16 min read
Verified is not filed: seven years of Companies House ID evidence
By The XTK team · Product
If your practice verifies a director's identity for Companies House, you must keep the request and every piece of evidence you considered for seven years — including for the people you refused to verify. The duty is regulation 15 of the Registrar (Identity Verification and Authorised Corporate Service Providers) Regulations 2025. It states precisely what to keep and precisely how long to keep it. It never says where.
That gap is the subject of this article. Identity verification became a legal requirement on 18 November 2025, starting a 12-month transition period that runs out on 17 November 2026, and the published figures put a little under half of the appointments in scope as verified by the end of June. Almost everything written for accountants about this regime answers one question — how do I verify somebody — and stops at the moment the evidence exists. The seven years that follow are where the compliance risk actually sits.
Nothing below requires you to install anything, and it applies whether your practice verifies ten identities or a thousand.
What exactly must an ACSP keep, and for how long?
Seven years, of two categories of person, and of more than most practices assume. Regulation 15 applies to anyone who is or has been an authorised corporate service provider — the duty does not end when your registration does. It requires records for every individual on whose behalf you delivered a verification or reverification statement, and, separately, for every individual in respect of whom you did not become satisfied under regulation 9 that the required personal information was true.
What the records must contain is the part worth reading twice. Regulation 15(5) requires them to include any records of the requests made under regulation 9, and “all information and evidence the relevant person considered when determining such requests”. Not the evidence you relied on. Not the evidence that persuaded you. All of it, including whatever you looked at and set aside.
Regulation 9(5) widens that further, and it is the sentence most summaries leave out: the ACSP “may consider other information and evidence in addition to that provided by the individual”. So a supplementary check your own team ran — a register search, a returned letter, a note of a call that resolved an address mismatch — is information you considered, and regulation 15 keeps it for seven years alongside the passport scan. The duty covers your working, not just the client's uploads.
The two start dates differ, and the second surprises people. For someone you verified, the seven years run from the date stated in the statement. For someone you refused, from the date you decided not to deliver one. Neither waits for anything else to happen.
Which documents count as evidence?
The evidence itself is fixed by the registrar rather than left to judgement. The Registrar's (Identity Verification by Authorised Corporate Service Providers) Rules 2025, made 24 January 2025 and in force from 25 February 2025, set out two routes. Which route you are on is decided by your own technology, not by the individual in front of you.
| Route | How many items | Examples from the rules |
|---|---|---|
| Option 1 — only where the ACSP can validate cryptographic features | One | Biometric or machine-readable passport, up to 6 months expired if the cryptographic features still validate; UK, Channel Islands, Isle of Man or EU photocard driving licence; biometric EU or EEA identity card; UK biometric residence permit or card |
| Option 2, Group A — where the ACSP cannot | Two from Group A, or one from A plus one from B | Passport or Irish Passport Card up to 18 months expired; EU or EEA identity card; UK biometric residence permit or card; PASS card; HM Forces ID or Veteran Card; photographic visa or work permit |
| Option 2, Group B — never on its own | Only alongside a Group A item | Birth, adoption, marriage or civil partnership certificate; bank or building society statement; mortgage, council tax or utility bill at the current address |
Read that table as a filing specification rather than a checklist, because that is what it becomes the moment the check is done. A practice on Option 2 collects two identity documents per individual, one of which may be a utility bill or a bank statement, and holds them for seven years. Multiplied across the directors and people with significant control in your client base, that is a body of highly sensitive personal data that arrived over a few months and has to be findable, and then deletable, years later.
Why is this clock unlike every other clock in your practice?
Because it does not wait for the client to leave. Under regulation 40 of the Money Laundering Regulations 2017, client due diligence records are kept for five years beginning when you know or reasonably believe the business relationship has ended. That is the clock most practice retention policies are built around, and it has a comfortable property: it starts at an event you will notice.
Regulation 15 has neither property. It is seven years rather than five, and it starts at the date of your own decision — a date that passes silently, on an ordinary Tuesday, months or years before the relationship ends, and possibly without a relationship ever beginning. Two clocks, two lengths, two triggers, on documents that often arrive in the same email.
So satisfying one does not satisfy the other, in either direction. Delete an identity check five years after a client leaves and you may be two years short on regulation 15. Keep it under a policy reading “seven years from the end of the engagement” and you are holding it longer than regulation 15 requires, which is its own problem. The wider set of retention periods a UK practice is already running has the same structure — several obligations, several clocks, one folder — and this is simply the newest and least forgiving member of the set.
What happens to the evidence for someone you refused?
You keep it for seven years from the day you refused, and this is the case the regime handles least intuitively. Regulation 15(3)(b) covers every individual in respect of whom you did not become satisfied — no exemption for a check that went nowhere, none for a person who never became a client.
