{"id":97801,"date":"2026-08-05T11:13:09","date_gmt":"2026-08-05T11:13:09","guid":{"rendered":"https:\/\/www.europesays.com\/britain\/97801\/"},"modified":"2026-08-05T11:13:09","modified_gmt":"2026-08-05T11:13:09","slug":"section-250-of-the-uk-crime-and-policing-act-2026","status":"publish","type":"post","link":"https:\/\/www.europesays.com\/britain\/97801\/","title":{"rendered":"Section 250 of the UK Crime and Policing Act 2026"},"content":{"rendered":"<p>What it means for company boards and directors\u2019 and officers\u2019 liability insurance.<\/p>\n<p>Executive summary<\/p>\n<p>Section 250 of the Crime and Policing Act 2026 (the CPA) came into force on the 29 June 2026. It materially changes how the law can attribute criminal liability to companies in the UK. Previously, an individual\u2019s crime could only be attributed to a company if that person represented the \u201cdirecting mind and will\u201d of the company, which was often difficult to prove given the size and complexity of modern companies. This was known as the \u201cidentification doctrine.\u201d The CPA changes the law to enable prosecutors to attribute criminal liability to an organisation if any \u201csenior manager\u201d commits any criminal offense while acting within the actual or apparent scope of their authority.<\/p>\n<p>While the Economic Crime and Corporate Transparency Act 2023 (ECCTA) changed the identification doctrine for a list of specific economic crimes, the CPA does so for any and all crimes (that are capable of being punished by a fine). This development is likely to increase the frequency, breadth, and intensity of corporate criminal investigations. This will have consequences for boards of directors and the directors\u2019 and officers\u2019 liability (D&amp;O) insurance programmes designed to protect them.<\/p>\n<p>The problem Section 250 seeks to address<\/p>\n<p>Historically, many corporate prosecutions in the UK ran into a practical obstacle. Prosecutors seeking to hold companies to account for criminal activity often needed to prove a specific mental state in order to prosecute the crime. This required them to attribute that mental state to someone who was the company\u2019s \u201cdirecting mind and will.\u201d In large, complex organisations, it can be difficult to pin this label to a single person (or small group), particularly when decision-making is distributed. In one well-publicised case, the Serious Fraud Office (SFO) failed to attribute criminal liability to a company as not even the CEO and CFO were held to be the \u201cdirecting mind and will.\u201d<\/p>\n<p>The ECCTA solution<\/p>\n<p>The ECCTA was drafted to make it easier for prosecutions to be brought against companies in respect of certain financial crimes listed in the Act. (For more details, see our earlier article: <a href=\"https:\/\/www.marsh.com\/en-gb\/industries\/professional-services\/insights\/identification-doctrine-reforms-d-and-o-impact.html\" rel=\"nofollow noopener\" target=\"_blank\">Impact of Identification Doctrine Reforms on D&amp;O Insurance | Marsh<\/a>.) As a result, the ECCTA allows attribution to a company of the criminal intent of any \u201csenior manager \u2026 acting within the actual or apparent scope of their authority\u201d who plays a \u201csignificant role\u201d in the decision-making, management, or organisation of the activities of the company or partnership.<\/p>\n<p>The CPA\u2019s solution<\/p>\n<p>Section 250 goes further than the ECCTA and expands attribution by providing that a body corporate or partnership can be treated as having committed an offense when a senior manager commits any criminal offense while acting within the actual or apparent scope of their authority. The following points should be kept in mind:<\/p>\n<p>Section 250 is not limited to economic crimes (though it is limited to crimes capable of being punished by a fine alone). For example, modern slavery, environmental, or data protection offences would be within its scope.<br \/>\nThere is no requirement that the criminal offence benefited the company or that the board of directors or senior leaders were aware of the criminal activity.<br \/>\n\u201cSenior manager\u201d is based on function and influence, not title alone.<br \/>\nThere is no \u201creasonable procedures\u201d defence built into Section 250. This is in contrast to the new \u201cfailure to prevent\u201d offence under the ECCTA. Under this, a company has a defence if it can show it had reasonable fraud prevention measures in place. (For more details, see: <a href=\"https:\/\/www.marsh.com\/en-gb\/industries\/professional-services\/insights\/uk-eccta-2023-guidance.html\" rel=\"nofollow noopener\" target=\"_blank\">The UK\u2019s Economic Crime and Corporate Transparency Act 2023: Part 3 | Marsh<\/a>.)