Fraud and Financial Crime · Session One
Introduction and the Financial Crime Landscape
How corporate accountability for financial crime has changed in the UK, what that change has meant in practice, and why the current period matters.
Disclaimer
This course is provided for general information and education only. It is not legal advice. Legislation, rules and regulatory guidance change, sometimes quickly. Readers should confirm the current position and obtain jurisdiction-specific professional advice where needed. The views and experience expressed are Russel Fielding's own and do not represent any employer or client organisation.
Session One: Introduction and the Financial Crime Landscape
Financial crime compliance is going through its most significant period of change in more than a decade. Corporate criminal liability has been redrawn. The failure to prevent model, once confined to bribery and the facilitation of tax evasion, now covers fraud.
Since 29 June 2026, an organisation can also be criminally liable if one of its senior managers commits an offence while acting within the actual or apparent scope of their authority, with no defence of reasonable procedures available.
That is the environment in which practitioners are now working. The changes are substantial, and they are still bedding in.
Who this session is for. This session is for compliance officers, financial crime leads, MLROs who carry fraud, bribery and market abuse risk as well as money laundering risk, risk managers, in-house counsel, senior managers, board members, and programme directors with delivery responsibility for financial crime work.
What this course covers and what it does not
Financial crime is a broad category. The term is used loosely across the industry and across regulators, and it overlaps with adjacent areas, including money laundering, market integrity, cybercrime and tax compliance. The scope of this course is:
- Fraud under the Fraud Act 2006, the related Theft Act 1968 offences, the Computer Misuse Act 1990, and the common law offence of cheating the public revenue.
- Bribery and corruption under the Bribery Act 2010, including the corporate offence under section 7.
- Insider dealing and market abuse under Part V of the Criminal Justice Act 1993 and the UK Market Abuse Regulation.
- The failure to prevent framework across bribery (Bribery Act 2010, section 7), facilitation of tax evasion (Criminal Finances Act 2017, sections 45 and 46) and fraud (Economic Crime and Corporate Transparency Act 2023, section 199).
Money laundering is not covered in this course except where it intersects with fraud or the movement of fraud proceeds. The AML Compliance course covers anti-money laundering compliance from legislative foundations through to daily operational practice. Where this course refers to AML obligations, it points to that course for depth.
Why the landscape has changed so quickly
Three shifts explain most of the change in the corporate financial crime picture over the last decade, and all three have accelerated in the last two years.
The move from individual to corporate accountability
For most of the twentieth century, prosecuting a company for an offence requiring mens rea, a guilty mind, meant proving that the directing mind and will of the organisation had committed it. In practice, that usually meant a board director or someone with equivalent control.
For modern organisations with complex management structures and devolved decision-making, that bar proved difficult to clear. The limits of the doctrine became increasingly hard to ignore as organisations grew in scale and complexity. The Barclays litigation remains a high-profile illustration: the courts declined to treat the relevant senior officers as the bank's directing mind and will for the purposes of the charges before them.
How the failure to prevent model spread
The failure to prevent model has proven to be one of the most influential pieces of legislative design of the last two decades. Bribery first, in 2010. Facilitation of tax evasion in 2017 and fraud in 2023, in force from 1 September 2025. The architecture is consistent: corporate liability is triggered where an associated person commits the underlying offence for the organisation's benefit, with a defence available where the organisation can demonstrate adequate or reasonable procedures in place to prevent it.
The model works because it changes the prosecutorial question. Instead of asking whether the organisation actively participated in the offence, it asks whether the organisation took proportionate steps to prevent it. That is a question investigators can test, prosecutors can put before a court, and organisations can answer through a documented, implemented and reviewed compliance programme.
Each of the three failure to prevent offences has its own government guidance, and each is structured around six broadly similar principles: top-level commitment, risk assessment, proportionate procedures, due diligence on associated persons, communication and training, and monitoring and review. The terminology differs in places (adequate procedures for bribery, reasonable procedures for tax evasion and fraud), but the architecture is the same. Session Five works through the framework in detail.
Why enforcement now feels more active
The third shift is enforcement. The Serious Fraud Office has been explicit that failure to prevent fraud will be used. On 17 April 2025, the SFO charged United Insurance Brokers Limited under section 7 of the Bribery Act 2010, alleging bribes of around USD 3 million paid to Ecuadorian state officials to secure reinsurance contracts worth USD 38 million. Should the case proceed to trial, it will be the first section 7 case heard by a jury. It remains an ongoing prosecution and should be understood on that basis. More broadly, the joint SFO and CPS corporate prosecution guidance was updated in August 2025 to reflect the failure to prevent fraud offence and the senior manager attribution test. The direction is clear: corporate financial crime enforcement is becoming more active.
