Companies House has added another practical layer to the UK’s identity-verification reforms: the personal code. Once an individual verifies their identity, they receive a code that can be used to connect that verified identity with roles held on the companies register. The guidance published in July turns a broad legal reform into a workflow that company secretaries and advisers need to manage carefully.

The important point is that verification is personal, while compliance is role-specific. A director who sits on several boards does not need a different identity for each company, but the verified identity has to be associated correctly with the relevant appointments and filings.

A code is not a password

The personal code is best understood as a reference linking Companies House’s verified-person record to the company register. It should not be treated like a shared account credential. Firms that collect codes from directors should handle them as controlled personal information, restrict who can access them and document why they are being used.

That matters for professional-services firms handling dozens or hundreds of entities. A spreadsheet of directors’ codes circulated around a team may be convenient, but it recreates the same weak access controls the wider reform is trying to remove. Secure company-secretarial systems should become the default storage point.

Directors and PSCs need a communication plan

Many directors will complete verification themselves and assume the task is finished. Company teams need to explain what happens next, particularly where the person is also a person with significant control. The business should know who has verified, which code belongs to whom and which appointments still need to be connected.

The risk is greatest in groups with dormant subsidiaries, joint ventures or overseas directors who do not interact regularly with UK filing systems. Those are exactly the appointments most likely to be discovered late, when an annual filing or corporate transaction makes the missing connection urgent.

Advisers cannot outsource responsibility indefinitely

Authorised Corporate Service Providers can verify identities on behalf of clients if they meet Companies House standards, including evidence checks and record retention. That helps larger groups, but it does not remove the need for the company itself to understand its population of directors and controllers.

A clean process starts with a role inventory, not with verification links. List directors and PSCs across the group, identify who is already verified, capture codes securely, and then assign responsibility for making the required associations. That is more reliable than asking individuals to respond to generic reminders.

The reforms are becoming operational rather than theoretical

The Economic Crime and Corporate Transparency Act reforms have been discussed for years. Personal codes are a sign that implementation has moved into everyday administration. Businesses that still think of identity verification as a future legal issue are likely to encounter it first as a blocked filing or an access problem.

The compliance burden is manageable, but only if it is treated like any other corporate register: named owners, controlled data and a recurring check that roles remain accurate.