Is Your Board Ready for the Failure to Prevent Fraud Offence?
The Failure to Prevent Fraud offence under the Economic Crime and Corporate Transparency Act 2023 makes UK boards criminally liable without documented reasonable procedures.
The offence has applied since 1 September 2025, and enforcement bodies including the Serious Fraud Office and Crown Prosecution Service have made clear that a written policy sitting in a compliance folder will not satisfy the statutory defence. For boards and NEDs, this is no longer a legal-team briefing item — it is a governance obligation with unlimited fines attached, and Q3 2026 board cycles are the moment to evidence it properly.
What Is the Failure to Prevent Fraud Offence?
The offence makes a “relevant organisation” criminally liable where an associated person — an employee, agent, subsidiary, or contracted service provider — commits one of the specified base fraud offences intending to benefit the organisation or its clients. Base offences include false accounting under the Theft Act 1968, fraudulent trading, cheating the public revenue, and false statements by directors. Critically, prosecutors do not need to prove that the board or senior management knew about the fraud. The organisation is liable unless it can show it had reasonable procedures in place to prevent it — the single statutory defence available.
Executive Action:
- Confirm which base fraud offences are most plausible in your organisation’s operating model — procurement, revenue recognition, and tax reporting are common exposure points.
- Ask General Counsel or the Chief Risk Officer for a written confirmation of “associated person” scope, including agents and outsourced service providers.
- Add the offence explicitly to the board risk register, distinct from existing bribery or tax evasion failure-to-prevent entries.
Which Organisations Fall Within Scope?
The offence applies only to “large organisations,” a status determined by meeting at least two of three thresholds in the financial year preceding the offence: more than 250 employees, more than £36 million in turnover, or more than £18 million in total assets. The test is applied on a group-wide basis, so a smaller UK subsidiary of a large group can fall within scope even if it individually looks modest. Organisations that cross the thresholds mid-year should apply the offence prospectively from the start of the financial year in which the threshold was crossed, not wait for a formal notification.
Executive Action:
- Run the two-of-three threshold test at group and subsidiary level, not just at the ultimate parent.
- Flag any entity approaching the thresholds so procedures are ready before the offence bites, not after.
- Review this alongside the wider Economic Crime and Corporate Transparency Act obligations already in motion, including Companies House identity verification.
What Do “Reasonable Procedures” Actually Require?
According to the Home Office’s Failure to Prevent Fraud Guidance, reasonable procedures must reflect six principles: top-level commitment, a dynamic fraud risk assessment, proportionate prevention procedures, fraud-specific due diligence, communication and training, and continuous monitoring and review. The guidance is explicit that a static policy document does not discharge the defence — organisations must be able to evidence the controls operating in practice, with dated records of risk assessments, training completion, and board-level review.
Most UK organisations have work to do here. According to a Foot Anstey fraud prevention and response survey, only 47% of businesses have anti-fraud policies in place, just 54% provide staff training on fraud, and only 20% have a dedicated, salaried fraud prevention role — despite 45% reporting they had to act on employee or contractor fraud in the preceding 12 months.
Executive Action:
- Commission a fraud risk assessment mapped explicitly to the six Home Office principles, not a generic financial crime review.
- Require evidence, not assurance — dated training records, monitoring logs, and minuted board discussion of fraud risk.
- Name a senior risk owner or “fraud champion” with a standing board reporting line.
How Should the Board Govern This Risk?
This offence sits squarely with the board, not just the finance or legal function, because the reasonable procedures defence depends on demonstrable “top-level commitment.” That means fraud prevention needs to appear as a standing item on the audit or risk committee agenda, with management reporting evidence rather than intent. It also intersects with existing governance obligations: UK Corporate Governance Code Provision 29 already requires boards to declare the effectiveness of their material internal controls, and a documented fraud prevention framework is now a natural component of that declaration rather than a separate exercise.
Boards that treat this as a one-off legal sign-off, rather than an ongoing control they can evidence, are the ones most exposed if the Serious Fraud Office or CPS comes asking. INFORMD’s Economic Crime Act CFO filing checklist covers the parallel identity verification obligations under the same Act — the two workstreams should be governed together, not in separate silos.
Executive Action:
- Add fraud prevention procedures as a distinct line item in the next Provision 29 material controls declaration.
- Request an annual, minuted board or audit committee review of fraud risk assessment and procedure effectiveness.
- Use INFORMD’s executive self-assessment tools and capital and control review templates to benchmark current procedures against the six-principle framework.
INFORMD provides intelligence briefings, tools and frameworks for senior business leaders across technology, finance, strategy and compliance. Based in Milton Keynes, UK, we help executives stay informed and act with confidence. Explore our full briefing library (/resources/) or access our free assessment tools (/tools-assessments/).
Stay ahead. Subscribe to INFORMD’s weekly executive briefing at informd.co.uk. Questions about how this affects your organisation? Get in touch, or watch for upcoming video briefings on this topic in our video library.
The offence took effect on 1 September 2025 under the Economic Crime and Corporate Transparency Act 2023. It applies to fraud committed by associated persons on or after that date, regardless of when the underlying conduct began.
Large organisations meeting at least two of three thresholds in the preceding financial year: more than 250 employees, more than £36 million turnover, or more than £18 million total assets. The test applies at group and subsidiary level.
It is the sole statutory defence to the offence. Organisations must show documented, actively operating procedures covering top-level commitment, risk assessment, due diligence, training, communication, and monitoring — not just a written policy.
The board and audit or risk committee, because the defence depends on evidenced top-level commitment. Many boards fold this into their UK Corporate Governance Code Provision 29 material controls declaration.
