Since 2017 a company can be convicted of a criminal offence because of what someone acting for it did, with no need to prove that anyone at board level knew. The only answer is a defence of reasonable prevention procedures, and that defence is documentary. If the risk assessment does not exist, neither does the defence.
On this page
What the Offences Are
Sections 45 and 46 of the Criminal Finances Act 2017 created two corporate offences: failure to prevent the facilitation of UK tax evasion, and failure to prevent the facilitation of foreign tax evasion. They came into force on 30 September 2017 and apply to “relevant bodies”: companies and partnerships.
The design borrows directly from the Bribery Act 2010. The organisation is liable for what someone associated with it did, unless it can show it had reasonable prevention procedures in place. That is a strict liability offence with a defence, not an offence requiring proof of corporate intent.
The Three Stages
An offence is committed only if all three stages are established. Each is a separate hurdle and each is worth examining.
- Stage one: criminal tax evasion by a taxpayer. There must be criminal evasion of tax by a person: fraudulent evasion, cheating the public revenue, or an equivalent foreign offence. Civil non-compliance, avoidance, error and carelessness are all outside the offence. No conviction of the taxpayer is required, but the conduct must amount to a criminal offence.
- Stage two: criminal facilitation by an associated person. A person associated with the relevant body must have criminally facilitated that evasion, while acting in that capacity. “Associated person” is wide: employees, agents, and any other person performing services for or on behalf of the organisation. Facilitation must itself be criminal, deliberate and dishonest, so negligence by the associated person is not enough.
- Stage three: failure by the relevant body to prevent it. This is where the defence operates.
The Reasonable Prevention Procedures Defence
It is a defence for the relevant body to prove that it had in place such prevention procedures as it was reasonable in all the circumstances to expect it to have, or that it was not reasonable in all the circumstances to expect it to have any.
Government guidance frames the expectation around six principles, which will be familiar from the Bribery Act:
- Risk assessment: a documented assessment of where and how the organisation could be exposed to the criminal facilitation of tax evasion by those acting for it.
- Proportionality of risk-based prevention procedures: the response should be proportionate to the risk identified, not a template.
- Top level commitment: evidenced involvement of senior management.
- Due diligence, on associated persons, particularly intermediaries, introducers, agents and contractors.
- Communication, including training, so that people know what is prohibited and how to raise concerns.
- Monitoring and review: procedures kept current as the business and its risks change.
Consequences
- An unlimited fine.
- A criminal conviction for the organisation, with the reputational consequences that follow.
- Regulatory consequences. For regulated firms, a conviction engages fitness and propriety and licensing considerations.
- Procurement consequences. Conviction can affect eligibility for public contracts.
- Ancillary orders, including confiscation under the proceeds of crime legislation.
HMRC is the investigating authority for the domestic offence. It publishes periodic information on the number of live investigations and opportunities under review, which has consistently shown activity across a broad range of sectors, not only financial services.
The Newer Sibling: Failure to Prevent Fraud
The Economic Crime and Corporate Transparency Act 2023 created a further failure to prevent offence, this time for fraud. It came into force on 1 September 2025 and applies to large organisations, defined by reference to statutory thresholds for turnover, balance sheet total and employee numbers.
The structure mirrors the tax offences: the organisation is liable where an associated person commits a specified fraud offence intending to benefit the organisation, subject to a defence of reasonable fraud prevention procedures.
| CFA 2017 ss45–46 | ECCTA 2023 failure to prevent fraud | |
|---|---|---|
| Applies to | All relevant bodies, any size | Large organisations only |
| Predicate conduct | Criminal facilitation of tax evasion | Specified fraud offences |
| Benefit requirement | None | Intended to benefit the organisation or its clients |
| Defence | Reasonable prevention procedures | Reasonable fraud prevention procedures |
Practically, most organisations should treat the two together. The risk assessment, governance, due diligence, training and monitoring that support one defence support the other, and a single integrated framework is easier to maintain and to evidence than two parallel sets of documents.
