UK Expands Corporate Criminal Liability for Senior Managers' Acts to All Offences
Summary: The UK Crime and Policing Act 2026, effective 29 June 2026, fundamentally expands corporate criminal liability by making organisations liable for any criminal offence committed by a senior manager acting within their actual or apparent authority. This removes the previous limitation to economic crimes and applies to companies of all sizes with no statutory compliance defence.
Table of Contents
Chapter 1 — From Identification Doctrine to Senior Manager Attribution
1.1 Evolution of UK Corporate Criminal Liability Framework
Historically, UK corporate criminal liability was governed by the common law "identification doctrine," which required prosecutors to show that the criminal conduct was committed by the company's "directing mind and will" — a narrow category typically limited to board-level directors. Courts interpreted this test restrictively, making it extremely difficult to prosecute large, complex organisations with decentralised management structures. The Economic Crime and Corporate Transparency Act 2023 introduced the first significant reform by creating a statutory "senior manager" test for specified economic crimes, expanding attribution beyond directors to individuals who play a "significant role" in managing or organising a substantial part of the organisation's activities.
Key Historical Limitations:
- Directing Mind and Will Test: Required the individual to represent the company's "embodiment" — courts rarely found this outside board-level directors, and even CEOs were sometimes held insufficiently senior
- ECCTA 2023 Reforms: Section 196 introduced the "senior manager" test but only for economic crimes, maintaining an artificial distinction between offences despite similar attribution mechanics
- Failure to Prevent Offences: The Bribery Act 2010, Criminal Finances Act 2017, and ECCTA's failure to prevent fraud offence created alternative liability routes but with narrower scope and "reasonable procedures" defences
- Prosecution Challenges: The identification doctrine proved particularly difficult for multi-nationals with complex management structures where responsibility for decisions was diffused across multiple senior figures
Corporate Criminal Liability Expanded to All Crimes Under the Crime and Policing Act 2026 - Arnold & Porter
The Crime and Policing Act 2026: A new era for corporate criminal liability? - Slaughter and May
The Crime and Policing Act 2026: Expanding Corporate Criminal Liability Beyond Economic Crime - Travers Smith
Chapter 2 — Key Changes Under the Crime and Policing Act 2026
2.1 Section 250 and the Expansion to All Offences
Section 250 of the Crime and Policing Act 2026, which came into force on 29 June 2026, represents a watershed moment in UK corporate criminal liability. It repeals sections 196-198 of the ECCTA and replaces them with a single provision applying to all criminal offences. Where a senior manager commits any criminal offence while acting within the actual or apparent scope of their authority, the organisation also commits that offence. The reforms apply to all bodies corporate and partnerships regardless of size, with no statutory defence available. The government confirmed during parliamentary debate that the identification doctrine "was never intended as an economic crime-only regime" and that the CPA ensures "businesses cannot continue to avoid liability where senior management have clearly used the business to facilitate or conduct crime."
Key Features of Section 250:
- All Offences in Scope: Criminal liability extends to every offence under the laws of England and Wales, Scotland, or Northern Ireland — not limited to economic crime
- No Size Threshold: Unlike the failure to prevent fraud offence which applies only to "large organisations," the CPA applies to companies of all sizes
- No Corporate Benefit Required: The company can be liable even where the senior manager's conduct was against the company's interests, including where the company is the victim of the crime
- No Statutory Defence: Unlike failure to prevent offences, there is no "reasonable procedures" or "adequate procedures" defence — if the senior manager commits the offence within scope, liability follows automatically
- Territorial Carve-Out: The provision includes a narrow exclusion where all conduct occurs outside the UK and the organisation would not commit the offence if the conduct were its own
- Apparent Authority: The senior manager need not have been authorised to commit the criminal act — it is sufficient that the act was of a type they were authorised to undertake or would ordinarily be undertaken by someone in that position
Crime and Policing Act 2026: A new dawn for corporate criminal liability - Ashurst Perkins Coie
All Crimes, All Companies: The Expansion of UK Corporate Criminal Liability from 29 June 2026 - Freshfields
UK Crime and Policing Act 2026 widens corporate criminal liability to all offences - Osborne Clarke
Chapter 3 — Offence Categories of Particular Risk
3.1 Beyond Economic Crime: New Enforcement Frontiers
The expansion to "all offences" means businesses must now consider criminal risk across a much broader spectrum of activities than traditional economic crime compliance. The definition of "senior manager" is functional rather than title-based, capturing anyone who plays a "significant role" in managing or organising a "substantial part" of the organisation's activities — potentially including divisional leaders, regional heads, senior project managers, and heads of finance or HR. The absence of a statutory defence means that even companies with robust compliance programmes can be prosecuted, though such measures remain critical for prevention and sentencing mitigation. Prosecuting agencies beyond the SFO and CPS, including the Environment Agency, Health and Safety Executive, Information Commissioner's Office, and National Crime Agency, now have clearer statutory routes to pursue corporate prosecutions.
