Session Six: Corporate Criminal Liability and the Senior Manager Test

Session Six: Corporate Criminal Liability and the Senior Manager Test | Ārai Tika

Fraud and Financial Crime · Session Six

Corporate Criminal Liability and the Senior Manager Test

From the directing mind doctrine to the statutory senior manager attribution regime. Who counts as a senior manager, and why the test matters.

Course: Fraud and Financial Crime: Legislation, Regulation and Practical Implementation Reading time: around 40 minutes Jurisdictions: UK primary, with New Zealand and Australia addressed throughout

Disclaimer

This course is provided for general information and education only. It is not legal advice. Legislation, rules and regulatory guidance change, sometimes quickly. Readers should confirm the current position and obtain jurisdiction-specific professional advice where needed. The views and experience expressed are Russel Fielding's own and do not represent any employer or client organisation.

Session Six: Corporate Criminal Liability and the Senior Manager Test

Until recently, prosecuting a company for a serious offence in England and Wales usually required the prosecution to identify the directing mind and will of the organisation and prove that this person committed the offence. In modern organisations with complex management structures, the identification doctrine became a substantial evidential barrier.

That position has changed through statutory reform. The Economic Crime and Corporate Transparency Act 2023 introduced a senior manager attribution test for a defined list of economic offences. The Crime and Policing Act 2026 replaced that limited route with a broader model for offences capable of being committed by an organisation. The shift reduces the protection that complex organisational structures previously offered and brings the UK position closer to other major jurisdictions.

This session covers the doctrine, the statutory reforms, the senior manager definition, how the test is likely to be applied, and what organisations should be doing under the current regime.

Who this session is for. Senior managers, board members, in-house counsel, compliance officers, risk leaders, internal audit and HR leads, and anyone advising on or responsible for corporate criminal exposure. This session is for organisations of any size; the senior manager test is not limited to large organisations.

The directing mind and will doctrine

Corporate criminal liability in England and Wales developed in the late nineteenth and early twentieth centuries. The common law rule that crystallised was the identification doctrine: a company could be liable for offences requiring proof of a mental element only if the prosecution could identify a natural person who constituted the directing mind and will of the company and whose state of mind could be attributed to the company itself.

The leading case is Tesco Supermarkets Ltd v Nattrass [1972] AC 153, where the House of Lords held that the directing mind and will were the board, the managing director and other senior officers who controlled the company's affairs. Branch managers and other middle-ranking staff were not, on the facts of that case, part of the directing mind.

The doctrine was workable in the early twentieth century, when companies were typically smaller and more centrally managed. It became increasingly difficult to apply as organisations grew in scale and complexity. By the early 2000s, prosecutors were openly arguing that the doctrine produced perverse outcomes: the larger and more decentralised an organisation, the harder it was to prove a criminal offence against it. The Barclays litigation later showed the practical difficulty of attributing alleged dishonesty by senior executives to a corporate body under the identification doctrine.

The Law Commission's options paper on corporate criminal liability set out the case for reform in detail. Two statutory responses followed.

Section 196 of the Economic Crime and Corporate Transparency Act 2023

Section 196 of ECCTA 2023 was the first response. It came into force on 26 December 2023. The provision created a statutory route to corporate criminal liability for a defined list of economic offences. Where a senior manager of an organisation committed one of those offences while acting within the actual or apparent scope of their authority, the organisation was also taken to have committed the offence.

Three points carry the structural weight of the provision.

First, the offences in scope of section 196 are listed in Schedule 12 to ECCTA 2023. They include fraud and false accounting under the Fraud Act 2006 and the Theft Act 1968, bribery offences under the Bribery Act 2010, money laundering offences under the Proceeds of Crime Act 2002, sanctions offences, certain tax evasion offences, and a range of related provisions. The list is wide but defined: it covers economic crime.

Second, senior manager is defined in section 196(4) as an individual who plays a significant role in the making of decisions about how the whole or a substantial part of the activities of the body corporate or partnership are to be managed or organised, or the actual managing or organising of the whole or a substantial part of those activities. The definition is functional, not titular. A regional managing director, a divisional head, the head of a substantial function, the chief financial officer or chief operating officer of a large entity will all typically qualify. Whether someone qualifies is a question of fact about the role they actually play, not the title on their business card.

