Financial Crime · Strategic Guide
Failure to Prevent Fraud: A Strategic Guide for Organisations and Senior Leaders
The failure to prevent fraud offence is not simply another compliance obligation. It changes the questions that investigators, prosecutors and boards will ask when fraud is committed for an organisation's benefit. Craig MacKenzie explains who is exposed, how liability arises, what reasonable procedures require in practice, and why the quality of the organisation's decisions may matter as much as the existence of its policies.
- Author
- Craig MacKenzie
- Role
- Partner and Solicitor Advocate
- Published
- 27 July 2026
- Reading time
- 27 minutes
The offence is a governance test
When fraud is discovered inside or around an organisation, the first instinct is often to ask who committed it.
The Economic Crime and Corporate Transparency Act 2023 adds a second question:
What did the organisation do, before the event, to prevent an associated person committing that fraud for its benefit?
That question reaches beyond the individual wrongdoer. A large organisation may commit a criminal offence where an employee, agent, subsidiary undertaking or another person providing services for or on its behalf commits a specified fraud intending to benefit the organisation or, in some circumstances, its client.
There is no need to prove that the board authorised the fraud. There is no need to show that a director knew about it. The individual who committed the underlying fraud need not even be prosecuted.
The organisation’s protection is the statutory defence that, when the fraud was committed, it had reasonable procedures in place to prevent fraud of that kind, or that it was not reasonable in all the circumstances to expect any such procedures.
This makes the offence a practical test of governance. Policies matter, but only as part of the evidence. The real questions are whether the organisation understood the routes by which fraud might be committed for its benefit, allocated responsibility, designed controls around those risks, communicated them, tested them and responded when warning signs appeared.
The defence is not the policy. The defence is the system the organisation can prove operated in practice.
This guide explains the legal framework and the strategic work required of boards, general counsel, compliance leaders and those responsible for fraud prevention.
The legal framework
The corporate offence is contained in sections 199 to 206 of the Economic Crime and Corporate Transparency Act 2023. It came into force on 1 September 2025.
In broad terms, an organisation is guilty where:
- it is a relevant body within the statutory scope;
- a person associated with it commits a listed fraud offence;
- the associated person acts in that capacity;
- the fraud is intended to benefit the organisation or a person to whom the associated person provides services for or on its behalf; and
- the organisation cannot establish the reasonable procedures defence.
Each element requires careful analysis. The offence is deliberately wider than traditional routes to corporate criminal liability because it does not depend upon attributing the conduct and state of mind of a directing mind or senior manager to the organisation.
The underlying fraud still has to be proved. If the associated person has not been convicted, the prosecution must establish to the criminal standard that the person committed a relevant base fraud offence. The new offence does not remove the need to prove dishonesty or the other elements of that underlying offence.
What it removes is the need to prove that those controlling the organisation participated in or knew about it.
Which organisations are in scope?
The offence applies to large incorporated bodies and partnerships across all sectors. It can include companies, limited liability partnerships, ordinary partnerships, bodies incorporated by statute, NHS trusts, some incorporated charities and overseas organisations where the required UK nexus exists.
An organisation is large if, in the financial year preceding the year of the base fraud, it satisfies at least two of the following three conditions:
| Criterion | Statutory threshold |
|---|---|
| Employees | More than 250 |
| Turnover | More than £36 million |
| Total assets | More than £18 million |
For a parent undertaking, the figures are aggregated across the organisation and its subsidiary undertakings, including those outside the United Kingdom. The calculation can therefore bring a UK entity or group within scope even where the relevant operating subsidiary is much smaller.
Organisations close to a threshold should not rely on an informal impression of size. The relevant accounting period, group structure and statutory calculation should be identified and recorded.
Smaller organisations should not disregard the legislation. A smaller company may itself be an associated person of a large organisation when it performs services for or on the large organisation’s behalf. It may consequently face contractual controls, audit rights, training requirements and information obligations imposed by clients seeking to protect their own position.
Some smaller subsidiaries may also be exposed in their own right under the specific subsidiary provisions.
What frauds are covered?
