Fake Company Registration Certificates in KYB Onboarding
How fraudsters forge Companies House certificates of incorporation and filing histories to pass KYB checks, and how compliance teams detect and stop it.

Summarize this article with
A fake company registration certificate is a Companies House certificate of incorporation, confirmation statement, or filing extract that has been edited, fabricated, or presented with a genuine company number but substituted details, in order to pass a KYB onboarding check. Because the underlying register is free and public, fraudsters can steal, edit, or misrepresent a real filing far more easily than they can forge a bank statement or a passport. This is the fraud-detection companion to our guide on how to verify a company registration certificate online: that article covers the legitimate lookup process, this one covers how the document gets faked and how it gets caught.
This article is for informational purposes only and does not constitute legal, tax, or regulatory advice. Consult a solicitor or compliance professional for guidance specific to your organisation. Legislation and guidance referenced are current as of 25 July 2026.
What a Certificate of Incorporation Proves โ and What It Does Not
A certificate of incorporation confirms that a company was legally formed on a specific date, under a specific name and company number, but it says nothing about who currently runs the business. It is issued once, at formation, and never updated โ a genuine certificate from 2019 remains genuine even if the company has since changed directors three times, moved its registered office twice, or been dissolved. KYB (Know Your Business) onboarding treats the certificate as only a starting point: proof the entity was validly created, not proof it is still trading, solvent, or controlled by the people a counterparty believes it is dealing with.
The filing history is what matters for ongoing risk, since it records confirmation statements, annual accounts, officer changes, and Persons with Significant Control (PSC) declarations as they happen. A counterparty who presents only the original certificate, without an up-to-date filing history alongside it, is showing a snapshot from formation day rather than the company's current legal state โ and that gap is where forged or manipulated documents tend to hide.
The 2026 Identity Verification Reform Changes the Fraud Calculus
Companies House now requires every director, LLP member, and person with significant control to verify their identity, closing a loophole that let anyone incorporate a UK company under a fabricated name. Mandatory identity verification became a legal requirement on 18 November 2025 under the Economic Crime and Corporate Transparency Act 2023 (ECCTA), using GOV.UK One Login's biometric checks or an Authorised Corporate Service Provider, with existing directors and PSCs given until 18 November 2026 to complete verification during a phased transition covering more than seven million individuals (GOV.UK, Verifying your identity for Companies House).
This is the largest change to UK company law in over 150 years, and it targets a specific fraud pattern: registering a brand-new shell company under an invented or stolen identity (Companies House, Verifying your identity with GOV.UK One Login). What it does not solve is forgery of documents relating to companies that already exist. A fraudster who cannot register a new shell under a fake name can still take a real, long-established company's genuine certificate and filing history and misrepresent who controls it today โ which is why document-level verification against the live register remains necessary even once ECCTA's identity checks are fully in force.
How Fraudsters Actually Forge These Documents
Editing a genuine downloaded PDF is the most common method, because Companies House filings โ the certificate of incorporation, confirmation statements, and accounts โ are free to view and download by anyone. A fraudster downloads a real filing, opens it in a PDF editor, and changes the registered office, director names, or filing date before presenting it as current, relying on the reviewer not cross-checking against the live register.
Fabricating a document from scratch is less common but still occurs, usually where the target is a one-off visual check rather than a determined verifier. This means recreating the Companies House layout, crest, and certificate wording in a design tool or, increasingly, using generative AI to produce a convincing image-based certificate with plausible registrar details and a fabricated company number that either does not exist or belongs to an unrelated entity.
Corporate identity theft is the more dangerous variant: using a real, active company's genuine number and name, but substituting the director names, PSC details, or registered office on the document presented. Because the company number checks out on a cursory glance, this survives a reviewer who confirms "yes, that company exists" without comparing every field against the live filing โ commentators tracking Companies House abuse have documented cases where dozens of companies were registered against residential addresses the occupants never authorised, showing how loosely register data can be manipulated when nobody checks it against reality (Tax Policy Associates, How criminals are setting up fake banks using Companies House).
