The failure to prevent fraud offence makes a large organisation criminally liable when a person acting for it commits fraud to benefit it. It came into force on 1 September 2025 under the Economic Crime and Corporate Transparency Act 2023. Incorporated charities and public bodies that meet the size thresholds are in scope. Reasonable fraud prevention procedures are the defence.
If you fund other organisations, this offence has probably reached your board papers already. Trustees ask whether the charity is caught, what "reasonable procedures" look like, and whether grantee checks count. This article answers those questions in plain words. It is not legal advice.
The offence sits in section 199 of the Economic Crime and Corporate Transparency Act 2023, usually shortened to ECCTA. A large organisation commits the offence when a person associated with it commits a fraud offence intending to benefit the organisation. The Home Office guidance is explicit that "it does not need to be demonstrated that directors or senior managers ordered or knew about the fraud". The organisation is liable unless it can prove a defence.
The defence is set out in the same section. The organisation must show it had prevention procedures in place that were reasonable in all the circumstances. It can also argue that it was not reasonable to expect any procedures at all. That second route will rarely help a funder.
The offence applies to fraud committed on or after 1 September 2025. The Home Office published its statutory guidance on 6 November 2024 and updated it on 10 October 2025.
Yes, if two conditions are met. First, the charity must be incorporated. That includes charitable companies and charitable incorporated organisations (CIOs, a legal form that gives a charity its own legal personality without company law). Unincorporated trusts and associations are outside the offence, because they are not "bodies corporate". The Home Office guidance says some charities "are incorporated and would therefore be in scope if they meet the criteria".
Second, the charity must be a large organisation. Section 201 of the Act sets the test and borrows the Companies Act 2006 definition of turnover. You are large if you met two of three tests in the financial year before the fraud. The tests are more than 250 employees, more than £36 million turnover, or more than £18 million in total assets. The tests apply to the whole group, so subsidiaries count.
Public bodies are covered too. The guidance names NHS trusts and local authorities as examples of organisations that can fall within scope.
This is the question trustees raise most often. Section 201 says turnover has the meaning given in the Companies Act 2006 for companies, and a "corresponding meaning" for other bodies. The Home Office guidance describes turnover as amounts derived from the provision of goods and services in the ordinary activities of the organisation. Most grant-making charities have income from donations, investments and legacies rather than sales.
The Charity Commission has taken a practical view. Its regulatory alert of 4 February 2025 describes the thresholds as "more than 250 employees, £36m of income or £18m in total assets". The regulator treats income, not commercial turnover, as the measure. The Home Office guidance says it "cannot provide details on exactly how the criteria apply to each case". It advises legal advice.
The safe course follows from both. Apply the test to total income in your accounts, as the Commission does. If you sit close to the line, take advice and record the reasoning.
Endowed foundations often pass the assets test on investments alone. A small charity can become large after a merger or a legacy, so repeat the test each year.
The guidance sets out six principles. It expects organisations to shape their procedures around them rather than copy a template.
The word "proportionate" matters. A community foundation and a national research funder face different risks, and the guidance expects different responses. Both need a written record that shows they thought about fraud and acted on it.
An associated person is an employee, agent or subsidiary, or anyone who "otherwise performs services for or on behalf of" the organisation. The Act says you judge that by looking at all the circumstances, not just the label on the contract.
For most funders this raises a careful distinction. A grant recipient that spends your money on its own charitable work is usually not performing services on your behalf. It receives a benefit from you rather than acting for you. The guidance is clear that people who provide services "to" an organisation are outside the definition. So a standard grantee is unlikely to be an associated person.
The picture changes when a partner delivers your programme for you. A charity that runs your grant scheme under contract may be an associated person. So may an intermediary that distributes your funds, or a delivery partner acting in your name. Their fraud, intended to benefit you, could become your offence. Those relationships deserve the fullest due diligence.
There is a wider point. Even where a grantee falls outside the offence, the same procedures protect the charity from fraud committed against it. Trustees already carry that duty under the Charity Commission's guidance on internal financial controls, CC8. The offence adds a criminal dimension to a duty you already hold.
Start with scope. Ask your finance lead and legal adviser to confirm whether the charity is a large organisation, and record the reasoning.
Then map your associated persons. List every organisation that acts for you or in your name, and separate them from ordinary grantees. Apply the strongest checks to the first group.
Next, write down your fraud risk assessment and the controls that answer each risk. Include the checks you run on organisations before money moves, and how you record them. Finally, put the topic on the board agenda at least annually, because top level commitment is the first principle.
For a plain-words companion, read our guide to what the Charity Commission expects of grant-makers. It covers the "know your partner" tools and CC8.
Key takeaways
Where a register check fits
The AI Due Diligence Checker is built into Flexigrant. It runs one search across Companies House, the Charity Commission for England and Wales and OSCR. You get a fixed-formula score you can read, with links to the source records. It supports your own due diligence process. It does not replace that process, and it does not certify compliance with the offence or the guidance described above. Learn more on the AI Due Diligence Checker feature page. Click here