New rules that came into force on June 29 this year have made it easier to find companies guilty of criminal offences. The changes mean that if any senior manager of a corporation or partnership commits any offence while acting under the actual or apparent scope of their work authority, then the organisation itself is also considered to have committed the offence.
Under the new legislation – section 250 of the Crime and Policing Act 2026 (CPA) – firms can be held liable for any crime, not just economic crimes, which are committed by senior managers within the scope of their work.
For UK businesses, this is a huge change, and has far-reaching consequences.
Who is legally identified as a senior manager?
The senior manager test is already part of UK legislation, and is unchanged from the Economic Crime and Corporate Transparency Act 2023 (ECCTA) which came into force in December 2023.
Law firm Herbert Smith Freehills Kramer(HSF Kramer) states on its website: “Companies may be held liable for the actions of any individual with meaningful decision-making authority. The concept of a ‘senior manager’ in this context will not necessarily be confined to board-level directors or those within scope of any applicable individual accountability regime, and heads of business units, divisional leads, and senior operational managers may all potentially be caught.”
Osborne Clarke states: “Identifying senior managers will require a fact-specific assessment in each case and could encompass senior project managers, senior finance and HR personnel, regional managers, and heads of business divisions, among others.
“A significant degree of uncertainty is likely to arise from establishing what constitutes a ‘substantial part’ of an organisation's activities and whether an individual was acting within the scope of their authority.”
How does a company become liable?
A senior manager carrying out criminal activity doesn’t have to be authorised to do this by the company, but it would need to come under the usual scope of their ‘apparent authority’. An example would be a CFO who creates false statements about the company’s finances, an HR manager who commits an immigration offence, or even a marketing director who authorises a campaign which knowingly includes misleading statements about the product, according to HSF Kramer.
However, the broadened scope of the regulations doesn’t distinguish between offences related to business activity and personal offending. The danger for businesses is that potentially, they could be prosecuted if there is a way that the offence can be linked to the senior manager’s role.
It would also include offences committed outside the UK under the extended scope of the regulations, but the prospect of a company being held legally responsible for any illegal activity by a senior manager overseas is relatively small. Osborne Clarke said: “It applies only if all the conduct constituting the offence occurs outside the UK; and the company would not itself commit the offence if the conduct were attributed directly to it.
“In practice, this limitation is narrower than it first appears, given that companies can be prosecuted for a number of offences where the wrongdoing takes place outside the UK but there is a close connection to the UK or a UK nexus: for example, a UK-incorporated company involved in a bribery or sanctions offence that takes place entirely overseas.”
Companies should take a series of actions to protect themselves from these new regulations, so they are prepared for any potential criminal actions by senior managers:
· Conduct a fact-specific review of management structures and authority across regions, offices, and functions, focusing on who actually makes decisions rather than who holds formal titles. Refresh this exercise as the organisation evolves.
· Review delegation frameworks,authority matrices, and client engagement protocols. The "apparentauthority" element is particularly important: informal or perceivedauthority counts, even where not formally documented.
· Update risk registers to coverall criminal offences, not just financial crime.
· Refresh training, which should move beyond economic crime. Senior personnel should understand the full scope of the CPA, with specific modules on insider dealing protocols, government-facing conduct, and the handling of material non-public information.
· Strengthen due diligence processes for senior staff: this should include not only appropriate vetting at recruitment or appointment, but also ongoing monitoring of individuals in senior management roles to identify potential behavioural, regulatory or integrity risks.
· Enhance whistleblowing procedures to ensure that relevant criminal risks are escalated for investigation. Organisations should ensure employees feel able to raise concerns and that issues are properly investigated and addressed.
· Review insurance and M&A due diligence. The CPA should be reflected in due diligence processes, and professional indemnity and directors' and officers' (D&O) insurers should be engaged to confirm that coverage responds to the broader range of offences now in scope.
· Assess internal investigation readiness, refreshing protocols so that investigation teams can quickly identify whether an individual under investigation is a senior manager under the statutory definition. Given the risk of potential corporate liability, this analysis should be conducted under legal privilege – whether within a well-defined internal team or conducted by external counsel.
Source: Osborne Clarke
We can help you
If you are worried about these changes, or have any other concerns about your business, then please contact us and we will do everything we can to assist you.

.png)
