The argument
The first year of the offence changes the practical question. The issue is no longer whether organisations have had time to create a policy. It is whether their decisions can be reconstructed from evidence if an associated person commits fraud for an intended organisational or client benefit.
FinCrimeRadar analysisA defensible reasonable procedures position is not a collection of policies. It is a traceable evidence chain connecting the fraud risk, the associated person, the intended benefit pathway, the prevention control, the management decision and the evidence that the control remained appropriate.
This is an analytical position, not wording found in section 199. The Act creates the offence and a defence based on procedures that were reasonable in all the circumstances at the time, or on it being reasonable to have no such procedures.[1] The Home Office guidance supplies six flexible principles, but expressly says that it does not provide a safe harbour and that only the courts can decide whether an organisation's procedures were reasonable.[4]
The practical consequence is narrower than a demand for perfect prevention. A failed control does not, by itself, prove that the procedures were unreasonable. Equally, the existence of a policy, training deck or due diligence file does not, by itself, answer why that measure addressed the relevant fraud risk. The defensible position lies in the connections between the risk understood, the judgement made, the control operated and the evidence retained.
- Risk and actorWhich in-scope fraud could the associated person commit through the role, service or relationship?
- Benefit pathwayHow could the conduct be intended to benefit the organisation, its client or another person served on its behalf?
- Control and decisionWhy was the chosen prevention response proportionate, and who accepted any residual exposure?
- Operation and reviewWhat shows that the response worked in practice and remained appropriate as the risk changed?
The rest of this essay tests that proposition against the statute, the statutory guidance and current prosecutorial guidance. It does not treat the six principles as a checklist, and it does not assume that documentation can rescue a control environment that was ineffective in practice.
What section 199 actually establishes
Statutory sourceSection 199 is not a general offence of corporate fraud. It creates organisational liability only when the statutory conditions connect a relevant body, an associated person, a specified fraud offence and an intended benefit.
The liability route
- Organisation: the core offence applies where the relevant body is a large organisation, judged against turnover, balance sheet and employee-count thresholds.[3] Separate aggregation rules apply where the relevant body is part of a group with a parent undertaking.[8]
- Associated person: the definition includes an employee, agent or subsidiary undertaking and can include another person who performs services for or on behalf of the body. The question is assessed by reference to all relevant circumstances, not merely the contractual label.[1]
- Base offence: the associated person must commit an offence listed in Schedule 13, or aid, abet, counsel or procure such an offence. Schedule 13 includes specified offences under the Fraud Act 2006, Theft Act 1968 and Companies Act 2006, among others.[2]
- Intended benefit: the associated person must intend to benefit the relevant body directly or indirectly, or intend to benefit a person to whom services are provided for or on the body's behalf. For that client-benefit limb, subsection 199(3) excludes liability where the body itself was or was intended to be a victim.[1]
The offence does not require proof that senior managers or directors ordered or knew about the fraud. That removes one traditional attribution barrier, but it does not remove the need to prove the associated person's base offence and the required intention to benefit. Subsection 199(2) also brings in a subsidiary that is not itself large: where the subsidiary's own employee commits fraud intending to benefit that subsidiary, and the fraud occurs in a financial year in which its parent undertaking qualifies as a large organisation, the subsidiary can still be guilty even though it would not meet the size test on its own.[1]
The defence is assessed at the time
Under subsection 199(4), the organisation has a defence if it proves that, when the fraud offence was committed, it had prevention procedures that were reasonable in all the circumstances, or that it was reasonable in all the circumstances not to have any such procedures.[1] The Home Office guidance states that the organisation bears that burden on the balance of probabilities.[4]
Guidance and prosecution contextThe Home Office frames reasonable fraud prevention through six principles: top-level commitment, risk assessment, proportionate risk-based prevention procedures, due diligence, communication including training, and monitoring and review. These principles are outcome-focused rather than a rigid minimum-controls list. The guidance says it will rarely be reasonable not even to have conducted a risk assessment, asks organisations to document decisions not to introduce a specific procedure, and warns that due diligence designed for a different risk may not be adequate for fraud prevention.[4]
The distinction between law and evaluation matters. The six principles are guidance, not additional statutory elements. The CPS says prosecutors can use them to structure lines of inquiry, identify weaknesses or omissions and assess a claimed defence.[5] The SFO's compliance programme guidance similarly treats the section 199 defence as one context in which it may assess whether a programme was effective in practice.[6] Neither source converts a paper framework into an automatic defence.
