Fraud and Financial Crime · Session Two
The Fraud Offences
The Fraud Act 2006, the related Theft Act offences, computer-enabled fraud, and cheating the public revenue. How prosecutors choose between offences, and a high-level survey of the main fraud types practitioners encounter.
Disclaimer
This course is provided for general information and education only. It is not legal advice. Legislation, rules and regulatory guidance change, sometimes quickly. Readers should confirm the current position and obtain jurisdiction-specific professional advice where needed. The views and experience expressed are Russel Fielding's own and do not represent any employer or client organisation.
Session Two: The Fraud Offences
Fraud remains one of the most prevalent crime types in England and Wales. The Crime Survey for England and Wales for the year ending December 2025 estimated 4.4 million fraud incidents. It is also the crime that regulated organisations are most likely to encounter, the crime that customers are most likely to experience, and the crime that now sits at the centre of the corporate criminal liability framework following the failure to prevent fraud offence.
This session covers the main offences that make up the criminal law of fraud in the UK. The Fraud Act 2006 is the core statute. Alongside it sit the Theft Act 1968 offences of false accounting and false statements by company directors, the Computer Misuse Act 1990, where unauthorised access to a computer system is involved, and the common law offence of cheating the public revenue for the most serious tax fraud cases.
The substantive law is settled in its essentials. The core structure of the Fraud Act has remained stable since enactment, and the approach to dishonesty was restated by the Supreme Court in 2017 and later applied in criminal appellate authority. The main movement is around the offences: regulatory expectations on firms, the corporate offence under section 199 of ECCTA, and the practical question of how financial crime compliance programmes should treat fraud as a category of risk.
The Fraud Act 2006
The Fraud Act 2006 came into force on 15 January 2007. It replaced a fragmented patchwork of deception offences from the Theft Acts of 1968 and 1978 with a single, simpler statutory framework. The deception offences had become difficult to apply, partly because of the technical requirement to prove that a person had been deceived, and partly because they did not work well for fraud committed against machines and computer systems. The Fraud Act fixed both problems.
Section 1 creates the general offence of fraud. The offence is committed where a person is in breach of one of three sections that set out how fraud can be committed: section 2 (fraud by false representation), section 3 (fraud by failing to disclose information), or section 4 (fraud by abuse of position). All three are offender-focused. None requires proof that any specific person was deceived. None requires proof that the offender succeeded in their enterprise. The offences are complete on the conduct of the offender combined with the requisite intent.
Section 2: Fraud by false representation
Fraud by false representation is committed where a person dishonestly makes a false representation, intending by making the representation either to make a gain for themselves or another, or to cause loss to another, or to expose another to a risk of loss.
A representation is false if it is untrue or misleading, and the person making it knows that it is or might be untrue or misleading. A representation can be expressed or implied. It can be made by conduct as well as by words. It can be a representation of fact, of law, or of someone's state of mind, including the maker's own state of mind. The Act specifically provides that a representation can be made to a machine: this brings card-not-present fraud, identity fraud against automated systems, and online payment fraud cleanly within the offence, without the prosecution having to identify a deceived person.
Section 2 is the main charging route under the Fraud Act. The Crown Prosecution Service prosecutes most fraud cases under it. It captures everything from low-value invoice fraud against a small business through to complex investment fraud. The flexibility of the offence, particularly the ability to charge it where a representation is made to a machine, makes it the natural fit for many cyber-enabled and consumer-facing fraud cases.
Section 3: Fraud by failing to disclose information
Fraud by failing to disclose is committed where a person dishonestly fails to disclose information which they are under a legal duty to disclose, and intends by failing to disclose to make a gain, cause loss, or expose another to a risk of loss.
The pivotal element is the legal duty to disclose. The duty can arise from statute, from a fiduciary relationship, from a contract, or from a recognised customary or industry practice that has the force of a legal duty. Where the facts of the alleged duty are in dispute, whether it amounts to a legal duty is a matter for the judge. Whether the relationship that would give rise to that duty actually existed is a matter for the jury.
Section 3 is less commonly charged than section 2, but it is significant in professional services contexts and in regulated industries where a duty to disclose is built into the legal or regulatory framework. Solicitor and client, agent and principal, and certain officer-of-the-company duties are the obvious examples.
