WPC HR
All articles
ComplianceWPC HR24 min read

Sponsor Management System Multi-Factor Authentication: What HR Teams Must Do Now

Published 2 September 2026

Sponsor Management System MFA: What Sponsors Do Now

Key Takeaways

  • Mandatory multi-factor authentication (MFA) for Sponsorship Management System users began on 3 September 2026. The Home Office is switching it on in phases and expects every sponsor to be covered by November 2026.
  • Any organisation granted a sponsor licence on or after 9 September 2026 has MFA enabled from day one, with no phasing and no run-up.
  • You get around two weeks of notice. The Home Office emails your Authorising Officer, Key Contact, Level 1 Users and Level 2 Users before your account is switched on.
  • Level 1 Users receive a one-time passcode by text message and must also enter their date of birth the first time they log in to an MFA-enabled account. If the date of birth held on SMS is wrong, they cannot get in.
  • Level 2 Users, and Level 1 Users with no mobile number on record, receive the passcode by email instead. For those users it is the email address that has to be right.
  • A passcode expires after 10 minutes. Three wrong dates of birth lock the account for 24 hours, and running out of passcode attempts locks it for 20 minutes.
  • Correcting a date of birth is not a self-service change. It goes through the sponsor change of circumstances form and a dedicated Home Office mailbox, so discovering the error on switch-on day is the expensive way to find out.
  • From 9 September 2026 you cannot appoint new Level 2 Users, and every existing Level 2 User must be converted to Level 1 or deactivated by 8 March 2027. Agency staff cannot be converted at all.
  • MFA carries no penalty of its own. The damage comes from a locked account that stops you meeting reporting deadlines. Our HR compliance software keeps key personnel records, reporting deadlines and sponsor files current, so an SMS lockout never turns into a compliance breach.

Introduction

On 3 September 2026 the Home Office began switching on mandatory multi-factor authentication for the Sponsorship Management System. From that date, logging in stops being a username and password and becomes a username, a password and a one-time passcode sent to a phone or an email inbox. Level 1 Users have to prove one more thing on top of that, which is their date of birth. The change is set out in Part 1 of the sponsor guidance, version 08/26, published on 28 August 2026, and in the Home Office's own SMS Guide 13 on multi-factor authentication, published on the same day.

This looks like an IT change and gets treated like one. It is not. Your SMS account is the only route you have to assign a Certificate of Sponsorship, report a change to a sponsored worker and keep your licence in good standing. An account nobody in the building can open is a compliance problem wearing an IT costume, and it becomes one on the day a reporting deadline falls.

There is one point worth separating before you read on. The start date of 3 September 2026 is confirmed in published Home Office guidance, as is the 9 September 2026 date for newly granted licences and the 8 March 2027 deadline for Level 2 Users. The completion of the rollout by November 2026 is stated in the guidance as an expectation rather than a fixed legal deadline, and the wording is that the Home Office expects MFA to be in place for all sponsors by then. Student sponsor guidance had not been updated to cover MFA at the time of writing, so student sponsors and multi-route licence holders should watch for their own notification rather than assume a date.

This post settles what MFA actually changes, what has to be correct in your records before your account is switched on, exactly what a lockout looks like and how long it lasts, how to fix a wrong date of birth, and what the Level 2 User phase-out means for teams that have quietly been running on a single Level 1 login for years.

What Multi-Factor Authentication Changes About Your SMS Login

Multi-factor authentication means proving who you are with more than one piece of evidence. Something you know, which is your password, plus something you have, which is the phone or mailbox that receives the code. A stolen password on its own stops being enough.

The Home Office puts the reasoning plainly in Part 1 of the sponsor guidance at paragraph L4.66. MFA "adds an extra layer of security by requiring users to use more than one verification factor to access their account", and it "protects sponsor accounts from unauthorised access, even if a password is compromised". SMS Guide 13 is blunter still, noting that as cyber scams become more sophisticated, multi-factor authentication helps to keep criminals out of the account.

In practice, three things change for your team:

  • Every login now needs a one-time passcode as well as a username and password. There is no way to opt out and no way to switch it off once your account is enabled.
  • Level 1 Users have to enter their date of birth the first time they log in to an MFA-enabled account using a mobile phone, and again whenever they later change their phone number or email address at login.
  • Shared logins stop working in any practical sense. If two people use one account, the passcode only ever reaches one phone or one mailbox, and that person becomes a bottleneck for everything the licence needs doing.

