Skip to main content
Evidence Essay

Failure to Prevent Fraud, One Year On: Reasonable Procedures Are an Evidence Chain

One year after section 199 came into force, the harder question is not whether an organisation owns fraud controls. It is whether it can show why those controls were reasonable for the fraud risk that existed at the time.

Jurisdiction
United Kingdom
Primary regime
Economic Crime and Corporate Transparency Act 2023, section 199
Effective date
[7]
Publication date
Evidence reviewed
Audience
Fraud risk, financial crime, compliance, investigations and governance practitioners

The argument

The first year of the offence changes the practical question. The issue is no longer whether organisations have had time to create a policy. It is whether their decisions can be reconstructed from evidence if an associated person commits fraud for an intended organisational or client benefit.

FinCrimeRadar analysis
A defensible reasonable procedures position is not a collection of policies. It is a traceable evidence chain connecting the fraud risk, the associated person, the intended benefit pathway, the prevention control, the management decision and the evidence that the control remained appropriate.

This is an analytical position, not wording found in section 199. The Act creates the offence and a defence based on procedures that were reasonable in all the circumstances at the time, or on it being reasonable to have no such procedures.[1] The Home Office guidance supplies six flexible principles, but expressly says that it does not provide a safe harbour and that only the courts can decide whether an organisation's procedures were reasonable.[4]

The practical consequence is narrower than a demand for perfect prevention. A failed control does not, by itself, prove that the procedures were unreasonable. Equally, the existence of a policy, training deck or due diligence file does not, by itself, answer why that measure addressed the relevant fraud risk. The defensible position lies in the connections between the risk understood, the judgement made, the control operated and the evidence retained.

  • Risk and actorWhich in-scope fraud could the associated person commit through the role, service or relationship?
  • Benefit pathwayHow could the conduct be intended to benefit the organisation, its client or another person served on its behalf?
  • Control and decisionWhy was the chosen prevention response proportionate, and who accepted any residual exposure?
  • Operation and reviewWhat shows that the response worked in practice and remained appropriate as the risk changed?

The rest of this essay tests that proposition against the statute, the statutory guidance and current prosecutorial guidance. It does not treat the six principles as a checklist, and it does not assume that documentation can rescue a control environment that was ineffective in practice.

What section 199 actually establishes

Statutory source

Section 199 is not a general offence of corporate fraud. It creates organisational liability only when the statutory conditions connect a relevant body, an associated person, a specified fraud offence and an intended benefit.

The liability route

  • Organisation: the core offence applies where the relevant body is a large organisation, judged against turnover, balance sheet and employee-count thresholds.[3] Separate aggregation rules apply where the relevant body is part of a group with a parent undertaking.[8]
  • Associated person: the definition includes an employee, agent or subsidiary undertaking and can include another person who performs services for or on behalf of the body. The question is assessed by reference to all relevant circumstances, not merely the contractual label.[1]
  • Base offence: the associated person must commit an offence listed in Schedule 13, or aid, abet, counsel or procure such an offence. Schedule 13 includes specified offences under the Fraud Act 2006, Theft Act 1968 and Companies Act 2006, among others.[2]
  • Intended benefit: the associated person must intend to benefit the relevant body directly or indirectly, or intend to benefit a person to whom services are provided for or on the body's behalf. For that client-benefit limb, subsection 199(3) excludes liability where the body itself was or was intended to be a victim.[1]

The offence does not require proof that senior managers or directors ordered or knew about the fraud. That removes one traditional attribution barrier, but it does not remove the need to prove the associated person's base offence and the required intention to benefit. Subsection 199(2) also brings in a subsidiary that is not itself large: where the subsidiary's own employee commits fraud intending to benefit that subsidiary, and the fraud occurs in a financial year in which its parent undertaking qualifies as a large organisation, the subsidiary can still be guilty even though it would not meet the size test on its own.[1]

The defence is assessed at the time

Under subsection 199(4), the organisation has a defence if it proves that, when the fraud offence was committed, it had prevention procedures that were reasonable in all the circumstances, or that it was reasonable in all the circumstances not to have any such procedures.[1] The Home Office guidance states that the organisation bears that burden on the balance of probabilities.[4]

