Companies face a broader corporate criminal liability test after the Crime and Policing Act 2026 expanded the circumstances in which organisations can be prosecuted for offences committed by senior managers.
Legal analysis of the Act says companies can now be prosecuted under UK law for any criminal offence committed by a senior manager where that person was acting within the actual or apparent scope of their authority. The change widens the senior manager attribution principle and increases the importance of governance, delegation, compliance controls, and board oversight.
Although regulated entities will be among the organisations examining the change most closely, its reach is not limited to financial services. Senior managers influence procurement, sales, finance, operations, HR, technology, market conduct, data handling, health and safety, and third party relationships. Where criminal conduct occurs within that authority, companies may face a more direct route to liability.
The Act builds on a policy direction that has been developing for several years. UK enforcement has increasingly focused on whether organisations have effective systems to prevent misconduct, detect risk, and respond quickly when problems emerge. The senior manager test raises the stakes because liability can be linked to the role and authority of individuals near the top of the organisation.
The practical consequence is a renewed need to define who is a senior manager, what authority they hold, how decisions are recorded, and how controls operate around high risk areas. Job titles alone will not answer those questions. Actual decision making power, delegated authority, reporting lines, and apparent authority to third parties may all become relevant.
Boards will need to examine whether their governance maps reflect how the business actually operates. Many organisations have formal committees, policies, and approval processes that look clear on paper, while informal influence and commercial urgency shape decisions in practice. That gap can create liability risk when senior individuals act beyond, or at the edge of, approved controls.
The Act also affects group structures. Parent companies, subsidiaries, joint ventures, and international operations can create ambiguity over authority. A regional executive, functional head, or divisional leader may be treated as senior for practical purposes even if ultimate board authority sits elsewhere. Companies with decentralised management models should review how accountability is allocated.
The regulatory direction is consistent with wider pressure on individual accountability. In financial services, FCA conduct rules have increased rescreening risk, with employers facing closer scrutiny over workforce conduct controls. The Crime and Policing Act extends the relevance of that accountability mindset beyond sector specific rules.
Compliance teams are likely to focus first on fraud, bribery, sanctions, money laundering, market conduct, consumer protection, environmental offences, data related offences, and health and safety. The wording described by legal advisers is broad enough to require attention across any area where senior managers can create criminal exposure for the company.
Training will need to become more targeted. Generic annual compliance modules are unlikely to be enough where individuals have significant authority over high risk decisions. Senior managers should understand the criminal risks attached to their functions, the limits of their authority, escalation expectations, and the personal and organisational consequences of ignoring controls.
Documentation will also matter. Companies should be able to show that risks were considered, decisions were approved through appropriate channels, concerns were escalated, and controls were monitored. A paper trail will not excuse misconduct, but weak records can make it harder to show that the company had reasonable systems and oversight.
The change may alter due diligence in mergers, acquisitions, and investment. Buyers will want to know whether target companies have clear authority structures, historic misconduct issues, whistleblowing records, regulatory correspondence, and evidence of compliance culture. Governance weakness can become a valuation issue where liability risk is harder to quantify.
Leadership teams will also need to examine culture. A company can have policies prohibiting misconduct while rewarding commercial behaviour that encourages excessive risk taking, opaque decisions, or pressure on junior staff. Enforcement attention often turns to that gap between written standards and operational incentives.
The immediate task is not simply to rewrite policies. Companies need to test whether authority, accountability, and controls are aligned. The broader senior manager liability test makes ambiguity more dangerous, especially where fast decisions are being made under commercial pressure.




You must be logged in to post a comment.