That last point is the quiet benefit. Sharing an SMS login has always been a breach of your sponsor duties, and our sister firm WorkPermitCloud has written about why sharing an SMS login puts a sponsor licence at risk for the individuals affected. MFA does not just forbid the practice, it makes it inconvenient enough that teams finally stop.

The Rollout Timetable and When Your Account Switches On

The Home Office trialled MFA voluntarily with a limited number of sponsors from November 2025. The mandatory phase runs to the following timetable, all of it drawn from paragraphs L4.58 to L4.71 of Part 1 of the sponsor guidance, version 08/26.

DateWhat happensStatus
November 2025Voluntary MFA trial opens with a limited number of sponsors.Completed
3 September 2026Mandatory MFA begins, switched on sponsor by sponsor in phases.Confirmed in guidance
9 September 2026Any organisation granted a sponsor licence on or after this date has MFA enabled immediately. No new Level 2 Users can be appointed from this date.Confirmed in guidance
By November 2026The Home Office expects MFA to be in place for all sponsors.Stated as an expectation, not a fixed deadline
8 March 2027Every remaining Level 2 User must have been converted to Level 1 or had their account deactivated.Confirmed in guidance

You do not choose your slot and you cannot request one. The guidance at L4.71 says the Home Office will contact you with instructions when MFA is due to be enabled on your account, and SMS Guide 13 sets the notice period at two weeks. That email goes to your Authorising Officer, your Key Contact, your Level 1 Users and your Level 2 Users.

Two weeks sounds generous until you consider what has to happen inside it. If a date of birth is wrong on the system, correcting it means a form and a Home Office mailbox rather than a click. If your only Level 1 User is on leave for a fortnight, the notice email lands in an inbox nobody is reading. The sensible assumption is that you have already been notified and have not noticed, and that the work below should be done this week rather than when the email arrives.

The Data Check Every Sponsor Should Run Before Switch-On

This is the whole job, and it takes about twenty minutes. Paragraph L4.69 of Part 1 states that you "must therefore ensure that the correct date of birth, phone number and email address have been recorded for each Level 1 User on your licence", and L4.70 adds the equivalent requirement for email addresses where a user will receive codes by email. What has to be right depends on which kind of user you are looking at.

User typeHow the passcode arrivesWhat must be correct on SMSWho can change it
Level 1 User with a mobile number on recordText message to the registered mobileDate of birth, mobile number, email addressThe Level 1 User can amend their own mobile and email. Date of birth cannot be self-served.
Level 1 User with no mobile number on recordEmail to the registered addressEmail address, and date of birth for first loginAs above.
Level 2 UserEmail to the registered addressEmail addressA Level 1 User must make the change. Level 2 Users cannot amend their own email address.
Authorising Officer and Key Contact who are not SMS usersNot applicable, they do not log inCurrent email address, so they receive the notificationA Level 1 User, or the change of circumstances form.

Date of birth is the one that catches people out

Mobile numbers and email addresses have always been loosely maintained and are easy to correct. Date of birth is different. It was captured when the user was added, in some cases years ago, and nobody has looked at it since. A transposed day and month, an American-format entry, or a placeholder typed in a hurry will all sit there harmlessly until the day MFA turns on, and then lock the person out.

Check it now, while the fix is cheap. Every Level 1 User should log in, open their own user details and read the date of birth against their passport or driving licence. The Home Office's SMS manual on managing user access sets out where the details sit in the system, and our guide to using the Sponsorship Management System day to day covers the wider navigation.

Personal mobiles, shared inboxes and the practical decisions

Two questions come up in every HR team at this point. The first is whether a personal mobile number can be used. It can, and for most Level 1 Users it will be, because the alternative is issuing a work handset. Tell the user why the number is held, record the lawful basis alongside your other staff data, and remove the number promptly when they leave. The second is whether a shared mailbox can receive the passcode for a Level 2 User. It can technically, but it recreates the shared-login problem you have just been handed a tool to fix. One named person, one mailbox they alone read, is the safer answer.

There is a third question nobody asks and should. What happens when the person holding the phone leaves? That is covered further down, because it is the single largest risk in this whole change.