Section 4: Fraud by abuse of position
Fraud by abuse of position is committed where a person occupies a position in which they are expected to safeguard, or not to act against, the financial interests of another, and dishonestly abuses that position with the intent to make a gain, cause loss, or expose another to a risk of loss.
The offence is broad. The position can be one of trust, of agency, or of fiduciary obligation, and the abuse can be by act or by omission. It is particularly applicable to insider fraud, where an employee in a position of responsibility uses that position to extract value from the employer or from customers. It is also the relevant offence where a director or senior employee uses a position of authority for personal advantage at the company's expense.
Whether the requisite position existed is a question of fact and degree. The Act gives no exhaustive definition. The courts have taken a broad and purposive approach: anything that puts the defendant in a fiduciary-style relationship with the victim, formal or informal, is likely to qualify.
Other Fraud Act offences
The Act also creates a small group of related offences:
| Section 6 | Possession of articles for use in fraud. The article can be anything, including a computer program or document. The intent must be that it be used in the course of, or in connection with, an offence under the Act. |
| Section 7 | Making or supplying articles for use in fraud. Targets the people who create or distribute the tools, kits, scripts, lists or templates that other people use to commit fraud. |
| Section 9 | Participating in fraudulent business by a sole trader. Mirrors the existing offence of fraudulent trading for companies under the Companies Act 2006, extending it to sole traders, partnerships and trusts. |
| Section 11 | Obtaining services dishonestly. Captures situations where a person dishonestly obtains a service without paying, without the elaborate machinery of deception that the old Theft Act offences required. |
Sections 6 and 7 are often charged in addition to substantive Fraud Act offences, particularly where a defendant is the maker or holder of phishing kits, card skimmers, fake invoices, or other instruments of fraud. They are also used as standalone charges where the prosecution has not yet established that a specific substantive fraud offence has been completed.
The test for dishonesty
Every Fraud Act offence requires dishonesty. The modern approach is the one set out by the Supreme Court in Ivey v Genting Casinos (UK) Ltd [2017] UKSC 67 and applied in criminal cases including Barton and Booth v R [2020] EWCA Crim 575. The Ghosh test no longer applies.
Under the Ivey test, the court asks two questions. First, what was the defendant's actual state of knowledge or belief as to the facts? This is a subjective question about what the defendant genuinely thought the situation was, including any honestly held but mistaken beliefs. Second, was the defendant's conduct, judged on the facts as they understood them to be, dishonest by the standards of ordinary, decent people? This is an objective question, judged by the standards of the wider community, not by the standards the defendant set for themselves.
The practical effect of the change is significant. Under the old Ghosh test, a defendant could resist a fraud conviction by arguing that, however much an ordinary jury might disapprove of their conduct, the defendant themselves did not consider it dishonest. That subjective second limb is gone. A defendant cannot now rely on their own personal view of acceptable conduct to defeat the charge. If ordinary people would regard the conduct as dishonest on the facts as the defendant understood them, the test is met.
In practice, the Ivey test means that defendants in financial crime investigations cannot defend their conduct by reference to industry practice, peer behaviour, or their personal view of acceptability. If the conduct is dishonest by ordinary standards, the conviction follows. This has reset expectations in internal investigations, regulatory enforcement, and the way firms communicate about grey-area decisions.
The Theft Act 1968 offences
Two offences in the Theft Act 1968 remain important in the modern fraud landscape: section 17 (false accounting) and section 19 (false statements by company directors). Both predate the Fraud Act and were not absorbed into it. They continue to be charged where they fit the facts better than the Fraud Act offences.
Section 17: False accounting
Section 17 is committed where a person dishonestly, with a view to gain or with intent to cause loss to another, destroys, defaces, conceals or falsifies any account, record or document required for an accounting purpose, or furnishes or makes use of an account or document which they know to be misleading, false or deceptive in a material particular.
The offence carries a maximum sentence of seven years on indictment. In practice, it is the offence most commonly charged in cases of fraudulent book-keeping, falsified expense claims, deliberately misstated management accounts, and falsified reporting to auditors, regulators or counterparties. It does not require any deception in the Fraud Act sense; what it requires is the dishonest manipulation of accounting records with the requisite intent.
