London image

London

Founded in 2012, Signature Litigation has grown into one of London’s pre-eminent specialist dispute resolution practices. From the outset, we set out to do things differently: a conflict-free, disputes-only platform designed to give clients the undivided focus and strategic agility that complex, high-stakes matters demand.

FIND OUT MORE
Gibraltar image

Gibraltar

Established in 2017, Signature Litigation's Gibraltar office was founded to address growing demand for specialist expertise in commercial litigation and private wealth disputes on the Rock.

FIND OUT MORE
Paris image

Paris

Signature Litigation AARPI houses one of France’s most enviable product liability practices, with the team also handling commercial and corporate litigation, insurance and reinsurance, toxic tort and ESG, civil fraud and asset tracing, international arbitration, administrative and public law.

FIND OUT MORE
Frankfurt image

Frankfurt

Frankfurt has emerged as one of Europe's foremost financial and commercial centres and, increasingly, as a bridge between European and Asian markets. With that growth comes an increasing demand for sophisticated dispute resolution. Signature Litigation established its Frankfurt office to meet this need, bringing our conflict-free, disputes-only platform to the German market.

FIND OUT MORE

Mark Beardsworth, Duncan Grieve and Sharon Takhar examine the joint SFO-CPS Corporate Prosecution Guidance in Thomson Reuters Regulatory Intelligence

10 September 2025

When key provisions of the Economic Crime and Corporate Transparency Act 2023 (ECCTA) came into force on 1 September 2025, it reformed the law of corporate criminal attribution for a wide range of economic crimes. Notably, a new Failure to Prevent Fraud (FTPF) offence became effective. In anticipation of this, the UK Serious Fraud Office (SFO) and the Crown Prosecution Service (CPS) recently updated their guidance on corporate prosecutions.

The joint SFO-CPS Corporate Prosecution Guidance outlines the common approach of the DPP and the Director of the SFO to the prosecution in England and Wales of corporate offending. Their approach to ECCTA includes the FTPF offence.

The new guidance states: “The prosecution of corporate entities, in appropriate cases, is an important part of the enforcement of criminal law and ensures the full range of criminality can be captured. Such prosecutions have a deterrent effect, protect the public, support ethical business practices and lead to increased confidence in the criminal justice system.”

Conceived as a corporate criminal offence for large organisations, the scope of FTPF is intentionally wide-ranging: it extends strict corporate liability to a range of fraud offences that include fraud by failing to disclose information, fraud by false representation, and fraud by abuse of position.

A speech given by Nick Ephgrave, the SFO’s Director, in April 2025 provides the clearest indication of how the agency plans to prosecute FTPF offences. “Come September, if they (companies) haven’t sorted themselves out, we’re coming after them,” said Ephgrave. “I’m very, very keen to prosecute someone for that (FTPF) offence. We can’t sit with the statute books gathering dust, someone needs to feel the bite.”

Ephgrave’s robust message is clearly aimed at company boards and their legal teams, encouraging them to update risk management frameworks and prepare for investigations.

So, what’s in the new guidance?

For prosecutors, a lower attribution threshold makes it easier to hold companies criminally liable for economic crimes listed under Schedule 12 ECCTA. When a senior manager commits a Schedule 12 offence, Section 196 of ECCTA allows corporate bodies to be held liable.

Corporate liability can be established under statutory provisions or common law. But prosecutors are now advised to prefer the ECCTA over the common law identification doctrine, which significantly lowers the charging threshold for corporates. Boards must understand precisely who qualifies as a senior manager and how their decisions could lead to corporate exposure.

The new guidance outlines the FTPF offence alongside Bribery Act and Criminal Finances Act offences. Valid defences are scarce: proving that procedures are “adequate” for bribery or “reasonable” for tax/fraud offences. Companies must expect scrutiny of their current compliance programmes and contemporaneous records.

Although the CPS continues to use the Full Code Test, prosecutors must also consider other factors: systemic compliance failings; prior warnings or sanctions; board-level knowledge or wilful blindness; and harm to market integrity or unidentified victims. In the guidance, mitigation factors are also listed, including early self-reporting, a mature compliance culture and genuine remediation.

