Apologies - I realize I never followed up on this.
OpenSSL kept reporting the old chain and the windows “show certificate” would return different chains depending on how you got to that dialog box.
We had to remove the R3 cert in a few places using CertMgr and then in the end - using Help thread for DST Root CA X3 expiration (September 2021) - #791 by webprofusion - Help - Let's Encrypt Community Support - removed it via the registry for the system user and rebooted. Then requesting new certificates worked ok.