The underlying or base offences are listed in Schedule 13 to the Act. For England and Wales they include:
- fraud by false representation;
- fraud by failing to disclose information;
- fraud by abuse of position;
- participation in a fraudulent business;
- obtaining services dishonestly;
- cheating the public revenue;
- false accounting;
- false statements by company directors; and
- fraudulent trading.
Aiding, abetting, counselling or procuring a listed offence is also covered.
This is not limited to the theft of money from an organisation. The offence is principally concerned with fraud committed for its benefit or for the benefit of certain clients. Relevant conduct may include:
- misleading customers to increase sales;
- concealing material facts during a tender;
- falsifying performance, quality or compliance data;
- manipulating accounts or revenue recognition;
- making dishonest statements to an insurer, lender or investor;
- supplying false information in support of a grant;
- dishonestly avoiding tax or public charges;
- disguising failures against environmental or regulatory standards;
- creating false records to meet contractual targets;
- concealing defects to secure payment or preserve a commercial relationship; or
- using synthetic documents, generated content or manipulated data to support a dishonest representation.
The legal label is less important at the risk-assessment stage than the dishonest pathway. Boards should ask where someone could make, withhold, alter or manufacture information in order to confer a commercial benefit.
Who is an associated person?
An associated person includes:
- an employee;
- an agent;
- a subsidiary undertaking; and
- any other person who performs services for or on behalf of the organisation.
Whether someone performs services for or on behalf of the organisation is determined by all the circumstances, not simply by the contractual description of the relationship.
This can extend beyond payroll. Depending on what they actually do, distributors, intermediaries, consultants, outsourced providers, contractors, service companies and other third parties may be associated persons.
There is, however, an important limit. A person who merely supplies goods or services to the organisation is not automatically providing services for or on behalf of it. External lawyers, accountants, engineers or valuers advising the organisation will not ordinarily become associated persons merely because they provide professional services to it. The analysis changes if they also perform a service externally for or on the organisation’s behalf.
The practical question is functional:
Whose business is this person carrying out, in what capacity, and for whose benefit?
A contract which says that a counterparty is an independent contractor will not decide the criminal law issue. Equally, a remote connection in a supply chain does not automatically create association. The work performed, the degree of control, the representations made to others and the commercial reality all matter.
Organisations should therefore map associated persons by activity, not simply generate a list of legal entities.
The fraud must be committed in the associated capacity
The base fraud must be committed while the person acts in their capacity as an associated person.
An employee’s private dishonesty, unrelated to their employment, does not engage the organisation’s liability merely because the individual happens to work there. The same is true of an agent acting for another principal.
The difficult cases will involve mixed purposes or disputed boundaries. An employee may act outside authority but still in the course of pursuing a business objective. An agent may breach express instructions while seeking to secure a contract. A service provider may use methods the organisation prohibited but from which it was intended to benefit.
Lack of authority is relevant, but it is not necessarily an answer. The statutory focus is on capacity, intended benefit and prevention, not simply whether the fraudster complied with internal rules.
What does “intending to benefit” mean?
The associated person must intend to benefit:
- the relevant organisation;
- a person to whom the associated person provides services for or on behalf of the organisation; or
- in defined circumstances, that person’s subsidiary undertaking.
No benefit needs to be received. The offence can be complete where the intended advantage never materialises.
The benefit need not be financial. Securing a contract, protecting market position, disadvantaging a competitor, avoiding a regulatory consequence or preserving a licence may be sufficient.
Nor must benefit to the organisation be the fraudster’s sole or dominant purpose. A salesperson may mis-sell principally to earn commission while also intending to increase company revenue. An executive may manipulate results to protect a bonus while intending to improve the organisation’s reported position. Mixed personal and corporate motives do not place the conduct outside the offence.
There is no statutory minimum benefit. Materiality may influence investigative and public-interest decisions, but it is not a threshold element of liability.
This makes incentive design central to prevention. Remuneration, promotion criteria, sales targets, delivery deadlines and management pressure may create the link between personal gain and organisational benefit.
The most dangerous fraud risk may sit where an individual’s reward depends upon producing the result the organisation wants.
What if the organisation is also a victim?
An organisation is not liable under section 199(1)(b) where it is itself the victim or intended victim of a fraud intended to benefit a client.
