CaraComp
CaraComp
Forensic-Grade AI Face Recognition for:
Get Started7-day refund guarantee**
digital-forensicsBy Cara Candelario

Director Identity Verification: Why the Companies House Gap Still Bites

Deepfake Laws Won't Protect Your Cases. Broken Identity Verification Already Risks Them.
A UK registry office setting symbolizes the push for stronger director identity verification after a major data exposure.

Last year, Companies House, the UK's official registry for corporate identities, handed investigators a case study nobody asked for. A vulnerability in its identity verification process exposed information linked to five million company directors, creating the conditions for corporate hijacking at industrial scale. No deepfake required. No synthetic face. Just a broken verification process that waved through bad actors while everyone else was busy debating AI-generated content.

TL;DR

Governments are scrambling to regulate deepfakes as a content problem, but the real fight is over identity verification infrastructure, and investigators without documented, auditable IDV workflows are already the weakest link in the chain.

That's the incident that has the UK's identity verification industry rattled right now. Biometric Update reports that the Companies House situation has surfaced deep anxieties across the UK's IDV sector, particularly around whether public-sector verification conducted under the Digital Verification Services framework is actually fit for purpose, or whether it's just undercutting private providers while delivering second-rate checks at taxpayer expense. The concern isn't abstract. It's about whether the infrastructure underpinning identity trust in this country is solid enough to stand on.

Spoiler: it often isn't. And deepfakes are only making that clearer.


Identity Verification Process: The Overlooked Real Threat

Identity Proofing Gaps Behind the Companies House Incident

Identity proofing is supposed to answer one plain question: is this person really who the document says they are? The Companies House incident shows what happens when that identity proofing step is weak, information tied to five million directors ended up exposed, not because anyone forged a passport, but because the checking process itself had a hole in it. Good identity proofing catches a bad document or a mismatched photo before it ever enters the system, and that's exactly the layer that failed here.

Verification Process Standards Regulators Are Now Demanding

A verification process only earns trust if it can be repeated, checked, and explained afterward. Regulators reviewing the Companies House fallout are asking whether the verification process behind public identity checks meets the same bar as private-sector document verification, or whether it quietly cuts corners. Any verification process that can't be audited after the fact is a liability waiting to surface, whether it sits inside a government registry or an investigator's case file.

Director Verification Service Gaps the Incident Exposed

A director verification service is only as good as the checks it actually performs, not the checks it claims to perform on paper. The gap in this case sat inside the verification service layer itself, where director details moved through the system without enough friction to catch a problem. Any verification service that skips a documented check step, even once, opens the same kind of hole that let five million director records slip through.

Directors and the ID Verification Standard Now Expected

Directors are now expected to sit behind a proper id verification standard, the same way company officers and bank signatories already do. Verify once, at the point of registration, and the id verification record should stay attached to that director for as long as they hold the role. When directors are not required to verify to that standard, the whole register carries the risk forward instead of closing it off early.

Politicians love a visible villain. Deepfakes, synthetic media that puts real faces on fake actions, make excellent villains. They're visual, they're alarming, and they generate headlines that write themselves. Alberta is proposing AI deepfake safeguards. South Korea just delayed its facial-recognition SIM registration trial to mid-2026 over risk concerns. The US is watching school districts in places like Radnor, Pennsylvania deal with AI-generated imagery targeting students. Legislators everywhere are reaching for the same tool: prohibition. Label deepfakes. Ban malicious use. Require disclosure.

Here's the problem. Regula puts it plainly: regulations that outlaw deepfakes without providing the detection tools to enforce them are, functionally, toothless. You can pass all the laws you want. Without the infrastructure to catch fake identities at the moment they're presented, at onboarding, at verification, at the point of transaction, those laws are theater.

Meanwhile, the actual fraud numbers are moving fast. Fintech Global reports that deepfake usage in biometric fraud attempts surged 58% in the past year, while injection attacks, where manipulated footage is fed directly into verification systems, rose 40% year-on-year. Global losses from insurance fraud alone using deepfakes now exceed an estimated $120 billion annually. These aren't projections. This is happening right now, across every sector that relies on digital identity to function. This article is part of a series, start with Deepfakes Hit 8 Million Courts Still Cant Prove A .

783%
increase in injection attacks against identity verification systems recorded in 2024, followed by an 88% rise in 2025
Source: World Economic Forum / Cybercrime Atlas

Let that land for a second. Injection attacks, where fraudsters bypass the camera entirely and feed pre-recorded or AI-generated video directly into the verification pipeline, increased 783% in a single year, according to the World Economic Forum's Cybercrime Atlas. That's not a trend line. That's a structural collapse in how we've historically assumed video-based verification works.


Companies House and the Institutional Reckoning Underway

Selfie Verification and Document Checks Under Fresh Scrutiny

Selfie verification, matching a live photo against a document photo, is one piece of a bigger identity verification chain, not the whole thing. The Companies House episode is a reminder that selfie verification alone, or a document check alone, cannot carry the full weight of proving identity when the surrounding process is weak. Layered checks, where a document, a photo, and a process log all point the same direction, catch problems that any single step would miss.

