The SFO takes a look behind the scenes: What companies need to know about Compliance right now

New British regulations and updated guidelines from the Serious Fraud Office (SFO) are increasing the pressure on companies to ensure their compliance programs are demonstrably effective not only on paper but also in practice.

Crime and Policing Act 2026: Tighter Corporate Liability

At the end of April 2026, the UK’s Crime and Policing Act (CPA) came into effect. It significantly tightens corporate criminal law through a reform of the so-called Senior Manager Test: In the future, companies can be held liable for criminal offenses committed by senior managers within the scope of their actual or apparent authority. In doing so, the legislature is consistently continuing the realignment of corporate liability initiated by the Economic Crime and Corporate Transparency Act 2023 (ECCTA)—with tangible consequences for corporate governance, compliance structures, and the responsibility of executives.

SFO Updates Guidelines on Corporate Compliance

Back in November 2025, the Serious Fraud Office (SFO) had already updated its guidelines for assessing compliance programs. The key message: The mere existence of policies, procedures, and controls is not enough. What matters is whether and how these are actually implemented in day-to-day operations.

The SFO may assess compliance programs in various procedural contexts—such as when deciding whether to pursue criminal prosecution, when considering so-called Deferred Prosecution Agreements (DPAs), or when determining sentencing following a conviction.

Six scenarios in which the SFO assesses compliance

The updated guidelines specify when an assessment of a company’s compliance program may take place:

  1. When deciding whether prosecution is in the public interest
  2. When considering Deferred Prosecution Agreements (DPAs)
  3. When determining whether to impose compliance monitorships as part of DPAs
  4. When asserting “reasonable procedures” to prevent bribery under the UK Bribery Act
  5. When assessing the defense based on “reasonably foreseeable procedures” under the ECCTA 2023
  6. When determining sentencing following a conviction for fraud or bribery

Effectiveness Over Documentation: The New Standard

The updated guidelines make it clear that compliance should not be viewed as a mere documentation exercise. The SFO examines on a case-by-case basis how policies and procedures are implemented in day-to-day operations. Various investigative tools are used in this process—ranging from voluntary or compelled disclosures to witness interviews and interrogations.

Conversely, isolated compliance violations do not automatically mean that a program is ineffective overall. The SFO always assesses the big picture.

Matthew Wagstaff, Director of Legal Services at the SFO, sums it up: “Effective compliance is not a tick-box exercise—it’s about creating genuine cultures that prevent fraud, bribery, and corruption.”

What does this mean for companies with international business relationships?

In its guidelines, the SFO explicitly refers to international frameworks—including the U.S. Department of Justice’s (DOJ) “Evaluation of Corporate Compliance Programs” and the guidelines of the French anti-corruption agency AFA.

Even though there are (as yet) no formal requirements defining what constitutes an “adequate” compliance program, these frameworks are recognized as points of reference.

Companies with an international focus are well advised to regularly subject their compliance management systems to a comprehensive effectiveness review—whether by the internal audit department or by external, specialized consultants who can proactively identify potential gaps.