ECCTA’s Failure to Prevent Fraud Offence in the United Kingdom: What “Reasonable Procedures” Now Look Like in Your Approvals & Disclosures Processes
by Murray Grainger, Senior Compliance Consultant, Case IQ
Large organisations can be prosecuted in the UK if someone acting for them commits fraud and the organisation is unable to show they had reasonable procedures to prevent it. The offence, created by section 199 of the Economic Crime and Corporate Transparency Act 2023 (ECCTA) and in force since September 2025, carries an unlimited fine. 2026 is its first full year in force.
The defence depends on evidence. This blog looks at who is in scope, what the offence covers and how your approvals and disclosures process can help you demonstrate that your compliance procedures worked.
Who’s in Scope
The offence applies to “large organisations” - meeting at least two of these three tests in the previous financial year:
- turnover of more than £36 million;
- total assets of more than £18 million; and
- more than 250 employees.
The tests can be applied across your whole group, and the organisation does not have to be UK-incorporated. A non-UK company can be caught if the underlying fraud has a UK connection, such as having activity in the UK or impacting UK victims.
What the ECCA Failure to Prevent Fraud Offence Covers
The organisation is liable when an associated person commits a specified fraud offence intending to “benefit” the organisation or its clients. Associated persons include employees, agents, subsidiaries and anyone else who performs services for or on behalf of the organisation.
The specified offences include fraud by false representation, fraud by failing to disclose information, fraud by abuse of position, false accounting, fraudulent trading and cheating the public revenue. The organisation does not need to have had actual knowledge about the fraud.
Reasonable Procedures: The Defence
Your organisation has a defence if you had reasonable fraud prevention procedures in place at the time.
UK Home Office guidance sets out six principles that shape what “reasonable” means:
- Top level commitment
- Risk assessment
- Proportionate, risk based prevention procedures
- Due diligence
- Communication including training
- Monitoring and review
Note that following the guidance is not a safe harbour. Prosecutors will look at whether procedures were proportionate to your actual risks and whether they operated in practice. The Serious Fraud Office’s November 2025 guidance on evaluating compliance programmes says it will “dig behind” high level assertions and expects companies to explain their compliance data.
UK Failure to Prevent Fraud Law: A Readiness Checklist for Compliance Officers
Download our free checklist to equip your compliance team with the expert insights and practical checklists they need to be comply with the ECCA Failure to Prevent Fraud Offence.
Where Approvals and Disclosures Fit
Conflicts of interest, gifts and hospitality and third party relationships are all classic routes to fraud that “benefits” the organisation. Think of an undisclosed interest in a supplier that inflates a contract or an agent who misrepresents a product to win business. Your approval process is where many of the UK Home Office’s six ECCTA reasonableness principles leave evidence.
Keeping evidence of your disclosure and approval volumes and outcomes by country, business unit and third party type helps you to assess where your risk lies under principle #2.
Recording your routing rules, and when and why they have changed allows you to demonstrate that your procedures are proportionate under principle #3. Normally for higher risk approval requests, thresholds should be stricter and extra approvers may be required.
Evidencing your due diligence under principle #4 is helped by screening all your third parties and counterparties both before their initial approval, then again at regular intervals during your business relationship. Attach your screening results to each such decision!
When requests are made, use this moment to remind your requesters of the relevant policy(ies). This supports principle #5—communication.
Under principle #6 (monitoring and review) track overdue, declined and escalated items and retain reports showing which controls were run including refusals. These records can provide a useful evidence trail if an investigation follows.
Five Practical Tips
- Confirm whether your group meets the large organisation test, and which entities and associated persons that brings into scope.
- Map where conflicts, gifts, hospitality and third party onboarding are approved today, including email and spreadsheets.
- Make sure screening runs before approval and that the result is stored with the decision.
- Keep a dated history of policy thresholds and approval rules.
- Report on declined and escalated requests, not just approvals.
How Case IQ Can Help
With Case IQ's Quantum Approvals & Disclosures solution automated sanctions, watchlist and adverse-media screening can be integrated directly into approval workflows, with potential matches flagged for adjudication. Case IQ also centralizes conflicts of interest, gifts and hospitality, and other approval and disclosure processes, using configurable workflows, policy thresholds and aggregate recipient or counterparty data to surface risk for review. Each request maintains a documented audit trail of approvals and compliance activity, helping demonstrate that established review procedures were consistently applied.
Book a personalized demo today to see how Quantum Approvals & Disclosures can help your compliance team streamline processes, reduce risk, and improve visibility.
Important: This post is for informational and educational purposes only. This post should not be taken as legal advice or used as a substitute for such. You should always speak to your own lawyer.
Learn More About Case IQ
Book a demo to learn about Case IQ's end-to-end suite of compliance and risk management solutions that can help your organization achieve compliance with confidence.
Frequently Asked Questions
What is the UK Failure to Prevent Fraud Offence?
The failure to prevent fraud offence was created by section 199 of the Economic Crime and Corporate Transparency Act 2023 (ECCTA). It can make a large organisation criminally liable when an associated person commits a specified fraud offence intending to benefit the organisation or its clients, unless the organisation can show that it had reasonable fraud prevention procedures in place.
Which organisations are in scope of the UK Failure to Prevent Fraud Offence?
The offence applies to large organisations that meet at least two of three tests in the previous financial year: turnover of more than £36 million, total assets of more than £18 million, or more than 250 employees. These tests can be applied across a corporate group. Non-UK organisations may also be in scope where the underlying fraud has a UK connection.
Who is considered an associated person under the Failure to Prevent Fraud Offence?
Associated persons can include employees, agents, subsidiaries, and other people or entities that perform services for or on behalf of the organisation.
What fraud offences are covered by ECCTA's Failure to Prevent Fraud Offence?
Specified offences include fraud by false representation, fraud by failing to disclose information, fraud by abuse of position, false accounting, fraudulent trading, and cheating the public revenue. The organisation does not need to have actual knowledge of the fraud for liability to arise.
What are reasonable fraud prevention procedures under ECCTA?
UK Home Office guidance identifies six principles for reasonable fraud prevention procedures: top-level commitment, risk assessment, proportionate risk-based prevention procedures, due diligence, communication including training, and monitoring and review.
Following the guidance is not an automatic safe harbour; procedures should be proportionate to the organisation's actual fraud risks and operate effectively in practice.
How can approvals and disclosures help demonstrate reasonable fraud prevention procedures?
Approvals and disclosures processes can create evidence that fraud prevention controls were applied in practice. Organisations can retain records of approval and disclosure volumes, risk-based routing rules, policy thresholds, screening results, declined and escalated requests, and monitoring activity to help demonstrate how their controls were designed, applied, and reviewed.
What records should organisations keep to support an ECCTA reasonable procedures defence?
Useful records can include a dated history of policy thresholds and approval rules, third-party and counterparty screening results, approval decisions, escalated and declined requests, overdue items, and reports showing which controls were applied. These records can help create an evidence trail if the organisation's fraud prevention procedures are later examined.
How can organisations prepare for the UK Failure to Prevent Fraud Offence?
Organisations should first determine whether they meet the large organisation test and identify the entities and associated persons in scope. They should then map existing approval processes for conflicts of interest, gifts, hospitality, and third-party onboarding, ensure relevant screening occurs before approval, retain screening and decision records, keep a dated history of approval rules and thresholds, and monitor declined and escalated requests.
Ready to Transform Your Investigation Process?
Join 80,000+ professionals who trust Case IQ to streamline their case management and ensure compliance.



