The main failure points are weak evidence collection, inconsistent checking standards, and overreliance on manual review without sufficient assurance. If the ACSP cannot reliably verify the person against acceptable documents, the verification may not meet the required standard. That creates compliance exposure and can undermine trust in the company formation or appointment process.
Where Companies House identity checks fail in practice
The failure points usually appear before a final yes or no decision is made. The verifier has to collect the right evidence, interpret it consistently, and decide whether the person really matches the documents and data presented. If any of those steps are handled loosely, the process can look complete while still missing the assurance needed for a reliable filing or appointment decision.
Weak evidence collection is the most obvious failure mode, but it is often compounded by process drift. Teams may accept incomplete documents, rely on screenshots or low quality scans, or fail to challenge inconsistencies that should have stopped the verification. That is why the control breaks down even when someone has “reviewed” the case.
Verification also fails when standards vary from reviewer to reviewer. If one operator is strict and another is permissive, the outcome depends more on who handled the case than on the evidence itself. That inconsistency is especially dangerous in a regulated filing environment, because it creates uneven assurance and makes later challenges harder to defend.
A useful reference point is Ultimate Guide to NHIs, What are Non-Human Identities, which is helpful here because it illustrates the broader identity discipline behind evidence, lifecycle, and assurance, even when the verification target is human rather than machine.
Why manual review is often the weakest link
Manual review can add judgment, but it cannot substitute for a repeatable verification method. The main risk is not that humans are always wrong, it is that manual processes are difficult to standardise at scale, easy to under-document, and prone to confirmation bias when reviewers expect the submitted evidence to be valid. If the ACSP is relying on manual checks, the quality of the review matters more than the fact that a review happened.
That is also why overreliance on manual review becomes a control weakness. Without clear acceptance criteria, reviewers may overfit to obvious fraud indicators and miss subtler mismatches such as inconsistent names, altered documents, expired evidence, or weak source provenance. The process can then satisfy a workflow step while failing the underlying assurance objective.
The operational implication is that the ACSP should treat manual review as the exception-handling layer, not the primary source of trust. When the reviewer cannot explain why the identity is credible, or cannot point to the exact evidence that supports the decision, the verification should be considered incomplete rather than “probably fine.”
For process design, NIST SP 800-207 Zero Trust Architecture is a useful authority because it reinforces the idea that trust should be verified with explicit evidence and bounded decision rules, not assumed because a process exists.
The same discipline is reflected in NIST SP 800-53 Rev 5 Security and Privacy Controls, especially the identification, authentication, access control, and audit families that support repeatable assurance.
Risk and Threat Considerations
When identity verification is weak, the immediate risk is false acceptance, which can allow a bad actor to create, control, or influence a company record without meeting the required standard. Over time, that creates compliance exposure, weakens trust in the formation process, and can make later remediation more expensive because the original verification decision is hard to defend.
Failure mechanism: The process accepts insufficient or inconsistently assessed evidence, so the verifier cannot reliably establish that the person matches the claimed identity or meets the standard required by the ACSP.
Impact: Incorrect registrations or appointments can slip through, leaving the company record less trustworthy and increasing the chance of regulatory challenge, downstream fraud, or costly correction work.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
NIST CSF 2.0, NIST SP 800-63 and CIS Controls v8 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST CSF 2.0 | PR.AA — Identity Management, Authentication, and Access Control | Identity verification depends on proving who is being accepted into the record. |
| Recommendation — Define and enforce identity proofing and authentication rules before accepting a filing or appointment. | ||
| NIST SP 800-63 | IAL — Identity Assurance Level | Companies House verification hinges on the strength of identity proofing and evidence quality. |
| AAL — Authenticator Assurance Level | Verifier confidence depends on how strongly the claimed identity is bound to the presented evidence. | |
| Recommendation — Set the required identity assurance level and reject cases that do not meet it. Require authenticator strength that matches the assurance needed for the transaction. | ||
| CIS Controls v8 | 5 — Account Management | Identity verification failures create weak onboarding and inappropriate acceptance paths. |
| 6 — Access Control Management | Verification quality directly affects who is allowed to act in the company record. | |
| Recommendation — Establish and enforce standard account and identity acceptance checks with documented approval criteria. Restrict acceptance of identity-based actions to cases that satisfy documented control checks. | ||
Practitioner Guidance
What to verify: Treat the decision as a standards problem, not a box-ticking exercise. The reviewer should be able to show which acceptable documents were used, what inconsistencies were checked, and why the final conclusion met the required bar.
Common mistake: Do not let “manual review completed” stand in for assurance. If the reviewer cannot reproduce the rationale from the evidence, the control is too subjective to trust.
Practitioner takeaway: The strongest verification process is the one that produces a defensible decision from consistent evidence, not the one that merely moves a case to completion.
Related resources from NHI Mgmt Group
- What are the main failure points when switching to a new password manager?
- How should security teams reduce cloud breach risk when misconfigurations and access errors are the main failure points?
- What are the main failure points in customer identity deletion workflows?
- What are the main failure points when integrating AI APIs into workflow automation?