Book a Call
← All articles Blog

Virtual Assistants for UK Recruitment Firms: A Compliance-First Guide

Liam Lloyd Liam Lloyd 23 min read

Virtual Assistants for UK Recruitment Firms: A Compliance-First Guide

It is twenty past nine on a Tuesday evening in March, and the managing director of a fourteen-person recruitment business in Leeds has three windows open on her laptop.

The first is a spreadsheet tracking which of her four preferred umbrella providers have supplied current evidence of PAYE compliance — two have, one sent something in November that she is fairly sure is out of date, and the fourth has stopped answering emails. The second is a diary reminder she set for herself in January: re-check RTW — warehouse contract, 6 workers, share codes expire. She cannot now remember whether she did it. The third is an email from a candidate she placed in 2023, requesting a copy of everything the business holds about him. It arrived on the seventh of the month. It is now the twenty-fourth.

None of these three things is difficult. Any of them, on its own, would take a competent person under an hour. Together, at nine-twenty at night, after a day of client calls and two candidate no-shows, they are the reason she is still at her desk — and the reason she has not looked at the two roles that came in on Friday.

This is the shape of the problem in UK recruitment right now. It is almost never one crushing obligation. It is fourteen small ones, each with its own deadline, evidence requirement and regulator, landing on people whose actual job is to talk to candidates and win business. In 2026 the number of those obligations rose sharply. The number of people available to absorb them did not.

What follows is a working guide to that problem — what changed this year, what the new rules actually ask you to produce, what it costs in hours, and where a properly managed virtual assistant fits in. It is written for the owner or operations lead of a small-to-mid-sized UK agency: the kind of firm that makes up the overwhelming majority of the sector and has no compliance department to hide behind.

2026: The Year the Liability Moved Up the Chain

Three things happened this year that changed the risk profile of running a recruitment business in Britain, and they happened within about six months of each other.

The first, and by some distance the largest, arrived on 6 April. Under new provisions inserted into ITEPA 2003, recruitment agencies became responsible for accounting for PAYE and Class 1 National Insurance on payments made to workers supplied through umbrella companies. Where there is no agency in the chain, that responsibility falls to the end client. HMRC has been explicit that this is a tax compliance measure rather than full regulation of the umbrella sector — but the practical effect is that if an umbrella in your supply chain fails to operate PAYE properly, HMRC can come to you for the shortfall. The Government’s own estimate is that the change protects around £2.8 billion in revenue by 2029–30, which tells you something about the scale of the non-compliance it was designed to catch.

Consider what that number implies about the population of umbrella companies currently operating in the UK market — and note that the legislation uses a deliberately broad definition of “umbrella company”, wide enough to capture Professional Employer Organisations and Employers of Record, precisely to stop firms restructuring their way out of it.

The obligation is no longer simply to choose a compliant umbrella. It is to be able to prove, after the fact, that you checked — and what you checked, and when.

The second change came the following day. The Fair Work Agency was established on 7 April 2026 under Part 5 of the Employment Rights Act 2025, consolidating enforcement functions previously scattered across the Employment Agency Standards Inspectorate, the Gangmasters and Labour Abuse Authority, and HMRC’s National Minimum Wage team. This matters less because of any single new power and more because of what consolidation does to enforcement behaviour. A single body with one intelligence picture, the ability to bring tribunal proceedings in a worker’s name, and the power to investigate arrears going back six years is a materially different proposition from three inspectorates each working a narrow remit. The Government has been candid that 2026–27 is a transitional year in which the FWA mostly absorbs existing functions. That is not a reason to relax. It is a reason to get your records straight before the agency finishes settling in.

The third change lands on 1 October 2026. Under the Border Security, Asylum and Immigration Act 2025, the duty to carry out right to work checks expands well beyond traditional employment to cover a much wider range of working arrangements — individual sub-contractors, gig and platform workers, and labour supplied through chains. Civil penalties remain at up to £45,000 per worker for a first breach and up to £60,000 for a repeat breach. For any business built on contingent labour, that is a significant widening of exposure, and the draft revised Code of Practice makes clear that complex supply chains are exactly where the Home Office expects to find failures.

