It creates potential corporate criminal liability where a specified fraud offence is committed by an employee, agent, subsidiary undertaking or other associated person intending to benefit the organisation, or in certain circumstances its client, and the organisation cannot establish the applicable defence concerning reasonable fraud prevention procedures. Directors or senior managers do not have to have ordered or known about the underlying fraud.

That changes the governance question.

The focus is no longer simply whether an organisation has controls to stop people stealing from it. Businesses in scope also need to think about fraud committed for its benefit.

Which organisations are in scope?

The offence applies to large incorporated bodies and partnerships across sectors.

For this particular offence, an organisation is “large” when it meets at least two of the following:

  • more than 250 employees
  • more than £36 million turnover; and
  • more than £18 million total assets.

These figures deserve particular emphasis because they are not the revised Companies Act 2006 medium-company limits applicable to financial years beginning on or after 6 April 2025.

A company with turnover of £45m, assets of £25m and 100 employees may be medium-sized for Companies Act reporting purposes under the newer thresholds but potentially meet two of the three statutory criteria for the failure-to-prevent-fraud offence.

Finance teams should therefore maintain a separate scope assessment.

The Home Office guidance also explains that the calculation can extend across subsidiary undertakings, including overseas subsidiary undertakings, for determining whether the organisation is large. The exact application can become more complex for unusual legal structures, so borderline cases warrant legal analysis.

What fraud is the organisation expected to prevent?

The offence does not cover every dishonest act in the abstract.

It applies where an associated person commits one of the specified base fraud offences in the circumstances required by ECCTA.

The Home Office guidance identifies offences including, for England and Wales, Fraud Act offences, false accounting, false statements by company directors, fraudulent trading and cheating the public revenue. Different underlying offences apply in the devolved jurisdictions.

A practical fraud-risk assessment should therefore start from realistic ways in which people acting for or on behalf of the organisation could manipulate information or conduct for organisational benefit.

Examples might include risks around:

  • sales practices
  • customer representations
  • contractual performance reporting
  • financial reporting
  • supplier arrangements
  • claims or applications
  • tax information
  • regulatory returns; and
  • performance-linked information.

The appropriate risks depend on the organisation rather than on a generic fraud checklist.

Who is an “associated person”?

Employees and agents can clearly fall within scope, as can subsidiary undertakings in the circumstances set out by the legislation.

Other persons can also be associated where they provide services for or on behalf of the organisation. The assessment is fact-specific.

The Home Office makes an important distinction: simply supplying services to a business does not automatically mean that supplier acts “for or on behalf of” it.

This makes third-party mapping an important implementation exercise.

Businesses should consider their:

  • sales agents
  • intermediaries
  • outsourced service providers
  • contractors
  • distribution arrangements
  • group companies; and
  • other parties performing functions externally that would otherwise sit inside the organisation.

The legal label placed on the relationship is not necessarily decisive.

What is the defence?

An organisation can have a defence where it had reasonable fraud prevention procedures, or where it can demonstrate that it was not reasonable in the circumstances to expect it to have any such procedures.

Ultimately, whether procedures were reasonable in a particular case is for the courts. The Home Office guidance is therefore important but does not provide an automatic safe harbour.

The Government's framework is built around six principles:

  1. top-level commitment;
  2. risk assessment;
  3. proportionate risk-based prevention procedures;
  4. due diligence;
  5. communication, including training; and
  6. monitoring and review.

These principles are outcome-focused rather than a prescribed control checklist.

The fraud risk assessment should be the foundation

For many organisations, this is the most important implementation document.

The Government says the assessment should consider the nature and extent of exposure to employees, agents and other associated persons committing relevant fraud. It should be dynamic, documented and kept under review.

An existing enterprise risk register can be a starting point, but it may not be enough.

Traditional fraud registers frequently concentrate on:

  • employee theft
  • cybercrime
  • supplier fraud
  • false expense claims; or
  • fraud against customers.

Those are important, but the new offence requires the organisation to turn the lens around and ask:

How could somebody acting for us commit a fraud that is intended to benefit us or, where relevant, our client?

That may expose very different incentives.

Sales targets, covenant pressure, performance bonuses, contract renewals, regulatory metrics or ambitious growth assumptions may all influence the risk assessment depending on the business.

Existing controls can be used, but should be mapped properly

The Home Office does not suggest creating a completely separate compliance universe where existing controls already address the identified risks.

Its guidance expressly recognises that existing regulatory compliance mechanisms, financial reporting controls and fraud-prevention measures may address relevant risks. The organisation should determine whether they are sufficient and add measures where gaps remain.

This is commercially important.

