Financial Crime · Strategic Guide

Corporate Criminal Liability: Senior Managers, Associated Persons and Failure to Prevent Fraud

Corporate criminal liability no longer turns on one test. A company may face direct liability through a senior manager, failure-to-prevent liability through an associated person, or liability under established statutory and common-law routes. Craig MacKenzie explains how boards should identify the correct route, separate corporate exposure from individual guilt and preserve the evidence on which both may depend.

Author
Craig MacKenzie
Role
Partner and Solicitor Advocate
Published
27 July 2026
Reading time
25 minutes

One event can create several liability questions

When suspected fraud emerges, organisations often ask a single question:

Is the company criminally liable?

The question is understandable, but too compressed.

A proper analysis may need to ask:

  • did an individual commit a substantive offence;
  • can that conduct and state of mind be attributed to a corporate body;
  • was the individual a senior manager acting within the actual or apparent scope of their authority;
  • did an associated person commit a qualifying fraud intending to benefit the organisation or, in some circumstances, its client;
  • was the organisation itself a victim or intended victim;
  • did it have reasonable fraud-prevention procedures;
  • does another statute impose a separate corporate offence;
  • did anyone consent to, connive in or assist the offence;
  • which legal entity employed, instructed, benefited from or controlled the relevant person; and
  • is there a sufficient UK connection?

Those routes overlap, but they are not interchangeable. Each has its own elements, evidential questions, scope and defence.

The central principle is:

Corporate liability is a route map, not a label.

An organisation should not begin by asking whether the conduct feels attributable to “the business”. It should identify every potentially relevant legal route, test its elements separately and preserve the evidence which may support or defeat each one.

The liability map

For fraud and economic crime, four broad routes should be kept distinct.

1. The traditional identification doctrine

At common law, an offence requiring a particular mental state could historically be attributed to a company where the relevant individual represented its directing mind and will for the function in question.

The doctrine was not simply a test of seniority. The court had to examine the constitution of the company, the relevant legal rule and the authority delegated for the particular function. In a large or decentralised organisation, responsibility might be dispersed in a way which made it difficult to identify one person as the company’s directing mind and will.

The Supreme Court in R v St Regis Paper Co Ltd and the Privy Council in Meridian Global Funds Management Asia Ltd v Securities Commission illustrate why attribution depends upon the purpose and construction of the relevant offence, rather than an assumption that the most senior person automatically embodies the company for every purpose.

The identification doctrine remains relevant outside the statutory senior-manager attribution rule and where legislation or its proper construction requires it. It should not, however, be treated as the only route by which a corporate can now commit an economic crime.

2. Senior-manager attribution under the current statutory rule

Section 196 of the Economic Crime and Corporate Transparency Act 2023 introduced a statutory attribution rule for specified economic crimes. With effect from 29 June 2026, section 250 of the Crime and Policing Act 2026 replaced that provision with a materially wider rule applying to criminal offences generally.

Broadly, where a senior manager of a body corporate or partnership, acting within the actual or apparent scope of their authority, commits an offence, the organisation is also guilty of the offence.

This is direct corporate liability. The senior manager’s offending is attributed to the organisation. It is not a failure-to-prevent offence and it does not carry a reasonable-procedures defence.

3. Failure to prevent fraud under section 199 ECCTA

Section 199 creates a separate offence for large incorporated bodies and partnerships. It can apply where an associated person commits a listed fraud offence intending to benefit the relevant body or, in defined circumstances, a person to whom the associated person provides services for or on behalf of the body.

The prosecution does not need to prove that a director or senior manager ordered or knew about the fraud.

The organisation has a defence if it proves that, when the fraud was committed, it had reasonable procedures to prevent such fraud, or that it was not reasonable in all the circumstances to expect it to have prevention procedures.

4. Other statutory and accessorial routes

The same facts may engage:

  • a substantive offence drafted to apply directly to a body corporate;
  • a separate failure-to-prevent offence, such as under the Bribery Act 2010 or Criminal Finances Act 2017;
  • statutory provisions imposing liability on an officer who consented to or connived in an offence;
  • conspiracy, encouragement or assistance;
  • money-laundering offences;
  • false accounting or fraudulent trading;
  • regulatory offences; and
  • confiscation, compensation, director-disqualification or civil consequences.