Here's what's interesting about watching regulators debate deepfake content laws while the financial sector quietly upgrades its entire identity stack: the institutions with the most to lose aren't waiting around. The US Centers for Medicare and Medicaid Services just expanded digital identity options for millions of beneficiaries. That's a federal agency extending biometric-backed verification to one of the most fraud-targeted populations in the country. In Ireland, a facial recognition payments firm just joined the Central Bank's Innovation Sandbox programme. The banking sector is stress-testing this infrastructure now, not after the legislation passes.

And the scale of adoption is telling. Regula's user base grew 62% to 240 million people, signaling that identity document verification is no longer a niche compliance function, it's core digital infrastructure, used by the same volume of people who use mainstream consumer apps. This isn't the early-adopter phase anymore.

"By 2026, 30% of enterprises will no longer trust identity verification solutions that rely solely on face biometrics due to AI-generated deepfakes." Keyless, 2026 Authentication Landscape Report

Read that again carefully. It doesn't say face biometrics are dead. It says face biometrics alone are no longer sufficient. The shift is toward layered, documented, auditable verification, where a facial comparison is one part of a chain of evidence, not the whole chain. That distinction matters enormously if you work investigations. Previously in this series: Platforms Rush To Face Scans To Fight Deepfakes Th.


Trusted by Investigators Worldwide
Run Forensic-Grade Comparisons in Seconds
Detailed facial comparison reports. Results in seconds.
Get Started
7-day refund guarantee**

Online Identity Verification Flaws: Professional Liability Risk

Biometric Verification and Authentication Layers That Actually Hold

Biometric verification works best as one link in a chain, alongside document checks and process logs, rather than a stand-alone answer. Strong authentication combines something the person has, like a passport or ID card, with something that proves it's genuinely them, like a live photo comparison. When authentication only checks one of those things, fraud gets through, and the Companies House incident shows what that gap looks like at national scale.

Let's be direct. If your current process for establishing that a photograph or video actually depicts your subject involves careful eyeballing and professional experience, you are already exposed. Not potentially exposed in some future regulatory environment, exposed today, in any court or deposition where opposing counsel decides to push on your methodology.

Here's the question that's coming for every investigator who hasn't updated their workflow: When a client hands you a "smoking gun" photo or video, what's your documented, repeatable, defensible process for proving it's actually the person it appears to be? If the answer involves the words "I compared it carefully," you're going to have a bad time when a judge asks you to walk through that process step by step.

This isn't hypothetical legal paranoia. The UK Fraud Strategy consultation currently under review is explicitly examining the standards and consistency of identity verification across sectors, including who bears liability when a verification process fails. The direction of travel is clear: weak process equals shared liability. That's how it works in finance, and it's heading toward investigations.

Why This Matters Right Now

  • ⚡ Courts are catching upOpposing counsel is increasingly aware of deepfake methodology and will challenge any comparison process that isn't documented and repeatable
  • 📊 The fraud tools are democratizing fastAI is lowering the barrier to identity fraud so dramatically that manual comparison simply can't keep pace with the sophistication of what investigators are now reviewing
  • 🔍 Facial comparison ≠ surveillanceKYC-standard facial comparison (your case, your subject, documented side-by-side methodology) is industry-standard investigative practice; it's what banks have required for years
  • 🔮 IDV infrastructure is consolidating around documented workflowsInvestigators who adopt these standards now are building the professional credibility that wins high-value cases Up next: Deepfake Laws Wont Protect Your Cases Broken Ident.

There's a tendency in investigative work to treat new verification tools as optional upgrades, nice to have, maybe useful on complex cases. That calculus has flipped. According to Infosecurity Magazine's coverage of the WEF analysis, five major trends are reshaping identity security simultaneously: AI tool democratization lowering fraud barriers, the persistence of presentation attacks in the near term, injection attack escalation, and critically, fragmented regulation that actively constrains defenses in the short term. Fragmented regulation means you cannot wait for the law to tell you what good practice looks like. You have to build it yourself, now.

The investigators closing cases faster than you, the ones whose work survives scrutiny when a case goes to litigation, are using documented, tool-backed, auditable facial comparison workflows. CaraComp was built specifically for this: facial comparison that produces a documented, reportable output your client can hand to a lawyer. That's not a luxury feature. At this point, it's table stakes.


Stop Waiting for a Law That Can't Actually Help You

What a Defensible Identity Verification Process Looks Like Online

A defensible identity verification process, whether it runs online or on paper, needs three things: a document check, a photo comparison, and a written record of both. Online identity checks make this easier in theory, because every step can be logged automatically, but only if the system is built to keep that information rather than discard it after a pass or fail decision. Investigators building their own identity verification process should borrow this same habit, keep the document, keep the photo, keep the notes.

The deepfake legislation coming through various parliaments and statehouses will eventually pass. Some of it will be well-designed. Most of it will outlaw things that are already practically unenforceable. None of it will hand you a methodology for standing in front of a judge and explaining, step by step, how you established that the person in your evidence is actually who your client says they are.