That does not mean that any loss or reputational harm makes the organisation a victim for all purposes. The statutory guidance distinguishes a loss which the fraud was intended to cause the organisation from indirect consequences flowing from discovery, such as reputational damage, regulatory scrutiny or the cost of remediation.
An organisation may occupy more than one position at the same time. It may be deceived by an employee about the methods being used, benefit from the resulting business, suffer collateral loss when the conduct is exposed and hold critical evidence about what occurred.
The correct analysis should therefore separate:
- the intended object of the deception;
- the intended recipient of the benefit;
- the person expected to bear the immediate loss;
- the organisation’s knowledge;
- the organisation’s later losses; and
- any client for whose benefit services were being performed.
Describing the organisation as “the victim” too early can obscure a more difficult intended-benefit analysis.
Territorial reach
The offence applies across the United Kingdom and can reach overseas organisations and conduct where there is a sufficient UK nexus.
In broad terms, that nexus may exist where an act forming part of the underlying fraud takes place in the United Kingdom, or where gain or loss occurs here. A UK employee’s fraud may expose an overseas organisation. An overseas associated person who targets UK victims may also bring an overseas organisation within scope.
Conversely, an overseas fraud by an overseas associated person of a UK organisation will not ordinarily engage the offence where no relevant act, gain or loss occurs in the United Kingdom.
Cross-border organisations should not reduce territorial analysis to the location of incorporation. They should map:
- where representations are made and received;
- where relevant decisions are taken;
- where systems and data are hosted or accessed;
- where contractual performance occurs;
- where the intended or actual gain arises; and
- where the victim suffers loss.
The reasonable procedures defence
It is a defence for the organisation to prove that, at the time of the fraud:
- it had reasonable prevention procedures in place; or
- it was not reasonable in all the circumstances to expect it to have any prevention procedures.
The organisation bears the legal burden of establishing the defence on the balance of probabilities.
That allocation matters. If a prosecution proves the underlying fraud, association, capacity and intended benefit, the organisation cannot simply require the prosecution to disprove the adequacy of its controls. It must produce evidence capable of showing that its procedures were reasonable in the circumstances then existing.
The Home Office statutory guidance is organised around six principles:
- top-level commitment;
- risk assessment;
- proportionate risk-based prevention procedures;
- due diligence;
- communication, including training; and
- monitoring and review.
The guidance is important but does not provide a safe harbour. Following its examples will not automatically establish the defence if the organisation ignored a specific risk in its own operations. Departure from the guidance is not automatically fatal where a different, reasonable approach can be justified.
Ultimately, the court will determine reasonableness against the facts of the particular fraud.
What “reasonable” should mean in practice
Reasonable does not mean perfect. The occurrence of fraud does not, by itself, prove that the controls were unreasonable. Even a strong system can be defeated.
Equally, a comprehensive policy suite does not prove that a reasonable system existed. A policy may be generic, poorly communicated, contradicted by incentives, ignored by managers or incapable of operating under commercial pressure.
The likely examination is chronological:
- What risk should the organisation have identified?
- What information was available when the risk assessment was made?
- Who owned the risk?
- What procedures were selected?
- Why were they considered proportionate?
- Were they resourced and implemented?
- Did the relevant people understand them?
- Were they followed in practice?
- What warnings, exceptions or near misses occurred?
- What did management do about them?
- Was the framework tested?
- Had it remained current when the fraud occurred?
The quality of contemporaneous decision-making will be crucial. A later explanation drafted after the event is weaker than a record showing that the risk was identified, debated and addressed before the fraud.
Reasonableness is not judged in the abstract. It is reconstructed from the decisions the organisation made when it still had the opportunity to prevent the conduct.
Principle 1: top-level commitment
Fraud prevention is a board and senior-management responsibility, even where day-to-day implementation is delegated.
The board should set a position which rejects business obtained or preserved through fraud, including where rejection causes short-term loss, delay or missed opportunity. That position must be reflected in decisions, not merely values statements.
