Identity Verification for Law Firms: The Definitive UK Guide to ECCTA, KYC and Client ID

Identity Verification for Law Firms: The Definitive UK Guide to ECCTA, KYC and Client ID

Identity verification used to be a quiet corner of a law firm’s onboarding process — collect a passport, take a copy, tick a box. It is now one of the most demanding and fastest-moving compliance areas a UK firm faces, and the change has happened in a remarkably short space of time. Two forces are responsible, and understanding that there are two — not one — is the single most important thing a firm can grasp about this subject.

The first is the long-standing anti-money laundering duty to verify a client’s identity before acting. The second, and genuinely new, is a statutory regime under the Economic Crime and Corporate Transparency Act 2023, which makes identity verification with Companies House mandatory for company directors, people with significant control, and members of limited liability partnerships. This second regime arrived with hard deadlines and an enormous affected population: over seven million existing directors and PSCs need to verify with Companies House, and commentary ahead of the November 2025 commencement suggested only around 58% felt fully prepared.

For law firms this is not a distant regulatory abstraction. Firms are affected directly and in two capacities: as advisers whose corporate clients must verify, and — for many firms — as Authorised Corporate Service Providers who can carry out and certify that verification themselves. The decisions a firm makes here, over the next year, will shape both its compliance exposure and its ability to keep filing on clients’ behalf.

This guide is the definitive reference on identity verification for UK law firms. It separates and explains the two regimes, sets out the ECCTA deadlines and mechanisms in detail, explains who can verify identity and by what methods, addresses the ACSP decision squarely, and confronts the real administrative burden these overlapping duties create. It is written for solicitors, COLPs, MLROs and practice managers, and draws throughout on Law Society guidance, Companies House rules, and the underlying legislation.

A note on who wrote this. This guide is published by OnBoardNow, which makes client onboarding software with built-in identity verification for regulated UK firms. We have a commercial interest in this area and have stated it. The guidance below is drawn from the Law Society, Companies House and the legislation, not from our product; where technology is relevant we say so and label it. Read every vendor-published guide with that interest in mind, this one included.

The Central Distinction: Two Kinds of Identity Verification

Almost every confusion in this area dissolves once one distinction is firmly held: “identity verification” now means two related but legally separate obligations, with different sources, standards, supervisors and consequences. A firm that blurs them will misjudge what it needs to do.

AML client verification. Under the Money Laundering Regulations 2017, a firm carrying out regulated work must verify the identity of its client as part of customer due diligence, before acting. This obligation is long-standing, applies to the firm’s own clients, is owed by the firm, and is supervised by the SRA. Its purpose is to prevent the firm being used as a conduit for money laundering.

ECCTA Companies House verification. Under the Economic Crime and Corporate Transparency Act 2023, individuals who are company directors, PSCs, or LLP members must verify their identity with Companies House to a prescribed standard. This obligation is new, attaches to those individuals in their corporate roles rather than to any particular retainer, and is administered by Companies House. Its purpose is to clean up the company register and stop UK corporate structures being used to hide illicit activity.

The two overlap in practice — a firm onboarding a corporate client is often dealing with individuals who each carry their own ECCTA obligation — but they remain distinct legal requirements. The standards differ: the Companies House standard under ECCTA is, in important respects, higher and more prescriptive than the traditional AML identity check. The supervisors differ: SRA for AML, Companies House for ECCTA. And the consequences of failure differ. A firm must satisfy both, and — this is the practical sting — a verification process built only for the old AML baseline may not meet the Companies House standard an ACSP must apply. Treating the two as one is how firms end up compliant with neither.

The ECCTA Identity Verification Regime in Detail

ECCTA represents the largest change to Companies House since company registration began in 1844. Its animating idea is a shift in the register’s character: from a passive repository that accepted and published whatever it was told, to an active gatekeeper with power to verify identities, query filings, and penalise non-compliance. Mandatory identity verification is the centrepiece of that shift, and it is being introduced in phases.

Who Must Verify, and by When

The phased rollout has specific dates, and getting them right matters because the consequences of missing them are serious.

