ECCTA’s Failure to Prevent Fraud: Your Policy Is No Longer the Defence

What ECCTA’s failure to prevent fraud offence requires, why the SFO says a policy alone will not hold up, and what a defensible fraud prevention programme looks like heading into 2026.

Dekoratives Bild

An employee inflates a supplier invoice to hit a bonus target. It is one person, acting alone, for their own benefit. Since 1 September 2025, it is also a crime your organisation can be prosecuted for, unless you can prove you saw it coming.

That is the failure to prevent fraud offence under the Economic Crime and Corporate Transparency Act (ECCTA), and 2026 is its first full year in force.

A fraud policy sitting in your document library will not defend you. What defends you is proving, after the fact, that your procedures were actually operating before the fraud happened. Most compliance leaders think they have that proof, but most do not.

I spent two days at the IBA Anti-Corruption Conference in London recently listening to regulators, prosecutors, and compliance officers describe what that proof needs to look like. The message was consistent enough to notice a pattern. Having a policy is no longer the test. The ability to show the policy worked is.

Here is what that test requires and where most organisations still fall short.

In This Article
  1. What Does Reasonable Procedures Mean Under ECCTA?
  2. Why the SFO Says Paper Policies Will Not Save You
  3. Does No Prosecution Yet Mean You Are Safe?
  4. What a Fraud Defence Looks Like in Practice

What Does Reasonable Procedures Mean Under ECCTA?

Reasonable procedures means a fraud prevention programme built around six principles set out in Home Office guidance: top-level commitment, dynamic risk assessment, proportionate prevention measures, fraud-specific due diligence, communication and training, and ongoing monitoring. It is a standard measured by evidence, not a document measured by existence.

The offence covers large organisations, defined as meeting two of three thresholds in the preceding financial year: more than 250 employees, more than £36 million in turnover, or more than £18 million on the balance sheet. If your organisation clears that bar and an associated person commits fraud for its benefit, criminal liability follows unless you can demonstrate reasonable procedures were in place.

Here is what each principle looks like in practice:

  • Top-level commitment, meaning your board and senior leadership visibly own fraud prevention rather than delegating it to compliance alone
  • Dynamic risk assessment, reviewed regularly rather than filed once and forgotten
  • Proportionate, risk-based prevention procedures matched to your size, structure, and exposure
  • Fraud-specific due diligence on associated persons, not generic third-party checks
  • Communication and training that reaches the people exposed to fraud risk
  • Monitoring and review that catches when procedures stop working

None of these principles describe a document sitting in a shared drive. They describe a programme that runs continuously and leaves a trail. Six principles are straightforward to read. They are considerably harder to operate.

See What a Tested Fraud Prevention Programme Looks Like

See how Mitratech helps build a defensible, auditable record of policy distribution, attestation, and version history, the evidence base a reasonable procedures defence depends on.

Sehen Sie, wie es funktioniert

Why the SFO Says Paper Policies Will Not Save You

Regulators have already told you what will not work. The Serious Fraud Office (SFO) and Crown Prosecution Service published updated joint prosecution guidance in August 2025, weeks ahead of the offence taking effect, and it does not treat a policy document as a defence on its own. What it wants is evidence that your procedures were operating, tested, and enforced before the fraud occurred, not evidence that they existed.

That is a real shift from how most compliance programmes have run for the last decade. Write the policy, publish it, tick the box, move on. But there is a problem with that approach now: it does not hold up in court.

One compliance leader put it plainly on a panel at the IBA conference. Policies used to be enough, because checking the box was the standard. Now regulators expect you to actively test your compliance environment and prove that it works. She was not speaking about ECCTA specifically. She may as well have been. Tested and proven, not written and filed, is what the reasonable procedures defence now demands.

Does No Prosecution Yet Mean You Are Safe?

As of mid-2026, nobody has been prosecuted under the failure to prevent fraud offence. Read that as a countdown, not a reprieve. The Serious Fraud Office’s own business plan described the offence coming into force as a landmark moment that would widen the reach of corporate prosecutions, and the Crown Prosecution Service has told organisations directly to prepare now, not to wait and see whether the law gets used.

The FCA, Financial Conduct Authority, opened the IBA conference as the keynote, which tells you that regulatory attention here is not confined to the SFO. Enforcement bodies across financial services, corporate crime, and sanctions are converging on the same expectation: prove your controls function under scrutiny, not just that they exist on paper.

