Session One: Introduction and the Financial Crime Landscape

Session One: Introduction and the Financial Crime Landscape | Russel Fielding

Fraud and Financial Crime  ·  Session One

Introduction and the Financial Crime Landscape

Reading time Around 30 minutes
Jurisdictions UK primary, with NZ and AU where the framework differs
Course Fraud and Financial Crime: Legislation, Regulation and Practical Implementation

Disclaimer

This course is provided for general information and educational purposes only. It does not constitute legal advice and is not a substitute for jurisdiction-specific professional counsel, as legislation, regulation, and regulatory guidance change. Readers should satisfy themselves as to the current position and seek appropriate professional advice where needed. All content represents the independent views and experience of Russel Fielding and does not represent any employer or client organisation.

Financial crime compliance is in the middle of the most significant period of change it has seen in over a decade. Corporate criminal liability has been redrawn. The failure to prevent model, until recently confined to bribery and the facilitation of tax evasion, now covers fraud.

From 29 June 2026, an organisation can also be criminally liable if one of its senior managers commits an offence while acting within the actual or apparent scope of their authority, with no defence of reasonable procedures available.

That is the environment in which practitioners are now working. The changes are substantial, and they are still bedding in.

Who this session is for. This session is for compliance officers, financial crime leads, MLROs who carry fraud, bribery, and market abuse risk, as well as money laundering risk, risk managers, in-house counsel, senior managers, board members, and programme directors with delivery responsibility for financial crime work.

What this course covers and what it does not

Financial crime is a broad category. The term is used loosely across the industry and across regulators, and it overlaps with adjacent areas, including money laundering, market integrity, cybercrime, and tax compliance. The scope of this course is the four offences that sit at the centre of the Fraud and Financial Crime pillar on russelfielding.com:

  • Fraud under the Fraud Act 2006, the related Theft Act 1968 offences, the Computer Misuse Act 1990, and the common law offence of cheating the public revenue.
  • Bribery and corruption under the Bribery Act 2010, including the corporate offence under section 7.
  • Insider dealing and market abuse under Part V of the Criminal Justice Act 1993 and the UK Market Abuse Regulation.
  • The failure to prevent framework across bribery (Bribery Act 2010, section 7), facilitation of tax evasion (Criminal Finances Act 2017, sections 45 and 46) and fraud (Economic Crime and Corporate Transparency Act 2023, section 199).

Money laundering is not covered in this course, except where it intersects with fraud as the means by which fraud proceeds are cleaned. The AML Compliance course already covers anti money laundering compliance from legislative foundations through to daily operational practice, and there is no benefit to readers in duplicating that material here. Where the course refers to AML obligations, it points to that course for the depth.

Why the landscape has changed so quickly

Three shifts explain most of the change in the corporate financial crime picture over the last decade, and they have all accelerated in the last two years.

The move from individual to corporate accountability

For most of the twentieth century, prosecuting a company for an offence requiring mens rea — a guilty mind — meant proving that the directing mind and will of the organisation had committed it. In practice, that usually meant a board director or someone with equivalent control.

For modern organisations with complex management structures and devolved decision making, that bar proved almost impossible to clear. The limits of the doctrine became increasingly hard to ignore as organisations grew in scale and complexity. Prosecutors found that the larger and more decentralised an organisation, the harder it was to identify the directing mind and will. The failed prosecution of Barclays in 2018, which collapsed in part because senior officers were not found to constitute the bank's directing mind and will, is a recent high-profile illustration of the problem.

How the failure to prevent model spread

The failure to prevent model has proven to be one of the most influential pieces of legislative design of the last two decades. Bribery first, in 2010. Facilitation of tax evasion in 2017. Fraud in 2023, in force from 1 September 2025. The architecture is consistent: corporate liability is triggered where an associated person commits the underlying offence for the organisation's benefit, with a defence available where the organisation can demonstrate adequate or reasonable procedures in place to prevent it.

The model works because it changes the prosecutorial question. Instead of asking whether the organisation actively participated in the offence, it asks whether the organisation took proportionate steps to prevent it. That is a question that regulators can investigate and that prosecutors can prove. It is also a question organisations can answer by maintaining the kind of compliance programme described in government guidance.

Each of the three failure-to-prevent offences has its own government guidance, and each is structured around six broadly similar principles: top-level commitment, risk assessment, proportionate procedures, due diligence on associated persons, communication and training, and monitoring and review. The terminology differs in places (adequate procedures for bribery, reasonable procedures for tax evasion and fraud), but the architecture is the same. In Session Five, we will go through the details of the framework.

