The Failure to Prevent Fraud Offence: What Large Organisations Must Do
The failure to prevent fraud offence came into force on 1 September 2025 and is the most significant change to UK corporate criminal liability in a decade. Created by the Economic Crime and Corporate Transparency Act 2023, it makes a large organisation criminally liable when someone associated with it commits fraud intending to benefit it, unless the organisation can show it had reasonable fraud prevention procedures in place. There is no requirement to prove that the board knew.
That last point is what makes it different. Under the old identification principle, prosecutors effectively had to pin knowledge on a directing mind of the company, which is why so few corporate fraud prosecutions succeeded. This offence removes that obstacle. This guide sets out who is in scope, what the defence actually requires, and what to do about it if you have not yet.
Who is in scope
The offence applies to large organisations, defined by meeting at least two of these three criteria:
- more than 250 employees
- more than 36 million pounds turnover
- more than 18 million pounds in total assets
Three details are commonly missed. First, it is not limited to companies: large partnerships, large charities and other not-for-profits, and incorporated public bodies are all in scope. Second, the thresholds are assessed across the organisation and its subsidiaries, so a group can be caught even where each individual entity looks small. Third, if you are a smaller organisation supplying a large one, expect the obligation to reach you through the contract, because in-scope customers are pushing fraud prevention terms down their supply chains.
How liability arises
The structure of the offence has three parts. An associated person must commit a base fraud offence, intending to benefit the organisation or someone to whom they provide services on its behalf.
An associated person is an employee, agent or subsidiary undertaking, and more broadly anyone providing services for or on behalf of the organisation. That definition is deliberately wide, and it catches contractors and intermediaries that many organisations do not think of as their own people.
The base offences are the specified fraud and dishonesty offences, including fraud by false representation, fraud by failing to disclose information and fraud by abuse of position under the Fraud Act 2006, along with false accounting, fraudulent trading, obtaining services dishonestly, participating in a fraudulent business, cheating the public revenue and false statements by company directors.
The benefit test catches situations organisations rarely see as their own risk. An employee who misleads a customer to win a contract is committing fraud intended to benefit the organisation even though the organisation never asked for it and would say it did not want it. The organisation being a victim of the same conduct does not remove liability.
Where the offence stops
Two limits are worth knowing precisely. The offence needs a UK nexus: an act of the underlying fraud must take place in the UK, or the gain or loss must occur in the UK. The Home Office guidance states plainly that the offence will not apply to UK organisations whose overseas employees or subsidiary undertakings commit fraud abroad with no UK nexus.
And the offence targets fraud committed to benefit the organisation. Straightforward employee theft from the employer, where the employee is defrauding the organisation itself, sits outside it. That is an internal control problem rather than this offence, though the two overlap in practice and the same controls address both.
The only defence, and what it requires
There is one defence: that the organisation had reasonable fraud prevention procedures in place when the fraud was committed, or that it was not reasonable in the circumstances to expect any procedures. The word is reasonable, not perfect. An organisation with sound, well-evidenced procedures can still suffer a fraud and still successfully defend the charge.
The government guidance sets out six principles that reasonable procedures are assessed against:
- Top level commitment. The board and senior management must own fraud prevention visibly, not delegate it to a policy document. Board minutes that record the discussion are evidence; a policy nobody at the top has read is not.
- Risk assessment. A documented, periodic assessment of where fraud could be committed by associated persons for the organisation's benefit. This is the foundation of everything else and the first thing an investigator will ask to see.
- Proportionate risk-based prevention procedures. Controls sized to the risks the assessment actually found, not a generic control set copied from elsewhere.
- Due diligence. Risk-based checks on the people and organisations acting on your behalf, including agents, intermediaries and suppliers.
- Communication, including training. People must know what is prohibited, what to do if they see it, and that raising it is safe. Training that is never refreshed is weak evidence.
- Monitoring and review. Procedures must be tested, and the results acted on. A control nobody has checked in three years is not a working control.