The government’s own posture backs this up. The Home Office published its Fraud Strategy 2026 to 2029 this year, a multi-year commitment that only makes sense if regulators expect to be using these powers for years, not months. And according to the Home Office’s Economic Crime Survey 2024, roughly one in four UK businesses with more than one employee experienced fraud in the past year, an estimated 389,000 businesses and 6.04 million individual incidents. Fraud is not a hypothetical you are preparing for. It is already happening at scale, and the law asking you to prove you tried to stop it is not going anywhere.

Turn Fraud Awareness Training Into an Audit Trail

See how Mitratech connects fraud-awareness training, speak-up reporting, and completion tracking into a single evidentiary record, so training is provable, not just delivered.

See the Solution

What a Fraud Defence Looks Like in Practice

A defensible programme carries a paper trail that a policy document does not. Approvals are dated. Nobody has to take training completion or policy attestation on faith. Both are logged per person, not assumed from a distribution list. Due diligence on associated persons follows the same discipline, refreshed on a schedule and not treated as a one-time check at onboarding. And when monitoring flags a gap, there is a record of what happened next, because a programme that never finds a gap has not been tested hard enough to trust.

Boards will be asked to explain their fraud controls to a court using roughly the same standard they already apply to bribery controls under the UK Bribery Act. The mechanics are familiar. The evidentiary bar has risen, and so has the expectation that speak-up channels really do surface concerns rather than sitting unused.

Get the sequencing right, and this becomes manageable. Get it wrong, and you find out during an investigation, when it is too late to fix.

The failure to prevent fraud offence will not be the last law built on this logic. The EU Anti-Corruption Directive rests on the same premise: a written policy does not defend you, a demonstrable one does. Reasonable procedures under ECCTA is the test in front of you today. It will not be the last version of this test your organisation faces.

At Mitratech, we help compliance and risk leaders build the evidence base a reasonable procedures defence requires, connecting policy attestation, fraud-awareness training, speak-up reporting, and enterprise risk visibility into a single record. None of that replaces judgement. It gives your board something to point to when a regulator asks the only question that matters: can you prove it.

Häufig gestellte Fragen

What does ECCTA stand for?
CCTA stands for the Economic Crime and Corporate Transparency Act 2023, a UK law that reformed Companies House powers, corporate transparency requirements, and corporate criminal liability. Its most significant compliance obligation for large organisations is the failure to prevent fraud offence, which took effect on 1 September 2025.
What is the ECCTA failure to prevent fraud offence?
It is a criminal offence under the Economic Crime and Corporate Transparency Act 2023 that came into force on 1 September 2025. Large organisations are liable if an employee, agent, or other associated person commits fraud intending to benefit the organisation, unless the organisation can prove it had reasonable fraud prevention procedures in place at the time.
Which organisations does the failure to prevent fraud offence apply to?
It applies to large organisations that meet at least two of three thresholds in the preceding financial year: more than 250 employees, more than £36 million in turnover, or more than £18 million in total assets. Smaller organisations fall outside the offence directly but can still face exposure through group structures or as an associated person of a larger organisation.
What counts as reasonable fraud prevention procedures?
The Home Office guidance points to six principles: top-level commitment, dynamic risk assessment, proportionate prevention procedures, fraud-specific due diligence on associated persons, communication and training, and ongoing monitoring and review. A written policy alone does not satisfy the standard. Organisations need evidence the procedures were operating and enforced.
Has any organisation been prosecuted under the failure to prevent fraud offence yet?
Not as of mid-2026. The Serious Fraud Office and Crown Prosecution Service updated their joint prosecution guidance in August 2025, ahead of the offence taking effect, and the SFO has described enforcement as a matter of when, not if. Organisations should treat the absence of a prosecution so far as a preparation window, not a signal of low risk.
How does this differ from the UK Bribery Act's failure to prevent bribery offence?
The legal structure is similar. Both are strict liability offences with a defence based on demonstrating reasonable or adequate procedures. The failure to prevent fraud offence extends that model to fraud committed by a wider group of associated persons, and arrives more than a decade after organisations built their Bribery Act controls, so expectations for what counts as reasonable have risen accordingly.