Where the Risk Actually Sits
The exposure is rarely in the organisation’s own tax affairs. It is in what people acting for it do for third parties. Common risk areas include:
- Labour supply chains: construction, logistics, care, agriculture and security, where umbrella companies, intermediaries and mini-umbrella arrangements feature.
- Introducers and agents, particularly where remunerated by commission and operating outside the organisation’s direct control.
- Overseas operations and correspondents, which engage the foreign tax evasion offence in s46.
- Payment and settlement arrangements that obscure the identity of the ultimate recipient.
- Advisory and structuring work, where the line between planning and facilitation can be crossed by an individual acting outside authority.
- Cash-intensive operations and situations where the organisation knowingly deals with customers whose own compliance is doubtful.
What Organisations Should Do
Building the defence
- Carry out and document a risk assessment. Specific to the business, covering each category of associated person and each jurisdiction. Date it, and record who approved it.
- Design proportionate procedures. Policy, escalation route, contractual terms with intermediaries, red flag guidance, and a mechanism for raising concerns.
- Evidence top level commitment. Board or senior management minutes recording consideration and approval.
- Do due diligence on associated persons, and record it. Introducer and agent files are the ones investigators ask for first.
- Train, and record the training, who attended, when, and what was covered.
- Monitor and review on a defined cycle, and record the review even when nothing changes.
- Integrate with anti-money laundering and anti-bribery frameworks rather than running three separate regimes.
If HMRC makes contact
- Establish what is actually alleged, which stage, and against whom. Stages one and two both require criminal conduct and are often assumed rather than evidenced.
- Take independent advice immediately, and consider whether the organisation’s interests and those of the individuals involved have already diverged.
- Get privilege right before the internal investigation starts. Define the client group, frame the legal context, and consider whether litigation privilege is available: see Three Rivers (No 6) and SFO v ENRC.
- Preserve documents and suspend routine deletion.
- Assemble the defence evidence: risk assessment, policies, training and due diligence records, with their dates.
- Consider self-reporting carefully and on advice. It is a significant step with consequences that need to be understood before it is taken.
Frequently Asked Questions
What are the corporate criminal offences?
Sections 45 and 46 of the Criminal Finances Act 2017 make it an offence for a company or partnership to fail to prevent a person associated with it from criminally facilitating tax evasion, s45 for UK tax, s46 for foreign tax. There is a defence of reasonable prevention procedures. The penalty is an unlimited fine and a criminal conviction for the organisation.
Does HMRC have to prove the company knew?
No, and that is the point of the offences. Before 2017 prosecuting a company required attributing an individual’s state of mind to it under the identification doctrine, which in practice meant proving a directing mind was complicit. Sections 45 and 46 remove that requirement: liability follows from the associated person’s conduct unless the organisation establishes the reasonable prevention procedures defence.
Does a civil tax dispute put us at risk?
Not by itself. Both of the first two stages require criminal conduct: criminal evasion by a taxpayer, and criminal facilitation by an associated person. Avoidance, error, carelessness and civil non-compliance are outside the offence. Where HMRC raises the offences, the first step is to establish whether criminal conduct is actually being alleged and evidenced at both stages, or whether the position has drifted from a civil compliance failure.
What does the defence actually require?
Prevention procedures that were reasonable in all the circumstances. Government guidance frames this around six principles: risk assessment, proportionate risk-based procedures, top level commitment, due diligence on associated persons, communication including training, and monitoring and review. Critically the defence is documentary: the risk assessment, policies, training records and due diligence files either exist with contemporaneous dates or they do not.
How does this relate to failure to prevent fraud?
The Economic Crime and Corporate Transparency Act 2023 created a parallel failure to prevent fraud offence, in force from 1 September 2025, with the same architecture and its own reasonable procedures defence. The key difference is scope: the fraud offence applies only to large organisations, while the tax offences apply to relevant bodies of any size. Most organisations should build one integrated framework covering both.