Skip to Content

Company bosses may be held responsible for staff fraud.

Corporate Failure to Prevent Fraud


Large organisations can now face criminal prosecution where an employee, agent, subsidiary undertaking or another associated person commits fraud intending to benefit the organisation or, in some circumstances, one of its clients.


The corporate offence of failure to prevent fraud was created by the Economic Crime and Corporate Transparency Act 2023 and came into force on 1 September 2025.


The prosecution does not have to prove that the board of directors or senior management ordered, approved or even knew about the fraud.


An organisation may have a defence if it can show that it had reasonable fraud-prevention procedures in place, or that it was not reasonable in the circumstances to expect it to have such procedures.


Why Was the Law Changed?


Historically, prosecuting a large company for fraud could be difficult because prosecutors often had to identify a sufficiently senior individual who represented the company's "directing mind and will".


This test could make it easier to prosecute a small company, where one or two directors controlled most decisions, than a large organisation with responsibilities spread across numerous departments and managers.


The reforms are intended to:


  • make organisations take greater responsibility for fraud risks;
  • encourage effective internal controls;
  • remove the advantage obtained by companies with weak oversight structures;
  • improve the prosecution of corporate economic crime; and
  • protect customers, investors, suppliers and the public.

When Is the Offence Committed?


A large organisation may commit the offence where:


  • an associated person commits one of the fraud offences covered by the legislation;
  • the associated person intends to benefit the organisation or a person receiving services from it; and
  • the organisation did not have reasonable fraud-prevention procedures in place.

The organisation does not necessarily need to receive the intended benefit successfully. An intention to benefit it may be sufficient.


The benefit may be financial or non-financial and may include:


  • obtaining or retaining business;
  • meeting sales targets;
  • avoiding a loss;
  • improving reported financial performance;
  • securing investment;
  • obtaining a contract;
  • avoiding regulatory action; or
  • benefiting a client for whom the organisation provides services.

Which Organisations Are Covered?


The failure-to-prevent-fraud offence applies only to large incorporated bodies and partnerships.


An organisation is generally regarded as large where it meets at least two of the following three conditions:


  • more than 250 employees;
  • turnover exceeding £36 million; and
  • total assets exceeding £18 million.

Group figures may be taken into account when deciding whether a parent organisation and its subsidiaries meet the size requirements.


The offence can apply to:


  • companies;
  • limited liability partnerships;
  • ordinary partnerships;
  • large incorporated charities;
  • incorporated public bodies; and
  • overseas organisations where the required UK connection exists.

Small and medium-sized organisations are not directly covered by this particular offence unless the statutory thresholds are met.


However, smaller businesses may still face prosecution for the underlying fraud or other corporate offences and may be required by clients or commercial partners to maintain similar controls.


Who Is an Associated Person?


An associated person can include someone who provides services for or on behalf of the organisation.


This may include:


  • employees;
  • agents;
  • subsidiary undertakings;
  • contractors;
  • consultants;
  • intermediaries;
  • sales representatives;
  • distributors; or
  • another person performing services on the organisation’s behalf.

The legal question concerns what the person does rather than merely the label used in their contract.


An organisation cannot necessarily avoid liability by describing someone as self-employed or an independent contractor.


Does Every Fraud by an Employee Make the Company Liable?


No.


The fraud must be committed with the intention of benefiting:


  • the organisation;
  • a subsidiary undertaking in relevant circumstances; or
  • a client or another person receiving services from the organisation.

The offence does not normally apply where the organisation is itself the intended victim of the fraud.


For example, an employee who steals company money solely for personal benefit would not ordinarily make the organisation liable under this failure-to-prevent offence. However, the employee could still be prosecuted for theft or fraud.


Where the fraud is intended to benefit both the employee and the organisation, the corporate offence may still apply.


Which Fraud Offences Are Covered?


The legislation applies to specified underlying offences, sometimes called base fraud offences.


These include offences involving:


  • fraud by false representation;
  • fraud by failing to disclose information;
  • fraud by abuse of position;
  • obtaining services dishonestly;
  • false accounting;
  • false statements by company directors;
  • fraudulent trading;
  • cheating the public revenue; and
  • certain related offences under Scottish and Northern Irish law.

Aiding, abetting, counselling or procuring one of the specified offences may also bring the conduct within the legislation.


Examples of Failure to Prevent Fraud


Possible examples include:


  • a sales employee making dishonest statements to win a contract;
  • a manager falsifying financial information to secure investment;
  • staff submitting false information to obtain public funding;
  • an agent misleading customers to increase the organisation's revenue;
  • employees manipulating accounts to meet performance targets;
  • a subsidiary undertaking using false documents to obtain finance;
  • a contractor dishonestly overcharging a client on the organisation's behalf; or
  • staff concealing information that must legally be disclosed to customers.

