One year of Failure to Prevent Fraud. What should firms be doing now?

This week marks one year since the Failure to Prevent offence came into force under the Economic Crime and Corporate Transparency Act 2023. While we haven’t seen a wave of headline prosecutions, it would be a mistake to conclude that the offence hasn’t had an impact.

For large organisations*, fraud prevention has moved further up the corporate agenda and with it, the need to demonstrate that reasonable steps have been taken to prevent fraud.

As a reminder, the offence creates potential criminal liability where an associated person commits certain fraud offences intending to directly or indirectly benefit the organisation or someone it provides services to.

An organisation’s key defence is asking the uncomfortable question: if fraud happened tomorrow, could we demonstrate that we had reasonable fraud prevention procedures in place? It’s not simply enough to have a Policy sitting on Sharepoint.

What should firms be doing one year in?

  • Re-examine your exposure. Agents, intermediaries, contractors and other associated persons can create significant exposure. Are you confident you understand where those risks sit across your business? 

  • Refresh the fraud risk assessment. Does it reflect your business as it operates today including new products, markets, customers and third parties? How does the risk assessment identify the firm’s key fraud risks and tailor anti-fraud controls accordingly?

  • Test your controls. Having a policy is not the same as having an effective control environment. Can you demonstrate that your procedures work? How have your controls been tested for effectiveness? 

  • Focus on evidence. Training records, risk assessments, due diligence, approvals, monitoring, whistleblowing arrangements, reporting, investigations, and management oversight can all help demonstrate that reasonable procedures were genuinely embedded (and not just documented).

  • Get the board engaged if they’re not already. Fraud prevention shouldn't sit solely with Legal or Compliance. It is a business risk and should be treated accordingly. If they’re not already engaged, fraud prevention needs Board-level attention.

Resource: Understanding the New Failure to Prevent Fraud Offence

How FINTRAIL can help

A year on, the firms in the strongest position aren't just documenting fraud prevention, they're testing it. FINTRAIL can help you pressure-test your exposure, refresh your risk assessment, assess whether your controls actually work, and build the evidence base to prove it.

If you're not confident you could answer the "reasonable procedures" question today, get in touch with FINTRAIL and our Head of Fraud, Francesca Pammer.


*A ‘large’ organisation is defined as meeting two or three out of the following criteria: (1) more than 250 employees; (2) more than £36 million turnover; (3) more than £18 million in total assets. Gov UK guidance confirms that ‘these criteria apply to the whole organisation, including subsidiary undertakings, regardless of where the organisation is headquartered, or where its subsidiary undertakings are located’.