For companies that cooperate, Deferred Prosecution Agreements (DPAs) remain an effective tool – but not an easy option. Full cooperation is essential including timely disclosure of internal investigation materials and, if appropriate, privilege waivers. Inadequate cooperation risks immediate prosecution and parallel prosecutions of individuals are expressly encouraged.

At an early stage, investigators are encouraged to deploy asset restraint orders and at sentencing, serious crime prevention orders and director disqualification orders. Boards should therefore expect requests for financial disclosure and possible trading restrictions, while their reporting and monitoring frameworks should be well maintained.

The new guidance depends on a co-ordinated approach. Consistent with the July 2025 memorandum of understanding between the SFO and its French and Swiss counterparts to strengthen cooperation on bribery and corruption cases, the SFO and CPS avoid potential conflict with domestic regulators, Eurojust, and foreign prosecutors. The response strategies of multinational groups should also be aligned across jurisdictions where they operate: strategic early filings in another jurisdiction or pursuing forum shopping options could be regarded as uncooperative behaviour.

To a large extent, the SFO-CPS guidance aligns with the SFO’s pre-existing Corporate Guidance: in relation to early self-reporting, genuine cooperation, and robust compliance programmes, which are all critical to secure a DPA.

But differences do exist. For example, entities incorporated by statute do not specifically feature in the SFO’s earlier guidance. The new joint guidance brings them into scope, expanding potential liability beyond typical corporate structures, and signalling that statutory bodies – such as the National Health Service (NHS) – must maintain adequate compliance and be prepared to cooperate fully with investigations.

The joint guidance focuses on high-level statutory changes and public interest factors that influence prosecution decisions, whereas the SFO’s Corporate Guidance details operational expectations at a more granular level with examples comparing cooperative and uncooperative behaviour, as well as engagement and investigation timelines.

Although the importance of transparent early engagement is common to both sets of guidelines, in the assessment of cooperation, the joint guidance emphasises cross-border coordination and multi-agency alignment. Together, they demonstrate an enforcement landscape that is increasingly rigorous for all types of corporate entity, underlining the message that self-reporting and proactive cooperation should act in tandem.

So, how should in-house teams prepare their organisations for the FTPF offence?

In deciding what practical steps to take, corporate procedures and processes may need to be revised. Timely action is not just relevant in a UK context, but will also apply to larger organisations with a developed international footprint. This will often include stakeholders across diverse jurisdictions, underpinned by a strategy that falls in line with global regulatory standards. Although enforcement may have slowed in the US, for example, self-reporting, robust compliance and risk frameworks continue to be paramount corporate priorities.

Specific points of action should include:

  • Ensuring that senior management takes ownership of fraud and bribery risks; establishing zero-tolerance policies; and implementing oversight mechanisms, including KPIs and quarterly risk reports.
  • Refreshing fraud and bribery risk mapping. This can include: business models, sectors, intermediaries, geography, group structures and client risks. Identifying UK touchpoints and potential victims.
  • Aligning controls and principles: top-level commitment; risk assessment; due diligence; proportionate procedures; communication and training; monitoring and reviewing. Applying each element to fraud risks.
  • Determining whether yours is a “large organisation” as defined by the ECCTA (>GBP 36m turnover; >GBP 18m balance sheet; >250 employees). If the answer is no, assessing whether your organisation could soon meet the relevant criteria, in the short or medium term, and plan accordingly. Mapping “associated persons” whose conduct could trigger liability: employees, agents, subsidiaries, and certain contractors.
  • Updating accountability frameworks for ECCTA’s senior manager attribution. Identifying who qualifies and how their decisions could expose your organisation to risk.
  • Strengthening procedures for onboarding, renewal, and due diligence for third parties, such as intermediaries, customers, JV partners, and vendors. Including adequate assurances and protections, such as warranties, audit rights and triggers for termination.
  • Reinforcing whistleblowing channels. Assessing the logging, review, investigation and remediation of whistleblowing reports. Conducting internal investigations in line with SFO expectations, preserving evidence, and ensuring that internal processes avoid any compromises to external reviews.
  • Planning protocols that identify key decision-makers and timelines.
  • Delivering training that is role-specific and risk-based, encompassing potential fraud and bribery scenarios. Maintaining records of uptake and refreshing them regularly.
  • Using internal audit to evidence monitoring and remediation; reporting outcomes to the board and tracking subsequent progress at every stage from implementation to completion.