Session Five: The Failure to Prevent Framework

Session Five: The Failure to Prevent Framework | Ārai Tika

Fraud and Financial Crime · Session Five

The Failure to Prevent Framework

Three prevention regimes. Four corporate offences. One architecture. Failure to prevent bribery, facilitation of tax evasion, and fraud. The adequate and reasonable procedures defences, and the six principles in practice.

Course: Fraud and Financial Crime: Legislation, Regulation and Practical Implementation Reading time: around 45 minutes Jurisdictions: UK primary, with New Zealand and Australia addressed throughout

Disclaimer

This course is provided for general information and education only. It is not legal advice. Legislation, rules and regulatory guidance change, sometimes quickly. Readers should confirm the current position and obtain jurisdiction-specific professional advice where needed. The views and experience expressed are Russel Fielding's own and do not represent any employer or client organisation.

Session Five: The Failure to Prevent Framework

The failure to prevent model is the most influential piece of corporate criminal law drafting of the last twenty years. It started as a single section in the Bribery Act 2010. It is now three prevention regimes, four statutory offences, three sets of statutory guidance, and the architecture against which corporate criminal liability is increasingly framed in the UK and internationally.

This session covers the three regimes together. The reason is practical. The architecture is closely aligned. The guidance for each regime is organised around materially similar principles, and the delivery work overlaps. An organisation that has built one of these programmes well is in a strong position to extend it to the others. An organisation that has not is exposed across the framework.

This is also the session in which the corporate offence under section 7 of the Bribery Act 2010, deferred from Session Three, is fully addressed.

Who this session is for. Compliance officers, financial crime leads, MLROs, in-house counsel, risk managers, internal audit, senior managers, board members, and programme directors with delivery responsibility for any of the three failure to prevent programmes. The session is also for transformation leads building or remediating control architecture in large regulated organisations.

Why the model exists

Until the Bribery Act 2010, prosecuting a company for an offence requiring mens rea meant proving that the directing mind and will of the organisation had committed it. For modern organisations with complex management structures and devolved decision making, that bar proved almost impossible to clear. The most public failure was the collapse of the Barclays prosecution in 2018, but the wider problem was longer running and well documented.

The failure to prevent model sidesteps the identification doctrine. It does not require the prosecution to prove that any specific person within the organisation committed the underlying offence. The corporate liability is direct. It is triggered by the commission of the underlying offence by an associated person, and is defended by the organisation showing that it had appropriate procedures in place to prevent it.

The model changes the prosecutorial question. Instead of asking whether the organisation actively participated in the offence, it asks whether the organisation took proportionate steps to prevent it. That is a question regulators can investigate and prosecutors can prove. It is also a question organisations can answer, by maintaining the kind of compliance programme described in government guidance.

The three regimes and four offences

The framework is commonly described as three prevention regimes: bribery, facilitation of tax evasion, and fraud. In statutory terms, those regimes contain four corporate offences, because the Criminal Finances Act 2017 separates UK and foreign tax evasion facilitation.

For practitioners, the useful starting point is not the label attached to each offence. It is the repeated structure: an associated person commits the underlying offence, the organisation faces direct liability, and the organisation must be able to evidence the prevention procedures it had in place at the time.

Bribery Act 2010, s.7 Failure of a commercial organisation to prevent bribery. The original offence. In force from 1 July 2011. Adequate procedures defence under section 7(2).
Criminal Finances Act 2017, s.45 Failure of a relevant body to prevent the facilitation of a UK tax evasion offence. In force from 30 September 2017. Reasonable prevention procedures defence under section 45(2).
Criminal Finances Act 2017, s.46 Failure of a relevant body to prevent the facilitation of a foreign tax evasion offence. In force from 30 September 2017. Reasonable prevention procedures defence under section 46(2). Requires a UK nexus.
ECCTA 2023, s.199 Failure of a large organisation to prevent fraud. In force from 1 September 2025. Reasonable fraud prevention procedures defence under section 199(4). Applies only to large organisations.

