Compliance checklists for credit management: what your business needs to cover

12 min read time

A compliance checklist for credit management should cover UK late payment law, the rules on reporting payment practices, how GDPR applies to the customer data you hold, fair contract terms and the legal limits on debt collection. This guide sets out exactly what belongs on that checklist, the regulation behind each item, and how to build compliance into the credit control process you already run, rather than treating it as a separate job. This is general guidance rather than legal advice. If you are unsure how a specific rule applies to your business, it is worth checking gov.uk or speaking to a solicitor before you act on it.

What compliance means for credit management

Compliance in credit management means following the specific laws and codes that govern how you extend credit, invoice customers, chase late payment and handle the personal data involved along the way. It sits alongside your normal credit control process, the credit checks, credit limits and payment reminders you already run, rather than replacing it. Where credit control is about getting paid on time, compliance is about doing it within the rules. A business can have an efficient credit control process and still fall short on compliance, for example by chasing debtors in a way that breaches harassment rules, or by holding onto customer data for longer than GDPR allows.

The credit management compliance checklist at a glance

Before going through each area in detail, here is the full checklist in one place.

  • Charge statutory interest and compensation correctly on late business to business payments

  • Check whether the duty to report on payment practices applies to your business

  • Decide whether to sign up to the Fair Payment Code

  • Register with the ICO and have a lawful basis for the personal data you hold on customers

  • Put payment terms and credit limits in writing before you extend credit

  • Keep debt collection communications within the Protection from Harassment Act and Administration of Justice Act

  • Retain financial and credit records for the periods HMRC and Companies House require

  • Review credit limits against up to date risk data, not a one off decision made at onboarding

The rest of this guide walks through each of these in more detail.

Late payment law: interest, compensation and payment terms

The Late Payment of Commercial Debts Regulations 2013 give every business the automatic right to charge statutory interest on overdue business to business invoices, whether or not your contract mentions it. The regulations apply across England, Wales and Northern Ireland, and separately in Scotland, and cover commercial debts only, not money owed by or to consumers. Statutory interest is charged at 8% above the Bank of England base rate, which stood at 3.75% as of the July 2026 rate decision, putting the statutory rate at 11.75%. On top of interest, you're also entitled to fixed compensation for the cost of chasing the debt, calculated per invoice rather than per customer.

Invoice amount

Fixed compensation you can charge

Up to £999.99

£40

£1,000 to £9,999.99

£70

£10,000 or more

£100

If your actual recovery costs are higher than the fixed amount, you can claim the difference as well. Building this into your standard terms means customers know the cost of paying late upfront, and you have a consistent, compliant basis for chasing every overdue invoice rather than deciding case by case.

Does the duty to report on payment practices apply to you

The duty to report on payment practices applies if your business meets two or more of three criteria on both of its last two balance sheet dates: annual turnover over £36 million, a balance sheet total over £18 million, or more than 250 employees. If that's your business, you're required to publish a report on your payment practices twice a year, within 30 days of each six month period. Since the rules were updated for financial years beginning on or after 1 January 2025, reports must also include the total value of payments not made within agreed terms and the percentage of invoices unpaid due to a dispute, not just average payment times. The requirement runs until 6 April 2031. Failing to report, or publishing a report that misrepresents your payment practices, is a criminal offence for the company and its directors.

Most small and medium businesses fall outside this duty, but it's worth checking your figures against the thresholds each year, particularly if you're growing quickly or have recently taken on new investment.

Should you sign up to the fair payment code

The Fair Payment Code is voluntary, but signing up gives suppliers a public signal that you pay on time and can be a requirement for tendering on public sector contracts. It replaced the Prompt Payment Code in late 2024 and is administered by the Small Business Commissioner, free to join, with awards lasting two years before businesses need to reapply. There are three tiers, based on the percentage of invoices you pay within agreed timeframes.

Award

Requirement

Gold

At least 95% of all invoices paid within 30 days

Silver

At least 95% of all invoices paid within 60 days, including 95% to small businesses within 30 days

Bronze

At least 95% of all invoices paid within 60 days

Signing up isn't a legal requirement, but it's worth weighing up if your business relies on public sector contracts or a supply chain of smaller businesses who value being paid reliably.

