Failure to Prevent Fraud: Managers and Associated Persons
A governance-level guide for managers on the UK's failure to prevent fraud offence: who counts as an associated person, what reasonable fraud prevention procedures require, and how liability differs from the failure to prevent bribery offence.
From 1 September 2025, a new corporate criminal offence has been live in the UK: failure to prevent fraud, introduced by the Economic Crime and Corporate Transparency Act 2023 (ECCTA). For most staff, the practical message is simple — don't commit fraud, and raise concerns when you see it. For managers, and for anyone overseeing sales, procurement, agents or other "associated persons," the obligations run deeper. This post looks at the offence from a governance perspective: who counts as an associated person, what "reasonable fraud prevention procedures" actually require of management, how this offence differs from the established failure to prevent bribery offence, and what line managers in higher-risk functions need to do differently. If you haven't already, read our companion guide, Failure to Prevent Fraud: All-Staff Awareness, for the foundational overview this post builds on.
Who Counts as an "Associated Person" Under the Offence?
The offence only applies to a "large organisation" (broadly, one that meets at least two of three thresholds in the relevant financial year: more than 250 employees, more than £36 million turnover, or more than £18 million in total assets — and this includes subsidiaries assessed alongside group-wide figures). But once an organisation is in scope, its exposure is not limited to its own workforce. The offence is committed where a person "associated with" the organisation commits fraud intending to benefit the organisation, and the organisation cannot show it had reasonable fraud prevention procedures in place.
An "associated person" is defined broadly and includes:
- Employees — at every level, not just senior management.
- Agents — anyone acting on the organisation's behalf, including introducers, brokers and intermediaries.
- Subsidiaries — and, by extension, their employees and agents where they are performing services for the parent.
- Any other person who performs services for or on behalf of the organisation — this is the deliberately wide catch-all, and it is where most managers underestimate their exposure. It can capture contractors, consultants, outsourced service providers and, depending on the facts, even certain joint venture partners.
Whether someone is "performing services" is a question of fact, not job title. A self-employed sales agent working exclusively for your organisation, a procurement consultant negotiating supplier contracts, or a third-party call centre handling customer payments could all be associated persons — even though none of them appear on the payroll. This is precisely why the offence is a governance issue and not just an HR one: managers who commission, supervise or rely on third parties acting for the organisation need to understand that those third parties' conduct can create criminal liability for the organisation itself.
What "Reasonable Fraud Prevention Procedures" Require of Management
The government's official guidance, published under ECCTA, sets out six principles that organisations should use to design and evidence reasonable procedures. These principles are guidance rather than a rigid checklist — proportionality runs through all of them — but for managers with governance responsibility, each has direct implications:
- Top-level commitment. Senior management and the board must visibly own fraud prevention, not delegate it entirely to compliance. Middle managers are the transmission mechanism for that tone — if you run a team, you are expected to model and reinforce it, not just point staff to a policy document.
- Risk assessment. Organisations must periodically assess where fraud risk actually sits in their business — which functions, which relationships, which associated persons. Managers of higher-risk areas should expect to contribute directly to this assessment; a generic, organisation-wide risk register that never asks "what could go wrong in procurement, specifically" will not hold up.
- Proportionate risk-based procedures. Controls should match the level of risk. A sector with its own established financial control regime — client money rules in legal services being one example, illustrated in our piece on SRA Accounts Rules and client money controls — shows how proportionate, sector-specific procedures can look in practice, even outside the fraud context.
- Due diligence. On associated persons themselves — new agents, intermediaries, suppliers and outsourced partners should be vetted before they start acting on the organisation's behalf, and periodically reviewed afterwards.
- Communication and training. Not a one-off induction module. Guidance and training need to be targeted at the people actually exposed to fraud risk, refreshed regularly, and documented so the organisation can evidence it happened.
- Monitoring and review. Procedures need to be tested and updated as the business, its associated persons and its risk profile change — a static policy written once and left untouched is a weak defence.
For a manager, the practical takeaway is that "we have a policy" is not a defence on its own. What matters is whether procedures are proportionate to the actual risk in your area, genuinely embedded in how the team works, and capable of being evidenced if the organisation is ever investigated.
Management Liability and How This Differs From Failure to Prevent Bribery
Managers who are already familiar with the failure to prevent bribery offence under the Bribery Act 2010 will recognise the general shape of this new offence — both rely on an "adequate/reasonable procedures" defence, and both hold the organisation, not just the individual wrongdoer, criminally liable. But there are important differences that matter for how governance should respond:
- Scope of application. The failure to prevent bribery offence applies to organisations of any size that carry on business in the UK. The failure to prevent fraud offence applies only to large organisations meeting the size thresholds — smaller organisations are outside its scope, even though individuals within them can still be prosecuted for fraud itself under existing law.
