Skip to main content

    Failure To Prevent Fraud Act

    Failure to Prevent Fraud: the new UK corporate offence

    The Failure to Prevent Fraud offence under the Economic Crime and Corporate Transparency Act 2023 makes large UK organisations criminally liable if an associated person commits fraud intending to benefit the organisation, unless the organisation has reasonable fraud-prevention procedures. The offence came into force on 1 September 2025 and applies to organisations meeting two of three thresholds: 250+ employees, £36m+ turnover, £18m+ total assets.

    6 min readBy Rajoka editorial

    The Failure to Prevent Fraud offence under the Economic Crime and Corporate Transparency Act 2023 makes large UK organisations criminally liable if an associated person commits fraud intending to benefit the organisation, unless the organisation has reasonable fraud-prevention procedures. The offence came into force on 1 September 2025 and applies to organisations meeting two of three thresholds: 250+ employees, £36m+ turnover, £18m+ total assets.

    For large UK organisations, this is the most consequential corporate criminal offence introduced in over a decade. For SMEs below the threshold, it's a model of what reasonable procedures look like, and many will want to adopt similar measures voluntarily.

    What the offence covers

    The offence is committed when:

    • An associated person of the organisation commits a "base fraud offence", and
    • They commit it intending to benefit the organisation (or a person to whom the organisation provides services), and
    • The organisation did not have reasonable procedures in place to prevent fraud.

    "Associated person" is broad. It includes employees, agents, subsidiaries, and any other person acting on the organisation's behalf or for its benefit. A senior officer committing fraud is an associated person. A part-time agent in another country acting on the organisation's behalf is an associated person.

    "Base fraud offences" include:

    • Fraud by false representation (Section 2 Fraud Act 2006).
    • Fraud by failing to disclose information (Section 3).
    • Fraud by abuse of position (Section 4).
    • Cheating the public revenue.
    • False accounting.
    • Fraudulent trading.
    • False statements by company directors.

    The list also includes attempts, conspiracies, and aiding/abetting.

    Who is in scope

    "Large organisations" only, defined as meeting at least two of three thresholds in the financial year before the offence is alleged:

    • More than 250 employees.
    • More than £36 million turnover.
    • More than £18 million total assets.

    For parent companies and subsidiaries, the thresholds are applied at the parent level. So a subsidiary with 50 employees and £5m turnover is in scope if its parent group exceeds the thresholds.

    SMEs below the thresholds are not subject to the offence. But the Government has signalled that the thresholds may be lowered in future, and many SMEs are voluntarily adopting similar measures as good practice.

    The reasonable procedures defence

    The defence to the offence is that the organisation had reasonable procedures in place to prevent fraud by associated persons, or that it was not reasonable in the circumstances for any such procedures to be in place.

    The Government published statutory guidance in November 2024 setting out what "reasonable procedures" looks like. The six guiding principles:

    1. Top-level commitment

    Senior management must visibly own the fraud prevention agenda. Not just signing off; actively driving.

    In practice: regular board-level review of fraud risk, named senior owner, written commitment communicated to staff.

    2. Risk assessment

    A documented assessment of fraud risks the organisation faces, by area of business activity.

    In practice: structured fraud risk assessment covering financial, operational, and reputational fraud; reviewed at least annually and on trigger events (new markets, new products, acquisitions).

    3. Proportionate procedures

    Fraud prevention measures should be proportionate to the risk identified.

    In practice: low-risk areas get basic controls; high-risk areas get specific controls. Don't apply heavy controls everywhere.

    4. Due diligence

    Due diligence on associated persons, particularly those in higher-risk roles or relationships.

    In practice: background checks on employees, vendor due diligence, KYC on agents and partners, periodic refresh.

    5. Communication and training

    Staff must know what fraud looks like, what the organisation's policies are, and how to report concerns.

    In practice: mandatory training (annual at minimum), accessible reporting channels, clear policies.

    6. Monitoring and review

    Active monitoring of fraud risks and the effectiveness of controls.

    In practice: internal audit involvement, fraud incident logging, periodic effectiveness review.

    What "in scope" organisations should do

    For organisations clearly in scope, the practical work:

    1. Initial fraud risk assessment

    A structured workshop reviewing every business activity and identifying:

    • The fraud risks specific to that activity.
    • The current controls.
    • The residual risk after controls.

    Document the assessment with rationale. Review annually.

    2. Gap analysis

    For each high-residual-risk area, identify the gap between current controls and what would be reasonable. Plan remediation.

    3. Policy and procedure updates

    Update employee handbooks, vendor onboarding, agent agreements, and similar documents to include fraud-prevention requirements.

    4. Training programme

    Annual training for all employees. Targeted training for higher-risk roles (sales, procurement, finance, agent management).

    5. Reporting and escalation

    A clear whistleblowing channel. Confidential reporting. Protection from retaliation.

    6. Investigation and response

    A documented process for investigating fraud allegations, including external reporting where required (to NCA via SAR, to police, to regulators).

    Penalties

    The offence is triable in the Crown Court. On conviction, unlimited fine for the organisation.

    In addition, the organisation may face:

    • Deferred Prosecution Agreement (DPA): a structured settlement involving fines, compliance monitoring, and remediation. Used in serious cases for cooperating organisations.
    • Reputational damage: prosecutions are public. Investor and customer reactions can be significant.
    • Director consequences: a conviction can disqualify directors under separate legislation.

    For organisations not yet in scope, the SFO and other prosecutors are taking the position that similar standards should apply progressively, particularly for organisations approaching the threshold.

    When the offence does not apply

    The defence available to the organisation includes:

    • The associated person did not act for the benefit of the organisation.
    • Reasonable procedures were in place.
    • It was not reasonable in the circumstances for any procedures to be in place.

    The third route is narrow. For a typical large organisation in 2026, the courts will expect at least some reasonable procedures.

    Bottom line

    For organisations clearly above the thresholds, the time to act is now if you haven't already. The offence is in force; an investigation could start at any time.

    For organisations approaching the thresholds, planning a 12-18 month implementation while still below the threshold is sensible. The defence depends on having reasonable procedures in place at the time of the alleged offence, not afterward.

    For organisations below the thresholds, this is a useful template for fraud-prevention best practice. The thresholds may lower in future.

    Rajoka Insights

    Operating notes from a UK house of brands.

    A weekly note from Mehmood. House-of-brands strategy, UK operating, and what's working across the portfolio. No fluff.

    Delivered via Substack. Unsubscribe anytime.

    Explore Rajoka

    Talk to Certivus about AML and KYC

    Pick a brand, pick a stage, or tell us your problem.