Preventing Fraud
A new Act aimed at preventing fraud has just come into force. Lana Wilks from our Commercial Litigation team looks at the details.
The Economic Crime and Corporate Transparency Act 2023 (“ECCTA”) introduces a new corporate offence of “failure to prevent fraud”, which came into force on 1 September.
This offence is designed to hold large organisations liable where they fail to prevent certain fraud or false accounting offences committed by persons associated with them, for the organisation’s benefit. The introduction of this offence significantly lowers the threshold for prosecuting organisations, as it is no longer necessary to prove the involvement of a “directing mind and will”.
A core aspect of the offence, is that to be convicted, the fraud must have been committed with the intention of benefitting the organisation or clients of the organisation. This can be a stand-alone intent or accompanied by an intent to benefit the associated person personally.
The “benefit” aspect does not have to be of financial gain, or any gain at all – just the intent to receive a benefit.
Scope of the Offence
The new offence covers a wide range of fraud and false accounting offences, including:
- Fraud by false representation (section 2, Fraud Act 2006)
- Fraud by failing to disclose information (section 3, Fraud Act 2006)
- Fraud by abuse of position (section 4, Fraud Act 2006)
- Obtaining services dishonestly (section 11, Fraud Act 2006)
- Participation in a fraudulent business (section 9, Fraud Act 2006)
- False statements by company directors (section 19, Theft Act 1968)
- False accounting (section 17, Theft Act 1968)
- Fraudulent trading (section 993, Companies Act 2006)
- Cheating the public revenue (common law)
Money laundering offences are expressly excluded, as organisations are already subject to separate anti-money laundering obligations and regulatory oversight by the Financial Conduct Authority.
Dishonesty
The offences caught under ECCTA use a dishonesty test, which has also changed recently.
Previously, the test for dishonesty was an objective one that considered whether conduct would be considered dishonest by the standard of an ordinary person, with a second limb being whether the defendant knew that conduct was dishonest.
In contrast, the test now considers the defendant’s actual state of knowledge of the relevant facts, and therefore if that conduct was dishonest by the standards of an ordinary person.
The core difference is that previously, if a defendant could argue that they did not see their conduct as dishonest, and had a distorted sense of “dishonesty”, they were less likely to be convicted. The recent change provides a higher conviction rate.
Organisations in Scope
The offence applies to all “large” corporate bodies, partnerships (including LLPs), subsidiaries, charities, and public bodies across all sectors. An organisation is considered “large” if it meets at least two of the following criteria:
- More than 250 employees
- Turnover exceeding £36 million
- Total assets exceeding £18 million
Group Companies: Where a parent company and its subsidiaries, taken together, meet the size threshold, the group will fall within the scope of the offence. Liability may attach to the entity directly responsible for the failure, or to the parent company if the fraud was committed by a subsidiary employee for the parent’s benefit and the parent failed to take reasonable steps to prevent it.
Penalties
Upon conviction, an organisation faces an unlimited fine. The court will determine the appropriate level of fine based on the circumstances of the case.
Individual Liability
The ECCTA does not introduce individual criminal liability for directors or officers solely on the basis of a company’s conviction for failure to prevent fraud. However, individuals remain liable for substantive fraud offences, or for encouraging or assisting fraud.
Defence
An organisation will have a defence if it can demonstrate that, at the time the fraud was committed:
- It had in place reasonable procedures to prevent fraud, or
- It was not reasonable in all the circumstances to expect the organisation to have any prevention procedures in place.
The Government will issue guidance, based on six flexible and outcome-focused principles, to assist organisations in developing and implementing appropriate procedures.
Practical Steps for Compliance
Organisations are encouraged to:
- Assess Fraud Risks: Identify and evaluate specific fraud risks relevant to the business, including risks posed by associates.
- Implement Reasonable Procedures: Develop and tailor procedures to address identified risks.
- Communicate and Train: Ensure procedures are communicated throughout the organisation and provide relevant training.
- Monitor and Review: Regularly review and update procedures to ensure ongoing effectiveness.