Whether the organisation is liable will depend on the underlying offence, the intended benefit and the procedures in place at the time.


Must the Employee Be Convicted First?


No.


An organisation can potentially be prosecuted even where the individual associated person has not been separately charged or convicted.


However, the prosecution must prove that the associated person committed the relevant underlying fraud offence.


A conviction of the associated person may provide evidence in the case against the organisation, but it is not always a prerequisite.


Can Company Directors Be Personally Prosecuted?


The failure-to-prevent-fraud offence is directed at the organisation. It does not create automatic personal criminal liability for a director or manager merely because they failed to stop the fraud.


However, individuals can still be prosecuted where they:


  • personally commit the fraud;
  • encourage or assist it;
  • conspire with others;
  • knowingly make false statements;
  • participate in false accounting;
  • consent to or connive in another offence where the legislation permits personal liability; or
  • commit a separate regulatory or company-law offence.

A director cannot assume that the corporate offence shields them from responsibility for their own conduct.


Senior Managers and Corporate Criminal Liability


The Economic Crime and Corporate Transparency Act also changed how certain economic crimes committed by senior managers can be attributed directly to an organisation.


For relevant economic crimes committed from 26 December 2023, an organisation may be liable where a senior manager commits the offence while acting within the actual or apparent scope of their authority.


A senior manager is not defined solely by job title. The court may consider whether the person plays a significant role in:


  • making decisions about how the organisation's activities are managed or organised; or
  • actually managing or organising a substantial part of those activities.

This can include senior operational and functional managers as well as board directors.


Further Reform of the Identification Principle


The Crime and Policing Act 2026 contains provisions extending the senior-manager attribution approach beyond the economic offences originally covered by the 2023 Act.


The effect and practical application of individual provisions may depend on commencement arrangements.


Organisations should therefore ensure that senior managers understand that criminal conduct within their actual or apparent authority may expose both the individual and the organisation to prosecution.


The Reasonable Procedures Defence


An organisation has a defence to the failure-to-prevent-fraud offence if it can prove that, when the fraud took place:


  • it had reasonable procedures designed to prevent associated persons from committing fraud; or
  • it was not reasonable in all the circumstances to expect it to have prevention procedures.

Simply having a written anti-fraud policy will not necessarily be sufficient.


The court may examine whether the procedures were:


  • appropriate to the organisation’s actual risks;
  • properly implemented;
  • understood by relevant staff;
  • supported by senior management;
  • monitored and reviewed; and
  • followed in practice.

The Six Fraud-Prevention Principles


Government guidance identifies six principles that should inform an organisation's fraud-prevention procedures.


Top-Level Commitment


The board, partners and senior management should demonstrate a clear commitment to preventing fraud.


This may include:


  • approving the fraud-prevention framework;
  • assigning responsibility to appropriate senior officers;
  • providing sufficient resources;
  • supporting staff who raise concerns;
  • avoiding unrealistic incentives; and
  • responding appropriately to suspected misconduct.

Risk Assessment


The organisation should assess the nature and extent of the risk that associated persons might commit fraud for its benefit.


The assessment should consider:


  • the sectors and countries in which it operates;
  • sales and performance incentives;
  • high-risk customers and transactions;
  • use of agents and intermediaries;
  • financial reporting;
  • procurement;
  • claims and applications for funding;
  • previous incidents or near misses;
  • new products and markets; and
  • the use of technology and artificial intelligence.

The risk assessment should be recorded and reviewed regularly.


Proportionate Risk-Based Procedures


Procedures should be proportionate to the organisation's size, structure, activities and identified risks.


They may include:


  • segregation of financial duties;
  • approval limits;
  • verification of representations made to customers;
  • controls over incentives and commission;
  • independent review of high-risk transactions;
  • financial reconciliations;
  • conflict-of-interest procedures;
  • whistleblowing arrangements;
  • investigation and disciplinary processes; and
  • record keeping.

Due Diligence


Organisations should carry out proportionate due diligence on people providing services for or on their behalf.


This may include checking:


  • identity and ownership;
  • qualifications and regulatory status;
  • criminal or disciplinary history where lawful and relevant;
  • reputation;
  • financial interests;
  • conflicts of interest;
  • relationships with customers or public officials;
  • subcontracting arrangements; and
  • the commercial justification for payments and commissions.