Section 17 is often charged alongside a Fraud Act offence. False accounting captures the manipulation of the records, and fraud by false representation captures the use of those records to extract value or to deceive.
Section 19: False statements by company directors
Section 19 makes it an offence for an officer of a body corporate or unincorporated association, or a person purporting to act as such, with intent to deceive members or creditors of the body corporate or association about its affairs, to publish or concur in publishing a written statement or account which to their knowledge is or may be misleading, false or deceptive in a material particular.
The offence carries a maximum sentence of seven years on indictment. It is the natural offence to charge against directors who sign off on misleading annual reports, false trading updates, or fabricated statements to creditors. It overlaps with section 17 (false accounting) and with section 4 of the Fraud Act (abuse of position), and prosecutors typically choose the framing that best matches the conduct in question.
The Computer Misuse Act 1990 and cyber-enabled fraud
Cyber-enabled fraud is now a core risk for regulated firms. In most cases, the substantive fraud charge is a Fraud Act offence, usually under section 2. Where the conduct also involves unauthorised access to a computer system, an offence under the Computer Misuse Act 1990 will often be charged as well.
The Computer Misuse Act 1990 creates three principal offences:
| Section 1 | Unauthorised access to computer material. Knowingly causing a computer to perform a function with the intent to secure access to any program or data held in any computer, where the access is unauthorised. |
| Section 2 | Unauthorised access with intent to commit or facilitate the commission of further offences. The section 1 offence with the aggravating element of an intent to commit a more serious offence, typically fraud. |
| Section 3 | Unauthorised acts with intent to impair, or with recklessness as to impairing, the operation of a computer. Captures cyber-attacks, malware, denial-of-service attacks, and similar conduct. |
Section 3ZA should also be kept in view. It covers unauthorised acts causing, or creating a risk of, serious damage. It is not the routine charge in ordinary fraud matters, but it matters where cyber conduct risks serious damage to human welfare, national security, the economy or the environment.
The Computer Misuse Act has been under Home Office review. The published government response and consultation material considered issues including statutory defences, extra-territorial reach, sentencing, and whether new offences should be created. As at the date of writing, the core statutory framework remains the 1990 Act.
In a typical cyber-enabled fraud case, the prosecution will charge under section 2 of the Fraud Act (false representation, where the representation has been made to a computer system) and either section 1 or section 2 of the Computer Misuse Act (for the unauthorised access element). Section 6 of the Fraud Act may also be charged for the possession of the relevant articles, particularly where the defendant is part of a wider operation.
The common law offence of cheating the public revenue
The common law offence of cheating the public revenue remains available for the most serious tax fraud cases. Most tax fraud is charged under the various statutory offences in the tax legislation, including section 106A of the Taxes Management Act 1970 (fraudulent evasion of income tax) and section 72 of the Value Added Tax Act 1994 (fraudulent evasion of VAT). The common law offence is reserved for cases where the conduct is of such seriousness, complexity, or scale that the prosecution wants the wider sentencing range available on indictment for an unspecified-maximum common law offence.
Cheating the public revenue is committed where a person, by some form of conduct, deprives HM Revenue and Customs of money to which it is entitled. The conduct can be by act or omission, including the failure to declare a tax liability, the deliberate submission of false returns, or the operation of a scheme designed to evade tax that is properly due. It does not require any deception in the technical sense.
The offence carries a theoretical maximum of life imprisonment. In practice, sentences are imposed by reference to the Sentencing Council's definitive guideline on fraud. Cheating the public revenue is charged against the most serious tax fraud, where the prosecution wants the flexibility of an unspecified-maximum offence and the gravity that the common law charge signals.
Sentencing and recent reform
The Sentencing Council's definitive guideline on fraud has been in force since 1 October 2014. It applies to fraud by false representation, fraud by failing to disclose, fraud by abuse of position, false accounting under section 17 of the Theft Act 1968, and conspiracy to defraud at common law. It also covers section 11 (obtaining services dishonestly) and certain related offences.
The guideline operates by reference to two main variables: harm (the actual or intended financial loss, with adjustments for non-financial harm) and culpability (the role of the offender, the degree of planning and sophistication, the nature of the targeted victim, and similar factors). The court places the offence in a category based on those two variables, then identifies a starting point and category range within the guideline. Aggravating and mitigating factors are applied to move within, and in exceptional cases outside, the range.