A targeted search of official SFO, CPS, Judiciary and National Archives case-law sources on 16 September 2026 did not identify a reported judgment applying section 199 or an official announcement of a completed section 199 prosecution. That search result is not proof that no unreported investigation, charge or other matter exists. This essay therefore does not predict how a court will weigh a particular control or evidence record.
The Defensibility Chain
FinCrimeRadar analysisOnce the offence elements are established, subsection 199(4) asks a single question: were the procedures reasonable in all the circumstances at the time, or was it reasonable to have none. In practice, an organisation answers that question by showing how six things connect, not by producing any one of them in isolation.
The six links below are FinCrimeRadar's own practitioner model for organising that evidence. They are not a restatement of section 199(4), and no court has adopted them. Where a link rests on something the statute or guidance actually says, the source is named. Everything else, including the ordering, the framing of each break and the practical consequence, is FinCrimeRadar's application of the statutory test to how these investigations tend to unfold.
-
Fraud risk
- Decision question
- What specific fraud mechanism could an associated person commit through this role, relationship or operating context, and has that mechanism been named rather than assumed to sit inside a general fraud policy?
- Supporting evidence
- A risk assessment that identifies the mechanism, the exposure and the operating context, refreshed when the business or the role changed.
- Common break
- Treating the existence of a fraud policy as proof that the specific mechanism was considered, when the policy never named the pathway that actually occurred.
- Defensibility consequence
- Without a risk-specific record, the organisation is arguing after the fact that a control addressed a risk it never demonstrably identified, which is a harder position to hold.
-
Associated person
- Decision question
- In what capacity was the person acting when the conduct occurred, and does the actual relationship, not the contract label, fit the statutory definition of an associated person?
- Supporting evidence
- Records of the working relationship in practice: instructions given, integration into the organisation's processes, and how the organisation relied on or directed the person's role at the relevant time.
- Common break
- Assuming a contractual label such as "independent contractor" or "introducer" settles the question, when the Act's associated-person test is assessed by reference to all relevant circumstances.
- Defensibility consequence
- If capacity is contested, the organisation ends up arguing status and reasonableness at the same time, which weakens both positions.
-
Intended benefit pathway
- Decision question
- How could the conduct have been intended to benefit the organisation, directly or indirectly, or a person served on its behalf, and does the fact pattern actually support that intention?
- Supporting evidence
- Analysis that traces the alleged conduct to a plausible organisational or client benefit: revenue, cost avoidance, target achievement or a service outcome for a client.
- Common break
- Assuming the benefit element is automatically satisfied because fraud occurred inside the business, without tracing the pathway, or overlooking that subsection 199(3)'s victim exclusion applies only to the client-benefit limb, not to a benefit claimed to run directly to the organisation itself.
- Defensibility consequence
- A benefit pathway that has not been traced leaves the organisation unable to test one of the statutory conditions before reasonableness even becomes the live question.
-
Prevention response
- Decision question
- Which specific control, or combination of controls, was mapped to this named fraud risk, and can that mapping be shown rather than inferred from a general control inventory?
- Supporting evidence
- A control record that states what the control was designed to catch for this risk and why it was proportionate to the risk's likelihood and impact.
- Common break
- Pointing to due diligence, training or monitoring built for a different risk, such as anti-money laundering or bribery, and treating it as fraud coverage because it exists.
- Defensibility consequence
- A control that was never designed for the risk in question does little to support reasonableness, however well it performs its original purpose.
