Modern Slavery and Human Trafficking Statement

Introduction and basis of this statement

This statement is made by Verifile Holdings Limited for and on behalf of the Verifile group, covering its operating companies, including Verifile Limited and Workpass Limited, and our operations in Portugal and Australia. It relates to the financial year ended 31 December 2025.

The group provides employment background screening and identity verification. Although our turnover is below the £36 million threshold that would require us to publish a modern slavery statement under Section 54 of the Modern Slavery Act 2015, we take the issue seriously and have chosen to publish one voluntarily, holding ourselves to the standard the Act sets. In preparing it we have regard to the UK government's updated Transparency in Supply Chains guidance of 24 March 2025, the OECD Guidelines for Multinational Enterprises and the UN Guiding Principles on Business and Human Rights.

We are a professional-services group of around 132 people, working in offices and remotely. Our own exposure to modern slavery is low, and our influence over the wider supply chains that sit behind the data and technology we buy is limited. This statement is honest about both. It describes the measures we actually take, and it does not claim controls, audits or supply-chain mapping that we do not carry out.

We are committed to acting ethically and with integrity in all our business dealings and relationships. We will not knowingly enter into or continue a relationship with any organisation we find to be involved in modern slavery or human trafficking.

1. Our structure, business and supply chains

The group is parented by Verifile Holdings Limited (company number 07450770). Its main operating company is Verifile Limited (company number 05129976), and Workpass Limited (company number 06529355) provides automated employment and income verification drawn from employer payroll systems. Our main office is in Bedford, our software engineering teams work in the UK and Portugal, and we run a support office in Brisbane, Australia, for the Asia-Pacific region. The work across the group is office-based, professional knowledge work. We carry out no manufacturing, buy no raw materials or goods for resale, and employ no low-skilled, seasonal or manual-labour workforce.

We deliver screening across more than 200 countries, so our supply chain is international by its nature. It is made up of data, technology and professional services rather than labour or goods, and it has four main parts:

  • Data sources around the world. Wherever possible we obtain records directly from official sources, such as government agencies, criminal-record registers, courts and credit reference agencies. These bodies control their own data and hold it in their own jurisdictions, and most are public authorities or established, regulated reference agencies.
  • Local search agents, used occasionally. Where a specific overseas check cannot be obtained directly, we engage a local agent to carry out that individual search, for example at a university, a former employer or a government office. They are selected case by case for a single search and are not retained on an ongoing basis.
  • Software and technology providers. The group runs on established cloud and business software, including our hosting provider and a range of software-as-a-service tools for security, communications, payments, finance and customer management.
  • Operational service providers with incidental access to data, such as IT support, secure document destruction, premises security and our external auditors.

We maintain a register of these sub-processors, sub-contractors and agents, last updated in April 2026.

2. Our policies

We hold an Anti-Slavery and Human Trafficking Policy, approved by our CEO in May 2025 and reviewed each year. It sets a zero-tolerance position on slavery, servitude, forced or compulsory labour and human trafficking, and it applies to everyone who works for the group in any capacity and to our suppliers, contractors and business partners. The policy is supported by our Whistleblowing, Health and Safety, and Grievance policies. It commits us to check the right to work of everyone we employ, to give every employee a written contract of employment, to tell new recruits about their statutory rights, and to pay at least the National Minimum Wage. In practice we go further: we are an accredited Living Wage Employer, recognised by the Living Wage Foundation, and we pay at least the Real Living Wage.

The policy also sets the standard we expect of our suppliers, contractors and business partners: that they prohibit the use of forced, compulsory or trafficked labour and that they hold their own suppliers to the same standard.

We back this with contractual controls. Our standard supplier terms require the organisations we buy from to comply with the Modern Slavery Act 2015 and allow us to terminate where they do not. Our standard customer terms carry a matching modern slavery clause, under which we warrant our own compliance with the Act and undertake to notify promptly if that position changes, with the right to terminate for material breach or for breach of applicable law.

3. Our due diligence

Our most direct control is over the people we engage. Everyone who works for the group, whether employee, contractor or temporary worker, is screened to an enhanced version of BS7858:2019 before they start, with a ten-year lookback, and is re-screened every two years. This includes identity and right-to-work checks, which are themselves controls against exploitation, and it applies equally to our colleagues in Portugal and Australia.

For the organisations in our supply chain, we work with established, reputable data sources, technology providers and professional firms, and we select international search agents as required. We set our expectations of these suppliers through our policy, as described above. As a low-risk group of our size, we do not operate supplier audits or supply-chain mapping, which would not be proportionate to our risk.

4. Where the risk is, and how we assess and manage it

We assess risk by asking first where workers could be exposed to exploitation, not only where commercial exposure sits with us. Within the group the risk to our own people is low: our workforce is professional and office-based, engaged and screened directly by us as described above. The data sources we use are predominantly public authorities and regulated reference agencies, and our technology and professional suppliers are established firms, so the risk to workers among our direct suppliers is also low. The greater residual risk, although still low and distant from us, sits with workers further down chains we cannot see: in the manufacturing of the hardware behind the cloud and technology services we rely on, and potentially in lower-tier suppliers in higher-risk jurisdictions. These are risks shared across the whole economy and many tiers removed from a business of our size and type. We manage what we can through the expectations we set for our suppliers, and we are candid that our leverage over these wider chains is limited.

We revisit this assessment at least once a year, and sooner if our suppliers, footprint or risk profile change materially.

5. Measuring our effectiveness

As a low-risk group we use simple, verifiable indicators rather than supplier-audit metrics. The indicators we track include the following:

We screen everyone who works for the group to an enhanced BS7858:2019 standard before they start, the same standard we are independently certified to deliver as a service (NSI Specialist Services Gold, the highest tier of that scheme). This screening, with identity and right-to-work checks, is a direct control against exploitation within our own workforce.

Every colleague is on a written contract of employment, and we complete the two-yearly re-screening cycle across the group.

Modern slavery concerns raised through our protected whistleblowing route: none were reported or identified within the group during the period. Reports made in good faith are protected from any detrimental treatment.

We review the policy and this statement each year.

6. Training

Every new joiner is introduced to this policy and the supporting policies at induction, and colleagues are made aware again when the policy is updated. All colleagues also complete annual data protection and information security training, which covers the correct handling of sensitive personal data. We keep this training current. Managers at all levels are responsible for making sure their teams understand the policy, and our policies remain available to everyone at any time.

Stakeholder engagement

We engage our internal and external stakeholders in the way we tackle modern slavery, in proportion to our size and risk. Internally, our Chief People Officer, HR team and managers own the day-to-day implementation of this policy, all colleagues are introduced to the policy at induction and reminded when it is updated, colleagues are invited to comment on the policy, and a protected whistleblowing route is open to everyone who works for the group. Externally, we set our expectations of suppliers through our policy and standard terms, as set out above, our protected reporting route is open to suppliers and business partners, and we are happy to discuss a proposed overseas search agent with a customer where that is relevant to their assignment.

Governance, approval and signature

Overall responsibility for this statement, and for the group's compliance with its legal and ethical obligations, rests with our Chief Executive Officer. Our Chief People Officer and HR team have day-to-day responsibility for implementing the underlying policy and monitoring its effectiveness. We review this statement each year. We will publish it on the Verifile website and intend to submit it to the UK government's modern slavery statement registry as voluntary good practice.

This statement was approved by the Board of Verifile Holdings Limited.