Section 7 of the Bribery Act has been in force for over a decade. The two Criminal Finances Act offences have been in force since 2017. The ECCTA offence is the newest, and the most recently active enforcement story. Each offence is unlimited as to fine. Each is enforceable through the standard criminal courts, with the SFO, HMRC and other prosecutors active in different parts of the framework.

Section 7 of the Bribery Act 2010

Section 7(1) provides that a relevant commercial organisation is guilty of an offence if a person associated with the organisation bribes another person, intending to obtain or retain business or a business advantage for the organisation. Section 7(2) is the defence: the organisation is not guilty if it proves that it had in place adequate procedures designed to prevent persons associated with it from undertaking such conduct.

Three points carry the practical weight.

First, a relevant commercial organisation includes any body incorporated under the law of any part of the United Kingdom, and any other body incorporated anywhere if it carries on a business, or part of a business, in any part of the United Kingdom. The territorial reach is therefore extremely wide. A foreign-incorporated company with a UK business is in scope for bribery committed by an associated person anywhere in the world.

Second, an associated person is any person who performs services for or on behalf of the organisation, regardless of legal status. Employees, agents, subsidiaries, joint venture partners, consultants and contractors are all potentially associated persons. Whether a person is an associated person is a question of fact in each case. Capacity matters more than label.

Third, the burden of proving adequate procedures sits with the organisation, on the balance of probabilities. The prosecution does not need to prove inadequacy. The organisation needs to prove adequacy. That is one of the most important features of the regime: it shifts the evidential burden.

Sections 45 and 46 of the Criminal Finances Act 2017

Sections 45 and 46 create the two corporate offences of failure to prevent the facilitation of tax evasion. Section 45 covers UK tax evasion. Section 46 covers foreign tax evasion.

Both offences have three stages. Stage one: the taxpayer has committed a tax evasion offence. Stage two: a person associated with the relevant body has facilitated that tax evasion, in their capacity as an associated person. Stage three: the relevant body has not had reasonable prevention procedures in place, or it was not reasonable in all the circumstances to expect the body to have such procedures.

The reasonable prevention procedures defence in section 45(2) and section 46(2) is closely modelled on section 7(2) of the Bribery Act, but uses the slightly looser language of "reasonable" rather than "adequate". HMRC's published guidance on the procedures relevant bodies can put in place to prevent the facilitation of tax evasion sets out the equivalent of the MoJ guidance for bribery. It is organised around materially similar principles, with terminology and emphasis adjusted for the tax evasion facilitation context.

HMRC has been the most visible enforcement body for the Criminal Finances Act offences, although the SFO and CPS can also bring proceedings. Public reporting indicates at least one charging decision under section 45 of the Criminal Finances Act 2017 and a wider pipeline of live cases and opportunities under review. Any named prosecution should therefore be treated by reference to the current public record and as ongoing if proceedings remain live.

Section 199 of the Economic Crime and Corporate Transparency Act 2023

Section 199 is the newest of the four statutory offences. It came into force on 1 September 2025. It is structured similarly to the bribery and tax evasion equivalents, but with two important differences.

First, section 199 applies only to large organisations. A body is a large organisation for these purposes if it satisfies any two of three thresholds in the relevant financial year: more than 250 employees, more than £36 million in turnover, or more than £18 million in total assets. The thresholds align with the Companies Act 2006 large company definition. Smaller organisations are outside the scope of section 199, although they remain in scope for the bribery and tax evasion offences.

Second, the offence is committed where an employee, agent, subsidiary undertaking or other associated person commits a base fraud offence intending to benefit the body or any person to whom services are provided on behalf of the body. The list of base fraud offences is set out in Schedule 13 to ECCTA 2023 and includes the Fraud Act offences, false accounting, the Theft Act 1968 offences of false statements by directors, cheating the public revenue, and several others.

The defence in section 199(4) is reasonable fraud prevention procedures. The Home Office guidance was published on 6 November 2024. It is structured around six principles that follow the MoJ and HMRC guidance closely, with adjustments for the fraud context.