Why enforcement now feels more active

The third shift is enforcement. The Serious Fraud Office has been explicit that the failure to prevent a fraud offence will be taken into account. In April 2025, the SFO charged United Insurance Brokers Ltd under section 7 of the Bribery Act 2010. That remains an ongoing prosecution and should be understood on that basis. More broadly, the joint SFO and CPS corporate prosecution guidance was updated in August 2025 to reflect the failure to prevent fraud offence and the senior manager attribution test. The direction of travel is clear: corporate financial crime enforcement is becoming more active, not less.

HMRC has also begun to use its corporate offences. In August 2025, Bennett Verby Ltd was charged under section 45 of the Criminal Finances Act 2017. That case has been widely reported as the first corporate prosecution under the failure to prevent facilitation of tax evasion regime, but it too remains ongoing. The FCA continues to treat market abuse as a significant enforcement priority and has pursued both civil and criminal cases through 2025 and into 2026.

The current UK anti-corruption strategy, published in December 2025, sets out the government's priorities for the years ahead. Transparency International's Corruption Perceptions Index for 2025 gave the UK its lowest score since the index was revised in 2012, while the UK remained 20th in the rankings. Taken together, those developments point to a more active enforcement environment.

The four offences in outline

Each of the four offences in the scope of the course has its own session in detail, but it is worth seeing them together at the outset.

Session Two: Fraud

Fraud is the most commonly reported crime in England and Wales. It accounts for around 45 per cent of all crime in the Crime Survey for England and Wales, with an estimated 4 million offences in the year ending September 2025.

The Fraud Act 2006 is the primary legislative instrument. It creates the three core offences of fraud by false representation, fraud by failing to disclose information, and fraud by abuse of position. Related offences in the Theft Act 1968 cover false accounting and false statements by company directors. The Computer Misuse Act 1990 covers cyber-enabled fraud involving unauthorised access to a computer system. The common law offence of cheating the public revenue remains available for serious tax fraud cases.

Fraud also engages the regulatory framework. The Payment Systems Regulator's mandatory reimbursement rules for in-scope APP fraud took effect on 7 October 2024, changing the economics of fraud prevention for payment service providers. The FCA Consumer Duty directly affects how firms prevent and respond to fraud, particularly when vulnerable customers are involved. The Online Safety Act 2023 imposes duties on online platforms regarding fraudulent content. The failure to prevent fraud offence under section 199 of ECCTA, in force since 1 September 2025, sits alongside all of this.

Session Three: Bribery and corruption

The Bribery Act 2010 is now fifteen years old. Section 1 is the general offence of bribing another person, section 2 is the offence of being bribed, section 6 is the specific offence of bribing a foreign public official, and section 7 is the corporate offence of failing to prevent bribery. The Act applies extraterritorially. It applies to conduct anywhere in the world where the organisation carries on business in the UK or where the person associated with the organisation has a close connection to the UK.

Adequate procedures are the only defence available under section 7. The Ministry of Justice guidance sets out the six principles that characterise adequate procedures. The international anti-bribery and corruption framework around the Bribery Act includes the OECD Anti-Bribery Convention, the UN Convention against Corruption, the US Foreign Corrupt Practices Act 1977, and ISO 37001, the international standard for anti-bribery management systems, which was substantially revised and reissued in 2025.

Session Four: Insider dealing and market abuse

Insider dealing and market abuse operate under two parallel regimes in the UK. The criminal offence of insider dealing is contained in Part V of the Criminal Justice Act 1993, sections 52 to 64. The civil regime is the UK Market Abuse Regulation, which was retained in UK law from 31 December 2020, having been onshored from the EU regulation that took effect on 3 July 2016. Article 14 of UK MAR prohibits insider dealing, recommending or inducing another person to engage in insider dealing, and the unlawful disclosure of inside information. Article 15 prohibits market manipulation. Article 16 requires the reporting of suspicious transactions and orders.

The FCA has discretion to pursue insider dealing as either a civil offence under UK MAR or as a criminal offence under the Criminal Justice Act 1993, and often opens cases on a dual-track basis. Criminal sanctions for insider dealing and market manipulation can include custodial sentences of up to ten years and unlimited fines. The civil regime carries unlimited financial penalties.

The forthcoming market abuse regime for crypto assets, currently the subject of FCA consultation, will extend the substance of UK MAR to a new asset class through 2026.

Session Five: The failure to prevent framework

The failure to prevent framework is, in 2026, made up of three corporate offences:

Bribery Act 2010
Section 7. The original corporate offence: failure of a commercial organisation to prevent bribery by an associated person. Adequate procedures defence.
Criminal Finances Act 2017
Sections 45 and 46. Failure to prevent the facilitation of UK tax evasion and failure to prevent the facilitation of foreign tax evasion. Reasonable procedures defence.
ECCTA 2023, s. 199
Failure to prevent fraud. In force from 1 September 2025. Applies to large organisations. Reasonable procedures defence.

