Government Publishes New Guidance on Failure to Prevent Fraud Offence

This week, the UK government has published its guidance to organisations on the new corporate criminal offence of failure to prevent fraud, introduced as part of the Economic Crime and Corporate Transparency Act 2023 (ECCTA) which will come in force from 1 September 2025.

Under the ECCTA, organisations may be found criminally liable where they fail to prevent fraud committed by a person associated with the company, on behalf of the organisation, with the aim of benefiting the organisation or their clients. Notably, the guidance makes clear that the benefit can be financial or non-financial and so disadvantaging a competitor would be within this scope.

As with the failure to prevent bribery offence under the Bribery Act 2010, the offence is one of strict liability and can give rise to an unlimited fine (although the courts “will take account of all the circumstances in deciding the appropriate level of fine for a particular case”). The offence also potentially give rise to victims of fraud pursuing a private prosecution of a company.

Who is Affected?

An “Associated Person” includes employees, agents, subsidiaries and any person who otherwise performs services for or on behalf of the company, as well as employees of subsidiaries of a company. Whilst the new offence only applies to “large” organisations, meaning one with (i) more than 250 employees; (ii) turnover of more than £36 million; and/or (iii) a balance sheet total of more than £18 million), it may be that SME’s will need to consider implementing strong internal anti-fraud policies and procedures. The reason being that such organisations may act for, or on behalf of, a large organisation that is within the scope of the legislation, and could therefore be considered an “associated person.”

Available Defences

Organisations will be able to avoid prosecution if they i) have reasonable procedures in place to prevent fraud (again, in line with the failure to prevent bribery model); and ii) the organisation was the victim or the intended victim of the fraud. This only applies where the intention was to benefit a person to whom services were being provided, for example, a client or customer.

In terms of “reasonable procedures” the guidance sets out six principles for organisations to implement (summarised below), though importantly it notes that organisations should take a holistic approach in consideration of the unique risks of its operations.

  • Principle 1: Top level commitment – Organisations must be able to demonstrate that their senior management are committed to preventing fraud and an open culture must be fostered in the organisation.
  • Principle 2: Risk assessment – The guidance recommends that organisations consider the (i) opportunity, (ii) motive, and (iii) means by which an associated person could commit fraud when undertaking a risk assessment. The assessment of risk should be dynamic and kept under review.
  • Principle 3: Proportionate risk-based prevention procedures – Whilst procedures must be robust, they should be proportionate to the potential fraud risks relevant to the specific organisation.
  • Principle 4: Due diligence – Organisations should review any existing due diligence procedures and ensure that they are updated as necessary. The guidance again suggests that such measures ought to be proportionate.
  • Principle 5: Communication (including training) –Regular anti-fraud training is noted as being a key principle and should be specific to the risks of different roles.
  • Principle 6: Monitoring and review – procedures should be reviewed regularly to ensure they are sufficient, and changes made where necessary, in light of any developments.

Next Steps

If you are considering reviewing or implementing a fraud strategy in view of the new corporate liability risk, then please do reach out to a member of our team for an initial discussion on potential next steps.

Scroll to Top

Quick Contact