-
Management judgement
- Decision question
- Who owned the decision to accept, mitigate or decline to act on this risk, and is the proportionality reasoning, including any accepted residual exposure, documented at the time rather than reconstructed afterwards?
- Supporting evidence
- A named decision-maker, a proportionality rationale, and, where a procedure was not introduced for a specific risk, a contemporaneous record of that decision and why it was reasonable.
- Common break
- A decision not to act that survives only as institutional memory, when the Home Office guidance specifically asks organisations to document a decision not to introduce a procedure for a given risk.
- Defensibility consequence
- An undocumented judgement forces the organisation to rely on recollection long after the event, which a fact-finder can discount even when the original decision was sound.
-
Operating evidence and review
- Decision question
- What shows the control actually operated as designed, that exceptions were identified and handled, and that the underlying risk assessment stayed current as the business changed?
- Supporting evidence
- Exception logs, review records, evidence that lessons from near misses fed back into the control, and a dated refresh of the risk assessment.
- Common break
- Treating the existence of a control as evidence that it worked, with no operating record, or letting a risk assessment go stale while the business grew or changed.
- Defensibility consequence
- Without operating evidence, a control looks identical whether it was effective or merely present, which is close to the distinction the SFO's compliance programme guidance draws between effective operation and a paper exercise.[6]
None of this converts a missing or weak link into an automatic statutory failure. A gap in the chain increases the organisation's evidential difficulty in discharging the subsection 199(4) burden[1]; it does not, by itself, prove that the procedures were unreasonable, and a full chain does not guarantee that a court will agree they were reasonable either. The judgement remains the court's, on the facts of the case.
Competing interpretations
FinCrimeRadar analysisPractitioners tend to collapse the reasonableness question into one of three shortcuts. Each is understandable and each is incomplete against what the statute and the guidance actually ask.
-
The policy inventory viewIncomplete
Ownership of an anti-fraud policy, a code of conduct and a training deck is treated as the defence itself. This answers whether a document exists, not whether that document addressed the fraud risk that actually materialised. The CPS's own corporate prosecutions guidance treats the six principles as a tool for identifying weaknesses and omissions, which assumes prosecutors will look past the paper rather than stop at it.[5]
-
The six-principle checklist viewIncomplete
Nominal coverage of all six Home Office principles, top-level commitment, risk assessment, proportionate procedures, due diligence, communication and monitoring, is treated as equivalent to reasonableness. The guidance itself frames the principles as outcome-focused and states expressly that it is not a safe harbour and that only a court decides whether procedures were reasonable in a given case.[4]
-
The outcome viewIncomplete
The occurrence of fraud is treated as proof, by itself, that the prevention procedures were unreasonable. Section 199(4) asks whether the procedures were reasonable in all the circumstances at the time, not whether they succeeded in every instance. A failed control is evidence to weigh; it is not, on its own, the statutory test.
-
The evidence-chain viewFinCrimeRadar's preferred reading
Reasonableness is evaluated through the traceable relationship between the fraud risk, the associated person, the benefit pathway, the control, the management judgement and the operating evidence, the Defensibility Chain above. This is FinCrimeRadar's analytical position for organising that evidence, not a judicially settled interpretation of section 199(4). Only a court applying the subsection to particular facts can decide whether specific procedures were reasonable.
Worked decisions
Both scenarios are synthetic. No organisation, person or contract described below is real. The facts are built to test the Defensibility Chain, not to predict how a court would rule.
The revenue-linked misrepresentation
A UK-based enterprise software vendor is a large organisation for the purposes of sections 201 and 202. A regional sales manager, employed directly by the vendor, closes a multi-year licensing contract with a public sector buyer. To satisfy the deal's data-residency eligibility criteria, the manager knowingly submits a certification stating that the vendor's hosting infrastructure meets a requirement it does not meet. The contract is signed, the vendor recognises the revenue, and the manager receives his usual sales commission on top of salary.
- The vendor's generic anti-fraud policy and annual ethics training predate this contract and mention misrepresentation to customers only in passing.