What Logging In Actually Looks Like Once MFA Is On

The flow set out in SMS Guide 13 is short. For a Level 1 User receiving the code by text message it runs as follows.

  • Enter your SMS username and password as you always have.
  • Select your mobile country code and confirm the mobile number the code should go to.
  • Enter your date of birth. It must match the date recorded against your record on the sponsor licence.
  • Wait for the text message from the sender ID 'GOVUK', which contains a six-digit passcode. Allow up to a minute for it to arrive.
  • Enter the passcode and select Submit. The passcode is valid for 10 minutes and stops working after that.

A Level 2 User, or a Level 1 User without a mobile number on file, follows the same path with the code arriving by email instead of text, and without the date of birth step. If the code has not arrived after a minute, SMS Guide 13 directs users to the option to amend the mobile number or email address rather than sitting and waiting, which is also how you correct a number that turns out to be wrong at the point of login. A Level 1 User who changes their number or email that way has to re-enter their date of birth.

One habit worth building now. Log in from the official Sponsorship Management System page on GOV.UK or a bookmark you created from it, never from a link in an email. That single rule defeats most of the phishing described later in this post.

Lockouts, Expired Codes and How to Get Back In

SMS Guide 13 sets out the failure states precisely, and they are worth knowing before you meet them rather than after. Most commentary on MFA stops at "you will need a passcode" and leaves the recovery route out, which is the part that decides whether a bad morning costs you an hour or a day.

What went wrongWhat happensHow long it lastsWhat to do
Passcode entered after 10 minutesThe passcode is rejected as invalid.No lockoutRequest a new passcode and enter it promptly.
Passcode entered incorrectlyYou have three attempts.No lockout until attempts are exhaustedRe-check the digits and try again within the three attempts.
New passcodes requested too many timesYou may request a new passcode twice. Beyond that the account locks.20 minutesWait it out, then request a fresh code and enter it inside the 10-minute window.
Date of birth entered incorrectly three timesThe account locks.24 hoursIf the date you entered is correct, the record on SMS is wrong. Follow the correction route below. Do not keep guessing.
Passcode never arrivesNo code is received after around a minute.No lockoutUse the option to amend the mobile number or email address, then request the code again.

When the date of birth held on SMS is wrong

This is the one that cannot be fixed from inside the system. A user cannot edit their own date of birth, and neither can a Level 1 User edit it for someone else. SMS Guide 13 directs you to complete the sponsor change of circumstances form and email it to MFACOC@homeoffice.gov.uk with "DOB change request" in the subject line.

That is a Home Office processing step with no published turnaround time, sitting between your user and their account. If a reporting deadline falls inside that window, the deadline does not move. This is precisely why the date of birth check belongs on your task list this week and not in the fortnight after the notification email lands.

For anything else that keeps a user out of the account, the route is the business helpdesk at BusinessHelpdesk@homeoffice.gov.uk. Queries have to come from someone named on the licence, and you should include your organisation name and licence number.

Level 2 Users Are Being Phased Out at the Same Time

MFA is arriving alongside a second change to SMS access that has had far less attention, and the two interact. Paragraph L4.58 of Part 1 states that from 9 September 2026 you can no longer appoint Level 2 Users to your licence. Existing Level 2 Users then have to be dealt with by a fixed date.

DateWhat it means for Level 2 Users
Before 9 September 2026Level 2 Users could still be appointed, including temporary staff supplied by an employment business.
From 9 September 2026No new Level 2 User can be appointed to any licence, and no further agency staff can be added as Level 2 Users.
By 8 March 2027Every existing Level 2 User must have been converted to a Level 1 User or had their account deactivated.
After 8 March 2027Accounts not dealt with will be deactivated. Agency staff Level 2 User accounts are deactivated regardless, because they cannot be converted.

A Level 2 User's permissions were always narrow. They could create a Certificate of Sponsorship and report activity on the workers whose CoS they had personally assigned, and little else. If your CoS process leans on Level 2 Users, read our guide to assigning a Certificate of Sponsorship correctly alongside this, because the people doing that work are about to change.

Converting a Level 2 User to Level 1

Conversion is not automatic and not everyone qualifies. A Level 1 User appointed after the licence is granted must be a paid member of staff or an office holder in your organisation, an employee of an organisation contracted to provide your HR services, or a UK-based representative. Separately, at least one Level 1 User, referred to in the guidance as your primary Level 1 User, must be an employee, director or partner within your organisation and, in most cases, a settled worker.

