Companies House identity verification is no longer a future reform that boards can leave with the company secretary.
The legal requirement began on 18 November 2025. Existing directors and people with significant control are now moving through a transition period, with individual deadlines linked to confirmation statements, company roles and personal circumstances.
For many businesses, the important date is therefore not a single national deadline. It is the company’s own next confirmation statement and the separate verification periods applying to its directors and people with significant control.
That makes this a live governance issue.
A company may have filed correctly for years, but the process now depends on individual directors completing verification, obtaining their personal codes and linking those codes to the correct company roles.
If one person is not ready, the filing process may be delayed. If responsibilities are unclear, the company may discover the problem only when its confirmation statement is due.
For ACCA SBR candidates, this is an excellent example of how a legal reform becomes a corporate governance, internal control and ethical issue.
Those developing their answers with an ACCA SBR tutor should be able to explain not only what the rule requires, but how a competent board should manage the risk.
The first mistake is treating 18 November as the deadline
The identity verification requirement became legally effective on 18 November 2025.
However, that date was the beginning of the transition process, not a single deadline by which every existing director and person with significant control had to complete every step.
Different people have different due dates.
An existing director must provide their Companies House personal code as part of the company’s next confirmation statement.
A person with significant control, usually referred to as a PSC, may have a separate 14-day period in which to provide their code.
This distinction matters because the same person can be both a director and a PSC.
In that situation, completing the director requirement does not automatically complete the PSC requirement. The personal code may need to be provided separately for each role.
A board that assumes one verification action covers everything could therefore leave an obligation incomplete.
The practical lesson is simple.
Companies should not ask only whether their directors have verified their identities. They should ask whether every relevant person has linked their verified identity to every role they hold.
What directors now need to do
Once an individual successfully verifies their identity, they receive a personal code.
That code belongs to the individual, not to the company.
A person who is a director of several companies does not need to complete a new identity check for every appointment. They can use the same personal code for each company role.
However, the code must still be provided in connection with each appointment.
For an existing director, this normally happens through the company’s next confirmation statement.
For a new company, the code is required as part of the incorporation process. Where a person becomes a director of an existing company, the verification information must be addressed as part of the appointment.
This creates an important distinction between identity verification and role confirmation.
The person verifies who they are once. They then use their personal code to connect that verified identity to the relevant company positions.
Boards need to understand both steps.
Knowing that a director has completed GOV.UK One Login is not enough if the company has not obtained the information needed for its filing.
PSC deadlines need separate attention
The requirements for people with significant control can be less straightforward.
Where a person is both a director and a PSC of the same company, the director code is provided through the confirmation statement.
The PSC code must be provided separately during a 14-day period starting on the day after the company’s confirmation statement date.
This timing does not necessarily change if the company files its confirmation statement early.
That means an early filing should not be treated as automatically moving the PSC verification window.
Where an existing PSC is not also a director, the relevant period is generally the first 14 days of the individual’s birth month.
A new PSC can usually provide their personal code when they are first added to the register or within the applicable 14-day period following registration.
These different routes create a genuine compliance risk.
A business may have directors, individual shareholders, parent company representatives and other controllers whose deadlines do not all fall on the same date.
A central record is therefore essential.
Without one, the company may know that people have verified their identities but still fail to provide the codes at the correct time.
This is not only the company secretary’s problem
It may be tempting for directors to view identity verification as an administrative filing task.
That would be a mistake.
The rules concern the identity of the people running, owning and controlling UK companies. They are part of wider reforms intended to improve the reliability of the companies register and make it harder to misuse corporate structures.
That gives the issue clear governance significance.
The board is responsible for ensuring that the company has suitable systems for meeting its legal obligations.
A company secretary, accountant or authorised agent may manage the process, but the board cannot transfer ultimate responsibility simply by assigning the task to someone else.
Directors should understand what must be done, who is responsible for each stage and how the board will know that the requirements have been completed.
A good governance process should provide assurance before the deadline, not an explanation after it has been missed.
The confirmation statement has become a control point
For existing directors, the next confirmation statement is now a critical control point.
The company should identify its due date well in advance and work backwards.
Waiting until the filing is being prepared creates unnecessary risk. A director may have problems verifying their identity, may not have suitable documents readily available or may discover that personal information does not match the Companies House register.
A director based overseas may need additional support. A group containing several companies may have different confirmation statement dates. A dormant company may receive less management attention even though its directors still have obligations.