Third, the actual or apparent scope of their authority is the boundary on attribution. The Explanatory Notes to ECCTA confirm that this does not require the senior manager to have been authorised to commit the criminal offence itself. It is enough that the conduct was of a type the senior manager was authorised to undertake, even where they exceeded their internal mandate or breached internal policy. Apparent authority extends the test further: an organisation may be liable where the senior manager appeared to have the authority to outsiders, regardless of internal restrictions.

Section 250 of the Crime and Policing Act 2026

Section 250 of the Crime and Policing Act 2026 is the second and wider reform. The Act received Royal Assent on 29 April 2026. Section 250 came into force on 29 June 2026 and applies to offences committed on or after that date.

Section 250 replaces the Schedule 12 limitation in section 196 of ECCTA and extends the senior manager attribution model to offences capable of being committed by an organisation. Its reach is broad, subject to the statutory territorial limitation for conduct occurring wholly outside the UK where the organisation would not itself commit the offence on those facts.

The definition of senior manager in section 250 mirrors the ECCTA definition. The actual or apparent scope of authority test is the same. The substantive change is the breadth of offences covered, not the structure of attribution.

The result is that an organisation may be criminally liable where a senior manager commits an offence, capable of being committed by the organisation, while acting within the actual or apparent scope of their authority. Relevant categories may include workplace safety, environmental protection, data protection, labour exploitation, cybercrime, public justice, corporate reporting and other regulatory or general criminal offences.

Two important features of the new regime

Two features of the new regime are particularly important for practitioners.

First, there is no statutory defence of adequate procedures or reasonable procedures. Unlike the three failure to prevent offences covered in Session Five, the senior manager attribution model does not provide a procedural defence to an organisation that can show it had appropriate systems and controls in place. The fact that the conduct was contrary to corporate policy, that training had been provided, that the senior manager was acting outside their internal mandate: none of these in itself prevents attribution. They remain relevant to mitigation, public interest assessments and DPA negotiations, but they are not a legal defence.

Second, the regime applies to organisations of all sizes. The 250-employee / £36 million turnover / £18 million in assets test in section 199 of ECCTA does not apply here. A small private company, a partnership, a charity, or a public body operating as a corporate entity may all fall within section 250 in the same way as a large listed company.

Who is a senior manager

The single most important practical question raised by the new regime is who counts as a senior manager. The statutory definition is functional and deliberately wide. It captures any individual who plays a significant role in either the making of decisions about how the whole or a substantial part of the organisation's activities are to be managed or organised, or the actual managing or organising of such activities.

Three observations follow.

Senior manager is not the same as the SMCR senior manager population in regulated financial services. A senior manager for ECCTA and CPA purposes may also be an SMCR senior manager, but the populations are not coterminous. The SMCR population is defined by specific functions and prescribed responsibilities. The senior manager test is defined by what the person actually does in the management of the organisation. A divisional head running a substantial line of business who is not an SMCR senior manager is still likely to be a senior manager for these purposes.

Senior manager is not the same as director. A non-executive director with limited operational involvement may not be a senior manager for these purposes, while a divisional managing director not on the board may well be. The test focuses on operational influence, not formal governance role.

Senior manager is not necessarily a small population. In a large complex organisation, the senior manager population is likely to extend well beyond the executive committee. Heads of country businesses, heads of substantial functions (finance, technology, operations, risk, compliance, legal, HR), heads of significant subsidiaries, and individuals with significant decision-making authority over major business activities are all potentially in scope.

Practical implications for organisations

The work organisations should be doing falls into five practical areas.

Map the senior manager population

Identify, as a documented exercise, who within the organisation is likely to fall within the section 250 definition. This is not a question of titles. It is a question of substantive role. For each candidate, capture the basis on which the person is treated as a senior manager: the decisions they make, the activities they manage, and the proportion of the organisation's activities that fall within their remit.

This exercise will produce, in most organisations, a list larger than the executive committee. It should be calibrated to the size and complexity of the organisation. A small business may have a handful of senior managers; a complex multinational may have dozens or more.

