Failure to prevent fraud: your procedures are now the defense

September 15, 2025

On 1 September 2025 the United Kingdom’s failure to prevent fraud offense came into force. A large organization can now be prosecuted because somebody acting on its behalf committed fraud. It does not matter whether anyone in the boardroom knew about it, approved it, or would have approved it if asked.

Most boards responded by asking their general counsel whether the organization has an anti-fraud policy, which it almost certainly does, and that is not the question the offense asks. The distance between the two is where the exposure sits.

The fraud it covers is the fraud committed for you

The offense sits at section 199 of the Economic Crime and Corporate Transparency Act 2023. It is easy to read as a rule about protecting a business from fraud, when what it actually does is close to the opposite.

Liability arises where an associated person commits one of the fraud offenses listed in Schedule 13 of the Act intending to benefit the organization or its clients. The Act defines an associated person broadly: an employee, agent or subsidiary undertaking, or anyone who “otherwise performs services for or on behalf of the body”. Fraud committed against the company is out of scope. Fraud committed for it is the entire point.

That inversion is worth sitting with, because the two present very differently in practice. Fraud against a business shows up as a loss, which somebody is always motivated to chase down, whereas fraud committed for it shows up as a good quarter that nobody has much reason to question.

The underlying offenses are unremarkable: fraud by false representation, fraud by failing to disclose information, fraud by abuse of position, obtaining services dishonestly, participating in a fraudulent business, false accounting, false statements by company directors, fraudulent trading, and cheating the public revenue. None of these is an exotic charge, and the novelty of the offense lies not in the conduct it describes but in who is now required to answer for it.

Whether you are in scope is a group question, not a company question

The offense applies to large organizations, meaning those that meet at least two of three tests in the financial year preceding the year of the fraud. The tests are more than 250 employees, more than £36 million in turnover, and more than £18 million in total assets.

Read at entity level that would exclude a great many businesses, but the test is not applied at entity level. Resources are counted cumulatively across a parent undertaking and its subsidiaries. A parent heading a group that meets the test is a large organization, and a subsidiary is capable of committing the offense where its parent meets it. The test runs across the group regardless of where the parent is headquartered or where its subsidiaries sit.

For an international group the practical consequence is blunt: a modest UK subsidiary does not get to measure itself. It is measured by the group it belongs to.

Interlocking flights of stairs and landings seen from above, with people spread across the levels

The offense reaches anyone performing services for or on behalf of the organization — employees, agents, subsidiaries and intermediaries alike. That is a considerably wider population than the one most fraud policies were written for.

“We did not know” stopped being an answer

The offense carries no knowledge requirement, so the prosecution does not have to show that a director knew, that the board was reckless, or that anyone senior was told anything at all. It has to show only that an associated person committed a base fraud offense intending to benefit the organization, and the penalty on conviction is an unlimited fine.

This sits on top of a change that took effect on 26 December 2023 and receives less attention than it deserves. Before that date, a company was criminally liable for an individual’s conduct only where that individual was the “directing mind and will” of the company — a test narrow enough that large organizations were, in practice, difficult to convict. Since then, where a senior manager acting within the actual or apparent scope of their authority commits one of the economic crimes listed in Schedule 12, the organization is guilty of the offense as well. “Senior manager” reaches anyone playing a significant role in managing a substantial part of the organization’s activities, which is a great many more people than the old test ever caught.

Taken together, senior-manager conduct is now attributed to the organization directly, while conduct by anyone else performing services on its behalf can trigger the failure to prevent offense. A route to corporate liability that was once narrow enough to be largely theoretical is now open at both ends.

The defense is procedures, and it is judged backwards

Section 199(4) provides a single defense. The organization must prove that at the time the fraud was committed it “had in place such prevention procedures as it was reasonable in all the circumstances to expect the body to have in place”. The alternative limb is that it was not reasonable, in all the circumstances, to expect any prevention procedures at all.

Read that the way it will be read in a courtroom. The defense does not turn on the fraud having been unforeseeable, on the individual having gone rogue, or on the organization having cooperated once it found out. It is a test of what existed beforehand, assessed afterwards by people reading documents you wrote before you knew they would matter.

The Home Office published its guidance on 6 November 2024 — forty-four pages, and a nine-month runway before the offense took effect. It frames prevention around six principles: top level commitment, risk assessment, proportionate risk-based prevention procedures, due diligence, communication including training, and monitoring and review.

Anyone who has worked on Bribery Act compliance will recognize that shape immediately, and the recognition is a trap. A bribery risk assessment maps where an organization might improperly pay someone. A fraud risk assessment maps where an organization might be tempted to misrepresent something. Those are different maps of the same business, and copying one across produces a document that looks complete while covering the wrong ground.

