Introduction: A New Era for UK Corporate Accountability
The United Kingdom has entered a new phase of corporate enforcement. As of June 2026, the Crime and Policing Act 2026 has fundamentally expanded the basis on which companies can be held liable for criminal offences in the UK. This means that any business operating within the UK jurisdiction can now be prosecuted for a much wider range of criminal conduct committed by its senior managers, regardless of whether that conduct constitutes an economic or financial crime. For company directors, compliance officers, and legal counsel, this development represents a shift from a narrow, rule-based system to a broad, conduct-based regime where the actions of individuals with significant responsibility directly translate into corporate guilt. The law is no longer limited to specific offences like fraud or bribery; it now covers virtually the entire criminal calendar.

This change, detailed in the Slaughter and May Corporate Update Bulletin of 3 September 2026, reverses decades of legal precedent that made prosecuting large firms notoriously difficult. The previous "identification principle" required prosecutors to show that the "directing mind and will" of the company, often the CEO or board, possessed the criminal intent. This left a gap where misconduct by regional directors or senior operational managers often went unpunished at the corporate level. With the implementation of the 2026 Act, the threshold has been lowered, and the perimeter of liability has been significantly widened, demanding immediate attention from every UK plc, SME, and multinational subsidiary. For boards in London, Manchester, and Edinburgh, the question is no longer if they will face greater scrutiny, but how they will adapt their governance structures to avoid becoming the test case that defines this new legal era.
Understanding the Crime and Policing Act 2026
The Crime and Policing Act 2026 received Royal Assent in late 2025 and came into force in June 2026, marking a watershed moment in UK business law. Historically, under the Corporate Manslaughter and Corporate Homicide Act 2007 and various economic crime acts, liability was largely confined to specific regulatory breaches. The new legislation broadens this by establishing a general corporate criminal liability framework. The Ministry of Justice (MoJ) has confirmed that the Act is designed to simplify prosecution routes for offences committed by employees in a senior position, removing the historic requirement to prove that a high-level individual was the "embodiment" of the company.
This legislative shift is not merely an incremental update; it is a structural overhaul aimed squarely at improving the UK's reputation as a difficult place to do business illegally. The Act introduces a statutory definition of "senior manager" that includes individuals who play a significant role in the making of decisions about how the whole or a substantial part of the company’s activities are managed or organised. This captures a much broader cohort than the traditional "directing mind" test. As of September 2026, legal experts at Slaughter and May note that this definition is broad enough to include chief financial officers, heads of divisions, and even senior regional directors who hold substantial autonomy, thereby increasing the surface area for potential criminal exposure significantly.
The Legislative Mechanism
The mechanism of the Act is deceptively simple yet powerful. It allows a company to be convicted if a senior manager commits a relevant offence acting within the scope of their actual or apparent authority. Crucially, the prosecution does not need to prove that the board knew about the crime or condoned it, only that the individual had the authority to act in the way they did. This objective standard makes it significantly easier for the Crown Prosecution Service (CPS) and the Serious Fraud Office (SFO) to secure convictions against legal entities. For businesses, this means that the actions of a rogue senior manager, even against company policy, can still implicate the corporate body if that manager had apparent authority to engage in the conduct.
Expanded Scope of Corporate Criminal Liability
The scope of the Crime and Policing Act 2026 is vast. It is no longer limited to "economic crimes" as defined under previous legislation such as the Economic Crime and Corporate Transparency Act 2023. Instead, the Act covers any criminal offence committed by a senior manager. This includes, but is not limited to, health and safety breaches, environmental offences, fraud, bribery, money laundering, and even data protection violations. According to the Home Office (gov.uk) impact assessment published in January 2026, the government expects the number of corporate prosecutions to increase by up to 40% over the next five years as a direct result of this expanded jurisdiction.
Consider the practical implications for a construction firm: previously, if a site manager falsified safety records and a worker was injured, the company might have faced regulatory sanctions only. Today, the company itself can be prosecuted for the criminal act of "perverting the course of justice" or fraud if the manager had authority over site reporting. Similarly, in the financial sector, a senior sales manager who unilaterally misrepresents a product to meet targets, acting within their authority to sell, could expose the bank to criminal liability for fraud. This expansion reflects a policy choice by Westminster to hold corporations accountable for systemic failures in governance, rather than treating criminality as the isolated act of a bad apple.
Key Implications for Boards and Senior Management
For UK company boards, this shift from "identification" to "senior manager" liability demands a radical rethink of collective decision-making and delegation. The primary implication is that independent judgment must be exercised with greater rigor than ever before. Non-executive directors (NEDs) and chairpersons cannot simply rely on internal audit reports; they must now actively verify that authority is not being delegated to individuals without adequate oversight and ethical training. If a senior manager has the apparent authority to sign off on a transaction, and that transaction is later deemed criminal, the board’s ignorance is no longer a valid defence for the corporate entity.
