The Crime and Policing Act 2026 received Royal Assent on 29 April 2026 and introduces a number of reforms to policing, public protection and criminal justice.
Of particular importance to businesses is the Act's expansion of corporate criminal liability.
The reforms make it easier to attribute criminal conduct to organisations and increase potential exposure across all sectors. As a result, organisations should review their governance and compliance arrangements to ensure appropriate oversight of senior management.
The changes reflect a wider policy shift towards increased corporate accountability and a greater willingness to hold organisations criminally responsible for wrongdoing committed by those in senior positions.
Background
Historically, the prosecution of corporate entities has been constrained and required prosecutors to establish that the offence was committed by an individual who constituted the company's 'directing mind and will'.
In practice, this often created difficulties when prosecuting large and complex organisations, where decision-making is spread across multiple levels of management. As a result, enforcement agencies frequently faced significant hurdles when seeking to attribute criminal conduct to corporate entities.
The new provisions seek to address those challenges by widening the circumstances in which the actions of senior individuals can be attributed to a company or partnership.
Expanded corporate criminal liability – what is changing?
Under section 250 of the Act, which came into force on 29 June 2026, the senior manager attribution model applies to all criminal offences.
Where a senior manager commits a criminal offence while acting within the scope of their actual or apparent authority, the offence may be attributed directly to the company or partnership itself. In effect, the organisation may be treated as having committed the offence and may be prosecuted alongside the individual concerned.
This represents a significant departure from the previous position under the identification doctrine and lowers the threshold for corporate prosecutions, particularly in larger and more complex organisations where decision-making is spread across multiple levels of management.
The implications extend beyond economic crime and may affect organisations across all sectors. Potential exposure may arise in relation to health and safety, environmental, data protection, consumer protection and other regulatory offences.
As a result, conduct that may previously have been addressed primarily through regulatory enforcement could now expose organisations to criminal investigation and prosecution. Businesses may also face an increased risk of criminal conviction, substantial financial penalties and reputational damage arising from proceedings involving both the organisation and the relevant senior manager.
Why does this matter for businesses?
Perhaps the most significant aspect of the reforms is that liability does not depend on the organisation benefiting from the offending conduct.
A company or partnership may face prosecution even where it has suffered loss as a result of a rogue senior manager's actions and may itself be viewed as a victim of the conduct.
The Act also does not provide a general compliance or 'reasonable procedures' defence. As a result, organisations with established policies, controls and compliance programmes may still face criminal liability where the statutory test is met.
Although prosecutors must continue to apply the Full Code Test, including consideration of whether prosecution is in the public interest, the reforms increase the potential exposure of organisations to criminal investigation and enforcement action.
What are the implications for health and safety and regulatory enforcement?
The reforms may be particularly significant for organisations operating in sectors with high regulatory risk, including construction, manufacturing, logistics, transport and healthcare.
While corporate liability for health and safety offences is already well established, the expanded attribution model may increase scrutiny of senior operational decision-makers where their actions or omissions contribute to offending. This is particularly relevant where responsibility for safety, risk management, operational controls or resource allocation sits below board level.
Following serious incidents, decisions relating to staffing, maintenance, training, supervision, budgeting, contractor management and risk assessments may come under further closer examination when enforcement action is being considered.
Organisations may also see increased co-operation between regulators and prosecuting authorities, creating the potential for both regulatory and criminal investigations arising from the same set of facts.
The reforms reinforce the importance of clear governance structures, documented decision-making and effective oversight of senior managers responsible for operational and safety-critical functions.
Who qualifies as a senior manager?
The Act adopts a functional definition of 'senior manager', focusing on the role performed by the individual rather than their formal job title.
The definition is broad and may include individuals who play a significant role in:
- Making decisions about how the whole or a substantial part of the organisation's activities are managed or organised
- Managing or organising the whole or a substantial part of those activities.
As a result, the definition is likely to extend beyond board directors and may capture divisional heads, regional leaders, operational executives and other senior decision-makers.
How does this impact your business?
You should consider whether accountability for key operational and regulatory risks is clearly allocated and documented. You may also wish to review governance arrangements, escalation procedures, incident reporting processes and internal investigation frameworks to ensure that risks are identified and addressed promptly.
Particular attention should be given to senior operational roles whose decisions may have implications for health and safety, environmental compliance, data protection and other areas of regulatory exposure.
Although the Act does not provide a compliance-based defence, robust governance and effective compliance systems remain important. Clear reporting lines, documented oversight, training, supervision, monitoring and internal audit processes are all likely to be relevant when prosecutorial authorities consider whether enforcement action is appropriate. Early investigation of potential issues and appropriate engagement with regulators may also help to demonstrate a proactive approach to risk management.
Conclusion
The Crime and Policing Act 2026 represents a significant expansion of corporate criminal liability.
By lowering the threshold for attributing criminal conduct to companies and partnerships, the reforms make it easier to prosecute organisations where senior managers commit offences within the scope of their actual or apparent authority.
Crucially, organisations may face criminal liability even where they did not benefit from the conduct and may themselves have suffered harm as a result of it.
For businesses, the message is clear. Governance, oversight and compliance are no longer simply matters of good corporate practice, they are increasingly central to managing criminal liability risks.
How we can help …
Our national Safety, Health and Environment Team advises organisations across a diverse range of sectors on compliance with their statutory health and safety, product safety and environmental obligations, and help them to manage their response to major incidents, and to protect their interests, particularly when faced with the threat of investigation or prosecution by the regulatory authorities. We also offer a wide range of training sessions and workshops. Please don't hesitate to contact us to discuss our services further.