Evidence of top-level commitment may include:
- defined board or committee oversight;
- a named executive owner;
- direct access for the compliance or ethics lead to the board or chief executive;
- sufficient long-term staffing, technology and training resources;
- regular, decision-focused management information;
- recorded challenge of high-risk incentives and practices;
- clear escalation and investigation authority;
- protection of independent reporting routes;
- consequences for breaches, applied regardless of seniority or commercial value; and
- continuity arrangements when key personnel leave or are absent.
Minutes should record more than that a policy was “noted”. They should show the issue presented, challenge offered, decision made, rationale, owner and deadline.
The board need not operate every control. It must be able to demonstrate that it understood the material fraud risks and exercised meaningful oversight of the response.
Principle 2: a dynamic risk assessment
The risk assessment is the foundation of the defence. It should identify how associated persons could commit relevant frauds while acting in that capacity and intending to benefit the organisation or its clients.
Many existing fraud assessments concentrate on fraud against the organisation: theft, false invoices, cyber-enabled diversion or dishonest expense claims. Those remain important, but they do not answer the statutory question.
The assessment must also examine fraud for the organisation:
- mis-selling to increase revenue;
- false submissions to win tenders;
- concealed defects to avoid delay or liability;
- manipulated environmental, safety or quality records;
- inflated performance data;
- dishonest grant or tax claims;
- fabricated due-diligence records;
- false customer or investor communications;
- improper revenue recognition;
- use of AI to create misleading records or representations; and
- third-party conduct which benefits the organisation while distancing it from the method.
A useful assessment should connect five things:
| Element | Question |
|---|---|
| Associated person | Who could act for or on behalf of the organisation? |
| Base fraud | What dishonest act or omission could they commit? |
| Intended benefit | How could the organisation or its client gain? |
| Pressure and opportunity | What incentives, access or weak controls could enable it? |
| Prevention | Which control reduces that specific route to fraud? |
Risk owners should consider opportunity, motive and rationalisation. They should draw on audit findings, complaints, investigations, data analysis, whistleblowing, disciplinary cases, regulator action, sector experience and near misses.
The assessment must be dynamic. Scheduled review is necessary, but event-driven review may matter more. Triggers may include:
- a new product, market or business model;
- entry into a new jurisdiction;
- acquisition or restructuring;
- a major tender or capital-raising exercise;
- severe financial pressure;
- changed commission or bonus arrangements;
- rapid staff turnover;
- new agents, distributors or outsourced functions;
- the introduction of generative AI or automated decision systems;
- regulatory change;
- a control failure, allegation or near miss; or
- evidence that employees are bypassing a procedure.
It will rarely be reasonable to have conducted no risk assessment. A decision not to introduce a control for a particular risk should be reasoned, authorised, documented and reviewed.
Principle 3: proportionate, risk-based procedures
The organisation should translate each material risk into clear, practical and enforceable procedures.
Proportionality does not mean doing the minimum. It means matching the nature and intensity of the control to:
- likelihood and potential impact;
- the organisation’s size and complexity;
- the seniority and autonomy of the associated person;
- the degree of control and supervision available;
- the value and urgency of the activity;
- the vulnerability of affected clients or victims;
- regulatory consequences;
- geographic reach;
- the reliability of existing controls; and
- the speed at which misconduct could cause irreversible harm.
Controls may include:
- segregation of duties;
- independent verification of representations;
- approval thresholds;
- reconciliation and exception reporting;
- conflict declarations;
- restrictions on system or data access;
- mandatory records of key decisions;
- controls over document generation and alteration;
- review of sales scripts and claims;
- tender and certification sign-off;
- human verification of AI-assisted output;
- dual-channel authentication for material payment or instruction changes;
- contractual obligations and audit rights;
- escalation routes;
- remuneration and clawback provisions;
- disciplinary consequences; and
- investigation and response protocols.
Controls must work during the conditions in which fraud is most likely: at year end, under a demanding target, during a crisis, when a major client threatens to leave or when senior management wants a rapid result.
A control which routinely yields to urgency may exist on paper but fail the practical test.
Principle 4: due diligence directed at the identified risk
Existing anti-money laundering, sanctions, procurement or onboarding checks may contribute to the framework. They should not simply be relabelled.