The ECCTA reforms therefore add routes. They do not replace every earlier doctrine or statutory mechanism.

Route one: the identification doctrine

The traditional doctrine matters because a company has no mind or hands apart from human actors. For an offence requiring dishonesty, knowledge, intention or recklessness, the law needs a basis for treating a person’s conduct and state of mind as those of the company.

That basis is not supplied merely because:

  • the person was an employee;
  • the company benefited;
  • the misconduct occurred at work;
  • several employees collectively possessed the necessary information; or
  • the board ought to have known.

The court asks whose acts and state of mind count as those of the company for the particular legal rule.

Why the doctrine created difficulty

In a small owner-managed company, the individual who commits the offence may plainly control the relevant corporate function. In a large group, authority can be spread through committees, regions, business units and reporting lines. No one person may possess every element of the offence.

That created an uncomfortable asymmetry. A small company could be easier to prosecute precisely because decision-making was concentrated, while a large organisation could be harder to prosecute because responsibility was divided.

The ECCTA rule was designed to address part of that problem for listed economic crimes. The Crime and Policing Act 2026 retained the senior-manager model and extended it to criminal offences generally. The rule widens the attribution inquiry beyond the narrow search for the directing mind and will, but only within its statutory terms.

Aggregation is not automatic

An organisation should be cautious about both extremes.

It is wrong to assume that fragments of knowledge held by different people can always be assembled into one corporate state of mind. It is equally wrong to assume that fragmented decision-making necessarily defeats liability.

The correct approach is offence-specific:

  1. identify the conduct and mental elements;
  2. identify the legal rule of attribution;
  3. map who performed, authorised or controlled the relevant function;
  4. examine delegations, reporting lines and actual practice; and
  5. test whether the necessary elements can lawfully be attributed under that route.

Route two: senior-manager attribution

What the current statutory rule does

Section 250 of the Crime and Policing Act 2026 provides that, if a senior manager of a body corporate or partnership acting within the actual or apparent scope of their authority commits an offence, the organisation is also guilty of the offence.

The rule came into force on 29 June 2026. It replaced section 196 ECCTA, which had applied only to the economic crimes listed in Schedule 12. The current rule is not confined to fraud or economic crime.

The date of the alleged conduct remains critical. Conduct before 29 June 2026 must be analysed under the law then in force, including the former Schedule 12 limitation. Conduct on or after that date engages the wider rule. The expansion does not retrospectively convert earlier conduct outside the former schedule into an attributable offence.

Who is a senior manager?

The statutory definition focuses on role, not title.

A senior manager is an individual who plays a significant role in:

  • making decisions about how the whole or a substantial part of the organisation’s activities are to be managed or organised; or
  • actually managing or organising the whole or a substantial part of those activities.

This can include a director or executive, but the inquiry is functional. A person below board level may qualify if their real responsibilities satisfy the test. Conversely, an impressive title should not decide the issue if the individual does not perform the statutory role.

Relevant evidence may include:

  • constitutional documents and reserved matters;
  • board and committee terms of reference;
  • job descriptions;
  • delegated-authority matrices;
  • management accounts and budgetary responsibility;
  • reporting lines;
  • operational control over a division, territory or product;
  • authority to set policy or approve exceptions;
  • responsibility for hiring, remuneration or discipline;
  • evidence of how decisions were actually made; and
  • communications showing whether others treated the person as authorised.

What is a substantial part?

The statute does not reduce “substantial part” to a fixed percentage of turnover, headcount or assets.

A business unit may be substantial because of its scale, risk, strategic importance, regulated status or degree of autonomy. A small function might also be critical if it controls pricing, financial reporting, market disclosures, sanctions compliance or another activity central to the alleged offence.

The question is fact-sensitive. Organisations should avoid assuming that only group-level executives can qualify.

Actual or apparent scope of authority

The senior manager must commit the offence while acting within the actual or apparent scope of their authority.

Actual authority may be express or arise from the role and responsibilities genuinely conferred. Apparent authority concerns how the organisation has represented the individual’s authority to others.

