\n\n

Companies can now be prosecuted under UK law for any criminal offence committed by one of their senior managers provided the manager was acting with the scope of their authority (actual or apparent).

This represents a fundamental expansion of corporate criminal liability from the previous position, under which companies would only be liable for most offences if the “directing mind and will” of the company was involved. In practice, the “directing mind and will” test made it almost impossible to prosecute large firms.

This is the third in a series of articles examining the Crime and Policing Act 2026 (the Act) and its implications for businesses. Our first briefing looked at four key implications for firms and our second briefing looked at the key concepts that underpin the new regime. In this third briefing, we examine the impact of the Act on UK regulated entities.

Introduction

The relevant provision of the Act, section 250, came into force on 29 June 2026.  This replaces sections 196–198 of the Economic Crime and Corporate Transparency Act 2023 (ECCTA), which extended corporate criminal liability to certain economic offences by senior managers, so that the senior manager attribution model is extended to all criminal offences.

When discussing the Act with authorised firms operating within the UK’s financial services regime, we have found there to be two areas of particular interest: (i) the interplay of the definition of “senior manager” under the Act with Senior Management Functions (SMFs) under the the Senior Managers and Certification Regime (SMCR); and (ii) the practical steps to be taken in light of the Act given the systems and controls already in place at these firms under regulatory requirements. We set out our thoughts on these issues below.

  1. Interplay with the SMCR

As highlighted in our prior briefings, a senior manager for the purposes of the new law is not the same as an SMF under the SMCR. Instead, the definition of senior manager under the Act is carried over from section 196 of ECCTA and is defined as an individual who plays a significant role in:

  1. the making of decisions about how the whole or a substantial part of the activities of the body corporate or partnership are to be managed or organised; or
  1. the managing or organising of the whole or a substantial part of those activities (the s250 Definition).

This is a deliberately broad and functional definition and the SFO has indicated that it expects the definition to be litigated. Under the SMCR, the most senior people in a regulated firm who perform key functions – SMFs – need Financial Conduct Authority (FCA) or Prudential Regulation Authority (PRA) approval. The regulators designate particular functions as SMFs so that they can identify a firm’s most senior decision makers and ensure firms clearly allocate responsibilities to those key individuals. Examples of SMFs include the Chief Executive, the Chief Finance Officer and the Chair.

In addition to SMFs, the Certification Regime covers specific functions that are not designated SMFs, but can have a significant impact on customers and/ or the firm. These are called Certification Functions. Certification staff are not approved by the FCA. Instead, firms need to check and certify that they are fit and proper to perform their role on appointment and at least once a year.

In terms of mapping the s250 Definition of senior manager to functions under the SMCR:

  1. SMFs are likely in scope of the s250 Definition given the nature of these roles, though should be considered on a case-by-case basis;
  2. Certification Functions are also potentially in scope – for example, holding the significant management certification function may indicate that the person is able to make decisions about or manage a ‘substantial’ part of the firm’s activities; and
  3. in addition to SMFs and Certification Functions, there may be other employees whose role falls within the s250 Definition [(for example, Head of Procurement depending on the scope of the role]).

Regulated entities will therefore, like unregulated entities, need to consider the s250 Definition against their employee population to identify who may be in scope of the Act. Firms may wish to do this at a high level – identifying categories of staff potentially in scope – rather than doing this exercise individual-by-individual, documenting the basis on which the mapping has been done (for example taking a cautious approach which potentially casts the net wider than the s250 Definition and avoiding labelling individuals as senior managers for the purposes of the Act).

The definition of ‘senior manager’ for these purposes is not limited to ‘employees’ of the corporate entity, but rather whether a person is – as a matter of fact – a ‘senior manager’ of that entity within the s250 Definition (regardless of their employment status). This may require firms to also consider whether any persons employed by third parties (e.g. under outsourcing arrangements or secondments) or in other parts of the same corporate group, may also be capable of meeting the s250 Definition.

Since the new provision applies to all companies regardless of where they are incorporated or where their senior managers are located, firms cannot regard individuals as being out of scope simply on the basis that they are outside the UK or employed by a non-UK entity.  We expect this may be a particular point of focus for international branches and groups with shared functions or matrix reporting across jurisdictions.

