All resources

Eunomia perspective · 2026-09-30 · Regulatory Updates & Compliance News, Third-Party Due Diligence & Supply Chain Compliance

Failure to Prevent Fraud: What Pharmaceutical Companies Need to Do

Published by Eunomia Pharma Services · Updated

What does the failure to prevent fraud offence mean for pharma companies?

Since 1 September 2025, a large organisation can be liable if an associated person, such as an employee, agent, subsidiary or service provider, commits a specified fraud intending to benefit it or its clients, unless it had reasonable fraud prevention procedures. Under ECCTA, large means meeting two of: more than 250 employees, £36 million turnover or £18 million assets.

Practical steps

  1. Check scope at group level using the previous financial year.
  2. Extend the risk assessment to fraud risks in scope.
  3. Add fraud risk to third-party due diligence and contracts.
  4. Update policies and training.
  5. Monitor, review and document decisions.

The practical steps above are Eunomia’s operational guidance. See the source notes below for the scope of the external references.

Since 1 September 2025, large organisations, including overseas organisations with a UK nexus, can be criminally liable if a person associated with them commits a fraud intending to benefit the organisation, or in some cases its clients, and the organisation did not have reasonable procedures to prevent it. The offence of failure to prevent fraud was introduced by the Economic Crime and Corporate Transparency Act 2023 (ECCTA). This article explains what it means for pharmaceutical and biotech companies, based on the Home Office guidance.

Who does it apply to?

The offence applies only to large organisations. ECCTA (section 201) defines a large organisation as one meeting two or three of these criteria, in the financial year before the fraud:

  • more than 250 employees;
  • more than £36 million turnover;
  • more than £18 million in total assets.

The criteria apply to the whole organisation, including subsidiaries, wherever it is headquartered. Smaller companies are not directly in scope, but the guidance notes they may be “associated persons” of a large organisation they provide services to. For biotech companies, that can matter when working with larger partners.

Who is an associated person?

Employees, agents and subsidiaries are associated persons, as is anyone providing services for or on behalf of the organisation. In pharma, that can include contract sales organisations, agencies, consultants and distributors, depending on the circumstances.

Which frauds are covered?

The guidance calls these “base fraud” offences. For England and Wales they include:

  • fraud by false representation, by failing to disclose information and by abuse of position (Fraud Act 2006);
  • participation in a fraudulent business and obtaining services dishonestly;
  • cheating the public revenue;
  • false accounting and false statements by company directors (Theft Act 1968);
  • fraudulent trading (Companies Act 2006).

The organisation can be prosecuted even if the associated person is not, as long as the prosecution can prove the base fraud was committed. On conviction, the organisation can receive a fine.

The defence: reasonable procedures

An organisation has a defence if it can prove it had reasonable fraud prevention procedures in place, or that it was reasonable not to have them. The guidance sets out six principles:

  1. Top level commitment
  2. Risk assessment
  3. Proportionate risk-based prevention procedures
  4. Due diligence
  5. Communication (including training)
  6. Monitoring and review

These closely resemble the six principles in the Ministry of Justice guidance on the Bribery Act 2010, so a mature anti-bribery programme is a useful starting point. The fraud guidance cautions, however, that applying procedures designed for a different type of risk will not necessarily be an adequate response. The guidance describes the fraud risk assessment as dynamic, documented and kept under regular review, and notes that organisations may extend existing risk assessments to cover the fraud risks in scope.

What pharma companies should do

  • Check whether you are in scope at group level, using the previous financial year.
  • Extend the risk assessment. Consider where associated persons could commit a fraud intending to benefit the company, for example in claims made to customers, information provided in applications for funding or reimbursement, invoices and expenses, and financial reporting. These are areas to assess, not findings.
  • Review third parties. Include fraud risk in due diligence and contracts for agencies, consultants, distributors and service providers.
  • Update policies and training so people understand the offence and how to raise concerns.
  • Monitor and review. The guidance expects organisations to learn from investigations and whistleblowing incidents and improve their procedures.
  • Document decisions. The guidance says that any decision not to implement procedures for a specific risk should be documented.

Our risk assessment service can extend an existing ABAC assessment to cover the fraud offence.

This article summarises Home Office guidance on the offence. It is not legal advice; confirm the position for your organisation with qualified advisers.

Sources and scope

External sources accessed 30 September 2026. Check the applicable country rules and current source text for a specific engagement.

Put this into practice