Search

Failure to Prevent Fraud: What Boards Must Have in Place 

Boards should be able to show that their organisation has assessed its exposure to failure to prevent fraud, assigned responsibility, implemented proportionate controls and checked that those controls work. Since 1 September 2025, organisations within scope can face criminal liability for specified fraud by associated persons, subject to the statutory defence. 

The board needs to connect its policies and decisions to what people actually do. Use the 12-point board checklist below to examine the evidence behind your organisation’s arrangements. 

What is the failure to prevent fraud offence? 

Failure to prevent fraud is a corporate criminal offence created by the Economic Crime and Corporate Transparency Act 2023 (ECCTA). It has applied since 1 September 2025. A large organisation may be liable when an associated person commits a specified fraud intending to benefit it, directly or indirectly. Directors and senior managers need not have ordered or known about the fraud. ECCTA, section 199. 

The offence can also apply where the fraud is intended to benefit a person receiving services from the associate on the organisation’s behalf, or a person whose subsidiary undertaking receives those services. This separate basis for liability is set out in section 199(1)(b)

The organisation has a statutory defence based on reasonable prevention procedures, explained below. A conviction can result in an unlimited fine under section 199(12). 

Which organisations are in scope of failure to prevent fraud? 

The offence principally applies to large bodies corporate and partnerships, including qualifying incorporated charities and public bodies. A body corporate is an organisation incorporated as a legal person, such as a limited company. A parent undertaking heads a group and is assessed using group figures. ECCTA, sections 199, 201 and 202. 

At least two of the following three conditions must be met in the financial year before the one in which the underlying fraud occurs: 

Condition Organisation that is not a parent undertaking Parent undertaking, assessed across its group 
Turnover More than £36 million More than £36 million net, or £43.2 million gross 
Balance sheet total More than £18 million More than £18 million net, or £21.6 million gross 
Employees More than 250 More than 250 in aggregate 

The employee figure is a monthly average, rather than the headcount on one date. Balance sheet total means total assets, not assets minus liabilities. Turnover thresholds are adjusted proportionately for financial years longer or shorter than 12 months. ECCTA, section 201. 

For groups, net means after the relevant adjustments eliminating group transactions; gross means before those adjustments. ECCTA, section 202 applies the definitions in Companies Act 2006, section 466(6)

For example, a standalone company whose preceding 12-month financial year shows average employment of 260 people, £30 million turnover and £20 million total assets meets two conditions. Its turnover being below £36 million does not take it outside scope. This is a hypothetical illustration of the statutory test. 

Can small subsidiaries and overseas organisations be caught? 

Yes, in defined circumstances. Under section 199(2), a subsidiary undertaking that is not itself large can be liable if its employee commits fraud intending to benefit it and its parent is a qualifying large organisation. A subsidiary’s employee can also expose a qualifying parent where the fraud is intended to benefit that parent. ECCTA, section 199(2), (7)–(8). 

The term subsidiary undertaking can include indirect subsidiaries and undertakings other than companies. Use the statutory definitions when assessing group scope. Companies Act 2006, sections 1161 and 1162

Overseas organisations can be caught where the underlying fraud falls within UK jurisdiction. The Home Office describes the necessary connection as an act forming part of the fraud taking place in the UK, or a gain or loss occurring here. If no part of the fraud takes place in the UK, merely intending a UK gain or loss is insufficient. For Scotland’s common-law offences, jurisdiction is assessed case by case. Home Office guidance, section 2.5. 

Smaller independent businesses are not all directly subject to this offence. Those providing services for or on behalf of a large organisation may face contractual fraud-prevention requirements. Home Office guidance, section 2.3. Group boards should connect their scope assessment to their subsidiary governance arrangements, so responsibilities and reporting routes are clear. 

Who counts as an associated person? 

An associated person includes an employee, agent, subsidiary undertaking, or another person performing services for or on behalf of the organisation. The legislation also makes specific provision for employees of subsidiary undertakings. Whether a service provider qualifies depends on all the relevant circumstances. Source: section 199(7)–(9). 

The distinction is between services for or on behalf of the organisation and services merely supplied to it. A supplier is not automatically associated because it has a contract with the organisation. Equally, a subcontractor may qualify without a direct contract. The Home Office guidance explains that the fraud must occur while the person is acting in their relevant capacity. Source: guidance, section 2.3. 