Guidance and prosecution context

The Home Office frames reasonable fraud prevention through six principles: top-level commitment, risk assessment, proportionate risk-based prevention procedures, due diligence, communication including training, and monitoring and review. These principles are outcome-focused rather than a rigid minimum-controls list. The guidance says it will rarely be reasonable not even to have conducted a risk assessment, asks organisations to document decisions not to introduce a specific procedure, and warns that due diligence designed for a different risk may not be adequate for fraud prevention.[4]

The distinction between law and evaluation matters. The six principles are guidance, not additional statutory elements. The CPS says prosecutors can use them to structure lines of inquiry, identify weaknesses or omissions and assess a claimed defence.[5] The SFO's compliance programme guidance similarly treats the section 199 defence as one context in which it may assess whether a programme was effective in practice.[6] Neither source converts a paper framework into an automatic defence.

Evidence limitation

A targeted search of official SFO, CPS, Judiciary and National Archives case-law sources on 16 September 2026 did not identify a reported judgment applying section 199 or an official announcement of a completed section 199 prosecution. That search result is not proof that no unreported investigation, charge or other matter exists. This essay therefore does not predict how a court will weigh a particular control or evidence record.

The Defensibility Chain

FinCrimeRadar analysis

Once the offence elements are established, subsection 199(4) asks a single question: were the procedures reasonable in all the circumstances at the time, or was it reasonable to have none. In practice, an organisation answers that question by showing how six things connect, not by producing any one of them in isolation.

The six links below are FinCrimeRadar's own practitioner model for organising that evidence. They are not a restatement of section 199(4), and no court has adopted them. Where a link rests on something the statute or guidance actually says, the source is named. Everything else, including the ordering, the framing of each break and the practical consequence, is FinCrimeRadar's application of the statutory test to how these investigations tend to unfold.

None of this converts a missing or weak link into an automatic statutory failure. A gap in the chain increases the organisation's evidential difficulty in discharging the subsection 199(4) burden[1]; it does not, by itself, prove that the procedures were unreasonable, and a full chain does not guarantee that a court will agree they were reasonable either. The judgement remains the court's, on the facts of the case.

Competing interpretations

FinCrimeRadar analysis

Practitioners tend to collapse the reasonableness question into one of three shortcuts. Each is understandable and each is incomplete against what the statute and the guidance actually ask.

  • The policy inventory viewIncomplete

    Ownership of an anti-fraud policy, a code of conduct and a training deck is treated as the defence itself. This answers whether a document exists, not whether that document addressed the fraud risk that actually materialised. The CPS's own corporate prosecutions guidance treats the six principles as a tool for identifying weaknesses and omissions, which assumes prosecutors will look past the paper rather than stop at it.[5]

  • The six-principle checklist viewIncomplete

    Nominal coverage of all six Home Office principles, top-level commitment, risk assessment, proportionate procedures, due diligence, communication and monitoring, is treated as equivalent to reasonableness. The guidance itself frames the principles as outcome-focused and states expressly that it is not a safe harbour and that only a court decides whether procedures were reasonable in a given case.[4]

  • The outcome viewIncomplete

    The occurrence of fraud is treated as proof, by itself, that the prevention procedures were unreasonable. Section 199(4) asks whether the procedures were reasonable in all the circumstances at the time, not whether they succeeded in every instance. A failed control is evidence to weigh; it is not, on its own, the statutory test.

  • The evidence-chain viewFinCrimeRadar's preferred reading

    Reasonableness is evaluated through the traceable relationship between the fraud risk, the associated person, the benefit pathway, the control, the management judgement and the operating evidence, the Defensibility Chain above. This is FinCrimeRadar's analytical position for organising that evidence, not a judicially settled interpretation of section 199(4). Only a court applying the subsection to particular facts can decide whether specific procedures were reasonable.

Worked decisions

Both scenarios are synthetic. No organisation, person or contract described below is real. The facts are built to test the Defensibility Chain, not to predict how a court would rule.

Scenario 01, internal associated person

The revenue-linked misrepresentation

A UK-based enterprise software vendor is a large organisation for the purposes of sections 201 and 202. A regional sales manager, employed directly by the vendor, closes a multi-year licensing contract with a public sector buyer. To satisfy the deal's data-residency eligibility criteria, the manager knowingly submits a certification stating that the vendor's hosting infrastructure meets a requirement it does not meet. The contract is signed, the vendor recognises the revenue, and the manager receives his usual sales commission on top of salary.