Consider what that file looks like. Somebody approached you, or was put forward as a director by an existing client. You asked for two documents. Something did not reconcile — the address history, the likeness, a document you could not satisfy yourself about — and you declined to deliver a statement. There is no engagement letter, possibly no client record in Practice Manager, and no year folder because there is no client to open one under. You are now the custodian of that person's passport image and proof of address for seven years, on a clock your own decision started.
Every instinct in a practice points the wrong way here. The natural response to a failed check is to close the file and delete the attachments — particularly when the person was never taken on and the data is exactly what you would rather not hold. Under regulation 15 that is the offence.
The refusals have no client, no engagement and no folder — and the longest clock in the regime starts the day you write one.
How many appointments are still unverified?
A little over half were unverified at the end of June, and the figure for people with significant control is worse. Companies House publishes quarterly management information on this, and the release covering April to June 2026 was published on 30 July 2026. As at 30 June 2026 it reports 4,710,086 director appointments verified, or 55.33%; 82,686 LLP member appointments, or 49.47%; and 2,571,827 individual PSC appointments, or 41.86%. Across all three, 7,364,599 appointments were verified — 49.68% of those in scope.
One correction is worth making because almost every secondary write-up of these numbers gets it wrong. These are appointments, not people. The release says so in its own notes: an individual can hold more than one appointment in more than one corporate body, so the number of verified appointments may not equal the number of verified individuals. “55% of directors are verified” is not what the table says, and a practice planning capacity off that sentence is planning off the wrong denominator.
Two further qualifications: the figures are unaudited management information, by the release's own description, and the July 2026 release restated earlier quarters after dormant-company appointments were added to both the verified count and the in-scope population. They are not comparable with figures from an earlier release.
The shape survives the qualifications: with under five months of the transition period left, the PSC line was furthest behind, and PSCs are disproportionately the people a practice chases rather than the ones who chase you.
The rules say what to keep. They do not say where.
Nothing in the regulations or the rules specifies a location, a format or a system. That silence is the practical question, because the duty in regulation 15 sits on the ACSP — on your practice and its officers personally — and is not delegated by uploading a file into somebody else's product.
In practice the evidence ends up in one of three places, rarely by deliberate choice: the verification vendor's platform, where the check was performed; a practice management or document management system; or a Google Workspace or Microsoft 365 tenant the practice controls directly.
The three are indistinguishable in year one and very different in year six. A seven-year duty outlasts subscriptions, procurement cycles, vendor acquisitions and the partner who signed the original order form. The question to ask of the first two is not whether the vendor stores the records — it does — but what happens on the day you stop paying, and whether that answer sits in the contract or in a help article that can change. A vendor that deletes on termination, or offers an export you must run inside a notice period, has handed you a criminal record-keeping risk with a date on it.
This is the same question an exit from any document system turns on, asked about the one category of record where getting it wrong is an offence rather than an inconvenience. The six questions in that article are the right ones to put to a verification vendor in writing, and the first of them — whose storage tenant are the bytes in — is the only one that changes the answer for all seven years at once.
Does holding ID documents for seven years conflict with data protection?
No, and regulation 15 is what makes that true — but it also fixes the date on which it stops being true. Article 5(1)(e) of the UK GDPR requires personal data to be kept in a form permitting identification for no longer than is necessary. A statutory duty to retain is exactly the answer to why you still hold a passport scan in year six. The difficulty is that it is also, precisely, the answer to why you should not hold it in year eight.
So the regime hands you a deletion date per individual, computable from a date you already recorded. Few retention obligations are that tidy, and acting on it is the hard part — the one described in the wider retention article: the records sit in storage, in the email archive, in whatever somebody saved locally, and in the backups behind all three. Deleting from one is not deleting, and no document tool makes that disappear, ours included.
What XTK does here, and what it does not
What it does is collect the evidence into somewhere you own. A document request is a checklist sent as one link — “passport or photocard licence”, “proof of address dated within three months” — and your client uploads against each line with no account and no password. Accepted types include PDF and images, iPhone HEIC among them, at up to 100 MB per file, which covers a photographed document without asking a director to work out how to make a PDF.
Two properties of that flow matter for this particular category of record. The bytes go straight from your client's browser to Google or Microsoft — a client upload through a request link never passes through XTK's servers at all, which is worth knowing before you invite somebody to send you their passport. And the file lands in that client's folder in your practice's own Drive, OneDrive or SharePoint, as an ordinary file you could open tomorrow without XTK's help. What XTK's backend does and does not hold is set out in full, including the operations where bytes do stream through it.
The retention property follows from that rather than from a feature. Nothing you have collected is ever removed automatically: cancelling a request closes the link, expiry closes the link, your client's submission closes the link, and none of the three deletes a file. Files that arrived stay in the client's folder. The seven-year clock therefore runs against storage your practice controls, not against a subscription — which is the only version of this that is safe to rely on, because the clock is longer than any software decision you are making this year.
Now the four places it does not help, because on a duty carrying a prison sentence the limits matter more than the pitch.
