Skip to main content
Sign up to updates
FIND A LAWYER
COMPANY NEWS

Failure to Prevent Fraud Offence: Why Boards Should Revisit Their Fraud Prevention Procedures One Year On

For organisations caught by the Economic Crime and Corporate Transparency Act 2023 (ECCTA), the Failure to Prevent Fraud Offence represents a significant shift in corporate criminal liability. Boards are increasingly expected to understand fraud risks, review fraud prevention procedures and ensure their organisations can demonstrate compliance with the reasonable procedures defence.

A year after the failure to prevent fraud offence came into force, many organisations may be taking comfort from the fact that there have been no reported prosecutions.

That may be a mistake.

The significance of the legislation was never expected to be measured by prosecution numbers alone. Instead, it has fundamentally changed what boards, directors and senior leadership teams should be thinking about when it comes to fraud risk, governance and corporate accountability.

Shortly after the offence came into force, the Serious Fraud Office and Crown Prosecution Service published joint prosecution guidance, making it clear that organisations should be taking steps to ensure they can demonstrate appropriate fraud prevention measures.

For many businesses, the focus has now shifted from understanding the legislation to answering a more practical question:

Could we demonstrate that we took reasonable steps to prevent fraud if we were challenged?

What Is The Failure To Prevent Fraud Offence?

The failure to prevent fraud offence applies to large organisations where an employee, agent, subsidiary or other associated person commits a specified fraud offence for the benefit of the organisation.

Importantly, an organisation can be held criminally liable even where senior management had no knowledge of the underlying fraud.

The offence currently applies to organisations meeting at least two of the following criteria:

  • More than 250 employees
  • Turnover exceeding £36 million
  • Assets exceeding £18 million

If convicted, an organisation can face unlimited fines.

The key defence is demonstrating that the organisation had reasonable procedures in place to prevent fraud. You can read our previous article with more detail here: Crack down on corporate fraud: what businesses need to know about the new ‘Failure to Prevent Fraud’ Offence 

Who Should Be Paying Attention?

The failure to prevent fraud offence currently applies to large organisations meeting the thresholds above. However, the underlying principles of fraud prevention, governance and risk management are increasingly being adopted as best practice across a much wider range of organisations.

Particular consideration should be given by:

  • Multinational groups
  • Manufacturing businesses
  • Education providers
  • Professional services firms
  • Charities and not-for-profit organisations
  • Businesses with complex supply chains or agency networks
  • Organisations operating across multiple jurisdictions

Even organisations that currently fall outside the statutory thresholds may benefit from reviewing their fraud prevention arrangements as part of wider governance, compliance and risk management activities.

Why The Failure To Prevent Fraud Offence Matters to Boards

Historically, prosecuting larger organisations for economic crime has often proved challenging because prosecutors needed to identify a sufficiently senior individual whose actions could be attributed to the company itself.

The failure to prevent fraud offence changes that dynamic.

Rather than asking whether senior leaders knew about wrongdoing, the focus becomes whether the organisation had taken appropriate steps to prevent it from happening in the first place.

This shifts fraud prevention firmly into the boardroom.

Just as boards are expected to oversee cyber security, health and safety, ESG and wider organisational risk, they should also understand:

  • where fraud risks exist within the organisation;
  • whether controls are proportionate to those risks;
  • how employees and associated persons are trained;
  • how concerns are reported and investigated; and
  • whether existing arrangements would stand up to scrutiny.

The organisations best placed to respond to the legislation are unlikely to be those with the longest policies – they will be those whose boards can demonstrate active oversight, engagement and accountability.

What Are ‘Reasonable Procedures’?

The most important protection available to organisations remains the reasonable procedures defence.

Government guidance identifies six principles that organisations should consider:

  • Leadership commitment;
  • Risk assessment;
  • Proportionate procedures;
  • Due diligence;
  • Communication and training; and
  • Monitoring and review.

Many organisations already have anti-fraud policies and reporting mechanisms in place. The challenge is whether those measures are appropriately documented, regularly reviewed and genuinely reflected in day-to-day operations.

A policy that exists but has not been embedded into the culture of the business is unlikely to provide much comfort if scrutiny follows.

Fraud can also give rise to complex and costly disputes long after the underlying events have occurred. Businesses suffering losses as a result of fraudulent activity may seek recovery from a range of parties, including financial institutions, advisers and other third parties where they believe duties have been breached. The commercial, reputational and legal consequences of fraud can therefore extend far beyond regulatory compliance, reinforcing the importance of prevention and robust governance arrangements.