A fourth pattern is a stale filing history that quietly omits a recent strike-off notice, Gazette publication, or dissolution action. The certificate and early filings are entirely genuine; what is missing is the most recent entry showing the company is no longer active, in liquidation, or subject to compulsory strike-off under the Companies Act 2006.
Ready to automate your checks?
Free pilot with your own documents. Results in 48h.
Request a free pilotReal Fraud Schemes This Enables
Invoice fraud and CEO fraud frequently start with a forged or manipulated registration document used to impersonate a real, trusted supplier, redirecting payment to an account the fraudster controls while the company details look legitimate on paper. Construction and facilities management see fraudulent subcontractor onboarding, where a forged or borrowed certificate lets a non-compliant contractor pass a tier-one contractor's paperwork check before work begins โ a pattern that echoes the CIS and compliance-certificate fraud covered in our vendor compliance certificate piece.
Synthetic company setups for money laundering or loan fraud pair a genuine or lightly-altered registration document with fabricated financial statements to clear a lender's onboarding threshold, echoing the tactics in our analysis of fake financial statements in business lending fraud. In each scheme, the registration certificate is rarely the fraud itself โ it is the credential that gets the fraudster past the door.
Detection Techniques That Actually Work
The single most effective control is cross-checking the company number directly on the free Companies House register rather than trusting the PDF a counterparty has sent. Searching find-and-update.company-information.service.gov.uk takes under a minute and shows the company's current status, registered office, officers, and PSC data as Companies House actually holds them โ any mismatch with the document received is the clearest signal of tampering.
Filing history review catches what a static certificate cannot: a strike-off notice, Gazette publication, or dissolution entry the document conveniently omits. PDF metadata analysis is a second layer โ the creation software, author field, and modification timestamps can reveal that a "2019 certificate" was actually last saved in an image editor a few weeks ago. Font and layout inconsistencies against the genuine template are a weaker but still useful signal, particularly for wholesale fabrications rather than edited originals. Finally, the absence of any verifiable digital element โ genuine digital certificates carry an authentication code checkable against Companies House's own systems โ on a document claiming to be an official digital certificate is itself a red flag.
| Red flag | Verification method | What it reveals |
|---|---|---|
| Company number matches, but director or PSC names differ from the document | Search the company number on the free Companies House register | Corporate identity theft โ real entity, fabricated control details |
| No recent filings beyond the incorporation certificate | Review the filing history tab on the register | Possible shell entity or deliberately stale document |
| Certificate presented as current for a dissolved or struck-off company | Check current status and Gazette notices on the register | Stale filing history concealing dissolution or strike-off |
| PDF creation date inconsistent with claimed certificate date | Inspect file metadata (creation software, save history) | Document edited or fabricated after the date it claims to represent |
| Layout, crest, or wording differs from the genuine Companies House template | Compare against a certificate ordered directly from Companies House | Wholesale fabrication rather than an edited genuine filing |
| No verifiable digital authentication code on a "digital certificate" | Attempt to verify the code, or order a fresh certified copy | Document does not originate from Companies House's own system |
What Compliance Teams Are Actually Asking
Compliance and fintech practitioners on specialist forums often ask how to tell a slightly outdated but genuine certificate from a deliberately manipulated one, since a company that has not updated its filings in a while can look superficially similar to one hiding something. The distinguishing factor is not the age of the certificate โ static by design โ but whether the current register entry (status, officers, PSC data) matches what the counterparty is claiming today; an old certificate paired with a consistent filing history is normal, one paired with a contradicting filing history is not.
A second recurring question is whether a single discrepancy, say a registered office address that does not match, is enough to reject a counterparty outright. In practice, one inconsistency should trigger a direct register check and, where relevant, a request for an explanation before any onboarding decision, but two or more inconsistencies on the same document, especially involving officer identity or company status, is treated by most compliance teams as grounds to pause the relationship pending verification with Companies House directly.
