right to work checks and day-one imposter scams are part of the threat.
The most uncomfortable example of the day: an employer had outsourced its checks, then received a tip-off that the person doing the work wasn’t the person who’d been checked. When they audited the files, nobody could confirm which of two photographs showed the employee, because no follow-up check had taken place.
The Home Office representative’s principle was simple: a right to work check should confirm that the person you employ is the person who turns up to work. Large employers with mature digital onboarding often confirm identity again on day one. That safeguard can break down in remote and distributed hiring, where a single point-in-time check offers less protection.
9. Sponsor licence holders have the least room for interpretation
For sponsor licence holders, right to work checks already sit inside your compliance duties, and sponsor licence audits already examine them closely.
The panel expects extended liability to become part of those reviews too – which means a wait-and-see approach carries more risk for you than for most. Where the guidance is unclear, several panellists considered checking the safer option: you can’t be penalised for checking more than the rules require, but you can be penalised for checking less. Keeping a clear, audit-ready evidence trail for every check now will matter as much as running the check itself.
10. Right to work is no longer only a human resources process
The organisational impact will last beyond the 1st October deadline.
Right to work now touches procurement, in-house legal, onboarding and hiring teams, global mobility, and risk – not just the team that runs the checks. In large organisations, teams often sign contracts and subcontracting arrangements without ever looping in the people responsible for right to work.
The readiness approach shared during the session has four stages:
- Identify your worker populations. Confirm who’s in scope, who’s out of scope, and where extended liability could arise
- Review your current right to work process from start to finish. Find the gaps against the new requirements
- Redesign the policies, procedures, and supplier or subcontractor contracts that need to change
- Implement the changes with clear communication and training for every team involved.
Where Amiqus fits
We’ve worked with the Home Office and digital verification service working groups throughout the consultation process. That’s helped us build services that are compliant and practical to use.
- Certified and registered today. Amiqus is a certified and registered digital verification service provider for right to work checks, and we’ve held and maintained this certification for years.
- eVisa and share code collection: join the early access waitlist. We are adding support for collecting eVisa and share code information as part of an Amiqus check. This removes manual chasing and reduces the need to copy information between systems. Talk to us to be one of the first to access the new feature.
- Re-verification and imposter checks: work is under way. We’re working with high-volume clients to support repeat identity confirmation for remote and contingent workers at scale, using the same facial similarity and biometric assurance as the initial check.
- Broader document coverage from 1st October. You’ll be able to use passports that expired within the last six months once you’ve completed a Near Field Communication (NFC) check. That should help more people complete the process first time.
Where to go from here
Working through the four steps above – identify, review, redesign, implement – takes time most teams don’t have spare before 1st October.
If you’d like a second pair of eyes on where you stand, speak to your relationship manager or get in touch to hear more about how we can help.
Missed the webinar?
Watch it on demand to tune in to the full conversation.
Sign up below and we’ll send you the link.


