Section 250 of the Crime and Policing Act 2026: five examples of how corporate criminal exposure may expand for financial services firms
Section 250 of the Crime and Policing Act 2026 (“CPA 2026”) marks a decisive shift in the landscape of corporate criminal liability in the United Kingdom.
From 29 June 2026, the statutory mechanism for attributing criminal liability to corporate entities, previously limited to economic crimes, applies to all criminal offences under the law of England and Wales, Scotland or Northern Ireland, subject to the territorial limitation in s.250(2).
An exceptional feature of s.250 is the absence of a statutory “adequate” or “reasonable” procedures defence for corporate entities.
The significance of the change is not simply that more offences are theoretically attributable to organisations. It is that the attribution question will now turn less on whether the relevant individual was the company’s “directing mind and will”, and more on whether they played a significant managerial role and were acting within the actual or apparent scope of their authority. For larger and more complex organisations, that materially widens the perimeter of potential criminal exposure.
Given the FCA’s increasing appetite for criminal prosecution – see our recent article here – the change is particularly important for financial services firms.1
Notwithstanding the absence of a statutory “adequate procedures” or “reasonable steps” defence, there are steps organisations can and should take to mitigate the expanded corporate risk. Existing corporate prosecution guidance provides that established positive corporate action around systems and controls, evidence of a culture of compliance, and prompt investigation and cooperation with the authorities, may support a submission that prosecution of a corporate entity is not in the public interest.
The change in context
Historically, prosecutors in the UK have struggled to hold corporate entities to account for criminal conduct. The common law “identification doctrine” required that the individual responsible for the offence be the “directing mind and will” of the company, typically one with authority to act independently of the board in respect of a particular function.2 This high threshold meant that, in practice, only a narrow class of individuals could expose the company to criminal liability.
The Economic Crime and Corporate Transparency Act 2023 (“ECCTA 2023”) introduced a new statutory avenue to corporate criminal liability for economic crime offences, allowing liability to be attributed where a “senior manager” committed an offence within the scope of their authority (s.196 ECCTA 2023).
Section 250(7) CPA 2026 expressly repeals sections 196–198 of ECCTA 2023, which had previously established a statutory attribution mechanism for economic crime offences only. The new provision replaces the economic crime-specific model with a single, comprehensive rule for all criminal offences.
In-force date, scope, and territorial limitation
Section 250 CPA 2026 came into force on 29 June 2026. From that date, any offence under the law of England and Wales, Scotland or Northern Ireland committed by a senior manager of a company or partnership, while acting within the actual or apparent scope of their authority, will be treated as an offence by the organisation itself (s.250(1), CPA 2026).
This is subject to a narrow territorial exclusion: a company will not be liable if all the conduct constituting the offence occurs outside the United Kingdom, and the organisation would not commit the offence if it had carried out the conduct itself (s.250(2), CPA 2026). The Explanatory Notes to the CPA state that this exclusion, “ensures criminal liability will not attach to an organisation based and operating overseas for conduct carried out wholly overseas, simply because the senior manager concerned was subject to the UK’s extraterritorial jurisdiction: for instance, because that manager is a British citizen”.
Absence of statutory defences for companies
Beyond the narrow, territorial limitation, a striking feature of s.250 CPA 2026 is the absence of any statutory defence for companies. Unlike the “failure to prevent” offences (such as s.7 Bribery Act 2010, s.45 Criminal Finances Act 2017, and s.199 ECCTA 2023), there is no statutory defence of having “reasonable” or “adequate” procedures in place to prevent offending. If a senior manager commits a criminal offence within the scope of their authority, the company will be exposed to criminal liability.
This is a significant departure from previous models of corporate liability. Under the “failure to prevent” regime, organisations could avoid liability by demonstrating that they had implemented reasonable procedures to prevent offending by associated persons. Under s.250 CPA 2026, no such safe harbour exists. The only statutory exclusion is the narrow territorial exclusion described above.
Extension to all criminal offences
The most significant effect of s.250 CPA 2026 is the extension of the s.196 ECCTA attribution model to all criminal offences, not just those relating to economic crime. This includes offences under regulatory regimes (such as financial services, competition law, and data protection), as well as common law offences (including gross negligence manslaughter). The provision applies to both bodies corporate and partnerships, with certain limited exceptions (s.250(3), CPA 2026).
