UK Crime and Policing Act 2026

Senior manager attribution now goes wider than fraud

UK Crime and Policing Act 2026

Fraud and Financial Crime · Article

The Crime and Policing Act 2026: senior manager attribution now goes wider than fraud

Section 250 removed the fence around senior manager liability. What began as an economic crime issue for compliance teams is now a corporate criminal liability issue for every function in the organisation.

Russel Fielding  |  July 2026  |  LLM (Distinction) in Fraud and Financial Crime, PMP, CIPM, PRINCE2

For more than two years, senior manager attribution was treated as an economic crime problem. Section 196 of the Economic Crime and Corporate Transparency Act 2023 meant that if a senior manager committed fraud, false accounting, bribery, money laundering, or one of a defined list of other offences within the scope of their authority, the organisation committed that offence too. Compliance teams built training around it, general counsel briefed the board on it, and everyone else filed it under financial crime and moved on.

Once section 250 was in force, that filing was wrong. The Crime and Policing Act 2026 removed the list. Senior manager attribution now applies to criminal offences that can be committed by a body corporate or partnership, not just the economic ones. This is not a technical update to an existing regime. It is a different regime, and it belongs on the desk of the health and safety lead, the data protection officer and the environmental compliance function as much as it belongs on the desk of the MLRO.

From directing mind to senior manager

For most of the last century, prosecuting a company for a criminal offence meant identifying its directing mind and will: someone senior enough, usually at board level, to be treated as the company itself. Tesco Supermarkets Ltd v Nattrass set that standard in 1972. It made large, complex organisations difficult to prosecute because the person committing the underlying offence was often several layers below the board.

ECCTA’s answer, in force from 26 December 2023, was section 196: a statutory senior manager test, but confined to the list of economic offences in Schedule 12. It was a genuine reform, but a bounded one. During the Act’s passage, wider corporate criminal liability reform remained on the policy agenda.

Section 250 is that wider reform. It replaces section 196 rather than sitting alongside it, and it retains the same definition of senior manager and the same actual or apparent authority test. What it drops is the list. From 29 June 2026, if a senior manager commits a criminal offence that can be committed by a body corporate or partnership while acting within the actual or apparent scope of their authority, the organisation is also liable for that offence.

What actually changed

Three things separate section 250 from the failure to prevent offences most compliance functions already know well.

There is no statutory procedures defence. Failure to prevent bribery, failure to prevent the facilitation of tax evasion, and failure to prevent fraud all carry a defence: show the organisation had adequate or reasonable procedures in place, and the prosecution fails. Section 250 has no equivalent. A well designed compliance programme, properly resourced and genuinely embedded, remains relevant to sentencing and to a prosecutor’s public interest assessment. It is not a legal defence to the charge itself.

There is no size threshold. Failure to prevent fraud applies only to large organisations, broadly those meeting two of three thresholds: more than 250 employees, more than £36 million turnover, and more than £18 million in assets. Section 250 applies to bodies corporate and partnerships of every size, including LLPs, where governance structures and defined roles are often less formal than in a large company.

There is no requirement that the organisation benefited. An organisation can be liable under section 250 even where it was itself harmed by the senior manager’s conduct, provided the conduct otherwise falls within the actual or apparent scope of the senior manager’s authority. Benefit to the organisation, which matters under the failure to prevent offences, is not the attribution test here.

The offence list that no longer exists

Because section 250 has no schedule, there is no tidy list to circulate. The offences now capable of being attributed to an organisation through a senior manager may include environmental offences under the Environmental Protection Act 1990, unauthorised access and impairment offences under the Computer Misuse Act 1990, unlawful obtaining or disclosure of personal data under the Data Protection Act 2018, offences under the Modern Slavery Act 2015, perverting the course of justice, and sector-specific health and safety offences where operational failure has physical consequences. This is not a complete list, and building one is less useful than accepting the underlying point: the criminal law now travels wherever a senior manager’s authority travels.

Who counts as a senior manager

The definition has not changed from ECCTA, which is precisely the point: it was always wider than most organisations assumed. A senior manager is anyone who plays a significant role in decisions about how the whole, or a substantial part, of the organisation’s activities are managed or organised, or in the actual managing or organising of the whole, or a substantial part, of those activities. It is a functional test, not a title test. It typically includes the obvious names: directors, the chief financial officer and the chief operating officer. It also reaches divisional heads, regional managing directors, and anyone else whose actual influence over a substantial part of the business meets the test, regardless of what their contract calls them.

It is also worth being precise about what it is not. The senior manager population under section 250 is not the same as the Senior Managers and Certification Regime population in regulated financial services. The two can overlap heavily, but SMCR is defined by prescribed functions and responsibilities, while the section 250 test is defined by what someone actually does. An organisation that has mapped its SMCR population and stopped there has not mapped its section 250 exposure.

Authority, under this test, is also not only what the organisation formally granted. Apparent authority counts too. A senior manager who acted outside their internal mandate but appeared, to a reasonable outsider, to be acting within it can still bring the organisation into the frame. A breach of internal policy is not, by itself, a shield.

What this actually asks organisations to do

None of this calls for panic, nor does it require a new department. It calls for treating senior manager exposure as a live governance question rather than a legal footnote.

Start with the population, not the policy. Most organisations can name their board. Far fewer can produce, without a scramble, a defensible list of who else meets the functional senior manager test, and on what basis. That list, and the reasoning behind it, is the first thing worth having ready.

Understand where authority actually sits, not where the organisation chart says it sits. Scope of authority, actual and apparent, is the whole test. An organisation that cannot describe what a given role is authorised to do, and cannot show that description was communicated clearly enough to constrain apparent authority as well, has a gap worth closing before an investigator finds it.

Treat escalation and investigation readiness as a control, not an afterthought. Because there is no statutory procedures defence, the value of a strong compliance programme has shifted from avoiding liability to shaping what happens if liability is alleged to attach. Prosecutorial discretion, sentencing, and any negotiated outcome will all consider what the organisation did once it knew, or ought to have known, that something was wrong.

A UK reform, for now

Neither New Zealand nor Australia has followed the UK down this specific path. New Zealand continues to rely on the common law identification doctrine, shaped by the Privy Council’s decision in Meridian Global Funds Management Asia Ltd v Securities Commission, itself on appeal from New Zealand. Australia’s Criminal Code Act 1995 includes attribution through high managerial agents and corporate culture concepts that have no direct UK equivalent. Organisations operating across all three jurisdictions now face different attribution rules in each one, which is its own governance problem and worth naming rather than assuming away.

Final thought

The failure to prevent offences taught compliance functions to think in terms of adequate procedures: build the programme, document it, and it becomes your defence. Section 250 does not work that way. No programme makes a senior manager’s criminal conduct someone else’s problem.

The only real answer is knowing, with precision, who your senior managers are, what they are actually authorised to do, and how quickly the organisation notices and responds when one of them steps outside that authority. That is harder than building a defence file. It is also the discipline now required.

Russel Fielding

LLM (Distinction), Fraud and Financial Crime  ·  PMP  ·  CIPM  ·  PRINCE2 Practitioner

Russel is a senior transformation consultant with more than two decades of experience as a business owner and inside large regulated organisations across financial services, higher education and professional sport. He writes russelfielding.com to share practical knowledge on compliance, transformation and financial crime, free and without registration.