WhoThe requirementTiming
New directors and PSCsMust verify identity before the appointment can be filedFrom 18 November 2025
Existing directors and PSCsMust verify as part of the next confirmation statement12-month transition from 18 November 2025
LLP members and general partnersWithin scope of the verification requirementIn line with the phased rollout
Anyone filing at Companies HouseFilers must be verified, or file through an ACSPFrom spring 2026
Corporate directorsVerification of the underlying individualsLater phase; date to be confirmed

The mechanism at the centre of the regime is the personal code. Once an individual verifies — whether directly with Companies House or through an ACSP — they receive a unique identifier that Companies House calls a personal code. Crucially, only one code is required per person, no matter how many directorships or LLP memberships they hold, and that code is supplied on relevant filings as confirmation that verification is complete. This is why the obligation is best understood as a one-time verification of the person, not a per-appointment task.

From spring 2026 a further and, for law firms, pivotal restriction takes effect: the range of individuals who may file documents at Companies House on a company’s behalf narrows to a verified officer or employee of the company, or an ACSP. This is the change that most directly affects firms that file for clients — without ACSP status, they will lose the ability to do so.

What Happens If the Deadline Is Missed

The consequences are not administrative footnotes. For individuals, failing to verify within the required timeframe risks criminal prosecution and civil financial penalties, and ultimately a company can be struck off the register. There is also an operational consequence that bites immediately: a director’s appointment cannot be filed at all unless the director has verified, which means non-compliance can freeze corporate activity rather than merely attract a later penalty.

For existing directors and PSCs, the 12-month transition means verification is due by the next confirmation statement falling within that window — which, for many companies, lands at various points across 2026. The practical risk is a last-minute scramble. Firms advising corporate clients are well advised to prompt directors to obtain their personal codes well ahead of the confirmation statement date, rather than discovering at filing time that a director is unverified and the filing cannot proceed.

Should a Law Firm Become an Authorised Corporate Service Provider?

ECCTA creates a role that many firms will need to decide about deliberately rather than drift into: the Authorised Corporate Service Provider. For firms that file at Companies House on clients’ behalf, this is close to a forced decision, and it deserves careful thought.

An ACSP is a business — a law firm, accountancy practice, or company secretarial provider — that is supervised for AML and authorised by Companies House to verify identities and file on clients’ behalf. When an ACSP verifies an individual, it delivers a verification statement to Companies House, the individual is treated as verified, and Companies House issues the personal code. The ACSP’s own unique identifier is attached to filings it makes, confirming the checks were done.

The use of ACSPs is expected to become the primary route for many companies, precisely because of the spring 2026 filing restriction: once filings by unverified individuals are refused unless routed through an ACSP, companies that rely on their solicitor or accountant to file will need that adviser to be an ACSP. For a firm that files for clients, the logic is therefore stark — register as an ACSP, or lose the ability to provide a service clients currently expect.

But ACSP status is not free of obligation, and a firm should weigh what it takes on. The firm must be supervised for AML. It must carry out identity verification to the Companies House standard — which, to repeat the point that firms most often miss, is higher and more prescriptive than the traditional AML check. And it takes on responsibility for the verifications it certifies: a verification statement is a representation to Companies House, with the accountability that implies. The decision, then, is not merely “do we want to keep filing?” but “are we equipped to verify to the required standard, reliably and at the volume our client base generates?” For many firms the answer will be yes, but it should be a considered yes, with the process built to match the standard.

Who Can Verify My Identity for Solicitors?

This is one of the most common questions clients ask their solicitors, and a precise answer depends on which of the two regimes is in play — a distinction the question itself usually does not draw.

For ECCTA Companies House verification, there are effectively three routes. First, an individual can verify directly with Companies House using the GOV.UK One Login service. Second, they can verify through an Authorised Corporate Service Provider — a solicitor, accountant, or other AML-supervised provider authorised for the purpose. Third, where the firm itself acts as an ACSP, the firm carries out the verification and files the verification statement on the individual’s behalf. All three routes lead to the same outcome: a verified identity and a personal code.

For a firm’s own AML client verification, the position is different. The firm itself is responsible for verifying its client’s identity as part of customer due diligence. It may use electronic identity verification tools to do so, and in limited, defined circumstances it may rely on verification carried out by another regulated party — but reliance does not transfer responsibility. If the firm relies on another’s verification and that verification was inadequate, the firm remains accountable to its supervisor. The responsibility for adequacy stays with the firm regardless of the tool or the third party used.

So the plain answer to a client asking “who can verify my identity?” is: for Companies House purposes, either GOV.UK One Login directly, or a regulated professional acting as an ACSP; for the law firm’s own AML checks, the firm itself, usually with the help of an electronic verification service. A regulated professional supervised for AML — a solicitor or accountant, registered as an ACSP where Companies House verification is involved — is the usual answer that covers both.

