BLOGRight to Work Compliance

Is Your Workforce Data Audit-Ready for 2026?

A year ago, we were discussing the future of Right to Work compliance in construction. In October 2026, those changes are becoming reality. At Digital Construction Week 2025, we explored the complexities of managing a transient workforce, the grey area surrounding Right to Work responsibilities, and the importance of establishing a digital thread of workforce information. Fast forward to today, and new Right to Work rules taking effect from 1 October 2026 will extend compliance obligations across a broader range of workforce arrangements, increasing the importance of knowing who is working on your sites and whether they're compliant to do so. We've been working closely with our customers to prepare them for exactly this shift, turning what was once a forward-looking conversation into practical readiness on live sites.
2026-08-25
13 min read

The question no one wants to answer under pressure

Ask any health and safety manager overseeing multiple construction sites a simple question, 'can you prove, right now, exactly who is on every one of your sites, that they are competent for the work they're doing, and that they have the legal right to work in the UK?', and you'll often see a pause. Not because the answer is unknown. But because the evidence to prove it lives in too many places at once.

Muster sheets in one system. Inductions in another. Competency records in a subcontractor's spreadsheet. Right to Work documents in an email chain somewhere. When everything is running smoothly, this patchwork holds together. The problem is that compliance is rarely tested when things are running smoothly. It's tested after an incident, during an audit, or when a regulator or insurer asks for proof, and that's exactly when fragmented data becomes a liability rather than an inconvenience.

This isn't a hypothetical concern. The UK's compliance landscape is tightening on several fronts at once, and the changes coming into force on 1 October 2026, which extend Right to Work check obligations to a wider range of working arrangements, including certain individual sub-contractor relationships, will place a sharper spotlight on whether contractors can consistently evidence who is legally permitted to work across their entire portfolio. For anyone managing a transient workforce across dispersed sites, that shift changes the stakes.

Let's be honest about what fragmented workforce data actually costs, not in the abstract, but in the escalating, practical ways it plays out on real projects.

The immediate cost: gaps you only discover when it's too late

The first and most visible cost is the audit that goes wrong.

Manual and semi-digital processes create predictable failure points. As one industry perspective puts it, records become "often outdated or missing, fragmented storage, weak evidence, no visibility and confusion across different emails." A lot of time is then spent chasing documents, confirming whether operatives were briefed, and "trying to prove what happened in the past without any real evidence."

That last phrase is the crux of the problem. Compliance isn't just about doing the right thing on site, it’s about being able to demonstrate you did the right thing, after the fact, to someone with the authority to penalise you if you can't.

When workforce data is scattered, the immediate costs stack up quickly:

  • Data gaps surface at the worst possible moment, during an audit, an insurance query, or a post-incident investigation, rather than in time to fix them.
  • Manual workarounds become the norm, with site teams reconstructing records under pressure instead of pulling them from a single source.
  • Right to Work status becomes a "grey area." Many main contractors historically left RTW checks to subcontractors, but they increasingly recognise that even where the legal responsibility sits elsewhere, they would still be impacted by the consequences of non-compliance.

And those consequences are not trivial. Under the Right to Work Scheme, employers can face civil penalties of up to £60,000 per worker for repeat breaches, alongside potential prison sentences where employers were aware that workers did not have the right to work in the UK, as well as risks to insurance validity and project delays if worker status has not been verified.

The operational cost: compliance rework quietly erodes productivity

The second cost is more insidious because it hides inside your day-to-day operations.

Every hour a site team spends chasing a missing induction record, verifying whether an operative's competency has expired, or manually reconciling attendance across systems is an hour not spent moving the project forward. In an industry already under pressure to do more with less, that drag is expensive, and it compounds across a portfolio.

The operational costs of fragmentation look like this:

  • Inefficient site management, because no one has a real-time, single view of who is on site, where, and whether they're compliant.
  • Lost productivity from compliance rework, as teams re-onboard the same rotating crews and re-verify the same records across multiple main-contractor systems.
  • Reliance on site teams to enforce process manually, which means consistency depends on individuals rather than systems, and standards inevitably drift between sites.