The organisation does not commit a new standalone offence. Rather, the senior manager’s conduct, and any requisite mental element, are attributed to the organisation by operation of s.250 CPA 2026.
The definition of “Senior Manager”
A central concept in s.250 CPA 2026 is the definition of “senior manager”. The term is defined as an individual who plays a “significant role” in:
the making of decisions about how the whole or a substantial part of the organisation’s activities are to be managed or organised, or
the managing or organising of the whole or a substantial part of those activities (s.250(3), CPA 2026).
This definition is deliberately broad and focuses on substance over form. It is not limited to board members or C-suite executives. Senior managers may include divisional heads, senior compliance officers, money laundering reporting officers (MLROs), and others with genuine influence over material areas of the business.
“Within the actual or apparent scope of their authority”
For corporate liability to attach, the senior manager must have been acting within the actual or apparent scope of their authority. This does not require that the individual was authorised to commit the criminal offence itself. Rather, it is sufficient that the act was of a type that the senior manager was authorised to undertake, or which would ordinarily be undertaken by a person in that position. The boundaries of this concept remain untested, and future case law will be critical in determining its precise scope.
The effect is that a company may be criminally liable even where the board or senior management were unaware of the conduct, or where the senior manager was acting contrary to the company’s interests, provided the conduct fell within the scope of their authority.
The current limitations of the Deferred Prosecution Agreement regime
At present, Deferred Prosecution Agreements (“DPAs”) are only available to corporate entities for a prescribed list of economic crime offences (set out in Schedule 17 to the Crime and Courts Act 2013). Those specified offences include fraud, bribery, Theft Act offences, and (since 1 September 2025) the corporate offence of failure to prevent fraud.
The gap between the ‘all offences’ approach to attribution under s.250 and the prescribed list of offences for which DPAs are available means that, unless the DPA regime is expanded, some newly attributable corporate offences may not be capable of resolution by DPA. That may increase the practical significance of prosecutorial discretion, including decisions not to prosecute where public interest factors weigh against proceedings.
The CPS and SFO joint corporate prosecution guidance
Notwithstanding the absence of a statutory compliance defence, the joint guidance issued by the Crown Prosecution Service (“CPS”) and the Serious Fraud Office (“SFO”) – the “Corporate Prosecution Guidance” – provides important context for organisations seeking to manage their risk exposure.
The Corporate Prosecution Guidance is important, but it is not a universal guide to every newly attributable offence: it expressly excludes corporate manslaughter and prosecutions by some specialist agencies under their own statutory frameworks.
The Corporate Prosecution Guidance sets out additional public interest factors that prosecutors should consider when deciding whether to bring proceedings against a corporate entity.
Relevant factors weighing against prosecution include:
A lack of a history of similar conduct involving prior criminal, civil and/or regulatory enforcement action.
The existence of a genuinely proactive and effective corporate compliance programme.
The offending represents isolated actions by individuals, for example by a rogue director.
Other factors, such as self-reporting, remedial action, and compensation of victims, may also be relevant. Conversely, a history of similar conduct, ineffective compliance programmes, or failure to report wrongdoing may weigh in favour of prosecution.
While these factors do not provide a legal defence, they are likely to be critical in practice, both in prosecutorial decision-making and in sentencing.
Five possible applications of s.250 in a financial services context
The breadth of s.250 CPA 2026 means that companies and partnerships may be exposed to criminal liability across a wide range of regulatory and criminal contexts.
The following five scenarios illustrate the potential reach of the new provision:
1. Failures in Suspicious Activity Reporting (SARs)
Sections 330 and 331 of the Proceeds of Crime Act 2002 (“POCA”) impose obligations to report knowledge, suspicion, or reasonable grounds to suspect of money laundering in the POCA regulated sector to the National Crime Agency (“NCA”).
A nominated officer or MLRO may, depending on the facts, fall within the statutory definition of “senior manager”, particularly in a financial services context where the MLRO may hold SMF17 under the Senior Managers and Certification Regime (“SMCR”).
