Stay in the know
Receive timely insights and briefings from HSF Kramer, tailored to keep you informed and ahead
It has never been more important for organisations to invest in technology to combat against cyber-crime and fraud. However, are organisations expected to do more to protect their customers against corporate fraud? The UK government has made it clear that its answer to this question is yes. Relevantly, on 1 September 2025, the “failure to prevent fraud” offence came into force in the UK, placing additional obligations on large organisations to prevent fraud in the UK. Failure to comply could result in significant fines. We can expect Australian governments to closely monitor enforcement outcomes and the extent to which organisations improve their fraud prevention procedures in the UK, to determine if an equivalent offence should be introduced in Australia.
Under the current state of the law in Australia, an organisation can be held liable for fraud in the following circumstances:
On 1 September 2025, a new offence of “failure to prevent fraud” was introduced in the UK, under section 199 of the Economic Crime and Corporate Transparency Act 2023 (ECCTA). It is a strict liability offence which applies if an “associate” of an “in scope” organisation commits one of the specified fraud offences for the direct or indirect benefit of the organisation.
A body corporate or limited partnership is “in-scope” if it is a “large organisation”. That is, if the organisation meets two of the following criteria: (i) more than 250 employees; (ii) more than £36 million annual turnover; or (iii) more than £18 million in total assets. An “associate” is defined broadly to include employees, agents, subsidiaries or persons who perform services for, or on behalf of the organisation. The list of relevant fraud offences is extensive and includes:
If the key components of the underlying offence are made out, the onus falls upon the defendant organisation to prove that it had reasonable fraud prevention procedures in place, or that it was unreasonable to expect it to have such procedures. Statutory Guidance provides for examples of good practice, including a commitment by the Board/senior management to preventing fraud, conducting risk assessments, implementing proportionate risk-based prevention measures and undertaking due diligence on associated persons to mitigate fraud risks, communication of fraud prevention policies (including training), and regular monitoring and review.
The maximum penalty for an organisation’s failure to prevent fraud is an unlimited fine.
There is no equivalent offence to the failure to prevent fraud offence in Australia at present. However, there are close similarities between the new offence and the offence of “failure to prevent foreign bribery” under section 70.5A of the Criminal Code Act 1995 (Cth), which was based on the UK equivalent. We expect Australian governments and regulators to monitor the outcomes from the “failure to prevent fraud” offence closely and to consider if an equivalent offence should be introduced here. Notably, ASIC’s enduring priorities include scam disruption, systemic compliance failures by large financial institutions which result in widespread consumer harm.
The new “failure to prevent fraud” offence expands the scope of liability for organisations with a nexus to the UK. The wrongdoing of an employee, agent or contractor will automatically be attributed to an organisation where it was undertaken for the benefit or gain of the organisation (irrespective of whether any such gain or benefit materialised). It will not matter whether the conduct was sufficiently connected to the scope of employment or authority. The strict liability nature of this offence places the burden on organisations to implement (and be able to demonstrate) “reasonable” fraud prevention procedures or explain why such procedures were unreasonable.
Further, the introduction of the failure to prevent fraud offence might encourage plaintiffs to seek to hold organisations liable for the fraud of its employees through vicarious liability claims, or for the fraud of others via accessorial liability claims. Cases arising out of the UK which establish the steps that an organisation ought to take for fraud prevention might also influence the development of the law and policy in Australia. One such case is Barclays Bank plc v Quincecare Ltd [1992] 4 All ER 363 which established the “Quincecare duty”, requiring banks to refrain from executing payment instructions if they have reasonable grounds to suspect fraud by an agent of the customer. Importing such concepts to Australia might result in greater obligations on organisations to have systems in place to detect and act upon suspicious transactions or instructions.
Partner, Sydney
Managing Partner, Melbourne Office, Melbourne
Senior Associate, Melbourne
Solicitor, Sydney
The contents of this publication are for reference purposes only and may not be current as at the date of accessing this publication. They do not constitute legal advice and should not be relied upon as such. Specific legal advice about your specific circumstances should always be sought separately before taking any action based on this publication.
© Herbert Smith Freehills Kramer 2026
Receive timely insights and briefings from HSF Kramer, tailored to keep you informed and ahead