The board should therefore treat the confirmation statement as part of the annual governance calendar.
Identity verification should sit alongside other scheduled checks, such as reviewing registered office details, director appointments, PSC information and share capital records.
The aim is to identify problems while there is still time to solve them.
The board needs a simple verification register
A company does not need an unnecessarily complicated system.
It needs a reliable record showing who is affected, what roles they hold, whether they have verified their identity and when the personal code must be provided.
A practical register could contain:
- The name of every director and PSC
- Each company role held by that person
- Whether identity verification has been completed
- The date the personal code was received
- The company’s confirmation statement date
- The separate PSC verification period, where applicable
- The person responsible for submitting the information
- Confirmation that each role has been linked successfully
- Any mismatch, delay or exception requiring follow-up
The register should cover the full group where relevant.
A director who sits on the boards of five group companies may need the same personal code connected to five separate appointments.
Tracking only the individual and not the appointments could create a false impression that the work is complete.
Personal codes need to be handled carefully
A Companies House personal code is intended to connect an individual’s verified identity to their company roles.
It should therefore be managed carefully.
The code is personal to the director or PSC, but it may need to be shared with the person filing on their behalf. This could be a company secretary, accountant, solicitor or authorised corporate service provider.
The company should have a clear process for receiving, storing and using these codes.
They should not be circulated casually through long email chains or stored in an uncontrolled spreadsheet that can be accessed by people with no role in the filing process.
Access should be limited to those who genuinely need the information.
The business should also know what to do if a code is believed to have been compromised.
This is a basic information security issue as well as a filing requirement.
An SBR answer could connect this directly to internal controls. Sensitive information should be protected through restricted access, secure storage and clear responsibility for its use.
Data mismatches can create last-minute problems
Identity verification depends on the personal information used during the verification process matching the information held by Companies House.
Problems may arise where a name has changed, a date of birth is incorrect or an authorised agent has submitted inaccurate information.
These are not issues a company wants to discover on the day of filing.
The board should make sure affected individuals review their Companies House information early.
Where the details are wrong, the records may need to be corrected before the personal code can be connected successfully.
This is another reason why the process should begin well before the confirmation statement deadline.
A failed verification attempt should trigger investigation, not repeated attempts using slightly different information.
The company needs to understand whether the problem sits with the identity documents, the Companies House record, the verification account or information submitted by an agent.
Groups face a larger coordination problem
Identity verification becomes more complicated in a group structure.
The same individual may be a director of several subsidiaries. Different subsidiaries may use different accountants or company secretarial providers. Confirmation statement dates may be spread across the year.
A group-level approach can reduce this risk.
The parent company should maintain visibility over verification across all UK entities, even where local teams manage the actual filings.
Without central oversight, one subsidiary may assume another team has obtained the director’s code. An agent may know that a director has verified their identity but not realise that the individual holds appointments in other group companies.
The issue becomes particularly important during acquisitions.
When a company joins a group, the buyer should review the identity verification status of its directors and PSCs as part of the governance handover.
The same applies when directors are appointed or removed as part of a restructuring.
Identity verification should be built into the appointment process rather than treated as a separate job that someone will complete later.
Boards should review their relationship with external agents
Many companies rely on accountants, solicitors or company formation agents to manage Companies House filings.
That arrangement may continue, but boards should confirm that responsibilities are clear.
The company should know whether the agent is authorised to complete the relevant work, what information it requires and when it needs to receive personal codes.
It should also understand which tasks remain with the individual director or PSC.
Using an agent does not remove the need for internal oversight.
A company should not assume that the agent will chase every director, identify every PSC deadline and correct every mismatch without clear instructions.
The engagement should define responsibilities.
The company should also maintain its own record of completed filings and verification status rather than depending entirely on information held by the agent.
Good outsourcing keeps accountability visible.
Poor outsourcing creates a gap where both parties assume the other is managing the risk.
The reform is designed to improve trust in the register
The Companies House register is used by lenders, investors, suppliers, customers, advisers and enforcement bodies.
Its value depends on the accuracy and reliability of the information it contains.
Identity verification is intended to make it harder for people to create companies or take control of existing companies using false or stolen identities.
For legitimate businesses, that should improve confidence in the register.
However, the benefit depends on organisations treating the process seriously.
