The Failure to Prevent Fraud Offence: What Finance and Audit Teams Need to Know
The ECCTA's new failure to prevent fraud offence is now in force. Here's what 'reasonable procedures' means in practice for finance, internal audit and compliance teams.
A new corporate criminal offence has quietly become one of the most significant compliance changes for UK organisations in years. The "failure to prevent fraud" offence, introduced by the Economic Crime and Corporate Transparency Act 2023 (ECCTA), is now in force — and the ICAEW's practical guidance published in March 2026 confirms that most large organisations, and the accountants who advise them, still have work to do.
What the offence actually says
Under the new offence, a large organisation can be held criminally liable if an employee, agent, subsidiary or other "associated person" commits fraud intending to benefit the organisation — even if senior management knew nothing about it. This is a significant departure from the usual "identification principle" in UK corporate criminal law, which normally required prosecutors to prove that a directing mind of the company was involved. Failure to prevent fraud removes that hurdle for fraud offences specifically.
The offence applies to "large organisations" — broadly, those meeting at least two of: more than 250 employees, more than £36m turnover, or more than £18m in total assets, assessed across the group where relevant. Smaller organisations are out of direct scope, but their clients, suppliers and group parents may not be — which is exactly why this affects far more accountants than the size thresholds suggest.
The only defence: reasonable fraud prevention procedures
There is one statutory defence: having "reasonable procedures" in place to prevent fraud by associated persons. This mirrors the structure of the Bribery Act's "adequate procedures" defence and the failure-to-prevent-tax-evasion offence — a pattern UK legislation is now using repeatedly, and one accountants advising on compliance will recognise.
Government guidance and ICAEW commentary point to the same broad framework as other failure-to-prevent regimes:
- Top-level commitment — visible board-level ownership of fraud prevention, not a policy filed and forgotten.
- Risk assessment — a documented assessment of where fraud risk actually sits in the organisation, updated as the business changes.
- Proportionate procedures — controls that match the organisation's actual risk profile, not a generic template.
- Due diligence on associated persons, including third parties acting on the organisation's behalf.
- Communication and training, so the policy is something staff actually know about.
- Monitoring and review, so procedures are shown to be live rather than static.
What this means in practice for finance and audit teams
This offence sits squarely in the territory internal audit and financial control teams already own, which makes it a natural extension of existing risk and controls work rather than a wholly new discipline. In practice, that means:
- Internal audit plans should explicitly test fraud-prevention controls against the "reasonable procedures" framework, not just general financial controls.
- Finance functions should expect fraud risk assessment to become a standing item, not an occasional exercise triggered by an incident.
- Group finance teams need to think beyond their own entity — the offence can be triggered by the conduct of subsidiaries, and procedures need to reflect that.
- Existing anti-bribery and anti-tax-evasion procedures are a useful starting template, since the "reasonable procedures" language deliberately echoes those regimes, but they should not simply be relabelled without a proper fraud-specific risk assessment.
Where this connects to Companies House reform
This offence doesn't exist in isolation — it's part of the same wave of ECCTA reform that introduced mandatory identity verification for directors and PSCs. Together, they represent a clear shift in UK policy toward treating economic crime prevention as an organisational design problem, not just an individual accountability one.
What to do now
For accountants advising in-scope organisations, or working in internal audit and risk roles within them: get a fraud risk assessment on record if one doesn't already exist, map it against the six-pillar "reasonable procedures" framework, and make sure board-level sign-off is documented, not assumed. Organisations that can point to a genuine, monitored fraud-prevention framework are in a materially different position than those relying on general good conduct policies — and given this is now an active offence, that gap is a live risk rather than a theoretical one.
What the penalty actually looks like
Unlike many regulatory breaches that carry a fixed maximum fine, conviction for failure to prevent fraud carries an unlimited fine, decided by the court based on the circumstances of the case, the scale of the fraud, and how far the organisation's procedures fell short of "reasonable." There is no de minimis exemption for the size of the fraud itself — a relatively modest fraud committed by an associated person can still expose a large organisation to prosecution if the underlying procedures were genuinely inadequate, because the offence is about the absence of reasonable prevention, not the scale of the loss.
A practical scenario worth thinking through
Imagine a regional sales manager at a large organisation inflates expense claims and diverts supplier rebates to a personal account over several years, believing (wrongly) that it benefits their sales figures and therefore, indirectly, the company. Under the old identification-principle approach, prosecuting the company itself for this would have been very difficult — the fraud wasn't authorised or known about by senior management. Under the new offence, the company's defence rests entirely on whether it can show reasonable fraud-prevention procedures were in place and operating — expense policy design, approval controls, and whether risk assessment had actually identified this kind of exposure. This is precisely the gap the offence was designed to close, and it's why internal audit's role in testing controls against a documented fraud risk assessment has become more central, not less, since the offence came into force.
Internal audit teams building this into their risk-based planning may find it useful to review it alongside our Internal Audit Fundamentals CPD course, and our Forensic Accounting course for the investigative skills this offence makes more relevant than ever.
This page was last updated:
Learnsignal Education Team
Expert Tutor at Learnsignal
Qualified professional with years of experience helping students advance their professional careers.
View all posts by Learnsignal Education Team

