Economic crime · Corporate transparency · Legal-sector compliance
The Economic Crime and Corporate Transparency Act 2023 is not just another company-law reform. It changes the compliance climate around corporate identity, company records, authorised agents, fraud prevention and professional gatekeepers. For law firms, the point is not simply that the Solicitors Regulation Authority has a role. The point is that legal practice now sits closer to the machinery designed to prevent misuse of companies, corporate filings and professional services.
Publication snapshot
- The ECCTA 2023 is a broad economic-crime and corporate-transparency statute, not a narrow SRA-only reform.
- The strongest public-interest point is the shift from passive registration towards more active corporate-identity and register-integrity controls.
- Companies House reform, identity verification, authorised corporate service providers and the failure-to-prevent-fraud offence are central to the compliance landscape.
- Law firms should not treat this as “more paperwork”; it is part of the legal sector’s gatekeeper risk in economic crime prevention.
- The practical test is whether a firm can evidence client identity, company-control checks, source-of-funds/source-of-wealth analysis, fraud-risk thinking, and clear escalation where the company record does not make sense.
The core point: transparency only works if gatekeepers use it
The supplied draft correctly identifies the ECCTA 2023 as a significant anti-economic-crime reform. But it overstates the issue if it treats the Act mainly as a direct expansion of SRA power.
The better analysis is broader. The Act changes the environment in which law firms operate. Companies House is no longer best understood as a passive recipient of filings. Company officers and people with significant control face identity-verification requirements. Authorised intermediaries have a more formal role. Large organisations face a new failure-to-prevent-fraud offence. Legal regulators sit within a system that increasingly expects professional gatekeepers to detect, prevent and escalate economic-crime risk.
That distinction matters. A law firm does not discharge its responsibility by saying a company exists on the register. The modern question is whether the registered information, client story, beneficial ownership, funding route, transaction purpose and risk profile make sense together.
Companies House is changing
The corporate register is being reshaped around better identity, data quality and misuse prevention.
Control needs verification
Directors, PSCs and those involved in company formation face a more formal identity-verification framework.
Professionals carry risk
Solicitors, accountants and company-service providers can become part of the defence against misuse of corporate structures.
Compliance must be provable
The practical question is not whether checks were said to exist, but whether the file shows what was checked and why.
What ECCTA changes: from filing culture to verification culture
For years, one of the central criticisms of UK corporate transparency was that companies could be formed and maintained with information that was easier to file than to trust. The ECCTA 2023 is part of the legislative response to that problem.
Its company-law reforms are aimed at improving the integrity of the register, strengthening the role of Companies House, making identity verification a central control point, and reducing the ability to misuse companies as anonymous or misleading vehicles. It also sits alongside broader economic-crime reforms, including measures aimed at fraud and corporate accountability.
The practical shift is cultural as well as legal. Filing is no longer enough. Professionals who form, advise or act for corporate clients need to understand whether the corporate record reflects reality. That includes who controls the company, who funds the transaction, who gives instructions, who benefits, and whether there are signs of nominee structures, false filings or unexplained funds.
Cleaner registers
The register is expected to become more reliable, with greater scrutiny of false or misleading information.
Verified control
Identity checks for company officers and people with significant control move corporate transparency closer to verified accountability.
Economic-crime prevention
The compliance burden shifts towards prevention, not simply reaction after a fraudulent structure has already caused harm.
The SRA role: important, but not the whole story
The SRA regulates solicitors and law firms in England and Wales. Its relevance to ECCTA is not that every company-law reform becomes an SRA enforcement matter. Its relevance is that solicitors often sit at key points in transactions where corporate structures, client identity, beneficial ownership, source of funds and economic-crime risk are assessed.
That means law firms need to treat ECCTA-related change as part of a wider risk environment. A solicitor forming companies, advising directors, acting in property transactions, handling client money, registering as an authorised corporate service provider, or dealing with opaque ownership structures may face a sharper professional-risk question if the file shows weak verification, weak inquiry or blind reliance on filings.
The SRA point should therefore be framed carefully. The Act is not best described as simply giving the SRA direct control over Companies House processes. The stronger point is that economic-crime prevention has become a clearer regulatory expectation across legal services, and that solicitors’ files must be able to show competent, evidence-led risk assessment.