The words do important limiting work. A senior manager’s wholly private offending is not attributed merely because of status. But an organisation cannot necessarily escape liability by showing that the criminal method was prohibited. A manager may be authorised to pursue a corporate objective, negotiate a transaction, approve revenue or communicate with a counterparty even though dishonesty was never authorised.

The analysis should separate:

  • the field of activity entrusted to the manager;
  • the decision or representation they were authorised, or appeared authorised, to make;
  • the dishonest or criminal means used;
  • the intended beneficiary; and
  • any personal departure from corporate business.

A policy saying “do not commit fraud” does not determine whether the person acted within the scope of authority when performing an authorised corporate function.

The individual offence still matters

The statutory rule does not create guilt without an underlying offence. The prosecution must prove that the senior manager committed the offence, including its required conduct and mental elements.

That requires disciplined attention to:

  • the exact representation, omission, accounting entry or transaction;
  • who made or authorised it;
  • what the individual knew or believed;
  • whether they were dishonest under the applicable test;
  • any intention to make a gain, cause loss or expose another to risk;
  • causation or jurisdictional requirements where relevant; and
  • available defences.

Corporate attribution should not be used to obscure weaknesses in the case against the alleged human offender.

No reasonable-procedures defence

Unlike section 199, the senior-manager attribution rule does not provide a defence based upon reasonable prevention procedures.

Strong compliance may still matter. It may:

  • make it less likely that the offence can be proved;
  • rebut an inference about authority, knowledge or dishonesty;
  • identify a genuinely personal departure;
  • affect charging and public-interest decisions;
  • demonstrate cooperation and remediation; and
  • reduce sentence.

It does not operate as a complete statutory defence to direct liability once the attribution elements are established.

Route three: failure to prevent fraud

The full framework is addressed in Failure to Prevent Fraud: A Strategic Guide for Organisations and Senior Leaders. For liability-mapping purposes, six distinctions are essential.

1. It applies only to large organisations

The offence applies to incorporated bodies and partnerships meeting at least two of the following conditions in the relevant preceding financial year:

  • more than 250 employees;
  • more than £36 million turnover; and
  • more than £18 million total assets.

The detailed group and subsidiary rules in sections 201 and 202 must be applied. A subsidiary which is not itself large can, in the circumstances specified by section 199(2), be liable where its employee commits fraud intending to benefit it and its parent undertaking is a relevant body.

2. It begins with a base fraud

The associated person must commit a fraud offence within Schedule 13, or aid, abet, counsel or procure such an offence.

For England and Wales, the list includes relevant Fraud Act 2006 offences, participation in a fraudulent business, obtaining services dishonestly, cheating the public revenue, false accounting, false statements by company directors and fraudulent trading.

The individual need not be separately prosecuted. Where there is no conviction, however, the prosecution must still prove in the corporate proceedings that the base fraud was committed.

3. The person must be associated

Employees, agents and subsidiary undertakings are expressly included. A person is also associated while providing services for or on behalf of the relevant body, judged by all the relevant circumstances.

The distinction between providing services for or on behalf of an organisation and providing services to it is critical.

An external adviser, supplier or contractor is not automatically associated merely because the organisation buys services from them. The issue is the function being performed and the capacity in which the person acted when committing the fraud.

Contract labels are relevant but not conclusive. Evidence should address:

  • what service was performed;
  • for whose benefit and on whose behalf;
  • who controlled or supervised it;
  • how the person was presented to customers or counterparties;
  • whether they could bind or represent the organisation;
  • the commercial allocation of responsibility; and
  • the capacity in which the alleged fraud occurred.

4. The fraud must carry the required intended benefit

The associated person must intend to benefit:

  • the relevant body; or
  • a person to whom the associated person provides services for or on behalf of the relevant body.

Actual benefit is unnecessary. The benefit need not be the sole or dominant motivation. A person may act partly for personal commission, bonus or advancement while also intending the company to gain sales, revenue, a contract, a market advantage or avoidance of loss.

The benefit can be indirect or non-financial. What matters is the associated person’s intention when committing the fraud.

This should not be confused with motive. Nor should an adverse eventual outcome be used to erase the intention that existed at the time.

5. Victim status has a defined role

Where the intended benefit is for a client or other service recipient, section 199 contains an exception if the relevant body was itself a victim or intended victim of the fraud.