- The vendor's fraud risk assessment has never separately considered sales-side misrepresentation in public sector bids.
- The manager's own manager approved the deal without querying the certification; independent compliance sign-off is only required above a contract value this deal fell below.
- No fraud conclusion has yet been reached. The facts above are what the internal investigation has established so far.
Show Source, Application and Action reasoning
Subsection 199(4) puts the burden on the organisation to prove that its procedures were reasonable in all the circumstances at the time the fraud was committed, or that it was reasonable to have none. The Home Office guidance treats due diligence and controls built for a different purpose as potentially inadequate for fraud prevention specifically.
A generic policy and training deck do not show that the vendor's risk assessment or approval controls addressed misrepresentation risk in public sector sales specifically. Removing the individual answers a personnel question, not the reasonable-procedures question.
Preserve the approval trail, the certification records and the risk assessment history, and assess whether the sign-off threshold and the absence of a sales-fraud risk category were themselves reasonable decisions at the relevant time, documented or not.
Change one fact: what if validation and sign-off controls had already operated?
Suppose independent validation of hosting-compliance certifications, a logged second-line sign-off for public sector deals above this value, and periodic monitoring of override rates had existed and actually operated before this contract was signed.
The assessment changes only partly. A genuinely operating validation and sign-off control would materially strengthen the prevention-response and operating-evidence links, and could support a reasonable-procedures defence for this specific fraud risk. It would not, by itself, prove reasonableness for every risk the vendor faces, and a control that existed on paper but never operated in practice would not change the assessment at all.
The eligibility certification agent
A UK financial services group engages an external market-access agent under a services agreement to help qualifying corporate clients access a government-backed trade guarantee scheme, earning a success fee on the referrals the group approves and submits. Acting under that agreement, the agent deliberately submits false trading-history evidence to make an ineligible client appear to qualify, which increases the group's guaranteed exposure fee income and the client's access to funding.
- The services agreement describes the agent as an "independent introducer" and states the agent is not the group's employee or agent for any regulatory purpose.
- The group's due diligence on the agent was completed under its anti-money laundering and anti-bribery programme and has not been revisited since the agent's role expanded to include eligibility document review.
- Group staff process the agent's submissions with limited independent verification of the underlying trading records.
- No fraud conclusion has yet been reached. The facts above are what has been established so far.
Show Source, Application and Action reasoning
The Act's associated-person definition can include a person who performs services for or on behalf of the body, assessed by reference to all relevant circumstances. The Home Office guidance warns that due diligence designed for a different risk may not be adequate for fraud prevention.
A contractual disclaimer does not resolve associated-person status where the agent's actual role and the group's reliance on the agent's submissions may fit the statutory description. Anti-money laundering and anti-bribery diligence was never designed to test the reliability of eligibility documents.
Document the actual working relationship and the scope of existing due diligence, and assess whether fraud-specific verification of the agent's submissions, not merely financial-crime onboarding, was needed and reasonable given the group's reliance on the agent's work.
Change one fact: what if the agent supplied only a standard product?
Suppose the agent instead supplied the group with standard application-processing software, with no role in preparing or submitting client eligibility evidence.
The assessment changes materially on the associated-person question. A pure product supplier with no service role in the conduct is a different relationship, and the fraud would not obviously arise from services performed for or on the group's behalf. That change does not resolve every other liability route open to a regulator or claimant, and it does not retrospectively validate due diligence that was never tested against the fraud risk in the relationship that actually existed.
What would change the assessment
Evidence limitationThis essay's assessment rests on the statute, the statutory guidance, prosecutorial guidance and the absence of a reported section 199 judgment as at 16 September 2026. FinCrimeRadar would revisit the analysis above if any of the following became available.
- A reported judgment applying section 199 to a specific set of facts, particularly one that tests the reasonable procedures defence.
- A completed prosecution, deferred prosecution agreement or other authoritative charging outcome that gives meaningful treatment to the defence.
- Revised Home Office statutory guidance on the offence.
