The UK's Failure to Prevent Fraud Offense: A Guide to the New Corporate Criminal Liability, Extraterritorial Reach, and the 'Reasonable Procedures' Defense
The UK's sweeping new corporate criminal offense imposes strict liability on large organizations globally if an associated person commits fraud to benefit the company. To avoid unlimited fines, businesses must prove they have actively enforced 'reasonable procedures' to prevent economic crime.
By Factlen Editorial Team
- Regulatory & Enforcement Agencies
- UK authorities emphasize that the era of 'tick-box' compliance is over, requiring active testing of fraud prevention controls.
- Corporate Compliance Advisors
- Legal professionals focus on the operational burden of mapping risks and harmonizing fraud controls with existing frameworks.
- Multinational Corporations
- Global businesses are grappling with the law's broad extraterritorial reach and the expansive definition of associated persons.
What's not represented
- · Small and Medium Enterprises (SMEs) indirectly affected by supply chain mandates
- · Whistleblowers reporting internal corporate fraud
Why this matters
This legislation fundamentally rewrites the rules of corporate accountability, exposing multinational companies to unlimited fines in the UK for the fraudulent actions of their rogue employees, subsidiaries, or third-party contractors. Organizations can no longer rely on a static compliance policy; they must actively prove their fraud prevention controls work in practice.
Key points
- The UK's Failure to Prevent Fraud offense imposes strict criminal liability on large organizations if an associated person commits fraud to benefit the company.
- The law applies globally to any large multinational corporation provided the underlying fraud has a UK nexus.
- An organization is classified as 'large' if it meets two of three criteria: >250 employees, >£36 million turnover, or >£18 million in assets.
- The sole defense against unlimited fines is proving the organization had 'reasonable procedures' in place to prevent the fraud.
- UK regulators have stressed that static compliance policies are insufficient; procedures must be actively tested and enforced.
For decades, prosecuting large corporations for economic crimes in the United Kingdom required navigating a notoriously difficult legal labyrinth. Law enforcement agencies had to prove that the "directing mind and will" of the company—typically the board of directors or senior executives—was directly involved in the illicit activity. This high bar meant that while individual rogue employees were frequently jailed, the corporate entities that profited from their actions often escaped criminal liability entirely.[5]
That era of corporate immunity effectively ended on September 1, 2025, when the "Failure to Prevent Fraud" offense officially came into force. Introduced as the cornerstone of the Economic Crime and Corporate Transparency Act 2023 (ECCTA), the legislation represents the most significant overhaul of the UK's financial crime compliance landscape since the Bribery Act of 2010.[4]
The new law fundamentally rewrites the rules of corporate accountability by introducing a strict liability standard. Under the ECCTA, an organization is automatically held criminally liable if an "associated person" commits a specified fraud offense with the intention of benefiting the company or its clients. Prosecutors no longer need to prove that senior management knew about, authorized, or orchestrated the fraud.[4]
The scope of the legislation is deliberately expansive, targeting what the government defines as "large organizations." To fall within the law's crosshairs, a company must meet at least two of three financial thresholds in the preceding year: more than 250 employees, an annual turnover exceeding £36 million, or total assets surpassing £18 million.[1]

Crucially, these thresholds are calculated on a consolidated, group-wide basis. A parent company cannot shield itself by isolating its operations into smaller subsidiaries. If a subsidiary commits a fraud that benefits the parent organization, the parent can be prosecuted directly.[4]
The definition of an "associated person" is equally broad, extending far beyond direct employees. The term encompasses agents, subsidiaries, consultants, and third-party service providers who perform services for or on behalf of the organization. This means a company could face criminal charges if an external contractor inflates invoices or falsifies data to secure a contract that benefits the parent firm.
Perhaps the most consequential aspect of the new offense is its aggressive extraterritorial reach. The law is not confined to businesses headquartered in the UK. A multinational corporation based in New York, Tokyo, or Frankfurt can be prosecuted in London if the underlying fraud has a "UK nexus."[1][4]
A UK nexus is established if an essential element of the fraud occurred within the United Kingdom, or if the fraudulent activity targeted UK-based victims. Consequently, global entities with even a tangential operational footprint in the UK have been forced to overhaul their global compliance frameworks to mitigate their exposure.[1]

A UK nexus is established if an essential element of the fraud occurred within the United Kingdom, or if the fraudulent activity targeted UK-based victims.
