FCA authorised · FRN 7249520117 325 0027Quote & buy →
Apex Insurance Brokers
Speak to a brokerGet a quote →

Corporate criminal liability

The failure to prevent fraud offence: what UK boards need to know

Since 1 September 2025, a large organisation is criminally liable if an employee, agent or other associated person commits fraud intending to benefit it or its clients, unless it can prove it had reasonable procedures in place to prevent that fraud. The offence is in section 199 of the Economic Crime and Corporate Transparency Act 2023. This reference sets out who is in scope, which frauds count, how the defence works and what it means for directors, with links to the legislation and Home Office guidance.

In short

From 1 September 2025, a company or partnership exceeding at least two of three thresholds (250 employees, £36 million turnover, £18 million balance sheet total) is criminally liable under section 199 of the Economic Crime and Corporate Transparency Act 2023 if an associated person commits a listed fraud intending to benefit it or its clients, unless it proves it had reasonable prevention procedures. The fine can be unlimited.

How the offence works

Section 199 of the Economic Crime and Corporate Transparency Act 2023 makes a “relevant body” — a body corporate or partnership, wherever incorporated or formed — guilty of an offence if it is a large organisation and a person associated with it commits a fraud offence intending to benefit, directly or indirectly, the organisation or a person to whom the associate provides services on its behalf, such as a client.

An associated person is an employee, agent or subsidiary undertaking, or anyone who otherwise performs services for or on behalf of the organisation, judged on all the relevant circumstances (section 199(7) and (9)). The guidance says people who provide services to an organisation, such as external lawyers, accountants or engineers, are not associated persons unless they also provide services for or on its behalf and the fraud is committed in that context. The fraud must be committed in the person’s capacity as an associate, and there must be a UK connection: part of the fraud takes place in the UK, or the gain or loss occurs here.

Who is in scope: the “large organisation” test

The offence applies only to large organisations. Under section 201, an organisation is large if it met at least two of these conditions in its financial year before the year in which the fraud was committed:

ConditionThreshold
TurnoverMore than £36 million
Balance sheet total (total assets)More than £18 million
EmployeesMore than 250 (monthly average)

For a parent undertaking, section 202 applies the test to the whole group, aggregating the parent and its subsidiary undertakings, including those operating wholly outside the UK. LLP networks, franchises and supply chain companies are not aggregated. A subsidiary that is not itself large can still be prosecuted where its own employee commits fraud intending to benefit it and its parent is a large organisation (section 199(2)).

Relevant bodies include companies, limited liability partnerships, partnerships and bodies created by Royal Charter or statute. Incorporated charities that meet the size test are in scope; unincorporated organisations other than partnerships are not. The Secretary of State can change the size test by regulations, or remove the large-organisation limit altogether (section 201(6) and (7)).

Which fraud offences are covered

The underlying “base” fraud offences are listed in Schedule 13. Aiding, abetting, counselling or procuring any of them also counts (section 199(6)).

JurisdictionBase fraud offences (Schedule 13)
England and WalesFraud by false representation, failing to disclose information or abuse of position (Fraud Act 2006, section 1); participating in fraudulent business carried on by a sole trader (section 9); obtaining services dishonestly (section 11); false accounting and false statements by company directors (Theft Act 1968, sections 17 and 19); fraudulent trading (Companies Act 2006, section 993); cheating the public revenue (common law)
Northern IrelandThe same offences, with false accounting and false statements by company directors under the Theft Act (Northern Ireland) 1969, sections 17 and 18
ScotlandFraudulent trading (Companies Act 2006, section 993) and the common law offences of fraud, uttering and embezzlement

Money laundering offences are not on the list. Regulations can amend it, but any offence added must be an offence of dishonesty, similar in character to those originally listed, or one of three money laundering offences under the Proceeds of Crime Act 2002 (section 200).

The defence, the Home Office guidance and what boards should do

It is a defence for the organisation to prove that, when the fraud was committed, it had the prevention procedures it was reasonable in all the circumstances to expect, or that it was not reasonable to expect it to have any (section 199(4)). The burden is on the organisation, on the balance of probabilities, and only a court can decide whether procedures were reasonable.

Section 204 requires the Secretary of State to publish guidance. The Home Office published it on 6 November 2024 and last updated it on 10 October 2025. It is advisory, but a court will take adherence to its six principles into account: top-level commitment, risk assessment, proportionate risk-based prevention procedures, due diligence, communication (including training) and monitoring and review. It is not a safe harbour: following it may not be enough if the organisation has particular risks it has not addressed. It also says it will rarely be reasonable not to have carried out a risk assessment, that an audit alone cannot amount to a defence, and that being regulated does not automatically mean existing compliance processes qualify.