HMRC has also begun to use its corporate offences. Bennett Verby Ltd, an accountancy firm, has been charged under section 45 of the Criminal Finances Act 2017 in connection with an alleged research and development tax credit fraud, alongside charges against individuals including cheating the public revenue and money laundering. It has been widely reported as the first corporate prosecution under the failure to prevent facilitation of tax evasion regime. It remains an ongoing case, with a provisional trial listed for September 2027.
The current UK anti-corruption strategy sets out the government's strategic approach to corruption at home and overseas. Taken together, these developments point to a more active enforcement environment than practitioners have worked in for some time.
The four offences in outline
Each of the four offences in the scope of the course has its own session in detail, but it is worth seeing them together at the outset.
Session Two: Fraud
Fraud remains the most commonly experienced crime in England and Wales. Recent Crime Survey for England and Wales data continues to put fraud at a substantial share of all crime, with millions of estimated incidents each year.
The Fraud Act 2006 is the primary legislative instrument. It creates the three core offences of fraud by false representation, fraud by failing to disclose information, and fraud by abuse of position. Related offences in the Theft Act 1968 cover false accounting and false statements by company directors. The Computer Misuse Act 1990 covers cyber-enabled fraud involving unauthorised access to a computer system. The common law offence of cheating the public revenue remains available for serious tax fraud cases.
Fraud also engages the regulatory framework. The Payment Systems Regulator's mandatory reimbursement rules for in-scope APP fraud took effect on 7 October 2024, changing the economics of fraud prevention for payment service providers. The FCA Consumer Duty directly affects how firms prevent and respond to fraud, particularly where vulnerable customers are involved. The Online Safety Act 2023 imposes duties on online platforms regarding fraudulent content. The failure to prevent fraud offence under section 199 of ECCTA, in force since 1 September 2025, sits alongside all of this.
Session Three: Bribery and corruption
The Bribery Act 2010 remains the central UK statute on bribery and corporate anti-bribery controls. Section 1 is the general offence of bribing another person, section 2 is the offence of being bribed, section 6 is the specific offence of bribing a foreign public official, and section 7 is the corporate offence of failing to prevent bribery. The Act applies extraterritorially, reaching conduct outside the UK where the statutory connection to the UK is made out.
Adequate procedures are the only defence available under section 7. The Ministry of Justice guidance sets out the six principles that characterise adequate procedures. The wider international anti-bribery framework around the Bribery Act includes the OECD Anti-Bribery Convention, the UN Convention against Corruption, the US Foreign Corrupt Practices Act 1977, and ISO 37001, the international standard for anti-bribery management systems.
Session Four: Insider dealing and market abuse
Insider dealing and market abuse operate under two parallel regimes in the UK. The criminal offence of insider dealing is contained in Part V of the Criminal Justice Act 1993, sections 52 to 64. The civil regime is the UK Market Abuse Regulation, retained in UK law from 31 December 2020, having been onshored from the EU regulation that took effect on 3 July 2016. Article 14 of UK MAR prohibits insider dealing, recommending or inducing another person to engage in insider dealing, and the unlawful disclosure of inside information. Article 15 prohibits market manipulation. Article 16 requires the reporting of suspicious transactions and orders.
The FCA has discretion to pursue insider dealing as either a civil matter under UK MAR or as a criminal offence under the Criminal Justice Act 1993, and often opens cases on a dual-track basis. Criminal sanctions for insider dealing and market manipulation can include custodial sentences of up to ten years and unlimited fines. The civil regime carries unlimited financial penalties.
The developing market abuse regime for cryptoassets is expected to extend market abuse style obligations to a new asset class as the legislative and regulatory framework is finalised.
Session Five: The failure to prevent framework
The failure to prevent framework is, in 2026, made up of three corporate offences:
| Bribery Act 2010 | Section 7. The original corporate offence: failure of a commercial organisation to prevent bribery by an associated person. Adequate procedures defence. |
| Criminal Finances Act 2017 | Sections 45 and 46. Failure to prevent the facilitation of UK tax evasion and failure to prevent the facilitation of foreign tax evasion. Reasonable procedures defence. |
| ECCTA 2023, s. 199 | Failure to prevent fraud. In force from 1 September 2025. Applies to large organisations. Reasonable procedures defence. |
Each offence has its own government guidance. Each set of guidance is structured around six principles that are recognisably similar but not identical. Each defence carries the same fundamental architecture: the organisation needs to demonstrate that it had a proportionate, documented, implemented and reviewed compliance programme in place at the time of the underlying offence.
