ISA 240 and Failure To Prevent Fraud: What organisations need to do now
The UK’s Failure to Prevent Fraud offence, in force since 1 September 2025, has sharpened the focus on how organisations identify, assess and manage fraud risk. At the same time, auditors’ responsibilities under ISA 240 have continued to evolve, increasing scrutiny. Is your organisation prepared?
Together, the new Failure to Prevent Fraud offence and ISA 240 are changing expectations of boards and senior management, as well as their relationship with auditors. Arguably, fraud risk is no longer a theoretical compliance issue – it is a core governance priority that needs to be factored into all senior management and board agendas.
What is changing in the fraud landscape?
The Failure to Prevent Fraud offence, introduced under the Economic Crime and Corporate Transparency Act 2023, creates corporate criminal liability where a large organisation fails to prevent fraud committed by an associated person for its benefit.
This represents a fundamental shift. Enforcement does not depend on proving that the organisation intended wrongdoing. Instead, the focus is on whether it had reasonable procedures in place to prevent it.
In parallel, ISA 240 requires auditors to obtain reasonable assurance that financial statements are free from material misstatement due to fraud, including identifying and assessing fraud risks and responding appropriately.
For organisations, this creates a convergence: Regulators are asking, did you prevent fraud? Auditors are asking, did you understand and respond to fraud risk properly?
The direction of travel is towards greater transparency, stronger evidence and more robust challenges.
Why this matters now
Fraud is not a narrow financial reporting issue. It is any intentional act involving deception for gain and can be committed by employees, management or third parties across the organisation.
The consequences can be significant:
Criminal liability for the organisation
Financial penalties, potentially linked to the harm caused
Reputational damage and loss of stakeholder confidence
Increased regulatory scrutiny and audit pressure
Exposure to civil litigation and shareholder claims
Crucially, regulators and auditors increasingly view weak fraud controls as evidence of poor governance and culture, not simply an operational gap.
The impact on the auditor relationship involving fraud risk
Auditors are now expected to take a more probing and evidence‑led approach to fraud risk. In practice, this means organisations should expect greater scrutiny of:
Fraud risk assessments
The design and effectiveness of controls
Incident response processes and records
Whistleblowing arrangements
Training and communication across the business
Auditors will not simply accept documented policies at face value; they will expect to see evidence that risk assessments are tailored, current and embedded in decision‑making.
Where this evidence is lacking, audit procedures may be extended and, in more serious cases, opinions may be modified.
What should organisations have in place for ISA 240?
The strongest theme across both ISA 240 and the Failure to Prevent Fraud regime is that everything starts with a credible fraud risk assessment.
A proportionate and effective framework should include:
-
A robust fraud risk assessment
This should reflect the organisation’s actual activities, geographies and relationships – not a mere generic template. It should consider:
Where fraud could occur
Who could commit it
The likelihood and potential impact
-
Proportionate controls and procedures
Controls should be aligned to the risks identified, focusing effort where exposure is highest. This includes both preventative and detective measures.
-
Strong tone from the top
Senior management must demonstrate that fraud, bribery and tax evasion are unacceptable. Culture is, essentially, a control, and not solely a communication exercise.
-
Due diligence and oversight
Organisations must understand who they do business with – including employees, agents and third parties – and manage and monitor these associated risks effectively and consistently.
-
Communication and training
Expectations need to be clearly articulated, with practical training that enables people to identify and respond to risk sufficiently.
-
Monitoring and review
Risk assessments and controls should be reviewed regularly to remain relevant as the business and its risk profile evolve.
These principles align closely with UK government guidance across all failure‑to‑prevent offences, reinforcing the need for consistency rather than siloed compliance approaches.
A practical takeaway
The most important step organisations can take is to develop and maintain a genuinely organisation‑specific fraud risk assessment that is actively owned by the board.
This matters because it underpins everything else:
It determines where controls are needed
It shapes the auditor’s assessment
It provides the foundation for a legal defence
Without it, policies and procedures risk becoming generic, ineffective and difficult to defend under scrutiny.
Looking ahead
The combined effect of ISA 240 and the Failure to Prevent Fraud offence is an increasingly demanding environment for organisations. Expectations are higher, and the margin for error is smaller.
For boards and senior management, the priority is clear and simple: to move beyond compliance and ensure fraud risk management is embedded, evidence‑based and aligned to how the business actually operates.
How we can help
Our forensic services team works with organisations to assess fraud risk exposure, design proportionate prevention frameworks and strengthen controls across complex business environments. We also support investigations, dispute resolution and expert determination where issues arise.
If you would like to discuss how the Failure to Prevent Fraud offence or ISA 240 could affect your organisation, or review the effectiveness of your current approach, please get in touch with our forensic fraud specialists.