Document the scope of authority

For each senior manager, document the actual scope of their authority. Record what they are authorised to do, what they are not authorised to do, what discretion they have, and what escalation routes apply. This helps the organisation argue, in any subsequent proceedings, that conduct outside that scope is not within the actual or apparent scope of authority for section 250 purposes.

The apparent authority test means that documentation alone is not sufficient. The way the senior manager is held out to external parties matters. If a person is presented externally as having broad authority, an internal document narrowing that authority may not displace the apparent authority test. Both sides of the question, the documented authority and the external presentation, need to be aligned.

Refresh the risk assessment

Risk assessments built for failure to prevent regimes are typically scoped to fraud, bribery and the facilitation of tax evasion. Section 250 reaches much further. The risk assessment should consider the range of offences for which the organisation could now be liable, including workplace safety, environmental protection, data protection, labour exploitation, cybercrime, offences against the person and offences against public justice. The question is not which offences cause the greatest concern, but which offences a senior manager could realistically commit within the actual or apparent scope of their authority.

Strengthen the control environment

Although the regime does not provide a procedural defence, the practical importance of effective controls is unchanged. A documented programme of policies, training, monitoring and review remains the primary basis on which the organisation can argue that conduct was outside the scope of authority, that the public interest does not require prosecution of the corporate as well as the individual, or that any DPA should be on favourable terms.

The control environment also matters for the detection and response side of the equation. Senior manager misconduct rarely emerges through the same channels as junior misconduct. Whistleblowing channels, independent audit access, board oversight of senior managers, escalation routes that bypass the senior manager in question: all of these matter more under the new regime than they did before.

Plan the response framework

Most organisations have an incident response framework geared to operational failures. Few have a framework geared to senior manager misconduct. The new regime tests the second, more uncomfortable, scenario. The framework needs to cover privileged investigation, board engagement, regulator and law enforcement notification where required, employee and HR action, public statement preparation, insurance notification and DPA preparation. None of this can be assembled at short notice once an incident is live.

Where this fits with the failure to prevent regime

The failure to prevent regime under section 7 of the Bribery Act 2010, sections 45 and 46 of the Criminal Finances Act 2017, and section 199 of ECCTA remains in force. Those offences carry an adequate procedures or reasonable procedures defence. The senior manager attribution regime does not.

For a single piece of senior manager conduct that constitutes a base fraud offence under Schedule 13 to ECCTA, a large organisation may face exposure through the failure to prevent fraud offence under section 199 and, separately, through direct attribution under section 250. The reasonable procedures defence may be available under section 199. It is not available under section 250. The charging route is a matter for prosecutorial discretion on the facts.

For senior manager conduct that does not fall within a failure to prevent offence, section 250 may be the principal route to corporate liability. The procedural defence under section 7 of the Bribery Act remains available where the prosecution is for failure to prevent bribery. It does not answer a charge based on direct attribution where the senior manager personally commits the bribery offence and the prosecutor proceeds under section 250.

Comparative position

The UK reform brings the position closer, although not identical, to the long-standing approach in the United States, where corporate criminal liability operates through respondeat superior. The US doctrine holds an organisation liable for offences committed by any employee acting within the scope of employment and at least partly to benefit the organisation. The UK senior manager test is narrower because it is limited to senior managers rather than all employees, but it may produce a comparable result for that population.

Other jurisdictions take different approaches. The Australian Commonwealth corporate criminal liability framework under Part 2.5 of the Criminal Code Act 1995 (Cth) uses a corporate culture test in addition to attribution by individuals. France, Germany and other civil-law jurisdictions operate distinct corporate liability regimes through their own criminal codes. The trend across comparable jurisdictions has been towards wider attribution and lower thresholds, although the detail differs materially between systems.

Jurisdiction equivalents

New Zealand

Corporate criminal liability in New Zealand operates through a combination of statutory provisions and the common law rules of attribution. The Crimes Act 1961 and individual regulatory statutes establish corporate offences. The leading authority on attribution remains the Privy Council decision in Meridian Global Funds Management Asia Ltd v Securities Commission [1995] 2 AC 500, on appeal from New Zealand, which set out a more flexible attribution rule than Tesco v Nattrass and remains influential in both jurisdictions.