That part is on you. And the Ondato analysis of global deepfake regulation makes the industry consensus clear: detection technology and verification infrastructure are the actual legal compliance baseline, not the legislation itself. The law describes what's prohibited. The technology is what proves it happened.

Key Takeaway

Deepfake laws may shape the rules of engagement, but they won't defend your evidence. Only documented, tool-backed identity verification, the kind that produces an auditable trail from source image to final report, will stand up when your work is challenged in court.

Look closely at what actually broke in the Companies House case, and the identity verification process itself is the story, not any single fraud technique. A document could be genuine, a photo could be a real match, and the overall identity verification process can still fail if there's no way to check the work afterward. That's why any serious identity verification process needs an audit trail as a basic requirement, not an add-on for complicated cases.

Passport checks remain a foundation of most identity verification process design, because a passport is issued under stricter controls than most other documents. But a passport alone only proves the document is real, it doesn't prove the person holding it is the person named on it. That's the gap that photo comparison and process documentation are meant to close, and it's the same gap that showed up in the Companies House exposure.

Authentication, in plain terms, means proving a claim is true rather than just plausible. Weak authentication accepts a document and a face and assumes they belong together; strong authentication checks that assumption against a documented process every single time. The Companies House incident is what happens when authentication becomes a formality instead of an actual check, at a scale of five million records.

None of this requires exotic technology. It requires treating information about identity, names, documents, photos, dates, as something that has to be verified and logged, not just collected. Organizations that treat information casually during onboarding are the ones that end up explaining a breach afterward. Organizations that treat the same information as evidence, kept in an auditable form, are the ones that can show regulators exactly what happened and when.

Online identity checks are not inherently weaker than in-person checks, despite what the instinct might say. An online process that logs the document, the photo, and the comparison result can be more auditable than an in-person check that relies on a staff member's memory of the encounter. The problem was never that Companies House verification happened online, it's that the online process didn't keep enough of a record to catch the gap before it became a five-million-record exposure.

For investigators, the lesson from Companies House translates directly into casework. Every photo, every document, and every step of the comparison process should leave a trail that a skeptical third party, a judge, a regulator, an opposing lawyer, could follow without asking you to explain what you meant. That's the same standard public registries are now being asked to meet, and it's a reasonable one to hold yourself to as well.

All company directors must complete id verification under the current framework, and that requirement is what makes the Companies House gap so significant. Mandatory identification requirements will apply across the register, not just to newly appointed officers, which means the existing pool of directors needed the same level of scrutiny as anyone joining fresh. When identity verification becomes a formality rather than an enforced step, mandatory idv rules on paper do little to close the actual gap on the ground.

Companies House sits alongside gov uk services as one of the places where a director's personal details are entered into an official record, which is exactly why the verification service wrapped around that entry point matters so much. The idv requirements attached to director registration exist to stop someone using a stolen or invented identity to control a company, and pscs, people with significant control, face a related but separate identification requirement of their own. A login to the Companies House system should never be treated as proof of identity on its own; it is only as trustworthy as the id verification that sat behind account creation in the first place.

Overseas directors and non-uk directors add another layer of difficulty, because the documents used to verify identity vary by country and are not always easy for a UK-based check to confirm quickly. Director identity checks for someone based outside the UK often rely on identity documents that a domestic verification service was never built to assess in detail. That's not a reason to skip the check; it's a reason to route non-uk directors through a verification service with the experience and document library to handle it properly.

A sound director verification process treats every director the same way it treats a new customer at a bank: check the document, check the person, log the result, and keep that log somewhere it can be found again. Director identity should never be assumed from a login, a signature, or a form filled out correctly, because none of those things prove the person behind them is real. The Companies House case shows what happens when that assumption is allowed to stand in for an actual check.

Policy discussions about mandatory idv tend to focus on the moment a director registers, but the code behind the verification service matters just as much as the policy sitting on top of it. A verification service that is well designed on paper but poorly built underneath will still let bad identities through, exactly as happened here. Getting the policy right is only half the job; the other half is making sure the code enforces it every single time, for every single director, without exception.

Frequently asked questions

What is director identity verification and why does it matter?

Director identity verification is the process of confirming that a company director is really who their documents claim, at the point of registration. The Companies House incident shows what happens when that process is weak: information tied to five million directors was exposed because the checking process itself had a hole in it, not because anyone forged a document.

What caused the Companies House director identity verification failure?

A vulnerability in the identity verification process itself caused the exposure, not a forged passport or deepfake. Director details moved through the system without enough friction to catch a problem, meaning the gap sat inside the verification service layer, allowing information linked to five million company directors to slip through unchecked.

Can new deepfake laws fix director identity verification problems?

No. Regulations that outlaw deepfakes without providing detection tools to enforce them are functionally toothless. Passing laws does nothing without infrastructure to catch fake identities at onboarding or verification. The real fix is a documented, auditable director identity verification standard applied once at registration and kept attached to that director going forward.

Ready for forensic-grade facial comparison?

Full forensic reports with detailed similarity scoring. Results in seconds.

Run My First Search