Companies House is changing how users sign in to its Find and update company information service. From late August, GOV.UK One Login becomes the main route for access, and all new users will need one. Existing Companies House credentials will continue to work for now, but the direction of travel is explicit: the government intends to move everyone to the individual One Login model.

For most directors, the change is minor. For finance, legal and company-secretarial teams that still share a single Companies House account, it is operationally significant. A GOV.UK One Login belongs to one person and uses multi-factor authentication. Companies House is telling organisations with shared credentials to start separating access before the old model becomes unavailable.

This is not the identity-verification deadline

The sign-in change is easy to confuse with the wider Companies House identity-verification reforms, but the two are separate. One Login is an authentication system for accessing government services. Identity verification is a legal requirement under the Economic Crime and Corporate Transparency Act for people setting up, running, owning or controlling UK companies.

That distinction matters because a user can be asked to move to One Login without being asked to verify their identity at that moment. Businesses should therefore maintain two checklists: who needs a personal login to submit or manage filings, and who needs to complete statutory identity verification and associate a personal code with their company roles.

Shared credentials create a governance problem

Shared accounts were convenient because a team could retain one password and an inbox such as accounts@company.co.uk. They were never particularly strong from an audit perspective. When several people use the same credentials, it is harder to establish who filed a form, who changed information and whether access was removed when an employee left.

One Login forces a more defensible model. Each person gets an individual account, their own email address and phone number, and multi-factor authentication. Companies House warns that sharing an account after linking it to One Login can trigger security controls and lock users out. That turns access management from an IT preference into a continuity issue.

Accountancy firms need a cleaner permissions map

The change is especially relevant for authorised corporate service providers and accountancy practices managing filings for many clients. Those firms already face identity-verification standards requiring evidence checks and record keeping. They now need to ensure operational access is just as structured: named users, documented responsibility for filings and clear offboarding when staff move roles.

The sensible approach is to inventory every person currently using a shared Companies House account, create individual accounts before the old route disappears, and document which entities each user is expected to manage. Waiting until a filing deadline turns a manageable migration into an avoidable compliance risk.

A small change that fits a larger register clean-up

Companies House has spent the past two years moving from a largely passive register toward a more active gatekeeping role. Identity verification, stronger powers to challenge information and the removal of misleading entries all point in the same direction. Individualised account access is a less visible part of that programme, but it supports the same objective: making corporate records easier to attribute to real people.

Businesses do not need to overreact to the late-August login screen. They do need to stop treating shared credentials as a permanent workflow. The old convenience is being designed out of the system.