Work through your Level 2 list now and sort each person into one of three piles. Convert, deactivate, or replace with someone else. Leaving the decision until early 2027 means making it in a hurry, and a deactivation that removes your last route into a function is worse than an early conversion you did not strictly need.

Agency staff cannot be converted

Paragraph L4.65 is explicit that Level 2 Users supplied by an employment business are not eligible to be converted into Level 1 Users. Their accounts will be deactivated. Sponsors who have used agency or interim staff to cover CoS assignment, which is common in the care sector and in seasonal recruitment, need a permanent internal alternative in place well before March 2027. Our care sector sponsor licence compliance guide covers the wider staffing pressures that sit behind this.

One Level 1 User Is a Single Point of Failure

MFA ties access to a specific phone and a specific mailbox belonging to a specific person. That is the point of it. It also means that if your licence runs on one Level 1 User, your entire ability to meet your sponsor duties now depends on one individual being contactable, holding a working phone and remembering their own date of birth as it was typed into a form some years ago.

The guidance does not leave this to good practice. Part 1 states that you "must have an eligible Authorising Officer and at least one Level 1 User throughout the life of your licence", and it sets out an escalation that ends badly for sponsors who let accounts go stale.

StageWhat happensTiming
Account goes unusedAn SMS user account is treated as inactive once the user has not accessed it for 12 months or more.12 months of no access
Home Office contacts youThe Authorising Officer and any inactive Level 1 Users are contacted with instructions to log in and check their details.On identification
Window to actLevel 1 Users must log in and check, and update if needed, their details. Level 2 User accounts must be confirmed as still needed.3 months from the date of contact
Accounts deactivatedAny account still inactive after that window is deactivated and loses SMS access.After 3 months
Licence suspendedIf the process leaves you with no active Level 1 Users, the licence is suspended and you must nominate at least one eligible Level 1 User.28 days from suspension
Licence revokedIf no eligible Level 1 User is nominated in that period, the Home Office will normally revoke the licence.After 28 days

Read that table next to MFA and the risk becomes obvious. An account that is hard to log in to is an account that gets logged in to less often, and an account that is used less often drifts towards the 12-month inactivity threshold. Two or three named Level 1 Users, each with their own correct details and each logging in occasionally, removes the whole chain. Our post on what happens when sponsor compliance fails covers suspension and revocation in full, and the Authorising Officer's responsibilities include making sure this staffing question has an answer.

What MFA Does Not Do, and Where the Real Risk Sits

It is worth being accurate about the consequence here, because some commentary has overstated it. There is no penalty for failing to set up MFA. It is switched on by the Home Office rather than by you, and the published guidance does not create a sanction for a sponsor whose users struggle with it. Nothing in Part 1 or Part 3 of the sponsor guidance says that an MFA problem in itself costs you your licence.

The exposure is indirect and it is real. Your sponsor duties run on deadlines that do not pause. Changes to a sponsored worker's circumstances have to be reported inside fixed windows, a Certificate of Sponsorship has to be assigned before a worker can apply, and your records have to be current if a compliance officer arrives. Every one of those depends on somebody being able to open SMS that day. A locked account does not breach an MFA rule, it breaches a reporting duty, and reporting duties are what enforcement action is actually built on.

Put plainly, the sequence that hurts you is: date of birth wrong, user locked out for 24 hours, correction form sits with the Home Office for an unknown number of days, a reportable change happens in that window, the report goes in late. Nothing in that chain is an MFA penalty. All of it is a sponsor duty failure. Our complete sponsor duties checklist sets out which deadlines you are working against.

Expect Phishing Dressed Up as the MFA Rollout

Sponsor licence holders have been targeted by phishing campaigns throughout 2026, and a mandatory login change is close to ideal cover for the next round. Your staff are expecting an unusual email from the Home Office about their SMS login. That is exactly the message a criminal wants to imitate.

The Home Office's business helpdesk guidance states the rule that defeats this. The Home Office will never provide you with a link or a password with which to log into SMS. A genuine notification tells you a change is coming. It does not hand you a door.

Three habits are enough. Log in only from your own bookmark or from GOV.UK, never from a link in a message. Treat any request for your password, passcode or date of birth as fraudulent, whoever appears to have sent it. If you think an account has been compromised, contact the business helpdesk immediately rather than waiting to be sure. Passcodes are the new target, and a passcode read out over the phone to a convincing caller undoes everything MFA was built to prevent.