That does not mean any organisation which loses money or reputation is automatically outside the offence. The inquiry is whether the loss caused or intended by the fraud was to be borne by the organisation, or the fraud was intended to harm it.

The liability analysis should distinguish:

  • direct intended harm to the organisation;
  • incidental or consequential harm after discovery;
  • a fraud intended only to benefit the individual;
  • a fraud intended to benefit the organisation;
  • a fraud intended to benefit a client; and
  • mixed intentions.

6. Reasonable procedures are a defence the organisation proves

The prosecution must prove the offence’s constituent elements. If those elements are established, the organisation bears the burden of proving the statutory defence on the balance of probabilities.

The defence concerns procedures which operated at the time of the fraud, not a policy reconstructed after discovery.

Relevant evidence may include:

  • a current and properly scoped risk assessment;
  • top-level governance and allocation of responsibility;
  • proportionate controls tied to identified risks;
  • due diligence on relevant associated persons;
  • communication and training;
  • monitoring, testing and review;
  • escalation and whistleblowing evidence;
  • action taken when controls were bypassed;
  • documented reasons for accepted residual risk; and
  • reliable records demonstrating operation in practice.

The central doctrine from Guide 2 remains:

The defence is not the policy. The defence is the system the organisation can prove operated in practice.

Senior manager and associated person are not synonyms

The distinction is fundamental.

QuestionSenior-manager attributionSection 199 failure to prevent fraud
Nature of liabilityDirect attribution of the offenceSeparate failure-to-prevent offence
Relevant individualSenior managerAssociated person
Organisation sizeNot confined to large organisationsLarge organisations, subject to statutory group rules
Underlying offencesCriminal offences generally from 29 June 2026; former Schedule 12 limitation applies to earlier conduct under section 196Schedule 13 fraud offences
Scope requirementActual or apparent scope of authorityActing in the capacity of an associated person
Intended corporate benefitDepends on elements of underlying offence, not a separate universal attribution requirementRequired statutory element, including specified client-benefit cases
Senior knowledgeOffending senior manager supplies the attributed conduct and mental stateNo need to prove director or senior-manager knowledge
Reasonable-procedures defenceNoYes

A person can be both a senior manager and an associated person. If so, the facts may engage both routes. That does not permit the elements of one to fill gaps in the other.

For example, a divisional director who dishonestly inflates revenue may be:

  • an individual suspect in false accounting or fraud;
  • a senior manager whose offence may be attributed under the statutory rule;
  • an employee and therefore an associated person for section 199; and
  • a person whose conduct exposes other directors or officers to separate scrutiny.

The prosecution must still prove whichever charge is brought. The organisation must analyse each route independently.

The entity question comes before the blame question

Corporate groups often speak commercially as one enterprise. Criminal liability generally attaches to legal persons.

An investigation should identify:

  • which entity employed the individual;
  • which entity contracted with the customer;
  • which entity issued the representation or accounts;
  • which entity received or was intended to receive the benefit;
  • which entity provided services to a client;
  • which entity controlled the relevant process;
  • whether a subsidiary acted for or on behalf of a parent;
  • where decisions and acts occurred;
  • which entity held the relevant policies and records; and
  • which entity qualifies as large for section 199.

Group branding, shared systems and matrix reporting can obscure those answers.

Parent and subsidiary exposure

A parent is not automatically criminally liable for every fraud within a subsidiary. Equally, formal separation does not end the inquiry.

Potential routes include:

  • direct attribution to a parent through its own senior manager;
  • direct liability of the subsidiary through its senior manager;
  • section 199 liability of a large parent where a subsidiary undertaking commits a base fraud intending to benefit the parent;
  • section 199 liability where an employee of a subsidiary commits fraud intending to benefit the parent;
  • liability of a subsidiary under the specific section 199(2) extension;
  • accessorial liability based on participation by individuals in another entity; and
  • separate regulatory or civil responsibility.

The intended beneficiary, the service relationship and the precise actor must be mapped, not inferred from a group chart.

Joint ventures, franchises and supply chains

Commercial connection is not enough.

