Noxia

Free tool · Calculator

Are you a “large organisation”? Two of three is enough.

Most firms know whether they are small. Fewer have run the actual test, and the two-of-three structure means two middling numbers do the work of one large one. It takes about a minute and the answer changes what you need on file.

Runs in your browser Nothing is sent anywhere Checked 23 September 2026

The short answer

The failure to prevent fraud offence, in force since 1 September 2025, applies to large organisations: those meeting at least two of three criteria — turnover over £36 million, balance sheet total over £18 million, or more than 250 employees. Enter your three figures and this returns whether you are in scope and how much headroom remains on each threshold. The only defence is reasonable prevention procedures in place at the time.

On this page · 5 sections

The example loaded is a firm that fails the test on one criterion and passes on two — which is exactly the case people get wrong, because it does not feel large.

Use the figures from your most recent accounts. Balance sheet total means gross assets before deducting liabilities, and employees means the average number over the period, not headcount today.

Your numbers

Opens on a worked example, not an industry average. Replace every figure with your own — there is no such thing as a default here.

£

From your most recent accounts. The threshold is £36 million.

£

Gross assets, before deducting liabilities. The threshold is £18 million.

Average number over the financial period, across the group. The threshold is more than 250.

Thresholds crossed—two is enough
Closest threshold not crossed—how much headroom is left
In scope?—for the failure to prevent fraud offence

—

What the answer actually changes

If you are in scope, the defence to the offence is having had reasonable fraud prevention procedures in place at the time — measured against six Home Office principles: top level commitment, risk assessment, proportionate risk-based prevention procedures, due diligence, communication and training, and monitoring and review.

Four of those are documentation you either have or do not. Two — risk assessment and monitoring — have to produce something dated, repeatedly. Those are the two that are usually missing, and a policy written after an incident evidences only the date it was written.

What this does not do

It does not tell you whether a particular incident involves one of the specified base offences the legislation attaches to, and it does not model group structures, where the figures may aggregate across subsidiaries in ways that need proper advice.

It is also a size test, not a risk assessment. A firm below every threshold can still have a serious fraud exposure, and a firm above all three can have a small one. The test decides which regime you are in; it says nothing about how likely anything is.

We are not lawyers and this is not legal advice. The figures are the published thresholds and the arithmetic is two-of-three.

If you are below every threshold, buy nothing. Not a compliance programme, not a policy pack, and not anything from us. Write your three figures down with today's date, check them at the next year-end, and spend the money on something that earns.

Questions people actually ask

What counts as a large organisation for failure to prevent fraud?

One meeting at least two of three criteria: turnover over £36 million, balance sheet total over £18 million, or more than 250 employees. Because two of three is sufficient, a firm with a modest balance sheet can be in scope on turnover and headcount alone.

What is the defence to the failure to prevent fraud offence?

Having had reasonable fraud prevention procedures in place at the time of the offence. Home Office guidance assesses this against six principles: top level commitment, risk assessment, proportionate risk-based prevention procedures, due diligence, communication and training, and monitoring and review.

Does the offence apply if nobody senior knew?

Yes. That is the purpose of a failure-to-prevent offence — it removes the requirement to identify a directing mind. The offence arises where an associated person commits a specified fraud intending to benefit the organisation and the organisation lacked reasonable prevention procedures.

What if we are just below the thresholds?

You are not in scope for this offence on size, but growth, an acquisition or a single strong year can cross a second threshold without any decision being taken. The practical answer is to record the three figures at each year-end and check them, rather than rediscovering the position after an incident.

Sources

  1. Wiggin LLP, “Failure to prevent fraud: new law comes into force”, 1 September 2025, re-read 24 September 2026: in force 1 September 2025; “large organisation” means meeting two of three criteria — turnover over £36m, balance sheet total over £18m, or more than 250 employees; the offence arises where an associated person commits a specified fraud intending to benefit the organisation; the defence is reasonable fraud prevention procedures, assessed against six Home Office principles. wiggin.co.uk ↗ — secondary; a law firm’s summary of the offence and the guidance, authoritative on the thresholds and the principles re-checked every 6 months
  2. The offence was introduced by the Economic Crime and Corporate Transparency Act 2023. This tool applies the size test only. It does not identify the specified base offences, model group aggregation, or assess risk. We are not lawyers and this is not legal advice. — a stated limit on the tool above

Checked 23 September 2026. Next scheduled check 23 March 2027. Numbers that move — leaderboards, live indices — are re-checked every 30 days; annual datasets and rules in force every six months; dated research once a year. If something here has gone stale before we got to it, tell us and we will correct it and say what changed.

The two principles that fail are the two that need a date.

Risk assessment and monitoring have to produce something dated, on a schedule, or the defence has nothing to point at. We build that as a running record rather than a document: the register, the recurring check, and the log of who reviewed what and when.

Start the conversation
Calculator: Are you a “large organisation”? Two of three is enough.