Failure to prevent fraud: One year on
The corporate offence of failure to prevent fraud offence has been in force for one year. Enforcement activity to date remains limited but evolving prosecutorial tools and other more recent reforms mean that corporates should be keeping risk assessment, governance and compliance frameworks under review.
The corporate offence
Since 1 September 2025, UK prosecutors have been able to take criminal enforcement action against large corporate organisations which do not have in place "reasonable prevention procedures" in relation to fraud.
We tracked the development of the corporate offence of failure to prevent fraud ("the Corporate Offence") from its inception. See our September 2025 blog post for links to analysis on how it applies to corporate organisations in the UK and further afield, situations in which the offence may be engaged and key considerations to bear in mind when designing and implementing "reasonable prevention procedures".
The UK enforcement environment
The Corporate Offence has not yet been used in any publicised cases. That is unsurprising. Large-scale corporate fraud investigations are typically complex, multi-jurisdictional and measured in years rather than months. However, the absence of publicised cases to date should not be interpreted as a lack of enforcement interest. The Serious Fraud Office ("SFO") has repeatedly indicated that it is actively seeking opportunities to identify corporates with deficient anti-fraud compliance arrangements. The National Crime Agency, City of London Police, Crown Prosecution Service and HM Revenue & Customs also remain operationally active.
Corporate criminal liability: A changing landscape
Corporates' potential criminal liability does not begin and end with fraud. The past year has seen substantial changes to rules governing how they may be held criminally liable for all offences. For detailed analysis of what these changes, effective from 29 June 2026, mean for corporates in various key sectors, see our June 2026 blog post.
As a practical matter, the interaction between these changes to rules on attribution and the Corporate Offence may influence the way investigations concerning suspected corporate fraud develop. Authorities can commence investigations on a broad basis but have more flexibility than ever about how to characterise misconduct by senior individuals when deciding how to conclude those investigations.
It is easier than ever for prosecutors to build cases against corporates on the basis that conduct amounting to the commission of criminal offences by those senior individuals should be attributed to the corporate. This matters for corporates for several reasons.
Firstly, it will often be easier for prosecutors to secure corporate convictions via this route (as opposed to using the Corporate Offence). They need not show that the conduct of the individual(s) in question was "for the benefit" of the corporate concerned (a prerequisite for the Corporate Offence). When making decisions about which action to take, prosecutors are not limited to the relatively narrow range of offences which may form the basis of a prosecution or corporate settlement for failure to prevent fraud. Importantly, particularly in cases where they may face difficulties establishing dishonesty on the part of individuals, their ability to attribute individuals' conduct amounting to the commission of other, often more technical, non-fraud based offences to the corporate will bring some matters out of the realms of regulatory enforcement action and potentially before the criminal courts. At a time when, notwithstanding commitments to taking action, numbers of new investigations and disposals by the SFO and CPS in cases concerning corporates are relatively low, this may clear the way for other specialist authorities with criminal enforcement remits (for example the Environment Agency or Information Commissioner's Office) to take action in respect of these types of offences.
Secondly, the consequences of investigations in which authorities are examining whether to attribute suspected criminal conduct of senior individuals to corporates may be substantially different to those in which they are looking at the possible application of the Corporate Offence. This is because, in the UK, even where authorities and courts are prepared to conclude and approve deferred prosecution agreements ("DPAs"), these are not available to conclude investigations concerning all criminal offences. Corporates will only be able to negotiate a DPA for the Corporate Offence and a relatively small number of other economic offences. There are substantial numbers of offences, many of which it may be easier for prosecutors to establish, for which DPAs are not available. In some cases, the fact that a corporate has been charged with and convicted of offences (as opposed to entering into a negotiated settlement) may have important commercial consequences, for example in relation to its ability to participate in public procurement processes.
As more instances of suspected misconduct occurring since 29 June 2026, when the changes to rules on attribution took effect, come to light, judgements for companies about whether proactively to self-report to authorities, or whether doing so may expose them to greater (or less easily quantifiable) risk of prosecution, may become more finely balanced.
Guidance on corporate cooperation issued prior to the most recent changes to rules on attribution has emphasised the potential benefits of providing information concerning the role of individuals in misconduct. That guidance stands in relation to action that may be taken concerning the Corporate Offence. However, there have not yet been any clear indications of how prosecutors will respond in cases where corporates proactively disclose details of conduct which could provide a foundation for action for other offences.
Practical points for risk assessments
Risk assessments and other compliance arrangements adjusted in response to the Corporate Offence and other changes to the law on corporate criminal liability should remain living documents. Business models evolve, geographic footprints expand, technologies change and new products, services and distribution channels create new opportunities for fraud and misconduct.
Practical questions to consider when re-evaluating and refreshing these arrangements will include:
- Do fraud prevention procedures remain aligned with current business activities, growth strategies and operational realities?
- Have lessons been incorporated from internal investigations, whistleblowing reports, regulatory findings or industry developments?
- Are fraud controls being tested and evidenced in practice rather than merely documented?
- Is responsibility for fraud risk clearly allocated across the three lines of defence?
- Are third-party management, commission arrangements, sales incentives and supply-chain relationships subject to appropriate scrutiny?
- Does management information permit meaningful challenge and oversight by boards and risk committees?
Can the organisation demonstrate periodic review, monitoring and remediation of fraud controls and compliance arrangements?