A compliance checklist for credit management should cover UK late payment law, the rules on reporting payment practices, how GDPR applies to the customer data you hold, fair contract terms and the legal limits on debt collection. This guide sets out exactly what belongs on that checklist, the regulation behind each item, and how to build compliance into the credit control process you already run, rather than treating it as a separate job. This is general guidance rather than legal advice. If you are unsure how a specific rule applies to your business, it is worth checking gov.uk or speaking to a solicitor before you act on it.
What compliance means for credit management
Compliance in credit management means following the specific laws and codes that govern how you extend credit, invoice customers, chase late payment and handle the personal data involved along the way. It sits alongside your normal credit control process, the credit checks, credit limits and payment reminders you already run, rather than replacing it. Where credit control is about getting paid on time, compliance is about doing it within the rules. A business can have an efficient credit control process and still fall short on compliance, for example by chasing debtors in a way that breaches harassment rules, or by holding onto customer data for longer than GDPR allows.
The credit management compliance checklist at a glance
Before going through each area in detail, here is the full checklist in one place.
The rest of this guide walks through each of these in more detail.
Late payment law: interest, compensation and payment terms
The Late Payment of Commercial Debts Regulations 2013 give every business the automatic right to charge statutory interest on overdue business to business invoices, whether or not your contract mentions it. The regulations apply across England, Wales and Northern Ireland, and separately in Scotland, and cover commercial debts only, not money owed by or to consumers. Statutory interest is charged at 8% above the Bank of England base rate, which stood at 3.75% as of the July 2026 rate decision, putting the statutory rate at 11.75%. On top of interest, you're also entitled to fixed compensation for the cost of chasing the debt, calculated per invoice rather than per customer.
Invoice amount | Fixed compensation you can charge |
|---|---|
Up to £999.99 | £40 |
£1,000 to £9,999.99 | £70 |
£10,000 or more | £100 |
If your actual recovery costs are higher than the fixed amount, you can claim the difference as well. Building this into your standard terms means customers know the cost of paying late upfront, and you have a consistent, compliant basis for chasing every overdue invoice rather than deciding case by case.
Does the duty to report on payment practices apply to you
The duty to report on payment practices applies if your business meets two or more of three criteria on both of its last two balance sheet dates: annual turnover over £36 million, a balance sheet total over £18 million, or more than 250 employees. If that's your business, you're required to publish a report on your payment practices twice a year, within 30 days of each six month period. Since the rules were updated for financial years beginning on or after 1 January 2025, reports must also include the total value of payments not made within agreed terms and the percentage of invoices unpaid due to a dispute, not just average payment times. The requirement runs until 6 April 2031. Failing to report, or publishing a report that misrepresents your payment practices, is a criminal offence for the company and its directors.
Most small and medium businesses fall outside this duty, but it's worth checking your figures against the thresholds each year, particularly if you're growing quickly or have recently taken on new investment.
Should you sign up to the fair payment code
The Fair Payment Code is voluntary, but signing up gives suppliers a public signal that you pay on time and can be a requirement for tendering on public sector contracts. It replaced the Prompt Payment Code in late 2024 and is administered by the Small Business Commissioner, free to join, with awards lasting two years before businesses need to reapply. There are three tiers, based on the percentage of invoices you pay within agreed timeframes.
Award | Requirement |
|---|---|
Gold | At least 95% of all invoices paid within 30 days |
Silver | At least 95% of all invoices paid within 60 days, including 95% to small businesses within 30 days |
Bronze | At least 95% of all invoices paid within 60 days |
Signing up isn't a legal requirement, but it's worth weighing up if your business relies on public sector contracts or a supply chain of smaller businesses who value being paid reliably.
Does running credit checks create a GDPR compliance issue
Running a credit check on a business customer does not create a GDPR compliance issue for you, because the information involved, company filings, credit history and any registered CCJs, is public information held and processed by the credit reference agency, not personal data your business is collecting or storing itself. Checking a company before you extend credit is standard credit control practice, not a compliance risk, and it's worth doing for every new customer regardless of how well you know them or how big the order is.