The six principles

The six principles are the structural backbone of all three programmes. The terminology differs slightly between the three sets of guidance, but the substance is the same. The principles are summarised below.

Top-level commitment The leadership of the organisation is committed to preventing the relevant conduct, communicates that commitment clearly, and supports the programme in practice. Not just policy statements, but visible decisions.
Risk assessment The organisation assesses the nature and extent of its exposure to the relevant risks. The assessment is documented, periodic, dynamic, and informs the rest of the programme.
Proportionate procedures The procedures the organisation puts in place are proportionate to the assessed risks. They are clear, practical, and accessible to the people who need to use them.
Due diligence The organisation applies appropriate due diligence procedures to associated persons. The depth of due diligence is calibrated to the assessed risk that the associated person presents.
Communication and training The organisation ensures that policies and procedures are embedded and understood throughout the organisation through communication and training proportionate to the risks faced.
Monitoring and review The organisation monitors and reviews the procedures designed to prevent the relevant conduct and makes improvements where necessary.

Across the three sets of guidance, the framework is materially consistent. The Ministry of Justice guidance on bribery, the HMRC guidance on tax evasion facilitation, and the Home Office guidance on fraud all work from the same six principles. The differences are mainly in emphasis and examples.

Adequate versus reasonable: does the difference matter?

The Bribery Act uses the word "adequate". The Criminal Finances Act and ECCTA use the word "reasonable". In practice, the safer view is not to build different programmes around that drafting difference. The public guidance for all three regimes points in the same direction: proportionate, risk-based, documented, embedded and reviewed procedures.

There is still limited contested case law on these defences. In Skansen Interiors Ltd, the company was convicted after unsuccessfully relying on the adequate procedures defence under section 7 of the Bribery Act 2010. There have been no public prosecutions yet under section 199 of ECCTA. For the newer regimes in particular, the practical position is that organisations should work from the statutory language and the published guidance, rather than wait for extensive appellate authority.

For delivery purposes, the distinction does not change the job. The programme still needs a credible risk assessment, proportionate controls, usable due diligence, training that reaches the right roles, and evidence of monitoring and review. Those are the features that will matter most if the programme is tested.

Who is an associated person

All three offences turn on conduct by an associated person. The definitions are similar across the three statutes but not identical.

Bribery Act 2010, s.8 An associated person is a person (an individual or any other body) who performs services for or on behalf of the relevant commercial organisation. Capacity is determined by reference to all the relevant circumstances, not solely the nature of the relationship between the person and the organisation.
Criminal Finances Act 2017, s.44 An associated person of a relevant body is an employee, agent or other person who performs services for or on behalf of the body, acting in that capacity. The same broad definition as the Bribery Act.
ECCTA 2023, s.199(7) An associated person of a body is an employee, agent, subsidiary undertaking or other person who performs services for or on behalf of the body, acting in that capacity. This includes the body's employees acting in their capacity as employees.

Three points are worth making. First, the categories are non-exhaustive. The drafting is deliberately wide. Second, the test is functional. Whether someone is an associated person depends on what they actually do, not on what their contract says. Third, the question is judged on the facts at the time the offence was committed, not by reference to subsequent reorganisation.

Building one programme that covers three offences

The architecture is the same. The risk types are not. An organisation that builds three separate failure to prevent programmes, with three governance structures, three risk assessments, three sets of training and three sets of procedures, will spend more, learn less, and end up with weaker controls than one that builds a single integrated programme.

A working integrated programme typically has the following features.