Failure To Prevent Fraud: Questions Every Board Should Be Asking

One year after implementation, boards may wish to consider:

  1. Have we conducted a fraud risk assessment within the last 12 months?
  2. Do we understand where fraud risks are most likely to arise in our organisation?
  3. Are our policies and controls proportionate to those risks?
  4. Have employees, managers and senior leaders received appropriate training?
  5. Is fraud prevention regularly discussed and documented at board level?
  6. Could we evidence our approach if challenged by regulators, prosecutors, insurers or stakeholders?

If answering any of those questions feels difficult, now may be the right time to review existing arrangements.

How Greenwoods Can Help

For many organisations, the challenge is no longer understanding the Failure to Prevent Fraud Offence. The challenge is demonstrating that their fraud prevention procedures and wider governance arrangements would withstand scrutiny if tested.

The challenge is understanding what “reasonable procedures” means in practice for a business of their size, sector and risk profile.

At Greenwoods, we help organisations move beyond simply having policies on paper and assess whether existing arrangements are likely to withstand scrutiny if challenged.

Our Corporate & Commercial and Employment teams can support with:

  • fraud risk assessments tailored to your organisation and sector;
  • reviews of existing policies, procedures and governance frameworks;
  • gap analyses against the reasonable procedures defence;
  • board and senior leadership workshops;
  • staff training and awareness programmes;
  • whistleblowing and reporting framework reviews;
  • internal investigations and incident response support; and
  • practical implementation plans designed around your specific risks and operational realities.

Importantly, there is no one-size-fits-all solution – what is proportionate for a multinational manufacturer will look very different from what is expected of a charity, education provider, professional services firm or privately owned business. We also help organisations align fraud prevention measures with existing governance, compliance and risk management frameworks, avoiding unnecessary duplication whilst ensuring procedures remain practical, proportionate and capable of being evidenced if challenged.

Our focus is on helping organisations implement practical, commercially sensible measures that strengthen governance, support compliance and remain workable in day-to-day operations.

In many cases, these conversations also create an opportunity to review wider governance, employment, compliance and risk management arrangements, ensuring boards have a joined-up view of organisational risk rather than addressing issues in isolation.

A Practical Example

We recently advised a large international business operating across multiple jurisdictions on its preparations for the Failure to Prevent Fraud Offence and the development of a practical, risk-based fraud prevention framework.

We worked closely with the organisation’s senior compliance function to understand the governance structures, controls and procedures already in place across the wider group.

This enabled us to identify where existing measures could support compliance with the UK regime and where targeted enhancements may be required.

A key challenge was balancing the UK’s requirements against compliance obligations in other jurisdictions. The objective was not to create a separate and burdensome compliance framework/policy, but to develop practical and proportionate measures that aligned with the organisation’s existing governance structures wherever possible.

By adopting a risk-based approach and building on the organisation’s existing assets and processes, we helped strengthen its position without creating unnecessary complexity or administrative burden.

This reflects a challenge facing many organisations today: demonstrating robust fraud prevention measures whilst maintaining operational efficiency across increasingly complex businesses.

Final Thoughts

The absence of prosecutions does not mean the absence of risk.

One year on, the failure to prevent fraud offence has already achieved one of its key objectives: moving fraud prevention from the compliance function into the boardroom.

For boards, the key question is no longer:

“Could fraud happen here?”

It is:

“Could we demonstrate that we did everything reasonably expected to prevent it?”

For many organisations, particularly those operating at scale or across multiple jurisdictions, now is the ideal time to revisit that question before somebody else asks it on their behalf.

In practice, that is likely to involve reviewing fraud risk assessments, governance arrangements, employee training programmes and wider fraud prevention procedures to ensure they remain proportionate to the risks faced by the organisation and capable of supporting the reasonable procedures defence if tested.

If your organisation would benefit from a review of its current fraud prevention arrangements, a fraud risk assessment or a board-level discussion around the reasonable procedures defence, please contact a member of our Corporate & Commercial or Employment team.

This update is for general purposes and guidance only and does not constitute legal or professional advice. You should seek legal advice before relying on its content. Greenwoods Legal Services Limited is a Limited company, registered in England, registered number 16115882. Our registered office is Queens House, 55-56 Lincoln’s Inn Fields, London, WC2A 3LJ. Authorised and regulated by the Solicitors Regulation Authority, SRA number 8011813. Details of the Solicitors’ Codes of Conduct can be found at www.sra.org.uk. All instructions accepted by Greenwoods Legal Services Limited are subject to our current Terms of Business. VAT Reg No: 502 6933 06




    By completing and submitting this form, you consent to Greenwoods Legal Services Limited processing your personal data to contact you in relation to your enquiry and to provide you with any other materials and information about our services that Greenwoods Legal Services Limited reasonably believes will be of interest to you. You are free to withdraw your consent at any time by emailing mailinglists@greenwoods.co.uk