Moreover, the Act holds the board collectively responsible for the culture it fosters. If a company promotes a high-pressure sales environment that implicitly encourages unethical behaviour, and a senior manager commits fraud to meet targets, the company is liable. This is a significant departure from the past, where boards often used compliance tick-boxes to shield themselves from liability. Now, as noted by Sarah Clarke, a former SFO prosecutor and now partner at a leading London law firm in an interview with the FT on 28 August 2026, "The boardroom must become the engine room of compliance. It is no longer enough to have a policy on paper; directors must demonstrate that they have taken every step to prevent the authority they grant from being abused." This creates a direct line of accountability from the shop floor to the boardroom.
The Issue of Delegation of Authority
Delegation of authority is now a double-edged sword. While it is necessary for the efficient running of large organisations, delegating significant operational control to senior managers creates immediate criminal risk. Companies must now map out their delegation matrices with legal precision. They must distinguish between operational authority (e.g., the power to hire and fire) and decision-making authority that carries legal risk (e.g., signing off on financial statements or regulatory representations). Boards should ensure that high-risk decisions are escalated to a committee that is explicitly empowered to review and approve them, thus absorbing the authority and limiting the exposure to a broader group that has collective oversight.
Rethinking Corporate Governance and Compliance in the UK
The introduction of the 2026 Act necessitates a complete overhaul of UK corporate governance. Compliance is no longer a back-office function but a C-suite strategic priority. Companies must look beyond the FCA’s conduct rules and consider the full criminal code. This requires updating whistleblowing channels to ensure they are effective and trusted, as early detection of a senior manager’s misconduct is now the only way to mitigate potential corporate liability. While the Act does not provide a specific defence for having "reasonable prevention procedures" (unlike the Bribery Act 2010), the Courts will likely consider such procedures as highly persuasive in determining sentencing and the level of culpability should a prosecution proceed.
Boards must also consider the "collective knowledge" problem. Under the new law, if no single senior manager has the full picture of a criminal scheme, but jointly they possess it, does the company have the requisite knowledge? Recent legal commentary in the Law Society Gazette (September 2026) suggests that the prosecution will aggregate the knowledge of all senior managers to establish corporate guilt. Therefore, siloed information within an organisation is no longer a protective barrier; it is a vulnerability. Companies must implement unified information systems that allow compliance officers to identify patterns of risk across the entire senior management population, flagging potential red flags before they become criminal acts.
Steps for UK Businesses to Mitigate Risk
Immediate action is required for all UK businesses now that the Act is in force. The first step is to conduct a comprehensive audit of all senior management roles to identify who falls within the statutory definition. This audit should be documented and reviewed by external legal counsel to ensure accuracy. The definitive list of "senior managers" should then be used to update internal training programs, focusing on ethical decision-making and the personal and corporate consequences of criminal conduct. Specific training should be provided on how to identify "red flags" related to fraud and bribery, as these remain the highest-risk areas for corporate prosecution.
Secondly, companies must revise their delegation of authority procedures. Boards should centralise final sign-off on any transaction that presents a high regulatory risk, such as major procurement contracts, merger agreements, or dealings with politically exposed persons. This prevents a single senior manager from having the "apparent authority" to commit a crime. Thirdly, boards must foster a culture of "speak up". This means actively demonstrating to staff that internal whistleblowing leads to positive change, not retaliation. The Financial Conduct Authority (FCA) has reported that, as of Q2 2026, over 60% of enforcement cases originate from internal whistleblower reports; empowering this channel is a vital protective measure.
Finally, a robust response plan must be developed for potential investigations. Companies should engage with legal counsel to prepare a crisis management playbook. This should include procedures for preserving digital evidence, cooperating with the SFO or CPS, and communicating with stakeholders. Preparing for a potential SFO investigation before it happens allows a company to respond swiftly and credibly, which can be a mitigating factor in any subsequent sentencing hearing. According to sentencing guidelines published by the Sentencing Council for 2026, companies that demonstrate proactive cooperation and early guilty pleas can reduce their financial penalties by up to one-third.
Conclusion: Navigating Enhanced Corporate Responsibility
The extension of UK corporate criminal liability via the Crime and Policing Act 2026 is a definitive shift towards stricter accountability. It is designed to protect the UK economy and ordinary people by holding corporations to a higher standard. For boards and senior management, this is not merely a compliance burden but a challenge to embed integrity at the heart of their corporate strategy. The days of distancing the company from the rogue actions of senior employees are over. Those who adapt, who invest in rigorous governance, and who treat the rule of law as a cornerstone of shareholder value will navigate this new era successfully, while those who hesitate risk facing the full force of the UK criminal justice system.
