The Failure to Prevent Fraud offence under the Economic Crime and Corporate Transparency Act 2023 makes large UK organisations criminally liable if an associated person commits fraud intending to benefit the organisation, unless the organisation has reasonable fraud-prevention procedures. The offence came into force on 1 September 2025 and applies to organisations meeting two of three thresholds: 250+ employees, £36m+ turnover, £18m+ total assets.
For large UK organisations, this is the most consequential corporate criminal offence introduced in over a decade. For SMEs below the threshold, it's a model of what reasonable procedures look like, and many will want to adopt similar measures voluntarily.
What the offence covers
The offence is committed when:
- An associated person of the organisation commits a "base fraud offence", and
- They commit it intending to benefit the organisation (or a person to whom the organisation provides services), and
- The organisation did not have reasonable procedures in place to prevent fraud.
"Associated person" is broad. It includes employees, agents, subsidiaries, and any other person acting on the organisation's behalf or for its benefit. A senior officer committing fraud is an associated person. A part-time agent in another country acting on the organisation's behalf is an associated person.
"Base fraud offences" include:
- Fraud by false representation (Section 2 Fraud Act 2006).
- Fraud by failing to disclose information (Section 3).
- Fraud by abuse of position (Section 4).
- Cheating the public revenue.
- False accounting.
- Fraudulent trading.
- False statements by company directors.
The list also includes attempts, conspiracies, and aiding/abetting.
Who is in scope
"Large organisations" only, defined as meeting at least two of three thresholds in the financial year before the offence is alleged:
- More than 250 employees.
- More than £36 million turnover.
- More than £18 million total assets.
For parent companies and subsidiaries, the thresholds are applied at the parent level. So a subsidiary with 50 employees and £5m turnover is in scope if its parent group exceeds the thresholds.
SMEs below the thresholds are not subject to the offence. But the Government has signalled that the thresholds may be lowered in future, and many SMEs are voluntarily adopting similar measures as good practice.
The reasonable procedures defence
The defence to the offence is that the organisation had reasonable procedures in place to prevent fraud by associated persons, or that it was not reasonable in the circumstances for any such procedures to be in place.
The Government published statutory guidance in November 2024 setting out what "reasonable procedures" looks like. The six guiding principles:
1. Top-level commitment
Senior management must visibly own the fraud prevention agenda. Not just signing off; actively driving.
In practice: regular board-level review of fraud risk, named senior owner, written commitment communicated to staff.
2. Risk assessment
A documented assessment of fraud risks the organisation faces, by area of business activity.
In practice: structured fraud risk assessment covering financial, operational, and reputational fraud; reviewed at least annually and on trigger events (new markets, new products, acquisitions).
3. Proportionate procedures
Fraud prevention measures should be proportionate to the risk identified.
In practice: low-risk areas get basic controls; high-risk areas get specific controls. Don't apply heavy controls everywhere.
4. Due diligence
Due diligence on associated persons, particularly those in higher-risk roles or relationships.
In practice: background checks on employees, vendor due diligence, KYC on agents and partners, periodic refresh.
5. Communication and training
Staff must know what fraud looks like, what the organisation's policies are, and how to report concerns.
In practice: mandatory training (annual at minimum), accessible reporting channels, clear policies.
6. Monitoring and review
Active monitoring of fraud risks and the effectiveness of controls.
In practice: internal audit involvement, fraud incident logging, periodic effectiveness review.
What "in scope" organisations should do
For organisations clearly in scope, the practical work:
1. Initial fraud risk assessment
A structured workshop reviewing every business activity and identifying:
- The fraud risks specific to that activity.
- The current controls.
- The residual risk after controls.
Document the assessment with rationale. Review annually.
2. Gap analysis
For each high-residual-risk area, identify the gap between current controls and what would be reasonable. Plan remediation.
3. Policy and procedure updates
Update employee handbooks, vendor onboarding, agent agreements, and similar documents to include fraud-prevention requirements.
4. Training programme
Annual training for all employees. Targeted training for higher-risk roles (sales, procurement, finance, agent management).
5. Reporting and escalation
A clear whistleblowing channel. Confidential reporting. Protection from retaliation.
6. Investigation and response
A documented process for investigating fraud allegations, including external reporting where required (to NCA via SAR, to police, to regulators).
Penalties
The offence is triable in the Crown Court. On conviction, unlimited fine for the organisation.
In addition, the organisation may face:
- Deferred Prosecution Agreement (DPA): a structured settlement involving fines, compliance monitoring, and remediation. Used in serious cases for cooperating organisations.
- Reputational damage: prosecutions are public. Investor and customer reactions can be significant.
- Director consequences: a conviction can disqualify directors under separate legislation.
For organisations not yet in scope, the SFO and other prosecutors are taking the position that similar standards should apply progressively, particularly for organisations approaching the threshold.
When the offence does not apply
The defence available to the organisation includes:
- The associated person did not act for the benefit of the organisation.
- Reasonable procedures were in place.
- It was not reasonable in the circumstances for any procedures to be in place.
The third route is narrow. For a typical large organisation in 2026, the courts will expect at least some reasonable procedures.
Bottom line
For organisations clearly above the thresholds, the time to act is now if you haven't already. The offence is in force; an investigation could start at any time.
For organisations approaching the thresholds, planning a 12-18 month implementation while still below the threshold is sensible. The defence depends on having reasonable procedures in place at the time of the alleged offence, not afterward.
For organisations below the thresholds, this is a useful template for fraud-prevention best practice. The thresholds may lower in future.