What Are the Methods a Firm Can Use to Verify an Individual?

A recurring question concerns the accepted methods for verifying an individual’s identity. In broad terms there are three, and a firm will frequently combine them depending on the assurance required.

MethodHow it worksWhere it fits
DocumentaryChecking a government-issued document (passport, driving licence) plus proof of addressThe traditional baseline; still valid but the weakest
Electronic / digitalA digital identity service checks documents and data against authoritative sourcesIncreasingly the default; scalable and auditable
Biometric with livenessFacial matching against the document plus a liveness check confirming a real, present personThe strongest; resists document fraud and deepfakes

The direction of travel is decisively toward electronic and biometric verification, and the reasons are worth understanding rather than merely noting. Documentary verification alone — receiving and checking a copy of a passport — establishes that a document exists and appears genuine. It does not establish that the person presenting it is the person the document describes, or that they are even present rather than a fraudster holding someone else’s papers. Electronic verification improves on this by checking the document and the person’s data against independent authoritative sources. Biometric verification with liveness detection goes furthest: it matches the presenter’s face to the document and confirms, through a liveness check, that a real person is genuinely present rather than a photograph, a screen recording, or a synthetic image.

This last capability has become materially more important because of deepfake identity fraud. As synthetic media improves, a photograph of a document — or even a video that is not liveness-checked — can be forged convincingly enough to defeat a documentary or naive digital check. Biometric verification with liveness detection is the current answer to that threat, which is why it is becoming the standard for higher-assurance verification and why regulators increasingly ask not merely whether a firm verifies identity, but by what method. A firm still relying solely on document copies is using the method most exposed to the fraud that is growing fastest.

The Growing Burden on Firms — and How to Contain It

Law Society guidance and commentary across the profession have been candid that these combined obligations amount to a growing burden on legal advisers, and it is worth being precise about why, because naming the problem accurately points to the solution.

A firm now potentially carries three overlapping identity responsibilities. It must verify its own clients for AML purposes. It must help or require its corporate clients’ directors and PSCs to meet their ECCTA obligations, and manage the risk that an unverified director derails a filing. And, if it acts as an ACSP, it must itself perform and certify Companies House verifications to a prescribed standard. Each has its own rules, its own standard, and — for the ECCTA elements — hard deadlines and a very large affected population arriving in a compressed period.

The load falls disproportionately at the point of client onboarding, and this is precisely where firms have historically been weakest. The SRA’s AML findings describe a profession that was already struggling with the manual version of identity and due diligence work before ECCTA added to it: across thousands of files reviewed, a substantial proportion showed inadequate client verification or risk assessment, and the failures were concentrated in exactly the onboarding steps ECCTA now makes more demanding. Adding a second, higher-standard verification regime on top of a manual process that was already failing is a recipe for gaps.

Done by hand, the work is slow and error-prone: collecting documents, checking them, recording the outcome, chasing the client for what is missing, tracking which director has a personal code and which does not, and reconstructing the audit trail when an inspector or a filing deadline arrives. This is the case for systematising identity verification rather than handling it document by document. A process that verifies electronically to the required standard, keeps the audit trail automatically, works for both AML client verification and — where the firm is an ACSP — Companies House verification, and tracks verification status across a client base, turns a mounting burden into a routine, repeatable step. The alternative is more manual work at exactly the point the regulators inspect most closely and exactly when the ECCTA deadlines are biting. The burden is real; the response is process design.

Frequently Asked Questions

Who can verify my identity for solicitors?

It depends on which verification is involved. For Companies House (ECCTA) verification, you can verify directly with Companies House using GOV.UK One Login, or through an Authorised Corporate Service Provider — a solicitor, accountant or other AML-supervised provider authorised for the purpose. For a law firm’s own AML client checks, the firm verifies your identity itself, usually with an electronic identity service. So the usual answers are: a regulated professional supervised for AML (and registered as an ACSP where Companies House verification is needed), or the direct GOV.UK One Login route. A regulated professional acting as an ACSP is the option that covers both regimes at once.

What are the top 10 KYC companies?

There is no authoritative single ranking, and the right choice depends on the sector and the specific need rather than on a generic top-ten list. The KYC and identity verification market includes providers focused variously on financial services, on legal and property, and on Companies House ECCTA verification specifically. For a UK law firm, the questions that actually determine the right provider are: does the tool verify to the Companies House standard (if the firm acts as an ACSP); does it offer biometric liveness detection to resist fraud; does it screen for AML, PEP and sanctions alongside identity; and does it integrate with the firm’s case management system. Evaluate providers against those criteria and your supervisor’s expectations rather than against a popularity list that will be out of date and may not reflect UK legal-sector needs.