Due diligence must address the fraud risk created by the person’s actual role. Depending on that role, relevant steps may include:
- verifying identity, ownership and trading history;
- checking professional or regulated status;
- assessing previous criminal, regulatory or civil issues;
- understanding business model and remuneration;
- identifying conflicts and dependencies;
- testing whether the person uses sub-agents;
- reviewing competence and resources;
- examining their fraud-prevention arrangements;
- including appropriate contractual standards, information rights and termination provisions;
- applying enhanced review to higher-risk relationships; and
- monitoring conduct throughout the relationship rather than only at onboarding.
Merger and acquisition work should examine the target’s exposure, past allegations, controls, incentives and associated-person relationships. Post-acquisition integration should not be left indefinitely. A newly acquired business can introduce risks which the parent’s policy was never designed to manage.
Due diligence should also be refreshed where circumstances change. An agent operating in a stable market may present a different risk when asked to secure an urgent public contract in a new jurisdiction.
Principle 5: communication, training and speaking up
The organisation should ensure that relevant people understand:
- the frauds they could commit in their roles;
- how personal incentives may align with organisational benefit;
- the controls that apply;
- what they must not do;
- how to seek advice;
- how to report concern;
- what happens after a report; and
- the consequences of breach.
Generic annual training may be inadequate for high-risk teams. Sales, finance, procurement, bid, marketing, claims, operations and senior-management roles may require scenario-based training built around the decisions they actually face.
Completion data alone is weak evidence of effectiveness. Better evidence may include:
- role-specific content;
- assessment results;
- targeted follow-up;
- records of questions and advice;
- observed changes in behaviour;
- testing through realistic scenarios;
- training for relevant agents and service providers; and
- updates after incidents or changes in risk.
Middle management is critical. A board message that fraud is unacceptable will be undermined if managers reward results achieved by circumventing controls.
Whistleblowing arrangements must be trusted, accessible and capable of producing a timely response. The organisation should consider independence, confidentiality, protection against victimisation, escalation, feedback and learning. Reports should not disappear within the same management chain implicated by the allegation.
Principle 6: monitoring, testing and review
The organisation should monitor both attempted fraud and the effectiveness of prevention measures.
Useful management information may include:
- control overrides and who authorised them;
- complaints and disputed representations;
- abnormal transactions or adjustments;
- missed reconciliations;
- due-diligence exceptions;
- training completion and assessment performance;
- whistleblowing trends;
- investigation outcomes;
- disciplinary action;
- contract-clause coverage for associated persons;
- repeated use of urgent or exceptional processes;
- AI-system access, prompts, outputs and approval records where relevant; and
- overdue remedial actions.
Testing should not be performed solely by those who designed the control. It should examine whether the procedure operates, whether it can be bypassed, whether staff recognise the risk and whether exceptions are escalated.
Review should occur periodically and after triggering events. The organisation should learn from its own investigations, sector enforcement, regulatory findings and deferred prosecution agreements.
The objective is not a static compliance file. It is a feedback system capable of adapting as the business and fraud methods change.
AI changes both the opportunity and the evidence
The statutory guidance expressly identifies emerging technology, including AI, as a source of new fraud opportunity.
AI can accelerate legitimate work, but it can also make dishonest conduct easier to scale and harder to identify. Relevant scenarios include:
- synthetic customer or supplier records;
- generated supporting documents;
- fabricated correspondence;
- altered audio or video;
- automated misrepresentations;
- false summaries of underlying data;
- concealment of a human decision behind an algorithmic output;
- bulk creation of misleading applications or claims; and
- use of unapproved tools outside monitored systems.
The prevention framework should address:
- approved and prohibited use cases;
- identity and access controls;
- human approval for material representations;
- verification against source evidence;
- retention of prompts, outputs, versions and metadata;
- model and system logging;
- restrictions on uploading confidential information;
- change control;
- third-party system due diligence;
- anomaly detection;
- escalation of suspected manipulation; and
- preservation steps when concern arises.
Saving only the final document may omit the evidence needed to determine who generated it, what instructions were given, how it changed and whether the output was knowingly adopted.
For AI-enabled work, the control record and the evidence record should be designed together.