A business may already have:

  • approval limits
  • contract review
  • revenue controls
  • whistleblowing channels
  • customer-acceptance procedures
  • compliance monitoring
  • internal audit
  • supplier due diligence
  • employee training
  • financial statement controls; and
  • disciplinary processes.

The task is to connect those controls to the fraud risks identified under ECCTA and evaluate whether the framework is proportionate.

A thick new policy that nobody follows is unlikely to be a better outcome than strengthening the controls already embedded in the organisation.

Due diligence extends beyond recruitment

Government guidance describes due diligence as a proportionate, risk-based process for persons providing services for or on behalf of the organisation. It can include appropriate screening and assessment of contractual relationships, agents and acquisitions.

The level of diligence should follow the risk.

A third party with authority to make significant representations to customers on the company's behalf presents a different profile from a low-risk supplier that merely sells routine goods to the company.

The same applies after acquisitions. Buying a business can introduce new people, incentive structures, geographies and practices into the fraud-risk environment.

Communication must reach the commercial side of the business

Fraud prevention cannot remain a Finance or Compliance document.

The Government places communication and training within the six-principle framework and expects policies to be understood by those whose activities create the relevant risks.

That can require targeted training for sales, procurement, finance, operations and senior management rather than one generic e-learning module.

There is an important cultural element too.

If a written policy says that financial information must be accurate but commercial management informally rewards people for “making the number at all costs”, the two messages are inconsistent.

Top-level commitment needs to be visible in actual management behaviour.

Monitoring makes the framework a continuing process

A fraud framework that was reasonable in September 2025 may not remain reasonable indefinitely.

Business models change. New agents are appointed. Acquisitions happen. Incentive schemes change. New fraud typologies emerge.

The Government therefore expects monitoring and review, including learning from investigations and whistleblowing matters and assessing whether fraud-prevention measures remain effective.

That can be integrated into existing governance rather than creating unnecessary parallel processes.

For example, boards may receive periodic reporting covering:

  • relevant incidents and allegations
  • training completion
  • significant control failures
  • changes in fraud risk
  • third-party due-diligence issues; and
  • progress against remediation plans.

Finance and audit implications

There is a natural overlap between ECCTA risk and financial reporting controls, but the two are not identical.

External auditors are auditing the financial statements rather than providing a legal opinion that the organisation's ECCTA defence is sufficient.

Nevertheless, fraud-risk information can be relevant to an audit. Management should expect the auditor to understand fraud risks affecting the financial statements and to make appropriate enquiries.

Where the organisation has identified risks involving revenue manipulation, false accounting or management incentives, those conclusions may also inform the auditor's fraud risk assessment.

Management should therefore avoid producing an ECCTA fraud assessment that conflicts inexplicably with the representations it makes to its external auditor.

What should businesses do now?

  1. Confirm whether the organisation is in scope using the ECCTA-specific size test.
  2. Document a fraud risk assessment focused on fraud intended to benefit the organisation or relevant clients.
  3. Map employees, agents, subsidiaries and other potentially associated persons.
  4. Link existing controls to the identified risks and document genuine gaps.
  5. Review high-risk third parties and contractual protections proportionately.
  6. Provide targeted training rather than relying solely on generic fraud awareness.
  7. Establish board-level monitoring and periodic reassessment of the framework.

Conclusion

The failure-to-prevent-fraud offence is best understood as a governance and controls requirement rather than a policy-writing exercise.

A defensible framework should show a logical chain: the organisation understood where relevant fraud might arise, designed proportionate measures to address those risks, communicated them to the right people and continued to monitor whether they worked.

Continue the assessment

Use the relevant Accoura tools to turn the guidance into a focused company, reporting or audit review.

Frequently asked questions

When did the UK failure-to-prevent-fraud offence take effect?

It came into force on 1 September 2025.

Which businesses are in scope?

Broadly, large incorporated bodies and partnerships meeting at least two of the statutory £36m turnover, £18m asset and 250-employee tests, subject to the detailed legislation.

Does the fraud have to be approved by directors?

No. The legislation does not require proof that directors or senior management ordered or knew about the fraud.

What are reasonable fraud prevention procedures?

There is no universal checklist. Government guidance uses six principles, including risk assessment, proportionate procedures, due diligence, communication and monitoring.

Do smaller businesses need to follow the offence?

The offence applies to large organisations, although Government guidance notes that its principles may also be useful good practice for smaller organisations.

Technical verification notes

The statutory scope, territorial nexus, associated-person analysis and application to particular group structures can be legally complex. Client-specific conclusions should be checked against ECCTA and current legal guidance rather than this general article alone.

Primary authority: Home Office failure-to-prevent-fraud guidance

Primary sources