By Zelda Pitman ,
Head of Thought Leadership - Management Liability
05/08/2026 · 8 minute read
What it means for company boards and directors’ and officers’ liability insurance.
Section 250 of the Crime and Policing Act 2026 (the CPA) came into force on the 29 June 2026. It materially changes how the law can attribute criminal liability to companies in the UK. Previously, an individual’s crime could only be attributed to a company if that person represented the “directing mind and will” of the company, which was often difficult to prove given the size and complexity of modern companies. This was known as the “identification doctrine.” The CPA changes the law to enable prosecutors to attribute criminal liability to an organisation if any “senior manager” commits any criminal offense while acting within the actual or apparent scope of their authority.
While the Economic Crime and Corporate Transparency Act 2023 (ECCTA) changed the identification doctrine for a list of specific economic crimes, the CPA does so for any and all crimes (that are capable of being punished by a fine). This development is likely to increase the frequency, breadth, and intensity of corporate criminal investigations. This will have consequences for boards of directors and the directors’ and officers’ liability (D&O) insurance programmes designed to protect them.
Historically, many corporate prosecutions in the UK ran into a practical obstacle. Prosecutors seeking to hold companies to account for criminal activity often needed to prove a specific mental state in order to prosecute the crime. This required them to attribute that mental state to someone who was the company’s “directing mind and will.” In large, complex organisations, it can be difficult to pin this label to a single person (or small group), particularly when decision-making is distributed. In one well-publicised case, the Serious Fraud Office (SFO) failed to attribute criminal liability to a company as not even the CEO and CFO were held to be the “directing mind and will.”
The ECCTA was drafted to make it easier for prosecutions to be brought against companies in respect of certain financial crimes listed in the Act. (For more details, see our earlier article: Impact of Identification Doctrine Reforms on D&O Insurance | Marsh.) As a result, the ECCTA allows attribution to a company of the criminal intent of any “senior manager … acting within the actual or apparent scope of their authority” who plays a “significant role” in the decision-making, management, or organisation of the activities of the company or partnership.
Section 250 goes further than the ECCTA and expands attribution by providing that a body corporate or partnership can be treated as having committed an offense when a senior manager commits any criminal offense while acting within the actual or apparent scope of their authority. The following points should be kept in mind:
Commentators expect this to raise the stakes for governance and compliance as it lowers the barriers for the SFO or police to bring prosecutions.
Section 250 is about attribution to the corporate entity, not to the board of directors. However, boards will feel the following effects.
If prosecutors can more readily attribute the offense to the organisation based on the conduct of senior management, then the pathway to a corporate case may be more straightforward. Even where individual director culpability is not alleged, executive and non-executive directors can still face:
Even when Section 250 is not framed as an “oversight failure,” real-world investigations often examine the following issues:
A UK investigation can trigger information requests or parallel actions in other jurisdictions, increasing defence cost and complexity. Though note that no offence is committed if all the conduct constituting the offence occurs outside the UK.
A corporate criminal investigation (or conviction) can lead to follow-on actions, including:
For financial institutions, the practical impact of Section 250 may be amplified by the sector’s dense regulatory environment and extensive use of delegated authority.
Banks, insurers, asset managers, and other regulated firms already operate under close Financial Conduct Authority (FCA) and Prudential Regulation Authority (PRA) scrutiny, with responsibilities often distributed across business heads, risk, compliance, operations, and front-office management. As a result, the widened attribution test may increase the risk of parallel criminal, regulatory, and supervisory inquiries arising from the same facts. This will particularly be the case in areas such as financial crime controls, sanctions, market conduct, customer treatment, operational resilience, outsourcing, and data governance. This makes clear reporting lines, documented decision-making, and robust oversight of senior managers especially important for regulated firms.
D&O insurance is designed to protect individual directors and officers in the event of regulatory investigations and claims alleging wrongful acts. Often D&O insurance will also cover companies in the event of securities claims. There may also be some limited entity investigation costs cover.
Section 250 is intended to increase the likelihood that a company will be prosecuted directly for a wider range of criminal offenses. However, defence costs for such entity investigations would not typically fall within a D&O policy’s scope. In addition, criminal fines and penalties are often uninsurable as a matter of public policy. Nor would the individuals whom the policy is designed to protect necessarily want to share their limit of liability with the company.
However, there are other ways in which corporate criminal investigations could trigger D&O cover. Boards should pay close attention to D&O policy features such as:
Because Section 250 is aimed at attributing corporate liability, an early phase of any investigation may focus on entity conduct. However, individual senior leaders are often interviewed and therefore require legal representation early in the process. D&O policies that respond only once an individual is formally named can therefore leave a costly gap in cover.
When an organisation is under criminal investigation or prosecution, it may face financial or governance constraints that reduce its ability (or willingness) to indemnify individuals. The company might also seek to distance itself from the individual alleged to have committed the criminal act in question. This puts a premium on having adequate Side A (non-indemnified insured person cover) or Side A DIC (difference-in-conditions) limits, depending on the risk profile.
Given the nature of Section 250, insureds should also consider the standard conduct exclusion in D&O policies for fraud, dishonesty, wilful criminal acts, etc. Will it only apply after final adjudication, with costs advanced until then? And will the fraud of one insured person be imputed to others?
D&O underwriters may respond to the broader enforcement environment by focusing more on compliance maturity and board oversight alongside reporting lines and delegation to “senior managers.” They may even focus on how the company identifies who qualifies as a “senior manager” for risk management purposes.
Section 250 of the Crime and Policing Act 2026 is a meaningful shift in UK corporate criminal liability attribution. Even though the legal mechanism targets the entity, boards should expect more enforcement touchpoints and more intensive governance scrutiny. Insurance buyers should check that the D&O programme they choose will respond to investigations at an early stage. They should also consider the adequacy of Side A ringfenced limits, as well as defence cost advancement in the event of alleged criminal activity. They should also look for strong severability provisions if an insured person is found to have behaved fraudulently. Speak to your Marsh contact if you have any questions about your coverage.
Disclaimer: This article is for general information and risk management discussion and is not legal advice. Organisations should consult their legal advisors regarding any specific facts and circumstances.