The failure to prevent fraud offence makes large organisations liable where an associated person commits fraud intending to benefit the organisation โ unless it had reasonable prevention procedures in place. This guide sets out who is in scope, the defence, and the records that evidence it.
The offence, in the Economic Crime and Corporate Transparency Act 2023, applies to large organisations โ meeting two of three thresholds under the Companies Act 2006: more than 250 employees, more than ยฃ36 million turnover, and more than ยฃ18 million in total assets. It came into force on 1 September 2025. An organisation can be liable where a person associated with it (such as an employee or agent) commits a specified fraud intending to benefit the organisation.
Legal duty โ Economic Crime and Corporate Transparency Act 2023 (failure to prevent fraud offence) ยท Home Office guidance on reasonable fraud-prevention procedures ยท In force 1 September 2025
The defence is having reasonable fraud-prevention procedures in place. The government guidance frames these around six principles, echoing the Bribery Act approach:
Principles โ Home Office guidance, "Guidance to organisations on the offence of failure to prevent fraud" (confirm the current version)
Most of the defence is about being able to show reasonable procedures were in place. Complys can already hold that evidence: the fraud-prevention policy as a versioned, read-and-acknowledged document, a risk assessment, training records, due-diligence documents (including on your supply chain via contractor compliance), and review dates with reminders. Complys does not detect or prevent fraud, and a dedicated fraud-prevention-governance module is a potential future Complys product โ the honest position today is that Complys is where the evidence lives.
Large organisations, judged by the Companies Act 2006 test โ meeting two of three: more than 250 employees, more than ยฃ36 million turnover, and more than ยฃ18 million in total assets. It applies to large bodies corporate and partnerships across sectors. Smaller organisations are outside the offence, though good fraud-prevention practice still matters commercially.
The failure to prevent fraud offence under the Economic Crime and Corporate Transparency Act 2023 came into force on 1 September 2025, after the government published its guidance on reasonable fraud-prevention procedures.
An organisation has a defence if it can show it had reasonable fraud-prevention procedures in place at the time (or that it was not reasonable to expect any). The government guidance frames reasonable procedures around principles similar to the Bribery Act's: top-level commitment, risk assessment, proportionate risk-based procedures, due diligence, communication and training, and monitoring and review.
No. Complys does not detect or prevent fraud and does not provide a dedicated fraud-governance module. What it can do today is hold the evidence a reasonable-procedures defence relies on โ the fraud-prevention policy as a versioned document, the risk assessment, training records with acknowledgement, due-diligence documents, and review dates. A dedicated fraud-prevention-procedures workspace is a potential future Complys product.
Explore: policy management software, risk assessment software, training matrix software, and contractor compliance software.