  • The vendor's generic anti-fraud policy and annual ethics training predate this contract and mention misrepresentation to customers only in passing.
  • The vendor's fraud risk assessment has never separately considered sales-side misrepresentation in public sector bids.
  • The manager's own manager approved the deal without querying the certification; independent compliance sign-off is only required above a contract value this deal fell below.
  • No fraud conclusion has yet been reached. The facts above are what the internal investigation has established so far.
What is the strongest next step for the vendor's reasonable-procedures position?

Show Source, Application and Action reasoning
Source

Subsection 199(4) puts the burden on the organisation to prove that its procedures were reasonable in all the circumstances at the time the fraud was committed, or that it was reasonable to have none. The Home Office guidance treats due diligence and controls built for a different purpose as potentially inadequate for fraud prevention specifically.

Application

A generic policy and training deck do not show that the vendor's risk assessment or approval controls addressed misrepresentation risk in public sector sales specifically. Removing the individual answers a personnel question, not the reasonable-procedures question.

Action

Preserve the approval trail, the certification records and the risk assessment history, and assess whether the sign-off threshold and the absence of a sales-fraud risk category were themselves reasonable decisions at the relevant time, documented or not.

Change one fact: what if validation and sign-off controls had already operated?

Suppose independent validation of hosting-compliance certifications, a logged second-line sign-off for public sector deals above this value, and periodic monitoring of override rates had existed and actually operated before this contract was signed.

The assessment changes only partly. A genuinely operating validation and sign-off control would materially strengthen the prevention-response and operating-evidence links, and could support a reasonable-procedures defence for this specific fraud risk. It would not, by itself, prove reasonableness for every risk the vendor faces, and a control that existed on paper but never operated in practice would not change the assessment at all.

Scenario 02, third-party associated person

The eligibility certification agent

A UK financial services group engages an external market-access agent under a services agreement to help qualifying corporate clients access a government-backed trade guarantee scheme, earning a success fee on the referrals the group approves and submits. Acting under that agreement, the agent deliberately submits false trading-history evidence to make an ineligible client appear to qualify, which increases the group's guaranteed exposure fee income and the client's access to funding.

  • The services agreement describes the agent as an "independent introducer" and states the agent is not the group's employee or agent for any regulatory purpose.
  • The group's due diligence on the agent was completed under its anti-money laundering and anti-bribery programme and has not been revisited since the agent's role expanded to include eligibility document review.
  • Group staff process the agent's submissions with limited independent verification of the underlying trading records.
  • No fraud conclusion has yet been reached. The facts above are what has been established so far.
How should the group assess this fact pattern?

Show Source, Application and Action reasoning
Source

The Act's associated-person definition can include a person who performs services for or on behalf of the body, assessed by reference to all relevant circumstances. The Home Office guidance warns that due diligence designed for a different risk may not be adequate for fraud prevention.

Application

A contractual disclaimer does not resolve associated-person status where the agent's actual role and the group's reliance on the agent's submissions may fit the statutory description. Anti-money laundering and anti-bribery diligence was never designed to test the reliability of eligibility documents.

Action

Document the actual working relationship and the scope of existing due diligence, and assess whether fraud-specific verification of the agent's submissions, not merely financial-crime onboarding, was needed and reasonable given the group's reliance on the agent's work.

Change one fact: what if the agent supplied only a standard product?

Suppose the agent instead supplied the group with standard application-processing software, with no role in preparing or submitting client eligibility evidence.

The assessment changes materially on the associated-person question. A pure product supplier with no service role in the conduct is a different relationship, and the fraud would not obviously arise from services performed for or on the group's behalf. That change does not resolve every other liability route open to a regulator or claimant, and it does not retrospectively validate due diligence that was never tested against the fraud risk in the relationship that actually existed.

What would change the assessment

Evidence limitation

This essay's assessment rests on the statute, the statutory guidance, prosecutorial guidance and the absence of a reported section 199 judgment as at 16 September 2026. FinCrimeRadar would revisit the analysis above if any of the following became available.

  • A reported judgment applying section 199 to a specific set of facts, particularly one that tests the reasonable procedures defence.
  • A completed prosecution, deferred prosecution agreement or other authoritative charging outcome that gives meaningful treatment to the defence.
  • Revised Home Office statutory guidance on the offence.
  • Revised CPS or SFO prosecution or compliance-evaluation guidance touching the offence.
  • A legislative amendment to sections 199 to 206 of the Act or to Schedule 13.
  • Reliable evidence that courts or prosecutors are, in practice, applying a materially different approach to programme effectiveness or to what evidence they treat as sufficient.

