Insights · Corporate liability
Failure to prevent fraud, one year on. What “reasonable procedures” means for your third parties
Since 1 September 2025, large organisations are liable for fraud committed by employees, agents and subsidiaries for their benefit. The main defence is reasonable procedures, and third parties are where most organisations are thinnest.

The failure to prevent fraud offence came into force on 1 September 2025, under the Economic Crime and Corporate Transparency Act 2023. A year on, most large organisations have a policy. Fewer can show the procedures behind it, and the gap is widest where the risk sits: with the agents, intermediaries and subsidiaries who act on their behalf.
Who is caught
An organisation is in scope if it meets two of three tests in the previous financial year: more than 250 employees, turnover above £36 million, or total assets above £18 million. Where it is incorporated does not matter, provided the underlying fraud has a UK connection.
It is liable when an “associated person” commits a specified fraud intending to benefit the organisation or its clients. Associated persons include employees, agents, subsidiaries and anyone else performing services on its behalf. A supplier who only provides goods is not, but a sales agent, a freight intermediary or a consultant introducing business usually is.
The penalty is an unlimited fine. The organisation does not need to have known.
The defence
The main defence is that reasonable fraud prevention procedures were in place at the time. (There is a narrower alternative: that it was not reasonable to expect the organisation to have any procedures. Few large organisations will be able to rely on it.) Home Office guidance sets out six principles: top-level commitment, risk assessment, proportionate procedures, due diligence, communication and training, and monitoring and review.
Two of those, risk assessment and due diligence, bite hardest on third parties, because an organisation knows least about the people acting for it from outside. They are also the two that a policy document cannot satisfy on its own.
What “reasonable” looks like for third parties
- A list of who acts for you, by name, with what they do and where.
- A risk rating for each, based on the work, the jurisdiction and the money that passes through them.
- Due diligence proportionate to that rating: identity, ownership, sanctions and adverse media for the higher-risk ones, with the result recorded.
- Contract terms that bite: audit rights, termination for fraud, and a duty to report.
- A review date, kept.
The test to apply now
Pick the three intermediaries who handle the most money or the most sensitive introductions on your behalf. For each, ask whether you could show a prosecutor, today, what you checked before you appointed them and when you last looked again. If the answer is a contract and an email, the procedures are not yet reasonable.
Sources
- The UK failure to prevent fraud regime takes effect on 1 September (Travers Smith, 2025)
- Organisations must prepare now for new fraud prevention law (Crown Prosecution Service)
Published 9 October 2026. General information, not legal advice; the position may have changed since publication.
Get new insights by email
A short note when we publish. Dated, sourced, and ending with what to check.