The legislation covers a comprehensive list of "base fraud" offenses detailed in Schedule 13 of the ECCTA. These include fraud by false representation, failing to disclose information, abuse of position, false accounting, fraudulent trading, and cheating the public revenue. Aiding or abetting any of these crimes also triggers corporate liability.[4]
For organizations caught in the crosshairs, the consequences of a conviction are severe. The law empowers the courts to levy unlimited financial fines. Beyond the immediate financial penalty, a conviction carries devastating reputational damage, potential exclusion from public procurement contracts, and intense ongoing regulatory scrutiny.[4]
There is only one statutory defense available to an organization facing prosecution: it must prove, on the balance of probabilities, that it had "reasonable procedures" in place to prevent the fraud at the time the offense occurred. Alternatively, the company must prove that it was reasonable under the circumstances not to have any procedures in place—a highly unlikely scenario for a large enterprise.
To guide businesses, the UK Home Office published a detailed framework outlining six core principles for reasonable procedures. These principles require top-level commitment from the board, comprehensive risk assessments, proportionate risk-based prevention procedures, rigorous due diligence on third parties, continuous communication and training, and ongoing monitoring and review.

As the law moves through its first full year of enforceability in 2026, the regulatory expectations have crystallized. The Serious Fraud Office (SFO) and the Crown Prosecution Service have made it unequivocally clear that a static, "tick-box" compliance policy sitting in a document library will not hold up in court.[2]
In its updated 2026 guidance for evaluating corporate compliance programs, the SFO emphasized a shift toward a performance-based model. Prosecutors are instructed to evaluate the actual, day-to-day operation of a company's controls. Organizations must provide concrete evidence that their procedures were actively tested, enforced, and capable of identifying risks before the fraud materialized.[2]
This represents a massive operational shift for compliance teams. While the "reasonable procedures" standard mirrors the "adequate procedures" required under the UK Bribery Act, fraud presents unique and complex challenges. Bribery typically involves outbound payments to secure an advantage, making it somewhat easier to track through financial ledgers.
Fraud, by contrast, is often deeply embedded in internal business processes. It can manifest as an employee manipulating sales data to hit a bonus target, a manager hiding vital information from investors, or a subsidiary engaging in dishonest sales practices to boost quarterly revenue.[5]

To build a defensible program, legal advisors are urging companies to conduct exhaustive, fraud-specific risk assessments. Organizations cannot simply recycle their existing anti-money laundering or anti-bribery frameworks; they must map out the specific opportunities, motives, and means by which an associated person could commit fraud to benefit the business.[1]
The enforcement landscape is rapidly intensifying. The Home Office's May 2026 Fraud Strategy Framework signaled a sharp uplift in enforcement resources, and the SFO's 2026-2027 Business Plan prioritized intelligence-led investigations and faster-moving corporate prosecutions.[2][3]
For large organizations globally, the grace period for adapting to the ECCTA has officially expired. The burden of proof has shifted entirely onto the corporate board, transforming fraud prevention from a theoretical best practice into an urgent, strictly enforced legal mandate.[5]
How we got here
October 2023
The Economic Crime and Corporate Transparency Act (ECCTA) receives Royal Assent in the UK.
November 2024
The UK Home Office publishes its statutory guidance outlining the six principles of 'reasonable procedures.'
September 2025
The Failure to Prevent Fraud offense officially comes into force, triggering strict liability for large organizations.
Early 2026
The Serious Fraud Office updates its compliance evaluation guidance, emphasizing active testing over 'tick-box' policies.
May 2026
The Home Office publishes the Fraud Strategy Framework 2026-2029, signaling a sharp uplift in corporate enforcement.
Viewpoints in depth
Regulatory & Enforcement Agencies
UK authorities emphasize that the era of 'tick-box' compliance is over, requiring active testing of fraud prevention controls.
Agencies like the Serious Fraud Office (SFO) and the Crown Prosecution Service view the new offense as a landmark tool to pierce the corporate veil. Historically, prosecuting large companies required proving that the 'directing mind and will' of the board was involved in the fraud. The strict liability nature of the new law removes this hurdle. In their 2026 guidance, regulators have stressed that a static policy document is not a defense; prosecutors will evaluate whether a company's procedures were actively monitored, tested, and capable of influencing corporate behavior.