Each offence has its own government guidance. Each set of guidance is structured around six principles that are recognisably similar but not identical. Each defence carries the same fundamental architecture: the organisation needs to demonstrate that it had a proportionate, documented, implemented and reviewed compliance programme in place at the time of the underlying offence.

The senior manager test and why it matters now

Failure to prevent is not the only route into corporate criminal liability. Section 196 of the Economic Crime and Corporate Transparency Act 2023 introduced a statutory senior manager attribution test for specified economic crime offences. From 26 December 2023, an organisation has been criminally liable where a senior manager commits one of the offences listed in Schedule 12 of ECCTA while acting within the actual or apparent scope of their authority. That list includes fraud, false accounting, bribery, money laundering, sanctions and tax offences.

Section 250 of the Crime and Policing Act 2026 replaces section 196 of ECCTA and extends the senior manager attribution model to every criminal offence. It comes into force on 29 June 2026. The implications are significant.

First, the test is no longer limited to economic crime. It can apply across the criminal law where a senior manager commits an offence within the actual or apparent scope of their authority.

Second, there is no reasonable procedures defence. Unlike the failure to prevent offences, an organisation cannot defend itself by showing that it had a robust compliance programme in place. If the test is met, liability attaches.

Third, there is no requirement that the organisation benefited from the conduct. An organisation can be criminally liable for an offence committed by a senior manager even where the organisation is the victim of the conduct, provided the conduct fell within the actual or apparent scope of the senior manager's authority.

Fourth, the test is not restricted to large organisations. Failure to prevent fraud applies only to large organisations (broadly, those exceeding two of three thresholds: 250 employees, £36 million turnover, £18 million in assets). The senior manager test under section 250 has no such restriction. It applies to organisations of all sizes across all sectors.

A senior manager is defined functionally, not by title. It captures any individual who plays a significant role in the making of decisions about how the whole or a substantial part of the organisation's activities are managed or organised, or in the actual managing or organising of those activities. Whether someone is a senior manager is a question of fact. In practice, the definition may extend well below board level.

How the course is organised

The nine sessions are designed to be read in sequence. They are also designed to be useful on their own. The structure follows the same logic as the AML Compliance course on the site: legislative foundations first, then the regulatory layer, then practical implementation.

The first six sessions cover the law. This session, the introduction, sets the frame. Session Two covers the fraud offences. Session Three covers bribery. Session Four covers insider dealing and market abuse. Session Five covers the failure to prevent framework across all three offences. Session Six covers the senior manager test and the broader picture of corporate criminal liability.

The last three sessions cover implementation. Session Seven covers the financial crime risk assessment, which is the foundation of every other control. Session Eight covers building and running the programme: governance, the relationship between the financial crime function and the MLRO, the design of cross-offence controls, and the supporting structures of training, whistleblowing, intelligence sharing and assurance.

Session Nine is the implementation summary: a consolidated obligations checklist cross-referenced to legislation and common failure modes, and a working reference to be returned to.

Each session ends with a brief Key Takeaways box, a pointer to the next session, and a Further Reading section listing the primary sources for that session. Where relevant, each session also includes a Jurisdiction Equivalents section addressing New Zealand and Australia.

Jurisdiction equivalents

New Zealand and Australia

The course is principle-led, so it would be valuable for any practitioner of fraud and financial crime. However, the examples are UK-led with New Zealand and Australia also addressed in each session, where the framework differs, with depth scaled to the extent to which the regime diverges from the UK position. This session sets out the broad picture, with the specifics dealt with in the relevant later sessions.

New Zealand

Fraud primarily falls within the Crimes Act 1961, particularly sections 240 to 243 (obtaining by deception, causing loss by deception), section 256 (forgery), and a range of related offences. The Secret Commissions Act 1910 covers the historic offence of taking secret commissions, although in practice, the Crimes Act provisions on corruption do most of the work today. Bribery is addressed in sections 99 to 106 of the Crimes Act, covering judicial corruption, corruption of ministers, members of Parliament and law enforcement, and the bribery of foreign public officials under section 105C. Insider conduct in financial markets is covered by Part 5 of the Financial Markets Conduct Act 2013, particularly subpart 1, which deals with insider conduct.

New Zealand does not have a direct equivalent of the UK's failure to prevent framework. Corporate liability is governed by a mix of statutory provisions and the common law identification doctrine. The Serious Fraud Office is the lead agency for serious or complex financial crime, with the Financial Markets Authority leading on market conduct, including enforcement of insider trading.