Boards should ask management to identify the actual relationships involved, including outsourced services, agents and group entities. A list of suppliers alone will not answer that question. 

Which fraud offences are covered? 

The underlying conduct must constitute an offence specified in Schedule 13, or aiding, abetting, counselling or procuring one of those offences under section 199(6). The list differs between UK jurisdictions. In England and Wales, it covers: 

  • Fraud by false representation, failing to disclose information or abuse of position: Fraud Act 2006, sections 1–4. 
  • Participating in a fraudulent business: Fraud Act 2006, section 9. 
  • Obtaining services dishonestly: Fraud Act 2006, section 11. 
  • False accounting: Theft Act 1968, section 17. 
  • False statements by company directors: Theft Act 1968, section 19. 
  • Fraudulent trading: Companies Act 2006, section 993. 
  • Cheating the public revenue: a common-law offence. 

Northern Ireland uses the corresponding Theft Act (Northern Ireland) 1969 provisions. Scotland has a different list of common-law offences, alongside fraudulent trading. ECCTA, Schedule 13. 

What does intention to benefit mean? 

The associated person must intend the fraud to benefit the organisation, directly or indirectly, or a person within the services relationship described above. The benefit need not be financial or the fraudster’s main motive. The organisation need not actually receive a benefit, although the underlying fraud offence must have been committed. ECCTA, section 199(1)Home Office guidance, section 2.4

For example, an employee might manipulate financial results both to increase their bonus and to make the company appear more profitable. In this hypothetical scenario, personal gain does not exclude corporate liability where benefiting the company is also intended. 

For the board, this means examining fraud intended to benefit the organisation as well as fraud committed against it. Consider the pressures created by sales targets, funding applications, financial reporting and remuneration arrangements. 

The exclusion for victims is specific. Under section 199(3), an organisation is excluded from liability under section 199(1)(b) if it is a victim or intended victim of the fraud. This concerns the intended benefits to service recipients or their parents described above. Reputational damage when fraud is discovered does not, by itself, make the organisation a victim for this purpose. ECCTA, section 199(3)Home Office guidance, section 2.4

What are reasonable fraud prevention procedures? 

The statutory defence requires the organisation to prove that, when the fraud occurred, it had the prevention procedures it was reasonable to expect in all the circumstances. Alternatively, it can prove that it was not reasonable to expect any prevention procedures. ECCTA, section 199(4)–(5). 

The organisation must establish the defence on the balance of probabilities, meaning that its case is more likely than not. Only a court can determine whether the procedures were reasonable in the particular case. Source: Home Office guidance, sections 1.2 and 2.6. 

The guidance is advisory. Following it does not guarantee a defence, and departing from it does not automatically defeat one. It states that having conducted no risk assessment will rarely be reasonable. Decisions not to introduce a procedure for a particular risk should be recorded with the reason and the responsible decision-maker. 

ECCTA does not prescribe a universal set of board documents or create a standalone offence of lacking a fraud policy. The underlying fraud and the other statutory conditions must be established. 

What should boards do under the six Home Office principles? 

Boards should use the six principles to examine whether prevention procedures fit the organisation’s risks and operate in practice. The principles inform the framework; the examples below translate them into questions for board oversight. Source: Home Office guidance, chapter 3. 

  1. Top-level commitment. Set clear expectations about rejecting fraud. Assign responsibility, provide resources and check whether incentives and management decisions support that position. 
  1. Risk assessment. Identify who could commit fraud, how it could benefit the organisation or relevant clients, and where controls could be bypassed. Record the assessment and review it as risks change. 
  1. Proportionate risk-based prevention procedures. Match controls to identified risks. These might include independent checks on financial adjustments, approval of customer claims and controls over funding submissions. 
  1. Due diligence. Make checks on associated persons proportionate to the risk. Review relevant contracts and address fraud controls when acquiring or integrating a business. 
  1. Communication, including training. Explain the offence and the relevant procedures. Tailor training to higher-risk roles and make reporting concerns practical and accessible. 
  1. Monitoring and review. Test controls, investigate concerns and track corrective action. Give the board information that reveals weaknesses and overdue decisions. 

Setting the tone from the top means showing how the board’s expectations influence decisions when commercial pressure makes an exception tempting. 

What evidence should the board be able to produce? 

A useful evidence pack connects the risk assessment, assigned responsibilities, operating controls and board decisions. The following 12-point checklist is a practical governance tool, not a statutory list or a guarantee of the defence. Adapt it to the organisation’s risks and use existing records where they do the job. 

