The Failure to Prevent Fraud offence – one year on

TLT picks out the key points you shouldn't miss...

What’s this about?

The Failure to Prevent Fraud ("FTPF") offence under the Economic Crime and Corporate Transparency Act 2023 ("ECCTA") came into force on 1 September 2025.  A year on, the implementation period is over. For in-scope organisations, the question is no longer simply whether policies, risk assessments and training were put in place, but whether those arrangements remain proportionate, are operating effectively and can be evidenced.

To help organisations do that, TLT has developed a Failure to Prevent Fraud Risk Assessment Tool. It provides a structured health check against the six principles in the Government guidance, helping organisations identify strengths, gaps and priorities for improvement.

Ben Cooper, Partner in Risk and Financial Crime, says...  

“A year ago, much of the focus was on getting frameworks in place. Organisations should now be asking a harder question: can we show that our fraud prevention procedures reflect our current risks and work effectively in practice? The first anniversary is a natural point to carry out that health check. Waiting until an allegation or investigation arises will be too late to address gaps in the procedures that applied at the relevant time.”

The points not to miss...

Why conduct a one-year review?

Risk has moved on. Products, routes to market, incentive arrangements, third-party relationships and operating models may have changed since the original assessment.

Controls need to work, not merely exist

Organisations should be able to evidence implementation, monitoring, challenge and remediation, rather than relying on policies alone. The evidential record matters. The statutory defence turns on the procedures in place at the time of the misconduct. A clear, contemporaneous audit trail will therefore be important if an organisation is required to explain why its procedures were reasonable.

Two common oversights

Outward fraud

FTPF is concerned with specified fraud committed with the intention of benefiting the organisation or, in certain circumstances, its clients. A framework focused principally on fraud against the organisation may therefore be incomplete.

Associated persons

risk does not stop with employees. Agents, subsidiary undertakings and anyone performing services for or on behalf of the organisation may expose it to liability. Depending on the circumstances, this may include intermediaries, introducers, distributors, contractors and consultants.

The reasonable procedures defence is likely to be the central battleground

The most important protection available to organisations remains the "reasonable procedures" defence.

To establish a defence, a firm must demonstrate either that:

  • it had reasonable fraud prevention procedures in place at the time of the misconduct; or
  • it was not reasonable in all the circumstances to expect the organisation to have such procedures.

The Government's guidance continues to be the primary reference point for assessing reasonableness, and is structured around six principles:

  1. Top-level commitment;
  2. Risk assessment;
  3. Proportionate risk-based prevention procedures;
  4. Due diligence;
  5. Communication and training; and
  6. Monitoring and review.

A key challenge for organisations is moving beyond documented policies and demonstrating that controls are embedded, understood and operating effectively in practice.

The Serious Fraud Office ("SFO") is focused on effectiveness

Since implementation, regulatory messaging has consistently reinforced that the existence of policies alone will not be sufficient.

The SFO has emphasised that compliance programmes will be assessed by reference to their effectiveness and how they operate in practice. Organisations should therefore be able to evidence not only the design of their fraud controls, but also how those controls are monitored, tested, challenged and improved over time.

In other words, firms should be prepared to demonstrate that their fraud prevention framework is a living programme rather than a static compliance exercise.

Enforcement risk remains real, even in the absence of prosecutions

Whilst there has been no enforcement action taken to date under this new offence, it is clear from regulators that prosecuting organisations that commit the failure to prevent fraud offence is a top priority. For instance, the Crown Prosecution Service and SFO released joint updated guidance following the entry into force of the offence to reinforce their priorities and considerations regarding the fight against corporate crime. Another important factor to keep in mind is that consent from the Director of Public Prosecutions will not be necessary (unlike under similar offences in the Bribery Act 2010), which means that private prosecutions from entities such as individuals and companies will be possible.

Questions organisations should ask now
  • Has our fraud risk assessment been refreshed to reflect changes since September 2025?
  • Does it address fraud intended to benefit the organisation or its clients, rather than focusing principally on fraud against us?
  • Have we identified all relevant associated persons, including agents, subsidiaries and third parties performing services for or on our behalf?
  • Can control owners demonstrate that key controls are operating as designed?
  • Are exceptions, overrides, incidents and near misses informing the risk assessment?
  • Does management information allow senior management to identify gaps and challenge the effectiveness of the framework?
  • Have lessons from investigations, whistleblowing reports, audit findings and business changes resulted in documented improvements?
  • Could we produce a coherent evidence pack if challenged by a prosecutor?
  • Is your framework still reasonable one year on?

How TLT can help

TLT's Failure to Prevent Fraud Risk Assessment Tool provides a structured review of an organisation's arrangements against the Government's six principles. It can help organisations assess the maturity of their current framework, identify gaps between documented procedures and operational practice, test whether controls remain proportionate to the current risk profile, strengthen the evidence supporting a reasonable procedures defence and prioritise practical remediation.

Use the tool to take stock of your position and identify where further assurance or enhancement may be needed. If the assessment identifies higher-risk areas or control gaps, our Risk and Financial Crime team can support targeted testing and remediation.

We can also support the design, testing and enhancement of fraud prevention frameworks to help organisations strengthen their position should their procedures ever come under regulatory scrutiny.

At a glance...

Tool Failure to Prevent Fraud Risk Assessment Tool
What's it relevant to? Failure to prevent fraud; fraud; financial crime

Authors: Ben Cooper, Meghan Millward, Ailbhe Redding, Hannah Yeager

This publication is intended for general guidance and represents our understanding of the relevant law and practice as at September 2026. For more information see our terms & conditions.

No items found.

Date published
17 Sep 2026

Failure to Prevent Fraud Risk Assessment

Abstract overlapping curved shapes in varying shades of violet and purple on a solid violet background.

Legal insights & events

Keep up to date on the issues that matter.

Abstract yellow background with overlapping translucent olive green curved shapes.

Follow us

Find us on social media

No items found.