Does running credit checks create a GDPR compliance issue

Running a credit check on a business customer does not create a GDPR compliance issue for you, because the information involved, company filings, credit history and any registered CCJs, is public information held and processed by the credit reference agency, not personal data your business is collecting or storing itself. Checking a company before you extend credit is standard credit control practice, not a compliance risk, and it's worth doing for every new customer regardless of how well you know them or how big the order is.

Where GDPR does apply is the customer data you hold and use day to day, contact details, invoices and correspondence about payment, rather than the credit check itself. Here what's needed is a clear lawful basis for holding it, usually legitimate interests, a privacy notice explaining what you do with customer data, and not keeping it for longer than necessary. This is more likely to come into play if you extend credit to sole traders or individuals rather than only limited companies, since you're then dealing with someone's own name and address rather than only company information.

Running a company credit check through a platform built for this purpose keeps this simple: you get the risk data you need, backed by the credit reference agency's own compliant handling of it, without taking on any extra compliance obligation for accessing it.

Setting credit terms and contracts that hold up

Every customer you extend credit to should have written payment terms agreed before the first invoice goes out, covering the credit period, the credit limit and what happens if payment is late. Verbal agreements or assumed terms are the most common reason credit disputes turn into drawn out, costly disagreements. Credit limits should be set from actual risk data rather than gut feel or the size of the order. Our credit control guide covers how to build this process from scratch, including how to set limits that reflect a customer's real ability to pay rather than how long you've worked with them.

One area worth particular care is if you extend credit to sole traders or small partnerships rather than only limited companies. Some agreements with individuals or partnerships of three or fewer partners can fall under separate consumer credit regulation, so it's worth checking with a solicitor if a meaningful share of your customer base falls into this category.

Debt collection: staying within the law when you chase payment

Chasing overdue payment is legal and expected, but the Protection from Harassment Act 1997 and section 40 of the Administration of Justice Act 1970 set limits on how you can do it. You can't contact a customer with a frequency or tone designed to intimidate, misrepresent the legal consequences of non payment, or imply enforcement action you haven't actually taken. Escalation should follow a clear, proportionate path: reminders before and after the due date, a formal notice referencing your statutory right to interest and compensation, and only then a statutory demand or a County Court Judgment if the debt remains unpaid. Keeping this escalation consistent across every customer is both good practice and a protection for your business if a dispute is ever challenged.

Record keeping businesses often overlook

Financial records, including invoices, credit notes and correspondence about payment, generally need to be kept for six years to satisfy HMRC and Companies Act requirements. Where those records contain personal data, GDPR still requires you to only keep what you need for that purpose, so it's worth separating the financial record you're required to retain from any wider customer data you could delete sooner.

A clear audit trail also matters if a customer later becomes insolvent. Records showing when credit was extended, what checks were run and how the account was managed can matter if a liquidator or administrator later scrutinises the debt.

Compliance checklist by business size

What applies to you depends largely on your size and who you extend credit to.

Requirement

All businesses extending business credit

Large companies and LLPs over the reporting threshold

Statutory interest and compensation rights

Applies automatically

Applies automatically

GDPR and ICO registration

Applies if you handle personal data

Applies if you handle personal data

Duty to report on payment practices

Not required

Required twice yearly

Fair Payment Code

Optional

Optional, though often expected for public contracts

Written credit terms and limits

Required in practice

Required in practice

Debt collection conduct rules

Applies automatically

Applies automatically

How Capitalise helps you manage credit compliantly

Capitalise's Credit Risk Manager brings your credit checks, credit limits and risk monitoring into one place, connected to the accounting software you already use. Because credit checks are run through the platform rather than pieced together from separate sources, the data you rely on for setting limits and monitoring risk sits within a single, consistently handled system, making it easier to demonstrate exactly how and why each credit decision was made.

Build compliance into your credit management today

Getting paid on time matters, but doing it within the rules protects your business just as much as the cash itself. Sign up to Capitalise to run compliant credit checks on new and existing customers, and keep every credit decision backed by data you can stand behind.

Credit check your customers, suppliers and partners - instantly

Check credit scores

Paul Surtees

Paul Surtees is CEO and Co-founder at Capitalise, a fintech platform helping small businesses access funding and monitor business credit. A former investor and mentor, he founded Capitalise to make business finance more accessible and transparent.

Read more articles