Insights

ISA 240 and Failure To Prevent Fraud: What organisations need to do now

Gettyimages 2209040571

The UK’s Failure to Prevent Fraud offence, in force since 1 September 2025, has sharpened the focus on how organisations identify, assess and manage fraud risk. At the same time, auditors’ responsibilities under ISA 240 have continued to evolve, increasing scrutiny. Is your organisation prepared?

Together, the new Failure to Prevent Fraud offence and ISA 240 are changing expectations of boards and senior management, as well as their relationship with auditors. Arguably, fraud risk is no longer a theoretical compliance issue – it is a core governance priority that needs to be factored into all senior management and board agendas.

What is changing in the fraud landscape?

The Failure to Prevent Fraud offence, introduced under the Economic Crime and Corporate Transparency Act 2023, creates corporate criminal liability where a large organisation fails to prevent fraud committed by an associated person for its benefit.

This represents a fundamental shift. Enforcement does not depend on proving that the organisation intended wrongdoing. Instead, the focus is on whether it had reasonable procedures in place to prevent it.

In parallel, ISA 240 requires auditors to obtain reasonable assurance that financial statements are free from material misstatement due to fraud, including identifying and assessing fraud risks and responding appropriately.

For organisations, this creates a convergence: Regulators are asking, did you prevent fraud? Auditors are asking, did you understand and respond to fraud risk properly?

The direction of travel is towards greater transparency, stronger evidence and more robust challenges.

Why this matters now

Fraud is not a narrow financial reporting issue. It is any intentional act involving deception for gain and can be committed by employees, management or third parties across the organisation.

The consequences can be significant:

  • Criminal liability for the organisation

  • Financial penalties, potentially linked to the harm caused

  • Reputational damage and loss of stakeholder confidence

  • Increased regulatory scrutiny and audit pressure

  • Exposure to civil litigation and shareholder claims

Crucially, regulators and auditors increasingly view weak fraud controls as evidence of poor governance and culture, not simply an operational gap.

The impact on the auditor relationship involving fraud risk

Auditors are now expected to take a more probing and evidence‑led approach to fraud risk. In practice, this means organisations should expect greater scrutiny of:

  • Fraud risk assessments

  • The design and effectiveness of controls

  • Incident response processes and records

  • Whistleblowing arrangements

  • Training and communication across the business

Auditors will not simply accept documented policies at face value; they will expect to see evidence that risk assessments are tailored, current and embedded in decision‑making.

Where this evidence is lacking, audit procedures may be extended and, in more serious cases, opinions may be modified.

What should organisations have in place for ISA 240?

The strongest theme across both ISA 240 and the Failure to Prevent Fraud regime is that everything starts with a credible fraud risk assessment.

A proportionate and effective framework should include:

  • Document Inspect

    A robust fraud risk assessment

    This should reflect the organisation’s actual activities, geographies and relationships – not a mere generic template. It should consider:

    • Where fraud could occur

    • Who could commit it

    • The likelihood and potential impact

  • Tech Lock

    Proportionate controls and procedures

    Controls should be aligned to the risks identified, focusing effort where exposure is highest. This includes both preventative and detective measures.

  • People Talk

    Strong tone from the top

    Senior management must demonstrate that fraud, bribery and tax evasion are unacceptable. Culture is, essentially, a control, and not solely a communication exercise.

  • Pinpoint

    Due diligence and oversight

    Organisations must understand who they do business with – including employees, agents and third parties – and manage and monitor these associated risks effectively and consistently.

  • Education

    Communication and training

    Expectations need to be clearly articulated, with practical training that enables people to identify and respond to risk sufficiently.

  • Recycle

    Monitoring and review

    Risk assessments and controls should be reviewed regularly to remain relevant as the business and its risk profile evolve.

These principles align closely with UK government guidance across all failure‑to‑prevent offences, reinforcing the need for consistency rather than siloed compliance approaches.

A practical takeaway

The most important step organisations can take is to develop and maintain a genuinely organisation‑specific fraud risk assessment that is actively owned by the board.

This matters because it underpins everything else:

  • It determines where controls are needed

  • It shapes the auditor’s assessment

  • It provides the foundation for a legal defence

Without it, policies and procedures risk becoming generic, ineffective and difficult to defend under scrutiny.

Looking ahead

The combined effect of ISA 240 and the Failure to Prevent Fraud offence is an increasingly demanding environment for organisations. Expectations are higher, and the margin for error is smaller.

For boards and senior management, the priority is clear and simple: to move beyond compliance and ensure fraud risk management is embedded, evidence‑based and aligned to how the business actually operates.

How we can help

Our forensic services team works with organisations to assess fraud risk exposure, design proportionate prevention frameworks and strengthen controls across complex business environments. We also support investigations, dispute resolution and expert determination where issues arise.

If you would like to discuss how the Failure to Prevent Fraud offence or ISA 240 could affect your organisation, or review the effectiveness of your current approach, please get in touch with our forensic fraud specialists.