- The refusals are the hardest case, and XTK does not solve them. A document request belongs to exactly one client in Practice Manager, so somebody you declined to verify — who may have no client record at all — has nowhere natural to sit. Those files need a deliberate answer of their own.
- XTK has no retention engine. It will not tell you that a file reaches seven years next month, will not delete it for you, and holds no concept of a retention period. Regulation 15's expiry dates have to live in whatever your practice uses to track obligations.
- Retrieval is not the same as storage. Uploads bypass XTK's servers, but downloading a file, zipping a selection or merging PDFs all stream through the backend — bytes pass through in flight and are never written to disk or stored, which is a different claim from “never touched”.
- The request history is a subscription record. The checklist, who was asked, when it was sent and what arrived against each line live in XTK's database and end when your account does; the documents in your Drive do not. Every vendor has that split — the part worth checking is which side of it your evidence sits on.
What to do before 17 November
None of this needs a software decision. It needs an hour, a written answer from one vendor, and a note of two dates.
- Establish whether your practice is acting as an ACSP and verifying identities at all. If not, regulation 15 does not bind you, and the work is chasing clients to verify directly rather than holding evidence.
- Ask your verification provider in writing: where are the records held, whose tenant are the bytes in, what happens if we stop paying, and for how long do you keep them? File the reply with your supplier records.
- Find out where a refused check currently ends up in your practice, by asking whoever did the last one. If the answer is an inbox or a deleted folder, that is the first thing to fix.
- Write the two clocks into your retention policy as separate lines — five years from the end of the relationship for due diligence, seven from the statement or refusal date for identity verification — rather than reconciling them into one number.
- Pull your list of unverified directors and PSCs now rather than in October, noting that the PSC population is the one furthest behind nationally.
Frequently asked questions
How long must an ACSP keep Companies House identity verification records?
Seven years. Regulation 15 of the Registrar (Identity Verification and Authorised Corporate Service Providers) Regulations 2025 requires records for every individual on whose behalf a verification or reverification statement was delivered, and for every individual the ACSP did not become satisfied about. The seven years run from the date stated in the statement, or — for a refusal — from the date the ACSP decided not to deliver one. The records must include the requests made under regulation 9 and all information and evidence the ACSP considered.
Do you have to keep records of identity checks that failed?
Yes, and for the same seven years. Regulation 15(3)(b) covers every individual in respect of whom the ACSP did not become satisfied that the required personal information was true. There is no exemption for a check that went nowhere or for a person who never became a client. The clock starts on the date of the decision not to deliver a statement, so it can begin before any engagement exists.
Is the seven-year period the same as the five years under the Money Laundering Regulations?
No — they differ in both length and trigger. Regulation 40 of the Money Laundering Regulations 2017 requires client due diligence records for five years beginning when the business relationship is known or reasonably believed to have ended. Regulation 15 requires seven years from the date of the verification statement or of a refusal. Satisfying one does not satisfy the other in either direction, so a retention policy needs both as separate lines rather than one reconciled figure.
What documents can an ACSP accept as identity evidence?
It depends on the ACSP's own technology. Under the Registrar's Rules 2025, Option 1 allows a single item — a biometric or machine-readable passport, a UK or EU photocard driving licence, a biometric EU or EEA identity card, a UK biometric residence permit or card — but only where the ACSP can validate cryptographic features. Where it cannot, Option 2 requires two items: two from Group A, largely photographic identity documents, or one from Group A plus one from Group B, which includes birth certificates, bank statements and utility or council tax bills at the current address.
What proportion of directors and PSCs have verified their identity?
As at 30 June 2026, Companies House reported 55.33% of director appointments verified, 49.47% of LLP member appointments and 41.86% of individual PSC appointments — 7,364,599 verified appointments in total, or 49.68% of those in scope. Those are appointments, not individuals: the release notes that a person can hold appointments in more than one corporate body. The figures are unaudited management information published on 30 July 2026, and that release restated earlier quarters after dormant-company appointments were added to the calculation.
Where should identity verification evidence be stored?
The regulations do not say, which makes it a decision rather than a default. The duty sits with the ACSP and its officers personally and is not transferred by uploading a file into a vendor's product, so the test is what happens to the records on the day you stop paying — seven years is longer than most software decisions survive. Storage in a tenant the practice controls directly, such as its own Google Workspace or Microsoft 365, removes that dependency. Whichever you choose, get the vendor's answer in writing.
Can XTK do Companies House identity verification?
No. XTK performs no identity verification, no cryptographic validation, no likeness assessment and no PEP or risk screening, so it cannot put a practice on Option 1 of the Registrar's Rules. Verification stays with whatever provider or process your practice already uses. What XTK does is collect the resulting evidence through a document request link — uploads go straight from your client's browser to your own Google Drive, OneDrive or SharePoint without passing through XTK's servers — and file it in that client's folder, where cancelling, expiry and submission all delete nothing. It has no retention engine, so it will not track or act on the seven-year expiry for you.