This legislative shift signifies that corporate criminal liability has become one of the most significant domains of business law in this decade. For a comprehensive overview of other legal changes affecting UK businesses, review our finance coverage for expert analysis and practical guides. It is incumbent upon every director to understand that the protection of the company now requires a level of vigilance that far exceeds the traditional fiduciary duty of care. The UK is signalling that the integrity of the marketplace is paramount, and it is willing to criminalise the companies that undermine it.
Social Impact: Protecting the Public and the Economy
This legal expansion is not a technicality confined to boardrooms; it has profound social implications for the UK public. When companies commit crimes such as mis-selling financial products, causing environmental damage, or breaching worker safety laws, it is often ordinary consumers and employees who suffer the consequences. The recent news on 2 September 2026 revealed that over 600 companies, including large names, underpaid staff below the minimum wage, resulting in £4 million being returned to workers. Under the previous legal framework, if this underpayment was a deliberate decision by a regional manager, the company itself might have faced only civil penalties. Today, this could be treated as a criminal offence, reinforcing the message that corporate malpractice regarding wages is not a cost of doing business but a crime.
The expansion serves as a deterrent, which protects low-income households and vulnerable workers who are most at risk of exploitation. Whether it is a care home cutting corners on staffing ratios or a construction firm ignoring safety protocols to meet deadlines, holding the corporate entity accountable ensures that the financial burden of misbehaviour falls on shareholders, not on injured workers or public services like the NHS. This aligns with the UK government’s stated aim of promoting fair work and ensuring that economic growth does not come at the expense of social welfare.
News Analysis: Why This Shift Occurred in 2026
The timing of this Act’s enforcement is critical. Throughout 2025 and early 2026, the UK faced several high-profile scandals in the water industry and financial services, where companies avoided criminal prosecution by blaming junior staff for catastrophic failures. This legislative adjustment is a direct response to that public frustration. The government has determined that the previous reliance on deferred prosecution agreements (DPAs) was insufficient to create deterrence. The new law aims to give prosecutors the upper hand in negotiations, compelling corporations to reform their cultures rather than merely paying a fine. This is part of a broader global trend, but the UK is now positioned as a leader in corporate criminal law enforcement. By broadening the scope to include non-financial crimes, Westminster is sending a clear message: if corporate carelessness leads to loss of life or harm to the environment, the company will be held criminally liable to the fullest extent of the law.
FAQ: UK Corporate Criminal Liability
Who counts as a 'senior manager' under the Crime and Policing Act 2026?
Under the Act, a senior manager is an individual who plays a significant role in making decisions about how the company’s activities are managed or organised. This includes directors, chief executives, and individuals in senior positions who have the authority to make strategic decisions. The definition is broad and fact-specific. Any employee who has the power to commit the company to a significant course of action, without higher approval, could be considered a senior manager for the purposes of the offence.
What is the difference between the 2026 Act and the old 'identification principle'?
Under the old 'identification principle', a company could only be held liable if the criminal act was conducted by the "directing mind and will" of the organisation, typically the CEO or board itself. The 2026 Act expands this liability to include any 'senior manager' who has significant responsibility. This makes it much easier for prosecutors to pursue companies since they no longer need to prove the crime was orchestrated from the very top of the corporate hierarchy.
Does the Act provide a defence if the company had robust compliance procedures?
Unlike the Bribery Act 2010, the Crime and Policing Act 2026 does not explicitly provide a statutory defence of having "adequate procedures". However, having strong compliance frameworks and a positive culture is highly likely to be a significant mitigating factor in sentencing and in the prosecutor's decision to bring charges in the first place. Companies cannot rely solely on compliance to escape liability, but it will demonstrably reduce their culpability and the resulting penalties.
Which offences are covered by the 'any offence' liability?
The scope is incredibly wide. It includes all criminal offences, from fraud, bribery, and money laundering to health and safety breaches, data protection offences, and environmental crimes. If a senior manager commits a criminal offence while acting within the scope of their actual or apparent authority, and the company is deemed to have failed in its duty of care, the corporation can be prosecuted. This applies to breaches of the Companies Act 2006 as well as the Theft Act 1968, making it essential for legal teams to conduct a full-spectrum risk assessment.
For more detailed guidance on governance and risk, ensure you review our resources on Baba International to stay ahead of the regulatory curve. Additionally, see our recent analysis on UK financial regulation changes which overlap with these criminal liability rules.
Baba International Editorial Team
Our editorial team specialises in UK and EU personal finance, health policy, and economic analysis. All content is researched using authoritative sources including the ONS, NHS, Bank of England, ECB, and Eurostat.
Related Reading
- EU Banking Competitiveness: What Commission's Reform Agenda Means for Cross-Border M&A
- UK AI and Telecoms: What Faster Upgrades Mean for Staying in the Race
- EU Stocks Rally: What Easing US Rate Rise Fears Mean for European Investors
- EU Banking IT Merger: What Accenture's VTS Acquisition Means for Competition
Comments
Post a Comment