Gatekeeper duties
Solicitors must maintain professional standards while avoiding blind facilitation of suspicious structures or transactions.
Client and transaction checks
The file should show identity, beneficial ownership, source-of-funds and source-of-wealth thinking where risk demands it.
Identity verification: the compliance issue hiding in plain sight
Identity verification is sometimes treated as administrative. That is a mistake. In economic-crime prevention, identity is a control point. If the people behind a company cannot be reliably identified, the rest of the compliance analysis becomes weaker.
For directors and people with significant control, the new identity-verification framework is intended to make corporate control harder to disguise. For law firms and other advisers, the practical question is how Companies House identity verification interacts with their own client due diligence. One does not simply replace the other.
A verified Companies House identity may help the file. It does not by itself prove source of funds, commercial purpose, absence of fraud risk, absence of sanctions risk, or absence of nominee arrangements. Compliance needs to connect the identity check to the wider transaction risk.
Identity verification: what the file should show
- Who is the client, who gives instructions, and who ultimately benefits.
- Who are the directors, PSCs, controllers, nominees or intermediaries.
- Whether Companies House identity verification is relevant and complete.
- Whether the firm’s own client due diligence supports the same picture.
- Whether source of funds, source of wealth and transaction purpose are coherent.
Authorised agents: opportunity and exposure
The ECCTA framework makes authorised intermediaries more important. Accountants, solicitors and other supervised professionals may act as authorised corporate service providers in the company-filing and identity-verification system.
That creates opportunity. It also creates exposure. A professional who verifies identity or files company material is not merely pressing buttons. They are participating in a system intended to improve register integrity. If the work is casual, under-resourced or treated as commodity administration, the risk increases.
For law firms, the operational question is whether they want to act in that role at all, and if so, whether they have documented procedures, trained staff, audit trails, escalation routes, conflict checks, data-protection controls and a clear decision about which clients or matters they will refuse.
What services are offered?
Company formation, filings, identity checks and corporate maintenance should not be bundled without clear risk controls.
Who approves risky matters?
High-risk structures need escalation, supervision and file notes explaining why the firm proceeded.
Can the file be tested?
The compliance record should show identity evidence, checks completed, anomalies found and decisions made.
Failure to prevent fraud: why prevention now matters more
The failure-to-prevent-fraud offence marks a wider policy direction. For large organisations, the question is no longer only whether senior management personally authorised misconduct. The question can become whether the organisation had reasonable fraud-prevention procedures in place when an associated person committed fraud for its benefit.
That matters for law firms in two ways. First, larger legal businesses may need to consider their own organisational fraud-prevention procedures. Secondly, law firms advising corporate clients need to understand how fraud-prevention culture, internal controls and reporting routes fit into corporate governance.
The practical Legal Lens point is that prevention needs evidence. A policy on a shared drive is not enough. Training, risk assessment, reporting lines, investigation records, third-party controls and board-level oversight may all become part of the proof that the organisation took fraud prevention seriously.
Risk identified
The organisation identifies where fraud could arise through employees, agents, subsidiaries or other associated persons.
Controls designed
Procedures are built around real risk, not generic policy language.
People trained
Staff and third parties understand escalation, red flags and reporting responsibilities.
Evidence retained
The organisation can show what it did before the problem, not only what it said afterwards.
Law-firm risk: the dangerous middle ground
The dangerous middle ground is where a law firm thinks the issue belongs to Companies House, while Companies House reform assumes professional advisers will act as serious gatekeepers.
A solicitor may not be responsible for every false statement on a company record. But if the solicitor is forming the company, advising on the transaction, handling funds, submitting filings, verifying identity or ignoring obvious inconsistencies, the file may later be scrutinised. Economic-crime risk often hides in ordinary-looking paperwork.
Examples include complex ownership chains without commercial explanation, repeated changes of control, unusual source-of-funds explanations, overseas entities with weak documentation, clients who resist identity checks, nominee arrangements, mismatched addresses, urgency without rationale, and instructions coming from someone other than the apparent client.
Identify the person giving instructions and the person who benefits.
Check whether the corporate record matches the transaction story.
Source-of-funds and source-of-wealth analysis should be risk-sensitive.
The commercial rationale should be coherent and evidenced.
Compliance discipline: what firms should do now
The response should not be panic. It should be disciplined implementation.
