Section 250 of the Crime and Policing Act 2026 (CPA) came into force on 29 June 2026. This new provision significantly extends a corporate’s potential criminal liability because where a senior manager commits any criminal offence under UK law, whilst 'acting within the actual or apparent scope of their authority', the corporate will also commit the offence and can be convicted and sentenced accordingly.
The provision only applies to the actions of a 'senior manager' however. This is a person who is:
- an individual who either plays a significant role in managing or organising the business, or a substantial part of it, or
- an individual who plays a significant role in making decisions about the managing or organising the business, or a substantial part of it.
Corporates should be wary of assuming that the offence will only apply to someone with the title of 'manager' or 'senior manager'. The term 'senior manager' is also not restricted to statutory directors and senior officers. Whether someone falls within the definition will depend on their role within the organisation and the tasks they perform.
The phrase 'acting within the actual or apparent scope of their authority' is designed to capture an individual's actions where they are of a type that the individual was authorised to undertake, or which would be expected to be undertaken. The example given in the explanatory note is where the Chief Financial Officer commits fraud by making false statements about a company’s financial position.
The offence does not apply in circumstances where the offence is committed overseas and, if the conduct was attributable to the company, there would be no offence. But otherwise, there is no statutory defence.
This new provision represents a further step towards placing responsibility on corporates of all sizes for the criminal actions of their officers and senior staff. It extends - and replaces - similar existing provisions relating solely to corporate crime found in the Economic Crime and Corporate Transparency Act 2023 (ECCTA) (including section 196 of ECCTA which held companies responsible for corporate crimes committed by senior managers acting within the actual or apparent scope of their authority). It also widens the common law 'identification doctrine' where a corporate can be found guilty of an offence if it is carried out by a person with the 'directing mind and will' of the organisation (namely, an individual so senior that their decisions are considered to be the corporate’s decisions).
The new provision also sits alongside the relatively new failure to prevent fraud offence under section 199 of ECCTA, introduced in September 2025. That offence is different in nature: it targets companies that fail to put in place adequate procedures to prevent fraud by persons associated with them, and it only applies to ‘large organisations’, namely those meeting at least two of: turnover above £36 million, assets above £18 million, or more than 250 employees. Section 250 of the CPA, by contrast, makes the corporate directly liable for a criminal offence committed by the senior manager. Importantly, where a senior manager of a large organisation commits an economic crime such as fraud, the corporate could potentially face prosecution under both provisions: under section 250 for the commission of the fraud itself by the senior manager, and under section 199 of ECCTA for failing to prevent the fraud. Unlike section 250, however, section 199 does provide a statutory defence if the company can show it had reasonable fraud prevention procedures in place. It remains to be seen how prosecutors will deploy these overlapping but distinct regimes in practice.
What steps should corporates be taking now?
As there is no ‘reasonable procedures’ defence, even the best compliance programme will not shield a corporate from liability where a senior manager commits an offence as part of their role. That said, robust compliance programmes and risk assessments remain vital. They reduce the likelihood of offending in the first place, and they will be relevant to decisions by prosecutors and courts as to bringing charges and sentencing (for example, they will be relevant as to whether a prosecution is in the public interest).
If they have not already done so, corporates are recommended to take the following steps to manage their exposure:
Firstly, a risk assessment to establish which individuals fall within the 'senior manager' definition (focusing on what each person does rather than their job title) is needed, alongside identifying any particular areas of risk.
Secondly, corporates should clearly document what each senior manager is and is not authorised to do, so that the boundaries of their authority are well defined. Consideration should be given to whether there are sufficient safeguards to in place to protect the business against the possibility of them committing a crime whilst acting in the actual or perceived scope of their authority.
Thirdly, this should be done alongside broadening risk assessments beyond fraud and bribery to cover criminal offences which are sector relevant, and providing training for senior managers on the new rules and review governance frameworks and compliance policies.
Finally, corporates should take the opportunity to review whistle-blowing policies and check that Directors' and Officers' insurance is up to date.
Rachel Warren is a partner at Charles Russell Speechlys
























No comments yet