- Revised CPS or SFO prosecution or compliance-evaluation guidance touching the offence.
- A legislative amendment to sections 199 to 206 of the Act or to Schedule 13.
- Reliable evidence that courts or prosecutors are, in practice, applying a materially different approach to programme effectiveness or to what evidence they treat as sufficient.
None of these would necessarily change the Defensibility Chain's structure. Several would change how much weight particular links deserve, or would answer questions this essay currently leaves open.
Practitioner summary
Six failure patterns recur across both scenarios above. Keep them visible when reviewing any fraud-prevention control environment, not only the two worked here.
The Inward-Only Map
- Risk
- Fraud committed for the organisation's benefit sits outside a risk assessment built only to catch fraud against the organisation.
- Signal
- The risk register lists external and third-party fraud threats, with no line item for an employee or agent acting to benefit the business itself.
- Response
- Add an explicit fraud-for-the-organisation risk category naming the roles that could commit it.
The Contract-Label Blind Spot
- Risk
- A third party genuinely performing services for or on behalf of the organisation is excluded from scope because the contract calls them an independent operator.
- Signal
- Due diligence stops at "not an employee" without testing the actual working relationship.
- Response
- Assess associated-person status on the relationship in practice, not the label, and document that assessment.
The Benefit-Path Gap
- Risk
- The organisation cannot show whether the intended-benefit element is satisfied, or excluded, before the reasonable-procedures defence even becomes relevant.
- Signal
- Investigation files record the fraudulent act but never analyse the fee income, contract value or client outcome it was meant to produce.
- Response
- Trace the specific benefit pathway and record whether the organisation, rather than a third party, was the intended victim.
The Paper Shield
- Risk
- A control mapped to a different risk gets credited as though it covered this one.
- Signal
- The same policy clause or training module is cited in answer to every fraud risk, regardless of mechanism.
- Response
- Map each control explicitly to the fraud risk it addresses and show the gap where none exists.
The Silent Override
- Risk
- A control that would have caught the fraud was never triggered, and no one is accountable for that gap.
- Signal
- Sign-off thresholds and their rationale exist only informally or were never reviewed against actual deal sizes.
- Response
- Require a named, contemporaneous rationale for every sign-off threshold, reviewed on a cycle that matches the risk.
Stale Assurance
- Risk
- Diligence performed for anti-money laundering or bribery purposes is relied on for fraud prevention without ever being refreshed for that purpose.
- Signal
- The due diligence file predates the relationship's current scope and was never revisited after the agent's role changed.
- Response
- Refresh and re-scope due diligence specifically for fraud risk at defined intervals or trigger events.
Knowledge check
Choose one answer for each question. The score supports review and does not certify legal compliance.
FAQ
Does one instance of fraud mean the procedures were unreasonable?
No. Section 199(4) asks whether procedures were reasonable in all the circumstances at the time, not whether they succeeded on every occasion. A failed control is evidence to weigh; it does not, by itself, prove the procedures were unreasonable.
Are existing anti-money laundering, bribery or whistleblowing controls sufficient?
Not automatically. The Home Office guidance warns that due diligence and controls designed for a different risk may not be adequate for fraud prevention. Each control needs to be mapped to the fraud risk it is meant to address.
Does a contract decide whether a third party is an associated person?
No. The Act's associated-person question is assessed by reference to all relevant circumstances, not the contractual label. A disclaimer in a services agreement does not settle the question on its own.
Can having no prevention procedures ever be reasonable?
Yes, in narrow circumstances. Subsection 199(4) allows a defence where it was reasonable in all the circumstances to have no such procedures, though the guidance says it will rarely be reasonable not even to have conducted a risk assessment.
What should be retained as evidence?
Risk assessments naming the specific fraud mechanism, control mappings showing which control addresses which risk, approval and override records, exception logs, and any documented decision not to introduce a particular procedure.
Is the Defensibility Chain a statutory test?
No. It is FinCrimeRadar's own analytical framework for organising evidence relevant to section 199(4). No court has adopted it, and it is not a substitute for the statutory language or a court's own assessment of the facts.