  • A single risk assessment exercise, scoped to cover all three risks, with shared inputs (geographic risk, third party risk, sector risk, customer and counterparty risk) and offence-specific outputs (which controls address bribery, which address tax evasion facilitation, which address fraud, which address multiple).
  • A shared due diligence framework on associated persons, with depth and breadth scaled by the highest applicable risk. A third party in a high bribery risk country who provides tax-sensitive services is in scope for both the bribery and the tax evasion regime; the due diligence should reflect both.
  • A common training framework with offence-specific modules, calibrated to the role. A finance team in head office faces a different mix of fraud, tax facilitation and bribery exposures from a sales team in an emerging market. Both need training; the content differs by role, not by regulation.
  • Shared monitoring and review infrastructure. The same exception reports, the same internal audit programme, the same management information set, with offence-specific overlays where the risk profile demands it.
  • Documented, board-level top-level commitment that explicitly covers all three areas. The Bribery Act tone-from-the-top statement extended to cover fraud and tax evasion facilitation is a perfectly acceptable starting point.

Where programmes commonly fall short

Failure to prevent programmes most commonly fall short in three areas.

The first is that the risk assessment is superficial. Many organisations complete this as a desk exercise, identifying theoretical risk categories without genuinely engaging with the specific characteristics of their business, the markets they operate in, the third parties they use, and the nature of their customer relationships. A risk assessment that could belong to any organisation in the industry is unlikely to be adequate for any specific one.

The second is that the programme exists on paper but not in practice. Policies are in place, training has been completed, and a register exists. But the policy is not well understood by the people who need to apply it, the training does not address real scenarios, and the register is used inconsistently. When the programme is tested, the gap between what the documentation says and what actually happens becomes visible.

The third is that third party risk is managed inadequately. The concept of an associated person is broad. The most significant prevention risks for many businesses arise in their supply chains, agent networks and partnership relationships, particularly in international markets. Due diligence that satisfies a procurement checklist but never asks practical questions about how the third party will actually behave is not adequate procedures by any sensible reading.

Sentencing and DPAs

All three offences are punishable by an unlimited fine on the organisation. Sentencing follows the Sentencing Council's Definitive Guideline on Fraud, Bribery and Money Laundering, which contains a section on corporate offenders. The starting point is a proportion of the relevant gross profit from the conduct, with culpability and harm factors moving the sentence within and beyond the category range.

In practice, many major corporate outcomes in this area have been resolved through Deferred Prosecution Agreements rather than contested trials. Prosecutors have published guidance on corporate prosecutions, and the CPS and SFO updated their joint corporate prosecution guidance in 2025. For practitioners, the practical implication is that the conversation about cooperation and self-reporting typically arises at the same time as the question of whether the organisation has adequate or reasonable procedures. A well-documented programme makes the cooperation conversation easier. A programme that exists only on paper makes both conversations harder.

The current enforcement environment

The current enforcement picture is active but still relatively thin in decided authority. Public reporting confirms continuing section 7 work by the SFO, public activity under section 45 of the Criminal Finances Act 2017, and no public charges yet under section 199. The statutory framework is now clearer than the case law applying it.

For section 7, the practical lesson remains the same. The burden sits on the organisation to prove adequate procedures. That makes documented design, implementation and review central from the outset, not something that can be assembled after an investigation starts.

For the Criminal Finances Act offences, HMRC's public material shows that enforcement activity is no longer theoretical. The absence of a large body of reported judgments should not be mistaken for low exposure. The regime has been live since September 2017 and remains an active compliance and investigation risk.

For section 199, the position is earlier in the enforcement cycle. The offence came into force on 1 September 2025, so the immediate operational focus is programme build, refresh and evidence. Large organisations should assume that prosecutors and regulators will expect a reasoned fraud prevention framework to have been in place from commencement.

The practical consequence is straightforward. Organisations should not wait for a larger run of cases before acting. The core expectations are already visible in the legislation, the statutory guidance and the direction of enforcement activity.

Jurisdiction equivalents

Australia

Australia's failure to prevent foreign bribery offence under section 70.5A of the Criminal Code Act 1995 (Cth) came into force on 8 September 2024. The architecture is closely modelled on section 7 of the UK Bribery Act, with an adequate procedures defence. The Australian Attorney-General's Department guidance on adequate procedures draws on the UK MoJ guidance. The Australian and UK frameworks are now closely aligned in their failure to prevent architecture.

