A client-facing compliance portal giving recruitment agencies self-serve access to payroll evidence, RTI submissions, and HMRC payment proof — shipped ahead of April 2026 Joint and Several Liability enforcement, with 50% of the addressable market adopting in Month 1.

.timeline
5 months (October 2025 — February 2026)
.year
2026
.tools
Figma, Jira, Confluence, Miro, Linear
.role
Product Lead
From April 2026, HMRC's Joint and Several Liability legislation made recruitment agencies directly liable for unpaid tax if their umbrella or payroll supplier couldn't prove compliance. Before this feature existed, agencies had no structured way to get that proof — they were chasing their payroll provider for screenshots, filling in spreadsheets from multiple data sources, or paying dedicated third-party verification providers that pulled the same data from payroll API integrations anyway. For smaller agencies, those third-party providers weren't an option; the cost was prohibitive. For larger ones, there was a real question of why they were paying for a service their payroll software should already provide. Either way, the compliance burden was falling on the wrong people, in the wrong format, under significant time pressure.
I identified the legislative risk early through active monitoring of the industry compliance landscape, and brought the case internally for building our own compliance hub rather than leaving clients to rely on third parties. The result was a new client-facing portal — built on a modernised tech stack with a redesigned UX — that gives agencies self-serve access to payroll summaries, RTI submission records, HMRC payment evidence, and downloadable compliance reports for any given tax month. The portal shipped to all customers in February 2026, ahead of the April enforcement date. Within the first month, 25% of all customers had adopted it — representing 50% of our addressable market, since the remaining customers are direct employers who don't face the same JSL exposure.
I first flagged Joint and Several Liability as a product opportunity in late 2024. Part of how I work is maintaining close awareness of legislative changes that create new workflows or new risks for our customers — JSL was an obvious one. From April 2026, recruitment agencies would be on the hook if their umbrella or payroll provider couldn't demonstrate compliance with HMRC. The question wasn't whether our customers would need this — it was whether they'd pay a third party for it, or whether we'd build it ourselves.
I researched the third-party verification market — providers like SafeRec and VeriPAYE — and spoke to customers about how they were currently handling compliance evidence requests. The picture was consistent: manual, fragmented, and disproportionately time-consuming. Payroll ops teams were pulling data from multiple places and stitching it into screenshots and spreadsheets on demand. Agencies were waiting days for audit packs. Some smaller agencies couldn't afford the third-party tools and had no plan. I made the case internally that we already held all the data these providers were reselling, and that building our own compliance hub would both retain our umbrella customer base through a major legislative shift and meaningfully improve their day-to-day operations.
The build had two significant constraints I had to navigate. The first was a GDPR problem. Workers in temporary employment move between agencies, and their employee records can contain historical data from previous engagements. We couldn't simply expose the full employee record to a client portal user — there was a real risk of surfacing information from a different agency relationship. I worked through the data access model carefully, scoping exactly what each client portal user could see and ensuring that compliance evidence was surfaced at the right level of granularity without exposing cross-agency worker data. The second constraint was a technical dependency: the feature needed to live in a new client portal we were simultaneously building to replace our legacy agency portal. That migration had to complete before we could ship compliance. I tracked it as a hard dependency from October, with the new portal delivered in December and the compliance hub production-ready by end of February — six weeks ahead of the legislative deadline.
Scope was another deliberate call. The full vision included a VAT compliance hub, company documentation management, and a worker-level audit report generator that would cross-reference right-to-work status, contract status, and RTI data against individual payslips. I made the decision to descope all of that from V1 and focus entirely on what agencies needed to demonstrate payment and submission compliance by April. The broader compliance vision remains on the roadmap — but shipping a complete, polished V1 of the core use case ahead of the deadline was more valuable than shipping a partial version of a broader one.
The portal shipped to all customers in February. Month 1 adoption was 25% overall — but once you account for the fact that only half our customer base faces JSL exposure (the other half are direct employers, not payroll service providers), that's 50% of the addressable market adopting in the first month. We tracked new logins created, document upload volume, and upload errors — the only failures were file size related, and we iterated quickly with better in-app guidance. The strongest signal came from a customer testimonial: the portal was described as "far superior to what the client receives from a purpose-built third-party provider." That competitor's product exists solely for this use case. Ours was a feature in a broader platform.
In hindsight, I'd have pushed harder to instrument time-to-compliance earlier — specifically tracking how long it took a payroll ops team to upload a full month's evidence pack. That data would have made the efficiency story quantifiable rather than anecdotal, and would have strengthened the case for the next phase of the roadmap.
Every problem worth solving has a human at the centre of it.