AUTHOR: Kritin Sundaram
DATE: 26 August 2025
Updated Guidance
Last week, the UK Crown Prosecution Service (“CPS”) and Serious Fraud Office (“SFO”) released updated joint guidance on the common approach to the prosecution of corporate offending in England and Wales, particularly in light of the new “failure to prevent fraud” offence under the Economic Crime and Corporate Transparency Act 2003 (“ECCTA”), which comes into force in less than a week’s time on 1 September 2025 (“Guidance”). For businesses, this update provides useful insight into prosecutorial thinking and highlights areas where strong internal processes can make a real difference.
Corporate Criminal Liability
Senior Manager liability
ECCTA now enables criminal liability to be attributed to an organisation, regardless of size, for a variety of criminal offences (under Schedule 12 of ECCTA) if such offences were committed by a “senior manager” acting within the scope of their authority. For example, this could include certain Companies Act offences, VAT fraud, false accounting or money laundering.
Failure To Prevent
ECCTA further imparts a legal duty on large organisations to put “adequate procedures” in place to prevent fraud, failure of which could result in such organisations becoming legally responsible for failing to prevent such fraud committed by their employees and other associated persons, where such offence has, according to the Guidance, “the intention of benefiting the organisation or a person to whom the organisation provides services, and also to certain parent undertakings where the fraud is committed by an associated person of a subsidiary for the benefit of the parent or a person to whom the parent provides services.”
The updated guidance also provides information on amendments to the “identification doctrine”, which is already in force and introduced a wider definition of who could be held accountable for an organisation’s actions.
Extraterritorial implications
A key feature of ECCTA, subject to limitations and restrictions as set out in the Act and additional guidance provided, is its wide extraterritorial effect for both senior management implication and “failure to prevent” offences. Corporations may be held liable for an offence even if the offending took place outside the UK, even if the organisation is based overseas, if there is a significant nexus to the UK.
As Nick Ephgrave, Director of the SFO said, “Now is the time to take action. Corporations must get their house in order or be ready to face investigation.”
Enhanced Corporate Compliance
It is clear that prosecutors may examine whether an organisation has created conditions where misconduct can thrive. They may look at incentive structures, oversight mechanisms, and whether leadership genuinely prioritises compliance or just pays lip service to it.
How organisations identify, assess and respond to compliance risks is crucial. A defence under the “failure to prevent” offence is that a corporation has adequate (for the purposes of the UK Bribery Act) or reasonable (for the purposes of ECCTA) procedures to prevent such offending. Further, showing a “top down” commitment from senior managers fostering a zero-tolerance culture towards fraud, thorough risk assessments and associated prevention measures, continuous monitoring, communication and review are crucial.
Leveraging Technology
Most organisations still rely on manual processes for identifying and preventing risks, as well as conducting investigations into allegations of misconduct and the use of such findings to further augment preventative measures.
Important information gets missed because it’s stored in different systems, similar cases are handled inconsistently across the organisation, investigations take weeks or months when stakeholders expect rapid responses, and administrative tasks consume resources that should focus on analysis. These inefficiencies become more problematic in light of the CPS-SFO guidance, which emphasises the importance of systematic, thorough responses to potential misconduct.
Forward-thinking organisations are adopting integrated investigation platforms that centralise
information and automate routine tasks. By showing a top-down culture of compliance, having proportionate procedures in place and acting on allegations of misconduct fast, organisations can take one step forward in showing commitment and cooperation with regulators and law enforcement.
LEIAA by Augmetec brings together all relevant data – from initial reports to witness statements to supporting documents – in a secure, single interface environment. Reduce administrative burdens, eliminate inefficiencies and provide a focused, single source of truth environment to be able to leverage key insights and trends.
The information contained in this blog post is for general informational purposes only and does not constitute legal advice. The author disclaims all liability for any loss or damage arising from reliance on information contained herein, and it should not be relied upon as a substitute for professional legal counsel.
