

The Economic Crime and Corporate Transparency Act (ECCTA) changed how companies operating in the UK must approach fraud prevention, internal processes and the accuracy of the public record. When we first covered it, the biggest obligations were on the horizon. They aren't anymore: the failure to prevent fraud offence has been in force since 1 September 2025, identity verification for directors became mandatory in November 2025, and the Act explicitly states that ignorance of your corporate responsibilities is not a defence.
To guide firms through the obligations, Workiro's CISO Luke Kiely sat down with audit and finance expert Robbie Hadfield, Solutions Director at Payhawk - you can watch the full conversation here. Their insights have aged well; here are six, updated for where the law now stands. If you're an accountant, read them twice: once for your clients, and once for your own practice, which the Act's ACSP regime now touches directly.
The failure to prevent fraud offence has a broader scope than most people assume. "When you think of fraud, generally you think about fraud against the company," says Robbie. "And that's not what this is about. It's fraud that benefits the company. I think a lot of the practices that get a bit dodgy here are around bribery, tendering processes and unfair benefits to certain companies or individuals."
Those practices now carry the prospect of unlimited fines for large organisations that can't show reasonable prevention procedures. "Companies: you've got to be more aware of your customers and make sure you're maintaining fair practices," says Robbie. "You've got to engage properly with your suppliers and make sure that you have appropriate due diligence on your supply chain." And due diligence that isn't documented might as well not have happened - the procedures defence lives or dies on the record.
"One of the key points of the Act is to make business leaders more accountable for what happens in an organisation," Luke points out - leadership cannot claim ignorance of fraudulent activity elsewhere in the business, because the law compels them to have processes preventing it. Robbie explains: "The government's trying to push governance and controls in businesses at multiple levels. It used to be very top down, it was on the directors to do everything. The ECCT starts broadening the responsibility of compliance - it's going down the organisation more, and it's looking at the key processes in the organisation."
For accountants advising directors, this is the conversation-starter: the question has moved from "did you follow the rules?" to "can you show the system that makes breaking them hard?"
"It's very easy to say management should be responsible for everything, but at the same time they have to delegate down, and when they delegate down they lose touch of what's going on," explains Robbie. "Most big companies tend to try and mitigate this through internal audit - but internal audits are never going to capture everything." The more robust protection is a culture of transparency and accountability - which, in practice, means processes people actually use, running through systems that record what happened without anyone having to remember to file it.
"A whistleblower programme is no longer a nice to have," says Luke. "Businesses now need some level of a whistleblower or confidential reporting programme in place that's going to allow employees of any level to report wrongdoings that they see inside the organisation." With the offence now live, this has shifted from preparation to gap: a large organisation without a credible reporting route will struggle to argue its prevention procedures were reasonable.
"Multinational organisations are automatically sucked into having to comply with this legislation if they've got any commercial footprint inside the UK," Luke points out - and the liability extends through subsidiaries and, increasingly, the supply chain. "Third-party supply chain, third-party risk management is becoming a significantly large topic of conversation" globally, he notes. Robbie's advice stands: "Having a global mindset straight away, that's what gets you ahead in the regulatory framework as you look at all the markets you operate in."
The letter of the Act is clear: clear, effective, regularly reviewed processes, with visibility of your operations. You need "visibility of where data is flowing, what data is being used, how it's being used, how long it's being retained for," says Luke - and with the offence in force, that technology conversation is no longer one to start; it's one to finish.
Robbie's adoption point is the part most compliance projects miss: "If you can make it easy for people to use whilst also making sure you get the right data flows around the organisation, you can achieve the best of both worlds - rather than the 'oh, here we go, compliance' mentality." A system nobody fights is a system that keeps the record by default - which is exactly what holding documents, emails, approvals and signatures in one place is for.
To see what a compliance-by-default client file looks like in practice - including the seven-year ACSP evidence trail accountants now need to keep - book a demo.
General information for accounting and professional-services firms, not advice – verify anything time-sensitive with the relevant tax authority or your professional body before acting on it.