Behind all of this sits the phased implementation of the Employment Rights Act 2025. The zero-hours and agency worker provisions — guaranteed hours offers, reasonable notice of shifts, compensation for short-notice cancellations — are not yet live, with commencement expected in 2027. But the allocation of duties is already sketched out, and it is not comfortable reading. The Government has confirmed that the end hirer will offer guaranteed hours, that both hirer and agency will carry the duty to give reasonable notice of shifts, and that employment agencies will be responsible for paying compensation where shifts are cancelled, curtailed or moved at short notice — with reimbursement terms left to agreement between agency and hirer. In practice: agencies pay out first and recover later, on the strength of records they need to have kept in real time.

Every one of these obligations produces paperwork. None of them produces revenue.

What the Regulators Now Ask You to Produce

There is a distinction worth drawing here, because it changes what kind of help is useful. Very little of the 2026 compliance burden is about judgement. Almost all of it is about evidence — creating it, filing it, retrieving it on demand, and showing the sequence in which it was created.

The Conduct Regulations record trail

Regulation 29 of the Conduct of Employment Agencies and Employment Businesses Regulations 2003 requires you to keep records sufficient to show that you have complied with the Act and the Regulations. Those records must be kept for at least twelve months after creation and retained for at least twelve months after you last provided work-finding services to a work-seeker or hirer. They can be held off-site — but if a Fair Work Agency compliance inspector asks for them, they must be delivered to the relevant trading premises by the end of the second business day following the request.

Two business days. That is the standard. Not “we’ll pull it together next week.”

Alongside that sit the front-end documentary obligations: Key Information Documents, work-seeker agreements, terms addressing transfer fees, and the Regulation 13 duty to give job seekers the information they need about the work offered. These are among the most commonly cited areas of non-compliance found by inspectors — not because agencies dispute them, but because they are generated in the rush of getting someone into an assignment and then never checked again.

The sanctions are not nominal. Breach of the Conduct Regulations is a breach of the Employment Agencies Act 1973, which is a criminal offence, carrying fines in the magistrates’ court, unlimited fines in the Crown Court, and — in the most serious cases — prohibition orders barring individuals from running an employment agency for up to ten years.

The umbrella due diligence file

The joint and several liability rules do not tell you which umbrella to use. They tell you that you will pay for it if you choose badly. That converts supplier selection into an evidencing exercise on a rolling cycle: current PAYE and NIC evidence for every provider on your PSL, payslip transparency checks showing gross pay, lawful deductions and net pay, National Minimum Wage compliance tested after deductions rather than at the headline rate, and a dated record of each check.

Four providers reviewed quarterly is sixteen evidence cycles a year, each with chasing, filing and follow-up attached. It is not intellectually demanding work. It is the kind of work that gets postponed until the week HMRC writes to you.

The right to work diary

Right to work compliance is unusually dangerous to run informally, because the statutory excuse depends on the correct prescribed check being completed before work began, by the party carrying the duty, with the evidence retained properly. There are three prescribed routes — manual document check, Home Office online check using a share code, and digital identity verification for British and Irish passport holders — and they are not interchangeable. Many civil penalties arise not because anyone ignored the rules but because the wrong method was applied to the person in front of them.

Time-limited permissions add a follow-up obligation that has to be diarised and actioned. This is calendar work: the sort of thing a dedicated person with a proper tracker never misses, and a consultant juggling twelve live roles misses roughly once a year — which is all it takes.

The Admin Arithmetic Nobody Budgets For

Now put a number on the hours.

A Totaljobs survey of 748 HR leaders, reported in August 2025, found recruiters spend an average of 17.7 hours of administrative work per vacancy — more than two full working days per hire, before anyone has had a meaningful conversation with a candidate. A 2024 SmartRecruiters survey of 533 talent professionals found 45% of talent acquisition leaders spend more than half their working hours on admin that could be automated. UK industry data from the same period puts the average at around 30% of the working week.