Your MFA Readiness Checklist

Work through this before your notification arrives rather than after it.

ActionWho does itWhy it matters
List every SMS user on the licence and their levelLevel 1 User or HR leadYou cannot check records you have not enumerated. Most sponsors find at least one account belonging to a leaver.
Check the date of birth held for every Level 1 UserEach Level 1 User, verified against IDA wrong date of birth is the only error that cannot be fixed from inside SMS.
Check the mobile number and email address for every userLevel 1 Users for themselves, and for Level 2 UsersLevel 2 Users cannot change their own email address.
Deactivate accounts belonging to leaversLevel 1 UserReduces the attack surface and stops accounts drifting into the 12-month inactivity rule.
Make sure you have at least two active Level 1 UsersAuthorising OfficerMFA ties access to individuals. One person is one illness away from a missed deadline.
Decide the future of every Level 2 UserAuthorising Officer and HR leadConvert or deactivate by 8 March 2027. Agency staff cannot be converted.
Confirm the Authorising Officer and Key Contact email addresses are currentLevel 1 UserThey receive the two-week notification. A stale address means no warning.
Brief users on the phishing rule and the login routeHR leadThe rollout is the perfect cover story for a credential attack.
Record the whole exercise in your sponsor filesHR leadEvidence of active licence management, which is what a compliance officer is looking for.

The final line matters more than it looks. Keeping evidence that you actively manage your licence sits alongside the records you already hold under Appendix D, and it is the kind of thing that shapes an officer's impression during a Home Office compliance visit.

How Can WPC HR Help?

MFA is a login change, but the work it creates is record keeping, and record keeping is what we build. Our HR compliance software holds your key personnel details, sponsored worker records and reporting deadlines in one place, so a change of Level 1 User, a leaver whose account needs deactivating or a reporting window that falls during a lockout is visible before it becomes a problem rather than after.

If you would rather have someone check the whole picture, our sponsor licence compliance audit reviews your key personnel structure, your SMS user list, your Appendix D files and your reporting history against current Home Office guidance, and tells you exactly where the gaps are. It is the same exercise a compliance officer would run, done while you still have time to fix what it finds.

📞 Call us: 020 8087 2343
📅 Book a free compliance audit: wpchr.co.uk/sponsor-licence-compliance-audit
🔗 See the platform: wpchr.co.uk/hr-compliance-software-features

Conclusion

Mandatory multi-factor authentication is not a difficult change. It is a twenty-minute data check that becomes a serious problem only when it is left until the login screen refuses to cooperate. Confirm the date of birth, mobile number and email address held for every Level 1 User, sort out your Level 2 Users well ahead of 8 March 2027, and make sure more than one person can open the account.

The deeper point is the one worth taking to your Authorising Officer. MFA has exposed how many sponsors run a licence worth their entire hiring pipeline on a single login held by a single person. The Home Office has now built an escalation that ends in revocation for sponsors who let SMS access lapse. Fixing that this month costs an afternoon. Fixing it during a suspension costs considerably more.

Glossary

TermDefinition
Authorising Officer (AO)The senior person in your organisation with overall responsibility for the sponsor licence and for the actions of everyone who uses the Sponsorship Management System.
Certificate of Sponsorship (CoS)The electronic record a sponsor assigns to a worker through SMS, which the worker then uses to apply for their visa.
Change of circumstances formThe Home Office form used to report changes that cannot be made through SMS, including a correction to a Level 1 User's date of birth for MFA purposes.
Key ContactThe named person who acts as the main point of contact between your organisation and the Home Office on licence matters.
Level 1 UserThe main day-to-day SMS user, with full access to the system's functions. Your primary Level 1 User must be an employee, director or partner in your organisation.
Level 2 UserA restricted SMS user who could create a CoS and report on workers whose CoS they assigned. No new Level 2 Users can be appointed from 9 September 2026 and existing ones end on 8 March 2027.
Multi-Factor Authentication (MFA)A login method requiring more than one form of proof of identity, in this case a password plus a one-time passcode, and a date of birth for Level 1 Users at first login.
One-time passcode (OTP)A six-digit code sent by text message or email that must be entered to complete an SMS login. It is valid for 10 minutes.
Settled workerA person who is a British citizen, has indefinite leave to remain, has settled status or otherwise has no immigration restriction on their right to work in the UK.
Sponsorship Management System (SMS)The Home Office online system sponsors use to assign Certificates of Sponsorship, report changes and manage their licence.
Sponsor guidance Part 1The Home Office document covering applying for a sponsor licence and managing key personnel, including all the MFA and Level 2 User rules described here. Current version 08/26.
SuspensionHome Office action that stops a sponsor assigning new Certificates of Sponsorship while the licence is investigated. It can end in revocation.

