Guides · Corporate crime
Failure to prevent fraud: where the real exposure sits
The offence under the Economic Crime and Corporate Transparency Act 2023 came into force on 1 September 2025, and the compliance response to it has largely been built by people whose existing anti-fraud work was designed to stop the organisation being defrauded. The offence is about something close to the opposite, and programmes built on the old assumption are pointed in the wrong direction.
The offence runs the other way
Liability arises where a person associated with a large organisation commits a specified fraud offence intending to benefit that organisation, or a person to whom the associated person provides services on the organisation’s behalf, and the organisation did not have reasonable fraud prevention procedures in place.
The intention to benefit is what relocates the risk. An employee who defrauds their own employer is not within the offence, because the intent runs against the organisation rather than towards it. What is within it is the salesperson who overstates performance figures to win a mandate, the trader who misrepresents a position, the bid team that misdescribes capability in a tender, the account manager who inflates numbers to hit a target. None of those people are stealing from the company. All of them are committing fraud that, if made out, was intended to benefit it.
That is not where anti-fraud control has historically been concentrated. Payment authorisation, segregation of duties, supplier verification and expenses review are all designed around the organisation as victim. They do very little about the organisation as beneficiary, and a risk assessment that simply catalogues existing controls will conclude that the organisation is well covered while leaving its actual exposure unexamined.
The organisation does not need to have benefited, and does not need to have known. Intention on the part of the associated person is enough. An organisation that received nothing, because the fraudulent bid was unsuccessful, is still within the offence.
Who is large, and who is associated
The threshold catches organisations meeting two of three criteria in the relevant financial year: turnover of more than £36 million, a balance sheet total of more than £18 million, and more than 250 employees. Groups are looked at in aggregate, so subsidiaries that would fall well below the thresholds standing alone are within the regime by virtue of the group they sit in.
Associated person is drawn as widely as the equivalent bribery concept: employees, agents, subsidiaries, and others performing services for or on behalf of the organisation. That reaches introducers, distributors, outsourced sales functions and contractors, which is where the difficult work is, because those are precisely the relationships over which the organisation has commercial leverage but limited visibility.
There is a UK nexus requirement rather than a UK incorporation requirement, so an overseas organisation can be caught where the underlying fraud has the necessary connection to the United Kingdom.
Reasonable procedures, and who has to prove them
The defence is that the organisation had reasonable fraud prevention procedures in place, or that it was not reasonable in the circumstances to expect it to have any. The burden sits on the organisation, to the civil standard.
That allocation is the operative fact for advisers. The organisation is not defending an allegation that its procedures were deficient; it is required to establish affirmatively that they were reasonable, which is an evidential task that has to be capable of being performed years after the event, by people who may have left, about a programme that has since changed. Documentation is the deliverable, not the policy.
The government guidance published in November 2024 is framed around familiar principles: top level commitment, risk assessment, proportionate procedures, due diligence, communication and training, and monitoring and review. It is guidance rather than a safe harbour, and reasonableness is judged against the organisation’s own risk profile.
The risk assessment is doing more work here than in the bribery context, because it is the document that has to demonstrate the organisation understood the inverted nature of the risk. A risk assessment that identifies procurement fraud and expenses abuse, and says nothing about incentives in the sales function or the accuracy of statements made to win work, is evidence against the organisation rather than for it. It shows, in its own words, that the exercise was conducted without understanding what the offence covers.
Primary sources
- Economic Crime and Corporate Transparency Act 2023, section 199, failure to prevent fraud
- Economic Crime and Corporate Transparency Act 2023, Part 5 (Sections 196 to 206, including the listed fraud offences and the large organisation thresholds.)