The full text is published in the Home Office guidance to organisations on the offence of failure to prevent fraud, and it is worth reading in the original rather than in summary if you are responsible for the response.
Anyone who has done Bribery Act work will recognise this
The design is deliberately modelled on section 7 of the Bribery Act 2010 and its adequate procedures defence. If your organisation built an anti-bribery programme, the architecture transfers: same governance, same risk-assessment discipline, same training and monitoring rhythm.
What does not transfer is the risk register. Bribery risk concentrates in a few places, typically third-party intermediaries, public officials and high-risk jurisdictions. Fraud risk is spread across sales, finance, procurement, marketing claims and customer-facing operations, which means the risk assessment has to be genuinely re-run rather than relabelled. Our UK Bribery Act compliance guide covers the structure you can reuse.
What to do in the first 90 days
If your organisation is in scope and has not yet acted, this is the sequence that produces evidence fastest:
- Confirm scope in writing. Test the two-of-three thresholds across the group and record the conclusion with the figures behind it. If you are close to the thresholds, plan as though you are in.
- Name an owner and take it to the board. Top level commitment is the first principle, and the minute recording that discussion is the first piece of evidence.
- Run a fraud risk assessment. Work by process rather than by department. For each one, ask who could commit fraud here to make our numbers look better, and what would stop them.
- Map your associated persons. List the agents, intermediaries, resellers and contractors acting for you, and apply risk-based due diligence to the ones with the most scope to cause harm.
- Test the reporting route. Most frauds are noticed by somebody before they are found by a control. If your speak-up channel is not trusted, that early warning is lost. Our guide to setting up a whistleblowing policy covers doing it properly.
- Write down what you decided and why. The defence is evidential. Decisions that were made but never recorded are worth very little in an investigation two years later.
The point of the offence
The purpose of a failure to prevent offence is not really to collect fines. It is to make prevention a board-level responsibility by removing the defence of not having known. Organisations that treat this as a document-production exercise will produce documents. Organisations that treat it as a prompt to ask where their own incentives could push people into misleading a customer will find things worth fixing, and the evidence will follow.
For the wider framework this sits in, see our guides to corporate compliance, corporate governance and ethical leadership, or start from the E-Business Ethics homepage.
Frequently asked questions
What is the failure to prevent fraud offence?
It is a corporate criminal offence created by the Economic Crime and Corporate Transparency Act 2023 and in force since 1 September 2025. A large organisation can be prosecuted where an associated person, such as an employee, agent or subsidiary, commits a specified fraud intending to benefit the organisation, and the organisation did not have reasonable fraud prevention procedures in place.
Which organisations does it apply to?
Large organisations, defined as those meeting at least two of three criteria: more than 250 employees, more than 36 million pounds turnover, and more than 18 million pounds in total assets. It covers bodies corporate and partnerships, and it applies to large not-for-profits such as charities and to incorporated public bodies, not only to companies.
What is the defence?
There is one defence: that the organisation had reasonable fraud prevention procedures in place at the time, or that it was not reasonable in the circumstances to expect any. Note the wording is reasonable, not perfect. A fraud can still occur at an organisation whose procedures were reasonable, and the defence can still succeed.
Does an organisation have to benefit from the fraud?
No. The test is that the associated person intended to benefit the organisation, or to benefit someone to whom they were providing services on the organisation's behalf. Whether the organisation actually gained anything is not the point, and an organisation that lost money can still be prosecuted if its own people defrauded a customer to win business.
Does it cover fraud committed overseas?
Only where there is a UK nexus. There must be an act of the underlying fraud in the UK, or a gain or loss occurring in the UK. The guidance is explicit that the offence will not apply to UK organisations whose overseas employees or subsidiaries commit fraud abroad with no UK nexus.
What is the penalty?
An unlimited fine on conviction on indictment. The wider cost is usually larger than the fine itself: the investigation, the disclosure obligations to regulators and customers, the effect on tenders and on the ability to bid for public contracts, and the reputational damage of a corporate criminal conviction.