Orchestrate for Accountancy

ECCTA compliance, ACSP obligations and Failure to Prevent Fraud procedures. Your practice needs to evidence all three.

Orchestrate automates the client onboarding, AML screening and compliance workflows that ECCTA and ACSP requirements are making more demanding - including four pre-built Failure to Prevent Fraud workflows that constitute your evidenced reasonable procedures defence.

The regulatory pressure on UK accountancy practices has never been higher. And it’s still rising.

The Economic Crime and Corporate Transparency Act 2023 (ECCTA) is reshaping what it means to be a compliant accountancy practice. Identity verification for directors and PSCs is now mandatory. The Failure to Prevent Fraud offence has been in force since 1 September 2025 - carrying unlimited fines for large organisations that cannot evidence reasonable fraud prevention procedures. Furthermore, from November 2026, accountancy firms filing on behalf of clients must be registered as an Authorised Corporate Service Provider (ACSP) with Companies House.

ACSP registration demands systematic identity verification

From November 2026, accountancy practices filing on behalf of clients must be registered with Companies House as an Authorised Corporate Service Provider. Registration requires AML supervision and identity verification records retained for seven years. Manual ID verification processes are not scalable to this requirement.

Failure to Prevent Fraud requires evidenced procedures - not just policies

The Home Office is explicit: a high-level risk assessment and generic training may not be enough. The guidance warns that firms must demonstrate documented, consistently applied, auditable procedures - not just assert that procedures exist.

AML and KYC checks are inconsistent across the practice

When compliance depends on individual staff remembering to run the right checks, the results vary. In an FCA and HMRC-supervised environment, that inconsistency is not a minor operational issue - it is a regulatory risk.

Making Tax Digital is compressing available admin time

With MTD for income tax now applying to clients earning over £50,000 (from April 2026) and further thresholds planned for 2027 and 2028, practices face growing client data obligations at exactly the moment ECCTA and ACSP requirements are adding compliance burden.

Orchestrate for Accountancy: from new client enquiry through AML screening, ACSP-compliant identity verification and Failure to Prevent Fraud procedures: in one automated workflow.

Orchestrate replaces the manual steps in your onboarding and compliance process with a single automated workflow - from initial enquiry through AML and KYC screening, Companies House identity verification, engagement letter generation and ACSP record-keeping - running consistently and completely, every time.

API connections run AML, fraud, PEP and sanctions checks simultaneously when a new client is opened. Results are stored automatically, creating the complete audit trail that satisfies both ACSP identity verification record-keeping requirements and the ‘reasonable procedures’ standard for Failure to Prevent Fraud compliance.

A policy document is not enough. ECCTA requires evidenced procedures.

The Home Office guidance on the Failure to Prevent Fraud offence is clear: “a high-level risk assessment, a policy statement and generic training may not be enough to discharge the reasonable procedures defence.” The onus is on your organisation to prove - on the balance of probabilities - that documented, consistently applied, auditable procedures were in place at the time of any alleged fraud.

For accountancy practices in scope of ECCTA - meeting two of: 250+ employees, £36m+ turnover, £18m+ in assets - Orchestrate’s four compliance workflows directly evidence the six pillars of the Home Office’s reasonable procedures framework. For smaller practices below the threshold, implementing these workflows demonstrates a standard of compliance that goes well beyond what regulators, professional indemnity insurers and ACSP supervisors expect.

Orchestrate includes four pre-built workflows that map directly onto the six pillars of the Home Office’s reasonable procedures framework:

Fraud Risk Assessment Manager

Structured, documented assessment of fraud risk exposure across the organisation - identifying threats, likelihood, impact and existing controls. Updated on a defined cycle.

Third-Party Fraud Risk Assessment

Systematic due diligence workflow for associated persons - employees, agents, subcontractors and third-party service providers - screening for fraud risk before and during engagement.

Annual Fraud Governance Review

Structured annual review workflow for senior leadership and the board - evidencing top-level commitment, reviewing the effectiveness of fraud prevention procedures, and documenting decisions.

Whistleblowing Form

Secure, confidential reporting workflow for employees and associated persons to report suspected fraud - with automated routing, case tracking and evidenced response.

