Economic Crime Act 2023: A CFO Filing Checklist for 2026
UK CFOs must prepare now: from Spring 2026, Companies House will restrict company filings to individuals who have completed identity verification (IDV) under the Economic Crime and Corporate Transparency Act 2023 (ECCTA). Directors, PSCs and anyone filing on a company’s behalf who has not verified will lose the ability to submit documents.
ECCTA received Royal Assent in October 2023 and is being implemented in stages. Mandatory identity verification for directors and people with significant control (PSCs) began on 18 November 2025. The next phase — restricting who can file at all — is where most finance functions still have exposure, because IDV compliance and filing-agent authorisation are two separate steps, and CFOs are often the ones who discover the gap only when a filing bounces.
What does ECCTA actually change for Companies House filings?
Under the new regime, Companies House will only accept filings from three categories of submitter: an individual who has completed their own IDV and is filing for themselves; an employee or officer of a company who has completed their own IDV and is filing on the company’s behalf; or an Authorised Corporate Service Provider (ACSP) — typically an accountant, company secretarial firm or law firm — filing on the company’s behalf. Anyone outside these three categories, including an unverified finance team member submitting a confirmation statement or accounts, will have the filing rejected.
This is a structural change to how finance and company secretarial functions operate, not a paperwork update. According to Companies House, an estimated 6 to 7 million directors and PSCs across the UK register will need to complete identity verification as the regime rolls out. Most CFOs assume this sits with legal or company secretarial — but where finance teams handle their own Companies House submissions (common in mid-market and PE-backed businesses without dedicated company secretaries), the CFO owns the risk directly.
- Executive Action: Confirm today who in finance and company secretarial actually submits Companies House filings, and whether each of those individuals has completed IDV.
- Map every UK entity in the group against its filing authorisation status — do not assume group-level compliance covers every subsidiary.
- Decide now whether to route filings through an ACSP rather than build internal IDV capability across every filer.
Which CFO responsibilities are directly exposed?
Three areas of CFO accountability intersect with ECCTA directly. First, statutory filings: annual accounts, confirmation statements and any changes to share capital or registered details all fall under the new filing restrictions. Second, director and PSC onboarding: every new director appointment and every individual newly meeting the PSC threshold must complete IDV before — or immediately after — appointment, and the CFO’s finance operations team is often the first to process the paperwork. Third, group structuring: M&A integration, entity rationalisation and internal reorganisations all generate a wave of filings, and unverified new directors in an acquired entity can stall post-completion administration.
The consequence of getting this wrong is not administrative inconvenience. Companies House guidance confirms that failure to verify identity is a criminal offence and can carry civil penalties, and a company directed by an unverified director also commits an offence. In the most serious cases of sustained non-compliance, a company can be struck off the register — a risk no CFO wants attached to a routine filing failure.
- Executive Action: Add ECCTA IDV status as a standing item in director onboarding and offboarding checklists.
- Brief the audit committee on strike-off and filing-rejection risk as part of the next internal controls update.
- Flag ECCTA exposure explicitly in any live or planned M&A due diligence process.
How should CFOs build an ECCTA compliance checklist before Spring 2026?
Treat this as a discrete compliance project with a hard deadline, not a background task for company secretarial. A workable CFO checklist covers five steps: audit every UK entity for current directors, PSCs and named filers; confirm IDV completion status for each individual via GOV.UK or their Companies House personal code; decide the filing model per entity — direct filing by verified staff versus an ACSP — and formalise it in writing; update onboarding process documents so IDV is completed before a new director’s appointment is filed; and build a recurring quarterly review, since directors and PSCs change and IDV is a one-off event tied to the individual, not the company.
Groups with multiple UK subsidiaries should not assume verification at the parent level extends anywhere else — IDV attaches to the individual and their specific appointments, but filing authorisation still needs confirming entity by entity. This is exactly the kind of cross-entity control gap that internal audit and the audit committee should be testing for now, ahead of the filing restrictions taking effect.
- Executive Action: Assign a single senior owner — CFO, company secretary or general counsel — for group-wide ECCTA compliance.
- Build IDV status into the finance team’s quarterly compliance dashboard alongside other statutory obligations.
- Use INFORMD’s executive self-assessment tools to benchmark your current filing-control maturity.
Where does this sit alongside other UK financial crime compliance obligations?
ECCTA identity verification does not stand alone. It sits within a broader UK economic crime agenda that already includes the corporate “failure to prevent fraud” offence, expanded Companies House powers to query and reject suspicious filings, and reforms CFOs have already had to absorb under the UK’s anti-money laundering framework. Finance leaders who treated UK AML reform as a one-off compliance sprint should note that ECCTA follows the same pattern: a phased regulatory rollout where the real cost falls on whoever owns the operational detail, not whoever signs off the policy.
Boards and audit committees are increasingly asking finance leaders to demonstrate control over the full filing chain, not just the numbers in the accounts. Building an ECCTA response now, rather than reacting to a rejected filing in Spring 2026, is the lower-cost path.
INFORMD provides intelligence briefings, tools and frameworks for senior business leaders across technology, finance, strategy and compliance. Based in Milton Keynes, UK, we help executives stay informed and act with confidence. Explore our full briefing library (/resources/) or access our free assessment tools (/tools-assessments/).
Stay ahead. Subscribe to INFORMD’s weekly executive briefing at informd.co.uk (/resources/).
ECCTA is UK legislation granting Companies House new powers to verify identities and query filings. It introduced mandatory identity verification for directors and persons with significant control (PSCs), which began on 18 November 2025 and is being phased in over roughly 12 months.
All company directors, LLP members and PSCs must verify their identity. Companies House estimates 6 to 7 million individuals across the UK register are affected. Verification is a one-off process per individual, regardless of how many directorships they hold.
Failure to verify is a criminal offence and can carry civil penalties. Companies directed by an unverified director also commit an offence, filings can be rejected, and in serious cases of non-compliance a company can be struck off the register.
Only ID-verified individuals filing for themselves, ID-verified employees or officers filing on their company’s behalf, or Authorised Corporate Service Providers (ACSPs) such as accountants or company secretarial firms will be permitted to submit filings from Spring 2026.
