The senior accounting officer regime puts a named individual's signature — and a personal £5,000 penalty — behind the quality of a large company's tax systems. UK-incorporated companies with turnover above £200 million or a balance sheet total above £2 billion in the preceding financial year must tell HMRC who their SAO is, and that person must certify every year that the company's tax accounting arrangements are appropriate — or explain why they are not. It is one of the few places in UK tax where liability attaches to a person rather than the company, which is precisely the point: somewhere in every large business, one director is meant to lie awake about whether the numbers feeding the returns can be trusted.
Who is in scope — and the aggregation trap
The thresholds are tested company by company but aggregated across UK group companies: a group of twelve entities each turning over £20 million is in scope for all twelve, and each UK company needs an SAO notification and certificate — usually the same person, usually the CFO or a senior finance director. The aggregation is where compliance quietly fails: acquisitions bring new entities into a group mid-year, dormant and holding companies get forgotten, and the regime's tidy list drifts from the group's actual structure. The certificate and notification deadlines track the accounts filing dates, so the SAO cycle belongs in the same calendar as the statutory accounts.
What the main duty actually demands
The statutory duty is to take reasonable steps to ensure the company establishes and maintains appropriate tax accounting arrangements — the systems, processes and controls through which transactions flow into returns for the regime's specified taxes — corporation tax, VAT, PAYE and the other named heads. Note what this is not: a guarantee the returns are right. An error can occur under appropriate arrangements, and conversely a lucky year of accurate returns does not prove the systems were sound. The duty is about the plumbing, not the water.
In practice, "reasonable steps" decomposes into things an SAO can evidence: knowing the end-to-end process for each material tax; risk-assessing where errors would come from (new systems, acquisitions, manual spreadsheets bridging ERP to return); testing the controls at the risky points; and remediating what testing finds. The spreadsheet bridge deserves its own mention — the majority of SAO qualifications and HMRC discussions we see involve some unglamorous manual step between systems that everyone knew about and nobody owned.
The certificate: unqualified, or honest
Each year the SAO certifies to HMRC either that arrangements were appropriate throughout, or delivers a qualified certificate naming the respects in which they were not. Qualification feels like failure and is usually the opposite: a qualified certificate identifying a known weakness with a remediation plan is the regime working as designed, and HMRC treats it far more kindly than an unqualified certificate later contradicted by discovered failures — which converts a systems conversation into a credibility one, with the personal penalty in play. The three £5,000 penalties are specific: on the SAO for failing the main duty, on the SAO for failing to certify (or certifying carelessly wrong), and on the company for not notifying who the SAO is. Modest sums, but personal, public within the business, subject to reasonable-excuse protections — and historically levied mostly for the administrative failures (the missed certificate, the un-notified appointment) that diligence alone prevents; an accounting error under genuinely reasonable arrangements is not itself a penalty trigger.
Where SAO fits the wider assurance stack
Large businesses now answer overlapping questions about tax governance: SAO certification, the published tax strategy obligation for large groups, HMRC's business risk review grading, corporate criminal offence prevention procedures (our CCO guide), and — for listed groups — the Provision 29 controls declaration reaching material tax controls too. Run separately these duplicate effort; run as one framework — a single tax control matrix, tested once, feeding certificate, strategy, BRR and board declaration alike — they become close to free of marginal cost. That consolidation is the practical upgrade most in-scope groups still have not made.
A working SAO cycle
The annual rhythm that keeps certificates unqualified and defensible: refresh the entity list against the group structure (post-acquisition especially); update the tax risk map for what changed — systems, people, new taxes, new territories; test the controls at the highest-risk handoffs; log and track remediation; and document the SAO's own engagement, because "reasonable steps" is proved by minutes and testing evidence, not job titles. For the SAO personally, the file matters: it is the difference between a defended position and an exposed one if HMRC ever asks how the certificate was supported.
Acumon supports SAOs and their teams with exactly this — tax control frameworks, risk mapping, testing programmes and certificate support — through our tax compliance and internal audit practices. If your group has crossed the thresholds recently, or the certificate is signed each year on trust rather than evidence, the gap between those two states is where the regime's teeth live.