Offence Categories of Particular Risk:
- Environmental and ESG Crimes: Senior managers authorising their business units to bypass environmental controls, or failing to comply with pollution and waste disposal regulations
- Health and Safety and Corporate Manslaughter: Section 250 provides a streamlined route for prosecuting workplace fatalities through gross negligence manslaughter attribution, sidestepping the need to prove systemic board-level management failure under the Corporate Manslaughter and Corporate Homicide Act 2007
- Technology, Data Protection, and Computer Misuse: Senior managers directing aggressive data practices could expose companies to criminal liability under the Data Protection Act or Computer Misuse Act
- Modern Slavery and Human Trafficking: Senior management involvement in supply chain violations could now be directly attributable to the organisation
- Perverting the Course of Justice: If a senior manager destroys evidence during an investigation, the company could face liability
- Offences Against the Person: While rare, even serious personal offences could trigger corporate liability if committed by a senior manager within the scope of their authority
Corporate criminal liability just got wider: What the CPA 2026 means for businesses - DLA Piper
All Crimes, All Companies: The Expansion of UK Corporate Criminal Liability from 29 June 2026 - Freshfields
Crime and Policing Act 2026: A new dawn for corporate criminal liability - Ashurst Perkins Coie
Chapter 4 — Compliance Strategies in the Absence of a Statutory Defence
4.1 Proactive Risk Management and Governance
While the CPA provides no statutory defence, robust compliance frameworks remain essential for reducing risk and influencing enforcement decisions. The Joint SFO-CPS Corporate Prosecution Guidance sets out public interest factors for and against prosecution, including: a genuinely proactive approach by management involving self-reporting and remedial actions; the existence of a genuinely proactive and effective compliance programme; and where the offending represents isolated actions by individuals. A strong compliance culture will be directly relevant to the public interest test that prosecuting agencies must apply before bringing charges. Given the significant uncertainty around what constitutes a "substantial part" of an organisation's activities and whether an individual was acting within their "apparent authority," businesses should undertake comprehensive risk assessments and governance reviews.
Practical Steps for Risk Mitigation:
- Identify Senior Managers: Conduct fact-specific mapping of management structures and authority across regions, offices, and functions — focusing on who actually makes decisions rather than who holds formal titles
- Review Authority Matrices: Examine delegation frameworks, authority matrices, and client engagement protocols — the "apparent authority" element means informal or perceived authority counts even where not formally documented
- Update Risk Registers: Extend risk assessments beyond traditional economic crime risks to cover all criminal offences, including health and safety, environmental, data, and workplace misconduct risks
- Refresh Training: Provide targeted training for senior and mid-tier management on key risk areas beyond economic crime, with specific modules on environmental compliance, health and safety, data protection, and the handling of material non-public information
- Strengthen Due Diligence: Implement appropriate vetting at recruitment or appointment and conduct ongoing monitoring of individuals in senior management roles
- Enhance Whistleblowing: Ensure employees feel able to raise concerns about senior manager conduct and that issues are properly investigated and addressed
- Review Insurance Coverage: Engage with professional indemnity and directors' and officers' insurers to confirm coverage responds to the broader range of offences now in scope
Corporate Criminal Liability Expanded to All Crimes Under the Crime and Policing Act 2026 - Arnold & Porter
Corporate criminal liability just got wider: What the CPA 2026 means for businesses - DLA Piper
Liability for the acts of senior managers: Changes under the Crime and Policing Act 2026 - Anthony Collins Solicitors
FAQ: UK Corporate Criminal Liability Expansion Questions Answered
What offences can now trigger UK corporate criminal liability?
Under the Crime and Policing Act 2026, corporate liability now extends to all criminal offences — not just economic crimes. This includes environmental offences, health and safety breaches, data protection violations, modern slavery, and even gross negligence manslaughter, provided they are committed by a senior manager acting within their actual or apparent authority.
Who qualifies as a "senior manager" under the new rules?
A senior manager is anyone who plays a significant role in making decisions about how the whole or a substantial part of the organisation's activities are managed or organised, or in actually managing those activities. The test focuses on functional reality rather than job titles, potentially capturing divisional heads, regional leaders, and senior operational managers.
Is there a "reasonable procedures" defence under the CPA?
No. Unlike failure to prevent offences under the Bribery Act or ECCTA, the CPA provides no statutory "reasonable procedures" or "adequate procedures" defence. If a senior manager commits an offence within the scope of their authority, the organisation's liability follows automatically as a matter of law, regardless of compliance measures.
How does the CPA interact with the existing failure to prevent offences?
The CPA operates alongside existing failure to prevent offences. Prosecutors may choose between routes depending on circumstances. The CPA requires proving the underlying offence by a senior manager, while failure to prevent offences require showing that an associated person committed the offence and the organisation lacked reasonable procedures — but the latter offers a compliance defence which the CPA does not.
Comments
Post a Comment