The Expansion of Corporate Criminal Liability: Preparing for Reforms – now in force since 29th June 2026

Since the 29th June 2026, under s.250 of the Crime & Policing Act 2026 (the “CPA”) businesses in England and Wales will face a significantly expanded risk of criminal liability. Companies may now be held criminally liable for any offence committed by a senior manager acting within the actual or apparent scope of their authority, even where the board had no knowledge of the conduct.

Earlier this year, we discussed the proposed reforms to the corporate criminal liability regime in England and Wales and what those changes might mean for businesses. Those reforms came into force on 29 June 2026, marking a significant shift in the way corporate criminal liability is attributed. We explore what these changes mean in practice and the steps businesses should take now that the legislation has come into effect.

The Changes to Corporate Criminal Liability

Historically, under Tesco v Nattrass establishing corporate criminal liability required prosecutors to establish wrongdoing by a person acting as the “directing mind and will” of a company. This test created significant evidential challenges, particularly in the context of large, complex, and multi-jurisdictional organisations, where no single person was responsible for directing and controlling a company.[1]

In 2023, section 196 of the Economic Crime and Corporate Transparency Act 2023 (the “ECCTA”) extended corporate liability for certain economic crimes committed by senior managers, as listed in Schedule 12. These offences included bribery, tax evasion, false accounting, money laundering, and fraud (collectively referred to as “economic crimes”). Under this framework, a company could be held liable where a senior manager committed an economic crime while acting within the actual or apparent scope of their authority.

S.250 of the CPA expands this principle significantly by using the same architecture as the section 196 ECCTA offence but applying it to all offending capable of being committed by the organisation. A company may be held criminally liable for any offence committed by a senior manager acting within the scope of their authority, whether actual or apparent. The reform therefore marks a substantial shift in corporate criminal liability, extending the senior manager attribution doctrine beyond economic crimes to encompass all criminal offences.

Given the expanded scope of corporate criminal liability, a central issue is how the law defines a “senior manager,” as liability in part now turns on whether the offending individual falls within this category.

The Definition of a “Senior Manager” and the Scope of the Regime

A “senior manager” is an individual who plays a significant role in:

  1. making decisions about the management of the whole, or a substantial part, of a business; or
  2. managing or organising the whole, or a substantial part, of those activities.

A key question is how “significant” an individual’s role must be before a business can be held liable for actions taken within the actual or apparent scope of their authority. Depending on the structure of the organisation, the definition could extend beyond board-level executives to include divisional heads, regional managers, and senior functional leads in areas such as finance, compliance, and operations. The precise boundaries of the definition are likely to be clarified through future enforcement activity and judicial consideration. It is important to note that this expansion of corporate criminal liability under the CPA (like the ECCTA) operates as a doctrine of attribution rather than the creation of a new substantive offence. It addresses how liability may be attributed to a company rather than whether the elements of a particular offence are made out. The absence of a “reasonable procedures” defence is therefore not a departure from the previous position under the Tesco v Nattrass framework, but a reflection of the fact that this is not a failure-to-prevent offence (like failure to prevent fraud under ss 119-206 of the ECCTA).

The key practical significance of the reform lies in the breadth of its application. By replacing the narrow “directing mind and will” test with a broader senior manager standard, which applies to all crimes, the CPA has the potential to capture a wider range of individuals whose conduct may be attributed to the company. These changes provide regulators and prosecutors with a more accessible route to corporate enforcement, thereby potentially increasing the likelihood of corporate investigations and prosecutions. The question now is how businesses should prepare for the changes that are in effect.

Preparing for Opening Night: What Businesses Should Do Now

1. Identify Senior Managers and Clearly Define the Scope of Their Authority

Companies should identify those individuals who fall within the statutory definition of a senior manager in respect of particular aspects of the business. Failure to do so may create unforeseen areas of exposure. Organisations should determine which employees may be affected and ensure they understand the implications of the new regime.

Businesses should also clearly define the scope of each senior manager’s authority through employment contracts, role descriptions, governance frameworks, and delegated authority structures. The broader and less clearly defined a senior manager’s authority is, the easier it may be for prosecutors to establish that a person was a senior manager acting within their scope. Clear documentation can therefore reduce uncertainty and minimise risk. An organisation may usefully explicitly exclude any criminal conduct from the scope of the individual’s delegated authority.

2. Strengthen Recruitment and Due Diligence Processes

Recruitment decisions are likely to attract greater scrutiny following the expansion of corporate criminal liability. Businesses should strengthen due diligence when recruiting senior managers, particularly for roles involving significant authority or regulatory exposure.

This may include enhanced background checks, more rigorous references, and interview processes designed to test judgment, integrity, and attitudes towards compliance. The objective is not only to identify past misconduct, but to assess whether candidates are likely to exercise authority responsibly.

3. Enhance Training and Awareness

Businesses should provide guidance on the types of criminal offences that may arise within the scope of a senior manager’s authority, taking into account sector-specific risks and organisational structure.

Training should include practical examples, decision-making scenarios, escalation procedures, and the internal controls designed to prevent misconduct. Senior managers should also be equipped to identify risks early and seek appropriate advice.

Whether organisations can distinguish, in advance, the risk appetite necessary for entrepreneurship (itself necessary for successful business) from the risk appetite of those more tempted to commit crime we are not qualified to say. It would be unfortunate indeed if one response to this legislation – which provides for no defence by the organisation – is that risk takers are less attractive hires, for that would be self defeating.

4. Conduct Regular Risk Assessments and Review Policies

Businesses should remain alert to internal and external developments and update their governance and control frameworks as risk profiles evolve. Mergers, restructuring, new markets, and regulatory developments may all create new exposures.

To address this, businesses should periodically review:

  1. who qualifies as a senior manager;
  2. the scope of their authority;
  3. recruitment and due diligence processes;
  4. relevant offence risks; and
  5. the adequacy of training and compliance measures.

Where gaps are identified, businesses should take practical steps to address them through clearer delegations, revised policies, enhanced training, and increased oversight.

Conclusion

The expansion of corporate criminal liability represents a significant shift in the UK’s enforcement landscape. Businesses can no longer limit the size of the board as a means of limiting exposure to corporate liability – whether or not a senior manager is a director is not determinative of liability. Nor can organisations focus solely on organisational misconduct or, in the regulatory sphere, those offences only capable of being committed by the organisation; they must also consider the actions of senior managers whose conduct may now be attributed directly to the company.

While the reforms create increased exposure to criminal liability, they also present an opportunity for businesses to reassess governance structures, delegation frameworks, recruitment processes, and training programmes. Businesses that fail to act now may find themselves exposed to criminal liability arising from decisions taken well below board level, even if the focus later is on those close to board level. Those organisations that do will be better positioned to manage risk and respond effectively to the new enforcement environment.

How Edmonds Marshall McMahon can help

The expansion of corporate criminal liability represents a significant shift in the UK’s enforcement landscape. Organisations should ensure their governance structures, delegated authority frameworks and compliance procedures are fit for purpose under the new regime.

EMM advises businesses, directors and senior executives on corporate criminal liability, internal investigations, regulatory enforcement and fraud prevention. If you would like to discuss how these reforms could affect your organisation, please get in touch with a member of our team.

corporate criminal liability

[1] Tesco Supermarkets Ltd. v Nattrass [1972] AC 153 (HL).

Dylan Silvain

Freddy Faull