When can a senior manager’s actions become a company’s liability?
GoodBlog | read time: 8 min
Published: 8 October 2026
For decades, corporate criminal liability for most offences depended on proving that the individual who committed the offence represented the company’s “directing mind and will”.
The Economic Crime and Corporate Transparency Act 2023 (ECCTA) began to change that position by introducing a statutory for specified economic crimes. Section 250 of the Crime and Policing Act, which came into force in June 2026, has now gone further, extending the test to corporate criminal offences more generally.
The change raises a broader question for companies: when can a senior manager’s actions render an organisation criminally liable?
What does the Crime and Policing Act 2026 change?
The traditional “directing mind and will” approach became increasingly difficult to apply in large organisations, where decision-making is spread across different functions and levels of management. The ECCTA began to address this by introducing a senior-manager attribution test for specified economic crimes. The Crime and Policing Act 2026 has now extended this approach to criminal offences more generally.
The practical effect is significant. Where a senior manager commits an offence while acting within the scope of their authority or remit, the organisation can also be liable, provided the other statutory conditions are met. In practice, the question is whether the conduct falls within the responsibilities and authority attached to the individual’s role, rather than whether they were authorised to commit the offence itself.
The provision is broad, covering any criminal offence that an organisation is capable of committing. It does not mean that a company becomes automatically liable whenever a senior employee commits an offence. The consideration is whether the statutory condition is met and the organisation could itself commit the offence in question.
For businesses, the change requires increased focus on where significant decision-making authority sits within the organisation’s hierarchy and how the associated risks are managed. The Home Office expects the reform to strengthen deterrence as well as making corporate prosecution possible in cases where the previous attribution test presented a barrier.
What does the senior manager test mean for companies?
The statutory definition does not map neatly onto an organisation chart. Companies will need to take a more structured approach to identifying who falls within the senior manager definition, understanding the authority attached to their roles and assessing the risks that arise from their decisions.
Who counts as a senior manager?
Establishing who within the organisation could fall within this statutory definition will be critical. This is not simply a question of identifying the board or the people with “senior” in their job title. The test focuses on the role an individual plays in managing or organising the whole or a substantial part of the business.
This could include a divisional or regional head responsible for managing a substantial part of the business, a Chief Financial Officer or Chief Operating Officer, or a senior functional leader with a significant decision-making role. In some businesses, the definition could extend to senior people in functions such as compliance, HR, marketing or sales depending on the role they play in managing or organising the organisation’s activities.
Companies should therefore map senior management responsibilities against the statutory test rather than relying on the organisation chart alone. Look at who has meaningful decision-making authority, what they are authorised to approve and which parts of the business they are responsible for managing or organising.
The exercise should then be overlaid with the organisation’s risk profile. Where a role carries significant authority over areas exposed to criminal risk, those responsibilities should be reflected in the relevant controls, training and oversight.
This assessment should be kept under review. Changes in structure, responsibilities or business activities can alter who falls within the definition and where the greatest exposure sits.
What criminal risks should a company assess?
Once the organisation has identified where significant authority sits, the next step is to consider the criminal risks associated with those areas of responsibility. The extension of the attribution test beyond specified economic crimes means companies should consider whether their existing risk assessments adequately capture the range of criminal risks that could arise from decisions made by senior managers.
The relevant risks will depend on the business. This is likely to include fraud, bribery and anti-money laundering risks, but for some companies environmental or health and safety offences may warrant greater attention.
For others, risks could arise from areas such as product claims, competition or regulatory compliance. Greenwashing is one example where decisions made by senior people about marketing or external communications could potentially create criminal exposure, depending on the offence and the circumstances.
The aim is not to create a list of every criminal offence that could conceivably affect the business. It is to identify where senior managers have significant authority and where the decisions they make could give rise to criminal risk for the organisation.
That assessment should then inform the controls, training and oversight around those areas of responsibility. It should also be reviewed when the business changes, particularly where new products, markets or regulatory requirements alter the organisation’s risk profile.
How should companies review senior management authority and controls?
Once senior managers have been identified, companies should look at the authority that comes with their roles and the controls that govern how that authority is exercised.
This means going beyond formal delegations and approval limits. Consider where senior managers have discretion over decisions that could create criminal risk, who can challenge those decisions, what checks or approvals apply, and how exceptions are handled.
The aim is not to prevent senior managers from making decisions. It is to make sure that risks are understood, that significant decisions are subject to appropriate controls and that there are clear routes for escalation where concerns arise.