- Underlying conduct. Bribery is a narrower, more clearly defined act. Fraud, as captured by this offence, covers a wide base offence list — including fraud by false representation, false accounting, participation in a fraudulent business, and cheating the public revenue, among others — so the range of conduct a manager needs to be alert to is considerably broader.
- Benefit requirement. The fraud offence requires that the associated person intended the fraud to benefit the organisation (or, in some cases, a person to whom the associated person provides services on the organisation's behalf). Fraud intended solely to benefit the individual, at the organisation's expense, generally falls outside the offence — though it may still expose the organisation to other risks and duties.
- Maturity of guidance. Bribery Act compliance has had over a decade to mature, with well-established case law and precedent. The failure to prevent fraud offence is new; there is little enforcement history yet, and government guidance is the primary reference point rather than settled case law. Managers should treat early compliance as building a track record, not simply adapting existing bribery controls and assuming they transfer across unchanged.
For governance purposes, the two offences should sit alongside each other within a wider economic crime compliance framework, but they cannot simply share a single generic policy. Fraud risk assessments, due diligence and monitoring need to be built around fraud-specific red flags — invoice manipulation, payment diversion, misrepresentation to customers or investors — not repurposed bribery checklists.
Practical Steps for Line Managers in Sales and Procurement
Sales and procurement are consistently flagged in the government guidance and by legal commentators as higher-risk functions, because they involve the two things fraud needs most: financial value and a degree of individual discretion. Managers overseeing these areas should focus on a few practical actions:
- Map who is acting on the organisation's behalf. List every agent, broker, commission-based introducer, outsourced sales partner or procurement consultant in your area. If any of them meet the "associated person" test, they need to go through due diligence and be brought into training and monitoring — not left outside the compliance perimeter because they are not employees.
- Scrutinise incentive structures. Commission schemes, sales targets and procurement bonus structures can unintentionally reward the exact behaviour — misrepresenting terms, inflating figures, steering business toward a preferred supplier for personal benefit — that the offence is designed to prevent. A related pattern worth understanding is how payment details get manipulated for private gain; our post on client account fraud and payment diversion risk walks through how that kind of fraud plays out in practice.
- Tighten approval and segregation controls. No single person in sales or procurement should be able to both set up a new supplier or customer and approve payment to them. Review who currently holds that combined access.
- Document your risk assessment for your function specifically. Generic organisational statements are not enough — be able to show what fraud risk looks like in your team, and what controls respond to it.
- Escalate, don't absorb. Managers who identify a suspicious pattern and handle it informally — rather than escalating through the organisation's fraud reporting channel — can undermine the very procedures the organisation is relying on as its defence.
Building this literacy across a management population is a training and CPD exercise as much as a legal one. Learnsignal's CPD courses can help managers and compliance teams build and evidence the fraud awareness training that the government's guidance expects to see.
Frequently Asked Questions
Does the failure to prevent fraud offence apply to my organisation if we are not "large"?
No — the corporate offence itself only applies to organisations that meet at least two of the three size thresholds (over 250 employees, over £36 million turnover, or over £18 million total assets) in the relevant financial year, including on a consolidated group basis. Smaller organisations remain outside the offence, though individuals can still be prosecuted for fraud under existing criminal law regardless of organisation size.
Can a manager be personally prosecuted under this offence?
The failure to prevent fraud offence itself is a corporate offence — it is the organisation that is prosecuted, not an individual manager, for failing to have reasonable procedures. However, a manager who personally commits fraud, or who is knowingly involved in it, can still be prosecuted under the underlying fraud offences that have always existed, entirely separately from this new corporate offence.
Is training alone enough to count as "reasonable procedures"?
No. Communication and training is only one of the six principles in the government's guidance, alongside top-level commitment, risk assessment, proportionate procedures, due diligence and monitoring and review. Training that is not backed by risk assessment, due diligence on associated persons, and ongoing monitoring is unlikely, on its own, to satisfy a court that reasonable procedures were in place.
How is this different from just following the Bribery Act 2010 approach we already have?
The two offences share a similar "reasonable/adequate procedures" defence structure, but they cover different conduct, different scope thresholds, and the fraud offence has a wider base list of underlying offences and its own government guidance. Existing bribery procedures are a useful starting point for governance structure, but fraud-specific risk assessment, due diligence and monitoring still need to be built out separately.
Understanding where your management responsibility begins — and who counts as an associated person in your team's activity — is the first step toward defensible procedures, not just a policy on paper. Explore Learnsignal's CPD training to give your managers and higher-risk functions the practical grounding this offence now expects.
This page was last updated:
Learnsignal Education Team
Expert Tutor at Learnsignal
Qualified professional with years of experience in teaching and helping students achieve their accounting qualifications.
View all posts by Learnsignal Education Team


