Oben Legal PLLC, New York. Attorney advertising.

Programme work is delivered through Themis Advisory Group

Oben Legal

United Kingdom

100 to 130 hours, documented

What a failure-to-prevent-fraud risk assessment has to contain before it counts as reasonable procedures, and why your bribery assessment does not cover it.

By Terence A. Oben6 min read

Since 1 September 2025, a large organisation can be criminally liable in the UK when someone acting for it commits fraud intended to benefit the organisation or its clients. There is one defence: reasonable fraud prevention procedures. And the government's guidance is clear that those procedures start with a documented risk assessment.

The Home Office's own impact assessment put that work at roughly 100 to 130 hours. That figure is worth taking seriously, because it tells you what the authorities think an adequate assessment looks like: not a paragraph added to the bribery register, but a piece of work in its own right.

Who is in scope

The offence applies to organisations meeting two of three tests: more than 250 employees, more than £36 million in turnover, more than £18 million in total assets. The tests are applied across the group, not entity by entity, and subsidiaries can be prosecuted in their own right.

Non-UK organisations are in scope where the fraud has a UK connection, such as UK victims or conduct in the UK. A US company with a UK sales operation, or with UK customers, should assume it is covered until its advisers say otherwise.

Why the bribery assessment does not cover it

An anti-bribery risk assessment asks how someone might corrupt a decision-maker. A fraud risk assessment asks how someone might deceive a customer, an investor or a counterparty for the company's benefit. The underlying offences are different: false representation, false accounting, dishonest failure to disclose, fraud against investors.

That puts different teams in the frame. Sales practices, marketing claims, customer disclosures, financial reporting and investor communications all come into scope. The people with the most detailed knowledge of those risks are rarely the people who own the bribery programme.

What the assessment should contain

The government's guidance is organised around six principles: top-level commitment, risk assessment, proportionate procedures, due diligence, communication and training, and monitoring and review. For the assessment itself, the working minimum is:

  1. A map of the associated persons who could commit fraud on the organisation's behalf, including agents, contractors and subsidiaries.
  2. For each business line, the fraud schemes that are realistically possible, considered through opportunity, motive and rationalisation.
  3. An assessment of which existing controls already address each risk, and how well.
  4. A record of the residual risks, the decisions taken about them and who took those decisions.
  5. A date for review, and the triggers that would bring it forward: a new market, a new product, an acquisition.

The practical point

The assessment is also your evidence. If a fraud ever happens, it is the first document a prosecutor will ask for.

Where to start

Confirm first whether the group meets the size test. If it does, assign a single owner with the authority to pull in sales, finance and legal, and agree the method before anyone starts listing risks. The hours go on the thinking, not the formatting.

Terence A. Oben

Attorney at law, admitted in New York. Fifteen years of legal, compliance and enterprise risk work across JPMorgan Chase, BNP Paribas, Deutsche Bank, Banco Santander and Ericsson.

Programme work runs through Themis Advisory Group

More from the Brief