Legal Framework and Liability
Presenting a forged or manipulated registration document to induce a business decision falls within false representation under Section 2 of the Fraud Act 2006, carrying a maximum sentence of ten years' imprisonment on indictment (legislation.gov.uk, Fraud Act 2006, Section 2). Separately, delivering a false or misleading document or statement to the registrar is itself an offence under Section 1112 of the Companies Act 2006, covering the filing side of the fraud rather than the document shown to a third party.
For regulated businesses, the obligation to scrutinise business documentation as part of KYB sits within the Money Laundering, Terrorist Financing and Transfer of Funds (Information on the Payer) Regulations 2017, which require customer due diligence proportionate to risk, including verification of a corporate customer's constitution and controlling persons (legislation.gov.uk, The Money Laundering Regulations 2017). A regulated firm that onboards on the strength of an unchecked, forged certificate is not merely exposed to the underlying fraud โ it risks its own compliance position under the MLR 2017 due diligence regime.
A Layered Approach to Detection
Manual detection methods, including routine visual review of documents, catch only around 37% of occupational fraud cases, with a median delay of 87 days before detection (ACFE, 2024 Report to the Nations). That gap exists because a well-edited PDF can pass a five-second glance every time; it only fails when checked against an independent source, which is why register cross-checking has to be a standing step in onboarding, not a discretionary one applied only when something already looks wrong.
CheckFile's approach layers structural analysis, metadata checks, and cross-document validation, built to cover 3,200+ document types and 32 jurisdictions. CheckFile also deploys an AI-generation detection layer as a complementary signal, not a replacement for cross-checking the official register. A forged Companies House certificate still has to be checked against the live register and its filing history to confirm the company's actual status, directors, and PSC data โ no amount of document-level analysis alone substitutes for that step.
For teams refining a full KYB workflow, our complete guide to business entity verification covers the wider process, and our industry verification guide sets out sector-specific checks across financing, construction, and regulated services. CheckFile's platform is also used in equipment financing and leasing, where a forged registration document paired with fabricated financials recurs โ see our security page, pricing, and homepage for more.
If your onboarding process still relies on a visual read of a PDF a counterparty has sent, CheckFile's AI-generated document detection adds AI-generation signals as a complement to your existing controls โ not a guarantee of catching every forgery, but a meaningful layer alongside register cross-checks and filing history review.
Frequently Asked Questions
Can a fake company registration certificate use a real company number?
Yes โ this is corporate identity theft, the most dangerous variant of the fraud. The company number and name are genuine and will pass a superficial check, but the director names, PSC details, or registered office on the document have been substituted. The only way to catch it is comparing every field against the live Companies House register, not just confirming the number exists.
Does the 2026 Companies House identity verification requirement stop certificate forgery?
It substantially reduces one specific risk โ registering a brand-new shell company under a fabricated identity โ but it does not stop forgery of documents relating to companies that already exist. Existing directors and PSCs have until 18 November 2026 to complete verification, and forged or manipulated certificates for long-established, genuine companies remain a live risk that requires independent document checks.
What is the fastest way to check if a Companies House certificate is genuine?
Search the company number on the free register at find-and-update.company-information.service.gov.uk and compare the company name, status, registered office, officers, and PSC data against the document presented. This takes under a minute and is more reliable than any visual inspection of the PDF itself.
What happens if a stale filing history hides a recent strike-off?
The certificate and early filings may be entirely genuine, but the register's current status field and any Gazette notices will show the strike-off or dissolution that the presented document omits. Checking the filing history tab, not just the certificate, is essential to catch this pattern.
Is presenting a forged registration certificate a criminal offence in the UK?
Yes. Using a forged or manipulated certificate to induce a business decision falls under false representation in Section 2 of the Fraud Act 2006, carrying up to ten years' imprisonment on indictment. Delivering false information to Companies House itself is a separate offence under Section 1112 of the Companies Act 2006.
Stay informed
Get our compliance insights and practical guides delivered to your inbox.