A joint-venture partner, franchisee, distributor, supplier or subcontractor may be an associated person only when the statutory services test is met in the relevant circumstances. The relationship may change by activity. A contractor might provide one service to the organisation and another for or on its behalf.

Risk assessment and contracts should therefore focus on functions, not labels.

Corporate liability and individual liability must be separated

An allegation against an organisation can create immediate tension between corporate and personal interests.

The corporate does not absorb the individual case

The statutory attribution rule makes the organisation guilty where its conditions are satisfied. It does not replace the senior manager’s own liability.

Section 199 does not impose personal liability merely because a director or compliance officer failed to prevent fraud. The person who committed, encouraged or assisted the base fraud may still be prosecuted, and other statutory provisions may apply to officers who consented to or connived in offending.

The investigation should avoid language such as “the company did it” until it can identify:

  • the human conduct;
  • the human mental state;
  • the attribution or failure-to-prevent route;
  • the relevant entity; and
  • any separate individual participation.

Conflicts can arise early

The organisation’s interest may be to demonstrate that a senior manager acted outside authority, concealed misconduct or defeated effective controls. The manager’s interest may be to show that the conduct was authorised, culturally accepted or based on information supplied by others.

Likewise, a company relying on reasonable procedures may need to show that an associated person bypassed them. The individual may argue that the control environment rewarded or tolerated the conduct.

Separate representation should be considered where interests may diverge. A single internal narrative should not be engineered to serve several parties whose legal positions are different.

Fair interviews improve evidence

Individuals should understand:

  • who the investigators act for;
  • the purpose and status of the interview;
  • how the account will be recorded and used;
  • whether confidentiality can be promised;
  • whether legal representation is appropriate;
  • any relevant employment duties; and
  • that the organisation’s lawyers do not automatically act for them.

The detailed process is addressed in Internal Investigations: Privilege, Interviews and Evidence Contamination. The governing principle is to protect independent first accounts rather than manufacture agreement.

The evidence prosecutors and organisations will reconstruct

Corporate exposure is often proved through an accumulation of ordinary business records.

Authority evidence

For senior-manager attribution:

  • delegation documents;
  • role descriptions;
  • committee minutes;
  • approval limits;
  • actual decision patterns;
  • representations to third parties;
  • reporting structures;
  • budgets and performance ownership; and
  • evidence of tolerated departures from formal limits.

Association evidence

For section 199:

  • employment and agency records;
  • contracts and statements of work;
  • outsourcing models;
  • customer-facing descriptions;
  • instructions and supervision;
  • invoicing and remuneration structures;
  • the service actually performed; and
  • the capacity in which the person acted.

Benefit evidence

This may include:

  • bonus and commission plans;
  • revenue targets;
  • forecasts;
  • tender objectives;
  • cost or loss-avoidance pressures;
  • management commentary;
  • internal approval papers;
  • treatment of revenue or liabilities;
  • client-service arrangements; and
  • communications revealing expected gain.

Mental-state evidence

Dishonesty and intention are rarely proved by one document. Investigators may examine:

  • what the person knew at each stage;
  • warnings received;
  • false explanations;
  • concealment;
  • deletion or alteration;
  • private and ephemeral communications;
  • repeated exceptions;
  • personal rewards;
  • inconsistent accounts; and
  • attempts to influence witnesses or records.

Control evidence

For the section 199 defence:

  • the risk assessment in force at the time;
  • ownership and governance;
  • training completion and comprehension;
  • control testing;
  • exception reports;
  • investigation history;
  • action following earlier warnings;
  • due diligence;
  • incentives and disciplinary outcomes; and
  • evidence that the control worked in comparable cases.

The investigation must preserve material pointing away from liability as carefully as material pointing towards it. Exculpatory and qualifying evidence can disappear when the response is built around a premature theory.

AI makes attribution harder, not irrelevant

AI can generate text, images, analysis, recommendations and transactions. It does not remove the need to identify the human and corporate route to liability.

An investigation should ask:

  • who selected or authorised the system;
  • who entered the prompt or instruction;
  • what data and retrieval sources were used;
  • what the system produced;
  • who reviewed, altered or adopted the output;
  • what decision followed;
  • who had authority for that decision;
  • whether warnings or uncertainty were visible;
  • whether the output was fabricated, mistaken or manipulated; and
  • who intended to gain.