Australia

Fraud is covered at the federal level under the Criminal Code Act 1995 (Cth), particularly in divisions 134 (obtaining property or financial advantage by deception) and 135 (general dishonesty offences). State and territory criminal codes cover other forms of fraud. Bribery of a Commonwealth public official is covered under sections 141 and 142 of the Criminal Code, and the foreign bribery offence under section 70.2. Australia introduced a corporate failure to prevent foreign bribery offence under section 70.5A of the Criminal Code, which came into force on 8 September 2024. The defence is one of adequate procedures, broadly mirroring the UK Bribery Act section 7 architecture.

Insider trading and market misconduct are covered by Part 7.10 of the Corporations Act 2001 (Cth), with the prohibition on insider trading at section 1043A. The Australian Securities and Investments Commission is the lead enforcement agency for market conduct.

Australia's framework is changing, so practitioners should work from the compiled legislation, the current Rules, and AUSTRAC guidance, along with any relevant transitional instruments.

Key takeaways

  • Corporate criminal liability in the UK has changed more in the last three years than in the previous thirty. The failure to prevent fraud offence, in force from 1 September 2025, and the senior manager attribution model, in force from 29 June 2026, are the defining changes.
  • The course covers four offence areas: fraud, bribery and corruption, insider dealing and market abuse, and the failure to prevent framework. Money laundering falls under the AML course; tax evasion is treated only as it appears in the failure-to-prevent framework.
  • Each of the three failure to prevent offences has its own government guidance, but the architecture is consistent across all three. An organisation that has built its anti-bribery programme well is in a strong position to extend the same architecture to the other offences.
  • The senior manager test under section 250 of the Crime and Policing Act 2026 carries no reasonable procedures defence, no benefit requirement, and no large organisation threshold. It extends across criminal offences and applies to organisations of all sizes.
  • The course is UK led, with New Zealand and Australia treated where the framework differs. Australia has had its own failure to prevent foreign bribery offence in force since September 2024. New Zealand has no equivalent regime.

Coming up in Session Two

The Fraud Offences

Session Two covers the fraud offences in detail. It works through the Fraud Act 2006, addresses the related offences under the Theft Act 1968 and the Computer Misuse Act 1990, and explains how prosecutors choose between offences.

It also provides a high-level survey of the main fraud types practitioners will encounter, with the published Scam Shield guide as the deeper reference on consumer fraud, the APP fraud reimbursement regime, vulnerable customers, and AI as both a fraud enabler and a fraud detector.

Further reading and resources

These primary sources are the most useful companions to this session. All are publicly available.

Economic Crime and Corporate Transparency Act 2023. Read section 196 on the senior manager attribution test for specified economic crime offences, in force from 26 December 2023, and section 199 on failure to prevent fraud, in force from 1 September 2025. Available at legislation.gov.uk.

Crime and Policing Act 2026. Read section 250 on criminal liability of bodies corporate and partnerships where a senior manager commits an offence. It received Royal Assent on 29 April 2026 and comes into force on 29 June 2026. Available at legislation.gov.uk.

Joint SFO / CPS Corporate Prosecution Guidance. Updated 18 August 2025. Useful for the current prosecution approach to the failure to prevent fraud offence and the senior manager attribution test. Available at gov.uk.

Home Office guidance on the failure to prevent fraud offence. Published 6 November 2024. Sets out the six principles for reasonable procedures. Available at gov.uk.

Ministry of Justice guidance on the Bribery Act 2010. Published February 2012. Sets out the six principles for adequate procedures. Available at gov.uk.

UK anti-corruption strategy. Published 8 December 2025. Sets out the government's strategic approach and priorities for the years ahead. Available at gov.uk.

New Zealand resources. Crimes Act 1961, sections 240 to 243 and sections 99 to 106. Financial Markets Conduct Act 2013, Part 5. SFO and FMA guidance and enforcement publications on serious fraud and market integrity. Available at legislation.govt.nz and agency websites.

Australia resources. Criminal Code Act 1995 (Cth), especially divisions 70, 134 and 135. Corporations Act 2001 (Cth), Part 7.10. ASIC and the Commonwealth Director of Public Prosecutions guidance on fraud, corruption and market misconduct. Available at legislation.gov.au and agency websites.

About the author

Russel Fielding is a senior transformation consultant with more than two decades of experience as a business owner and working inside large regulated organisations across financial services, higher education, and professional sport. He holds an LLM in Fraud and Financial Crime from BPP University, awarded with distinction, alongside PMP, CIPM and PRINCE2 qualifications.

The articles, guides and courses on russelfielding.com are free to access and written in plain language by someone who has delivered the work.