For a health and safety manager operating in a roaming role across multiple projects, this is the heart of the anxiety: you are accountable for consistent standards, but you're dependent on dispersed site teams to deploy them, and you have limited visibility of whether they actually are.

The financial and reputational cost: when the numbers and the name are on the line

The third tier is where operational drag becomes organisational risk.

Regulatory penalties are the obvious headline, but they're rarely the whole story. A single compliance failure can trigger a chain reaction: an invalidated insurance position, a client questioning your governance, a framework relationship put at risk. In a market where major UK contractors increasingly buy through preferred-supplier lists and multi-project frameworks, credibility on compliance isn't a nice-to-have, it’s a condition of staying on the list.

The financial and reputational costs include:

  • Direct regulatory exposure, including civil penalties of up to £60,000 per worker for repeat breaches and, in cases where employers were aware workers did not have the right to work in the UK, potential prison sentences.
  • Reputational damage that outlasts the incident itself, particularly damaging in an industry where reference-ability and peer reputation drive procurement.
  • Personal and organisational accountability. Under evolving building safety duties, named individuals increasingly carry responsibility for competence management and safe evacuation. "Compliance is part of brand protection" is not a slogan here, it’s a description of where the risk actually sits.

The uncomfortable truth is that these costs are asymmetric. The savings from a lightweight, manual process are small and immediate. The costs of that process failing are large, delayed, and land squarely on the people accountable for governance.

The strategic cost: what fragmentation stops you from becoming

The final cost is the one that's easiest to ignore because it never shows up on an invoice, the opportunities fragmentation quietly forecloses.

If you can't demonstrate consistent compliance across your current portfolio, scaling that portfolio only multiplies the risk. If your workforce data can't be trusted or compared across sites, you can't produce the portfolio-wide KPIs that clients, insurers and leadership increasingly expect. And if compliance is a firefight rather than a foundation, you're structurally disadvantaged against competitors who have turned governance into a repeatable capability.

Increasingly, that same workforce data is being asked to do more, evidencing local labour percentages, training hours and social value for public-sector and ESG-exposed clients under frameworks such as PPN 06/20 and CSRD reporting obligations. Data you can't consolidate is data you can't leverage.

What "readiness" actually looks like

The good news is that the technology has caught up with the problem, and fast. The shift that matters is moving workforce information out of disconnected folders and email threads and into a single, live operating picture where identity, competency, Right to Work status and site presence are linked to a verified individual.

For a health and safety manager evaluating what readiness looks like, the practical markers are these:

  • A single source of truth. One place where the records for who is on site, their competencies, and their compliance status live, not a patchwork across systems and subcontractors.
  • Right to Work verified digitally and enforced at the point of entry. Biosite has integrated government-certified ID checks via ppac into its workforce management systems, enabling real-time RTW verification, digital storage of RTW status, and, where access control is in place, integration with site entry so that unverified workers can be paused or prevented from gaining access. Verification isn't a one-off at induction; it supports ongoing confirmation in case a status expires or is revoked.
  • "One person, one profile." Biometric identification that de-duplicates worker profiles across sites, so a competency or a right-to-work status attaches to the individual and follows them consistently as they move between your projects.
  • Audit-ready records by default. Tamper-resistant, real-time data that provides the evidence trail, competency, induction, briefing and evacuation records, you can produce on demand, rather than reconstruct after the fact.
  • Consistency across dispersed sites. Standards applied by the system, not left to the variable enforcement of individual site teams.

None of this is about adding another layer of admin. It's about replacing the layers you already have, the spreadsheets, the email chains, the paper sign-offs, with something that produces the proof automatically.

The bottom line

Workforce visibility used to be framed as an operational efficiency, a way to cut queuing at the gate or tighten up time and attendance. That framing is now out of date. With Right to Work obligations expanding in October 2026 and building safety expectations sharpening, the ability to consistently evidence who is on your sites has become a compliance imperative.

The four costs of inaction, the failed audit, the productivity drain, the penalty and reputational hit, and the ceiling on growth, don’t arrive all at once. They escalate. And they escalate fastest for the organisations still relying on fragmented data when someone finally asks them to prove it.

The question isn't whether you'll be asked to demonstrate consistent compliance across your portfolio. It's whether your data will be ready when you are.