FAQ

Frequently asked questions

  • Mandatory MFA began on 3 September 2026 and is being switched on sponsor by sponsor. The Home Office expects it to be in place for all sponsors by November 2026, and any organisation granted a licence on or after 9 September 2026 has it enabled immediately. You cannot request a particular date. The Home Office will email your Authorising Officer, Key Contact and SMS users roughly two weeks before your account is enabled.

  • No. It is mandatory for all SMS users at Level 1 and Level 2, and the Home Office controls when your account is switched on. There is no opt-out and no deferral process. What you can control is whether your records are correct when it happens.

  • They will not be able to log in, and three incorrect attempts will lock the account for 24 hours. The correction cannot be made inside SMS. You need to complete the sponsor change of circumstances form and email it to MFACOC@homeoffice.gov.uk with "DOB change request" in the subject line. Because that takes Home Office processing time, checking the date of birth now is the single most useful thing you can do this week.

  • Ten minutes. If you do not enter and submit it within that window it stops working and you need to request a new one. Allow up to a minute for the code to arrive before assuming there is a problem.

  • It depends on which limit you hit. Three incorrect dates of birth lock the account for 24 hours. Exhausting your passcode attempts and requests locks it for 20 minutes. Neither is a compliance breach in itself, but both can stop you meeting a reporting deadline, which is.

  • No. Level 2 Users receive their passcode by email, so it is the email address that has to be correct. They cannot change their own email address on SMS, so a Level 1 User needs to do it for them before the account is switched on.

  • Sharing a login has always been a breach of your sponsor duties and can result in action against your licence. MFA makes it impractical as well, because the passcode only ever reaches one phone or mailbox. Every person who needs SMS access should have their own account.

  • Not from 9 September 2026. From that date no new Level 2 Users can be appointed to any licence. Existing Level 2 Users must be converted to Level 1 Users or have their accounts deactivated by 8 March 2027.

  • No. The guidance states that Level 2 Users supplied by an employment business are not eligible to be converted into Level 1 Users, and their accounts will be deactivated. If agency or interim staff currently assign your Certificates of Sponsorship, you need a permanent internal alternative before March 2027.

  • You must have at least one throughout the life of the licence, but one is a single point of failure now that access is tied to an individual's phone and date of birth. Two or three active Level 1 Users, each with their own correct details, is the sensible arrangement. It also protects you from the inactive account process, which can lead to suspension and then revocation if you end up with no active Level 1 User.

  • Not directly. MFA is switched on by the Home Office and there is no published penalty for struggling with it. The risk is indirect. If nobody can open the account, you cannot assign a Certificate of Sponsorship or report a change inside the deadline, and missed reporting duties are what enforcement action is built on.

  • The sponsor guidance that sets out the MFA rollout is the Workers and Temporary Workers guidance, and SMS Guide 13 says MFA applies to all SMS users. Student sponsor guidance had not been updated to cover MFA at the time of writing, so student sponsors and multi-route licence holders should treat their notification email as the reliable signal rather than working to a date.

  • The business helpdesk at BusinessHelpdesk@homeoffice.gov.uk, for anything other than a date of birth correction, which goes through the change of circumstances form instead. The query has to come from someone named on the licence and should include your organisation name and licence number.

  • Do not click anything in it. The Home Office will never send you a link or a password with which to log into SMS, so any message doing so is fraudulent. Log in from your own bookmark or from GOV.UK, and report the message to the business helpdesk. Never give a passcode, password or date of birth to a caller, however convincing they sound.

Share this article

Protect your sponsor licence with WPC HR.

Real-time Right to Work monitoring, visa expiry alerts and SMS reporting, backed by IAA-regulated practitioners.

Sponsor Management System MFA: What Sponsors Do Now