This does not mean every inaccurate AI output is fraud. Dishonesty remains essential to the relevant base offences. An error, hallucination, system failure or negligent deployment may instead create contractual, data, consumer, professional or regulatory exposure. The organisation must avoid treating “the AI did it” as either a conclusion or a defence.
The board’s evidence pack
If the defence may later have to be proved, the organisation should be capable of producing a coherent evidence pack without constructing it retrospectively.
That pack may include:
- the applicable group and threshold analysis;
- board and committee responsibilities;
- the current and historic risk assessments;
- fraud-prevention plans;
- policies and procedures;
- mapping of controls to identified risks;
- records of approval and challenge;
- budgets and resource decisions;
- due-diligence records;
- relevant contract terms;
- training content, attendance and assessment;
- monitoring data and reports;
- test plans and results;
- whistleblowing arrangements;
- investigation protocols;
- incident and near-miss learning;
- records of remedial action;
- reasons for accepting residual risk;
- evidence of periodic and event-driven review; and
- document-retention and version history.
The pack should show dates. The question is what existed when the base fraud occurred, not merely what was improved after discovery.
Remediation remains important. It can reduce continuing risk and affect enforcement decisions. It should be clearly distinguished from the pre-existing framework so that the organisation does not accidentally misstate when a control was introduced.
Common weaknesses
1. A risk assessment focused only on fraud against the company
This misses the statutory concern: fraud intended to benefit the organisation or its clients.
2. A generic policy with no risk-control mapping
The organisation cannot show which procedure addressed the route by which the actual fraud occurred.
3. Reliance on regulated status or external audit
Regulation and audit may contribute evidence, but neither automatically establishes reasonable procedures. An audit is not designed to identify every fraud or prove this defence.
4. Treating all third parties alike
The real issue is what services they perform, for whom, with what authority and under what incentives.
5. Training measured only by attendance
Completion shows exposure to material, not understanding or changed behaviour.
6. Controls contradicted by reward
A written prohibition is weakened where remuneration, promotion or management pressure encourages the prohibited result.
7. Undocumented exceptions
Repeated “one-off” overrides can become the actual operating process.
8. No plan for allegations benefiting the organisation
Many investigation procedures are built for theft from the company. They may not provide sufficient independence where the alleged conduct helped a business unit or implicated senior management.
9. Policies which have not followed the technology
AI-enabled work may sit outside traditional approval, retention and monitoring processes.
10. Retrospective tidying
Backdating, overwriting or presenting remediation as a pre-existing control can create a separate evidential and credibility problem.
What prosecutors and investigators are likely to examine
An investigation is unlikely to stop at the policy folder. Relevant evidence may include:
- board minutes;
- internal audit;
- emails and messaging;
- target and bonus documents;
- complaints;
- whistleblowing reports;
- control exceptions;
- approval chains;
- training records;
- draft and final representations;
- system logs;
- AI-generation records;
- risk registers;
- legal and compliance advice;
- disciplinary history;
- previous incidents; and
- how the organisation responded after discovery.
Investigators will look for the distance between formal policy and operational reality.
They may ask:
- Was this risk visible?
- Who benefited?
- Who had authority to stop it?
- Were warning signs raised?
- Were controls bypassed openly?
- Did management reward the outcome?
- Was an exception documented?
- Did the organisation investigate similar conduct before?
- Were lessons implemented?
- Can the organisation prove the procedure existed and operated at the relevant time?
Care is required when gathering material. The organisation must preserve evidence, avoid contamination, identify the client for any legal advice, protect privilege where it properly arises and prevent premature factual conclusions from hardening into the corporate record.
Discovery of suspected fraud
The reasonable procedures question is primarily historical, but the organisation’s response after discovery remains important.
The immediate priorities will usually include:
- controlling ongoing harm;
- preserving physical and digital evidence;
- securing relevant systems without destroying logs or generation history;
- establishing an appropriately independent decision structure;
- defining the purpose and scope of any internal investigation;
- considering employment, contractual, regulatory and reporting duties;
- assessing individual and corporate exposure separately;
- reviewing whether legal privilege may apply;
- recording decisions and their evidential basis; and
- remediating identified weaknesses without rewriting history.
