The corporate criminal offences (CCO) make a business criminally liable — strict liability, unlimited fine — if anyone associated with it facilitates tax evasion, unless the business can show it had reasonable prevention procedures in place. For eight years the regime was easy to dismiss as a paper tiger: plenty of guidance, no prosecutions. That changed in August 2025, when HMRC charged an accountancy firm and six individuals in the first CCO prosecution — and with the new failure-to-prevent-fraud offence in force since September 2025, "failure to prevent" liability now covers most economic crime a large organisation could touch.
If your risk assessment still dates from a 2018 training slide, here is the current landscape.
The CCO offences: how strict liability works
Under the Criminal Finances Act 2017 there are two offences: failure to prevent the facilitation of UK tax evasion (any relevant body, wherever based), and of foreign tax evasion — which needs both a UK nexus and conduct criminal in the foreign country and here. The structure matters more than the labels. The prosecution does not need to show the board knew anything. It needs three things: a taxpayer criminally evaded tax; an associated person of the business — employee, agent, contractor, anyone performing services for it — criminally facilitated that evasion; and the facilitation happened while acting for the business. At that point the business is guilty, full stop, unless it proves the defence: that it had reasonable prevention procedures, or that it was reasonable to have none.
The defence is the whole game, and HMRC's guidance builds it on six principles: risk assessment, proportionate procedures, top-level commitment, due diligence over associated persons, communication and training, and monitoring and review. A dusty policy that no one has read fails the test precisely because the test is about what the organisation actually does.
From theory to charge sheet
HMRC's enforcement numbers were, for years, the sceptic's favourite exhibit. The latest published figures show one charging decision, 13 live investigations and dozens of further opportunities under review across 11 business sectors — modest, but no longer zero. The first prosecution, launched in August 2025 against a Stockport accountancy firm over alleged R&D tax credit fraud, is the signal case: the defendant is a professional services firm, the alleged facilitation is client work, and every accountant, adviser and intermediary in the country understood the message. Investigations in this space run for years; the pipeline behind the first case is the real story.
The new sibling: failure to prevent fraud
Since 1 September 2025, the Economic Crime and Corporate Transparency Act adds a parallel offence: large organisations are criminally liable where an associated person commits fraud intending to benefit the organisation (or its clients), subject to the same style of reasonable-procedures defence. "Large" means meeting two of three thresholds — 250 employees, £36 million turnover, £18 million total assets — measured across the group, so plenty of owner-managed groups qualify without thinking of themselves as large.
The scope is wider than people assume: fraud by the organisation's people for its benefit — inflated sales claims, misleading statements to customers or investors, cooking performance figures — not fraud against the company. No prosecutions had surfaced by autumn 2026, but the same was said of CCO for eight years, and prosecutors have described the first case as a matter of when rather than if. Alongside it, the Act's reform of the identification doctrine (from December 2023) means a senior manager's economic crime is now attributable to the company directly — the old "directing mind" shield is gone.
What reasonable procedures actually look like
Regulators publish principles; enquiries test specifics. In practice, a defensible framework for a mid-size business is a connected set of ordinary things:
- A written risk assessment, refreshed on a cycle, that names the realistic routes — which services, clients, referrers, jurisdictions and payment flows could facilitate evasion or fraud, and who the associated persons are (contractors and introducers included);
- Proportionate controls mapped to those risks: engagement acceptance checks, payment controls, referral-fee due diligence, contract clauses obliging associated persons to comply;
- Visible top-level ownership — a named senior owner, board minutes showing the topic actually discussed;
- Training that matches roles, not an annual all-staff video — the tax team, sales team and anyone handling client money face different temptations;
- A monitoring loop: whistleblowing routes, periodic testing, and evidence that near-misses changed something.
Documentation is not bureaucracy here; it is the defence. In a prosecution, the difference between conviction and acquittal is the file showing what the organisation assessed, decided and did — dated before the conduct, not after the dawn raid.
Adjacent obligations worth bundling in
Businesses in the AML-regulated sector also pay the economic crime levy — from financial year 2026/27, £10,200 for medium entities (UK revenue over £10.2 million to £36 million), £36,000 for large (to £500 million), £500,000 to £1 billion, and £1 million above that — and their AML risk assessments cover much of the same ground as CCO ones. The efficient move is a single financial-crime framework: one risk assessment spine covering evasion facilitation, fraud, and money laundering, with offence-specific annexes, rather than three binders maintained by three people who have never met.
The practical test for your business
Ask three questions. Could you hand a prosecutor a current, dated risk assessment covering tax evasion facilitation and — if you meet the size thresholds — fraud? Can you show what changed because of it? And would your riskiest associated person (the commission-hungry introducer, the overseas agent) know they are covered by it? Two noes is the gap between having procedures and having a defence.
Acumon builds and reviews financial-crime prevention frameworks — risk assessments, procedures and training mapped to the CCO six principles and the fraud-offence guidance — through our anti-fraud and AML audit teams, with forensic accounting on call for the investigations nobody plans to need.