<\/p>\n<p>Commentators expect this to raise the stakes for governance and compliance as it lowers the barriers for the SFO or police to bring prosecutions.<\/p>\n<p>Impact on boards<\/p>\n<p>Section 250 is about attribution to the corporate entity, not to the board of directors. However, boards will feel the following effects.<\/p>\n<p>Greater likelihood of investigations, dawn raids, and compelled interviews<\/p>\n<p>If prosecutors can more readily attribute the offense to the organisation based on the conduct of senior management, then the pathway to a corporate case may be more straightforward. Even where individual director culpability is not alleged, executive and non-executive directors can still face:<\/p>\n<p>Requests for documents and communications<br \/>\nInterviews (including under compulsion in some cases)<br \/>\nScrutiny of board minutes, delegation of authority, and reporting lines<\/p>\n<p>Heightened scrutiny of governance and oversight<\/p>\n<p>Even when Section 250 is not framed as an \u201coversight failure,\u201d real-world investigations often examine the following issues:<\/p>\n<p>Whether the board set an appropriate tone, culture, and risk appetite level<br \/>\nWhether reporting and escalation routes worked, including whistleblowing provisions<br \/>\nWhether compliance and internal audit were able to work independently and had sufficient resources<br \/>\nWhether red flags were documented and acted upon<\/p>\n<p>Multi-jurisdictional impact<\/p>\n<p>A UK investigation can trigger information requests or parallel actions in other jurisdictions, increasing defence cost and complexity. Though note that no offence is committed if all the conduct constituting the offence occurs outside the UK.<\/p>\n<p>\u201cFollow-on\u201d exposures: civil claims, regulatory actions, and reputational harm<\/p>\n<p>A corporate criminal investigation (or conviction) can lead to follow-on actions, including:<\/p>\n<p>Regulatory investigations (e.g., from the Information Commissioner\u2019s Office, Health and Safety Executive, or Environment Agency)<br \/>\nEmployment and whistleblower disputes tied to the underlying conduct and the leadership\u2019s response<br \/>\nDirector disqualification proceedings in the event of insolvency<br \/>\nDerivative actions or shareholder litigation alleging breach of directors\u2019 duties<\/p>\n<p>Heightened risk for financial institutions<\/p>\n<p>For financial institutions, the practical impact of Section 250 may be amplified by the sector\u2019s dense regulatory environment and extensive use of delegated authority.<\/p>\n<p>Banks, insurers, asset managers, and other regulated firms already operate under close Financial Conduct Authority (FCA) and Prudential Regulation Authority (PRA) scrutiny, with responsibilities often distributed across business heads, risk, compliance, operations, and front-office management. As a result, the widened attribution test may increase the risk of parallel criminal, regulatory, and supervisory inquiries arising from the same facts. This will particularly be the case in areas such as financial crime controls, sanctions, market conduct, customer treatment, operational resilience, outsourcing, and data governance. This makes clear reporting lines, documented decision-making, and robust oversight of senior managers especially important for regulated firms.<\/p>\n<p>The role of D&amp;O insurance<\/p>\n<p>D&amp;O insurance is designed to protect individual directors and officers in the event of regulatory investigations and claims alleging wrongful acts. Often D&amp;O insurance will also cover companies in the event of securities claims. There may also be some limited entity investigation costs cover.<\/p>\n<p>Section 250 is intended to increase the likelihood that a company will be prosecuted directly for a wider range of criminal offenses. However, defence costs for such entity investigations would not typically fall within a D&amp;O policy\u2019s scope. In addition, criminal fines and penalties are often uninsurable as a matter of public policy. Nor would the individuals whom the policy is designed to protect necessarily want to share their limit of liability with the company.