← CompanyProof Journal

KYB AND COMPLIANCE

Companies House One Login turns registry access into a control problem

Companies House One Login is now an access-control issue for KYB and compliance teams, not just a sign-in change. Map users, codes and filing deadlines before registry workflows fail.

26 August 202611 minute read2,262 words
Companies House One Login turns registry access into a control problem — CompanyProof Research

Why this is material now

Companies House One Login became a near-term registry operations issue on 20 August 2026, when Companies House announced that the sign-in screen for the Find and update company information service will change in late August and GOV.UK One Login will become the main sign-in option. Existing users may continue with their current details for now, but the older option will move lower on the page. More importantly for operations teams, all new users will need a GOV.UK One Login to access Companies House services.

Observed fact: Companies House described this as a sign-in change, not an identity-verification request. CompanyProof analysis: that distinction matters, but it does not make the change small. Product, compliance, credit and risk teams that rely on UK registry filings now need to manage two connected evidence streams: who can access a registry service, and whether each director, PSC or equivalent role has completed the identity-verification step required for the relevant filing or 14-day window.

The development is especially relevant because it lands during the 12-month identity-verification transition that began on 18 November 2025. Companies House has already made identity verification a compulsory part of incorporation and new appointments for new directors and PSCs, and existing directors must provide their personal code with the company’s next confirmation statement. The current sign-in change therefore increases pressure on internal access inventories, agent workflows and stale-fact monitoring before the transition moves further toward compliance activity.

Separate sign-in, identity proofing and role evidence

The first implementation decision is to stop treating “verified” as one field. Companies House materials separate at least three concepts. First, a person may have a Companies House account or a GOV.UK One Login used to sign in. Second, a person may have completed identity verification through GOV.UK One Login or through an Authorised Corporate Service Provider. Third, the person’s verified status must be linked to each relevant Companies House role by providing the Companies House personal code and an identity-verification statement at the required moment.

GOV.UK One Login itself is not a corporate authorisation system. The government’s design guidance for business users says One Login can be used by people carrying out work tasks, including Companies House users, but it does not prove whether a user belongs to a particular organisation or performs a particular role; that eligibility decision remains with the service. CompanyProof analysis: teams should not infer that a One Login proves authority to file, authority to act for a company, or verified status for every role shown on a register.

The personal code guidance adds another important control point. A Companies House personal code is an 11-character code issued after identity verification. It is personal to the individual, not to the company, and the same code may be used for multiple appointments. Companies House also says the code can be shared with trusted filers, such as an agent, but should be kept secure; if compromised, Companies House can change it and cancel the previous code. This is a classic evidence-lineage problem: the code is not a public identifier to scatter across spreadsheets, but it is also not useful if nobody can retrieve it before a filing deadline.

Shared accounts are the immediate break point

The most concrete new risk is shared account usage. Companies House now says each GOV.UK One Login must be linked to one individual, using that person’s own email address and phone number. If a team shares a Companies House account, Companies House says it should start planning how access will be managed when One Login is compulsory. It also warns that sharing an account after linking to GOV.UK One Login can trigger security controls that lock users out.

This follows an earlier WebFiling migration pattern. For WebFiling, Companies House said only one person can connect each WebFiling account to their GOV.UK One Login, and anyone who shares those accounts needs to create a separate One Login using a different email address. The lesson for KYB and company-secretarial workflows is clear: one account per person should become the baseline, and shared credentials should be treated as a remediation item, not a convenience.

CompanyProof analysis: the registry access model should now be documented at user, entity and role level. For each user, record the service they use, the email address under their control, whether multi-factor authentication is set up, whether they are an internal employee or external agent, and which companies they can act on. For each company, record confirmation statement dates, directors, PSCs, LLP members where applicable, the known verification status and the evidence source used. This does not require legal advice; it requires a controlled inventory that can be tested before filings are due.

Deadlines are not one November date

A common implementation trap is to treat mid-November 2026 as the only relevant deadline. Companies House guidance is more granular. A current director must provide their Companies House personal code as part of the company’s next confirmation statement, and a director of more than one company must do this for each company. For PSCs, the 14-day period depends on the person’s situation. A PSC who is also a director of the same company provides the code separately for each role, with the PSC 14-day period starting the day after the company’s confirmation statement date. A PSC who is not a director must provide the code within the first 14 days of their birth month.

Companies House’s own transition plan says identity verification became compulsory for new directors and PSCs from 18 November 2025 and started a 12-month transition phase for more than 7 million existing directors and PSCs. No earlier than the end of 2026, Companies House expects to complete the transition period for all individuals on the register requiring identity verification and start compliance activity against those who have failed to verify. No earlier than November 2027, it expects presenter identity verification and ACSP registration requirements for third-party filing to come into effect, with at least six months’ notice.

