What does a non-compliant Statement of Work actually look like?

Oct 4, 2026 · 8 min read
J
Joe Johnson

A non-compliant Statement of Work rarely announces itself. It doesn't usually fail on one dramatic clause, it fails quietly, across a small number of gaps that sit in six areas: worker classification, right to work, modern slavery, data protection and cyber security, insurance and liability, and commercial and financial risk. Any one gap on its own is common and often unremarkable. Several in the same document, and in the same supplier relationship, is the pattern that actually signals risk. Most reviews check price and scope. Few check all six.

Ask most Procurement or Finance teams what a non-compliant Statement of Work looks like, and the answer is usually a shrug, or a guess about missing signatures. In practice, non-compliance is rarely that visible. It shows up as an absence: a check that was never done, a clause that was never added, a supplier chain that was never mapped past the first tier. This guide sets out the six risk areas a Statement of Work actually needs checking against, what non-compliance looks like in each, and which ones get missed most often.

What does a non-compliant Statement of Work actually look like?

It looks ordinary. Most non-compliant Statements of Work aren't obviously bad documents, they're documents where one or two specific checks were never done, in one or two specific areas. The risk isn't a single red flag, it's an accumulation across six areas that most reviews never look at together: worker classification, right to work, modern slavery, data protection and cyber security, insurance and liability, and commercial and financial risk.

What are the six risk areas in a Statement of Work?

  1. Worker classification. Whether the arrangement is a genuine service or disguised labour supply, the IR35 test covered in our guide to genuine contracted-out services versus disguised labour supply.
  2. Right to work. Whether everyone actually delivering the engagement, including anyone supplied through a sub-contractor, has an evidenced right to work in the UK.
  3. Modern slavery and labour exploitation. Whether the supply chain behind the Statement of Work has been checked past the named supplier, not just at group level.
  4. Data protection and cyber security. Whether system or data access granted under the Statement of Work is matched by a security schedule and a data processing agreement.
  5. Insurance and liability. Whether the supplier holds evidenced, current cover appropriate to the engagement, and whether liability caps actually match the risk.
  6. Commercial and financial risk. Whether the pricing structure, payment terms and the supplier's financial standing hold up for the scale of the engagement.

What does worker classification risk actually look like?

It looks like a Statement of Work that reads as a job description with a supplier's letterhead on it: named individuals, hours logged, day rates, and no accountability for a defined outcome. Time-and-materials pricing tied to named people, covered in our procurement due-diligence checklist, is one of the clearest tells.

What does right-to-work risk actually look like?

It looks like a flow-down clause that exists on paper but was never evidenced: your Statement of Work says the supplier is responsible for right-to-work checks, but nobody has ever asked to see them. It's most likely to be missed where work is delivered through a sub-contractor rather than the named supplier directly, since that's the population most reviews never look past. GOV.UK's own employer's guide to right-to-work checks sets out what evidence should actually exist.

What does modern slavery risk actually look like?

It looks like a supply chain nobody's mapped past the first name on the contract. A modern slavery statement published at group level says little about whether any individual Statement of Work has actually been checked, particularly where a supplier sub-contracts again, and that second or third tier is where visibility usually stops. The Home Office's guidance for businesses on slavery and human trafficking in supply chains sets the expectation that this checking should reach the actual supply chain, not just the named counterparty.

What does data protection and cyber security risk actually look like?

It looks like a Statement of Work that grants system or data access without a matching security schedule, without a data processing agreement referenced anywhere, and without a named contact accountable for it. Access is often the easiest thing to grant and the hardest thing to later prove was controlled.

What does insurance and liability risk actually look like?

It looks like cover that's assumed rather than evidenced: no certificate on file, cover that's expired, or a liability cap that was copied from a template and never checked against what the engagement could actually go wrong.

What does commercial and financial risk actually look like?

It looks like pricing that doesn't match the classification test, payment terms that create dependency on one supplier, or an engagement of real scale with no visibility into whether the supplier is financially able to deliver it.

Which risk area do finance and procurement teams miss most often?

Worker classification and modern slavery tend to be the two areas most likely to slip through, and for the same structural reason: both require looking past the named supplier to who is actually doing the work, not just at the Statement of Work itself. Right to work, insurance and data protection are usually checked, if inconsistently, because they're easier to ask for evidence of in one place. Classification and supply-chain risk require someone to actually trace the engagement to the people delivering it.

Why do these risks cluster in the same documents?

Because they share a root cause: vague scope. A Statement of Work that describes activities instead of outcomes is also the one most likely to name individuals instead of deliverables, skip the sub-contracting question, and leave insurance and data protection unaddressed, because nobody treated it as a service to be delivered in the first place. Fix the scope question and several of the other five often improve alongside it.

How should you check a Statement of Work against these six areas?

Read every Statement of Work against all six, not the one or two your team happens to specialise in. Procurement usually owns commercial risk, HR or contingent workforce owns classification and right to work, and Legal or Information Security own data protection, which is exactly why the gaps appear between teams rather than inside any one team's remit. A single register that scores every Statement of Work against all six, reviewed by whoever actually owns each area, closes that gap.

How CoComply can help

Checking six risk areas across a handful of documents is manageable with the right checklist. Checking them consistently across a few hundred Statements of Work, across every supplier tier, is not, which is why most reviews only ever check the two or three that are easiest to ask about. CoComply's AI reads every Statement of Work and MSA you hold and scores each one across all six risk areas, so nothing gets missed because it fell between two teams' remits. You can request your free analysis of your first five documents to see how your own Statements of Work score.

Frequently asked questions

What does a non-compliant Statement of Work actually look like?

It rarely looks obviously wrong. It looks like an accumulation of small gaps across six areas: worker classification, right to work, modern slavery, data protection and cyber security, insurance and liability, and commercial and financial risk.

What are the six risk areas a Statement of Work should be checked against?

Worker classification, right to work, modern slavery and labour exploitation, data protection and cyber security, insurance and liability, and commercial and financial risk.

Which risk area do procurement and finance teams miss most often?

Worker classification and modern slavery are the two most likely to be missed, since both require tracing the engagement past the named supplier to who is actually delivering the work.

What happens if these risks go unchecked?

Exposure depends on the area: worker classification risk can trigger retrospective IR35 liability, right-to-work and modern slavery gaps carry civil and reputational exposure, and unmanaged data protection, insurance or commercial risk surfaces later, usually when something has already gone wrong.

Is a legal review of a Statement of Work enough to catch these risks?

Not on its own. A legal review typically checks enforceability and drafting. These six risks are largely about visibility, whether the underlying facts (who's really doing the work, whether checks were actually done) match what the document says, which a document-only review can miss.

Share