Insights

Will the UK’s new Crime Act create real opportunities to prosecute fraud?


There is concern that senior managers in England and Wales may now find themselves under considerably greater personal and professional pressure due to changes in the Crime and Policing Act.

Since June this year, a UK company or partnership can be convicted of a criminal offence committed by one of its senior managers, provided that the manager was acting within the actual or apparent scope of their authority.

The Crime and Policing Act 2026 (CPA) extends the statutory “senior manager” attribution model beyond the economic offences previously covered by the Economic Crime and Corporate Transparency Act 2023 (ECCTA). The new test now captures most aspects of UK criminal law.

This reform is intended to bring corporate criminal liability into line with modern organisational structures, where important decisions are often dispersed across divisions, jurisdictions, and management functions, rather than concentrated exclusively in the boardroom.

For those of us who have spent decades investigating fraud, corruption, and the concealment of corporate wrongdoing, this is a significant and overdue reform. Investigations can sometimes wither on the vine, as managers hide their wrongdoing or negligence by claiming ignorance of either events, the actions of their colleagues, or their responsibilities.

The standard defense for managerial suspects implicated in criminality tends to be “ignorance.” This can be almost impossible to break down. Prosecutors seeking to convict a company of an offence require proof of knowledge, dishonesty, intention, or recklessness to identify an individual who represented the organisation’s “directing mind and will.”

In a small owner-managed company, that individual is easy to identify. In a multinational corporation, however, responsibility may be divided between the board, executive committees, and regional management. Compliance functions may be similarly diversified among specialists. The larger and more decentralised the organisation, the harder it is to identify a single controlling mind whose criminal conduct can be attributed to the firm.

Historically, this fact has led to unsatisfactory disparities. Smaller businesses could be prosecuted due to their simpler managerial structure, while larger organisations often avoided attribution because of their fragmented and inbuilt governance arrangements.

The ECCTA sought to address this problem by allowing specified economic crimes committed by senior managers to be attributed to the organisation. The new CPA completes this process by extending the model to all criminal offenses.

But who is a senior manager in the context of this new law? It would appear functional rather than dependent upon title. According to the new CPA, a senior manager is an individual who plays a significant role in:

  • making decisions about how the whole or a substantial part of the organisation’s activities are managed or organised; or
  • managing or organising the whole or a substantial part of those activities.

It stands to reason that analysis must therefore concentrate on what the individual really does, not merely what appears on their business card.

Clearly CEOs will be candidates, but depending upon the organisation, the definition may also capture regional directors, heads of compliance, data protection officers, and so on.

The UK government presents this as providing greater clarity, because it focuses on the degree of managerial influence rather than formal status, which is broadly correct. It is more realistic than pretending that all meaningful corporate decisions originate at board level.

Yet the concept of a “substantial part” of an organisation remains open to conjecture, and therefore an evidential burden to be overcome. What constitutes a substantial part of an organisation – such as an international bank, a law firm, or an international charity – will differ considerably.

Whether the legislation proves successful (or not) should be measured by its ability to identify the decision-making processes behind corporate offending and hold the correct organisations and individuals to account.

Corporate liability arises where a senior manager commits an offense while acting within the actual or apparent scope of their authority. However, this does not mean that the company has authorised the criminal conduct. A chief financial officer will rarely be authorized to falsify accounts. Preparing and approving financial information does fall within the ordinary scope of that officer’s functions. However, if they dishonestly manipulate that information, the offence may consequently be attributed to the company.

This distinction is critical. A corporate policy stating that employees must obey the law will not, by itself, place criminal conduct outside the scope of authority. Nor can an organisation necessarily escape liability by demonstrating that a manager breached an internal policy while carrying out an otherwise authorised function.

From a management and governance perspective, the reform has several advantages:

  • First, it establishes a more intelligible attribution test, with investigators no longer needing to engage in an artificial search for a single directing mind.
  • Second, it encourages organisations to properly document authority, spelling out reporting lines, delegated powers, and approval thresholds. These policies will become integral evidence in determining whether an individual was a senior manager and whether the conduct fell within their authority.
  • Third, it removes the structural advantage previously enjoyed by large, decentralised organisations. Complexity should not become a defence to criminal accountability.
  • Finally, it should improve accountability for conduct causing serious public harm, with corporate offending no longer confined to financial crime.

The concern is that senior managers may now find themselves under considerably greater personal and professional pressure. Although the legislation does not create blanket personal criminal liability merely because an individual is described as a “senior manager,” the prosecution must still prove that the individual committed the underlying offence, including the requisite mens rea element.

Although the company and the individual may initially appear to share an interest in establishing what happened, their positions may then sharply diverge. The organisation may seek to show that the manager acted outside their authority, concealed information, or disregarded instructions. The manager may argue that the conduct reflected accepted commercial practice, institutional pressure, or directions from more senior personnel.

It may be that this conflicting interest will create difficult questions concerning legal representation, privilege, and access to documents. Managers should not assume that lawyers appointed by the company also represent them personally. Scapegoating may become an issue.

I would anticipate that this latest raft of legislation will inadvertently create a risk of defensive management, like that created by anti-money-laundering regulations that saw an increase in “just in case” Suspicious Activity Reports.

Unlike the ECCTA’s failure-to-prevent-fraud offense, section 250 of the CPA contains no statutory defense based upon reasonable or adequate procedures. A company may find itself falling foul, even where it had a meaningful compliance structure in place.

This does not render compliance irrelevant. Strong systems may prevent an offense or identify it sooner. In addition, it may influence the ultimate decision whether a prosecution is in the public interest, not to mention sentencing. This may demonstrate to the prosecution that the conduct was exceptional rather than culturally tolerated.

However, organisations need to appreciate that policies and training are risk controls, not defences. Furthermore, Baker McKenzie has observed that deferred prosecution agreements (DPAs) may not be available for many of the non-economic offenses now brought within the attribution regime.

The new law is thus a welcome correction. It seeks to provide greater clarity, removing an unjustifiable advantage for complex organisations, giving prosecutors (and asset recovery lawyers) a more credible route to corporate accountability.

But enforcement must remain evidence-led and fair. Corporate and individual culpability are related concepts, so they are not interchangeable. Whether the legislation proves successful (or not) should be measured by its ability to identify the decision-making processes behind corporate offending and hold the correct organisations and individuals to account. Not by how many managers are investigated.

To provide some context, three years after its enactment there have been no prosecutions under the ECCTA, which may speak to inherent evidential difficulties.

Where both these Acts will hopefully have a positive impact is in strengthening the arms of regulators and lawyers seeking recompense for victims on the lower burden balance of probabilities. The issue of proving criminality beyond all reasonable doubt remains.

This article was originally published by GRIP.


England's new Crime and Policing Act is a welcome correction, but enforcement must remain evidence-led and fair, says Tony McClements.

Tony McClements

Head of Investigations



Global Asset Recovery