A lot of fraud problems start with something small enough to dismiss. A mismatch in the ledger. A supplier query that doesn’t quite add up. A manager pushing hard to recognise revenue early. By the time the issue becomes obvious, the business owner is no longer dealing with a bookkeeping irritation. They’re dealing with loss, exposure, and a decision that has to be made quickly.
That pressure has changed. In the UK, fraud inside a business is no longer only a matter of recovery, dismissal, insurance, or litigation strategy. For some organisations, it is now a criminal law issue for the company itself. For others outside the formal scope, it has become a commercial issue because larger customers, lenders, investors, and legal advisers increasingly want proof that fraud risks are being managed properly.
If you run an SME or a mid-market company, or advise one, the right question is no longer “Could fraud happen here?” The right question is “Could we show, with evidence, that we took reasonable steps to prevent it?”
The Unseen Threat That Can Ruin Your Business
The call usually comes late. Your finance lead has found a pattern in the bank reconciliations. A customer disputes invoices that your team insists are correct. A stock shortfall appears, then grows. Someone says it’s probably an error. Someone else says it has been happening for months.
That’s the point where directors often realise the damage isn’t limited to the missing money. Fraud contaminates trust. It disrupts reporting, relationships, valuations, lending conversations, and legal strategy. It pulls management away from trading and into damage control.

When a private problem becomes a corporate exposure
For years, many businesses treated fraud as an internal misfortune. You investigated, tried to contain the loss, spoke to solicitors, and hoped the matter stayed quiet. That approach is no longer enough where the law expects prevention, not just reaction.
The practical problem is that fraud rarely arrives with a label. It may look like an aggressive sales tactic, a convenient journal entry, a manipulated expense claim, a side arrangement with a supplier, or a third party saying what your company wants said. The conduct can sit inside ordinary operations for a long time before anyone joins the dots.
Practical rule: Trust matters in business. Trust is not a control.
Business owners often tell me the same thing in different words. “We’ve known these people for years.” “Our culture is strong.” “We’d know if something was wrong.” Sometimes they would. Often they wouldn’t. Fraud survives where documentation is weak, oversight is light, and nobody wants to challenge a profitable result.
The first mistake is delay
Once suspicion arises, delay makes everything harder. Records get overwritten. Stories settle. Staff talk to each other. Third parties start protecting themselves. If lawyers become involved later, they inherit a messier factual picture and a weaker evidential base.
A useful starting point for non-specialists is this Blowfish Technology fraud guide, because it helps frame the operational warning signs before a business reaches full crisis mode. That matters because the new legal environment rewards businesses that can show active fraud thinking, not businesses that only react after the loss has become undeniable.
What keeps directors awake now isn’t only the fraud itself. It’s the prospect that a business can suffer the fraud, fund the investigation, absorb the reputational fallout, and still face scrutiny over whether it should have prevented the conduct in the first place.
Understanding the Failure to Prevent Fraud Offence
The legal change sits in the Economic Crime and Corporate Transparency Act 2023. The new failure to prevent fraud offence takes effect from 1 September 2025 under section 199, and it allows prosecutors to hold a company criminally liable where an associated person commits a specified fraud offence intending to benefit the organisation, unless the organisation can prove it had reasonable prevention procedures in place, as outlined in this overview of the Economic Crime and Corporate Transparency Act.
What the offence actually does
The easiest way to understand it is this. The law asks not only, “Did someone commit fraud?” It also asks, “Was that person acting in a way connected to the company, and can the company prove it took reasonable steps to stop that happening?”
That is a major shift in corporate accountability. A prosecution doesn’t depend on proving that senior management personally carried out the fraud. The company can be exposed because of what an associated person did for its benefit.
Who counts as an associated person
The term is deliberately broad. It can include employees, agents, subsidiaries, and representatives. In practice, the risk is wider than many boards first assume because business gets done through people who sit both inside and outside the legal entity.
A useful analogy is this. If your business sends people into the market to win work, negotiate terms, produce figures, secure funding, or speak to customers, the law doesn’t stop at the payroll list when asking who created the fraud risk.
Which organisations are in scope
The offence applies to large organisations. The threshold used in the material provided is that a company is in scope if it meets at least two of these criteria: £36m turnover, £18m balance sheet, 250 employees. That catches many mid-market groups that do not think of themselves as large in any practical sense.
For business owners, this matters for two reasons:
- Group structures matter: A business can be closer to the threshold than management realises.
- Growth changes the analysis: An acquisition, restructuring, or period of expansion can move a company into scope faster than expected.