Maximum sentences for the principal offences are summarised below.
| Fraud Act 2006, s.1 | 10 years on indictment. Summary maximum is the general limit in a magistrates' court. |
| Theft Act 1968, s.17 | 7 years on indictment. 6 months summary. |
| Theft Act 1968, s.19 | 7 years on indictment. 6 months summary. |
| Computer Misuse Act, s.1 | 2 years on indictment. 12 months summary. |
| Computer Misuse Act, s.2 | 5 years on indictment. 12 months summary. |
| Computer Misuse Act, s.3 | 10 years on indictment (life if life is endangered). |
| Cheating the public revenue | Maximum sentence at large. Sentenced by reference to the fraud guideline. |
Sentencing matters because it shapes charging strategy, plea discussions, internal decision-making, and the assessment of litigation risk. The guideline does not alter the substantive law of fraud, but it does shape how seriously cases are investigated, charged, and resolved in practice.
The main fraud types
The criminal law of fraud is broadly the same whatever the typology. What changes is the operational picture: who the victims are, how the fraud is committed, what controls firms are expected to operate, and which regulator takes the lead. The following survey focuses on the main fraud types regulated firms encounter.
Authorised push payment fraud
Authorised push payment, or APP, fraud is fraud where the victim is induced to authorise a payment from their account to one controlled by the fraudster. Because the victim authorises the payment, the historical position was that liability sat with the victim rather than the firm. That position has changed.
The Payment Systems Regulator's mandatory reimbursement rules for in-scope APP fraud took effect on 7 October 2024 and apply to payments made over the Faster Payments and CHAPS systems. The rules require sending and receiving payment service providers to reimburse victims for in-scope losses up to £85,000 per claim, with the cost split equally between the sending and receiving PSPs and claims assessed against a defined standard of customer care. The economics of APP fraud prevention have shifted as a result: firms now have direct financial exposure to APP fraud, and the controls expected of them are correspondingly more robust.
APP fraud typologies include investment fraud (where the victim is persuaded to transfer money to a fake investment platform), romance fraud (where a relationship is fabricated to extract money), purchase fraud (where the victim pays for goods or services that do not exist), invoice fraud (where the victim is induced to pay a legitimate-looking invoice to a fraudster's account), impersonation fraud (where the fraudster poses as a bank, the police, or a government department), and CEO fraud (where the fraudster poses as a senior executive instructing a payment).
Identity fraud and account takeover
Identity fraud is fraud committed using another person's identifying information without their knowledge or consent. It includes the opening of new accounts in the victim's name (application fraud), the takeover of existing accounts (account takeover fraud), and the use of stolen identifying details to obtain credit, services or benefits. The Fraud Act offence is typically section 2 (fraud by false representation, the representation being that the offender is the named individual).
Industry fraud datasets remain useful for tracking identity fraud and account takeover trends. Account takeover, in particular, has grown as authentication systems have hardened against initial application fraud and offenders have shifted to taking over existing accounts where the credentials have already passed checks.
Card and payment fraud
Card and payment fraud covers fraudulent use of payment cards (card present, card not present, lost and stolen, mail non-receipt), and fraudulent use of other payment instruments. Strong Customer Authentication, fully in force for UK e-commerce from March 2022 under the Payment Services Regulations 2017 and the related FCA rules, has materially reduced card-not-present fraud since enforcement began. The picture continues to evolve as new payment methods, particularly tap-to-pay on mobile devices and pay-by-link arrangements, change the attack surface.
Investment fraud
Investment fraud covers the full range of schemes where victims are persuaded to part with money in the expectation of returns that do not materialise. The forms vary widely, from boiler-room operations selling fake shares, through pyramid and Ponzi schemes, to sophisticated long-running deceptions involving fake regulators, fake performance records, and fake withdrawal mechanisms. Cryptoasset-related investment fraud is now a significant part of the landscape. Regulator warning lists and consumer fraud guidance remain useful reference points.
Insider fraud
Insider fraud is fraud committed by employees, contractors, or others with legitimate access to the organisation's systems and assets. It is the typology most likely to be charged under section 4 of the Fraud Act (abuse of position) or section 17 of the Theft Act 1968 (false accounting), depending on the conduct. It is also, in many regulated firms, the typology that is hardest to detect, because the offender starts inside the access controls.