Glass office towers photographed from street level against a clear sky

The large-organization test is applied across a parent undertaking and its subsidiaries rather than entity by entity, so a modest UK subsidiary of a large international group does not get to measure itself.

What a fraud risk assessment has to contain to be worth anything

The weakest assessments start from the control environment and reason outward: here are the approval limits, here is segregation of duties, therefore here is the residual risk. That reasoning can only ever find risks the existing controls already contemplate.

A useful one starts from pressure. Where in this organization does somebody have both a reason to misrepresent something and the means to do it?

  • Incentives that pay on a self-reported number. Which targets, commissions, bonuses or earn-outs pay out on a number that the person reporting it can influence? Revenue recognition at period end, milestone sign-off and self-reported utilization are where this concentrates.
  • Representations nobody outside the team checks. What does the organization assert to customers, lenders, insurers and regulators that nobody outside the asserting team ever checks? Capability statements in tenders, covenant compliance certificates and sustainability claims are all fraud by false representation if they are knowingly wrong.
  • Associated persons outside the culture. Agents, introducers, distributors and outsourced sales sit inside the statutory definition and outside the culture. A commission-only intermediary in a distant market has every incentive the offense contemplates and none of the supervision.
  • The parts that quietly always deliver. Which part of the business consistently hits its numbers without anyone being able to explain precisely how? That is a question about the business rather than about its controls, and usually the most productive one on the list.

Then write down what you decided, including the risks you decided not to spend money on. A board minute recording a reasoned decision not to act is evidence of a process that functions, whereas an absence of any record is evidence of nothing at all and reads badly at three years’ distance.

Where the assessment turns up something that has already happened rather than something that might, it stops being a compliance exercise. Corporate investigations and financial investigations answer different questions from the ones a risk assessment asks, and the sequence matters: what you do in the first week after a finding shapes what you are able to prove later.

The border does not help

The offense has wide extraterritorial reach. It applies to a large organization wherever in the world it is located, provided the fraud took place in the UK or the gain or loss occurred in the UK. An overseas organization can be prosecuted where its associated person committed fraud abroad and the victims were UK-based — though that route requires actual loss in the UK, not merely intended loss.

For a group with any UK footprint, the question of what procedures existed will be put to the group, not to whichever entity happens to sit nearest the conduct.

Where to start

Four things are worth doing in order, and the order matters more than it looks.

  1. Establish whether the group meets the threshold, counting across the parent and its subsidiaries rather than entity by entity.
  2. Commission a fraud risk assessment rather than a rebadged bribery one, and require it to name specific pressures in specific parts of the business instead of risk categories.
  3. Close the associated-person gap. Agents, introducers and outsourced functions are in scope and are almost never covered by internal training or internal reporting lines.
  4. Record the decisions and the reasoning behind them, and put a review date on the record.

None of this is a compliance exercise in the sense of producing an artifact and filing it. The offense asks a governance question — whether the organization knows where it would be tempted to misrepresent something, and whether it has done anything about it — and a policy on its own answers neither half of that. Two books on our Book of the Month shelf deal with how ordinary commercial pressure turns into criminal conduct. Lying, Cheating and Stealing examines where sharp practice becomes crime, and How to Steal A Lot of Money — Legally looks at the far larger sums that never cross the line at all.


Falcone International

Bring us a question like this one

We handle corporate investigations, due diligence, financial investigations and duty of care — usually for people who need something established quietly, and established properly, before it turns into a problem.

Talk to usSee what we do

Discover more Insights from Falcone International

“Never Split the Difference” offers an inside look into the world of high-stakes hostage negotiations, translated into tactics for personal and business use. Chris Voss, a former FBI negotiator, shares strategies that center around empathy, active listening, and tactical mirroring to sway outcomes. This book is an essential guide for anyone aiming to improve their negotiation skills and interpersonal effectiveness.

In “On Intelligence,” John Hughes-Wilson offers an insightful journey through the clandestine world of intelligence and espionage. Covering historical events to modern dilemmas, the book illuminates the inner workings of intelligence agencies and their impact on world history. This exploration encourages critical thinking about the role of intelligence in society and the ethical issues it presents.

Fraud rises when budgets tighten. Pressure goes up, headcount comes down, and controls that quietly depended on someone having spare time stop working. This weekend read sets out where exposure concentrates during a downturn and which defenses actually hold: strong internal controls, systems that flag the patterns people miss, a crisis plan written before it is needed, and a culture in which raising an anomaly is not a career risk.

Joel Brenner sets the demand for transparency against the need for secrecy and finds that most institutions have no coherent answer to the collision. “Glass Houses” is less a privacy book than an account of what secrecy now costs, who can still maintain it, and how little of it survives in a world where nearly every action leaves a record somewhere.

Discover how we use our integrated capabilities for our clients

Case Studies and Client Stories