Failure to Prevent Fraud: All-Staff Awareness Guide
The UK's new failure to prevent fraud offence under ECCTA affects every employee, not just senior leaders. Learn what it means, and the fraud red flags all staff should know.
Since 1 September 2025, UK organisations have faced a new corporate criminal offence: failure to prevent fraud. It sits alongside longer-standing "failure to prevent" offences for bribery and tax evasion, and it changes the stakes for everyday conduct at work. An organisation can now be prosecuted if an employee, agent or other person acting on its behalf commits fraud intending to benefit it — even if senior leaders knew nothing about it. The only defence is showing that reasonable fraud prevention procedures were in place. That makes this everyone's issue, not just a legal or compliance one, and building the right habits is exactly what structured CPD training is designed to support.
What is the "failure to prevent fraud" offence?
The offence was introduced by the Economic Crime and Corporate Transparency Act 2023 (ECCTA) and came into force on 1 September 2025. It applies to "large organisations" — those that meet at least two of the following three criteria in the preceding financial year:
- Turnover of more than £36 million
- A balance sheet total of more than £18 million
- More than 250 employees
Where an organisation meets that threshold, it can be held criminally liable if a person "associated" with it — an employee, agent, subsidiary, or anyone else performing services on its behalf — commits a fraud offence intending to benefit the organisation or its clients. Crucially, this is a form of strict corporate liability: the organisation does not need to have approved, encouraged or even known about the fraud to be prosecuted. The one statutory defence available is proving that the organisation had reasonable fraud prevention procedures in place at the time, or that it was unreasonable to expect such procedures given the circumstances.
Why this is an all-staff issue, not just a leadership one
Because the offence is triggered by the conduct of "associated persons," it is not confined to directors or senior managers. A single fraudulent invoice approved by a junior finance assistant, an inflated expenses claim, or a procurement decision influenced by an undeclared personal interest can all count as the underlying fraud that exposes the whole organisation to prosecution. The organisation and its associated persons in scope go well beyond the boardroom — which is exactly why the guidance treats staff awareness as a core part of prevention, not an afterthought. If you're looking at this from a governance or oversight angle rather than day-to-day awareness, our companion guide, Failure to Prevent Fraud: Managers and Associated Persons, covers what the offence means for those with management and oversight responsibilities.
Common fraud red flags every employee should know
You don't need a forensic accounting background to spot fraud — you need to know what to look for and feel confident raising it. Some of the most common patterns employees encounter include:
Invoice fraud
Watch for invoices from suppliers nobody recognises, duplicate invoices for the same goods or services, invoices with slightly altered supplier details, or an email claiming a supplier's bank account has changed. Mandate fraud — where fraudsters impersonate a genuine supplier to redirect payments — relies on staff processing a changed payment instruction without checking it through a separate, trusted channel.
Expenses fraud
This includes inflated mileage or subsistence claims, fictitious or altered receipts, personal purchases submitted as business expenses, and the same expense claimed more than once. Individually these can look minor, but they are still fraud, and a pattern of tolerated small claims can normalise much larger abuse.
Procurement fraud
Red flags here include undeclared conflicts of interest (a contract awarded to a supplier connected to a family member or friend), kickbacks or gifts from suppliers in exchange for favourable treatment, orders deliberately split to stay under an approval threshold, and bid-rigging between suppliers who should be competing.
Payment diversion and impersonation fraud
Urgent payment requests that appear to come from a senior colleague, a client, or a known supplier — but arrive via an unusual email address, request unusual urgency, or ask for payment details to be changed — are a growing risk across every sector. For a closer look at how this plays out in a professional-services setting, see our related piece on client account fraud and payment diversion risk.
Why your conduct matters to the "reasonable procedures" defence
Government guidance sets out six principles an organisation's fraud prevention procedures should reflect: top-level commitment, risk assessment, proportionate risk-based prevention procedures, due diligence, communication (including training), and monitoring and review. Notice that "communication and training" sits alongside due diligence and monitoring as one of the six — it is not a box-ticking extra. If staff across the organisation don't know what fraud looks like, don't understand why controls exist, or don't feel able to report a concern, that is a real gap in the organisation's defence, not just a training gap. Every time you follow an approval process properly, query an unusual request, or report something that doesn't look right, you are contributing directly to the evidence an organisation would need to rely on that defence.
What good practice looks like day to day
Awareness only helps if it translates into habits. In practice, that means:
- Verifying any changed payment or bank details through a separate, known contact method — never by simply replying to the email that requested the change
- Following your organisation's expenses and procurement policies in full, even when a shortcut seems harmless
- Declaring any personal or family connection to a supplier, client or contractor before getting involved in a decision that involves them
- Never bypassing approval limits or splitting a purchase to avoid sign-off
- Speaking up early through your organisation's normal reporting line or whistleblowing channel if something looks wrong, even if you're not certain
- Keeping your fraud awareness current through regular refresher training, rather than treating it as a one-off induction topic
None of this requires specialist skills. It requires knowing what to look for and having the confidence to act on it — which is precisely the gap that focused, practical training is designed to close.
Frequently asked questions
Does the failure to prevent fraud offence apply to my employer?
It applies to "large organisations" that met at least two of the three size criteria — turnover above £36 million, balance sheet assets above £18 million, or more than 250 employees — in the preceding financial year. Many mid-sized and large employers across sectors are in scope, and even organisations below the threshold often choose to adopt similar prevention procedures as good practice.
Could I be personally prosecuted if I don't commit fraud myself?
The failure to prevent fraud offence is a corporate offence charged against the organisation, not individual employees who simply fail to spot fraud. However, an employee who actually commits fraud — for example, by submitting a false expenses claim or approving a fictitious invoice — can still face personal criminal liability under existing fraud law, separately from any charge against the organisation.
What should I do if I suspect fraud at work?
Report it through your organisation's usual channel — typically your line manager, finance team, compliance function, or a confidential whistleblowing line. You don't need proof, only a genuine concern. Acting early, and through the proper channel, is exactly the kind of conduct the "reasonable procedures" defence depends on.
Is this the same as the "failure to prevent bribery" offence?
No, though the two are similar in structure. The failure to prevent fraud offence under ECCTA is a distinct corporate offence covering fraud specifically, sitting alongside the existing failure to prevent bribery offence under the Bribery Act 2010 and failure to prevent tax evasion facilitation under the Criminal Finances Act 2017. Many organisations are reviewing all three together as part of a wider economic crime prevention programme.
Build fraud awareness across your whole organisation
The failure to prevent fraud offence has raised the bar for what "everyone plays their part" actually means in practice. Giving all staff — not just finance and compliance teams — a clear, practical understanding of fraud red flags and reporting routes is one of the most direct ways an organisation can strengthen its reasonable procedures defence. Learnsignal's CPD courses can help you build and evidence that awareness across your teams, and the companion guide referenced above is the next step for anyone with oversight or governance responsibility.
This page was last updated:
Learnsignal Education Team
Expert Tutor at Learnsignal
Qualified professional with years of experience in teaching and helping students achieve their accounting qualifications.
View all posts by Learnsignal Education Team


