Executive Summary
At a recent Ethixbase360 executive roundtable in London, senior compliance, legal and risk leaders joined Michael Leo Gallagher, Chief Investigator at the UK's Serious Fraud Office (SFO), to discuss the evolving corporate enforcement landscape — including ECCTA, emerging fraud risks, and the SFO's enforcement priorities.
Six themes emerged: the SFO is becoming faster and more intelligence-led; cooperation and trust directly determine outcomes; technology is reshaping both enforcement and risk; the Failure to Prevent Fraud offence raises expectations for senior management; third-party risk remains one of the greatest areas of exposure; and strong speak-up cultures matter as much as policies on paper.
Key Statistics
Key Observations
The SFO Is Becoming Faster, More Proactive, and Intelligence-Led
Average investigation times are falling. Increased UK government funding has enabled the SFO to significantly expand its intelligence division, investing in data analytics, AI-assisted review capabilities and enhanced case management systems. The agency recently hosted an international anti-corruption conference attended by representatives from 29 agencies. Against reduced FCPA enforcement activity in the United States, the SFO appears to be strengthening its role within the global enforcement landscape.
Cooperation Matters and Trust Can Determine Outcomes
The SFO discussed the Ultra Electronics Deferred Prosecution Agreement (DPA). The case began in 2018 following a voluntary self-report regarding alleged bribery involving contracts in Algeria. Discussions stalled after the SFO learned the company had failed to disclose a separate matter involving airport contracts in Oman. Following a change in ownership and leadership, renewed, fuller cooperation led to a DPA within eight months. Trust can be lost — but it can also be rebuilt.
Technology Is Reshaping Both Enforcement and Compliance
The SFO discussed its continued investment in AI-assisted document review, digital forensics, and data analytics. The discussion also highlighted how rapidly evolving technology is creating new fraud risks — referencing the ongoing AOG Technics investigation, in which AI-generated certificates were allegedly used to present used aircraft parts as new.
Failure to Prevent Fraud Raises Expectations for Senior Management
Following the dismissal of the Barclays prosecution — where the court was not persuaded that the company's "directing mind and will" had been established — ECCTA broadens the circumstances in which organizations can be held liable for senior managers, extending beyond board members to regional and functional leaders. Investigators will examine whether risk assessments drove meaningful resource allocation and whether concerns were escalated quickly.
Third-Party Risk Remains One of the Greatest Areas of Exposure
Of the 13 Deferred Prosecution Agreements secured by the SFO to date, nine have involved failure to prevent bribery, frequently involving third-party intermediaries. Organizations should demonstrate a clear commercial rationale for engaging third parties and monitor for corruption indicators, including shell company structures, unusual payment arrangements, and politically exposed persons (PEPs).
Strong Speak-Up Cultures and Organizational Learning Matter
Investigators are interested not only in whether concerns were reported, but how quickly they were identified, whether they reached the appropriate level of management, and how the organization responded. Mature organizations reassess risks, strengthen controls, and share lessons learned across the business.
Key Concepts
- ECCTA (Economic Crime and Corporate Transparency Act)
- UK legislation introducing the Failure to Prevent Fraud offence and broadening senior management liability beyond board members to those who play significant roles in decision-making.
- Failure to Prevent Fraud offence
- A new corporate offence under ECCTA requiring organizations to have reasonable fraud prevention procedures, assessed against Home Office guidance.
- Deferred Prosecution Agreement (DPA)
- A negotiated resolution between a company and the SFO, dependent on transparent engagement, well-preserved evidence, and consistent facts throughout an investigation.
- "Directing mind and will"
- The legal test referenced in the dismissed Barclays prosecution, which ECCTA's senior-management liability provisions were designed to broaden beyond.
- Politically exposed persons (PEPs)
- One of the corruption indicators organizations are expected to monitor for within third-party relationships, alongside shell company structures and unusual payment arrangements.
Frequently Asked Questions
Key Takeaways & Actions
- ✓Invest in risk-based, intelligence-led compliance programmes rather than policy-only approaches.
- ✓Ensure due diligence on third parties is proportionate to actual risk, and reassess relationships periodically.
- ✓Maintain strong speak-up mechanisms and swift escalation pathways for concerns.
- ✓Prepare for a broader senior-management liability net under ECCTA — extending beyond the boardroom.
- ✓Treat AI and technology as both a due-diligence tool and a new source of fraud risk requiring monitoring.
- ✓If self-reporting, disclose the full scope of an issue upfront rather than incrementally.