

Knowing what's actually happening inside their organisation is not something most business leaders need encouragement on. Any executive worth their salt has a view of what's going on, built up as the business scales - the journey from scrappy spreadsheet reconciliation to your very own over-complicated CRM integration is a corporate rite of passage.
But there's a new audience for your internal reporting now, and it isn't the board. UK government agencies can inspect both your finances and your internal processes if they suspect fraud - and if you're found wanting, the fine is unlimited.
The changes arrive care of the Economic Crime and Corporate Transparency Act, passed in 2023 and rolled out in stages since. Company registration requirements were tightened first. Identity verification for directors and people with significant control became mandatory in November 2025. And the big one - the failure to prevent fraud offence - has been in force since 1 September 2025. This is no longer preparation territory; it's the operating environment.
The name is self-explanatory; the burden is significant. Companies operating in the UK, regardless of where they're headquartered, can be held criminally liable when someone acting for them - an employee, an agent, a subsidiary - commits fraud intended to benefit the business. Companies House and the Serious Fraud Office have significant new powers to interrogate financial reports and corporate structure, and if fraud is found there is no cap on the resulting fine, even if senior leadership were unaware it was happening. That's the same enforcement spirit the SEC has wielded in the US against companies like Uber and SolarWinds.
Smaller companies are spared the offence itself: it applies to "large" organisations, meeting two of three criteria - turnover over £36m, balance sheet over £18m, more than 250 employees. (Rule of thumb: big enough to need an audit, big enough to be in scope.) But smaller firms shouldn't relax entirely - large customers are pushing the same requirements down their supply chains through due diligence, and the Act's other measures, from identity verification to the ACSP record-keeping regime for accountants, apply regardless of size.
The only defence the Act offers is reasonable fraud-prevention procedures - rigorous, consistently monitored, and demonstrable. Note the third word.
When the SFO comes looking, the question is not whether your controls existed in principle but whether you can produce them: the risk assessment with a date on it, the policy with a distribution record, the approval chain showing who signed off and when, the review that actually happened. Scrupulous documentation of your operational activity and your internal processes is the whole game. An undocumented control, to an investigator, looks identical to no control at all.
That's why the practical starting point is unglamorous: look at where your business's evidence actually lives. If approvals happen in email threads in personal inboxes, if policies live on a shared drive nobody versions, if the record of who agreed what is reconstructed from memory - the defence you're entitled to is one you can't mount.
When documents, communications, approvals and signatures flow through one system with an audit log that can't be edited, the demonstration is a search, not a project. In Workiro's Accountex London 2026 survey (48 UK firms, 904 answers), the recurring theme from practitioners was exactly this gap between work done and work provable - and closing it is cheaper than any conversation with the SFO.
To dig into the requirements and the practical response, watch our free webinar Trading in the UK? You need to comply with the ECCT Act, featuring Workiro's CISO Luke Kiely and Payhawk's Robbie Hadfield. Or see what an evidence-by-default process looks like on your own workflows - book a demo.