The expansion of UK corporate criminal liability

Section 250 of the Crime and Policing Act 2026 (“CPA”) significantly expands the scope of corporate criminal liability in the UK. Under the new regime, organisations can be liable where a “senior manager” commits a criminal offence when “acting within the actual or apparent scope of their authority”.

This reform expands the circumstances in which criminal liability may be attributed to organisations for offences committed by their people. For businesses, the impact is clear: the risk of criminal liability arising from the conduct of senior personnel has increased significantly.

The previous framework

Traditionally, corporate criminal liability in the UK relied on the identification doctrine requiring prosecutors to establish that an organisation’s “directing mind and will” was involved in the offending conduct. This presented an obstacle to the prosecution of large organisations with complex governance structures.

Three reforms have sought to address the obstacle.

Three key developments

First, section 196 of the Economic Crime and Corporate Transparency Act 2023 (“ECCTA”) introduced a senior management attribution test for specified economic crimes including fraud, false accounting and bribery.

Second, section 199 ECCTA introduced the ‘failure to prevent fraud’ offence. Extending the ‘failure to prevent’ model beyond bribery and tax evasion facilitation, the offence creates criminal liability for large organisations where an associated person commits a specified fraud offence for the organisation’s benefit, unless the organisation can demonstrate reasonable fraud prevention procedures.

Third, section 250 of the CPA extends the senior manager attribution test from specified economic crimes to all criminal offences,

How does section 250 work?

Section 250 is broad in scope. It creates potential corporate criminal liability in relation to the likes of financial crimes (such as fraud, embezzlement, bribery and tax evasion offences), consumer protection offences, data protection offences (including offences relating to cyber incidents), wildlife crime offences, environmental breaches and health & safety offences. The latter category is familiar with the concept of “senior manager” via section 1 of the Corporate Manslaughter and Corporate Homicide Act 2007.

Section 250 of the CPA is, on its face, straightforward. An organisation will be criminally liable where a “senior manager” commits an offence while acting within the “actual or apparent scope of their authority”.

In practice, questions about the interpretation of both concepts will shape the application of the regime.

 Senior manager

Section 250 defines a “senior manager” as an individual who plays a significant role in either:

“(a) the making of decisions about how the whole or a substantial part of an organisation’s activities are managed or organised; or

(b) the managing or organising all or a substantial part of those activities.”

The definition focuses on function rather than job title. It extends beyond directors and company officers to regional heads, divisional leaders and other operational decision-makers. As a result, “senior manager” status may not align with formal corporate structure charts.

By focusing on the reality of decision-making rather than formal titles or reporting lines, the regime significantly expands the range of individuals whose criminal conduct may be attributed to an organisation.

The implications are particularly significant from an insider risk perspective. PwC’s Insider Risk: Client Survey Insights 2026 found that 60% of organisations regard insider risk as an important or critical issue. The extension of the senior manager attribution test to all offences increases the pool of insiders whose conduct may expose organisations to criminal liability.

Unlike the ‘failure to prevent fraud’ offence, the regime applies regardless of organisational size. All organisations should therefore identify the individuals who may fall within the definition of “senior manager and ensure that they are subject to appropriate training, oversight and compliance.

Actual or apparent authority

Corporate criminal liability will only arise where the senior manager was acting within the actual or apparent scope of their authority.

The Explanatory Notes to the CPA explain that this is intended to be a broad test: “it would be enough that the act was of a type that the senior manager was authorised to undertake, or which would ordinarily be undertaken by a person in that position.”

The focus is likely to be less on formal governance arrangements and more on the practical exercise of authority within the organisation. While the concepts of “actual” or “apparent” authority are familiar in civil law, their application in the criminal sphere remains uncertain and may be a fertile ground for dispute.

Why section 250 matters

Corporate criminal risk can no longer be viewed solely through the lens of economic crime. Organisations should therefore assess potential exposure to a broader range of offences.

Two additional points are worth bearing in mind.

First, liability under section 250 does not depend on establishing that the organisation benefited from the offending conduct. Unlike the ‘failure to prevent’ fraud offence in ECCTA, liability flows directly from the senior manager’s conduct.

Second, there is no defence based on the existence of reasonable or adequate prevention procedures.

Taken together, these features create a more direct route for regulators and enforcement agencies to establish corporate criminal liability.

Takeaway message

Section 250 of the CPA significantly expands the scope of UK corporate criminal liability.  While the regime provides no reasonable or adequate procedures defence, robust governance, oversight and compliance frameworks are essential in an attempt to avoid senior managers committing offences and, where they do, in providing a platform to take appropriate investigation and protective measures in order to manage risk and protect reputation.

STAY INFORMED