The guidance places responsibility for preventing and detecting fraud with those charged with governance. Practical steps for an in-scope board:

Penalties, personal liability and insurance

An organisation convicted of the offence is liable to a fine (section 199(12)). The Home Office and the CPS describe it as an unlimited fine; on summary conviction in Scotland or Northern Ireland the fine cannot exceed the statutory maximum. Prosecutors include the CPS and the Serious Fraud Office, with the Crown Office and Procurator Fiscal Service in Scotland and the Public Prosecution Service in Northern Ireland. Section 206 makes it eligible for a deferred prosecution agreement, which the guidance notes is available in England and Wales only, and lists it as a “serious offence” for the purposes of serious crime prevention orders. The guidance says an organisation’s co-operation and full disclosure are taken into account in deciding whether to prosecute.

The offence creates no personal liability for directors or managers who failed to prevent a fraud. Anyone who commits the underlying fraud, or encourages or assists it, can still be prosecuted for it, including directors and senior managers.

Where insurance fits. The offence is committed by the organisation, and criminal fines are generally not insurable. Directors can still be investigated personally where a fraud raises questions about their own conduct. A directors’ and officers’ (D&O) policy can typically help individual directors with legal defence and investigation costs, subject to the policy wording, limits and exclusions. Policies typically exclude deliberate fraud and dishonesty, and D&O insurance should not be relied on to pay fines or penalties. Apex arranges D&O insurance: see D&O defence costs and investigations cover.

Smaller organisations and the senior manager rule

Organisations below the size test are outside section 199, but not outside corporate criminal liability:

For founders and directors of growing companies, see what a founder is personally liable for and D&O insurance for startups.

Frequently asked

When did the failure to prevent fraud offence come into force?

The offence in section 199 of the Economic Crime and Corporate Transparency Act 2023 came into force on 1 September 2025, under commencement regulations S.I. 2025/349. The Home Office published its guidance on reasonable fraud prevention procedures on 6 November 2024, and the gap was intended to give organisations time to develop and implement those procedures. Because the size test looks at the financial year before the fraud, organisations need to check their position each year.

Does the failure to prevent fraud offence apply to small companies?

Generally not. It applies to companies, LLPs, partnerships and other incorporated bodies that met at least two of three conditions in the previous financial year: more than 250 employees, more than £36 million turnover, more than £18 million balance sheet total. Group figures are aggregated, and a subsidiary that is not itself large can be liable if its parent is. Smaller organisations can also be associated persons of large clients, and organisations of any size can be liable for offences committed by senior managers acting within their authority.

Can directors be prosecuted personally for failure to prevent fraud?

No. The offence is committed by the organisation, and the Home Office guidance confirms it does not create individual liability for people who failed to prevent a fraud. Anyone who commits the underlying fraud, or encourages or assists it, can still be prosecuted for that fraud. The joint SFO and CPS guidance says prosecuting an organisation should not be a substitute for prosecuting culpable individuals, including directors and senior managers.

What is the penalty for failure to prevent fraud?

A fine. Section 199(12) of the Act provides for a fine on conviction, which the Home Office and the CPS describe as unlimited; on summary conviction in Scotland or Northern Ireland the fine cannot exceed the statutory maximum. It is also listed as a serious offence for serious crime prevention orders, and in England and Wales it can be resolved through a deferred prosecution agreement.

What counts as reasonable fraud prevention procedures?

The Act does not prescribe them, and only a court can decide whether procedures were reasonable in a particular case. The Home Office guidance sets out six principles: top-level commitment, risk assessment, proportionate risk-based prevention procedures, due diligence, communication (including training), and monitoring and review. The organisation must prove its procedures were reasonable on the balance of probabilities. The guidance is not a safe harbour, and it says it will rarely be reasonable not to have carried out a risk assessment.

Does D&O insurance cover the failure to prevent fraud offence?

Not the offence itself. The offence is committed by the organisation, and criminal fines are generally not insurable. Where individual directors or officers are investigated or need legal representation, a D&O policy can typically help with their defence and investigation costs, subject to the policy wording, limits and exclusions. Policies typically exclude deliberate fraud and dishonesty, so D&O insurance should not be relied on to pay fines or penalties.

Review your board’s cover

Talk to us about D&O insurance for your directors and officers and how it responds to investigations, subject to the policy terms. Or call 0117 325 0027.

Get a quote Call 0117 325 0027

Apex Insurance Brokers Limited is authorised and regulated by the Financial Conduct Authority. Registered in England and Wales, company number 07014570. This page is general information, not legal or tax advice on your individual circumstances, and it does not guarantee that cover will be available or on what terms.