Urgency should not produce premature findings that fraud occurred, that a named person was dishonest or that the organisation must self-report. Equally, uncertainty is not a reason for inaction.
The companion guide, The First 24 Hours After Suspected Corporate Fraud, addresses that response in detail.
Self-reporting and cooperation
The discovery of a possible base fraud does not create one universal reporting answer.
The organisation may need to consider:
- mandatory regulatory notifications;
- contractual reporting duties;
- data-protection obligations;
- reports to insurers, auditors or funders;
- engagement with law enforcement;
- a report to the Serious Fraud Office;
- suspicious activity reporting;
- disclosure to markets or investors; and
- duties arising in another jurisdiction.
Each has a different trigger, recipient, timeframe and consequence.
The Serious Fraud Office’s Corporate Co-operation Guidance makes early self-reporting and genuine cooperation highly relevant to enforcement outcome, including the possibility of a deferred prosecution agreement. It does not make self-reporting a mechanical substitute for investigation and legal analysis.
A rushed report may contain inaccurate concessions, waive strategic options or prejudice individuals. Delay may create a different problem, particularly where evidence is at risk or a mandatory obligation applies.
A self-report should be an informed strategic decision, not a reflexive confession or a tactic for postponing action.
The decision should be taken by the correct decision-maker on a documented understanding of the known facts, evidential gaps, legal duties, privilege issues and investigation plan.
A board-level action framework
Senior leaders should be able to answer the following questions now.
Scope
- Does the organisation meet the statutory size test?
- Has the group calculation been documented?
- Which jurisdictions and business units create a UK nexus?
Exposure
- Who performs services for or on behalf of the organisation?
- Where could they commit a listed fraud in that capacity?
- How could the organisation or its clients be intended to benefit?
- Which incentives, pressures or technologies make that conduct more likely?
Prevention
- Which control addresses each material risk?
- Is it preventive, detective or both?
- Does it work under commercial pressure?
- Who can override it?
- How are overrides recorded and reviewed?
Governance
- Who owns fraud prevention?
- What reaches the board?
- What management information demonstrates effectiveness?
- Are challenge, decisions and resources recorded?
People and third parties
- Is due diligence linked to actual role and risk?
- Are contracts adequate?
- Is training role-specific?
- Can staff and associated persons raise concerns safely?
Technology and evidence
- Are AI uses known and governed?
- Are prompts, outputs, approvals and audit trails retained where needed?
- Can evidence be preserved quickly without changing it?
Assurance
- Who tests controls independently?
- What has failed or been bypassed?
- Were findings remediated?
- What triggers an early review?
Response
- Is there an investigation and incident-response plan?
- Can independence be established quickly?
- Who decides on notifications and self-reporting?
- Can the organisation distinguish pre-existing controls from remediation?
If the answers are dispersed across departments, assumed rather than evidenced, or dependent on one individual, the framework may not yet be defensible.
Frequently asked questions
Does the prosecution have to prove that the board knew about the fraud?
No. The offence is designed to avoid that requirement. The prosecution must prove the relevant base fraud, the associated-person relationship, action in that capacity and the required intention to benefit. Board knowledge is not an element.
Must the individual fraudster be convicted first?
No. If there is no conviction, the prosecution must itself prove to the criminal standard that the associated person committed the base fraud.
Is the organisation liable whenever an employee commits fraud?
No. The employee must commit a listed fraud while acting in the relevant associated capacity and with the required intention to benefit the organisation or qualifying client. Purely private fraud or fraud solely against the organisation may fall outside this offence, although other criminal and civil liabilities may apply.
Is an anti-fraud policy enough?
No. It may be part of the evidence, but the organisation must establish reasonable procedures in the circumstances. Risk assessment, implementation, resourcing, communication, enforcement, testing and review all matter.
Can an organisation rely on existing compliance systems?
Existing systems may be used and duplication is not required. The organisation should test whether those systems actually address each identified failure-to-prevent-fraud risk. Regulated status, anti-money laundering processes or audit do not automatically establish the defence.
What if it was reasonable not to introduce a particular control?