Insider fraud is one of the key risks that the failure to prevent fraud offence under section 199 of ECCTA is designed to address. The reasonable procedures defence requires firms to consider what their employees could do for the firm's benefit, and against the interests of customers, counterparties, or the public revenue, and to put proportionate controls in place. Session Five covers the offence in detail.
Mandate fraud and invoice redirection
Mandate fraud, sometimes called invoice redirection or vendor account takeover, is fraud where the offender impersonates a supplier and persuades the victim organisation to redirect legitimate payments to an account the offender controls. It is one of the most successful fraud typologies against corporate victims, particularly where finance teams are spread thin and supplier change requests come in by email. The Fraud Act offence is typically section 2 (false representation as to the supplier's bank details).
The regulatory framework around fraud
The criminal law of fraud sits inside a broader regulatory framework that imposes obligations on regulated firms to prevent fraud, treat customers who have been victims of fraud fairly, and report fraud through the relevant channels. The principal elements of the framework are summarised below.
| FCA Principles and Consumer Duty | Principle 6 (treating customers fairly) and Principle 12 / Consumer Duty (acting to deliver good outcomes for retail customers) bear directly on how firms prevent and respond to fraud, particularly for vulnerable customers. |
| FCA Financial Crime Guide | FCG sets out the FCA's expectations on fraud controls within regulated firms. Fraud is addressed in FCG 4. |
| PSR mandatory APP reimbursement | In force from 7 October 2024. Applies to in-scope APP fraud losses on Faster Payments and CHAPS. Sets the standard of care expected of sending and receiving PSPs. |
| Online Safety Act 2023 | Imposes duties on regulated online services to take proportionate steps to address fraudulent content, including paid-for fraudulent advertisements. Enforced by Ofcom. |
| Failure to prevent fraud (ECCTA s.199) | Corporate offence in force from 1 September 2025. Applies to large organisations. Reasonable procedures defence. Covered in detail in Session Five. |
| Action Fraud and the NFIB | Action Fraud is the UK's national reporting centre for fraud, operated by City of London Police. Reports feed into the National Fraud Intelligence Bureau. |
This regulatory framework is the layer through which the criminal law becomes operational inside firms. It shapes controls, governance, customer treatment, reporting, investigations, and escalation decisions.
AI as fraud enabler and fraud detector
Generative AI now sits on both sides of the fraud problem. As an enabler, it has reduced the cost and improved the quality of social engineering: deepfake voice and video are used in CEO impersonation and APP fraud, and the text generated for phishing and romance fraud no longer carries the linguistic markers that consumers and firms once relied on. As a detector, AI is increasingly used in transaction monitoring, anomaly detection, and document forensics.
The practical questions are governance ones: how to test the controls, manage model risk, explain decisions to customers and regulators, and keep human judgement in the loop where it matters most. Where model risk, privacy and explainability are material, AI governance materials should sit alongside the fraud control framework.
Jurisdiction equivalents
New Zealand
Fraud in New Zealand is dealt with primarily under the Crimes Act 1961. Sections 240 to 243 cover obtaining by deception and causing loss by deception, which together do much of the work that sections 2 and 3 of the UK Fraud Act do. Section 256 covers forgery, and sections 257 and 258 cover the use and possession of forged documents. False accounting-type conduct may also be charged under section 220 (theft by a person in a special relationship) or section 260 (false statements by promoter, director or officer), depending on the facts. The New Zealand offences are more deception-focused than the post-2006 UK offences, so direct mapping should be avoided.
The Serious Fraud Office is the lead agency for serious or complex fraud in New Zealand, with the police prosecuting the majority of fraud cases. New Zealand does not have a direct equivalent of the UK failure to prevent fraud offence.
Australia
Federal fraud offences are contained in the Criminal Code Act 1995 (Cth). The principal offences are in division 134 (obtaining property or financial advantage by deception) and division 135 (general dishonesty offences, including obtaining a gain or causing a loss by deception and conspiracy to defraud the Commonwealth). The Code defines dishonesty by reference to the standards of ordinary people, without requiring proof that the defendant knew the conduct was dishonest by those standards.
