5 min read

The Crime and Policing Act 2026 and its potential impact on Directors and Officers and D&O insurers

Read more

By Francesca Muscutt, Chris Dyke and Declan Finn

|

Published 28 September 2026

Overview

On 29 June 2026, one of the most significant reforms to UK corporate criminal liability in decades came into force. Whilst it has not attracted the same attention as the Economic Crime and Corporate Transparency Act 2023 (ECCTA), its implications could prove equally far-reaching for companies, directors, and their insurers. 

Section 250 of the Crime and Policing Act 2026 extends the “senior manager” attribution model beyond economic crime to all criminal offences. Now, where a senior manager commits a criminal offence whilst acting within the actual or apparent scope of their authority, the company itself may also be treated as having committed that offence.

The change represents a substantial broadening of the reforms introduced by ECCTA, which applied the senior manager attribution model only to specified economic crimes. The new regime potentially brings offences relating to a wide range of other regulatory and criminal misconduct within scope. 

The expansion of corporate criminal exposure raises important issues for directors and senior managers, and D&O insurance programmes. 

 

A new statutory route to corporate criminal liability 

Historically, prosecutors seeking to attribute criminal wrongdoing to a company often faced significant difficulties under the common law “directing mind and will” doctrine. In large and complex organisations, identifying an individual who both had the necessary knowledge of the criminal conduct and effectively embodied the company could be challenging. Section 250 provides a statutory route which moves away from this restrictive doctrine. Instead, liability can arise where a “senior manager” commits an offence whilst acting within the actual or apparent scope of their authority.

The statutory definition of senior manager is broad. It is anyone who plays a significant role in making decisions about, managing or organising, the whole or a substantial part of a company's activities. This may extend beyond board members and C-suite executives to encompass business unit leaders and other operational decision-makers, depending on the facts.

 

Criminal exposure is expanding beyond economic crime 

Much commentary around corporate criminal liability has focused on fraud, bribery, and money laundering. The significance of section 250 is that it is not confined to these areas. Companies may now face criminal exposure arising from conduct in areas such as: 

  • Environmental and pollution incidents
  • Health and safety failings
  • Sanctions breaches
  • Data protection offences
  • Modern slavery and human trafficking offences
  • Other sector-specific regulatory crimes

Importantly: 

  • The company does not need to have benefited from the criminal conduct
  • The board need not have authorised or even known about the conduct
  • There is no statutory “reasonable procedures” or “adequate procedures” defence to the criminal offence, as there is under ECCTA for economic crimes

Whilst strong governance, compliance, and risk management frameworks may assist in mitigation and may influence prosecutorial decision-making, they will not provide a complete defence to attribution. The result is a materially broader route to corporate criminal liability and, ultimately, prosecution across a much wider range of offences. 

The legislation contains an overseas conduct limitation where all the conduct constituting the offence occurs outside the UK and the company would not itself commit the offence if that conduct were its own. However, the practical application of that carve-out is likely to be tested in future cases, particularly where there is a close nexus between the English company and the overseas entity alleged to have committed the offence.

 

Why directors and senior managers should take notice 

Although section 250 creates a mechanism for prosecuting companies, investigations are unlikely to focus solely on the corporate entity. Criminal and regulatory investigations routinely examine who was responsible for decision-making, who exercised oversight and how concerns were identified, escalated, and managed. Directors and senior managers may find themselves required to explain decisions they made and demonstrate how they discharged their responsibilities. 

Even where no wrongdoing is ultimately established, investigations often generate significant legal costs, management distraction, and reputational damage. 

Moreover, corporate criminal investigations rarely occur in isolation. Depending on the circumstances, they may trigger: 

  • FCA or PRA scrutiny for regulated firms
  • Parallel regulatory investigations (i.e. the ICO, Health & Safety Executive or Environment Agency)
  • Internal investigations
  • Whistleblowing complaints
  • Shareholder claims

Also what begins as a corporate investigation or claim, may escalate into a personal issue for the senior managers and directors implicated. 

 

D&O insurance  

D&O insurance is principally designed to protect individual directors and officers against claims arising from the performance of their duties. Whilst some policies contain limited entity cover in the context of securities claims, D&O insurance is not intended to insure corporate criminal liability itself. Moreover, corporate fines and penalties will generally remain uninsurable as a matter of public policy.

Consequently, for D&O insurers the most significant insurance implications are likely to arise not from the company's (potential or actual) criminal liability but from the defence costs incurred by directors and senior managers caught up in investigations. The effect of the expansion of corporate criminal exposure may be that corporates are incentivised to launch internal investigations with a view to pro-active self-reporting of criminal conduct to regulators in a wider range of circumstances. This may create an exposure for directors and senior managers who may be required to give evidence as part of an internal investigation by a corporate at a stage before an investigation is launched by an investigatory or regulatory body. 

Individuals may require specialist legal representation early and usually long before any allegation is proven. They may need support responding to interviews, information requests, disclosure exercises, and parallel regulatory inquiries. These costs can become substantial, particularly where investigations continue over several years. Where individuals are unable to obtain indemnification from the company, or where indemnification is restricted, a D&O policy may provide a critical source of protection. 

 

Policy wording and limits 

The criminal reforms reinforce the importance of understanding exactly how D&O policies respond to investigations. 

Key questions include: 

  • Is an investigation a covered claim? 
  • Are interview preparation and representation costs covered? 
  • What conduct exclusions (fraud, dishonesty, wilful conduct) may apply? 
  • Will defence costs be advanced pending a final determination of fraud or dishonesty? 
  • Are policy limits sufficient where multiple insured persons require separate legal representation? 

A key feature of criminal corporate investigations is their long duration. Defence costs can accumulate over months and years before the investigating authority reaches any conclusion. Multiple individuals may require separate legal representation, significantly increasing expenditure and eroding insurance limits. Policy wording, investigation coverage, and the adequacy of limits are important considerations. 

 

Looking ahead 

Section 250 of the Crime and Policing Act 2026 marks a significant expansion of UK corporate criminal liability. By applying the senior manager attribution model to all criminal offences, it broadens the circumstances in which companies may face criminal liability (triggering internal investigation and reporting considerations), investigation, and prosecution.

As corporate investigations become easier to pursue and more frequent, scrutiny of directors and senior managers is likely to increase in parallel. This will drive greater demand for defence costs protection, and closer examination of D&O policy wordings and limits. 

The key question for companies and their boards is whether their governance structures, crisis response plans and insurance programmes are prepared for the investigations and personal scrutiny that will follow these reforms. 

Authors