Join our Newsletter — 33% off our NHI Course

Authorised Corporate Service Provider

An Authorised Corporate Service Provider is a regulated intermediary that can carry out identity verification checks for Companies House on behalf of clients. In this context, the role sits within an AML supervised framework and carries legal responsibility for verifying directors and persons with significant control to the required standard.

What an Authorised Corporate Service Provider does

An Authorised Corporate service provider is not just a filing intermediary. It performs regulated identity verification for Companies House, so the role is tied to evidencing who a director or person with significant control is, and doing so to the required standard under supervised AML obligations.

That makes the term part corporate compliance, part identity assurance, and part legal accountability. The value of the role is not simply submitting forms; it is converting an external client relationship into a verified corporate record that can withstand regulatory scrutiny.

Why the role matters in corporate transparency

The ACSP model exists because corporate registers depend on trust in the verifier, not just trust in the person being verified. If the verification step is weak, false or incomplete, the downstream company record can carry misleading ownership or control information.

That matters for incorporation, officer appointments, beneficial ownership checks, and broader anti-financial-crime controls. In practice, the ACSP sits between the client and the state registry, so its quality directly influences the reliability of company data used by regulators, counterparties, and due diligence teams.

Verification duties, records, and accountability

An ACSP must be able to justify how identity was checked, what evidence was relied on, and why the outcome met the expected standard. The operational challenge is not merely collecting documents, but keeping the verification process consistent, auditable, and defensible when questions arise later.

That is why documentation, internal review, and evidence retention matter. A weak process can create a gap between the apparent legitimacy of a filing and the actual confidence the verifier should have had in the client’s identity.

Where corporate service providers handle high volumes, governance becomes as important as the individual case decision. The organisation needs a clear ownership model for who can verify, who can approve exceptions, and who is accountable when a verification fails.

Common control failures and what they affect

The biggest failure mode is overreliance on the process becoming routine. If verification becomes a box-ticking exercise, the provider can miss mismatches, synthetic identities, or incomplete beneficial ownership evidence, and those errors can flow directly into the public record.

Another risk is inconsistency between staff, channels, or client types. A provider that applies different standards depending on volume, urgency, or customer pressure can weaken both compliance and trust in the registry outcome.

For practitioners, the point to remember is that the ACSP role is only as strong as the verification discipline behind it. The designation creates authority, but the actual protection comes from evidencing the identity check, not assuming the label itself is enough.

Risk and Threat Considerations

Because an ACSP can influence what Companies House accepts as verified, weakness in the role can be abused to legitimise false corporate data, obscure control, or support misuse of the company register. The risk is not only regulatory non-compliance, but also the possibility that inaccurate verification helps bad actors create a veneer of legitimacy.

Failure mechanism: inadequate checks, poor recordkeeping, or inconsistent review can allow fabricated or misrepresented identities to pass through a trusted intermediary and into statutory records.

Impact: that can undermine corporate transparency, increase exposure to fraud or money laundering typologies, and leave the provider facing supervisory, legal, and reputational consequences.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

CIS Controls v8, NIST CSF 2.0 and NIST SP 800-63 set the technical controls, while DORA define the regulatory obligations.

Framework Control / Reference Relevance
CIS Controls v8 CIS 5 — Account Management ACSP verification depends on controlling who may create and manage trusted corporate records.
CIS 6 — Access Control Management The role relies on ensuring only authorised staff can approve identity checks and related submissions.
CIS 8 — Audit Log Management ACSPs need traceable evidence of how identity checks were performed and approved.
Recommendation — Restrict and review who can perform ACSP verification and filing actions. Enforce least-privilege access for staff who handle verification evidence and filings. Log verification steps, reviewer actions, and submission outcomes for auditability.
NIST CSF 2.0 GV.RM-01 — Risk Management Strategy ACSPs must manage the compliance and trust risk created by identity verification on behalf of clients.
PR.AA-01 — Identity Management, Authentication, and Access Control The term centers on verifying who a corporate actor is before records are accepted.
DE.CM-01 — Continuous Monitoring Providers need ongoing oversight to detect process drift and repeated verification weakness.
Recommendation — Define risk ownership and escalation for verification failures and exceptions. Apply controlled identity verification before submitting corporate filings. Monitor verification quality and flag unusual filing or exception patterns.
NIST SP 800-63 IAL-2 — Identity Assurance Level 2 Identity verification for regulated filings aligns with assurance-driven identity proofing concepts.
IAL-3 — Identity Assurance Level 3 Higher-risk corporate verification scenarios may require stronger identity proofing and evidence.
AAL-2 — Authenticator Assurance Level 2 ACSP portals and staff workflows need stronger access assurance for regulated actions.
Recommendation — Use an assurance-based verification standard proportionate to the filing risk. Escalate verification strength for higher-risk or higher-impact corporate cases. Require stronger authentication for staff actions that approve or submit verified records.
DORA ICT third-party risk management — ICT Third-Party Risk Management ACSPs act as trusted intermediaries whose control quality affects regulated records and downstream trust.
Recommendation — Assess and govern third-party verification providers as regulated control dependencies.

Practitioner Guidance

Governance implication: ACSPs should treat verification as a controlled compliance function, not an administrative convenience. The provider needs clear ownership for standards, escalation, and exception handling so that identity checks remain defensible under supervision.

What to watch for: repeated edge cases, rushed onboarding, or a growing reliance on manual judgement without clear evidence can signal that the process is drifting away from the required standard. That is usually where verification quality starts to erode first.

Practitioner takeaway: if the ACSP cannot explain and evidence the verification path, it should assume the control failed, even if the filing itself was accepted.