The fraud offences covered
The offence is broad because the underlying fraud offences are broad. The verified material states that it covers nine key fraud types drawn from UK statutes, including:
- Fraud by false representation
- Fraud by failing to disclose information
- Fraud by abuse of position
- Fraudulent trading
- False accounting
- Obtaining services fraudulently
- Cheating the public revenue
- False statements by company directors
Those offences come from existing UK legislation, including the Fraud Act 2006, Companies Act 2006, and Theft Act 1968, as summarised in the analysis at Regulatory and Compliance.
The broad point is simple. If a person connected to your business commits a qualifying fraud to benefit the business, the company may have to defend its own prevention framework in criminal terms.
Why this is different from ordinary anti-fraud work
Most businesses already have some controls. Finance policies. Delegated authorities. Audit trails. Staff handbooks. Approval limits. That doesn’t mean they have a defensible failure to prevent fraud framework.
The legal test is not whether your policies look respectable in a board pack. It is whether they were reasonable for your fraud risks, and whether you can prove that with documents, decisions, training records, monitoring, and follow-up.
That distinction catches companies out. They think they have governance. What they have is paperwork with no fraud mapping behind it.
The High Stakes of Non-Compliance
When directors hear “failure to prevent fraud”, many assume the issue belongs to compliance teams and listed groups. That’s too narrow. The stakes are legal, commercial, and personal.
For organisations in scope, the penalties include unlimited fines, potential director disqualification, and serious reputational damage. The offence also has extraterritorial reach where there is a UK nexus. A fraud issue that starts in operations can quickly become a board issue, a lender issue, and a disputes issue.

The direct consequences
A corporate fraud investigation drains management time long before any final outcome. Accounts must be reviewed. data preserved. staff interviewed. legal strategy coordinated. external messaging controlled. If the issue touches customers, funders, or public authorities, the circle widens quickly.
The reputational effect is often underestimated. Even where a business survives the immediate financial hit, commercial counterparties start asking harder questions. Why didn’t controls spot this earlier? Who approved the transaction? Why should we trust the numbers now?
SMEs are not outside the problem
Even where a company is not itself in scope, larger counterparties may still treat fraud controls as a condition of doing business. That pressure is already visible in the material provided. A 2024 PwC UK Economic Crime Survey found 42% of SMEs under 250 employees reported fraud incidents in the past 24 months, and 26% lacked basic prevention procedures, as cited in Proskauer’s analysis of the offence.
That matters because large organisations now have their own incentive to review the fraud risk posed by suppliers, agents, introducers, and delivery partners. If your business cannot satisfy those due diligence questions, you may lose work before any allegation of wrongdoing is ever made.
The same Proskauer material also notes estimates that non-compliant mid-market firms could lose £50k-£200k annually in lost opportunities. Whether that loss appears through delayed onboarding, reduced panel inclusion, failed tenders, or heavier contract terms, the commercial message is clear. Buyers prefer suppliers who can explain their controls clearly and evidence them cleanly.
A short view and a long view
Here is the trade-off many businesses face:
| Immediate instinct | Longer-term consequence |
|---|---|
| Keep spend low and rely on trust | Harder to prove prevention later |
| Use generic policies | Weak defence if risks were never mapped |
| Wait until a problem appears | Evidence deteriorates and options narrow |
| Assume clients won’t ask | Due diligence catches up during renewal or tender |
If a board treats fraud prevention as optional administration, the market may treat that board as a risk.
The companies that manage this well do something very unglamorous. They create evidence. They can show what risks they identified, why they ranked them as they did, what controls they introduced, who they trained, which third parties they reviewed, and how they tested whether the controls worked.
Common Objections and Why They No Longer Stand
Businesses don’t usually fail on fraud prevention because nobody cares. They fail because they rely on assumptions that once felt sensible and now create risk.
We trust our people
Good businesses should trust their people. But fraud risk doesn’t disappear because the culture feels decent. In fact, long-serving and highly trusted individuals can create the greatest blind spots because colleagues stop challenging them.
The underlying problem involves segregation of duties, override risk, pressure around targets, and weak review of exceptions. A trusted finance manager who can post journals, approve changes, and explain variances without challenge presents a very different risk from one who works inside a documented review structure.
Use trust to build teams. Use controls to protect the business.
Controls will slow us down
Poorly designed controls do slow businesses down. That objection has some truth in it. Heavy approval chains, duplicated sign-offs, and irrelevant training frustrate staff and create workarounds.
Proportionate controls are different. A forensic accountant doesn’t start by importing a big-company compliance manual into a growing business. They start by asking where fraud could realistically occur, who could do it, what benefit the business might receive, and what evidence would show the control works.
