Let’s be honest – things are brutal for agencies right now. Margins are tight, audits are tougher, and one mistake could lose you your frameworks. That’s why this matters.
Over the past few months, we’ve spoken with several agencies that had a gut feeling something wasn’t right with their new compliance provider. So they did the smart thing – they booked independent audits to check if corners were being cut.
What came back was horrifying – and every single one of them had been using the same provider.
🔴 “Interviews” done via static self-submitted forms – no questions, no human, no proper assessment.
🔴 Fitness to Work (FTW) certificates signed by someone not legally permitted to do it – this is where many agencies are being misled.
Certain Practitioners may have clinical skills and training, SEQOHS sets strict requirements about who can deliver and sign off on occupational health assessments. It’s not just about being a registered health professional – it’s about specific competence in occupational health, immunisation interpretation, and risk-based clearance.
SEQOHS standards require:
1.1: “All health professionals delivering clinical services are registered/licensed with the relevant regulatory body.”
2.1: “All clinical staff employed by the service, and contractors engaged, have the knowledge, skills, experience and relevant qualifications for the work they undertake.”
2.6: “Staff and contractors who advise on and/or deliver immunisations, or otherwise engage in medicines management, are clinically competent and practise in accordance with national standards and guidelines.”
To be compliant, Fitness to Work clearance must be signed off by a qualified occupational health nurse or doctor (with NMC or GMC registration and OH training). Even if a registered practitioner is not registered with the NMC or GMC, and has general healthcare expertise, they aren’t recognised as competent under SEQOHS for OH risk assessment; meaning the certificate is invalid and will result in an immediate core fail during any SEQOHS or framework audit.
🔴 EPP certificates missing IVS details – certificates don’t even mark IVS next to the relevant sections, leaving no confirmation of proper Exposure-Prone Procedure (EPP) clearance.
🔴 AI-driven clearance – Allegations have surfaced that AI is being utilised to renew FTW’s services.
🔴 Automation over accountability – FTW renewals are being issued by scripts within seconds, with no review of original declarations or health records.
Technical audits and whistleblower evidence show the provider’s platform is dangerously insecure:
No enforced HTTPS redirect – leaving data vulnerable to interception.
Missing security headers (HSTS, CSP, HttpOnly cookies).
Open ports (22, 80, 3000) exposing admin-level services.
No reliable audit logs – certificate dates and details can be altered without a trace.
Privacy policy contradictions – they claim:
“We store your personal data on our servers in the UK. We will only transfer information outside of the UK or EEA where we have a valid legal mechanism in place.”
Yet independent testing shows data is actually stored in Germany, breaching trust and potentially the law.
Several whistleblowers – including staff from agencies who’ve used this provider – have come forward with alarming evidence.
One insider told us:
“I don’t think they realise they’re trying to do me out of my own job – but doing it badly by cutting massive corners. Yes, automation is great to a point, but sometimes things need a human touch. If it weren’t for humans, no one would catch on to just how bad this is!”
We’ve received evidence of:
FTW certificates are being renewed without a seemingly thorough medical review.
Sensitive health records are being stored on insecure systems.
This evidence is now being shared with auditors, key stakeholders, regulators, and governing bodies.
If you have used or are working with this provider, please review your certificates. Ensure that someone has signed them off who is registered with the GMC or NMC and holds the proper occupational health qualifications or training. If not, ask for a full refund.
Even if you don’t use us, there are plenty of reputable businesses out there who do things right – companies that value governance, accuracy, and compliance above shortcuts.
All this automation could render compliance managers’ jobs obsolete. Automation has its place – it can speed up admin and routine checks – but these are critical verifications that need a human touch, not a botched script. Verifying blood test results and titres, confirming IVS for EPP clearance, reviewing health declarations for safeguarding issues, checking the authenticity of documents, ensuring Fitness to Work sign-off is done by the right qualified professional, and verifying qualifications and registrations are all tasks that require trained eyes and judgement. When these checks are left to automation, they’re wide open to abuse – fake documents slip through, risks go unnoticed, and there’s zero accountability. Don’t be replaced by a computer that can’t do the job correctly. Don’t let the wool be pulled over your eyes.
💬 Ask yourself:
Would your agency survive if this came out in your next framework audit?
Would you trust certificates that don’t even show IVS for EPP clearance?
If you don’t, it will be too late the next time you are audited.
❌ Don’t risk your place on the framework.
❌ Don’t risk your candidates.
❌ And definitely don’t risk your own job in compliance.
✅ At HB Compliance, we don’t cut corners:
✔️ Face-to-face interviews
✔️ Nurse-led decisions
✔️ Verified documents
✔️ Independent from recruitment
✔️ Proper governance and accountability
✔️ We comply fully with SEQOHS standards – using qualified, trained occupational health professionals and nurses to support agencies.
You can trust us. And you’ll never have to wonder how it was done, as we will show you the evidence!
This isn’t just a warning – it’s your heads-up, before it’s too late.