Australia does not, at the time of writing, have a direct equivalent of the UK failure to prevent fraud offence or the UK failure to prevent facilitation of tax evasion offences. Corporate liability for fraud and tax offences is dealt with under other provisions of the federal and state criminal codes.

New Zealand

New Zealand has no equivalent failure to prevent regime. Corporate liability for bribery, fraud and tax evasion is dealt with under a mix of statutory provisions and the common law identification doctrine. New Zealand has signed the OECD Anti-Bribery Convention and the UN Convention against Corruption, but the legislative model used in the UK and now in Australia has not yet been adopted in New Zealand.

Key takeaways

  • The failure to prevent framework is commonly described as three prevention regimes: bribery, facilitation of tax evasion, and fraud. In statutory terms, it contains four corporate offences: section 7 of the Bribery Act 2010, sections 45 and 46 of the Criminal Finances Act 2017, and section 199 of ECCTA 2023.
  • All three offences sidestep the directing mind and will doctrine. They create direct corporate liability, triggered by the conduct of an associated person, with a procedural defence available where the organisation can show appropriate procedures.
  • Section 199 applies only to large organisations (broadly, those meeting two of three thresholds: 250 employees, £36 million turnover, £18 million in assets). Section 7 and the Criminal Finances Act offences apply regardless of size.
  • The government guidance across the three regimes is materially consistent. It is organised around closely aligned principles: top-level commitment, risk assessment, proportionate procedures, due diligence, communication and training, and monitoring and review.
  • The practical implication for organisations is that a single integrated programme covering all three offences will be more effective and more efficient than three separate programmes.
  • Australia's failure to prevent foreign bribery offence under section 70.5A of the Criminal Code Act 1995 (Cth) is closely modelled on the UK section 7. New Zealand has no equivalent regime.

Coming up in Session Six

Session Six covers the senior manager test and the broader picture of corporate criminal liability. From the directing mind and will doctrine through section 196 of ECCTA 2023, the session explains what a senior manager means as a matter of law, why the test is functional rather than titular, and why it changes the corporate risk picture for organisations of all sizes.

Further reading and resources

The following primary sources are the most useful companions to this session. All are publicly available.

  • Bribery Act 2010, sections 7 and 8. The corporate offence and the definition of associated person. Available at legislation.gov.uk.
  • Ministry of Justice guidance under section 9 of the Bribery Act 2010. The statutory guidance on adequate procedures, updated since original publication. Available at gov.uk.
  • Criminal Finances Act 2017, sections 44 to 52. The corporate offences of failure to prevent facilitation of UK and foreign tax evasion. Available at legislation.gov.uk.
  • HMRC guidance on the corporate offences under the Criminal Finances Act 2017. Published 6 September 2017, updated 18 May 2018. Available at gov.uk.
  • Economic Crime and Corporate Transparency Act 2023, section 199 and Schedule 13. The corporate offence of failure to prevent fraud and the list of base fraud offences. Available at legislation.gov.uk.
  • Home Office guidance on the failure to prevent fraud offence. Published 6 November 2024, updated since. Available at gov.uk.
  • Joint CPS and SFO guidance on corporate prosecutions. Updated in 2025. Available through the CPS and SFO websites.
  • Sentencing Council Definitive Guideline on Fraud, Bribery and Money Laundering. In force since 1 October 2014. Available at sentencingcouncil.org.uk.
  • Bribery, Corruption and the Modern Compliance Challenge. The published companion guide on this site. Available at araitika.com.
  • Australia. Criminal Code Act 1995 (Cth), section 70.5A. Failure to prevent foreign bribery, introduced by the Crimes Legislation Amendment (Combatting Foreign Bribery) Act 2024 (Cth) and in force from 8 September 2024. Available at legislation.gov.au.

Ārai Tika

Written by Russel Fielding — LLM (Distinction), Fraud and Financial Crime · PMP · CIPM · PRINCE2 Practitioner