That usually leads to targeted changes, not blanket bureaucracy. Examples include clearer approval logic for manual adjustments, fraud-specific wording in third-party contracts, exception reporting around unusual transactions, and role-based training for the people who face the main risk.
This law only affects large corporates
Legally, the offence targets large organisations. Commercially, that’s not where the story ends. If your customer, principal, funder, or acquirer is in scope, your controls may become part of their due diligence.
That changes the conversation for SMEs and owner-managed businesses. You may never face prosecution under this offence. You may still lose contracts, face tougher onboarding, or attract harsher warranties and indemnities if you cannot demonstrate sensible anti-fraud governance.
We already have policies
Many companies do have policies. The problem is that they often sit at the wrong level of abstraction. A code of conduct is not a fraud risk assessment. A generic whistleblowing policy is not the same as a prevention framework tied to your specific revenue lines, procurement model, approval routes, and third-party relationships.
A court or investigator is unlikely to be impressed by documents that were never connected to identified fraud risks.
We’ll deal with it if something happens
That is the most expensive approach. Once suspicion hardens into allegation, you need to preserve evidence, manage employees carefully, brief solicitors, and protect privilege where possible. All of that becomes more difficult if the business has never mapped its risks or documented its controls.
A more realistic view is this:
- Prevention reduces legal exposure: It gives you a defence framework.
- Preparation reduces investigation cost: Clean records and clear controls shorten the fact-finding process.
- Documentation improves credibility: Boards, insurers, counterparties, and legal advisers take a better view of businesses that can evidence decisions.
The objection usually sounds financial. The underlying issue is often uncertainty about what proportionate action looks like.
That is exactly where a forensic accounting exercise earns its place. It converts a vague fear into a defined risk map, a control plan, and an evidence trail that people can effectively use.
Building Your Defence with Reasonable Procedures
The only defence to a failure to prevent fraud charge is proving that the organisation had reasonable prevention procedures in place. That phrase causes most of the anxiety because it sounds subjective. In practice, it becomes manageable once you build it around the government’s principles and document each decision properly.

The most important point from the published guidance is that a dynamic, documented risk assessment sits at the centre of the defence. The assessment should analyse opportunity, motive, and rationalisation, and proportionate controls should follow from that analysis, as summarised in this Skillcast guide to failure to prevent fraud guidance.
Start with the fraud risk assessment
Here, businesses either build a defensible position or create a false sense of security.
A proper fraud risk assessment asks practical questions. Where can someone manipulate reporting? Where can management estimates be bent? Which third parties interact with customers or public bodies on our behalf? Which teams face pressure linked to bonuses, margins, or contract renewal? Where could someone persuade themselves that the conduct is justified?
Those questions need written answers. Undocumented thinking is very hard to rely on later.
A useful companion read for directors and legal teams is this legal guide on preventing business fraud, because it helps translate the legal principle into operational questions that can be asked inside the business.
Apply the six principles in a practical way
The six principles are familiar in outline. What matters is how they operate in your business.
-
Top-level commitment
Boards need to do more than approve a policy. They should show that fraud prevention sits within governance, decision-making, and reporting. Minutes, board papers, and follow-up actions matter. -
Risk assessment
This is the engine room. The assessment should be specific to the business model, not copied from another sector. A retailer, logistics operator, and financial services firm face different fraud pressure points. -
Proportionate procedures
Controls should match the risk. A known vulnerability in revenue recognition needs a different response from a low-risk back-office process.
What proportionate controls often look like
In practice, the strongest frameworks tend to include a mix of operational, contractual, and monitoring controls:
- Targeted sign-offs: Additional review around manual journals, unusual credits, round-sum adjustments, or late changes to reporting assumptions.
- Third-party due diligence: More scrutiny of agents, introducers, distributors, and high-risk suppliers. Contract terms can include fraud clauses and escalation rights.
- Role-specific training: Sales, finance, procurement, and senior management should not all receive the same generic message.
- Adapted internal audit work: Existing audits can be amended to screen specifically for fraud anomalies rather than ordinary process compliance.
- Monitoring and review: Procedures need regular reassessment as trading patterns, staffing, systems, and counterparties change.
For businesses that want a structured starting point, this fraud risk assessment checklist for UK organisations is one example of how the work can be organised around identifiable weak spots.
Why generic compliance fails
A health and safety process does not prevent false accounting. A broad ethics statement does not address override risk in financial reporting. Businesses often overestimate the value of policies that have never been adapted for fraud-specific scenarios.
What works is specificity. If the risk sits in management estimates, build review around estimates. If the risk sits in third parties, strengthen diligence and contract controls. If the risk sits in incentive structures, review how commercial pressure might drive misconduct.
The practical discussion below is worth watching because it helps put “reasonable procedures” into a business context rather than a purely legal one.