New Zealand has not introduced a statutory senior manager attribution regime equivalent to section 196 of ECCTA or section 250 of the Crime and Policing Act 2026.

Australia

Australia's general approach to corporate criminal liability is set out in Part 2.5 of the Criminal Code Act 1995 (Cth). Division 12 deals with the criminal responsibility of bodies corporate. The framework includes attribution through high managerial agents, a concept comparable to senior managers, and, distinctively, a corporate culture test under section 12.3, under which intent, knowledge or recklessness can be attributed to a body corporate where the corporate culture existing within the body directed, encouraged, tolerated or led to non-compliance.

The Australian framework is more developed than the UK position was before ECCTA. The UK and Australian approaches are now closer than they were, although the corporate culture limb of the Australian test has no direct equivalent in UK law.

Key takeaways

  • Corporate criminal liability in England and Wales has historically operated through the directing mind and will doctrine. The doctrine produced increasingly difficult outcomes as organisations grew larger and more complex.
  • Section 196 of ECCTA 2023, in force from 26 December 2023, introduced a statutory senior manager attribution test for a defined list of economic offences in Schedule 12.
  • Section 250 of the Crime and Policing Act 2026, in force from 29 June 2026, replaces the Schedule 12 limitation and extends the senior manager attribution test to offences capable of being committed by an organisation.
  • Senior manager is defined functionally. It captures individuals who play a significant role in decisions about, or the actual management of, the whole or a substantial part of the organisation's activities. It is not a title test. In large organisations the population extends well beyond the executive committee.
  • There is no statutory defence of adequate or reasonable procedures under the senior manager attribution regime. The regime applies to organisations of all sizes.
  • Practical actions include mapping the senior manager population, documenting scope of authority, refreshing the risk assessment, strengthening the control environment, and planning a senior manager response framework.

Coming up in Session Seven

Session Seven covers the financial crime risk assessment, the central document on which every other part of a financial crime programme depends. The Bribery Act requires it. The Criminal Finances Act requires it. ECCTA requires it. The FCA requires it. The session sets out what a working risk assessment looks like across the four offence areas, what supervisors expect, where assessments most often fall short, and the practical steps needed to build one that does the job.

Further reading and resources

The following primary sources are the most useful companions to this session. All are publicly available.

  • Economic Crime and Corporate Transparency Act 2023, sections 196 to 198 and Schedule 12. The statutory senior manager attribution regime for economic offences. In force from 26 December 2023. Available at legislation.gov.uk.
  • Crime and Policing Act 2026, section 250. The broader statutory senior manager attribution regime, in force from 29 June 2026. The Act received Royal Assent on 29 April 2026. Available at legislation.gov.uk. Practitioners should also consult the Explanatory Notes published alongside the Act.
  • Economic Crime and Corporate Transparency Act 2023, section 199 and Schedule 13. The failure to prevent fraud offence and the list of base fraud offences. The offence applies to large organisations and carries a reasonable procedures defence.
  • Tesco Supermarkets Ltd v Nattrass [1972] AC 153. The leading authority on the directing mind and will doctrine. Available through the standard case law databases.
  • Meridian Global Funds Management Asia Ltd v Securities Commission [1995] 2 AC 500. The Privy Council's restatement of the rules of attribution on appeal from New Zealand. Influential in both UK and New Zealand corporate criminal liability cases.
  • Law Commission, Corporate criminal liability: an options paper. The Commission's analysis of the case for reform of the identification doctrine. Available at lawcom.gov.uk.
  • Explanatory Notes to ECCTA 2023 and to the Crime and Policing Act 2026. Useful interpretive aids on the senior manager test, actual or apparent authority, and the relationship between the new regime and the common law identification doctrine. Available at legislation.gov.uk alongside the Acts.
  • Joint SFO and CPS Corporate Prosecution Guidance. Available at sfo.gov.uk.
  • Australia. Criminal Code Act 1995 (Cth), Part 2.5. The Australian general framework for corporate criminal liability, including the corporate culture test in section 12.3. Available at legislation.gov.au.

Ārai Tika

Written by Russel Fielding — LLM (Distinction), Fraud and Financial Crime · PMP · CIPM · PRINCE2 Practitioner