Fraud is no longer something businesses are expected to avoid - it's something they have to actively, consistently prove they're preventing, across the whole organisation and its subsidiaries. That's the sharpest edge of the Economic Crime and Corporate Transparency Act (ECCTA), passed in 2023 and now arriving in stages - and if you run or advise a UK firm, the stage that matters has changed: the biggest pieces are no longer coming. They're in force.
For accountants the Act cuts twice. Your clients will ask you what it means for them, because you're the professional they trust with anything that has Companies House in it. And your own firm is directly in scope: practices that file on behalf of clients are being pulled into the Authorised Corporate Service Provider (ACSP) regime, with its own registration, identity-verification and record-keeping duties. This piece covers what's actually in force, what's still coming, and where the real exposure sits.
Company registration rules (from 2024). The first wave tightened Companies House itself: no more PO box registered addresses, a lawful-purpose statement at incorporation, and a registrar that "actively scrutinises" rather than accepts in good faith. These apply to every UK company, with the old small-company exemptions removed. The gov.uk summary is here.
The failure to prevent fraud offence (from 1 September 2025). The headline change is now live. A large organisation can be criminally liable where an "associate" - an employee, agent or subsidiary - commits fraud intending to benefit it, even if senior leadership knew nothing. The only defence is having reasonable fraud-prevention procedures in place, and ignorance is explicitly not one. "Large" means meeting two of three tests: turnover over £36m, balance sheet over £18m, more than 250 employees. As a rule of thumb, if the business is big enough to need an audit, it should assume it's in scope - and smaller firms in the supply chains of large ones are feeling the requirements flow down through due diligence questionnaires anyway.
Identity verification (from 18 November 2025). New directors and people with significant control must now verify their identity with Companies House, either directly or through an ACSP - which, for most small companies, means their accountant. Existing directors verify through the company's next confirmation statement, on a 12-month transition running into late 2026. This is where the Act lands squarely on your desk: every incorporation and every confirmation statement your firm handles now carries a verification step, and the evidence behind it.
The remaining piece is the one that changes how firms file. Companies House intends to restrict who can deliver documents on behalf of companies, so that third-party filing becomes an ACSP-only activity. That "presenter measures" stage was originally pencilled for spring 2026 and has been postponed to no earlier than November 2026 - a postponement, not a cancellation, and the registration and evidence duties it rests on are already live.
Two details in the ACSP regime deserve more attention than they're getting. First, the record-keeping: firms must retain the evidence behind every identity check for seven years - we've covered what the ACSP seven-year record-keeping duty actually requires in detail. Second, the sanction. The penalty for getting it wrong isn't primarily a fine; it's exposure. A suspended or ceased ACSP is published, by name, and Companies House contacts the people that firm verified to tell them they may need to be verified again. The regulator tells your clients before you do. For a practice whose whole value rests on being trusted with the record, that's a heavier deterrent than any invoice.
Further down the track sit the remaining reporting reforms, including the move to software-only, fully tagged iXBRL accounts filing - timetabled later, but pointing in the same direction: structured, verifiable, digital records as the default.
Across every stage of the Act, the pattern is the same: the defence is never good intentions, it's the record. For failure to prevent fraud, that means documented risk assessments, communicated policies, due diligence on suppliers and agents, and monitoring you can evidence. For identity verification, it means the checks themselves plus seven years of retrievable proof. In each case the question a regulator will ask is not "were you honest?" but "show me."
That's a filing-system question as much as a legal one. A firm whose verification evidence, engagement records and approval trails live in one place, against the client, with an audit log that can't be edited, can answer "show me" in minutes. A firm whose evidence is spread across inboxes, scans and a shared drive is betting its name on a reconstruction job. Rachel Fowler, who runs Rachel Fowler Advisory, a regulated insolvency practice in Northern Ireland where every decision must be retained and auditable, describes the standard worth aiming at: "Everything is where it should be. Nothing gets lost. The whole story is there."
For a walkthrough of the requirements with our CISO Luke Kiely and Payhawk's Robbie Hadfield, the webinar Trading in the UK? You need to comply with the ECCT Act is free to watch. And if your firm is working out how to hold ACSP evidence, client verification records and approvals in one defensible place, book a demo - bring a real client file and we'll show you what the seven-year record looks like when it keeps itself.
General information for accounting and professional-services firms, not advice – verify anything time-sensitive with the relevant tax authority or your professional body before acting on it.