Firm ACSP Compliance Policy & Procedures Manual (2026 Edition) ICAEW PRACTICE ASSURANCE READY
REGULATORY COMPLIANCE DEED • ECCTA 2023 & MLR 2017

Firm ACSP Operating Policy & Procedures Manual

Internal Practice Compliance Manual for Authorised Corporate Service Provider Functions, Director Identity Verification & Cardiff Registrar Representations

APPOINTED PRACTICE: WESTMINSTER ACCOUNTANCY LIMITED
COMPANY REGISTRATION NUMBER: 04088172
REGISTERED OFFICE: WESTMINSTER HOUSE 9 CHAPEL PLACE, LONDON, EC2A 3DQ
POLICY OPERATIONAL DATE: 12 September 2026
COMPLIANCE PRINCIPAL / MLRO: Compliance Principal & MLRO
REGULATORY ARCHITECTURE: ReguLex UK Sovereign Registry Standards
Statutory Policy Index
1. Statutory Authority & Scope (ECCTA s.29)
2. Compliance Principal & MLRO Oversight
3. Identity Verification Due Diligence Standards
4. Management of 11-Digit Personal Codes
5. Confirmation Statement (CS01) Audits
6. London Gazette Strike-Off Defence (s.1000)
7. Appropriate Registered Office Rules (s.2)
8. Suspicious Activity Reporting (SAR) Protocols
9. Client Fee Addendums & Liability Shields
10. Staff Training & Verifiable CPD Retention

1. Statutory Scope & Authorised Corporate Service Provider (ACSP) Authority

This Manual establishes the internal operating protocols of WESTMINSTER ACCOUNTANCY LIMITED ("the Practice") acting as an Authorised Corporate Service Provider under Section 29 of the Economic Crime and Corporate Transparency Act 2023 (ECCTA 2023). As a firm supervised for anti-money laundering compliance under the Money Laundering, Terrorist Financing and Transfer of Funds (Information on the Payer) Regulations 2017 (MLR 2017) by the ICAEW or ACCA, the Practice is legally authorised to conduct statutory identity verification (IDV) on behalf of corporate clients, officers, and Persons with Significant Control (PSCs).

All partners, qualified practitioners, and fee-earning staff must strictly adhere to the controls set out herein prior to submitting statutory filings, attesting director verification statements, or lodging formal objections with the Registrar of Companies.

2. Designated Compliance Principal & MLRO Oversight

Overall responsibility for ACSP governance, identity verification attestation, and anti-financial crime controls resides with the designated Compliance Principal / Money Laundering Reporting Officer (MLRO). The Compliance Principal must ensure:

  • All verification attestations delivered to Companies House are verified against original biometric or certified documentary evidence;
  • Practice ACSP registration status is renewed annually with Companies House and our primary professional supervisory body;
  • No Confirmation Statement (CS01) is approved or electronically transmitted if any officer remains in unverified default following the transitional cliff-edge.

3. Identity Verification Due Diligence Standards (Biometric vs Secondary)

Standard Commercial "Know Your Customer" (KYC) checks are legally insufficient to meet Companies House ACSP standards. Prior to delivering an identity verification statement under ECCTA 2023 s.12(3), practice staff must apply the Registrar's verification benchmark:

  • Primary Biometric Validation: Direct electronic verification using cryptographic NFC chip inspection of a biometric passport, UK biometric residence permit, or approved national identity card coupled with liveness facial comparison; or
  • Secondary Documentary Verification: In the absence of biometric NFC validation, inspection of two independent, unexpired government-issued documents, verified in-person or via high-resolution certified electronic copy, corroborating full legal name, date of birth, and residential address.
Mandatory Prohibition: Practice staff are strictly prohibited from verifying any individual whose identity documentation displays tampering, name discrepancies, or expired validity. Any suspected document fabrication must be immediately escalated to the MLRO.

4. Management & Vaulting of 11-Digit Personal Verification Codes

Upon completion of identity verification, Companies House assigns each individual an 11-digit alphanumeric personal verification code. This code is unique to the individual for life and connects their personal statutory record across all UK corporate directorships.

The Practice must treat all personal verification codes as restricted cryptographic compliance assets. Codes must be stored within our AES-256 encrypted registry vault, accessible solely by authorised compliance staff, and never transmitted via unencrypted email. Codes must be re-validated prior to each annual Confirmation Statement filing.