Do LLP members have to verify identity?

Yes. Under ECCTA, the identity verification requirement extends to members of limited liability partnerships and to general partners, not only to company directors and PSCs. The requirement applies regardless of the individual’s nationality or place of residence. LLP members are brought within the regime as part of its phased rollout, and, as with directors, only one personal code is needed per individual no matter how many appointments or memberships they hold. An LLP that assumes the rules apply only to companies has misread the scope.

What are three methods a firm can use to verify the identity of an individual?

Three broad methods. First, documentary verification: checking a government-issued document such as a passport or driving licence, usually alongside proof of address. Second, electronic or digital verification: a digital identity service checks the document and the individual’s data against independent authoritative sources. Third, biometric verification with liveness detection: facial matching against the document plus a check confirming a real, present person rather than a photograph or synthetic image. Firms increasingly favour the electronic and biometric methods because they scale better, produce a stronger and more consistent audit trail, and resist the document fraud and deepfakes that defeat simple documentary checks.

What is the difference between AML verification and ECCTA verification?

AML verification is a firm’s duty under the Money Laundering Regulations 2017 to verify its client’s identity before acting, as part of customer due diligence, supervised by the SRA. ECCTA verification is a separate statutory requirement for company directors, PSCs and LLP members to verify their identity with Companies House to a prescribed standard, administered by Companies House. They overlap when a firm onboards a corporate client, but they are distinct obligations with different standards, supervisors and consequences. A firm must satisfy both, and — importantly — a verification tool built only for the old AML baseline may not meet the higher Companies House standard that an ACSP is required to apply.

Does a law firm have to register as an ACSP?

If the firm files documents at Companies House on clients’ behalf, then in practical terms yes. From spring 2026, filings made by unverified individuals will not be accepted unless routed through an Authorised Corporate Service Provider, so a firm that wants to continue filing for clients will need ACSP status. Becoming an ACSP requires the firm to be supervised for AML and able to verify identity to the Companies House standard. Firms that do not file for clients have less immediate pressure, but many will still find ACSP status valuable for serving corporate clients through the transition. The decision should be deliberate, taken with the required verification standard clearly in mind.

How should a firm verify identity to meet both AML and ECCTA requirements?

The efficient approach is a single onboarding process that verifies to the higher of the two standards and produces one audit trail serving both regimes. Because the Companies House ECCTA standard is more prescriptive than the traditional AML check, a process built to meet it will generally also satisfy the AML client-verification duty. In practice this means using electronic verification, ideally with biometric liveness detection to resist fraud, capturing the evidence and the outcome automatically, and — where the firm is an ACSP — being able to generate the verification statement Companies House requires. Running two separate manual processes for the two regimes duplicates effort and multiplies the chance of a gap; running one process built to the higher standard is both less work and more defensible.

Identity verification has become a multi-layered, actively-supervised obligation for UK law firms, and the firms that navigate it best will be those that grasp its structure rather than reacting to each requirement in isolation. The structure is this: two regimes, not one. The AML duty to verify clients, owed by the firm and supervised by the SRA, continues as before. ECCTA has added a statutory Companies House regime, owed by individuals in their corporate roles, administered by Companies House, running to a higher standard, arriving on hard deadlines, and reshaping who may file — with a new ACSP role that many firms must take on to keep serving clients.

Three actions follow. Understand and separate the two regimes, and satisfy both — conflating them is the root of most errors here. Decide deliberately whether to become an ACSP, recognising that for firms which file for clients the spring 2026 restriction makes it close to mandatory. And verify to the standard the moment requires, using electronic and biometric methods that resist the fraud simple document checks cannot.

Underlying all of it is a shift in what regulators expect: not merely that a firm verifies identity, but that it does so rigorously, to the right standard, and can prove it on demand. Meeting that expectation manually, across two overlapping regimes, at the volume a busy firm generates, is where the gaps appear. Systematising it — one process, built to the higher standard, producing the audit trail automatically, covering both regimes — is what turns a genuine and growing burden into a routine step. The obligations are not going to lighten; the sensible response is to build the process that makes them manageable.

Leave a Reply

Your email address will not be published. Required fields are marked *