Interview coordination alone is a documented sink: roughly two-thirds of recruiters report that scheduling a single interview takes between thirty minutes and two hours, and around a third call it the most time-consuming part of the job.

Seventeen and a half hours of admin per vacancy. On a desk running eight live roles, that is close to four working weeks of administration sitting inside a single month’s workload.

Set that against the commercial reality of the sector in 2026. APSCo puts the UK recruitment industry at around £43 billion, with 2025 marking the first post-pandemic contraction. The REC recorded a 5.3% decline in real gross value added that year, forecasts 4.4% growth in 2026, and reported that 35% of member firms experienced bad debt against 29% across sectors generally. Vacancy demand has fallen for more than two consecutive years, though the rate of decline is easing. Temporary margins typically run at 15–30% of the charge rate before costs, and 8–15% net once employer National Insurance, pension contributions and holiday pay are accounted for.

And the sector is overwhelmingly small. Industry status reporting counted just over 30,000 recruitment agencies in the UK employing around 201,000 people, of which 79.5% are micro-businesses with fewer than ten employees. These are the firms now carrying joint and several liability for PAYE across their supply chain, an expanded right to work regime from October, a new consolidated enforcement body, and a two-business-day record production standard.

The REC’s own commentary for 2026 put the structural problem plainly: growing internal headcount the traditional way no longer stacks up financially for most agencies, particularly when competing against national firms able to absorb higher costs. Which leaves two options — absorb the work personally, or find capacity somewhere other than a UK payroll.

Candidate Data: The Second Regulator in the Room

While all of this was happening in employment law, data protection did not stand still.

Recruitment is a data-heavy business. A single placement generates a CV, interview notes, reference correspondence, right to work evidence, payroll details, and often health or criminal record information — some of it special category data, all of it belonging to someone with enforceable rights.

The ICO’s position on lawful basis is settled, and a surprising number of agencies still get it backwards. For the core activity of recruitment, legitimate interests is generally the appropriate basis rather than consent — consent is the wrong tool given the imbalance of power, and contract is inappropriate before an offer has been accepted. What legitimate interests requires in exchange is a documented assessment kept on file. Consent remains necessary for marketing and anything outside the recruitment purpose.

Subject access requests carry a one-month response deadline, and the clock starts when the request arrives, not when you work out where the data lives. The difficulty is rarely legal. It is that candidate data has scattered across an ATS, a CRM, a shared inbox, a scheduling tool and three consultants’ personal folders, and nobody has ever built a map. ICO enforcement here typically begins with one complaint from an individual whose deletion request was ignored — after which the regulator asks for evidence of your wider practices, and the conversation stops being about a single candidate.

Retention is the same story. UK GDPR names no specific period for candidate data, which is precisely why so many agencies hold records from 2018 with no activity since. A defined, automated retention rule — commonly two to three years for unplaced candidates — is straightforward to implement and almost never gets implemented, because it is a project rather than a task.

One further change matters if you use any offshore support. The Data (Use and Access) Act provisions on international transfers came into force on 5 February 2026, and the ICO updated its transfer guidance that January to match. A transfer risk assessment is now called a “data protection test” in UK legislation, and the standard it applies is whether protection in the destination country is not materially lower than the UK equivalent. Existing IDTAs and UK Addendums do not need rewriting because of the DUAA, provided they were already compliant — but the assessment behind them must reflect the new test. More on that below.

The Human in the Loop: Why Automation Alone Fails an Inspection

The obvious response to an administrative burden is to automate it, and a great deal of the recruitment technology sold in 2026 promises exactly that. Some of it is genuinely useful. But there is a specific reason why pure automation is a poor fit for the compliance side of a recruitment business, and it is not a philosophical objection — it is a regulatory one.