5. Handling Unverified Officers & Confirmation Statement (CS01) Audits

Under Companies Act 2006 s.853A (as amended by ECCTA), the Registrar of Companies must reject any Confirmation Statement containing unverified directors or PSCs. Filing rejection immediately places the subject entity into statutory default.

The Practice enforces a 60-Day Pre-Filing Audit Cadence: 60 days prior to a client's Confirmation Statement review date, the practice automated radar audits the officer register. If an unverified officer is identified, written notice is dispatched requesting verification within 21 days. If the officer fails to comply within 14 days of the filing deadline, the file is escalated for formal disengagement under Section 9 of this Manual.

6. London Gazette Strike-Off Defence & Section 1000(4) Emergency Stay Procedures

When a client company defaults on annual filings, Companies House Cardiff publishes a First Gazette Notice in The London Gazette pursuant to Companies Act 2006 s.1000. This notice initiates a 60-day countdown to dissolution, triggering commercial bank account freezes across major clearing banks (Barclays, HSBC, Lloyds, NatWest) and Crown forfeiture (Bona Vacantia s.1012).

Where the subject company is an active trading entity, the Practice is empowered under Section 1000(4) to lodge an immediate formal Objection to Striking Off with the Registrar in Cardiff. The application must formally state: (1) active trading status; (2) commercial harm of bank account freezing; and (3) a 21-day professional undertaking by the Practice to bring all statutory filings into compliance. Lodging the petition stays dissolution for 90 days.

7. Appropriate Registered Office Policy (ECCTA s.2 & Form AD01/RP07)

Under Section 2 of ECCTA 2023, all company registered offices must be an "appropriate address" where documents delivered can be expected to come to the attention of a company representative, and recorded by acknowledgment of receipt. PO Boxes and unstaffed mail forwarding addresses are strictly unlawful.

Where the Practice provides Registered Office facilities, client companies must maintain an active compliance retainer. In the event of client abandonment or non-payment, the Practice shall file Form AD01 or Form RP07 with the Registrar to strike the unauthorised registered office address and relocate the entity to the Companies House Default Address Repository (Cardiff CF14 8LH).

8. Suspicious Activity Reporting (SAR) Protocols

In accordance with Part 7 of the Proceeds of Crime Act 2002 (POCA) and the Terrorism Act 2000, staff must report any knowledge or suspicion of money laundering, fraud, or identity theft to the MLRO. The MLRO shall evaluate whether to submit a Suspicious Activity Report (SAR) to the National Crime Agency (NCA).

Staff must maintain absolute confidentiality and avoid "tipping off" any client, director, or third party that a SAR has been considered or submitted (POCA s.333A).

9. Client Fee Addendums & Criminal Liability Insulation (CA 2006 s.1112A)

Companies Act 2006 Section 1112A creates criminal offences for delivering false or misleading statutory statements to Companies House without reasonable excuse, carrying penalties of Level 5 fines (£5,000) or up to 2 years imprisonment on indictment. To insulate the Practice from civil and criminal liability:

  • All corporate clients must execute the ECCTA Statutory Fee-Protection Engagement Addendum, establishing director verification as an extraordinary Crown mandate billed under our statutory schedule (£250.00 + VAT);
  • The addendum must explicitly hold the client director personally liable for the truthfulness of identity declarations;
  • If a client director refuses verification, the Practice must issue a formal Partial Disengagement Deed disclaiming all responsibility for annual confirmation statement filings and subsequent dissolution.

10. Staff Training & Verifiable Record Retention (3–5 Years)

Under MLR 2017 Regulation 24 and the ICAEW Revised CPD Regulations 2023 (Rule 3.2), the Practice must ensure that all relevant personnel receive regular, structured training in economic crime and corporate transparency enactments.

All fee-earning staff must complete the 4.0-Hour Verifiable CPD Masterclass on ECCTA Practice Compliance and achieve an 80% pass mark on the formal examination. The Practice Manager must retain the consolidated Practice Verifiable CPD Register and individual cryptographic certificate audit logs for a minimum of three years (or five years for statutory audit teams) for immediate presentation during ICAEW QAD or ACCA Practice Monitoring reviews.

Formal Policy Adoption by Appointed Practice

WESTMINSTER ACCOUNTANCY LIMITED
Adopted on 12 September 2026 by Senior Partner / Compliance Principal

Statutory Bureau Verification & Archive

ReguLex UK • Sovereign Practice Bureau
Archived in Sovereign Compliance Register • OGL v3.0 Crown Standards