This is particularly important where a senior manager has substantial autonomy over a business unit or function. A strong policy framework will provide little protection if commercial pressure, targets or local practices allow controls to be bypassed in practice.
Companies should therefore test whether controls operate as intended. That might involve reviewing decision-making and approval processes, testing how exceptions are dealt with, and checking whether senior managers receive appropriate training and challenge in areas where their decisions carry significant criminal risk.
Understanding where authority sits, and whether the controls around that authority work in practice, can reduce the risk of the underlying criminal conduct occurring in the first place.
How should senior managers be trained?
Senior managers should understand how the decisions they make can create criminal risk for the organisation, particularly where they have significant autonomy over a business unit or function. Training for senior managers should therefore be tailored to their roles and any specific risks.
This should explain the criminal risks, the limits of their authority, the controls and approval processes that apply to their decisions, and when they should seek advice or escalate a concern. It should also make it clear that commercial pressures or local practices do not override those requirements.
Training should be refreshed when responsibilities, business activities or the organisation’s risk profile change, and companies should consider whether senior managers understand and apply the requirements in practice, rather than simply whether they have completed the training.
How can employees challenge senior management?
The new test also makes the effectiveness of speak-up and investigation arrangements more important.
Employees need credible ways to raise concerns about senior people without having to report through the individual involved. The route may differ between organisations, but there should be a clear mechanism for escalating concerns where the normal reporting line is inappropriate.
The same applies when a concern is raised. Organisations should know who can investigate allegations involving senior management, how conflicts will be managed and who is responsible for deciding what happens next.
This is particularly important where the conduct could create corporate criminal liability. An organisation that cannot effectively challenge or investigate senior-level decisions may discover a problem only after the potential offence has already occurred.
Controls reduce risk, but do not remove liability
Strengthening controls around senior management authority does not provide a defence to the section 250 test. Instead, the purpose is twofold – prevention and being able to demonstrate that an organisation has good governance processes in place.
This is an important distinction from failure-to-prevent offences under the Bribery Act 2010 and ECCTA. Those offences expressly provide a defence where an organisation can demonstrate that it had adequate or reasonable procedures in place to prevent the relevant misconduct.
Section 250 has no equivalent defence. Where a senior manager commits an offence within the scope of their actual or apparent authority, the organisation can also be held liable. The existence of policies, training or other controls is not a defence to liability. However, their value lies in reducing the risk that senior management decisions result in criminal conduct in the first place.
The practical focus should therefore be on whether those controls work in practice. This means looking beyond whether policies and procedures exist to whether they mitigate the risk of misconduct by senior management, provide appropriate challenge and escalation, and identify concerns early enough for action to be taken.
For legal and compliance teams, the distinction is important: controls under section 250 are primarily a means of managing and reducing criminal risk, rather than a means of protecting the organisation from liability after an offence has occurred.
How should companies integrate the senior manager test with existing compliance programmes?
For most organisations, much of the necessary infrastructure will already exist. Fraud, bribery, sanctions, health and safety, environmental and other compliance programmes should be reviewed to see whether they adequately address the risks created by senior-manager decision-making.
The senior-manager assessment should also be kept current. Restructuring, acquisitions, new markets, changes in reporting lines and changes in individual responsibilities can all alter where significant authority sits.
The objective is to understand the relationship between people, authority and risk, and then test whether the organisation’s controls operate effectively in that environment.
How can businesses prepare for the senior manager test?
The Crime and Policing Act brings greater focus to the relationship between senior management responsibility, decision-making authority and corporate criminal risk. For businesses, responding effectively means understanding where that responsibility sits and whether the systems around it work to mitigate any risks.
GoodCorporation helps organisations assess and strengthen ethics and compliance programmes by testing how policies, controls and processes operate in practice. This can include reviewing senior management responsibilities, senior manager risk mapping, assessing criminal and regulatory risks, examining decision-making and escalation arrangements, and testing whether controls provide effective challenge where it matters.
The objective is not to build a separate compliance exercise around section 250. It is to use the change as an opportunity to test whether the organisation’s existing approach is capable of managing the risks that come with senior decision-making. Existing frameworks can provide a useful starting point. For example, GoodCorporation’s Fraud Prevention Framework sets out practical principles covering risk assessment, senior management commitment, training, compliance and monitoring and speak-up arrangements.
For legal, compliance and ethics teams, that provides a practical starting point: understand where significant authority sits, identify the risks attached to it and test whether the organisation’s controls are strong enough in practice. GoodCorporation can help you assess these areas and identify where your existing compliance framework may need to be strengthened. Get in touch to discuss your approach.
work with us