Since 1 September 2025, a large organisation can be criminally liable in the UK when someone acting for it commits fraud intended to benefit the organisation or its clients. There is one defence: reasonable fraud prevention procedures. And the government's guidance is clear that those procedures start with a documented risk assessment.
The Home Office's own impact assessment put that work at roughly 100 to 130 hours. That figure is worth taking seriously, because it tells you what the authorities think an adequate assessment looks like: not a paragraph added to the bribery register, but a piece of work in its own right.
Who is in scope
The offence applies to organisations meeting two of three tests: more than 250 employees, more than £36 million in turnover, more than £18 million in total assets. The tests are applied across the group, not entity by entity, and subsidiaries can be prosecuted in their own right.
Non-UK organisations are in scope where the fraud has a UK connection, such as UK victims or conduct in the UK. A US company with a UK sales operation, or with UK customers, should assume it is covered until its advisers say otherwise.
Why the bribery assessment does not cover it
An anti-bribery risk assessment asks how someone might corrupt a decision-maker. A fraud risk assessment asks how someone might deceive a customer, an investor or a counterparty for the company's benefit. The underlying offences are different: false representation, false accounting, dishonest failure to disclose, fraud against investors.
That puts different teams in the frame. Sales practices, marketing claims, customer disclosures, financial reporting and investor communications all come into scope. The people with the most detailed knowledge of those risks are rarely the people who own the bribery programme.
What the assessment should contain
The government's guidance is organised around six principles: top-level commitment, risk assessment, proportionate procedures, due diligence, communication and training, and monitoring and review. For the assessment itself, the working minimum is:
- A map of the associated persons who could commit fraud on the organisation's behalf, including agents, contractors and subsidiaries.
- For each business line, the fraud schemes that are realistically possible, considered through opportunity, motive and rationalisation.
- An assessment of which existing controls already address each risk, and how well.
- A record of the residual risks, the decisions taken about them and who took those decisions.
- A date for review, and the triggers that would bring it forward: a new market, a new product, an acquisition.
The practical point
The assessment is also your evidence. If a fraud ever happens, it is the first document a prosecutor will ask for.
Where to start
Confirm first whether the group meets the size test. If it does, assign a single owner with the authority to pull in sales, finance and legal, and agree the method before anyone starts listing risks. The hours go on the thinking, not the formatting.