Reasonableness is fact-specific. A decision not to implement a measure should be based on a proper risk assessment, proportionately reasoned, authorised, documented and reviewed. It will rarely be reasonable to have conducted no risk assessment at all.
Does the offence apply to overseas companies?
It can. An overseas organisation may be exposed where the underlying fraud has the required UK nexus, for example because an act forming part of it occurs here or gain or loss occurs here.
Are senior leaders personally guilty of failing to prevent fraud?
The section 199 offence applies to the relevant organisation, not to an individual simply because they failed to prevent the conduct. Individuals may still face liability if they commit, encourage or assist the underlying fraud, or under other applicable offences and regulatory regimes.
What is the penalty?
An organisation convicted of the offence can receive a fine. The financial consequence may be accompanied by investigation costs, compensation, regulatory action, procurement consequences, remediation, reputational damage and litigation.
Final perspective
The failure to prevent fraud offence changes the significance of conduct which produces a business advantage.
An organisation may condemn the individual, return the benefit and suffer serious loss after discovery. None of those facts alone answers what it did before the fraud to understand and control the risk.
The most defensible organisations will not be those with the largest policy library. They will be those able to show a clear chain from risk, to decision, to control, to testing, to improvement.
Understand how fraud could benefit the organisation. Build controls that survive pressure. Preserve the evidence that they worked.
When specialist legal advice matters
The design of a prevention framework is a compliance and governance exercise. It also needs to anticipate the legal and evidential questions that arise if a suspected fraud is later discovered.
Early specialist advice may be particularly important where:
- the organisation’s statutory scope is uncertain;
- an associated person or intended benefit analysis is complex;
- conduct spans jurisdictions;
- senior management may be implicated;
- the organisation may be both victim and beneficiary;
- an investigation must be structured independently;
- legal privilege requires careful consideration;
- evidence is dispersed across systems or AI tools;
- reporting or self-reporting decisions arise; or
- the adequacy of existing procedures may itself be under scrutiny.
Craig MacKenzie advises on corporate investigations, fraud risk, evidence preservation and engagement with criminal investigators and prosecutors through his role as a Partner and Solicitor Advocate at Forbes Solicitors.
Legal services are not provided through this website. Craig does not accept instructions independently of Forbes Solicitors. Any instruction is subject to Forbes Solicitors’ conflict checks, onboarding procedures and formal acceptance.
Failure to prevent fraud is ultimately a question of what an organisation understood, what it did and what it can prove.
Craig MacKenzie provides strategic advice through Forbes Solicitors to organisations and senior leaders on fraud prevention procedures, internal investigations, corporate and individual exposure, and engagement with investigators or regulators.
Request a confidential consultationDo You Require Advice About Your Circumstances?
This material provides general information and is not a substitute for advice about a specific investigation or case.
Craig provides legal services exclusively through Forbes Solicitors. To make an initial enquiry, contact Craig at:
craig.mackenzie@forbessolicitors.co.uk
An enquiry does not constitute an instruction. Forbes Solicitors must confirm in writing that it has accepted the matter before any solicitor–client relationship arises.
Related Guidance
The First 24 Hours After Suspected Corporate Fraud
Guide 1 in this series: controlling harm, preserving evidence and making defensible decisions on day one.
AI-Enabled Financial Crime and Corporate Investigations
The cornerstone guidance hub on how AI is changing fraud, corporate liability and investigations.
Deepfake and Voice-Clone Fraud
Guide 3 in this series: legal and investigative response when synthetic media is used in suspected fraud.
Internal Investigations: Privilege, Interviews and Evidence Contamination
Guide 5 in this series: protecting privilege, first accounts and the integrity of the internal investigation.
Corporate Criminal Liability: Senior Managers, Associated Persons and Failure to Prevent Fraud
Guide 6 in this series: mapping the routes to corporate liability and separating corporate exposure from individual guilt.
When an AI Failure Is Not Fraud but Still Creates Regulatory Exposure
Guide 8 in this series: identifying the regulatory, civil and professional routes when an AI failure is not fraud.
Fraud and Financial Crime
Craig's defence practice in serious fraud and financial crime investigations.
Business Crime
Advice for companies, directors and senior managers facing criminal exposure.