Each workflow produces a complete, timestamped, auditable record. The Fraud Risk Assessment Manager and Annual Governance Review are configured to your organisation’s specific risk profile. The Third-Party Fraud Risk Assessment runs as part of your standard onboarding and supplier engagement process. The Whistleblowing Form creates a secure, evidenced channel for internal reporting - with automated case routing and a full audit trail.

Taken together, these four workflows constitute the documented, auditable ‘reasonable procedures’ that the ECCTA guidance requires you to evidence - not just assert.

Accountancy sector note: As an ACSP, your practice must not only verify client identity but demonstrate systematic, auditable procedures for doing so. The Fraud Risk Assessment Manager and Third-Party Fraud Risk Assessment workflows are designed to cover the client relationships and referral networks that create fraud risk exposure for accountancy practices. The Annual Governance Review creates the senior-level documented commitment that both ECCTA and ACSP supervision require.

Be among the first UK accountancy practices with a fully automated, ACSP-compliant onboarding and Failure to Prevent Fraud operation.

Orchestrate is already delivering automated compliance and onboarding workflows for UK professional services firms. We are now working with a select group of forward-thinking accountancy practices - including firms actively preparing for ACSP registration and Failure to Prevent Fraud obligations - to implement Orchestrate and establish what best-in-class looks like in this sector.

If your practice is ready to build the compliance infrastructure that ECCTA demands - we’d love to talk.

What it looks like in practice.

Frequently asked questions

What software automates client onboarding for UK accountancy firms?

Meritec Orchestrate automates the full client onboarding journey for UK accountancy practices, including AML and KYC screening, ACSP-compliant identity verification, engagement letter generation and compliance sign-off workflows. It integrates with Xero, Sage and existing practice management systems. Onboarding time is typically reduced from days to under an hour for straightforward engagements.

Orchestrate includes four pre-built compliance workflows that map onto the six pillars of the Home Office’s reasonable procedures guidance: Fraud Risk Assessment Manager (risk assessment + proportionate procedures), Third-Party Fraud Risk Assessment (due diligence), Annual Fraud Governance Review (top-level commitment + monitoring) and Whistleblowing Form (communication + monitoring). Each produces a complete, timestamped, auditable record.

From November 2026, accountancy firms filing on behalf of clients must be registered as an Authorised Corporate Service Provider (ACSP) with Companies House, and must retain identity verification records for seven years. Orchestrate automates the identity verification workflow and stores all records with timestamps in a compliant, auditable format - making seven-year retention straightforward and ACSP supervision defensible.

Orchestrate can be configured to automate client data collection, review routing and submission tracking for MTD for income tax. The platform adapts as MTD thresholds change - currently £50,000 from April 2026, with £30,000 and £20,000 thresholds planned for 2027 and 2028.

Karbon, IRIS and similar tools are primarily practice management platforms focused on task management, billing and deadline tracking. Orchestrate focuses on compliance workflow automation - specifically the ACSP, ECCTA, AML, Failure to Prevent Fraud and onboarding processes that generic practice management tools do not automate. The two can work alongside each other via API integration.

Straightforward onboarding and AML workflow implementations are typically delivered in six to ten weeks. ACSP-compliant identity verification records and the four Failure to Prevent Fraud workflows can be added incrementally. Meritec conducts a discovery session before project start with no obligation to proceed.

ISO 27001:2022 certified

Independently audited information security management - the standard regulated firms require from technology partners.

In business since 1996

30 years delivering technology solutions to UK organisations. A proven long-term partner, not a start-up.

UK-based platform and team

Developed, hosted and supported entirely in the UK. Your client data does not leave UK jurisdiction.

Proprietary platform — no third-party dependency

Meritec owns its platform IP. Your workflows aren’t subject to a third-party vendor’s roadmap changes or pricing decisions.

It’s time to make your work flow.

Tell us how your practice currently handles onboarding, ACSP verification and Failure to Prevent Fraud compliance. We’ll show you how Orchestrate automates all three - and builds the evidenced audit trail that constitutes your reasonable procedures defence.