<\/p>\n<p>However, there are other ways in which corporate criminal investigations could trigger D&amp;O cover. Boards should pay close attention to D&amp;O policy features such as:<\/p>\n<p>The scope of Investigation cost cover for insured persons (e.g., legal fees for interviews, witness attendance, and document disclosure notices)<br \/>\nThe definition of an insured person (will just directors and officers be covered, or will senior managers be covered too?)<br \/>\nHow coverage is triggered (e.g., by an investigation, a request for documents, an internal investigation, or only after a written \u201cclaim\u201d is made against an insured person)<br \/>\nWhether cover is available for pre-claim or informal inquiries<\/p>\n<p>Because Section 250 is aimed at attributing corporate liability, an early phase of any investigation may focus on entity conduct. However, individual senior leaders are often interviewed and therefore require legal representation early in the process. D&amp;O policies that respond only once an individual is formally named can therefore leave a costly gap in cover.<\/p>\n<p>When an organisation is under criminal investigation or prosecution, it may face financial or governance constraints that reduce its ability (or willingness) to indemnify individuals. The company might also seek to distance itself from the individual alleged to have committed the criminal act in question. This puts a premium on having adequate Side A (non-indemnified insured person cover) or Side A DIC (difference-in-conditions) limits, depending on the risk profile.<\/p>\n<p>Given the nature of Section 250, insureds should also consider the standard conduct exclusion in D&amp;O policies for fraud, dishonesty, wilful criminal acts, etc. Will it only apply after final adjudication, with costs advanced until then? And will the fraud of one insured person be imputed to others?<\/p>\n<p>D&amp;O underwriters may respond to the broader enforcement environment by focusing more on compliance maturity and board oversight alongside reporting lines and delegation to \u201csenior managers.\u201d They may even focus on how the company identifies who qualifies as a \u201csenior manager\u201d for risk management purposes.<\/p>\n<p>Conclusion<\/p>\n<p>Section 250 of the Crime and Policing Act 2026 is a meaningful shift in UK corporate criminal liability attribution. Even though the legal mechanism targets the entity, boards should expect more enforcement touchpoints and more intensive governance scrutiny. Insurance buyers should check that the D&amp;O programme they choose will respond to investigations at an early stage. They should also consider the adequacy of Side A ringfenced limits, as well as defence cost advancement in the event of alleged criminal activity. They should also look for strong severability provisions if an insured person is found to have behaved fraudulently. Speak to your Marsh contact if you have any questions about your coverage.<\/p>\n","protected":false},"excerpt":{"rendered":"What it means for company boards and directors\u2019 and officers\u2019 liability insurance. Executive summary Section 250 of the&hellip;\n","protected":false},"author":2,"featured_media":41121,"comment_status":"","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":"","_share_on_mastodon":"0"},"categories":[4],"tags":[623,13093,8489,5,6],"class_list":["post-97801","post","type-post","status-publish","format-standard","has-post-thumbnail","category-uk","tag-article","tag-financial-professional-liability","tag-global","tag-uk","tag-united-kingdom"],"share_on_mastodon":{"url":"https:\/\/pubeurope.com\/@UnitedKingdom\/117042610488990800","error":""},"_links":{"self":[{"href":"https:\/\/www.europesays.com\/britain\/wp-json\/wp\/v2\/posts\/97801","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.europesays.com\/britain\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.europesays.com\/britain\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/britain\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/britain\/wp-json\/wp\/v2\/comments?post=97801"}],"version-history":[{"count":0,"href":"https:\/\/www.europesays.com\/britain\/wp-json\/wp\/v2\/posts\/97801\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/britain\/wp-json\/wp\/v2\/media\/41121"}],"wp:attachment":[{"href":"https:\/\/www.europesays.com\/britain\/wp-json\/wp\/v2\/media?parent=97801"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.europesays.com\/britain\/wp-json\/wp\/v2\/categories?post=97801"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.europesays.com\/britain\/wp-json\/wp\/v2\/tags?post=97801"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}