UK Crime and Policing Act 2026 widens corporate criminal liability to all offences
Published on 20th July 2026
Section 250 removes a longstanding barrier to corporate prosecution and applies to companies of all sizes, with no compliance defence available
At a glance
"Senior manager" status turns on actual decision-making influence, not job title or formal reporting lines.
A company can face liability even where it is the victim of its own senior manager's offending.
The territorial carve-out offers limited protection; companies remain exposed for qualifying conduct occurring entirely abroad.
On 29 June 2026, section 250 of the Crime and Policing Act 2026 (CPA) came into force. It represents the latest and most significant step in a series of legislative changes to make it easier to find companies guilty of criminal offences.
Now, where a senior manager of a body corporate or partnership commits any offence while acting within the actual or apparent scope of their authority, the organisation also commits the offence. The practical implications for UK businesses are far-reaching.
New framework for attribution
For decades, the dominant test for corporate criminal liability was the common-law "identification doctrine," or "directing mind and will" test. In large, complex organisations, this test was almost impossible to satisfy, with courts holding that even CEOs and other senior executives may not hold sufficient authority for their alleged dishonesty to be attributed to their firms.
Under section 250 CPA, firms will be held liable for any crime (not just economic crimes) committed by their "senior managers".
Who is a 'senior manager'?
The definition of "senior manager" remains unchanged from the Economic Crime and Corporate Transparency Act 2023 (ECCTA).
The test focuses on the practical reality of managerial influence, rather than formal job titles or reporting lines. It captures any individual who plays a significant role in:
- the making of decisions about how the whole or a substantial part of the organisation's activities are to be managed or organised, or
- the actual managing or organising of the whole or a substantial part of those activities.
Identifying senior managers will require a fact-specific assessment in each case and could encompass senior project managers, senior finance and HR personnel, regional managers, and heads of business divisions, among others.
A significant degree of uncertainty is likely to arise from establishing what constitutes a "substantial part" of an organisation's activities and whether an individual was acting within the scope of their authority.
Actual or apparent authority
The senior manager must be acting within the "actual or apparent" scope of their authority. This does not mean the senior manager needs to have been authorised to carry out the criminal conduct. It is sufficient if the act falls within the type of activity the senior manager was authorised to undertake, or which would ordinarily be undertaken by someone in that position: for example, a CFO who commits fraud by deliberately making false statements about a company's financial position.
Until tested in the courts, there may be uncertainty as to whether specific acts fall within an individual's "apparent authority".
Despite the senior manager test under ECCTA having been in force since December 2023, prosecutors have yet to bring any proceedings based on that provision, let alone proceedings testing the boundaries of these concepts.
Broadened scope
The broadened scope draws no distinction between "business-related" offences and more "personal" types of offending. This could, in principle, lead to firms being prosecuted for offences far outside the normal range of business misconduct, so long as prosecutors can link the conduct to a qualifying senior manager and their role.
Territorial reach
The CPA is not limited to conduct in the UK. There is a territorial carve-out, but it is narrow: it applies only if all of the conduct constituting the offence occurs outside the UK; and the company would not itself commit the offence if the conduct were attributed directly to it.
In practice, this limitation is narrower than it first appears, given that companies can be prosecuted for a number of offences where the wrongdoing takes place outside the UK but there is a close connection to the UK or a UK nexus: for example, a UK-incorporated company involved in a bribery or sanctions offence that takes place entirely overseas.
Principal risks for businesses
- No statutory defence. Unlike the "failure to prevent fraud" offence under ECCTA, there is no defence available if the senior manager committed the offence within the scope of their role, regardless of the quality of the organisation's compliance programme.
- No requirement for corporate benefit. The company can be liable even where the senior manager's conduct was against the company's interests. For example, if a senior manager fraudulently diverts company funds into their own account, the company could face liability for fraud under the CPA, even though it is the victim of the crime.
- Limited DPA availability. The list of offences for which deferred prosecution agreements are a possible resolution route for corporates has not been expanded to reflect the broader range of offences now captured by the CPA. DPAs remain largely limited to economic crimes.
- Money laundering exposure. Once a reasonable suspicion of corporate criminal liability arises, any connected revenues may be treated as proceeds of crime under money laundering regulations.
- Confiscation regime overhaul. The CPA also substantially overhauls the confiscation regime under the Proceeds of Crime Act 2002, including reforms aimed at making it easier to calculate a defendant's benefit from crime, enabling realistic and enforceable orders, and clarifying the requirements for restraint orders to facilitate asset preservation during investigations.
- Size threshold. The CPA applies to companies of all sizes, unlike the "failure to prevent fraud" offence, which applies only to companies meeting certain turnover or headcount thresholds.
Compliance
A strong compliance programme will not provide a legal defence under the CPA. It will, however, be a significant factor in whether the SFO or CPS considers prosecution to be in the public interest.
The Joint SFO-CPS Corporate Prosecution Guidance sets out public interest factors for and against prosecution in corporate cases, including: a genuinely proactive approach by management, involving self-reporting, remedial actions and compensation of victims; a lack of history of similar conduct; the existence of a genuinely proactive and effective compliance programme; and where the offending represents isolated actions by individuals.
Prosecutorial discretion and resourcing may become one of the most important practical limits on how far the CPA regime is tested. However, there is limited comfort in a regime where protection against liability depends less on statutory safeguards and more on how aggressively prosecutors choose to exercise their powers. Corporates can expect that activists and non-governmental organisations may seek to pressure investigators and prosecutors to push the boundaries of this new area of law.
Osborne Clarke comment
The Crime and Policing Act 2026 represents a significant expansion of corporate criminal liability. To mitigate their risk, organisations should consider taking the following actions as a matter of priority:
- Conduct a fact-specific review of management structures and authority across regions, offices, and functions, focusing on who actually makes decisions rather than who holds formal titles. Refresh this exercise as the organisation evolves.
- Review delegation frameworks, authority matrices, and client engagement protocols. The "apparent authority" element is particularly important: informal or perceived authority counts, even where not formally documented.
- Update risk registers to cover all criminal offences, not just financial crime.
- Refresh training, which should move beyond economic crime. Senior personnel should understand the full scope of the CPA, with specific modules on insider dealing protocols, government-facing conduct, and the handling of material non-public information.
- Strengthen due diligence processes for senior staff: this should include not only appropriate vetting at recruitment or appointment, but also ongoing monitoring of individuals in senior management roles to identify potential behavioural, regulatory or integrity risks.
- Enhance whistleblowing procedures to ensure that relevant criminal risks are escalated for investigation. Organisations should ensure employees feel able to raise concerns and that issues are properly investigated and addressed.
- Review insurance and M&A due diligence. The CPA should be reflected in due diligence processes, and professional indemnity and directors' and officers' (D&O) insurers should be engaged to confirm that coverage responds to the broader range of offences now in scope.
- Assess internal investigation readiness, refreshing protocols so that investigation teams can quickly identify whether an individual under investigation is a senior manager under the statutory definition. Given the risk of potential corporate liability, this analysis should be conducted under legal privilege – whether within a well-defined internal team or conducted by external counsel.
If you would like to discuss how these provisions affect your organisation and what steps you should be taking, please contact the experts below.