blog

Failure to Prevent Fraud: What Are 'Reasonable Procedures' and How Can You Prepare?

The new corporate crime regulation that could catch you off guard

From September 1, 2025, the Failure to Prevent Fraud offence under the Economic Crime and Corporate Transparency Act 2023 came into effect. It follows the UK's existing Failure to Prevent Bribery (2011) and Failure to Prevent Facilitation of Tax Evasion (2017) laws. Your company could be criminally liable — even if leadership was unaware of the fraud.

Does this law apply to you?

If your organisation meets two or more of these criteria, you're in scope:

  • More than 250 employees
  • More than £36 million turnover
  • More than £18 million total assets

It applies to fraud committed by employees, agents, subsidiaries and anyone providing services for your business. Your only defence: proving you had 'reasonable procedures' in place to prevent fraud. A Government guidance document was published November 2024. [Summary available at cognexo.com/wp-content/uploads/2025/02/Failure-to-Prevent-Fraud-Gov-Guidelines.pdf]

Why take action now?

  • Law took effect: September 1, 2025
  • Guidance published: November 2024
  • Preparation period: 23 months (vs. just 5 months for the 2017 tax evasion law)

The high stakes

  • Criminal liability for your organisation — even if senior leaders were unaware
  • Unlimited fines if convicted
  • Severe reputational damage from prosecution
  • No personal liability for directors — but responsibility to implement protections

What makes procedures 'reasonable'? The government's six key principles:

  1. Top-level commitment — assign a senior executive/board member to lead fraud prevention; allocate a dedicated budget; ensure clear accountability
  2. Risk assessments — conduct formal fraud risk assessments, update regularly; identify high-risk areas (e.g. aggressive sales incentives, complex supply chains)
  3. Proportionate risk-based procedures — the bigger and more regulated your company, the more is expected; sectors like finance, healthcare and energy face higher scrutiny; document why certain risks are higher/lower
  4. Due diligence — screen employees, suppliers and agents for red flags; build fraud prevention clauses into contracts; monitor workload and stress factors
  5. Communication and training — policies must be "embedded and understood throughout the organisation"; regular fraud-specific training (not just a one-off); track engagement
  6. Monitoring and review — update policies regularly; investigate fraud incidents rigorously; keep detailed records of all training programmes and risk assessments

Government note: "It may be deemed reasonable not to introduce measures in response to a particular risk. However, it will rarely be considered reasonable not to have even conducted a risk assessment."

Four steps you can take immediately

  1. Assign a fraud prevention lead (senior executive or board member)
  2. Designate a fraud prevention budget with documented rationale
  3. Invest in high-impact areas — training, technology and compliance systems
  4. Document every decision — show how you assessed risks and took action, signed off by senior stakeholders

Using technology to prove your policies work

The government stresses policies must be "embedded and understood throughout the organisation." The best defence is an audit trail proving continuous training, policy updates and engagement tracking. Cognexo provides: bite-sized, gamified daily learning; adaptive learning that assesses each learner's knowledge and optimises content; automated tracking to prove every employee has engaged; seamless integration into daily workflows.

Related Post