Firms should identify which parts of their practice engage corporate formation, company maintenance, property, client money, trusts, tax, insolvency, overseas entities, mergers, acquisitions, investment structures, or high-risk clients. They should then decide what the file must show in each category.
The best compliance systems are practical. They help fee earners ask the right questions, escalate the right matters and stop the wrong ones. They are not just a folder of policies that nobody uses.
ECCTA and economic-crime compliance pack
- Updated client due-diligence and beneficial-ownership procedures.
- Checklist for directors, PSCs, authorised agents and Companies House identity verification.
- Source-of-funds and source-of-wealth templates with escalation triggers.
- Fraud-risk assessment for firm operations and higher-risk client services.
- Training records for company-services, property, corporate and private-client teams.
- File-review process for high-risk structures, overseas entities and urgent transactions.
- Refusal and exit policy where client identity, purpose or funding cannot be reconciled.
- Board or COLP/COFA reporting on economic-crime risk trends and remediation.
Implementation challenge: small firms need usable systems
One legitimate concern in the draft is implementation burden. Smaller firms may not have large compliance teams, dedicated analysts or expensive software. That does not remove the obligation to manage risk, but it does affect how systems should be designed.
A smaller firm does not need an over-engineered compliance machine. It needs a clear intake process, sensible templates, escalation rules, training, supervision, file reviews and the confidence to refuse work where the client story cannot be made coherent.
The regulatory test should not reward paperwork theatre. It should reward usable controls. A short file note explaining why a risk was identified, what was checked, who approved it and why the firm proceeded can be more valuable than a long generic policy that did not affect the decision.
Map risk areas
Identify where the firm touches companies, money, control, property, entities or high-risk jurisdictions.
Standardise checks
Use simple templates for identity, beneficial ownership, funding and transaction purpose.
Escalate anomalies
Make it easy for fee earners to pause when the corporate record does not match the client story.
Record decisions
File notes should explain the risk, checks, outcome and approval route.
Review and learn
Use file audits and near-miss reviews to improve the system before a regulatory problem arises.
Source anchors
These anchors support the corporate-transparency, economic-crime and legal-sector compliance framework. They do not prove that any particular solicitor, law firm, company, director, PSC or authorised corporate service provider has acted improperly.
- Economic Crime and Corporate Transparency Act 2023 — primary legislation for the corporate-transparency and economic-crime reform framework.
- GOV.UK: Changes to UK company law — official Companies House and government guidance collection on ECCTA implementation.
- GOV.UK: Identity verification for Companies House — official guidance on identity verification under the Companies House reform programme.
- GOV.UK: Register as a Companies House authorised agent — official route for authorised corporate service providers.
- SRA: Money laundering and terrorist financing resources — SRA guidance and resources for firms managing AML risk.
- SRA: Financial sanctions regime guidance — SRA guidance on sanctions compliance for firms.
- GOV.UK: Failure to prevent fraud guidance — official guidance on the corporate offence and reasonable fraud-prevention procedures.
Closing point
The ECCTA 2023 is not only about Companies House. It is about the credibility of the corporate record and the professionals who help people use it.
For law firms, the public lesson is simple. Do not treat corporate transparency as someone else’s filing problem. Treat it as part of the file’s integrity.
A register is only as reliable as the people who use, check and challenge it. The modern compliance question is not “did the company exist?” It is “did the firm understand who stood behind it, why the transaction made sense, where the money came from, and what the file would show if a regulator asked?”
Economic-crime compliance, Companies House reform and file evidence
Get a free written assessment before a corporate-compliance gap becomes a regulatory problem
Legal Lens can help turn an ECCTA, AML or corporate-transparency concern into a structured compliance map. The assessment separates client identity, beneficial ownership, Companies House checks, source of funds, source of wealth, transaction purpose, escalation triggers and the evidence your file should show.
Compare Companies House information with the client story, control structure and transaction purpose.
Map identity, beneficial ownership, funding, wealth, sanctions, AML and escalation decisions.
Identify policy updates, file notes, training, supervision, refusal triggers and review points.
Independent Legal Lens consultancy. Legal Lens is not a regulated solicitors’ firm, AML supervisor, company service provider, regulator, auditor or claims-management company. A preliminary assessment is not a substitute for regulated legal advice, specialist AML advice, professional compliance advice, formal representation or regulator-facing advice where that is needed.