None of these would necessarily change the Defensibility Chain's structure. Several would change how much weight particular links deserve, or would answer questions this essay currently leaves open.

Practitioner summary

Six failure patterns recur across both scenarios above. Keep them visible when reviewing any fraud-prevention control environment, not only the two worked here.

The Inward-Only Map

The risk assessment maps fraud against the organisation, and stops there.

Risk
Fraud committed for the organisation's benefit sits outside a risk assessment built only to catch fraud against the organisation.
Signal
The risk register lists external and third-party fraud threats, with no line item for an employee or agent acting to benefit the business itself.
Response
Add an explicit fraud-for-the-organisation risk category naming the roles that could commit it.

The Contract-Label Blind Spot

A supplier agreement is treated as settling who counts as an associated person.

Risk
A third party genuinely performing services for or on behalf of the organisation is excluded from scope because the contract calls them an independent operator.
Signal
Due diligence stops at "not an employee" without testing the actual working relationship.
Response
Assess associated-person status on the relationship in practice, not the label, and document that assessment.

The Benefit-Path Gap

Fraud is confirmed, but nobody has traced whom it was meant to help.

Risk
The organisation cannot show whether the intended-benefit element is satisfied, or excluded, before the reasonable-procedures defence even becomes relevant.
Signal
Investigation files record the fraudulent act but never analyse the fee income, contract value or client outcome it was meant to produce.
Response
Trace the specific benefit pathway and record whether the organisation, rather than a third party, was the intended victim.

The Paper Shield

A generic anti-fraud policy is held up against a fraud it was never designed to catch.

Risk
A control mapped to a different risk gets credited as though it covered this one.
Signal
The same policy clause or training module is cited in answer to every fraud risk, regardless of mechanism.
Response
Map each control explicitly to the fraud risk it addresses and show the gap where none exists.

The Silent Override

An approval threshold was met on paper, and nobody queried what sat beneath it.

Risk
A control that would have caught the fraud was never triggered, and no one is accountable for that gap.
Signal
Sign-off thresholds and their rationale exist only informally or were never reviewed against actual deal sizes.
Response
Require a named, contemporaneous rationale for every sign-off threshold, reviewed on a cycle that matches the risk.

Stale Assurance

Due diligence built for a different risk is trusted to still be current for this one.

Risk
Diligence performed for anti-money laundering or bribery purposes is relied on for fraud prevention without ever being refreshed for that purpose.
Signal
The due diligence file predates the relationship's current scope and was never revisited after the agent's role changed.
Response
Refresh and re-scope due diligence specifically for fraud risk at defined intervals or trigger events.

Knowledge check

Choose one answer for each question. The score supports review and does not certify legal compliance.

1. Beyond the associated person's base offence, what must the prosecution also establish for a section 199 conviction?
2. How is associated-person capacity assessed?
3. Which statement about the intended-benefit element is correct?
4. Who carries the reasonable-procedures defence burden, and to what standard?
5. What is the correct relationship between the Home Office guidance and FinCrimeRadar's Defensibility Chain?

FAQ

Does one instance of fraud mean the procedures were unreasonable?

No. Section 199(4) asks whether procedures were reasonable in all the circumstances at the time, not whether they succeeded on every occasion. A failed control is evidence to weigh; it does not, by itself, prove the procedures were unreasonable.

Are existing anti-money laundering, bribery or whistleblowing controls sufficient?

Not automatically. The Home Office guidance warns that due diligence and controls designed for a different risk may not be adequate for fraud prevention. Each control needs to be mapped to the fraud risk it is meant to address.

Does a contract decide whether a third party is an associated person?

No. The Act's associated-person question is assessed by reference to all relevant circumstances, not the contractual label. A disclaimer in a services agreement does not settle the question on its own.

Can having no prevention procedures ever be reasonable?

Yes, in narrow circumstances. Subsection 199(4) allows a defence where it was reasonable in all the circumstances to have no such procedures, though the guidance says it will rarely be reasonable not even to have conducted a risk assessment.

What should be retained as evidence?