A company that misses its own obligations cannot argue that identity verification is only relevant to suspicious businesses.
The rules apply to normal companies and responsible directors as part of the wider effort to protect the integrity of the corporate system.
A strong board should therefore present compliance as part of good governance, not as an inconvenience imposed on honest businesses.
Non-compliance can affect more than the filing
Missing the requirement can create legal and operational consequences.
The company may face difficulty completing filings. The individuals involved may expose themselves to enforcement action or financial penalties. Delays may also affect transactions that depend on an accurate and current Companies House record.
The reputational impact should not be ignored.
A lender, investor or purchaser carrying out due diligence may question why a company has not complied with a basic legal requirement concerning its directors and controllers.
The failure could suggest wider weaknesses in governance and record keeping.
That does not mean every administrative error indicates serious misconduct.
It does mean the board should recognise how the failure may appear to outsiders.
Good compliance protects the company from both the direct consequence and the negative inference.
This creates a useful SBR governance scenario
For SBR candidates, a scenario might describe a company approaching its confirmation statement date without all directors having completed verification.
The company secretary may have sent reminders, but one director has not responded. Another director may have verified their identity but not supplied their personal code. A PSC may wrongly believe the director filing covered both roles.
A weak answer would simply state that the company should comply with Companies House requirements.
A stronger answer would identify the governance and control failures.
The board has not assigned clear responsibility. There is no central record of roles and deadlines. The process relies on informal reminders. There is no escalation procedure where an individual fails to act.
The answer should then recommend practical action.
Management should identify every director and PSC, confirm the relevant deadlines, obtain the necessary personal codes and escalate outstanding cases to the chair.
The company should maintain a verification register and include the process within its annual compliance calendar.
This is applied, board-ready advice.
There is also an ethical dimension
Professional accountants involved in the process have ethical responsibilities.
They should act with integrity and professional competence. They should not submit information they know is incomplete or inaccurate simply to meet a filing deadline.
They should also protect confidential information and explain the consequences of non-compliance clearly to the board.
A difficult situation may arise if a director refuses to verify their identity or asks the accountant to submit a filing without the required information.
The accountant should not allow pressure from a senior individual to override legal and professional obligations.
The matter should be documented and escalated through the appropriate governance structure.
Where necessary, the professional accountant may need to obtain legal or professional advice.
The key exam point is that the accountant’s responsibility is not limited to processing whatever information management provides.
Professional competence includes recognising when a filing cannot properly proceed.
How to write about identity verification in SBR
Candidates should avoid turning an answer into a detailed explanation of the verification service.
The exam is more likely to reward discussion of governance, internal control, ethics and accountability.
A strong paragraph might read:
The approaching confirmation statement creates a compliance risk because not all directors have provided their personal codes. The company secretary should maintain a central register of directors, PSCs and relevant deadlines, with unresolved cases reported to the board before the filing date. This will reduce the risk of an incomplete filing and demonstrate appropriate oversight of the company’s legal obligations.
That paragraph identifies the risk, applies it to the scenario and recommends a control.
Candidates following an ACCA SBR course should practise this type of concise, applied answer rather than memorising every administrative detail.
The immediate board actions
Boards should now establish whether every relevant individual has completed identity verification.
They should check the date of the next confirmation statement, identify separate PSC deadlines and make sure personal codes are available to the person responsible for filing.
They should also review whether directors hold roles in other group companies and whether those appointments have been addressed.
Any mismatch in personal information should be investigated promptly.
Where an external agent is involved, responsibilities and timescales should be confirmed in writing.
Finally, the board should require evidence that each role has been linked successfully rather than relying on verbal assurances that the individuals have “done the verification”.
A governance reform not an admin update
Companies House identity checks may appear procedural, but the underlying issue is trust.
The reforms are intended to provide greater confidence that the people shown as directing and controlling UK companies are who they claim to be.
That makes compliance a board responsibility.
The deadline that matters will depend on the person, the role and the company’s filing timetable. This is precisely why boards cannot afford to ignore it.
A business that begins early can resolve mismatched information, coordinate multiple appointments and give its advisers enough time to complete the filings correctly.
A business that waits may discover too late that verification is only the first step and that each relevant role still needs to be connected.
The practical message is clear.
Identify the people. Map the roles. Record the deadlines. Obtain the codes. Confirm the filings.
That is how a board turns a changing legal requirement into a controlled governance process.