The senior manager test and why it matters now
Failure to prevent is not the only route into corporate criminal liability. Section 196 of the Economic Crime and Corporate Transparency Act 2023 introduced a statutory senior manager attribution test for specified economic crime offences. From 26 December 2023, an organisation has been criminally liable where a senior manager commits one of the offences listed in Schedule 12 of ECCTA while acting within the actual or apparent scope of their authority. That list includes fraud, false accounting, bribery, money laundering, sanctions and tax offences.
Section 250 of the Crime and Policing Act 2026 replaces section 196 of ECCTA and extends the senior manager attribution model to every criminal offence. It came into force on 29 June 2026. The implications are significant.
- First, the test is no longer limited to economic crime. It can apply across the criminal law where a senior manager commits an offence within the actual or apparent scope of their authority.
- Second, there is no reasonable procedures defence. Unlike the failure to prevent offences, an organisation cannot defend itself by showing that it had a robust compliance programme in place. If the test is met, liability attaches.
- Third, there is no general requirement that the organisation benefited from the conduct. An organisation may be criminally liable for an offence committed by a senior manager even where the organisation did not gain from the conduct, provided the offence was committed within the actual or apparent scope of the senior manager's authority.
- Fourth, the test is not restricted to large organisations. Failure to prevent fraud applies only to large organisations, broadly those exceeding two of three thresholds: 250 employees, £36 million turnover, £18 million in assets. The senior manager test under section 250 has no such restriction. It applies to organisations of all sizes across all sectors.
A senior manager is defined functionally, not by title. It captures any individual who plays a significant role in decisions about how the whole or a substantial part of the organisation's activities are managed or organised, or in the actual managing or organising of those activities. Whether someone is a senior manager is a question of fact. In practice, the definition may extend well below board level. Session Six examines this in detail.
How the course is organised
The nine sessions are designed to be read in sequence. They are also designed to be useful on their own. The structure follows the same logic as the AML Compliance course on this site: legislative foundations first, then the regulatory layer, then practical implementation.
The first six sessions cover the law. This session, the introduction, sets the frame. Session Two covers the fraud offences. Session Three covers bribery. Session Four covers insider dealing and market abuse. Session Five covers the failure to prevent framework across all three offences. Session Six covers the senior manager test and the broader picture of corporate criminal liability.
The implementation sessions cover the financial crime risk assessment, the design and operation of the programme, and the consolidated implementation checklist. Together, they move from risk assessment to governance, controls, training, whistleblowing, intelligence sharing, assurance and practical evidence.
Session Nine is the implementation summary: a consolidated obligations checklist cross-referenced to legislation and common failure modes, and a working reference to be returned to. Each session ends with a brief Key Takeaways box, a pointer to the next session, and a Further Reading section listing the primary sources for that session. Where relevant, each session also includes a Jurisdiction Equivalents section addressing New Zealand and Australia.
Jurisdiction equivalents
The course is principle-led, so it is useful to any practitioner of fraud and financial crime. The examples are UK-led, with New Zealand and Australia also addressed in each session where the framework differs, and depth scaled to the extent to which the regime diverges from the UK position. This session sets out the broad picture, with the specifics dealt with in the relevant later sessions.
New Zealand
Fraud primarily falls within the Crimes Act 1961, particularly sections 240 to 243 (obtaining by deception, causing loss by deception), section 256 (forgery), and a range of related offences. The Secret Commissions Act 1910 covers the historic offence of taking secret commissions, although in practice the Crimes Act provisions on corruption do most of the work today. Bribery is addressed in sections 99 to 106 of the Crimes Act, covering judicial corruption, corruption of ministers, members of Parliament and law enforcement, and the bribery of foreign public officials under section 105C. Insider conduct in financial markets is covered by Part 5 of the Financial Markets Conduct Act 2013, particularly subpart 1, which deals with insider conduct.
New Zealand does not have a direct equivalent of the UK's failure to prevent framework. A mix of statutory provisions and the common law identification doctrine governs corporate liability. The Serious Fraud Office is the lead agency for serious or complex financial crime, with the Financial Markets Authority leading on market conduct, including enforcement of insider trading.