In November 2024 the ICO published the outcomes of consensual audits of AI-powered recruitment tools, conducted between August 2023 and May 2024 across sourcing, screening and selection products. The regulator issued 296 recommendations, all accepted or partially accepted by the organisations involved. The findings were not marginal. Some tools inferred characteristics such as gender and ethnicity from a candidate’s name rather than asking. Some features allowed recruiters to filter candidates by protected characteristics. Several providers collected far more data than the tool needed and retained it indefinitely, in some cases building large candidate databases without the knowledge of the people in them.

Among the ICO’s central recommendations: providers and users should conduct robust and meaningful human reviews and quality checks on AI outputs, rather than treating the output as finished.

That recommendation is reinforced by Article 22 of the UK GDPR, under which candidates have the right not to be subject to solely automated decision-making and profiling where it produces legal or similarly significant effects. Screening candidates through solely automated means requires an Article 22 exception plus safeguards — including the candidate’s right to obtain human intervention, express a point of view, and challenge the decision.

A compliance system with no human in it is not a compliance system. It is a liability generator running at speed.

The point generalises well beyond AI screening tools. Umbrella due diligence needs someone to read what came back and notice the certificate is eleven months old. A right to work check needs someone to look at the person’s actual status and select the correct prescribed route, not the default one. A subject access request needs someone to search the shared inbox the ATS integration does not touch. A Key Information Document needs someone to notice the pay rate in it no longer matches the assignment.

This is the case for a virtual assistant rather than a subscription. Software tells you a task is overdue. A person notices that the answer you received does not actually answer the question you asked — then chases it, logs the chase, and tells you on Thursday that the fourth umbrella still has not replied.

It is also the case for a dedicated assistant rather than a rotating pool. Compliance work is cumulative. Its value comes from someone knowing that this client always sends share codes late, that this consultant files reference notes in the wrong field, that last quarter’s audit flagged the same two gaps. That knowledge does not transfer between freelancers.

The South African Advantage

Which raises the obvious question of where that person should sit. For UK recruitment firms specifically, South Africa has become the strongest answer available, and the reasons are structural rather than promotional.

The working day is the same working day

South Africa runs on GMT+2. During British Summer Time that is one hour ahead of the UK; in winter, two. A South African assistant’s working day therefore sits almost entirely inside yours. They start before you and finish around the same time. No overnight handover, no waiting until tomorrow for an answer, no antisocial call times for either party.

For compliance work this is not a convenience — it is the whole thing. A two-business-day record production standard does not survive a twelve-hour delay in the middle. Neither does chasing an umbrella provider who answers the phone between ten and four, or resolving a right to work discrepancy before a Monday shift starts.

English that does not need translating

South African business English is a British English variant, not an American one learned as a second language. Spelling follows UK conventions. Date formats match. The idiom, the register, the sense of what “as soon as possible” means in a professional email — these align in a way that removes a whole category of friction from candidate and client correspondence.

VAConnect’s published client testimonials return to this point repeatedly. One UK marketing manager, quoted in a Clutch review, contrasted previous offshore arrangements involving constant scheduling gymnastics and cultural miscommunication with a South African assistant who simply understood the brief. A Birmingham founder in the same set of reviews said her South African team understood her communication style immediately, with no translation required — literal or cultural.

For a recruitment firm, where a badly worded rejection email or a tonally wrong client update does real commercial damage, that matters more than in most functions.

POPIA and GDPR: the dual-compliance posture

This is the part most UK agencies underestimate, and it is where South Africa separates from the rest of the offshore market.

South Africa has its own comprehensive data protection statute — the Protection of Personal Information Act, or POPIA — enforced by an independent Information Regulator. Its conditions for lawful processing are substantially similar in structure and intent to the GDPR: purpose limitation, minimality, security safeguards, data subject participation, and restrictions on further processing. Section 72 governs cross-border transfers, requiring that recipients outside South Africa be subject to law, binding corporate rules or a binding agreement providing adequate protection.

In one respect POPIA is stricter than either the EU or UK GDPR: it protects the personal information of juristic persons — companies and trusts — not only natural persons. That is an international outlier, and it means a South African provider operates under a broader definition of protected data than a UK-only operation does.

