Voluntary verification allows directors and PSCs to prove their identity before the requirement becomes compulsory, either directly through GOV.UK One Login or via an ACSP. Mandatory verification means the check must be completed for new appointments, while existing directors and PSCs get a 12 month period to comply. The practical difference is timing, not the underlying identity standard.
What actually changes between voluntary and mandatory verification
For Companies House, the identity check itself does not become a different standard when it moves from voluntary to mandatory. What changes is the obligation to complete it, who must do it, and by when. Voluntary verification is an early option for directors and PSCs; mandatory verification turns that same proofing step into a filing and appointment requirement with a transition period for existing officeholders.
The practical distinction matters because it changes operational sequencing. Under a voluntary model, organisations can spread verification work ahead of deadlines and resolve edge cases before statutory pressure builds. Under a mandatory model, verification becomes part of compliance hygiene, so late appointments and unverified incumbents can create a hard stop or deadline-driven remediation problem.
Who is affected and when the clock starts
In practice, the people most affected are new directors, existing directors, and PSCs. New appointments must satisfy the verification requirement at the point the mandatory regime applies, while existing directors and PSCs are given a 12 month window to comply. That makes timing the main operational variable, not a new identity assurance level or a different substantive check.
Voluntary verification is useful for organisations that want to reduce future friction. It lets directors and PSCs complete the process before a filing event, so the company is not trying to assemble documents, reconcile names, and coordinate approval under deadline pressure. Once mandatory verification is in force, the same work becomes part of the governed lifecycle rather than an optional readiness step.
Risk and Threat Considerations
The main risk is not that mandatory verification changes the identity test, but that delayed completion creates administrative exposure at the point an appointment or filing must proceed. For entities with many appointments, group structures, or frequent PSC changes, missed deadlines can interrupt governance processes and increase the chance of rejected or delayed submissions.
Failure mechanism: The company leaves verification until a mandatory deadline, then encounters bottlenecks in onboarding, evidence collection, or third-party processing, especially where the ACSP route is used and multiple individuals must be coordinated at once.
Impact: Appointments or filings can be delayed, compliance exceptions can accumulate, and management time shifts from routine governance to deadline recovery. For teams that rely on orderly corporate records, the operational risk is most visible when verification becomes a blocking dependency rather than a preparatory task.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
NIST CSF 2.0, NIST SP 800-63 and CIS Controls v8 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST CSF 2.0 | GV.OC-03 — External Dependencies and Relationships | Companies House verification depends on governed external identity evidence and filing relationships. |
| PR.AA-01 — Identity Management, Authentication, and Access Control | The question hinges on identity proofing and whether the same identity standard is applied earlier or later. | |
| GV.RM-03 — Risk Management Strategy | The 12 month transition changes compliance timing and operational risk planning. | |
| Recommendation — Track verification dependencies so appointment and filing processes do not stall at deadline time. Apply a consistent identity proofing process and manage the timing of required verification. Plan remediation windows so mandatory verification deadlines are met without filing disruption. | ||
| NIST SP 800-63 | IAL — Identity Assurance Level | The difference is timing of identity verification, not the underlying identity assurance concept. |
| AAL — Authenticator Assurance Level | The verification process depends on how the identity is proven during onboarding or filing. | |
| FAL — Federation Assurance Level | Voluntary verification may be completed through GOV.UK One Login or via an ACSP-mediated route. | |
| Recommendation — Use the same assurance standard and schedule verification before it becomes compulsory. Choose an approved proofing path and ensure the resulting identity evidence is retained. Validate that any federated or delegated verification path preserves the required assurance. | ||
| CIS Controls v8 | 5.4 — Audit Log Management | Verification status and completion need auditable records for governance and compliance. |
| 6.3 — Access Granting and Revocation | Appointment timing and compliance windows are access governance issues for corporate roles. | |
| Recommendation — Retain auditable proof of who verified, when they verified, and through which route. Grant or maintain role-linked access only after required verification is complete. | ||
Practitioner Guidance
What to prioritise: Treat voluntary verification as a planning window, not as a convenience step. The best use of it is to clear directors and PSCs early, then track remaining unverified individuals against filing and appointment timelines.
What to verify: Confirm which people are already verified, which route they used, and whether any upcoming appointment or PSC change will trigger a mandatory deadline before the 12 month transition ends. Keep that evidence with your corporate records so you can show completion without reconstructing it later.
Common mistake: Assuming that because the underlying identity standard is unchanged, the deadline can be managed informally. In practice, the risk is timing failure, so the control objective is to avoid letting verification become a last-minute dependency on a statutory event.
Practitioner takeaway: Voluntary and mandatory verification are the same check from an assurance perspective, but they demand different operational discipline, early completion turns identity proofing into routine hygiene, while delay turns it into a compliance bottleneck.
Related resources from NHI Mgmt Group
- What is the difference between a graph based identity platform and a tool that only visualizes imported data?
- What is the difference between probabilistic and deterministic identity verification?
- What is the difference between workload identity verification and secret rotation?
- What is the difference between KBA and stronger identity verification methods?