Three changes. Three different dates. One law that has been quietly rewriting what it means to run a company in the UK.
The Economic Crime and Corporate Transparency Act 2023 has been rolling out in stages since it passed. Most companies engaged with the early headlines and assumed the heavy lifting was done. It was not.
Right now, the changes that matter most are the ones that landed in the last twelve months, and the one that has a deadline four months away.
The Identity Verification Clock Is Running Out
From 18 November 2025, identity verification became a legal requirement for all UK company directors and Persons with Significant Control.
Around 6 to 7 million individuals need to complete it. The absolute backstop deadline is 18 November 2026. That is four months from now.
The Real Deadline Hidden in Your Filing Date
But here is where people are getting caught. The real deadline is not November 2026 for most companies. It is your next confirmation statement filing date.
If a director on your board has not verified by the time that statement comes due, Companies House will not accept it. The company cannot file. Strike-off risk follows.
No Personal Code, No Directorship
New directors appointed from 18 November 2025 onwards cannot be validly appointed without providing a Companies House personal code at the time of filing. There is no grace on that. The appointment does not exist without it.
The verification itself is free. It takes ten to twenty minutes through GOV.UK One Login using a passport or driving licence. Each verified individual receives a unique personal code which applies across all their Companies House roles. Verify once, use everywhere.
The Double-Verification Trap for PSCs
For PSCs who are also directors, the process requires providing the code twice. Once through the confirmation statement as a director. Again through a separate service within fourteen days of the confirmation statement date, in the capacity of PSC.
Filing agents and third-party accountants who submit documents on behalf of companies face their own IDV requirements too, though Companies House has pushed that phase back to no earlier than November 2026.
Failure to Prevent Fraud: Already in Force, Often Misunderstood
Since 1 September 2025, the UK has had a new strict liability criminal offence on its books. If an employee, agent, or subsidiary commits fraud with the intention of benefiting your company or its clients, and your company does not have reasonable fraud prevention procedures in place, the company can be prosecuted.

The offence sits in Section 199 of ECCTA. The Serious Fraud Office described its deployment as a landmark moment that would widen the reach and breadth of prosecutions. The SFO and Crown Prosecution Service published joint prosecution guidance shortly before the offence came into force.
Why Small Businesses Are Swept into the Scope
Technically, the offence directly targets large organisations, defined as those exceeding two of three thresholds: more than 250 employees, more than £36 million turnover, or more than £18 million total assets.
But smaller businesses are not off the hook entirely. Large clients and supply chain partners are now asking suppliers and contractors to demonstrate their own fraud controls before awarding contracts. If you work with larger organisations, their compliance requirements flow down to you whether you are technically in scope or not.
The Strict Standard for “Reasonable Procedures”
The defence available is straightforward to understand but requires evidence to rely on. A company must show it had reasonable fraud prevention procedures in place at the time the fraud occurred.
Government guidance sets out six principles: top-level commitment, risk assessment, proportionate procedures, due diligence, communication and training, and monitoring and review. Existing compliance processes do not automatically qualify. ECCTA requires a specific assessment against the fraud offence, not just general compliance frameworks.
29 June 2026: The Change Nobody Is Talking About Enough
This one is the biggest. And it arrived this month.
The Crime and Policing Act 2026 received Royal Assent on 29 April 2026. Section 250 came into force on 29 June 2026 and it replaces Section 196 of ECCTA entirely.
Under the old ECCTA provision, a company could be held criminally liable for a limited list of economic crimes committed by a senior manager acting within their authority. Fraud, bribery, tax evasion, money laundering.
Under Section 250 of the Crime and Policing Act, that list is gone. It is now any criminal offence.
Health and safety violations. Data protection breaches. Environmental offences. Licensing infringements. If a senior manager commits any criminal offence while acting within the actual or apparent scope of their authority, the company is guilty of that offence too.
What This Means if You Run a Limited Company
Three separate obligations are now sitting on your desk, whether you have looked at them or not.
Identity verification is the most time-sensitive. Check when your company’s next confirmation statement is due. Every director and PSC on your register needs to have verified before that date. If you use an accountant or filing agent to submit on your behalf, they need to verify too under the incoming ACSP requirements. Our limited company accounting team handles Companies House compliance and can confirm where your directors stand.
On fraud prevention, if you have ten or more employees and handle client money, invoicing, or payments of any kind, it is worth spending time on a documented fraud risk assessment even if you sit below the large organisation threshold. The question is not whether you are legally required to have one. It is whether you want to be able to demonstrate you took the issue seriously if something goes wrong. Lanop’s team works with startups and growing businesses on exactly this kind of compliance groundwork.
On the Crime and Policing Act, the immediate action is to identify who in your business qualifies as a senior manager under the substantive definition, not just by title. Then assess where their decision-making creates risk. This does not require legal counsel for most small businesses. It requires honest thinking about who is making material decisions and whether your oversight of those decisions is visible and documented.
Corporation tax, director responsibilities, and annual compliance all interact with these changes. Getting them right together matters more now than it did before June.
One Law, Three Layers
ECCTA began as a response to the abuse of UK corporate structures for fraud and money laundering. What it has become is something broader: a systematic raising of the bar for what it means to run a company properly in the UK.
Identity verification cleans up who is actually on the register. Failure to prevent fraud puts responsibility for employee conduct on the company. The Crime and Policing Act 2026 closes the gap that let large complex organisations escape liability for crimes their senior people committed inside the business.
Lanop works with limited companies, contractors, and growing businesses across all stages of HMRC and Companies House compliance. If you want to check where your company stands on any of the changes above, get in touch today.