The official April-to-June 2026 statistics page is also material for monitoring, because it confirms that Companies House is publishing quarterly data on the number and percentage of director and PSC appointments that comply with identity-verification requirements. Separately, Law Debenture’s practitioner commentary reads those Q1 2026-2027 numbers as showing only 55% of directors, 50% of LLP members and 42% of PSCs had informed Companies House of verified identity by the end of June. CompanyProof analysis: even where teams do not rely on that commercial commentary, the existence of official quarterly measures means stale-fact monitoring should be refreshed when Companies House updates its datasets.

Build a registry-access evidence ledger

A practical response is to build an evidence ledger for UK registry access and identity verification. At minimum, record: the company number; confirmation statement due date; directors and PSCs as observed on Companies House; whether each person is in scope; whether each has completed identity verification; where the personal code is stored or how it will be obtained; whether the same person holds multiple roles; the filing owner; the sign-in account used; and the date each fact was last checked. The point is not to duplicate Companies House. It is to preserve the timestamped evidence that explains why a filing or risk decision was made.

For CompanyProof users and similar evidence-led workflows, the useful pattern is to separate observed registry facts from internal interpretations. Observed facts include the Companies House due date, the public role, the guidance version and the source URL. Internal analysis includes the team’s risk label, the owner assigned to chase a director, and the decision to use direct One Login verification or an ACSP route. Keeping those layers separate helps avoid the “verified somewhere” ambiguity that appears when sign-in, identity proofing and role linkage are collapsed into a single CRM field.

Teams should also monitor service reliability without overreacting to anecdote. The GOV.UK One Login status page reported no incidents for 26 August 2026 and recent prior days, while Parliament’s 2026-2027 public targets for Companies House include 99.5% minimum digital-service availability. That does not remove the need for contingency planning. It means the control should be evidence-based: check official status, preserve error screenshots, document rejected filings, and avoid assuming that an individual’s inability to retrieve a code proves that the registry record itself is wrong.

What to do this week

First, freeze shared credential growth. Do not create new shared Companies House access patterns, and identify any team mailbox or legacy WebFiling account still used by more than one person. Assign individual One Login owners for operational users, but avoid representing One Login ownership as role authority. The organisation still needs to decide who is authorised to act for each company and how that authority is evidenced.

Second, run a deadline sweep. Pull the next confirmation statement date for each UK entity, then identify directors and PSCs whose role-specific verification evidence is still missing. For PSCs, calculate the correct 14-day window rather than assuming a single portfolio deadline. For groups with overseas directors, dormant subsidiaries or distributed shareholders, use earlier internal cut-off dates so the team can handle mismatch, document or email-address problems before the statutory window is reached.

Third, create a stale-fact review cadence. Companies House has committed to quarterly identity-verification statistics, guidance pages are being updated, and the transition plan includes future phases for limited partnerships, corporate directors, corporate members of LLPs, officers of corporate PSCs, presenters and ACSP filing. This is not a one-time clean-up. It is an ongoing registry-data governance process that should sit beside KYB refresh, credit review and vendor due diligence. For teams that want to operationalise this evidence trail, CompanyProof’s evidence-ledger approach is a useful model for separating public-source facts from internal risk decisions.

TIMELINE

Companies House access and identity-verification timeline

Sourced milestones for access migration, identity-verification rollout and future Companies House implementation phases.

13 October 2025WebFiling migration prompt

Customers signing in to WebFiling were prompted to connect the account to GOV.UK One Login; only one person could connect each WebFiling account.

18 November 2025Mandatory identity verification began

New directors and PSCs needed identity verification for incorporation or appointment, and the 12-month transition for existing roles began.

30 July 2026Deadline guidance and Q1 statistics refreshed

Companies House updated guidance on when to verify and published April-to-June 2026 identity-verification official statistics.

20 August 2026Find and update sign-in change announced

Companies House said GOV.UK One Login would become the main sign-in option in late August 2026 and warned shared-account users to plan individual access.

No earlier than end 2026Transition completion and compliance activity

The transition plan says Companies House should complete the transition for in-scope individuals and start compliance activity against those who failed to verify.

No earlier than November 2027Presenter and ACSP filing phase

Companies House expects presenter identity verification and ACSP registration for third-party filing to come later, with at least six months’ notice.

COMPARISON

Control map for registry access and verification evidence

Comparison of the distinct controls teams should not collapse into one “verified” flag.

Sign-in accessIndividual One Login

Each GOV.UK One Login must be linked to one individual with their own email address and phone number; shared use can trigger lockouts.

Organisation or role authorityNot proven by One Login alone

GOV.UK One Login does not prove that a user belongs to an organisation or performs a particular role; that eligibility is handled separately.