Australia
Fraud is covered at the federal level under the Criminal Code Act 1995 (Cth), particularly in divisions 134 (obtaining property or financial advantage by deception) and 135 (general dishonesty offences). State and territory criminal codes cover other forms of fraud. Bribery of a Commonwealth public official is covered under sections 141 and 142 of the Criminal Code, and the foreign bribery offence under section 70.2. Australia introduced a corporate failure to prevent foreign bribery offence under section 70.5A of the Criminal Code, in force from 8 September 2024. The defence is one of adequate procedures, broadly mirroring the UK Bribery Act section 7 architecture.
Insider trading and market misconduct are covered by Part 7.10 of the Corporations Act 2001 (Cth), with the prohibition on insider trading at section 1043A. The Australian Securities and Investments Commission is the lead enforcement agency for market conduct. Australia's AML/CTF framework is also changing. Practitioners should work from the current compiled legislation, current Rules, AUSTRAC guidance and any applicable transitional instruments.
Key takeaways from Session One
- Corporate criminal liability in the UK has changed more in the last three years than in the previous thirty. The failure to prevent fraud offence, in force from 1 September 2025, and the senior manager attribution model under section 250 of the Crime and Policing Act 2026, in force from 29 June 2026, are the defining changes.
- The course covers four offence areas: fraud, bribery and corruption, insider dealing and market abuse, and the failure to prevent framework. Money laundering falls under the AML Compliance course; tax evasion is treated only as it appears in the failure to prevent framework.
- Each of the three failure to prevent offences has its own government guidance, but the architecture is consistent across all three. An organisation that has built its anti-bribery programme well is in a strong position to extend the same architecture to the other offences.
- The senior manager test under section 250 of the Crime and Policing Act 2026 carries no reasonable procedures defence, no benefit requirement, and no large organisation threshold. It extends across criminal offences and applies to organisations of all sizes.
- The course is UK-led, with New Zealand and Australia treated where the framework differs. Australia has had its own failure to prevent foreign bribery offence in force since September 2024. New Zealand has no direct equivalent regime.
Coming up in Session Two
Session Two covers the fraud offences in detail. It works through the Fraud Act 2006, addresses the related offences under the Theft Act 1968 and the Computer Misuse Act 1990, and explains how prosecutors choose between offences.
It also provides a high-level survey of the main fraud types practitioners will encounter, with the published Scam Shield guide as the deeper reference on consumer fraud, the APP fraud reimbursement regime, vulnerable customers, and AI as both a fraud enabler and a fraud detector.
Further reading and resources
The course relies on primary legislation, statutory guidance, regulator materials and public enforcement announcements. Where a case is ongoing, it is described only by reference to the public charge or announcement. No view is expressed on guilt, liability, merits or likely outcome.
These primary sources are the most useful companions to this session. All are publicly available.
- Economic Crime and Corporate Transparency Act 2023. Read section 196 on the senior manager attribution test for specified economic crime offences, in force from 26 December 2023, and section 199 on failure to prevent fraud, in force from 1 September 2025. Available at legislation.gov.uk.
- Crime and Policing Act 2026. Read section 250 on criminal liability of bodies corporate and partnerships where a senior manager commits an offence. It received Royal Assent on 29 April 2026 and came into force on 29 June 2026. Available at legislation.gov.uk.
- Joint SFO / CPS Corporate Prosecution Guidance. Updated 18 August 2025. Useful for the current prosecution approach to the failure to prevent fraud offence and the senior manager attribution test. Available at gov.uk.
- Home Office guidance on the failure to prevent fraud offence. Sets out the six principles for reasonable procedures. The offence came into force on 1 September 2025. Available at gov.uk.
- Ministry of Justice guidance on the Bribery Act 2010. Published February 2012. Sets out the six principles for adequate procedures. Available at gov.uk.
- UK anti-corruption strategy. Sets out the government's strategic approach and priorities. Available at gov.uk.
- New Zealand resources. Crimes Act 1961, sections 240 to 243 and sections 99 to 106. Financial Markets Conduct Act 2013, Part 5. SFO and FMA guidance and enforcement publications on serious fraud and market integrity. Available at legislation.govt.nz and agency websites.
- Australia resources. Criminal Code Act 1995 (Cth), especially divisions 70, 134 and 135. Corporations Act 2001 (Cth), Part 7.10. ASIC and Commonwealth Director of Public Prosecutions guidance on fraud, corruption and market misconduct. Available at legislation.gov.au and agency websites.
Ārai Tika