Sources and methodology
Scope: this Evidence Essay analyses the UK failure to prevent fraud offence as at 16 September 2026. The Defensibility Chain, the competing-interpretations analysis and both worked scenarios are FinCrimeRadar's own practitioner framework and synthetic teaching material; they are not statutory text, judicial authority or legal advice.
Method: every statutory and regulatory proposition below was checked directly against the cited primary source on 16 September 2026, not taken from secondary commentary. A separate targeted search of official SFO, CPS, Judiciary and National Archives case-law sources on the same date did not identify a reported judgment applying section 199 or an official announcement of a completed section 199 prosecution. That absence of a result is not proof that no unreported matter exists, and this essay does not treat it as one.
- [1] Economic Crime and Corporate Transparency Act 2023, section 199legislation.gov.uk (UK National Archives), current text as enacted. Supports the offence structure, the associated-person and intended-benefit conditions, the section 199(3) victim exclusion, the section 199(2) subsidiary route, and the section 199(4) reasonable-procedures defence and its timing. Open source → Evidence reviewed 16 September 2026.
- [2] Economic Crime and Corporate Transparency Act 2023, Schedule 13legislation.gov.uk (UK National Archives). Supports the list of base fraud offences, including offences under the Fraud Act 2006, the Theft Act 1968 and section 993 of the Companies Act 2006. Does not cover every fraud-related offence in English law, only those Schedule 13 lists. Open source → Evidence reviewed 16 September 2026.
- [3] Economic Crime and Corporate Transparency Act 2023, section 201legislation.gov.uk (UK National Archives). Supports the large-organisation size test: turnover, balance sheet total and employee-count thresholds, at least two of three met in the preceding financial year. Does not itself cover a group structure; see source 8 for the separate group-aggregation rule. Open source → Evidence reviewed 16 September 2026.
- [4] Home Office, Economic Crime and Corporate Transparency Act 2023: guidance to organisations on the offence of failure to prevent fraud (accessible version)Updated 10 October 2025. Supports the six-principle framing, the express safe-harbour disclaimer, the balance-of-probabilities defence burden, the guidance on risk assessment, on documenting a decision not to introduce a procedure, and on due diligence built for a different risk. Statutory guidance, not binding law; it explicitly disclaims safe-harbour status. Open source → Evidence reviewed 16 September 2026.
- [5] Crown Prosecution Service, Corporate Prosecutions guidancecps.gov.uk, updated 10 November 2025. Supports the statement that CPS treats the six principles as a tool for structuring lines of inquiry, identifying weaknesses or omissions, and assessing a claimed defence. Prosecutorial guidance describing the CPS's own approach, not a judicial ruling on any specific set of procedures. Open source → Evidence reviewed 16 September 2026.
- [6] Serious Fraud Office, Guidance on Evaluating a Corporate Compliance ProgrammePublished 26 November 2025. Supports the statement that the SFO names the section 199 defence as a context for evaluating whether a compliance programme operated effectively rather than existing only on paper. SFO evaluation guidance, not a finding on any particular organisation's programme, and not binding on a court's own assessment under section 199(4). Open source → Evidence reviewed 16 September 2026.
- [7] The Economic Crime and Corporate Transparency Act 2023 (Commencement No. 4) Regulations 2025 (SI 2025/349)legislation.gov.uk (UK National Archives), made 13 March 2025. Supports the statement that sections 199 to 206 of, and Schedule 13 to, the Act came into force on 1 September 2025. A commencement instrument, not the substantive offence itself. Open source → Evidence reviewed 16 September 2026.
- [8] Economic Crime and Corporate Transparency Act 2023, section 202legislation.gov.uk (UK National Archives). Supports the group-aggregation rule: a parent undertaking is a large organisation if its group, aggregating each member's turnover, balance sheet total and employee count under section 201, met at least two of the three thresholds. A specific group structure needs checking against section 202 directly. Open source → Evidence reviewed 16 September 2026.