Skip to main content

Article

Section 250 of the UK Crime and Policing Act 2026

What the UK Crime and Policing Act 2026 means for directors and officers.

What it means for company boards and directors’ and officers’ liability insurance.

Executive summary

Section 250 of the Crime and Policing Act 2026 (the CPA) came into force on the 29 June 2026. It materially changes how the law can attribute criminal liability to companies in the UK. Previously, an individual’s crime could only be attributed to a company if that person represented the “directing mind and will” of the company, which was often difficult to prove given the size and complexity of modern companies. This was known as the “identification doctrine.” The CPA changes the law to enable prosecutors to attribute criminal liability to an organisation if any “senior manager” commits any criminal offense while acting within the actual or apparent scope of their authority.

While the Economic Crime and Corporate Transparency Act 2023 (ECCTA) changed the identification doctrine for a list of specific economic crimes, the CPA does so for any and all crimes (that are capable of being punished by a fine). This development is likely to increase the frequency, breadth, and intensity of corporate criminal investigations. This will have consequences for boards of directors and the directors’ and officers’ liability (D&O) insurance programmes designed to protect them.

The problem Section 250 seeks to address

Historically, many corporate prosecutions in the UK ran into a practical obstacle. Prosecutors seeking to hold companies to account for criminal activity often needed to prove a specific mental state in order to prosecute the crime. This required them to attribute that mental state to someone who was the company’s “directing mind and will.” In large, complex organisations, it can be difficult to pin this label to a single person (or small group), particularly when decision-making is distributed. In one well-publicised case, the Serious Fraud Office (SFO) failed to attribute criminal liability to a company as not even the CEO and CFO were held to be the “directing mind and will.”

The ECCTA solution

The ECCTA was drafted to make it easier for prosecutions to be brought against companies in respect of certain financial crimes listed in the Act. (For more details, see our earlier article: Impact of Identification Doctrine Reforms on D&O Insurance | Marsh.) As a result, the ECCTA allows attribution to a company of the criminal intent of any “senior manager … acting within the actual or apparent scope of their authority” who plays a “significant role” in the decision-making, management, or organisation of the activities of the company or partnership.

The CPA’s solution

Section 250 goes further than the ECCTA and expands attribution by providing that a body corporate or partnership can be treated as having committed an offense when a senior manager commits any criminal offense while acting within the actual or apparent scope of their authority. The following points should be kept in mind:

  • Section 250 is not limited to economic crimes (though it is limited to crimes capable of being punished by a fine alone). For example, modern slavery, environmental, or data protection offences would be within its scope.
  • There is no requirement that the criminal offence benefited the company or that the board of directors or senior leaders were aware of the criminal activity.
  • “Senior manager” is based on function and influence, not title alone.
  • There is no “reasonable procedures” defence built into Section 250. This is in contrast to the new “failure to prevent” offence under the ECCTA. Under this, a company has a defence if it can show it had reasonable fraud prevention measures in place. (For more details, see: The UK’s Economic Crime and Corporate Transparency Act 2023: Part 3 | Marsh.)

Commentators expect this to raise the stakes for governance and compliance as it lowers the barriers for the SFO or police to bring prosecutions.

Impact on boards

Section 250 is about attribution to the corporate entity, not to the board of directors. However, boards will feel the following effects.

Greater likelihood of investigations, dawn raids, and compelled interviews

If prosecutors can more readily attribute the offense to the organisation based on the conduct of senior management, then the pathway to a corporate case may be more straightforward. Even where individual director culpability is not alleged, executive and non-executive directors can still face:

  • Requests for documents and communications
  • Interviews (including under compulsion in some cases)
  • Scrutiny of board minutes, delegation of authority, and reporting lines

Heightened scrutiny of governance and oversight

Even when Section 250 is not framed as an “oversight failure,” real-world investigations often examine the following issues:

  • Whether the board set an appropriate tone, culture, and risk appetite level
  • Whether reporting and escalation routes worked, including whistleblowing provisions
  • Whether compliance and internal audit were able to work independently and had sufficient resources
  • Whether red flags were documented and acted upon

Multi-jurisdictional impact

A UK investigation can trigger information requests or parallel actions in other jurisdictions, increasing defence cost and complexity. Though note that no offence is committed if all the conduct constituting the offence occurs outside the UK.