For the UK exporter, the mechanics are sharper since February 2026. South Africa does not benefit from UK adequacy regulations, so a restricted transfer needs an Article 46 safeguard — usually the ICO’s International Data Transfer Agreement or the UK Addendum — supported by a completed transfer risk assessment, now framed in legislation as a data protection test against the “not materially lower” standard.

POPIA is what makes that assessment straightforward rather than fraught. You are not arguing that contractual clauses alone can substitute for a legal framework. You are pointing to a statutory regime with an active regulator, substantially similar principles, and its own cross-border transfer rules.

A UK recruitment firm sending candidate data to South Africa is not exporting into a vacuum. It is exporting into a jurisdiction with its own data protection statute, its own regulator, and a legal test its own law already requires it to meet.

Scale, and what it says about quality

The South African global business services sector is no longer a niche. It created 26,346 new jobs servicing international markets in 2025 — its highest annual total since 2018 — with around 90% filled by young people, according to Business Process Enabling South Africa. Sector revenue grew from roughly USD 1.04 billion in 2019 to an estimated USD 2.91 billion in 2024, and the national masterplan targets 500,000 cumulative jobs by 2030.

The most telling figure for a British reader is the market split. Of the international markets serviced from South Africa, the United Kingdom accounts for the largest share by a wide margin — a proportion BPESA has put at around 62%, well ahead of the US, Australia and Europe. South African delivery teams are not primarily built for American clients and adapted for Britain. They were built for Britain.

Cost, without the usual trade-off

Offshore cost savings usually come with a quality discount, and buyers price that in. South Africa is the market where that trade has been least true. Published comparisons put fully loaded South African costs at roughly 50–60% below UK equivalents, with attrition running materially lower than the largest Asian delivery markets — which tends to close whatever per-head gap exists once full-cycle hiring and retraining costs are counted.

For a firm working on 8–15% net temp margins, freeing a consultant from seventeen hours of admin per vacancy at a fraction of a UK administrator’s cost is not a marginal efficiency. It is the difference between a desk that breaks even and one that bills.

Structuring the Engagement So It Survives Scrutiny

A virtual assistant improves your compliance position only if the engagement itself is set up properly. Six things to get right:

Put the data protection paperwork in place before day one. A written processor agreement under Article 28, an IDTA or UK Addendum covering the transfer, and a completed data protection test documenting your reasoning. A one-off exercise, and the single most common thing agencies skip.

Know what cannot be delegated. The statutory excuse for right to work is created by the party carrying the duty; you cannot outsource the excuse itself and rely on it. An assistant can gather share codes, diarise expiries, prepare files, chase candidates and flag discrepancies. The prescribed check and its retention sit with you. Build the workflow so the assistant does the ninety per cent that is preparation and your named responsible person does the ten per cent that is legally load-bearing.

Give them named, logged access — not shared credentials. Individual accounts in your ATS and CRM with role-appropriate permissions. Shared logins destroy the audit trail you are trying to build.

Define the evidence standard, not just the task. “Chase the umbrella providers” produces chasing. “Obtain current PAYE evidence from each PSL provider, save to the compliance folder with the date received, and report exceptions every Friday” produces a file you can hand an inspector.

Set a weekly exception report. The value of a dedicated assistant is not that everything gets done silently. It is that you find out on Friday morning which four things did not get done, while there is still time.

Use a managed provider rather than a marketplace hire. This work involves special category data, payroll information and candidate records. Vetting, background checks, contractual data protection obligations and continuity cover are not optional extras here. VAConnect has operated since 2008, runs its own vetting and skills-testing pipeline before any candidate reaches a shortlist, handles employment and compliance on its side, and replaces a placement at no additional cost if it is not performing.

What to Delegate First: A 90-Day Sequence

Days 1–30 — Build the map. Every system holding candidate data, who has access, how to export and delete from each. A retention audit. A compliance folder structure with a naming convention that survives an inspector’s request.