Evidence to locate Question for the board or responsible committee 
1. Entity and group scope assessment Which entities are caught, using which financial year, figures and legal analysis? 
2. Associated-person assessment Who can act for us, and where do services, group relationships or subcontracting create exposure? 
3. Dated fraud risk assessment Does it address fraud intended to benefit us or relevant clients, including pressure from targets and rewards? 
4. Responsibilities and escalation routes Who owns the framework, each material risk and each control? Can concerns reach the appropriate decision-maker? 
5. Risk-to-control mapping What prevents each identified fraud, and what happens if someone bypasses that control? 
6. Decisions about gaps and exceptions Where have we decided against a procedure, why, who authorised that decision and when will it be reconsidered? 
7. Due diligence and relevant contract records What did checks identify, and how were concerns about agents or service providers addressed? 
8. Acquisition and integration records, where relevant Have acquired entities’ risks, responsibilities and controls been brought into the framework? 
9. Training and communication evidence Can people in higher-risk roles recognise the issue and apply the procedure, beyond completing a course? 
10. Reporting and investigation arrangements Can people raise concerns safely, and are investigation responsibilities and escalation decisions clear? 
11. Control-test results and follow-up What was tested, by whom, what failed and what evidence confirms that corrective action worked? 
12. Board records and review schedule What information was challenged, what decisions followed, who owns the actions and what triggers an earlier review? 

This checklist applies the statutory scope and defence provisions alongside the Home Office’s six principles. Its emphasis on evidence of operation also reflects the SFO’s guidance: having policies and controls does not, by itself, establish that a compliance programme is effective. Source: SFO compliance guidance, section 9.3. 

How can the board test a reassuring report? 

Take a hypothetical report stating that all finance staff have completed fraud training and every manual revenue adjustment requires approval. Those statements describe controls, but leave their operation untested. 

Ask management to trace a recent adjustment through the supporting documents, approval and subsequent testing. Establish whether the approver checked the evidence, whether an override was possible and how any exception reached the risk owner. Agree who will remedy a weakness and what evidence will demonstrate closure. 

This is a suggested board challenge, not an audit methodology. The test should fit the risk, and the people testing the prevention plan should be independent of its authors, as recommended in the Home Office guidance. A minute records the board’s decision; it cannot substitute for an operating control. 

Frequently asked questions 

Can directors be prosecuted personally for failing to prevent fraud? 

Section 199 creates an offence for the organisation, not personal liability for a director simply because they failed to prevent it. Individuals can still be prosecuted for committing, encouraging or assisting the underlying fraud. Source: Home Office guidance, chapter 2. 

Does an external audit or compliance with the UK Corporate Governance Code establish the defence? 

No. Neither an audit nor Code compliance is sufficient on its own. Relevant work can contribute, but the organisation needs to assess whether it covers the fraud risks involved. Existing control testing need not be duplicated where it already addresses the specific risk. Source: Home Office guidance, sections 3.3.7 and 4.2–4.3. 

How often should fraud prevention procedures be reviewed? 

Set the review frequency according to the organisation’s risks. The Home Office describes risk assessments commonly taking place annually or every two years, with earlier reviews when circumstances change. There is no universal annual review deadline under section 199. Home Office guidance, sections 3.2.7 and 3.6.2. Companies applying the UK Corporate Governance Code should also account for Provision 29’s annual review of the risk management and internal control framework. FRC, UK Corporate Governance Code 2024. 

Does the reasonable procedures defence protect the organisation from every fraud charge? 

No. It is a defence to failure to prevent fraud. Separate rules can make an organisation liable for a senior manager’s own offending. Since 29 June 2026, section 250 of the Crime and Policing Act 2026 provides a broader attribution route where a senior manager commits an offence within their actual or apparent authority, subject to its statutory conditions. Section 199’s defence does not transfer to that route. Crime and Policing Act 2026, section 250 and section 255(3)(k)

Share on social media:

Other Insights

Remain at the forefront of industry trends with our macro and market commentary, delivering the latest updates, in-depth analysis, and expert insights

Download PDF

Download PDF

Download PDF

Download PDF

Download PDF

Download PDF

Download PDF

Download PDF

Download PDF

Download PDF

Download PDF

Download PDF

Download PDF

Download PDF

Download PDF

Download PDF

Download PDF