Ethics Insight writing

What the UK's Failure to Prevent Fraud Offence Means for Portfolio Companies

A plain-English guide to when the offence is likely to matter, what investors should ask, and why smaller businesses should not ignore it.

Since 1 September 2025, the UK has had a corporate offence of failure to prevent fraud. That sentence alone is enough to make many boards and portfolio-company leaders either panic or switch off.

Neither reaction helps.

The sensible question is simpler: does this change anything practical for the businesses you own, back, or advise?

In some cases, yes. In others, not directly. But even where a business is unlikely to be in scope today, the offence is still a useful prompt to tighten fraud prevention before growth makes that harder.

Source note: this article reflects the UK Home Office guidance on the offence of failure to prevent fraud, updated 10 October 2025, and the Economic Crime and Corporate Transparency Act 2023.

What the offence does

Under the Economic Crime and Corporate Transparency Act 2023, a large organisation can be criminally liable if an employee, agent, subsidiary undertaking, or another associated person commits a specified fraud offence intending to benefit the organisation, and the organisation did not have reasonable fraud prevention procedures in place.

Two points matter straight away.

First, this is not limited to situations where directors ordered the fraud. The Home Office guidance is explicit that the prosecution does not need to show that senior managers knew about it.

Second, the issue is not only direct employees. The offence is framed around associated persons who provide services for or on behalf of the organisation. That should make investors and operating teams think carefully about where business is really being done through intermediaries, subsidiaries, distributors, introducers, or delegated commercial relationships.

Who is in scope?

The offence applies to large organisations only. Broadly, that means an incorporated body or partnership that meets at least two of the following thresholds:

For groups, the assessment can be made across the wider organisation, not only the individual operating company you happen to be looking at.

That is where some portfolio companies may get caught out. A standalone investee may look too small. But if it sits inside a larger group structure, the position may be different. This is one reason the scope question should go to legal counsel early rather than being waved away by management.

What counts as a good response?

The official guidance is helpful here. It sets out six principles that should inform reasonable fraud prevention procedures:

This is useful because it pushes the conversation away from box-ticking. A company does not become safer because it pasted “zero tolerance” into a policy. It becomes safer when it has looked at how fraud could arise in its own business model and built sensible controls around that reality.

What investors should ask portfolio companies

Start with five practical questions.

  1. Are we in scope now, or likely to be soon?

Do not leave this to assumption. Check the thresholds properly, especially where growth, consolidation, or group structures muddy the picture.

  1. Where could someone commit fraud for the company’s benefit?

Think beyond finance-team stereotypes. Sales, procurement, channel partners, contract managers, project teams, and country leadership may all face pressure points where fraud can be rationalised as helping the business.

  1. Which associated persons create the greatest exposure?

If the business relies heavily on agents, introducers, distributors, or subsidiaries operating with patchy oversight, those relationships deserve attention.

  1. What evidence exists that prevention procedures work in practice?

Ask for examples of training, approvals, escalation routes, monitoring, investigations, and changes made after issues were found.

  1. Who owns review and improvement?

Fraud prevention decays quickly when it sits in a document nobody revisits.

Why smaller businesses should still care

Some portfolio companies will conclude, correctly, that they are not in scope today. That should not end the discussion.

The same guidance says its principles may still be helpful as good practice for smaller organisations. That makes sense. Most growing businesses eventually discover the awkward gap between informal trust and scaled control. Authority gets delegated. Markets widen. Third parties multiply. A founder can no longer see every payment, promise, or workaround.

If you wait until the business is unquestionably large before building a fraud-prevention framework, you are doing the hardest bit late.

A better way to use the offence

For investors, this is less about legal theatre and more about readiness.

If a portfolio company is in scope, it should get legal advice and treat the offence seriously. If it is close to scope, use this as a chance to build procedures that can scale. If it is nowhere near the thresholds, borrow the discipline anyway and keep it proportionate.

That usually means focusing on real pressure points:

The law will matter most to larger organisations. But the underlying question is relevant much more widely: if somebody committed fraud while trying to help this business, what would have stopped them?

If leadership cannot answer that with confidence, the problem is already here, whether the statute applies yet or not.

More Ethics Insight writing