“Follow-on” exposures: civil claims, regulatory actions, and reputational harm

A corporate criminal investigation (or conviction) can lead to follow-on actions, including:

  • Regulatory investigations (e.g., from the Information Commissioner’s Office, Health and Safety Executive, or Environment Agency)
  • Employment and whistleblower disputes tied to the underlying conduct and the leadership’s response
  • Director disqualification proceedings in the event of insolvency
  • Derivative actions or shareholder litigation alleging breach of directors’ duties

Heightened risk for financial institutions

For financial institutions, the practical impact of Section 250 may be amplified by the sector’s dense regulatory environment and extensive use of delegated authority.

Banks, insurers, asset managers, and other regulated firms already operate under close Financial Conduct Authority (FCA) and Prudential Regulation Authority (PRA) scrutiny, with responsibilities often distributed across business heads, risk, compliance, operations, and front-office management. As a result, the widened attribution test may increase the risk of parallel criminal, regulatory, and supervisory inquiries arising from the same facts. This will particularly be the case in areas such as financial crime controls, sanctions, market conduct, customer treatment, operational resilience, outsourcing, and data governance. This makes clear reporting lines, documented decision-making, and robust oversight of senior managers especially important for regulated firms.

The role of D&O insurance

D&O insurance is designed to protect individual directors and officers in the event of regulatory investigations and claims alleging wrongful acts. Often D&O insurance will also cover companies in the event of securities claims. There may also be some limited entity investigation costs cover.

Section 250 is intended to increase the likelihood that a company will be prosecuted directly for a wider range of criminal offenses. However, defence costs for such entity investigations would not typically fall within a D&O policy’s scope. In addition, criminal fines and penalties are often uninsurable as a matter of public policy. Nor would the individuals whom the policy is designed to protect necessarily want to share their limit of liability with the company.

However, there are other ways in which corporate criminal investigations could trigger D&O cover. Boards should pay close attention to D&O policy features such as:

  • The scope of Investigation cost cover for insured persons (e.g., legal fees for interviews, witness attendance, and document disclosure notices)
  • The definition of an insured person (will just directors and officers be covered, or will senior managers be covered too?)
  • How coverage is triggered (e.g., by an investigation, a request for documents, an internal investigation, or only after a written “claim” is made against an insured person)
  • Whether cover is available for pre-claim or informal inquiries

Because Section 250 is aimed at attributing corporate liability, an early phase of any investigation may focus on entity conduct. However, individual senior leaders are often interviewed and therefore require legal representation early in the process. D&O policies that respond only once an individual is formally named can therefore leave a costly gap in cover.

When an organisation is under criminal investigation or prosecution, it may face financial or governance constraints that reduce its ability (or willingness) to indemnify individuals. The company might also seek to distance itself from the individual alleged to have committed the criminal act in question. This puts a premium on having adequate Side A (non-indemnified insured person cover) or Side A DIC (difference-in-conditions) limits, depending on the risk profile.

Given the nature of Section 250, insureds should also consider the standard conduct exclusion in D&O policies for fraud, dishonesty, wilful criminal acts, etc. Will it only apply after final adjudication, with costs advanced until then? And will the fraud of one insured person be imputed to others?

D&O underwriters may respond to the broader enforcement environment by focusing more on compliance maturity and board oversight alongside reporting lines and delegation to “senior managers.” They may even focus on how the company identifies who qualifies as a “senior manager” for risk management purposes.

Conclusion

Section 250 of the Crime and Policing Act 2026 is a meaningful shift in UK corporate criminal liability attribution. Even though the legal mechanism targets the entity, boards should expect more enforcement touchpoints and more intensive governance scrutiny. Insurance buyers should check that the D&O programme they choose will respond to investigations at an early stage. They should also consider the adequacy of Side A ringfenced limits, as well as defence cost advancement in the event of alleged criminal activity. They should also look for strong severability provisions if an insured person is found to have behaved fraudulently. Speak to your Marsh contact if you have any questions about your coverage.

Disclaimer: This article is for general information and risk management discussion and is not legal advice. Organisations should consult their legal advisors regarding any specific facts and circumstances.

Related insights