Communication and Training


Policies and procedures should be communicated clearly to employees and other relevant associated persons.


Training should be tailored to the risks faced by different teams.


It may cover:


  • recognising fraud;
  • accurate record keeping;
  • customer and supplier representations;
  • approval requirements;
  • conflicts of interest;
  • reporting concerns;
  • protection for whistleblowers; and
  • the consequences of dishonest conduct.

Monitoring and Review


Fraud risks and controls should be monitored and reviewed.


Reviews may be required following:


  • a fraud allegation;
  • an acquisition or merger;
  • entry into a new market;
  • the introduction of a new product;
  • changes to commission or bonus arrangements;
  • a regulatory finding;
  • significant staff turnover; or
  • changes in technology or working practices.

Is Having No Procedures Ever Reasonable?


The legislation recognises that there may be circumstances in which it was not reasonable to expect an organisation to have a particular prevention procedure.


However, a large organisation is likely to find it difficult to justify having no fraud-prevention procedures at all.


The organisation should be able to explain and document why its controls were reasonable in light of the risks identified at the time.


What Is the Penalty?


An organisation convicted of failure to prevent fraud can receive an unlimited fine.


The court may consider:


  • the seriousness and duration of the fraud;
  • the benefit sought or obtained;
  • the loss caused or intended;
  • the organisation’s size and financial position;
  • the involvement of senior personnel;
  • the quality of its prevention procedures;
  • previous misconduct;
  • cooperation with investigators; and
  • whether the organisation self-reported the matter.

A conviction may also lead to:


  • confiscation of criminal proceeds;
  • compensation orders;
  • regulatory action;
  • exclusion from public contracts;
  • loss of licences or professional status;
  • civil claims;
  • reputational damage; and
  • increased compliance and insurance costs.

Deferred Prosecution Agreements


In England and Wales, a qualifying organisation suspected of economic crime may in some circumstances enter into a Deferred Prosecution Agreement with a designated prosecutor.


The agreement may require the organisation to:


  • pay a financial penalty;
  • compensate victims;
  • disgorge profits;
  • cooperate with an investigation;
  • improve compliance procedures;
  • submit to monitoring; and
  • pay prosecution costs.

A Deferred Prosecution Agreement requires judicial approval and is not automatically available merely because an organisation self-reports.


The Criminal Finances Act 2017


The original Criminal Finances Bill became the Criminal Finances Act 2017.


The Act amended legislation including the Proceeds of Crime Act 2002 and strengthened powers concerning:


  • money laundering;
  • recovery of criminal property;
  • terrorist property;
  • unexplained wealth orders;
  • disclosure orders;
  • account freezing and forfeiture; and
  • corporate failure to prevent the facilitation of tax evasion.

Failure to Prevent the Facilitation of Tax Evasion


Part 3 of the Criminal Finances Act 2017 created two corporate offences:


  • failure to prevent the criminal facilitation of UK tax evasion; and
  • failure to prevent the criminal facilitation of foreign tax evasion.

These offences came into force on 30 September 2017.


An organisation may commit an offence where:


  • a taxpayer commits criminal tax evasion;
  • a person associated with the organisation deliberately and dishonestly facilitates that tax evasion; and
  • the organisation failed to prevent the facilitation.

The law concerns criminal tax evasion rather than lawful tax planning or avoidance that does not amount to a criminal offence.


Who Is Covered by the Tax-Evasion Offence?


Unlike the newer failure-to-prevent-fraud offence, the tax-evasion facilitation offences are not restricted to large organisations.


They can apply to corporations and partnerships of any size.


An associated person may include:


  • an employee;
  • an agent;
  • a contractor;
  • a consultant;
  • a subcontractor; or
  • another person providing services for or on behalf of the organisation.

The Tax-Evasion Reasonable Procedures Defence


An organisation may have a defence where it can show that it had reasonable procedures designed to prevent the criminal facilitation of tax evasion, or that it was not reasonable to expect such procedures.


HMRC guidance identifies principles including:


  • risk assessment;
  • proportionate prevention procedures;
  • top-level commitment;
  • due diligence;
  • communication and training; and
  • monitoring and review.

Money Laundering Is Separate


The failure-to-prevent-fraud offence does not replace anti-money-laundering legislation.


Regulated organisations may have separate duties involving:


  • customer due diligence;
  • verification of beneficial ownership;
  • ongoing transaction monitoring;
  • suspicious activity reports;
  • record keeping;
  • risk assessment;
  • staff training; and
  • appointment of responsible officers.

Failure to comply with anti-money-laundering requirements can lead to separate criminal, regulatory and professional consequences.


