open navigation close navigation Menu

Failure To Prevent Fraud: A New Era Of Corporate Accountability

Monday, 10 August 2026

Independent Review of Disclosure and Fraud Offences: Fraud in the Digital Age published by the Home Office on 14 July 2026

We published an article in September 2025 on the failure to prevent fraud offence and addressed how this offence continues to develop, in our July 2026 article on the impact of the Crime and Policing Bill on extending corporate criminality by amending the Economic Crime and Corporate Transparency Act.

This is an area that has been further developed by the Independent Review of Disclosure and Fraud Offences: Fraud in the Digital Age by Jonathan Fisher KC and published by the Home Office, addressing the Failure to Prevent Fraud offence introduced by ECCTA, the new offence marks a deliberate shift away from relying solely on individual wrongdoing and towards holding organisations accountable for the systems, controls and culture that enable fraud to occur.

The report describes fraud as one of the defining crimes of the digital age, with online platforms, digital technologies and increasingly sophisticated criminal methods creating new challenges for enforcement authorities.

The new corporate offence

Section 199 of the Economic Crime and Corporate Transparency Act 2023 introduced a new failure to prevent fraud offence, which came into force on 1 September 2025. The offence creates corporate criminal liability where an associated person commits a specified fraud offence for the benefit of an organisation, and the organisation has failed to implement reasonable fraud prevention procedures.

A company will not be guilty if it can demonstrate either:

  • that it had reasonable fraud prevention procedures in place at the time of the offending; or
  • that it was not reasonable in the circumstances to expect such procedures. 

Government guidance accompanying the legislation sets out six principles intended to help organisations develop appropriate prevention frameworks.

They are:

  • Top-Level Commitment - The organisation's leadership should foster a culture in which fraud is never acceptable.
  • Risk Assessment - Organisations should periodically assess the nature and extent of their exposure to fraud risks.
  • Proportionate Risk-Based Prevention Procedures - Fraud prevention measures should be proportionate to the risks identified.
  • Due Diligence - Businesses should carry out appropriate due diligence on associated persons, including employees, agents, intermediaries, contractors and other parties performing services on their behalf.
  • Communication (Including Training) - Fraud prevention policies and procedures should be communicated throughout the organisation and, where appropriate, to associated persons.
  • Monitoring and Review - Organisations should continuously monitor, review and improve their fraud prevention procedures.

Does ECCTA go far enough?

Under Section 199 ECCTA, a large organisation has a defence if it can demonstrate that it had reasonable fraud prevention procedures in place when the fraud occurred, or that it was not reasonable to expect such procedures. The six principles are therefore likely to form the foundation of any assessment by prosecutors or courts of whether an organisation's anti-fraud framework was reasonable.

The Review notes, however, that the scope of the failure to prevent fraud offence is relatively narrow. It applies only to large organisations that meet at least two of the following thresholds: more than 250 employees, annual turnover exceeding £36 million and total assets above £18 million. As a result, the Review estimates that only around 0.2% of UK businesses fall within scope.

The report also highlights that, while the Economic Crime and Corporate Transparency Act 2023 strengthens corporate criminal liability by reforming the identification doctrine and broadening the circumstances in which the actions of senior managers can be attributed to a company, the offence does not currently extend to fraud committed by users of online platforms. The Review therefore argues that a significant accountability gap remains within the digital economy despite these important reforms.

The Review's assessment

The Review views the introduction of the offence as an important and welcome development in the UK's corporate crime framework. It describes the measure as evidence of a growing acceptance that businesses have a responsibility to actively prevent economic crime occurring within their organisations.

However, the report also argues that the offence does not go far enough.

One of its principal criticisms is that the legislation only addresses fraud committed by employees, agents or other associated persons for the benefit of the organisation itself. It does not extend to fraud committed by users of online platforms, even where those platforms host, facilitate or profit from fraudulent activity.

The proposed next step: Extending liability to online platforms

A central conclusion of the Review is that a significant accountability gap remains within the digital economy. The report points to evidence that substantial volumes of fraud originate online, particularly through social media platforms and user-generated content services. Yet these organisations currently bear no equivalent criminal liability for fraud conducted by users on their platforms.

To address this, the Review recommends the creation of a new corporate criminal offence for providers of regulated user-to-user services under the Online Safety Act 2023. This proposed offence would mirror the ECCTA model and would require platforms to implement reasonable procedures designed to prevent fraud occurring through their services.

The report argues that such an extension would:

  • close an existing accountability gap;
  • embed fraud prevention into platform governance;
  • encourage greater investment in monitoring and detection technologies;
  • strengthen cooperation with law enforcement; and
  • rebalance responsibility across sectors currently involved in fraud prevention.

A broader shift in corporate responsibility

Ultimately, the Review presents the failure to prevent fraud offence as part of a wider movement in UK economic crime policy towards prevention rather than reaction. It concludes that fraud can no longer be addressed solely through the prosecution of individual offenders. Instead, organisations whose structures, systems or business models create opportunities for fraud are increasingly expected to take proactive steps to mitigate those risks.

In the Review's assessment, the ECCTA offence establishes an important foundation for that approach. However, it also signals that further reforms may be required if corporate accountability is to keep pace with the realities of digital-age fraud and the growing role played by online infrastructure in facilitating criminal activity.

The full report is available here: 2025.12.31.Independent.Review.of.Disclosure.and.Fraud.Second.Report.Print.Version.CM


About the author:

Karen O’Donnell is Governance & ESG Knowledge Manager at Equiniti, where she provides expert insight on regulatory developments, corporate governance and shareholder engagement to support issuers navigating an evolving market landscape.

Need help navigating ECCTA?

Please reach out to your Relationship Manager who will be able to assist further, or find more information on our dedicated ECCTA Hub.

Visit the ECCTA hub
share-xx