
From 18 November 2025, millions of company directors became subject to mandatory identity-verification requirements under new Companies House rules.
The Government’s free verification service uses GOV.UK One Login. Depending on the individual, verification through One Login may involve using photographic identification, matching their face to it, answering security questions or beginning the process online before attending a Post Office.
The alternative is to have an Authorised Corporate Service Provider – such as an accountant or solicitor – verify the director’s identity. That provider may charge a fee.
After verification, Companies House issues a personal code that the director uses to connect their verified identity to their company roles.
When the only free government route uses One Login and avoiding it may cost money, the choice is not genuinely free.
This is an important example of how government-backed digital identity infrastructure can become effectively compulsory in practice – and how a wider Digital ID system could develop by the back door.
Built on a Troubled System: One Login
This new verification regime relies on GOV.UK One Login – a project already beset by scandal and dysfunction:
Despite repeated warnings, the Government continues to throw money at the problem – over £300 million of taxpayer funds and counting.
Critics have compared One Login to “Post Office Horizon all over again.”
Mission Creep and Surveillance Risks
Companies House says these requirements do not create a digital ID. It is true that directors can verify through an authorised provider rather than One Login.
But those using the Government’s free route have their verified real-world identity connected to a reusable One Login account. Companies House also issues every verified director with a personal code used to connect that identity to their company roles.
Our concern is not simply the existence of a code. It is that mandatory identity checks are being placed behind infrastructure designed to work across an expanding range of government services.
Once built, such systems rarely stay contained. History shows how data collected for one purpose is soon repurposed for others – from tracking, data-matching, or even future credit-scoring or sanctions enforcement. This is mission creep in action.
No Need for Coercion
If necessary, company directors already have safe, proven ways to confirm their identity, without the new dangers inherent in this scheme:
Increased risk of data breaches and identity theft
Exclusion of those without the right documents or technology
Loss of control over personal information
A dangerous precedent for future digital identity expansion
What We’re Calling For
We want to see:
Update 19 March 2026: The huge Companies House WebFiling security breach, which exposed millions of sensitive personal records including directors’ dates of birth and residential addresses, and may have enabled unauthorised changes to company records, shows exactly why the ongoing rollout of One Login is such a problem.


