When the offence of Failure to Prevent Fraud came into force, organisations were asked a simple but important question: are your fraud prevention procedures reasonable? One year on, the question has evolved. It’s no longer about whether you have a framework in place. It’s about whether that framework is embedded, understood and working in practice.
The introduction of the Failure to Prevent Fraud offence under the Economic Crime and Corporate Transparency Act (ECCTA) marked a significant shift in corporate accountability. The legislation places responsibility on large organisations to have reasonable fraud prevention procedures in place to prevent fraud committed by employees, agents, subsidiaries, or other associated persons for the benefit of the organisation or, in certain circumstances, its clients.
For many organisations, the past year has been spent reviewing risk registers, updating policies, delivering training and strengthening governance arrangements. These were important first steps. However, regulators, prosecutors and stakeholders are unlikely to be satisfied by policies sitting on a shelf.
The real test is whether your organisation can demonstrate that fraud prevention is part of everyday decision-making.
From Compliance Exercise to Organisational Culture
Over the last twelve months, TIAA has worked with many organisations, helping them make positive progress. Leadership teams have shown greater interest in fraud risk and discussions about fraud prevention are taking place beyond specialist functions.
But a key question remains:
Could you confidently demonstrate today that your fraud prevention procedures are effective?
Having a fraud policy is one thing. Demonstrating that staff understand it, managers apply it and leaders actively support it is something entirely different.
The legislation’s six guiding principles, including top-level commitment, risk assessment, due diligence, communication and monitoring, were never intended to be a one-off compliance checklist. They were designed to encourage continuous improvement and ongoing vigilance.
Four Questions Organisations Should Be Asking Themselves
One year on, organisations should consider whether they can answer “yes” to the following questions:
- Have We Refreshed Our Fraud Risk Assessment?
Fraud risks continue to evolve.
Changes in technology, procurement practices, hybrid working arrangements and the growing use of artificial intelligence may have altered your organisation’s exposure since your original assessment was completed.
If your fraud risk assessment hasn’t been reviewed recently, now is the time.
- Can Staff Recognise Fraud Risks?
Training should not simply be about awareness. It should equip staff with the confidence to identify concerns, challenge unusual activity and know how to report potential fraud.
Ask yourself: would staff know what fraud might look like in their role?
- Is Leadership Providing Visible Commitment?
The tone set by senior leaders remains critical.
Employees are more likely to raise concerns, challenge inappropriate behaviour and follow procedures when they see leaders actively discussing integrity, transparency and accountability.
- Are We Monitoring Effectiveness?
Many organisations invested significant effort in developing controls. Fewer have established robust mechanisms for measuring whether those controls are working.
Monitoring activity, reviewing incidents, analysing trends and learning from near misses are all important indicators of an effective fraud prevention programme.
The Growing Importance of Evidence
One of the most important developments over the past year has been a growing recognition that organisations need to be able to evidence what they have done.
If challenged, could you demonstrate:
- When fraud risks were assessed?
- How decisions were made?
- What training was delivered?
- How concerns were monitored and addressed?
- What actions were taken following reviews or investigations?
The organisations best placed to meet the expectations of the Failure to Prevent Fraud offence are not necessarily those with the largest policies or most complex procedures. They are the organisations that continually review, challenge and improve their approach.
Fraud prevention should not be viewed as a standalone compliance requirement. It is part of a wider commitment to good governance, ethical culture and organisational resilience.
One year on, now is the ideal time to pause and reflect:
What have you done to comply and, more importantly, how do you know it’s working?
How TIAA Can Help
Whether you are reviewing your existing arrangements, refreshing your fraud risk assessment or seeking independent assurance over your fraud prevention framework, TIAA’s specialist counter fraud team can help.
Our Fraud Health Check provides an independent assessment of your organisation’s readiness, helping you identify strengths, address gaps and demonstrate confidence in your fraud prevention arrangements.
Because when it comes to fraud prevention, compliance is only the beginning. Building a resilient organisation is the real objective.