Failure to Prevent Fraud: What the New Offence Means for PE-Backed UK Businesses
The failure to prevent fraud offence is now live. Here is what reasonable procedures look like for a growing business, and why finance owns more of it than legal.
The Economic Crime and Corporate Transparency Act introduced a corporate offence of failing to prevent fraud, and it has been in force since 1 September 2025. It applies to large organisations, but the definition is wider than many Finance Directors assume, and portfolio companies are often caught once group numbers are aggregated.
The offence is simple in shape. If an employee, agent or subsidiary commits a fraud intended to benefit the organisation, the organisation can be prosecuted unless it can show it had reasonable fraud prevention procedures in place.
Check whether you are in scope
The thresholds look at the whole group, not the individual trading company. Two of the following must be met: more than 250 employees, turnover above £36m, or total assets above £18m. A buy and build platform can cross these lines quickly after two or three bolt-ons.
Even where a company sits below the thresholds, investors and lenders are starting to ask the same questions during diligence. Treating the guidance as good practice is usually cheaper than explaining why you have not.
What reasonable procedures look like
Government guidance sets out six principles: top level commitment, risk assessment, proportionate procedures, due diligence, communication and training, and monitoring and review. None of these are new ideas, but very few SMEs have them written down in a form that would stand up to scrutiny.
The risk assessment is where most of the work sits. It should consider where staff have both the motive and the opportunity to misstate results, mislead customers or manipulate pricing for the company's benefit. Sales incentives, revenue targets tied to exit value and earn out mechanics are obvious places to start.
Why finance owns more of this than legal
Most of the procedures that actually prevent fraud live in the finance function: approval limits, segregation of duties, journal review, revenue cut off checks and supplier onboarding. Legal can draft the policy, but the evidence that controls operate comes from finance.
That evidence matters. A policy without operating controls behind it is unlikely to be treated as reasonable. Keep records of reviews performed, exceptions found and how they were resolved.
A practical starting point
Run a short workshop with the board and senior managers to map fraud risks by business area. Compare the result with your existing controls, close the obvious gaps, and agree an annual review date. That alone puts most growing businesses in a far stronger position than they are today.