Identity proofing routeOne Login or ACSP

Companies House guidance lists GOV.UK One Login and Authorised Corporate Service Provider verification as available routes.

Role linkagePersonal code plus statement

The same personal code can be used to confirm verified status for each relevant director or PSC role, but the code is personal to the individual.

Director deadlineNext confirmation statement

Existing directors provide the personal code in the company’s next confirmation statement and must do so for each company where they are a director.

Non-compliance responseDefault letters and enforcement routes

Companies House describes default letters and possible enforcement routes including prosecution, referral and financial penalties.

PROCESS

A practical control path for One Login rollout

Four connected controls turn an access migration into an operating process that filing and compliance teams can actually manage.

Step 1Map access owners

List every person who files, reviews or administers registry activity, then assign a named owner for each responsibility.

Step 2Complete identity setup

Confirm that each required user has completed the appropriate identity and personal-code steps before the operational deadline.

Step 3Test filing continuity

Run a controlled filing or access check and verify that an authorised backup can take over without sharing credentials.

Step 4Retain the control record

Record who changed, what was tested and when the result was confirmed so later access failures can be investigated quickly.

CONTINUE THE WORKFLOW

Move from reading about evidence to using it.

FREQUENTLY ASKED QUESTIONS

Ten practical answers.

Direct answers to the questions implementation teams are most likely to ask.

01Is Companies House One Login the same as identity verification?

No. Companies House says the late-August change is to the sign-in process for the Find and update company information service and is not, by itself, a request to verify identity. Identity verification is a separate legal requirement for directors, PSCs and other in-scope roles. A person may use GOV.UK One Login to sign in and may also use it as one route to verify identity, but teams should track sign-in access, identity proofing and role linkage as separate controls.

02What changed on 20 August 2026?

Companies House announced that GOV.UK One Login will become the main sign-in option for the Find and update company information service in late August 2026. Existing users can keep signing in with current details for now, but that option will be lower on the sign-in page. All new users will need GOV.UK One Login to access Companies House services. Companies House also warned shared-account users to plan individual access.

03Can a team keep using one shared Companies House account?

That is now a clear operational risk. Companies House says each GOV.UK One Login must be linked to one individual using their own email address and phone number. It warns that sharing an account after linking to GOV.UK One Login can trigger security controls that lock users out. Earlier WebFiling guidance used a similar pattern: only one person can connect each WebFiling account to One Login, and other users need separate accounts.

04Does GOV.UK One Login prove a person belongs to a company?

No. Government design guidance for business users says GOV.UK One Login does not prove whether a user belongs to a particular organisation or performs a particular role; that eligibility still needs to be handled by the service. CompanyProof analysis: a One Login account should not be treated as proof of filing authority, directorship, PSC status or agent authority without separate supporting evidence.

05When must existing directors provide their personal code?

Companies House guidance says an existing director must provide their Companies House personal code as part of the company’s next confirmation statement. If the person is a director of more than one company, the code must be provided for each company. The same individual usually verifies once, but must connect that verified identity to each relevant appointment or role.

06How do PSC verification windows work?

Companies House says PSCs must verify and provide their Companies House personal code, but the 14-day period depends on the situation. If the PSC is also a director of the same company, they provide the code separately for each role, and the PSC 14-day period starts the day after the company’s confirmation statement date. If the PSC is not a director, the window is the first 14 days of the person’s birth month as shown on the register.

07What is a Companies House personal code?

It is an 11-character code issued to a person after identity verification. Companies House says the code is personal to the individual, not to the company. It may be used to confirm verified status for director and PSC roles and may be needed for future filing requirements. The code should be kept safe; if it is compromised, Companies House can issue a new code and cancel the previous one.

08What happens if identity verification is missed?

Companies House says it will take action in line with its non-compliance approach. Its guidance says failing to meet identity-verification requirements can be an offence, and its non-compliance publication describes default letters and possible enforcement routes, including prosecution, referral to the Insolvency Service and financial penalties. This article is not legal advice; teams should use the guidance to design controls and obtain advice for specific cases.

09Why do the official identity-verification statistics matter for KYB?

The April-to-June 2026 official statistics page says Companies House publishes quarterly performance data showing the number and percentage of director and PSC appointments that comply with identity-verification requirements. For KYB, credit and risk teams, that creates a refresh trigger: a previously captured status can become stale as new filings, role changes, due dates and statistics are published.

10What should a compliance or product team implement first?

Start with a registry-access inventory. List each user, whether access is individual or shared, the Companies House services used, the companies they act on, and the role-verification status for directors and PSCs. Then add due dates, personal-code evidence locations and source timestamps. Check official GOV.UK One Login status for service incidents before attributing access failures to registry-data problems, and maintain a documented escalation path for missed or rejected filings.