FAILURE TO PREVENT FRAUD: ONE YEAR ON

On 1 September 2025, the UK’s new Failure to Prevent Fraud (FTPF) offence came into force, reshaping the fraud compliance landscape for organisations operating in or with connections to the UK. This forms part of a broader move in the UK toward making it easier to prosecute companies.

The new offence is similar to the UK Bribery Act failure to prevent offence, in that it makes it significantly easier for prosecutions to be brought against a company under English law where employees, subsidiaries or third parties commit fraud for the benefit of the company or its clients.

Having in place effective fraud procedures is the only defence to the new offence and many companies have significant work to do to conduct risk assessments and put in place such procedures, including by uplifting existing policies and processes.

What is the new offence and what has changed?

Companies are now liable for fraud committed by their subsidiaries, employees or third parties where that fraud is for the benefit of the company or its clients (outward fraud). There is no requirement for the company or its senior management to be aware of the fraud.

Previously, in order for a company to be convicted for fraud-related offences, it had to be shown that a senior manager or (prior to December 2023) – the ‘directing mind and will’ of the company – was involved. In practice this made it near-impossible to prosecute large companies for fraud.

There are nine underlying fraud offences which trigger liability under the FTPF offence, the most important of which for most companies are fraud by false representation, fraud by failure to disclose information, false accounting and tax evasion.

Oct-Dec 2026 Issue

Norton Rose Fulbright LLP