Risk assessments naming the specific fraud mechanism, control mappings showing which control addresses which risk, approval and override records, exception logs, and any documented decision not to introduce a particular procedure.

Is the Defensibility Chain a statutory test?

No. It is FinCrimeRadar's own analytical framework for organising evidence relevant to section 199(4). No court has adopted it, and it is not a substitute for the statutory language or a court's own assessment of the facts.

Sources and methodology

Scope: this Evidence Essay analyses the UK failure to prevent fraud offence as at 16 September 2026. The Defensibility Chain, the competing-interpretations analysis and both worked scenarios are FinCrimeRadar's own practitioner framework and synthetic teaching material; they are not statutory text, judicial authority or legal advice.

Method: every statutory and regulatory proposition below was checked directly against the cited primary source on 16 September 2026, not taken from secondary commentary. A separate targeted search of official SFO, CPS, Judiciary and National Archives case-law sources on the same date did not identify a reported judgment applying section 199 or an official announcement of a completed section 199 prosecution. That absence of a result is not proof that no unreported matter exists, and this essay does not treat it as one.

  1. [1] Economic Crime and Corporate Transparency Act 2023, section 199legislation.gov.uk (UK National Archives), current text as enacted. Supports the offence structure, the associated-person and intended-benefit conditions, the section 199(3) victim exclusion, the section 199(2) subsidiary route, and the section 199(4) reasonable-procedures defence and its timing. Open source → Evidence reviewed 16 September 2026.
  2. [2] Economic Crime and Corporate Transparency Act 2023, Schedule 13legislation.gov.uk (UK National Archives). Supports the list of base fraud offences, including offences under the Fraud Act 2006, the Theft Act 1968 and section 993 of the Companies Act 2006. Does not cover every fraud-related offence in English law, only those Schedule 13 lists. Open source → Evidence reviewed 16 September 2026.
  3. [3] Economic Crime and Corporate Transparency Act 2023, section 201legislation.gov.uk (UK National Archives). Supports the large-organisation size test: turnover, balance sheet total and employee-count thresholds, at least two of three met in the preceding financial year. Does not itself cover a group structure; see source 8 for the separate group-aggregation rule. Open source → Evidence reviewed 16 September 2026.
  4. [4] Home Office, Economic Crime and Corporate Transparency Act 2023: guidance to organisations on the offence of failure to prevent fraud (accessible version)Updated 10 October 2025. Supports the six-principle framing, the express safe-harbour disclaimer, the balance-of-probabilities defence burden, the guidance on risk assessment, on documenting a decision not to introduce a procedure, and on due diligence built for a different risk. Statutory guidance, not binding law; it explicitly disclaims safe-harbour status. Open source → Evidence reviewed 16 September 2026.
  5. [5] Crown Prosecution Service, Corporate Prosecutions guidancecps.gov.uk, updated 10 November 2025. Supports the statement that CPS treats the six principles as a tool for structuring lines of inquiry, identifying weaknesses or omissions, and assessing a claimed defence. Prosecutorial guidance describing the CPS's own approach, not a judicial ruling on any specific set of procedures. Open source → Evidence reviewed 16 September 2026.
  6. [6] Serious Fraud Office, Guidance on Evaluating a Corporate Compliance ProgrammePublished 26 November 2025. Supports the statement that the SFO names the section 199 defence as a context for evaluating whether a compliance programme operated effectively rather than existing only on paper. SFO evaluation guidance, not a finding on any particular organisation's programme, and not binding on a court's own assessment under section 199(4). Open source → Evidence reviewed 16 September 2026.
  7. [7] The Economic Crime and Corporate Transparency Act 2023 (Commencement No. 4) Regulations 2025 (SI 2025/349)legislation.gov.uk (UK National Archives), made 13 March 2025. Supports the statement that sections 199 to 206 of, and Schedule 13 to, the Act came into force on 1 September 2025. A commencement instrument, not the substantive offence itself. Open source → Evidence reviewed 16 September 2026.
  8. [8] Economic Crime and Corporate Transparency Act 2023, section 202legislation.gov.uk (UK National Archives). Supports the group-aggregation rule: a parent undertaking is a large organisation if its group, aggregating each member's turnover, balance sheet total and employee count under section 201, met at least two of the three thresholds. A specific group structure needs checking against section 202 directly. Open source → Evidence reviewed 16 September 2026.