The Crime and Policing Act 2026: Corporate Criminal Liability Just Got Personal
Key highlights
The Crime and Policing Act 2026 (CPA), section 250, came into force on 29 June 2026, extending corporate criminal liability to cover all criminal offences committed by senior managers. There is no 'reasonable procedures' defence this time. If a senior manager commits a crime in connection with their role, the company is criminally liable, regardless of what policies were in place. The definition of 'senior manager' is deliberately broad and will capture roles many organisations haven't yet considered. If your business has any connection to the UK and you haven't yet prepared, you are already exposed.
It's a fundamental shift, and if your organisation has any connection to the UK, wherever you're headquartered, you need to understand what it means.
What does the Crime and Policing Act 2026 actually change?
Companies have always been capable of criminal liability, but historically for most offences this required the offence to be committed by someone ‘directing the mind and will of the company’, typically interpreted as directors alone. ECCTA extended that to senior managers and now the CPA goes further still: liability now attaches to anyone who plays a significant role in the management of the company’s activities, or a substantial part of them. The question is no longer whether someone held a board seat, but whether they exercised real authority.
The scope of qualifying offences has expanded just as dramatically. Under ECCTA, corporate criminal liability was limited to a specified list of economic crimes. The CPA significantly widens that remit. Sexual offences, data protection breaches, consumer protection violations, unlawful discrimination: all of these can now trigger corporate liability if committed by a senior manager acting within the actual or apparent scope of their authority.
In practice, that means if a third party reasonably believed a manager had the authority to act on behalf of the company, liability can attach, even if that manager had breached every internal policy you've written.
Who qualifies as a senior manager under the CPA?
The definition is deliberately broad. A senior manager could be someone who plays a significant role in:
- Making decisions about how the whole organisation, or a substantial part of it, is managed or organised (think Heads of HR, Compliance, or Finance)
- Actually managing or organising all or a substantial part of those activities (regional managing directors, senior HR personnel, operational leads)
Many organisations will not yet have mapped this clearly. Reporting lines are often informal. Authority is assumed rather than documented. Job titles don't always reflect actual decision-making power. Under the CPA, that ambiguity becomes criminal risk.
Why reasonable procedures won't save you this time
Under ECCTA, having 'reasonable procedures' in place was a valid defence. Organisations invested in compliance frameworks knowing they could point to them if something went wrong. That is of course still important but the CPA removes that safety net entirely.
This is where the shift in mindset needs to happen. Your compliance documentation alone is no longer enough. What matters is the structure of authority itself: who has it, how it's exercised, and whether anyone is watching. The question is no longer 'do we have a policy?' It's 'do we know exactly who holds enough authority to expose this organisation to criminal liability, and are we watching how they use it?'
Does the CPA affect companies outside the UK?
Yes. This is not a domestic issue. The CPA has broad reach, though section 250 does provide limited defences: where all of the conduct constituting the offence occurred outside the United Kingdom, or where the organisation would not have committed the offence had the conduct been attributable to it directly rather than to the senior manager. However, if you have UK-based staff, UK operations, UK clients, or UK-connected transactions, relying on these defences is unlikely to be straightforward.
A company headquartered in Singapore, the US or the Netherlands can face criminal prosecution in the UK if a senior manager commits a relevant offence with a UK nexus. For multinational organisations, this means your governance review can't stop at the UK subsidiary. You need visibility across the entire structure.
What should organisations do now?
The CPA is now in force, but for organisations that haven't yet prepared, it's not too late to act. Here's where to focus:
- Map your senior managers. Identify which roles qualify under the CPA definition, with particular focus on those with higher criminal risk exposure. Don't rely on job titles alone.
- Audit authority and governance. Review reporting lines, delegation of authority frameworks, and what power each senior manager actually exercises. Where authority is assumed rather than documented, close the gap.
- Conduct enhanced due diligence. Review historical complaints, whistleblowing reports and grievances for all senior managers. Know what risks are already sitting in the system.
- Update policies and procedures. Disciplinary policies, whistleblowing frameworks, codes of conduct: all need to reflect the new liability landscape.
- Build detection systems. Implement or strengthen mechanisms for identifying and reporting suspicious activities before they become criminal exposure.
- Train everyone. This isn't just a board-level issue. All employees need to understand how the new regime works and what it means for them.
This is a governance problem, not just a legal one
The CPA is the most significant expansion of corporate criminal liability in the UK in decades. But treating it as a purely legal risk misses the point. This is a governance problem at its core. Do you know who holds authority in your organisation? How they use it? Whether what's documented actually matches the reality of the situation?
In our governance reviews, a common pattern emerges: organisations that assumed their structures were clear discover gaps the moment they try to map them. Reporting lines that exist on paper but not in practice. Authority that's been delegated informally and never documented. These aren't administrative oversights anymore, under the CPA, they're potential criminal exposure.
The organisations that move now will manage this risk. Those that wait may find themselves responding to an investigation rather than preventing one.
Our team works with organisations globally to review governance structures and build compliance frameworks that hold up under scrutiny. If you need to understand your exposure under the CPA, speak to our legal advisory team.
About the author
Nicole Spurling is a corporate transactional lawyer with more than 12 years’ experience. She specialises in advising companies, entrepreneurs & founders, PE/VC, investors, and management teams on exits, acquisitions, bolt-ons, spinouts, SEED and Series A investment rounds, as well as cross-border corporate restructuring. Having previously been at a UK Top 50 Law Firm she has acted for a number of businesses based in the United Kingdom and Internationally.
Contacts
The contents of this article are intended for informational purposes only. The article should not be relied on as legal or other professional advice. Neither Vistra Group Holding S.A. nor any of its group companies, subsidiaries or affiliates accept responsibility for any loss occasioned by actions taken or refrained from as a result of reading or otherwise consuming this article. For details, read our Legal and Regulatory notice at: https://www.vistra.com/notices. Copyright © 2026 by Vistra Group Holdings SA. All Rights Reserved.