Working rule: If you cannot show why a control exists, who owns it, and how you test it, you probably do not yet have a reliable defence.
A forensic accounting team is often most valuable here because it bridges legal risk, financial process, and evidence. It can identify where the business is exposed, challenge assumptions management has normalised, and document the reasoning in a form that stands up later.
A Forensic Accountant’s Role in Prevention and Response
The six principles behind a failure to prevent fraud defence closely mirror what good forensic accounting work already does. Risk assessment, due diligence, monitoring, policy support, training input, and documented review are not add-ons to the discipline. They are core parts of it, as discussed in this Travers Smith commentary on the guidance.

Proactive defence
In prevention work, a forensic accountant tests the business in the places where ordinary management reporting can be too optimistic. That means examining transaction flows, approvals, override points, unusual trends, reporting adjustments, third-party dependencies, and the quality of documentary support behind key decisions.
The output should be practical, not academic. A board needs to know where the exposure sits, what controls already exist, what gaps remain, and what should be documented now.
Typical preventive work includes:
- Fraud risk assessments: Mapping opportunity, motive, and rationalisation across functions and third-party relationships.
- Control reviews: Stress-testing segregation of duties, approvals, reconciliations, anomaly review, and management override exposure.
- Due diligence support: Looking more closely at high-risk agents, suppliers, or counterparties where the business may inherit fraud risk.
- Reporting frameworks: Creating evidence trails that show the board considered the risk and implemented a reasoned response.
For businesses seeking that kind of support, Lighthouse Consultants’ work on the role of forensic accountants outlines how forensic accounting can sit alongside legal, audit, and compliance functions.
Reactive response
When suspicion has already arisen, the forensic accountant’s role changes, but it becomes even more critical. The immediate tasks are to secure evidence, reconstruct events, quantify loss, and separate fact from speculation.
That often involves reviewing accounting records, transaction histories, journal patterns, invoices, communications, and supporting documents with a litigation mindset. The aim is not merely to say that something looks wrong. It is to establish what happened, who was involved, what the financial effect was, and what evidence can support disciplinary action, recovery work, settlement discussions, insurance claims, or court proceedings.
A strong forensic accounting response can also help legal teams by turning complex financial events into a clear chronology. That matters in witness preparation, pleadings, negotiations, and expert evidence.
Why this matters to directors and lawyers
Directors need evidence they can act on. Lawyers need financial analysis they can rely on. Internal teams often sit too close to the issue to provide either with enough independence.
That is why forensic accounting matters on both sides of the problem. Before an issue, it helps create a defensible prevention framework. After an issue, it helps establish the facts in a way that survives scrutiny.
A useful test is whether the analysis would still make sense if it were disclosed in a negotiation, disciplinary process, or courtroom. If not, it needs more work.
Conclusion From Liability to Leadership
The businesses that handle failure to prevent fraud well do not treat it as a box-ticking burden. They treat it as proof that the company is organised, credible, and serious about governance.
That matters far beyond criminal law. A business with documented fraud risk assessment, sensible controls, clear reporting lines, and evidence of review is easier to trust. Customers notice it during procurement. Investors notice it during due diligence. Lawyers notice it when a dispute erupts. Boards notice it when a problem appears and the facts are still manageable.
The opposite is also true. Businesses that rely on habit, trust, and generic policy wording leave themselves exposed at the worst possible moment. They may discover that what felt efficient in peacetime becomes expensive under scrutiny.
Three practical conclusions follow.
- First, this risk is real: The legal framework changes the consequences of inaction.
- Second, the defence is proactive: You cannot invent reasonable procedures after the event.
- Third, the work must be evidenced: A good intention is not the same as a documented control environment.
For SMEs and mid-market companies, there is also a wider commercial reason to act. Even if your business sits outside the formal scope today, larger counterparties may still expect the discipline that the law has brought into focus. If you can answer those questions clearly, you protect more than compliance. You protect contracts, reputation, and negotiating position.
This is a good moment to be deliberate. Review where fraud could benefit the business, where associated persons create exposure, which controls work, and what you could prove if challenged. Where the answer is uncertain, bring in specialists who can bridge accounting evidence, operational reality, and legal risk.
A calm, structured response is always cheaper than a rushed one built in the middle of a crisis.
If you want a confidential discussion about your fraud exposure, control gaps, or the evidence needed for a defensible prevention framework, speak to Lighthouse Consultants. Their forensic accounting team works with business owners, boards, and lawyers on fraud risk assessments, investigations, internal audits, loss quantification, and expert reporting across UK disputes and compliance matters.
Tags: forensic accountant, forensic accounting