Corporate Compliance Advisors
Legal and compliance professionals focus on the operational burden of mapping risks and harmonizing fraud controls with existing anti-bribery frameworks.
For compliance teams, the offense represents a massive operational shift. Advisors point out that while the 'reasonable procedures' standard mirrors the UK Bribery Act, fraud is inherently more complex to map because it can be committed internally (such as false accounting to hit targets) or externally against clients. Law firms are advising multinational clients to conduct exhaustive, fraud-specific risk assessments across their entire supply chains, warning that relying on outdated, generic financial crime frameworks will leave them exposed to unlimited fines.
Multinational Corporations
Global businesses are grappling with the law's broad extraterritorial reach and the expansive definition of 'associated persons.'
Multinational companies, particularly those headquartered in the US or Asia, are raising concerns about the jurisdictional scope of the ECCTA. Because the law applies to any large organization with a 'UK nexus,' a foreign parent company could face prosecution in London for the actions of a rogue third-party consultant operating in another country, provided the fraud targeted UK victims or benefited the parent. This has forced global entities to impose stringent new contractual certifications and due diligence requirements on their global vendors and subsidiaries.
What we don't know
- How aggressively the Serious Fraud Office will pursue foreign-headquartered parent companies for the actions of their distant subsidiaries.
- Whether the courts will ultimately accept integrated financial crime frameworks as 'reasonable procedures' or demand entirely standalone fraud programs.
- The exact threshold at which a third-party service provider's actions are deemed to have been intended to benefit the parent organization.
Key terms
- Economic Crime and Corporate Transparency Act 2023 (ECCTA)
- The UK legislation that introduced the failure to prevent fraud offense to tackle the use of corporate structures for economic crime.
- Associated Person
- An employee, agent, subsidiary, or third-party service provider who performs services for or on behalf of an organization.
- Strict Liability
- A legal standard where an organization can be held criminally liable for an offense regardless of its intent or the knowledge of its senior management.
- UK Nexus
- A jurisdictional link to the United Kingdom, such as an essential element of the crime occurring within the UK or the fraud targeting UK-based victims.
- Reasonable Procedures
- The statutory defense requiring companies to implement and actively enforce risk-based controls, due diligence, and training to prevent fraud.
- Serious Fraud Office (SFO)
- The UK government department responsible for investigating and prosecuting complex fraud, bribery, and corruption.
Frequently asked
What is the Failure to Prevent Fraud offense?
It is a strict liability corporate offense under the UK's Economic Crime and Corporate Transparency Act 2023. It makes large organizations criminally liable if an associated person commits fraud to benefit the company.
Does the law apply to companies based outside the UK?
Yes. The law has extraterritorial reach and applies to any large multinational corporation if the underlying fraud has a 'UK nexus,' such as targeting UK victims or involving a UK subsidiary.
What constitutes a large organization?
A company is considered large if it meets two of three criteria: more than 250 employees, over £36 million in annual turnover, or more than £18 million in total assets.
What is the penalty for non-compliance?
Organizations found guilty face unlimited financial fines, significant reputational damage, and the potential for increased regulatory scrutiny.
How can a company defend itself?
The sole defense is proving that the organization had 'reasonable procedures' in place to prevent fraud at the time the offense occurred, based on six principles outlined by the UK Home Office.
Sources
[1]Simmons & SimmonsCorporate Compliance Advisors
ECCTA Fraud Prevention Toolkit and FAQs
Read on Simmons & Simmons →[2]Mayer BrownRegulatory & Enforcement Agencies
Eye on Economic Crime: Key takeaways from the UK Serious Fraud Office's Business Plan 2026-27
Read on Mayer Brown →[3]Trowers & HamlinsCorporate Compliance Advisors
Fraud: what lies ahead for 2026
Read on Trowers & Hamlins →[4]KennedysCorporate Compliance Advisors
Failure to prevent fraud: the new corporate offence
Read on Kennedys →[5]Factlen Editorial TeamMultinational Corporations
Synthesis by Factlen editorial team
Read on Factlen Editorial Team →
Every angle. Every day.
Get guides stories with full source coverage and perspective breakdowns delivered to your inbox.