A failure by an MLRO to make a SAR could therefore expose the company to criminal liability where the MLRO falls within the statutory definition of a senior manager and is acting within the actual or apparent scope of their authority
2. “Tipping Off” / prejudicing an investigation
Sections 333A and 342 of POCA create offences of “tipping off” and prejudicing a money laundering investigation. Senior managers may find themselves in possession of information, the disclosure of which might amount to one of these offences. If a senior manager commits such an offence within the scope of their authority, the company may be prosecuted.
Our recent article on the Court of Appeal’s judgment in R v Osmond, which clarifies the scope of the s.333A(3) tipping off offence, can be found here.3
3. Financial services offences – misleading the regulator
Section 398 of the Financial Services and Markets Act 2000 (“FSMA 2000”) makes it an offence to knowingly or recklessly provide false or misleading information to the Financial Conduct Authority (“FCA”).
The FCA has brought several cases in which it has alleged that Senior Managers have not complied with disclosure obligations and/or have sought to mislead the regulator. See for example our recent article here.4 Criminal conduct by senior managers may now be attributed to their firm.
4. Markets offences
Sections 89–91 of the Financial Services Act 2012 (“FSA 2012”) create criminal offences relating to misleading statements, misleading impressions, and false or misleading statements in relation to benchmarks.
Senior managers responsible for market disclosures, benchmark submissions, and/or trading activities could render the company criminally liable for such offences.
5. Destroying, falsifying, or concealing evidence
Section 177(3)(a) FSMA 2000 criminalises the falsification, concealment, destruction or otherwise disposal of a document which a person knows or suspects is or would be relevant to such an FCA investigation. Section 177(3)(b) criminalises any “causing or permitting” of the same.
The FCA has prosecuted under this provision in the recent past, in a case concerning the alleged deletion of WhatsApp messages in an insider dealing investigation. Where a senior manager engages in such conduct, or perhaps more likely, “causes or permits” any deletion or destruction of potential evidence, the corporate may be held criminally liable.
These examples are illustrative rather than exhaustive. In practice, the potential reach of s.250 CPA 2026 will depend on the wording of the underlying offence, the role and authority of the senior manager, any applicable statutory defence or limitation, and the relevant prosecutor’s public interest assessment.
What boards should so now
The expansion of corporate criminal liability under s.250 CPA 2026 requires immediate and careful attention from boards, general counsel, and senior management. In the absence of a statutory compliance defence, organisations must look to the factors identified in the Corporate Prosecution Guidance to assess their ability to resist prosecution should a senior manager commit an offence.
Key actions include:
Reviewing and strengthening compliance frameworks. While not a defence, a genuinely proactive and effective compliance programme remains a critical factor in the public interest assessment and may weigh against prosecution.
Enhancing training and oversight. Proactive risk management will require awareness across key functions and among senior managers that individual criminal conduct can expose the company to criminal liability.
Documenting remedial action and self-reporting. In the event of discovery of a potential offence by a senior manager, prompt investigation, self-reporting, remedial action, and cooperation with authorities may all be relevant to the question of whether a prosecuting agency deems the public interest test for prosecution to be met.
The coming into force of s.250 CPA 2026 is a landmark moment for corporate criminal liability in the United Kingdom.
Although the commission of an offence by a senior manager should be inherently unlikely in most well-run companies, the legal, regulatory and reputational consequences for the organisation if such conduct occurs are now materially more significant. Corporate exposure will no longer be confined to economic crime or dependent upon establishing that the relevant individual was the company’s directing mind and will.
Organisations should therefore ensure that governance arrangements, escalation processes, investigation capability, training programmes and compliance frameworks are capable not only of reducing risk, but also of supporting persuasive public interest arguments against prosecution should an incident occur.
Alan Ward is a Partner in the Regulation and Investigations group at Stephenson Harwood LLP.
1 FCA – Financial Crime Agency?, Alan Ward
2 Tesco Supermarkets Ltd v Nattrass [1972] AC 153, confirmed in Serious Fraud Office v Barclays Plc [2018] EWHC 3055 (QB).
3 Court of Appeal upholds solicitor's conviction and clarifies scope of POCA tipping off offence | Stephenson Harwood
4 FCA Decision Notice in the case of Carlos Ricardo Fuenmayor: lessons on disclosure obligations for Senior Managers | Stephenson Harwood