Home » How the new ‘Failure to Prevent Fraud’ offence can apply to small law firms
The "Failure to Prevent Fraud Offence" - how it can be applied to smaller law firms and SME’s
Gavin Ball
Financial crime compliance consultant
In September 2025, the UK’s new “failure to prevent fraud” offence came into force, holding large organisations criminally liable if they profit from fraud committed by an “associated person”.
While smaller firms may not be directly in scope, adopting the offence’s underlying principles is a strategic and effective way to manage their own fraud risks and meet increasing client and regulatory expectations.
In this article, we outline what has changed, what actions the SRA is taking, and what firms should be doing now to remain compliant.
What the “failure to prevent fraud” offence entails
Under the Economic Crime and Corporate Transparency Act 2023 (ECCTA), a “relevant body” can be convicted of this new corporate offence if an associated person commits a specified fraud offence with the intention of benefiting the organisation or its clients, and the organisation did not have reasonable prevention procedures in place.
Failure to prevent fraud definitions
- Associated Person: This is a broad category that includes employees, agents, and subsidiaries. Importantly, smaller law firms providing services to a larger firm could be considered an “associated person”.
- Intention to benefit: The organisation does not need to have actually benefited from the fraud for the offence to apply, only that the fraud was committed with this intention.
- A defence of “reasonable procedures”: The only defence against the offence is for the organisation to prove that it had “reasonable fraud prevention procedures” in place, or that it was unreasonable to expect it to have any at all. The government’s guidance outlines six principles for designing these procedures.
Why the offence is relevant for smaller law firms
Even if a small law firm does not meet the “large organisation” threshold (250+ employees, £36m+ turnover, or £18m+ in assets), the new offence will still have a significant impact.
- Increased client expectations: Larger clients subject to the offence will perform heightened due diligence on their “associated persons,” including suppliers and smaller firms. A robust, documented fraud prevention programme will become a competitive necessity.
- Regulatory foreshadowing: The new offence signals a broader shift in regulatory expectations towards proactive prevention. As with earlier legislation on bribery and tax evasion, legal sector regulators like the SRA will expect all firms, regardless of size, to take proactive steps to manage fraud risk.
- Vulnerability to risk: Smaller law firms often have fewer resources and less segregation of duties, making them more vulnerable to internal and external fraud. A single fraudulent act can cause devastating financial and reputational harm.
Applying the requirements effectively in a smaller firm
The government’s six guiding principles for prevention procedures can be adapted to be proportionate and effective for smaller law firms.
1. Top-level commitment
Visible buy-in from partners is crucial for setting the firm’s anti-fraud culture. In a small firm, partners’ active endorsement and oversight of prevention policies will have a direct and powerful impact.
2. Risk assessment
Conduct a thorough, inward-looking fraud risk assessment to identify specific vulnerabilities. For smaller firms, a risk assessment could focus on:
- Areas of high trust: Where one employee or partner has multiple accounting responsibilities, such as handling client receivables and processing payments.
- Fee-earner activity: Examine billing practices and expense reimbursement procedures, which can be misused to benefit the firm and the individual.
- Supply chain partners: Review the due diligence on external consultants or referrers who may be seen as “associated persons”.
- High-pressure targets: Identify if bonus structures or performance metrics could incentivise fraudulent behaviour.
3. Proportionate procedures
Implement controls based on the identified risks. Smaller firms can implement simple, but effective measures:
- Segregation of duties: Don’t let one employee handle every part of a financial transaction. Simple segregation, like having one person create invoices and another approve payments, can provide a strong control.
- Clear policies: Have a documented, accessible anti-fraud policy that everyone can understand.
- Approval processes: Require multi-person sign-off for expense claims, large payments, and changes to client account details.
4. Due diligence
Perform basic, risk-based checks on employees, partners, and key business contacts. For a smaller firm, this can involve:
- Formal vetting: Conduct proper reference and background checks for all new hires, especially those handling financial matters.
- Supplier scrutiny: Record basic information on business contacts and suppliers, such as a physical address and phone number, to verify legitimacy.
- Technology screening: Use internet searches and credit reports to vet high-risk individuals or entities.
5. Communication and training
Ensure all staff, from partners to support staff, receive fraud prevention training.
- Tailored training: Provide regular, bespoke training that uses real-world examples relevant to the firm’s practice areas.
- Open reporting culture: Cultivate an environment where staff feel safe reporting concerns, without fear of victimisation.
- Whistleblowing mechanism: Establish a confidential, or even anonymous, reporting channel for suspicious activity.
6. Monitoring and review
Regularly assess and update your firm’s controls.
- Ongoing audits: Perform unscheduled, random audits of high-risk areas like cash handling, accounts, and payroll to discourage fraudulent activity.
- Account monitoring: Routinely check the firm’s bank accounts online to look for anomalies.
- Incident review: In the event of a breach, conduct a thorough review to understand how and why it happened and to revise policies accordingly.
Conclusion
The new failure to prevent fraud offence represents a significant shift towards corporate accountability. For small law firms, embracing its principles is not just about mitigating legal risk, but also about reinforcing client trust and strengthening internal controls. By implementing proportionate, risk-based procedures, firms can use the requirements of this new legislation as a blueprint for building a more resilient and trustworthy practice.