  1. Suggested practical steps for regulated firms

Regulated firms are already subject to requirements to have adequate systems and controls in a number of areas, including to counter the risk of the firm being used to further financial crime, and can face regulatory investigations and enforcement penalties in the event of inadequate procedures or misconduct by their staff. However, regulated firms still need to consider and take into account the impact of the Act on their business, albeit their starting point for governance and control frameworks may be relatively advanced.

In addition to the actions noted in relation to senior managers in point 1 above, regulated firms may want to consider taking the following five key steps:

  1. Assess likely offences and broaden risk assessments: The first step to be taken is to assess and document which offences are most likely to present a risk for the firm – as noted in our second briefing, examples of potential offences for which firms could now be held liable under the Act where committed by senior managers (subject to the extra-territoriality limitations) include (beyond economic offences) environmental offences, data protection and computer misuse offences,  forgery, potential sexual offences, perverting the course of justice and failing to respond to compelled information requirements. Having done this, existing risk assessments – for example, in relation to financial crime – will need to be broadened to capture these offences.  Risks may include the possibility of non-compliance with representations and warranties given in various contractual agreements such as financing documents and insurance policies, regarding the entity’s compliance with applicable laws.
  1. Review and update governance and compliance frameworks: Existing governance and compliance frameworks, including relevant policies and procedures, will need to be reviewed and updated to take into account the firm’s assessment of the impact of the Act and the output of the updated risk assessments to address any gaps.  Resources should be prioritised on the areas of highest risk. Although there is no defence of reasonable procedures (unlike with failure to prevent offences), the effectiveness of relevant systems and controls is likely to be a significant factor in assessing the public interest in a criminal prosecution against the company. Importantly, if a prosecution is in prospect, Deferred Prosecution Agreements (DPAs) will not be available for the broader offences captured by the Act: DPAs remain limited to specified economic offences under Schedule 17 of the Crime and Courts Act 2013.
  1. Strengthen senior staff vetting and monitoring: As a result of the SMCR, regulated entities are already required to take a number of additional steps in relation to appointing and validating their senior staff. However, given the raised risk exposure for firms under the Act, firms may still wish to consider reviewing their senior staff vetting processes and/or monitoring to identify any scope for enhancement.
  1. Training and internal communications: Internal training in relation to the Act and its impact on the firm is important. As part of this, training should be provided to legal, compliance and internal investigations teams as these functions will now need to take into account the Act in their day-to-day roles. There should also be targeted regular training for senior individuals so that they can identify potential criminal issues and escalate them effectively in line with procedures. This training should be delivered not only to SMFs but to all senior staff who may meet the s250 Definition. Beyond formal training, firms should also ensure that there are clear internal communications about the Act and its implications for the business and the importance of escalating concerns. Regulators have consistently emphasised the importance of the right “tone from the top” – senior leadership should be visibly engaged in communicating the firm’s expectations and commitment to lawful conduct, setting a culture in which compliance is prioritised and potential issues are raised without hesitation.
  1. Update incident response procedures: Firms should review and update existing incident response procedures to ensure they adequately address scenarios in which a senior manager may have committed a criminal offence which triggers the Act. This includes reviewing escalation channels so that potential criminal conduct is promptly brought to the attention of appropriate decision-makers and investigation protocols so that those decision-makers have guidance on handling such incidents. It will also be important to consider carefully and quickly whether and when a self-report ought to be made to the relevant authorities. Whistleblowing procedures should be assessed to ensure that employees feel confident reporting concerns about senior individuals and whistleblowing, internal investigations and HR procedures may also need to be updated to address how the firm will approach situations where a senior manager is suspected of or charged with a criminal offence. Firms should also consider how their incident response framework interacts with regulatory notification obligations.

Concluding remarks

Regulated firms are likely to be starting from a relatively advanced base when it comes to systems and controls, given the existing requirements imposed by the FCA and the PRA but there is still work to be done if they are to most effectively mitigate the risk of a potentially damaging criminal investigation, particularly in areas beyond financial crime where criminal liability has historically been unlikely to attach to firms.

Firms need to assess and factor the impact of the Act into their control frameworks, ensuring that this new route to corporate liability is addressed as part of their wider system of policies, procedures, risk assessments and monitoring. By integrating the Act into the broader compliance architecture – rather than treating it as a standalone exercise – regulated firms can build on their existing strengths and ensure they are well positioned to manage the risks presented by this significant expansion of corporate criminal liability.

Please contact us if you would like to discuss how the Act may affect your firm.