01 / Why you are getting these
You did not do anything wrong
Since 1 September 2025, large UK firms can be criminally liable if someone acting for them commits fraud, unless they had reasonable procedures in place. To prove they do, they check their suppliers. That check arrives as a due-diligence questionnaire, and every large customer words theirs differently.
You are simply in a big customer's supply chain. You are being asked to evidence that you take fraud prevention seriously, against the six principles the Home Office set out. Answer them well and you protect the contract. Answer them badly, or late, and you put it at risk.
02 / What they are actually asking
Every question maps to six principles
However a questionnaire is worded, each question traces back to one of the six Home Office principles for reasonable fraud-prevention procedures. Once you see the structure, the questionnaire stops being a wall of text.
-
01
Top-level commitment
Leadership owns fraud risk and fosters a culture where fraud is never acceptable, with a board-level owner and a signed-off anti-fraud policy.
-
02
Risk assessment
The organisation assesses the nature and extent of its exposure to the risk of fraud being committed by associated persons, and keeps it current.
-
03
Proportionate risk-based procedures
Prevention procedures are proportionate to the fraud risk and to the nature, scale and complexity of the organisation. Covers payment controls, segregation of duties and a speak-up route.
-
04
Due diligence
Risk-based due diligence is applied to employees, agents, subcontractors and other associated persons, with red flags documented and acted on.
-
05
Communication (including training)
Fraud prevention policies and procedures are communicated, embedded and understood across the organisation, including through training.
-
06
Monitoring and review
Procedures are monitored, reviewed and improved over time, with incidents logged and corrective actions evidenced.
03 / How to answer once and reuse
Answer once. Then never from scratch again.
The mistake is treating each questionnaire as a fresh writing job. Do the work once, as a maintained profile, and every future questionnaire becomes a matter of matching and tailoring.
Build one control profile
Write one clear statement, with evidence, for each of the six principles. This is the asset you reuse on every questionnaire, not throwaway text for one customer.
Map each incoming question to a principle
Go through the questionnaire and tag every question to the principle it belongs to. Duplicates and re-wordings collapse into the same answer.
Answer from the profile, honestly
Pull the evidenced answer from your profile. Where you cannot yet evidence a claim, record it as a gap with an owner and a date rather than overstating.
Export a clean pack and keep the trail
Send a consistent, branded response, and keep a record of how each answer was produced. If a customer or regulator asks, you can show your working.
04 / Common mistakes
What loses you the contract
Answering every questionnaire from scratch
Slow, inconsistent, and each version drifts from the last. Maintain one profile and reuse it.
Claiming procedures you cannot evidence
A confident answer you cannot back up is worse than an honest gap with a plan. Evidence is the point.
Leaving no audit trail
If you cannot show how an answer was reached, it is hard to stand behind it later. Keep the record.
Treating it as a one-off
The same customers ask again at renewal, and new customers ask for the first time. Stay ready, not reactive.
05 / Common questions
Questions
- Do I have to answer an anti-fraud questionnaire?
- There is no law forcing you to complete a customer's questionnaire, but the customer can make a satisfactory response a condition of winning or keeping the contract. Since the failure-to-prevent-fraud offence went live, large firms have to evidence due diligence on their supply chain, so a complete, well-evidenced answer is increasingly the price of staying on the approved supplier list.
- What is the ECCTA 2023 failure to prevent fraud offence?
- The Economic Crime and Corporate Transparency Act 2023 makes large organisations criminally liable when someone acting for them commits fraud for their benefit, unless they had reasonable fraud-prevention procedures in place. It came into force on 1 September 2025. Large firms pass that expectation down their supply chain as due-diligence questionnaires.
- What if I do not have all the evidence yet?
- That is normal, and it is better to know before your customer does. Map each question to the six principles, answer what you can evidence honestly, and record the gaps as actions with owners and dates. A credible plan to close a gap reads far better than a claim you cannot back up.
- Can I reuse my answers for the next customer?
- Yes, and that is the point. Every questionnaire maps back to the same six Home Office principles, just worded differently. Maintain one control profile and you answer once, then reuse and tailor it for every customer that asks. That is what Attestamo does.
Answer your next questionnaire once
Attestamo maintains your control profile across the six principles, drafts an evidenced answer to each question a customer sends, and flags the gaps. Answer once, respond to all.
Attestamo drafts evidence of reasonable procedures and keeps an audit trail. It is not legal advice.