Where GDPR does apply is the customer data you hold and use day to day, contact details, invoices and correspondence about payment, rather than the credit check itself. Here what's needed is a clear lawful basis for holding it, usually legitimate interests, a privacy notice explaining what you do with customer data, and not keeping it for longer than necessary. This is more likely to come into play if you extend credit to sole traders or individuals rather than only limited companies, since you're then dealing with someone's own name and address rather than only company information.
Running a company credit check through a platform built for this purpose keeps this simple: you get the risk data you need, backed by the credit reference agency's own compliant handling of it, without taking on any extra compliance obligation for accessing it.
Setting credit terms and contracts that hold up
Every customer you extend credit to should have written payment terms agreed before the first invoice goes out, covering the credit period, the credit limit and what happens if payment is late. Verbal agreements or assumed terms are the most common reason credit disputes turn into drawn out, costly disagreements. Credit limits should be set from actual risk data rather than gut feel or the size of the order. Our credit control guide covers how to build this process from scratch, including how to set limits that reflect a customer's real ability to pay rather than how long you've worked with them.
One area worth particular care is if you extend credit to sole traders or small partnerships rather than only limited companies. Some agreements with individuals or partnerships of three or fewer partners can fall under separate consumer credit regulation, so it's worth checking with a solicitor if a meaningful share of your customer base falls into this category.
Debt collection: staying within the law when you chase payment
Chasing overdue payment is legal and expected, but the Protection from Harassment Act 1997 and section 40 of the Administration of Justice Act 1970 set limits on how you can do it. You can't contact a customer with a frequency or tone designed to intimidate, misrepresent the legal consequences of non payment, or imply enforcement action you haven't actually taken. Escalation should follow a clear, proportionate path: reminders before and after the due date, a formal notice referencing your statutory right to interest and compensation, and only then a statutory demand or a County Court Judgment if the debt remains unpaid. Keeping this escalation consistent across every customer is both good practice and a protection for your business if a dispute is ever challenged.
Record keeping businesses often overlook
Financial records, including invoices, credit notes and correspondence about payment, generally need to be kept for six years to satisfy HMRC and Companies Act requirements. Where those records contain personal data, GDPR still requires you to only keep what you need for that purpose, so it's worth separating the financial record you're required to retain from any wider customer data you could delete sooner.
A clear audit trail also matters if a customer later becomes insolvent. Records showing when credit was extended, what checks were run and how the account was managed can matter if a liquidator or administrator later scrutinises the debt.
Compliance checklist by business size
What applies to you depends largely on your size and who you extend credit to.
Requirement | All businesses extending business credit | Large companies and LLPs over the reporting threshold |
|---|---|---|
Statutory interest and compensation rights | Applies automatically | Applies automatically |
GDPR and ICO registration | Applies if you handle personal data | Applies if you handle personal data |
Duty to report on payment practices | Not required | Required twice yearly |
Fair Payment Code | Optional | Optional, though often expected for public contracts |
Written credit terms and limits | Required in practice | Required in practice |
Debt collection conduct rules | Applies automatically | Applies automatically |
How Capitalise helps you manage credit compliantly
Capitalise's Credit Risk Manager brings your credit checks, credit limits and risk monitoring into one place, connected to the accounting software you already use. Because credit checks are run through the platform rather than pieced together from separate sources, the data you rely on for setting limits and monitoring risk sits within a single, consistently handled system, making it easier to demonstrate exactly how and why each credit decision was made.
Build compliance into your credit management today
Getting paid on time matters, but doing it within the rules protects your business just as much as the cash itself. Sign up to Capitalise to run compliant credit checks on new and existing customers, and keep every credit decision backed by data you can stand behind.
%3Aquality(80)%3Afill(transparent)&w=1080&q=75)
%3Aquality(80)%3Afill(transparent)&w=3840&q=75)
%3Aquality(80)%3Afill(transparent)&w=3840&q=75)
%3Aquality(80)%3Afill(transparent)&w=3840&q=75)
%3Aquality(80)%3Afill(transparent)&w=3840&q=75)