ACSPs should first confirm they are registered with an AML supervisory body, then register to conduct identity verification on behalf of clients before the mandatory deadline. They should update client onboarding, evidence collection, and record keeping so directors and PSCs can be verified against the Companies House standard. Planning early reduces compliance risk and avoids last minute disruption when verification becomes mandatory.
What ACSPs need to have ready before the 2025 verification deadline
ACSP preparation is mostly a readiness exercise across eligibility, process design, and evidence handling. The core operational question is whether your firm can reliably verify the right people, keep auditable records, and complete verification without creating onboarding bottlenecks when the change becomes mandatory.
The first practical checkpoint is registration status. If an ACSP is not already set up to perform verification activity, the firm needs to confirm the supervisory requirement, map the internal ownership for the service, and align the client intake journey with the Companies House standard before clients start expecting it as a default step.
The second checkpoint is process scope. Directors and PSCs will need to be handled consistently, which means the ACSP needs a repeatable identity-verification workflow, a clear evidence standard, and a retention approach that supports later challenge or audit. That workflow should be designed to fit into onboarding rather than sit beside it as a separate manual exception path.
For organisations that want a wider governance reference point, the underlying issue is a controlled identity-verification process, not a one-off form check. ACSPs can use Ultimate Guide to NHIs as a broader reference for lifecycle, governance, and evidence discipline, even though the Companies House use case is human identity verification rather than non-human identity management.
How to adapt onboarding, evidence collection, and record keeping
Most of the implementation risk sits in the handoff between client onboarding and verification evidence. ACSPs should decide in advance what evidence is acceptable, how discrepancies are escalated, who approves exceptions, and how the firm proves that verification was completed against the required standard. If those decisions are left until go-live, the process becomes inconsistent and slow.
Client onboarding should be updated so the verification step is not treated as an optional afterthought. In practice, that means collecting the required identity information earlier, validating completeness before submission, and making sure staff understand when a case can move forward and when it must pause. The aim is to avoid rework, not merely to tick a compliance box.
Record keeping needs the same level of discipline. An ACSP should be able to show what was checked, when it was checked, what evidence supported the decision, and who completed it. If the firm already has strong AML controls, that helps, but the verification process still needs its own operating procedure because the Companies House requirement has a specific outcome and a specific deadline.
For teams building a formal operating model, the most useful external benchmark is the regulated identity standard itself, especially where evidence quality and verification assurance matter. eIDAS 2.0, the EU Digital Identity Framework is useful context for how digital identity assurance is being formalised across jurisdictions, while NIST SP 800-63 Digital Identity Guidelines remains a practical reference for assurance, authenticator strength, and identity proofing concepts.
Risk and Threat Considerations
The main risk for ACSPs is not just missing a deadline, it is creating a rushed verification process that produces weak evidence, inconsistent decisions, and avoidable client disruption. If the firm cannot prove how a director or PSC was verified, the compliance exposure persists even if the operational step was completed.
Failure mechanism: Late registration, unclear ownership, and manual ad hoc evidence handling can cause missed deadlines, incorrect verification outcomes, and poor auditability. Those weaknesses tend to surface first when volume rises and teams try to process cases quickly.
Impact: The firm can face regulatory friction, onboarding delays, rework, and loss of client confidence, especially if verification becomes a bottleneck just as it turns mandatory. Well-run processes reduce that risk by making the verification decision repeatable, traceable, and easy to evidence.
Where identity assurance and evidence quality are the dominant concerns, broader control guidance can help shape the operating model. OWASP ASVS is useful as a verification-minded control reference for authentication and access assurance concepts, and FATF Recommendations provide the wider AML and customer due diligence context that many ACSPs already operate within.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
NIST CSF 2.0, CIS Controls v8 and NIST SP 800-63 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST CSF 2.0 | GV.OC — Organizational Context | ACSPs must align verification operations to regulatory obligations and client onboarding context. |
| PR.AA — Identity Management, Authentication and Access Control | Identity verification depends on controlled proofing, evidence collection, and decision assurance. | |
| PR.DS — Data Security | Verification creates sensitive identity records that need retention and protection. | |
| Recommendation — Define ownership, scope, and operating context for Companies House verification before rollout. Establish consistent identity proofing and verification controls for directors and PSCs. Protect verification evidence and retain it in a controlled record-keeping process. | ||
| CIS Controls v8 | 6 — Access Control Management | Verification workflows depend on defined authorization and case-handling roles. |
| 3 — Data Protection | ACSPs must preserve identity evidence without exposing it unnecessarily. | |
| Recommendation — Assign clear roles for who may collect, approve, and retain verification evidence. Store verification records securely and limit access to authorized staff only. | ||
| NIST SP 800-63 | 3 — Digital Identity Guidelines | The change is fundamentally about identity proofing and assurance outcomes. |
| Recommendation — Use assurance concepts to set acceptable verification evidence and decision thresholds. | ||
Practitioner Guidance
What to prioritise: Confirm whether you are already in the right supervisory position to offer the service, then lock the operational owner for registration, process changes, and evidence retention. That sequence matters because process design is pointless if the firm cannot lawfully or practically deliver the service.
What to verify: Test the end-to-end journey with a real case, from initial intake to retained record, and verify that staff can show exactly what was checked against the Companies House standard. If the evidence trail is ambiguous, the process is not ready, even if the case was technically completed.
Common mistake: Treating the change as a compliance date only. The real implementation issue is throughput and consistency, so the firms that do best are the ones that redesign onboarding early enough to absorb demand without creating last-minute queues.
Practitioner takeaway: The goal is to make verification a routine, auditable service step, not a manual exception process that only works when volumes are low.
Related resources from NHI Mgmt Group
- How do identity teams prepare for agent verification without confusing it with human identity checks?
- Why do regional identity verification tools become a risk as companies expand internationally?
- How should security teams handle identity verification when trust changes after login?
- How should organisations prepare identity verification for AMLR and eIDAS 2.0?
Deepen Your Knowledge
Reviewed and updated by the NHIMG editorial team on September 19, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org