State and territory criminal codes cover fraud committed against non-Commonwealth victims and in non-federal contexts. Each state has its own offences, broadly equivalent in substance to the Commonwealth provisions. Practitioners working across multiple states should refer to the relevant state code rather than relying on the Commonwealth offences alone.
Australia does not have a corporate failure to prevent fraud offence equivalent to UK ECCTA section 199. It does have a corporate failure to prevent foreign bribery offence under section 70.5A of the Criminal Code (Cth), in force from 8 September 2024. Australian fraud control is otherwise driven primarily by AUSTRAC supervision in the AML/CTF context, ASIC enforcement in the corporate and market context, and the ACCC in the consumer context.
Key takeaways
- The Fraud Act 2006 is the primary criminal law of fraud in the UK. Section 1 creates the general offence, committed by breach of section 2 (false representation), section 3 (failure to disclose where there is a legal duty), or section 4 (abuse of position). All three are offender-focused and do not require proof that a specific person was deceived.
- The Theft Act 1968 offences of false accounting (section 17) and false statements by company directors (section 19) remain important. They are typically charged where books and records or director statements are the centre of gravity of the conduct.
- Cyber-enabled fraud is often charged as a Fraud Act offence, with a Computer Misuse Act 1990 offence added for the unauthorised access element.
- The Ivey test for dishonesty, confirmed for criminal law by Barton and Booth, removes the subjective second limb of the old Ghosh test. A defendant cannot rely on their own view of acceptability to defeat the charge.
- The Sentencing Council's fraud guideline has been in force since 2014. For the principal Fraud Act offence, the maximum sentence on indictment is ten years.
- The regulatory framework around fraud has tightened materially. The PSR APP reimbursement regime, the Consumer Duty, the Online Safety Act 2023 duties, and the failure to prevent fraud offence under section 199 of ECCTA all bear on regulated firms.
Coming up in Session Three
Session Three covers the bribery offences in detail. It works through the Bribery Act 2010 sections 1, 2 and 6, the international anti-bribery framework, facilitation payments, gifts and hospitality, and the FCA Principles for Businesses as they apply to bribery and corruption. The corporate offence under section 7 of the Bribery Act is treated alongside the other failure to prevent offences in Session Five. The companion bribery and corruption materials cover adequate procedures and the points where programmes commonly fall short.
Further reading and resources
The following primary sources are the most useful companions to this session. All are publicly available.
- Fraud Act 2006. The principal statute. Sections 1 to 4 (general fraud offence and the three ways of committing it), section 6 (possession of articles), section 7 (making or supplying articles), section 9 (fraudulent business by sole trader), section 11 (obtaining services dishonestly). Available at legislation.gov.uk.
- Theft Act 1968, sections 17 and 19. False accounting and false statements by company directors. Both offences remain in force and are charged regularly. Available at legislation.gov.uk.
- Computer Misuse Act 1990. Sections 1, 2 and 3 (unauthorised access, unauthorised access with intent, unauthorised acts impairing operation). Available at legislation.gov.uk.
- Sentencing Council Definitive Guideline on Fraud, Bribery and Money Laundering. In force since 1 October 2014. Available at sentencingcouncil.org.uk.
- CPS legal guidance on the Fraud Act 2006. The CPS's published guidance to its own prosecutors on charging decisions under the Act. Available at cps.gov.uk.
- Ivey v Genting Casinos (UK) Ltd [2017] UKSC 67 and Barton and Booth v R [2020] EWCA Crim 575. The current test for dishonesty in criminal law. Available on the BAILII database.
- PSR Specific Direction on mandatory reimbursement for APP fraud. In force from 7 October 2024. Available at psr.org.uk.
- FCA Financial Crime Guide, FCG 4. The FCA's guidance on fraud controls in regulated firms. Available through the FCA Handbook.
- Consumer fraud and fraud prevention materials. Companion materials on consumer fraud, vulnerable customers and practical fraud controls. Available on this site.
- Industry fraud datasets. Aggregate data on identity fraud, insider fraud, account takeover and related trends from reputable industry sources.
- New Zealand. Crimes Act 1961, sections 240 to 243, 256 to 258, 220, and 260. Available at legislation.govt.nz.
- Australia. Criminal Code Act 1995 (Cth), divisions 134 and 135. Available at legislation.gov.au.
Ārai Tika