Days 31–60 — Take the calendar work. Umbrella evidence cycles. Right to work follow-ups for time-limited permissions. Key Information Document reviews against current assignment terms. Interview scheduling, where the largest single block of consultant time disappears.

Days 61–90 — Own the recurring processes. Subject access request intake and first-pass collation. Reference chasing. Weekly exception reporting. Candidate status emails — the ones that never get sent when everyone is busy, and that cost you candidates when they do not arrive.

By month three the objective is not that your assistant knows your business. It is that your compliance file could be produced within two business days by someone other than you, at any point, without a scramble.

The Competitive Gap

Something has quietly become true over the past eighteen months. Two agencies of identical size, in the same vertical, billing the same clients, are now operating on completely different economics — and the variable is not talent, market knowledge or client relationships. It is whether the administrative and compliance load sits on the people who are supposed to be billing.

In the first firm, the managing director is at her desk at nine-twenty on a Tuesday reconciling umbrella evidence. Her consultants are booking their own interviews at thirty to a hundred and twenty minutes a time. Nobody has run a retention audit since 2023. The subject access request is on day seventeen and untouched. The two roles that came in on Friday will be picked up on Thursday, by which point one will have gone to a competitor.

In the second, a dedicated assistant on GMT+2 has been working since seven-thirty. The umbrella evidence file is current because it is reviewed on a cycle. The right to work diary is a live document. Interviews are booked and reconfirmed. The subject access request was collated on day two. The Friday roles were being sourced by Monday lunchtime.

That gap will not narrow on its own. It compounds — because the second firm’s consultants are in front of clients, and the first firm’s are in front of spreadsheets. And in a year when liability moved up the supply chain, enforcement consolidated into a single agency, and the right to work regime widened to cover contingent labour, the cost of being the first firm has risen sharply.

The 2026 changes were not designed to punish small agencies. But they were written on the assumption that businesses handling other people’s employment, tax and personal data would have the capacity to evidence what they do. Most UK recruitment firms — 79.5% of them with fewer than ten staff — do not have that capacity sitting idle. They have to build it. The only real question is whether they build it on a UK payroll at UK cost, or somewhere the working day already overlaps, the English already matches, and the data protection regime already stands up to a transfer risk assessment.


Productivity Comparison: Three Approaches to Recruitment Compliance

DIY CoordinationGeneric FreelancersVAConnect
Who does the workConsultants and the MD, after hoursRotating pool, task-by-taskOne dedicated, vetted assistant
Working hours vs UKYours — evenings and weekendsVariable; often overnight offshoreGMT+2 — 1–2 hours ahead, near-total overlap
Umbrella due diligenceAd hoc, usually reactiveNot typically in scopeScheduled review cycle with dated evidence file
RTW diary & follow-upsManual reminders, easily missedFragmented across contributorsLive tracker, weekly exception report
Conduct Regs record trailScattered; 2-day production is a scrambleNo continuity of knowledgeStructured folder, inspection-ready
SAR handlingStarts late, often near deadlineRarely trusted with candidate dataDay-two collation, first-pass review
Data protection postureUK GDPR only, informally appliedUnknown jurisdiction; no processor termsPOPIA + UK GDPR, IDTA and data protection test in place
Vetting & background checksN/ABuyer’s responsibilityCompleted before shortlist
Continuity if absentWork stopsStart again with someone newManaged backup cover
Cost vs UK admin hireHighest — senior time on junior workLow headline, high management overheadRoughly 50–60% below UK fully loaded cost
Knowledge accumulationSits with the person who leavesNoneCompounds; 98% placement retention

Ready to take the compliance load off your consultants? VAConnect places dedicated, vetted South African virtual assistants with UK recruitment firms — timezone-aligned, British-English fluent, and operating under both POPIA and UK GDPR safeguards. See how we support regulated sectors on our Industries page, or book a 30-minute discovery call to talk through what your desk could hand over first.


Sources

Share
Ready when you are

Ready to stop managing
and start scaling?

Book a 30-minute discovery call. No pitch, no pressure — just a conversation about what you need off your plate.