Failure to Prevent Fraud Offence: Guidance and Size Test
· 6 minute read
The failure to prevent fraud offence is a corporate crime that applies only to large organisations, defined by a size test on turnover, assets and staff. This guide covers what the offence is, who it applies to, and the reasonable procedures defence, alongside our failure to prevent fraud guidance summary and a size test below. This is general awareness information, not legal advice, stated as at September 2026 and last reviewed 24 September 2026.
What the failure to prevent fraud offence is
The offence is in section 199 of the Economic Crime and Corporate Transparency Act 2023 and came into force on 1 September 2025 (SI 2025/349) (legislation.gov.uk). It applies only to large organisations, as defined by the size test below.
Failure to prevent fraud guidance
The Home Office published statutory guidance on 6 November 2024. It sets out six principles an organisation’s procedures should follow: top-level commitment, risk assessment, proportionate risk-based prevention procedures, due diligence, communication (including training), and monitoring and review. The defence to the offence is that the organisation had reasonable procedures in place, proved on the balance of probabilities, or that it was not reasonable to expect it to have any.

The size test
Under section 201 of the Economic Crime and Corporate Transparency Act 2023 (legislation.gov.uk), a body is a large organisation only if it met two or more of these conditions in the financial year before the year of the fraud offence: turnover more than £36 million; balance sheet total (total assets) more than £18 million; average number of employees more than 250. “More than” is strict, so exactly 250 employees does not meet that condition. Employee numbers are the monthly average across the financial year, and turnover is adjusted proportionately if the financial year is not twelve months.
If your organisation is the parent of a group, section 202 (legislation.gov.uk) assesses you on your whole group’s aggregate figures instead: aggregate turnover more than £36 million net, or £43.2 million gross; aggregate balance sheet total more than £18 million net, or £21.6 million gross; aggregate employees more than 250.

The offence and the hub, and how they differ
This page covers the corporate criminal offence and who it applies to. Our Fraud Prevention hub covers something different: day-to-day fraud recognition training by role, for every employee, regardless of whether your organisation meets the size test. Many organisations use both: the corporate offence is about your organisation’s own liability, and role training is about your people spotting fraud aimed at them or your customers.
Train your team on this
Failure to Prevent Fraud: The UK’s New Corporate Crime covers the offence, the size test and the six principles in more depth, for the people in your organisation who need to act on this. See the course. It sits within our governance and compliance courses.
Frequently asked questions
What is the failure to prevent fraud offence?
A corporate offence in section 199 of the Economic Crime and Corporate Transparency Act 2023, in force since 1 September 2025, that applies only to large organisations. It is committed where a person associated with the organisation, such as an employee, agent or subsidiary, commits a specified fraud offence intending to benefit the organisation or its clients, unless the organisation can show reasonable prevention procedures.
Who does the failure to prevent fraud offence apply to?
Only large organisations, defined by a size test: meeting two or more of three conditions on turnover, balance sheet total and average employees in the previous financial year. Use our size test above for your own figures.
What is the defence to the failure to prevent fraud offence?
That the organisation had reasonable procedures in place to prevent the fraud, proved on the balance of probabilities, or that it was not reasonable to expect it to have any. The Home Office's statutory guidance sets out six principles these procedures should follow.
More from Insights
All insights-
Data (Use and Access) Act 2025: What's Confirmed So Far
The Data (Use and Access) Act 2025 commenced most of its data protection changes on 5 February 2026, with a new complaints duty from 19 June 2026.
-
Employment Rights Act 2025 Changes: The Full Timeline
The Employment Rights Act 2025 changes arrive in stages from December 2025 to 2027. The Act was previously called the Employment Rights Bill.
-
Subject Access Request Time Limit: A Free Calculator
The subject access request time limit is one month from receipt, at the latest, but extensions and stopping the clock can move your deadline.
Ready to train your team?
Tell us which courses you're interested in and roughly how many learners, and we'll come back with a price within 24 hours.