Skip to content

01 / Why you are getting these

You did not do anything wrong

Since 1 September 2025, large UK firms can be criminally liable if someone acting for them commits fraud, unless they had reasonable procedures in place. To prove they do, they check their suppliers. That check arrives as a due-diligence questionnaire, and every large customer words theirs differently.

You are simply in a big customer's supply chain. You are being asked to evidence that you take fraud prevention seriously, against the six principles the Home Office set out. Answer them well and you protect the contract. Answer them badly, or late, and you put it at risk.

02 / What they are actually asking

Every question maps to six principles

However a questionnaire is worded, each question traces back to one of the six Home Office principles for reasonable fraud-prevention procedures. Once you see the structure, the questionnaire stops being a wall of text.

  1. 01

    Top-level commitment

    Leadership owns fraud risk and fosters a culture where fraud is never acceptable, with a board-level owner and a signed-off anti-fraud policy.

  2. 02

    Risk assessment

    The organisation assesses the nature and extent of its exposure to the risk of fraud being committed by associated persons, and keeps it current.

  3. 03

    Proportionate risk-based procedures

    Prevention procedures are proportionate to the fraud risk and to the nature, scale and complexity of the organisation. Covers payment controls, segregation of duties and a speak-up route.

  4. 04

    Due diligence

    Risk-based due diligence is applied to employees, agents, subcontractors and other associated persons, with red flags documented and acted on.

  5. 05

    Communication (including training)

    Fraud prevention policies and procedures are communicated, embedded and understood across the organisation, including through training.

  6. 06

    Monitoring and review

    Procedures are monitored, reviewed and improved over time, with incidents logged and corrective actions evidenced.

03 / How to answer once and reuse

Answer once. Then never from scratch again.

The mistake is treating each questionnaire as a fresh writing job. Do the work once, as a maintained profile, and every future questionnaire becomes a matter of matching and tailoring.

01

Build one control profile

Write one clear statement, with evidence, for each of the six principles. This is the asset you reuse on every questionnaire, not throwaway text for one customer.

02

Map each incoming question to a principle

Go through the questionnaire and tag every question to the principle it belongs to. Duplicates and re-wordings collapse into the same answer.

03

Answer from the profile, honestly

Pull the evidenced answer from your profile. Where you cannot yet evidence a claim, record it as a gap with an owner and a date rather than overstating.

04

Export a clean pack and keep the trail

Send a consistent, branded response, and keep a record of how each answer was produced. If a customer or regulator asks, you can show your working.

04 / Common mistakes

What loses you the contract

Answering every questionnaire from scratch

Slow, inconsistent, and each version drifts from the last. Maintain one profile and reuse it.

Claiming procedures you cannot evidence

A confident answer you cannot back up is worse than an honest gap with a plan. Evidence is the point.

Leaving no audit trail

If you cannot show how an answer was reached, it is hard to stand behind it later. Keep the record.

Treating it as a one-off

The same customers ask again at renewal, and new customers ask for the first time. Stay ready, not reactive.

05 / Common questions

Questions

Do I have to answer an anti-fraud questionnaire?
There is no law forcing you to complete a customer's questionnaire, but the customer can make a satisfactory response a condition of winning or keeping the contract. Since the failure-to-prevent-fraud offence went live, large firms have to evidence due diligence on their supply chain, so a complete, well-evidenced answer is increasingly the price of staying on the approved supplier list.
What is the ECCTA 2023 failure to prevent fraud offence?
The Economic Crime and Corporate Transparency Act 2023 makes large organisations criminally liable when someone acting for them commits fraud for their benefit, unless they had reasonable fraud-prevention procedures in place. It came into force on 1 September 2025. Large firms pass that expectation down their supply chain as due-diligence questionnaires.
What if I do not have all the evidence yet?
That is normal, and it is better to know before your customer does. Map each question to the six principles, answer what you can evidence honestly, and record the gaps as actions with owners and dates. A credible plan to close a gap reads far better than a claim you cannot back up.
Can I reuse my answers for the next customer?
Yes, and that is the point. Every questionnaire maps back to the same six Home Office principles, just worded differently. Maintain one control profile and you answer once, then reuse and tailor it for every customer that asks. That is what Attestamo does.

Answer your next questionnaire once

Attestamo maintains your control profile across the six principles, drafts an evidenced answer to each question a customer sends, and flags the gaps. Answer once, respond to all.

Attestamo drafts evidence of reasonable procedures and keeps an audit trail. It is not legal advice.