The statement “AI did it” may conceal several different possibilities:

  • a person used AI deliberately to commit fraud;
  • a person knowingly adopted a false output;
  • a person was reckless or negligent but not dishonest;
  • the system failed without human dishonesty;
  • an outsider compromised the system;
  • records were fabricated after the event; or
  • the output was accurate but the surrounding account is false.

Only some of those possibilities amount to fraud.

Preserve the decision chain

The final output is rarely enough. Preserve:

  • prompts and system instructions;
  • outputs and alternative versions;
  • model, account and configuration data;
  • retrieved sources;
  • access and authentication logs;
  • human edits;
  • approval records;
  • communications;
  • transaction data; and
  • the preservation process.

As Guide 4 explains:

Preserve the generation trail, not merely the final output.

The objective is to prove who did what, with what authority and state of mind, for whose intended benefit, and through which entity.

A disciplined response protocol

Phase 1: define the suspected event

Record:

  • what is known;
  • what is alleged;
  • the source of the concern;
  • what remains inference;
  • continuing harm;
  • affected transactions and systems; and
  • immediate reporting or preservation duties.

Do not assign corporate or individual guilt at this stage.

Phase 2: map the people and entities

Identify every relevant:

  • legal entity;
  • senior manager;
  • employee, agent, subsidiary or service provider;
  • customer or service recipient;
  • intended beneficiary;
  • victim or intended victim;
  • decision-maker; and
  • potentially conflicted person.

Phase 3: test each liability route

For each potential offence, create a separate elements table:

  1. the substantive offence;
  2. the alleged actor;
  3. the required conduct;
  4. the required mental state;
  5. the relevant attribution or failure-to-prevent rule;
  6. authority or association;
  7. intended benefit where required;
  8. jurisdiction;
  9. defence; and
  10. supporting and contradictory evidence.

This prevents the strength of one route from disguising a gap in another.

Phase 4: preserve before interviewing

Secure volatile and third-party evidence before alerting potentially implicated people where lawful and proportionate.

Keep a decision log. Preserve native material and metadata. Suspend routine deletion where necessary. Protect privileged legal advice without treating pre-existing records as privileged merely because lawyers collect them.

Phase 5: investigate independent accounts

Interview in an order designed to preserve knowledge and avoid contamination. Identify the client. Give clear warnings. Test documents fairly. Record changes in recollection and the material shown.

Phase 6: make route-specific decisions

The board or authorised committee should receive advice distinguishing:

  • individual exposure;
  • direct corporate exposure;
  • failure-to-prevent exposure;
  • regulatory and civil exposure;
  • available defences;
  • reporting decisions;
  • remediation; and
  • unresolved evidential issues.

A conclusion that section 199 is not engaged does not answer senior-manager attribution. A reasonable-procedures defence does not resolve direct attribution. A corporate exposure assessment does not establish an individual’s guilt.

Questions boards should ask

  1. Which legal entity is exposed under each possible route?
  2. What is the precise underlying offence?
  3. Who is alleged to have committed it?
  4. Is that person arguably a senior manager, an associated person, or both?
  5. What evidence establishes their real function and authority?
  6. In what capacity were they acting?
  7. Who was intended to benefit?
  8. Is the organisation truly a victim, or did it suffer only consequential harm after discovery?
  9. Does senior-manager attribution, section 199, another statute or the identification doctrine apply?
  10. What evidence supports and contradicts each element?
  11. Can the organisation prove that its prevention procedures operated at the time?
  12. Have conflicts between the organisation and individuals been recognised?
  13. Have AI, platform and third-party records been preserved?
  14. Are reporting, disclosure, privilege and cooperation decisions being made separately?
  15. Can the board explain why its present conclusion is provisional or final?

Common analytical failures

Treating every senior employee as a senior manager

The statutory test is functional. Title, salary or prestige alone does not establish a significant role in deciding or managing the whole or a substantial part of the organisation’s activities.

Treating prohibition as absence of authority

A person may commit an offence while carrying out an authorised corporate function. The fact that dishonest methods were forbidden does not by itself answer the actual-or-apparent-authority question.

