Join our Newsletter — 33% off our NHI Course
Home FAQ Identity Beyond IAM Why do the new Companies House identity checks…
Identity Beyond IAM

Why do the new Companies House identity checks matter for companies and their advisers?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated September 19, 2026 Domain: Identity Beyond IAM

The new checks matter because they reduce the chance that false or concealed identities are used to set up, run, own, or control UK companies. For advisers, identity verification becomes a legal responsibility, not just a formality. If firms do not adapt their processes, they risk fines, restrictions on company activity, and avoidable onboarding delays for directors and PSCs.

Why the checks matter for company formation and control

Companies House identity checks matter because incorporation, filing and ownership records are only useful if the people behind them are real, traceable and accountable. When identity is verified, it becomes harder to create shell companies, hide beneficial ownership, or misuse UK companies for fraud, laundering or other abuse. That strengthens the reliability of the register itself and the decisions that depend on it.

The practical effect is that identity becomes part of the control environment, not just a compliance step. A stronger register improves trust in directors, persons with significant control and filing histories, which matters for lenders, counterparties, investigators and regulators who rely on Companies House data to assess who is actually responsible for a company’s actions.

For firms that rely on registered company data in onboarding or due diligence, the benefit is also operational: better identity assurance reduces the need to second-guess every record and lowers the odds that a false filing, misdirected appointment or concealed controller will flow downstream into contracts, payments or account setup.

What changes for advisers, accountants and formation agents

For advisers, the change is not just that they must ask for more evidence. They need a process that can prove who was checked, when, by whom and on what basis. That shifts the work from informal admin to a governed control, because failure to verify properly can create legal exposure, delay incorporations, and undermine the adviser’s own standing with the client and the registrar.

This is especially important where advisers act as a gatekeeper for high-volume onboarding. If identity checks are bolted onto an existing workflow without clear ownership, firms can end up with inconsistent evidence, weak exceptions handling and avoidable bottlenecks. The risk is not only non-compliance, but also friction when a legitimate director or PSC cannot be processed quickly because the firm cannot evidence the check.

In practice, advisers should treat the change as an operating model issue: the control must be repeatable, auditable and proportionate to volume. That means embedding the checks into client intake, document review, escalation and record retention, rather than relying on individual staff judgment each time.

Why this is an identity control, not just a filing rule

Identity verification matters here because the main failure mode is impersonation, concealment or delegated misuse of authority. The control is designed to reduce the chance that an unverified individual can form, direct or obscure control of a company through a legal registration process. For practitioners, that makes the regime closer to access governance than to simple paperwork.

NHIMG’s Ultimate Guide to NHIs is useful background because it shows how weak identity governance creates downstream risk, especially when credentials, ownership and lifecycle controls are poorly managed. The same basic lesson applies here: if identity is not governed at the point of entry, every later record and decision inherits that weakness.

The broader lesson is that identity assurance has to be maintained over time, not only at incorporation. Changes in directors, PSCs, agent relationships and filing authority can all reopen the same trust problem if the organisation does not revisit evidence, authority and record accuracy when circumstances change.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

CIS Controls v8, NIST CSF 2.0 and NIST SP 800-63 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
CIS Controls v85 — Account ManagementCompany verification depends on trustworthy account and role onboarding.
6 — Access Control ManagementAdvisers need controlled authority for filings and ownership changes.
Recommendation — Enforce account verification and access approval before creating or changing company records. Restrict filing and ownership changes to approved, traceable users and workflows.
NIST CSF 2.0PR.AA — Identity Management, Authentication, and Access ControlIdentity assurance underpins reliable company registration and filing records.
GV.RM — Risk Management StrategyThe checks reduce fraud, concealment, and compliance risk in company records.
Recommendation — Apply identity assurance controls to validate who can create, update, or control company data. Treat Companies House identity verification as part of the organisation's risk governance model.
NIST SP 800-63IAL — Identity Assurance LevelThe question centers on how strong identity proofing affects trust in records.
Recommendation — Use appropriate identity assurance evidence for the role and risk of the filing action.

Practitioner Guidance

What to verify: Firms should verify not only that a person was checked, but that the check is linked to the correct role, client entity and date. A valid process needs an auditable trail for directors and PSCs, plus a clear rule for when higher scrutiny is required because the ownership or control structure is complex.

Implementation sequence: Start by mapping which client journeys touch Companies House filings, then assign ownership for evidence collection, approval, exception handling and retention. After that, make sure staff can stop an onboarding or filing when the identity evidence is incomplete rather than bypassing the control to keep volume moving.

Common mistake: Treating the new requirement as a one-time onboarding task. The real operational risk appears when firms assume a checked identity stays trustworthy indefinitely, even though appointments, control changes and agent relationships can change the answer later.

Practitioner takeaway: The firms that do best will treat Companies House verification as a governed identity control with clear evidence and escalation, not as a form to clear at the last minute.

Deepen Your Knowledge

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Reviewed and updated by the NHIMG editorial team on September 19, 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org