facebook

New rules that came into force on 29 June 2026 have made it easier in certain circumstances to attribute criminal liability to a company or partnership. Under section 250 of the Crime and Policing Act 2026, an organisation may be held criminally liable where a senior manager commits an offence under UK law while acting within the actual or apparent scope of their authority.

Under the new legislation – section 250 of the Crime and Policing Act 2026 (CPA) – firms can be held liable for any crime, not just economic crimes, which are committed by senior managers within the scope of their work.

For UK businesses, this is a huge change, and has far-reaching consequences.

Who is legally identified as a senior manager?

The senior manager test is already part of UK legislation, and is unchanged from the Economic Crime and Corporate Transparency Act 2023 (ECCTA) which came into force in December 2023.

Law firm Herbert Smith Freehills Kramer (HSF Kramer) states on its website: “Companies may be held liable for the actions of any individual with meaningful decision-making authority. The concept of a ‘senior manager’ in this context will not necessarily be confined to board-level directors or those within scope of any applicable individual accountability regime, and heads of business units, divisional leads, and senior operational managers may all potentially be caught.”

Osborne Clarke states: “Identifying senior managers will require a fact-specific assessment in each case and could encompass senior project managers, senior finance and HR personnel, regional managers, and heads of business divisions, among others.

“A significant degree of uncertainty is likely to arise from establishing what constitutes a ‘substantial part’ of an organisation's activities and whether an individual was acting within the scope of their authority.”

How does a company become liable?

A senior manager carrying out criminal activity doesn’t have to be authorised to do this by the company, but it would need to come under the usual scope of their ‘apparent authority’. An example would be a CFO who creates false statements about the company’s finances, an HR manager who commits an immigration offence, or even a marketing director who authorises a campaign which knowingly includes misleading statements about the product, according to HSF Kramer.

The provision covers all types of criminal offence, rather than economic crime alone. However, an organisation will not automatically be liable for a senior manager’s personal offending. The senior manager must have been acting within the actual or apparent scope of their authority when committing the offence.

The provision can also apply where conduct occurs outside the UK if the relevant offence has an appropriate UK connection or extraterritorial application. However, it does not apply where all the conduct constituting the offence takes place outside the UK and the organisation itself could not have been prosecuted had that conduct been attributed directly to it. Businesses dealing with possible overseas offences should obtain specialist legal advice.

Businesses may wish to consider the following general risk-management measures. The appropriate steps will depend on the organisation’s size, structure and activities, and businesses should obtain specialist legal, employment, insurance or compliance advice where necessary:

  • Conduct a fact-specific review of management structures and authority across regions, offices, and functions, focusing on who actually makes decisions rather than who holds formal titles. Refresh this exercise as the organisation evolves.
  • Review delegation frameworks, authority matrices, and client engagement protocols. The "apparent authority" element is particularly important: informal or perceived authority counts, even where not formally documented.
  • Update risk registers to cover all criminal offences, not just financial crime.
  • Refresh training, which should move beyond economic crime. Senior personnel should understand the full scope of the CPA, with specific modules on insider dealing protocols, government-facing conduct, and the handling of material non-public information.
  • Strengthen due diligence processes for senior staff: this should include not only appropriate vetting at recruitment or appointment, but also ongoing monitoring of individuals in senior management roles to identify potential behavioural, regulatory or integrity risks.
  • Enhance whistleblowing procedures to ensure that relevant criminal risks are escalated for investigation. Organisations should ensure employees feel able to raise concerns and that issues are properly investigated and addressed.
  • Review insurance and M&A due diligence. The CPA should be reflected in due diligence processes, and professional indemnity and directors' and officers' (D&O) insurers should be engaged to confirm that coverage responds to the broader range of offences now in scope.
  • Assess internal investigation readiness, refreshing protocols so that investigation teams can quickly identify whether an individual under investigation is a senior manager under the statutory definition. Given the risk of potential corporate liability, this analysis should be conducted under legal privilege – whether within a well-defined internal team or conducted by external counsel.

Important: This article is for general information only and does not constitute financial, investment, legal, tax, regulatory or insurance advice, or a recommendation of any product, provider or course of action. The information, figures, fees, interest rates, tax rules, allowances, legal requirements, products and account terms referred to were believed to be correct at the time of writing but may have changed since publication. Do not rely on this article as a statement of the current position. Always check the latest information with the relevant government department, regulator or provider and obtain appropriately qualified professional advice before taking or refraining from action.

Sources: Crime and Policing Act 2026, Home Office guidance, HSF Kramer and Osborne Clarke.

We can help you

If you would like help reviewing your business’s management structures, financial controls and general risk-management processes, please contact us. For advice on the legal application of these rules or a specific incident, you should speak to an appropriately qualified solicitor.