Assuming benefit proves attribution

A corporate benefit may be relevant evidence, but it does not itself prove that a senior manager committed an offence within the statutory attribution rule. Each element remains necessary.

Assuming loss makes the company a victim

Reputational damage, repayment and enforcement consequences may follow a fraud intended to benefit the organisation. Later loss does not automatically negate the original intended benefit.

Calling every supplier an associated person

Providing services to an organisation is not the same as providing services for or on its behalf. The function and capacity must be analysed.

Merging a group into one accused

Commercial unity does not erase legal personality. Employment, contracting, benefit, control and conduct must be assigned to the correct entities.

Using the reasonable-procedures defence against every charge

The defence belongs to section 199. It is not a universal defence to direct corporate criminal liability.

Investigating only the incriminating theory

An inquiry that fails to preserve alternative explanations may destroy the evidence needed to distinguish fraud, control failure, mistake, system error and individual misconduct.

Frequently asked questions

What changed with the senior-manager test?

Section 250 of the Crime and Policing Act 2026 allows an offence committed by a senior manager acting within the actual or apparent scope of their authority to be attributed to the organisation. It replaced the narrower ECCTA provision on 29 June 2026 and applies to criminal offences generally. Its statutory elements must still be proved.

Is every director a senior manager?

Not automatically, although many directors will satisfy the functional test. The court will examine the individual’s real role in making decisions about, or managing or organising, the whole or a substantial part of the organisation’s activities.

Can someone below board level be a senior manager?

Yes. A divisional, regional or functional leader may qualify if their actual role is sufficiently significant. Job title is evidence, not the statutory test.

Does acting against policy mean the manager acted outside authority?

Not necessarily. The analysis concerns the actual or apparent scope of authority, not whether fraud was permitted. A manager may use dishonest means while performing a function they were authorised to perform.

Is an associated person the same as a senior manager?

No. Employees, agents, subsidiary undertakings and others providing services for or on behalf of a body can be associated persons. Senior manager is a separate functional category used by the attribution rule.

Must the company actually receive a benefit for section 199?

No. The associated person must have the required intention to benefit the organisation or the specified service recipient. The intended benefit need not materialise and need not be the person’s sole or dominant motivation.

Can a company be both victim and defendant?

Potentially, but the analysis is route and fact specific. For the client-benefit limb of section 199, the statutory victim exception may apply where the organisation was itself a victim or intended victim. Consequential loss or reputational damage alone does not necessarily establish that status.

Do good procedures provide a defence to senior-manager attribution?

No. Good compliance may undermine the underlying allegation and affect charging or sentence, but there is no equivalent to the statutory reasonable-procedures defence available under section 199.

Can both the company and the individual be prosecuted?

Yes. Corporate attribution does not extinguish the individual offence. Section 199 also sits alongside liability of the person who committed, encouraged or assisted the base fraud.

Conclusion

Corporate criminal liability now requires more precision, not less.

The organisation must identify the human act, mental state, function, authority, association, intended beneficiary and relevant legal entity. It must then test each statutory and common-law route on its own terms.

The current attribution rule asks whether a senior manager committed an offence while acting within the actual or apparent scope of authority. Section 199 asks whether an associated person committed a qualifying fraud with the required intended benefit and, if so, whether the organisation can prove reasonable prevention procedures. The traditional identification doctrine and other statutory routes may still matter.

Those questions cannot safely be answered by corporate instinct, group branding or a broad assertion that the person was a rogue.

Map the route. Preserve the evidence. Separate the parties. Test the elements.

Corporate liability is a route map, not a label.

Corporate liability is a route map, not a label.

Craig MacKenzie provides strategic advice through Forbes Solicitors to organisations and senior leaders on corporate criminal liability, fraud investigations, individual and organisational exposure, evidence preservation and engagement with investigators or regulators.

Request a confidential consultation

Do You Require Advice About Your Circumstances?

This material provides general information and is not a substitute for advice about a specific investigation or case.

Craig provides legal services exclusively through Forbes Solicitors. To make an initial enquiry, contact Craig at:

craig.mackenzie@forbessolicitors.co.uk

07976 258 258

An enquiry does not constitute an instruction. Forbes Solicitors must confirm in writing that it has accepted the matter before any solicitor–client relationship arises.

Related Guidance