Noxia

Field note · What we found

Two of three, and you have a criminal offence to defend.

Most corporate offences require somebody senior to have done something. This one requires an employee to have committed fraud intending to benefit the organisation, and for the organisation to have had no reasonable procedures in place to stop it. The size test is the first thing to run, and it catches firms that do not think of themselves as large.

4 min read Sources checked 23 September 2026

The short answer

The failure to prevent fraud offence came into force on 1 September 2025. It applies to large organisations, defined as meeting at least two of three criteria: turnover over £36 million, balance sheet total over £18 million, or more than 250 employees. The offence is committed when an associated person commits a specified fraud intending to benefit the organisation. The only defence is having had reasonable fraud prevention procedures in place, measured against six Home Office principles.

On this page · 6 sections

Run the test before reading anything else, because if you fail it the rest is background reading and if you pass it the rest is a deadline you have already missed.

The size testAn organisation is large for the purposes of the failure to prevent fraud offence if it meets at least two of three criteria: turnover over 36 million pounds, balance sheet total over 18 million pounds, or more than 250 employees. Meeting two or three of these brings the organisation in scope. Meeting one or none leaves it out of scope for the offence, though its directors and the individuals involved remain liable for fraud itself.THE SIZE TESTTurnover, balance sheet, headcountHow many thresholds do you cross?Two or threeIn scope. The defence is your procedures.One or noneOut of scope for this offence only.Close to a thresholdGrowth crosses it without a decision being taken.Thresholds: turnover over £36m, balance sheet total over £18m, more than 250 employees.The size testAn organisation is large for the purposes of the failure to prevent fraud offence if it meets at least two of three criteria: turnover over 36 million pounds, balance sheet total over 18 million pounds, or more than 250 employees. Meeting two or three of these brings the organisation in scope. Meeting one or none leaves it out of scope for the offence, though its directors and the individuals involved remain liable for fraud itself.THE SIZE TESTTurnover, balance sheet, headcountHow many thresholds do you cross?Two or threeIn scope. The defence is your procedures.One or noneOut of scope for this offence only.Close to a thresholdGrowth crosses it without a decision beingtaken.Thresholds: turnover over £36m, balance sheet totalover £18m, more than 250 employees.
A two-of-three test, which means two mid-sized numbers do what one large one would.Wiggin LLP briefing on the failure to prevent fraud offence, read 23 September 2026.

Two of three is the part that surprises people. A firm with a £40m turnover and 260 staff is large even if its balance sheet is thin. So is a property business with a heavy balance sheet, a modest turnover and 300 people on the books.

What the offence actually is

It is not a duty to prevent all fraud, and it is not liability for fraud committed against you. It is committed when an associated person — an employee, agent, subsidiary or someone else performing services for the organisation — commits a specified fraud intending to benefit the organisation, and the organisation had no reasonable prevention procedures.

Three consequences follow from that wording and they are worth separating.

  1. Nobody senior has to know. That is the point of a failure-to-prevent offence. The old identification doctrine required a directing mind; this does not.
  2. The fraud has to be aimed at benefiting you. An employee defrauding their own employer is not this offence. An employee inflating a claim, misleading a customer or cooking a tender to win work is.
  3. Your procedures are the defence, and they have to exist before the event. A policy written after an incident is evidence of nothing except the date it was written.
The defence is not that fraud did not happen. It is that you had reasonable procedures in place at the time it did.

The six principles the defence is measured against

Home Office guidance sets out six: top level commitment, risk assessment, proportionate risk-based prevention procedures, due diligence, communication and training, and monitoring and review.

Four of those six are documentation exercises that a firm either has or does not. Two of them — risk assessment and monitoring — are the ones that need to produce a dated artefact on a recurring basis, and they are the two most likely to be missing. A risk assessment done once in 2025 and never revisited satisfies neither.

The practical form this takes in a business of that size is a register: what could an employee do that would benefit us dishonestly, what stops it, who checks, and when was that last checked. If that document does not exist, the defence has nothing to point at.

