
12 months on: is your fraud prevention strategy still fit for purpose?
September marks 12 months since the failure to prevent fraud offence came into force. If your organisation falls within scope, this is a useful opportunity to step back and consider whether the fraud prevention measures put in place before September 2025 remain effective and appropriate.
September marks 12 months since the failure to prevent fraud offence came into force. If your organisation falls within scope, this is a useful opportunity to step back and consider whether the fraud prevention measures put in place before September 2025 remain effective and appropriate.
Changes to your organisation, suppliers, systems, markets or the wider fraud landscape may all mean that measures that were considered reasonable 12 months ago now need to be reviewed or strengthened.
To help organisations identify potential gaps, we have developed a short Fraud Health Check Questionnaire, which can help you assess your current approach and prioritise areas for improvement.
Section 199 ECCTA: a reminder
Section199 of the Economic Crime and Corporate Transparency Act ("ECCTA") introduced a corporate criminal offence of failure to prevent fraud. It applies to large organisations where an "associated person" commits fraud for that organisation's benefit.
An organisation will have a defence where it can demonstrate that it, at the time of the fraud, had reasonable fraud prevention measures in place. A relevant body will not be guilty of the failure to prevent offence if it was or was intended to be a victim of the offence.
An "associated person" can include employees, agents, or any other person who otherwise performs services for or on behalf of the relevant body.
See our previous article on s199 for further details about the offence.
What does "large organisation" actually mean?
A "large organisation" for the purposes of ECCTA is a body corporate or partnership (including incorporated charities), which satisfies at least two of the three following criteria in the year preceding the year of the fraud offence:
More than £36 million turnover
More than £18 million total assets
More than 250 employees
The offence can also apply to a parent company if the group headed by it satisfies (in aggregate) at least 2 of the 3 criteria set out above.
12 months on: time to review?
The Home Office guidance recommends that organisations should keep their fraud prevention measures "under review". The frequency of that review should be at consistent intervals such as every 12 months or 2 years. However, organisations should also consider whether there are any other factors that might trigger an earlier, proactive review of such measures. In our view, such factors might include:
a fraud event that the organisation has suffered
the emergence of a new fraud trend or threat
exposure to an industry or practices that might be at a higher risk of fraud.
For many organisations, the 12-month anniversary of the offence coming into force therefore provides a natural opportunity to revisit their fraud prevention measures and consider whether they remain appropriate.
If an organisation's fraud prevention measures are not adequate or "reasonable" then the organisation risks being prosecuted as having failed to prevent fraud in the event of a fraud incident.
Section 250 CPA 2026: a wider corporate criminal liability landscape
Organisations of all sizes may also wish to review their fraud prevention strategy, particularly in the light of s250 of the Crime and Policing Act 2026 ("CPA 2026"), which came into force on 29 June 2026, and which applies to organisations regardless of size.
In addition to the failure to prevent offence under s199 ECCTA, s196 ECCTA provided that an organisation (of any size) could be criminally liable if a senior manager committed an economic crime listed in schedule 12 ECCTA whilst acting within the actual or apparent scope of their authority (or if they assist in the committing of such an offence).
From 29 June 2026, however, s196 ECCTA has been replaced by s250 CPA 2026, which expands corporate criminal liability further to any criminal offence committed by a senior manager acting within actual or apparent authority (i.e. not just those economic crimes listed in schedule 12 ECCTA, with the exception of any offences committed entirely outside of the United Kingdom or any offences where the organisation would not commit the offence if that conduct were the organisation's (rather than the senior manager's)). See our recent article.
Key fraud risk areas
Fraud is an evolving threat, and organisations should therefore remain alert to emerging trends and vulnerabilities. As part of your review, there are a number of areas that may be worth considering.
Treating fraud as a finance-only issue
Fraud is often viewed as an issue that sits solely with the finance or accounts team. This can lead to other departments neglecting their own responsibilities in fraud prevention
For example, procurement teams may need to consider red flags in supplier relationships, while HR, IT and operational teams may each have different exposure to fraud risks.
Effective fraud prevention should therefore be considered an organisation-wide responsibility, rather than something that sits within one function.
Incomplete fraud risk assessments
A fraud risk assessment should reflect the full range of risks faced by your organisation. Assessments that are too narrowly focused may fail to consider all areas of the organisation or the full spectrum of potential fraud risks.
For example, organisations may assess risks related to financial fraud but overlook risks such as intellectual property theft, data manipulation or inaccurate reporting.
Gaps in supplier contracts
Third party relationships can create another area of vulnerability, particularly where suppliers, agents, contractors or other service providers perform services on behalf of an organisation.
Supplier contracts should therefore be considered as part of your fraud risk assessment. Depending on the circumstances, organisations may need appropriate contractual protections, reporting obligations and flow down provisions to ensure that relevant fraud prevention standards are also reflected further down the supply chain.
Weak reporting and whistleblowing arrangements
Fraud can go undetected because employees are unsure how to report it or reluctant to do so. A lack of clear reporting mechanisms can prevent organisations from identifying and addressing fraud in its early stages.
Organisations should consider whether their reporting and whistleblowing arrangements are sufficiently clear and accessible, whether people understand how concerns will be handled and whether there are appropriate protections against retaliation.
What should you do next?
As we are now 12 months on from the introduction of the failure to prevent offence, you should consider whether it is an appropriate time for your organisation to assess its fraud prevention measures and the audit undertaken to design them (particularly if any of the factors which have been identified above are present).
Take our free Fraud Health Check Questionnaire to help you identify gaps in your organisations fraud prevention measures and prioritise areas for improvement.
If your fraud risk has evolved since your last assessment, your fraud risk assessment and prevention measures may need to be updated accordingly and new fraud prevention measures designed, implemented and embedded in the organisation. Your fraud prevention measures must reasonably address the risks that are specific to your organisation.
Ultimately, your fraud prevention measures are only as good as the analysis that goes into understanding the risk they are designed to address.
Our fraud specialists can help organisations assess their fraud risks and develop proportionate prevention measures tailored to their specific circumstances.
If you would like to discuss your organisation's approach, please contact a member of our Fraud team.
Get in touch today
Are you looking for legal services?
Fill out our form to find out how our specialist lawyers can help you.