What Should Organisations Do Now?


Organisations covered by the failure-to-prevent-fraud offence should:


  • identify who may be an associated person;
  • carry out and document a fraud risk assessment;
  • review incentives, targets and commission structures;
  • assess risks involving agents, subsidiaries and contractors;
  • update anti-fraud policies and contractual terms;
  • provide targeted training;
  • maintain confidential reporting arrangements;
  • investigate allegations properly;
  • monitor the effectiveness of controls; and
  • retain evidence showing how the procedures operate in practice.

Procedures copied from another organisation without considering the business's actual risks may not be reasonable.


What Should Directors and Senior Managers Do?


Directors and senior managers should ensure that fraud prevention is treated as a governance issue rather than left solely to the legal or compliance department.


They should consider:


  • who has overall responsibility;
  • whether sufficient resources have been provided;
  • whether risks are reported to the board;
  • whether whistleblowers are protected;
  • whether incentives encourage improper conduct;
  • whether high-risk transactions receive independent scrutiny;
  • whether disciplinary action is applied consistently; and
  • whether lessons are learned from incidents.

What Should Happen When Fraud Is Suspected?


An organisation should obtain legal advice promptly and consider:


  • protecting documents and electronic evidence;
  • preventing the destruction or alteration of records;
  • controlling access to affected systems;
  • conducting a properly scoped investigation;
  • protecting whistleblowers and witnesses;
  • notifying insurers;
  • considering regulatory reporting duties;
  • assessing whether victims should be informed;
  • considering self-reporting to an enforcement authority; and
  • avoiding interference with a police or regulatory investigation.

Legal professional privilege should be considered when planning an internal investigation.


Finding a Corporate Crime Solicitor


Use the search facility at the top of this page to find a solicitor experienced in corporate crime, fraud, tax investigations, money laundering, regulatory compliance or internal investigations.


A solicitor can advise on fraud-prevention procedures, criminal investigations, self-reporting, individual liability and the organisation's response to suspected misconduct.


Disclaimer


Solicitors.com is not a firm of solicitors. This article provides general information about corporate criminal liability and does not constitute legal advice. Organisations and individuals should obtain advice from a suitably qualified solicitor about their particular risks and circumstances.


Feedback


If you believe this page contains an error or requires updating, please contact us. We welcome amendments that help keep our legal information accurate and useful.


Company bosses may be held responsible for staff fraud.
Image Description
related news
recent articles
Double Jeopardy Law

What is Double Jeopardy? and is it still Law in the UK?..

link

Revenge Porn and Intimate Image Abuse

Is Revenge Porn Illegal in England.
Hundreds of people in England have had explicit photos or videos published on the internet without their consent, but what..

Charity Fundraising, Vulnerable Donors and the Law

Law targeting charity fundraising - Vulnerable people are to be protected from fundraising activities by charities, the chancellor has announced in the budget...

Social Media hampering police investigations.

Its time social media worked better with the police...

What is a Section 60 notice?

Over 2000 section 60 notices have been issued in London last year..

link

Restrictive Covenants

Restrictive covenants - If you happen across a restrictive covenant in a contract, what is it and why is it in place?..

Radicalisation Laws

Radicalisation Laws - For too long many have said we, as a country, are a soft touch, perhaps allowing free speech when the speech in question is inciteful for..

Finders Keepers | Finders Law

Finders Keepers | Finders Law
Ever since the phrase came into being in the early nineteenth century, documented as no halfers-findee, lossee seekee, which sou..

Stop and Search Laws to be changed?

Police Chiefs are calling for a change in the 'stop and search' l..

link

Anti-Social Behaviour

Anti-Social Behaviour.
Anti-social behaviour is defined as activities that are unacceptable and reduce the quality of life for others, this could be by harassm..

Children and the law - Committing a crime

Children and the law - Committing a crime.
A child under 10 will not be charged with a criminal offence but they can face consequences for their actions.
The..

How to apply to become a British Citizen

British Citizen application| Process.
If you are looking to apply to become a British Citizen, we recommend that you contact a firm of solicitors that have exp..

Image Description
Is there anything wrong with this page? - any amendments will receive accreditation - email us

Solicitors.com are not a firm of solicitors, and any content on the site should not be used in substitute for obtaining Legal advice from a solicitor regulated in the UK, Solicitors.com recommends that you contact a firm of solicitors to discuss your individual legal requirement. Whilst we strive to bring you accurate up to date content, all content on this site is not legal advice and is not guaranteed to be correct. Use of this site does not create a client relationship.

Information by area of law
Back to top