Where the fraud risk actually sits now

There is a specific modern version of this worth naming: a system that generates output on the organisation's behalf. If your software writes quotes, claims, tender responses or customer-facing statements, and it overstates something in a way that wins you business, the question of who committed the fraud gets complicated — but the question of whether you had procedures to prevent it does not.

That is a variant of the problem in automated decisions about people and the reason we keep arguing for an audit layer: a record of what the system was shown and what it produced is the only thing that turns "we do not know what happened" into evidence.

What this does not tell you

It does not list the specified frauds. The offence attaches to a defined schedule of base offences and whether a given incident is one of them is a legal question about facts we do not have.

We are not lawyers and this is not legal advice on your exposure. What we would say is that the size test is a five-minute exercise with three numbers you already have, and that a firm which has not run it is not making a judgement — it is deferring one. The same is true of the thresholds in the eleven-duty grid, and the size test itself is a free calculator.

Questions people actually ask

Who does the failure to prevent fraud offence apply to?

Large organisations, defined as meeting at least two of three criteria: turnover over £36 million, balance sheet total over £18 million, or more than 250 employees. Because two of three is enough, a firm with a modest balance sheet can still be in scope on turnover and headcount alone.

When did the failure to prevent fraud offence come into force?

1 September 2025. It was introduced by the Economic Crime and Corporate Transparency Act 2023 and creates corporate criminal liability where an associated person commits a specified fraud intending to benefit the organisation.

What is the defence to failure to prevent fraud?

Having had reasonable fraud prevention procedures in place at the time of the offence. Home Office guidance measures this against six principles: top level commitment, risk assessment, proportionate risk-based prevention procedures, due diligence, communication and training, and monitoring and review.

Does the offence cover fraud committed against the organisation?

No. The offence requires the associated person to have intended to benefit the organisation. An employee stealing from their own employer is a different matter; an employee inflating a claim or misleading a customer to win the organisation work is the case this offence addresses.

Sources

  1. Wiggin LLP, “Failure to prevent fraud: new law comes into force”, 1 September 2025, re-read 24 September 2026: the offence came into force 1 September 2025; “large organisation” means meeting two of three criteria — turnover over £36m, balance sheet total over £18m, or more than 250 employees; the offence arises where an associated person commits a specified fraud intending to benefit the organisation; the defence is reasonable fraud prevention procedures, assessed against six Home Office principles — top level commitment, risk assessments, proportionate risk-based prevention procedures, due diligence, communication and training, and monitoring and review. wiggin.co.uk ↗ — secondary; a law firm’s summary of the offence and the guidance. Authoritative on the thresholds and the six principles, not a substitute for the statute re-checked every 6 months
  2. The offence was introduced by the Economic Crime and Corporate Transparency Act 2023. The schedule of specified base offences is not reproduced here and whether a given incident falls within it is a legal question. — a stated limit on the coverage above
  3. The observation that four of the six principles are documentation and two must produce a dated artefact on a recurring basis, and the point about systems that generate output on the organisation’s behalf, are ours. We are not lawyers. — our own argument, labelled as such

Checked 23 September 2026. Next scheduled check 23 March 2027. Numbers that move — leaderboards, live indices — are re-checked every 30 days; annual datasets and rules in force every six months; dated research once a year. If something here has gone stale before we got to it, tell us and we will correct it and say what changed.

Cite this note

Noxia, “Two of three, and you have a criminal offence to defend”, Field notes, 23 September 2026; sources checked 23 September 2026. https://www.noxia.co.uk/field-notes/two-of-three-and-you-have-an-offence

A risk register is a document. Keeping it current is a pipeline.

The two principles that fail audits — risk assessment and monitoring — need a dated artefact produced on a schedule, not a policy written once. We build that: the register, the recurring check, the record of who reviewed what and when, exportable in a form somebody else can read.

Talk to us about this