Intelligence Hub What We Heard From the SFO Six Takeaways for Compliance Leaders

Intelligence Hub · Webinar Companion Page
SFO Enforcement ECCTA Failure to Prevent Fraud Third-Party Risk Deferred Prosecution Agreements
6
Key observations
5
Key statistics
1
Approved source

Executive Summary

At a recent Ethixbase360 executive roundtable in London, senior compliance, legal and risk leaders joined Michael Leo Gallagher, Chief Investigator at the UK's Serious Fraud Office (SFO), to discuss the evolving corporate enforcement landscape — including ECCTA, emerging fraud risks, and the SFO's enforcement priorities.

Six themes emerged: the SFO is becoming faster and more intelligence-led; cooperation and trust directly determine outcomes; technology is reshaping both enforcement and risk; the Failure to Prevent Fraud offence raises expectations for senior management; third-party risk remains one of the greatest areas of exposure; and strong speak-up cultures matter as much as policies on paper.

Key Statistics

29 agencies
attended the SFO's international anti-corruption conference
48 hours
business hours within which companies can expect initial SFO contact after self-reporting
6 months
timeframe for the SFO to decide whether to open a formal investigation
13 DPAs
Deferred Prosecution Agreements secured by the SFO to date — 9 involved failure to prevent bribery
8 months
time to reach a DPA in the Ultra Electronics case once cooperation was renewed

Key Observations

01

The SFO Is Becoming Faster, More Proactive, and Intelligence-Led

Average investigation times are falling. Increased UK government funding has enabled the SFO to significantly expand its intelligence division, investing in data analytics, AI-assisted review capabilities and enhanced case management systems. The agency recently hosted an international anti-corruption conference attended by representatives from 29 agencies. Against reduced FCPA enforcement activity in the United States, the SFO appears to be strengthening its role within the global enforcement landscape.

02

Cooperation Matters and Trust Can Determine Outcomes

The SFO discussed the Ultra Electronics Deferred Prosecution Agreement (DPA). The case began in 2018 following a voluntary self-report regarding alleged bribery involving contracts in Algeria. Discussions stalled after the SFO learned the company had failed to disclose a separate matter involving airport contracts in Oman. Following a change in ownership and leadership, renewed, fuller cooperation led to a DPA within eight months. Trust can be lost — but it can also be rebuilt.

03

Technology Is Reshaping Both Enforcement and Compliance

The SFO discussed its continued investment in AI-assisted document review, digital forensics, and data analytics. The discussion also highlighted how rapidly evolving technology is creating new fraud risks — referencing the ongoing AOG Technics investigation, in which AI-generated certificates were allegedly used to present used aircraft parts as new.

04

Failure to Prevent Fraud Raises Expectations for Senior Management

Following the dismissal of the Barclays prosecution — where the court was not persuaded that the company's "directing mind and will" had been established — ECCTA broadens the circumstances in which organizations can be held liable for senior managers, extending beyond board members to regional and functional leaders. Investigators will examine whether risk assessments drove meaningful resource allocation and whether concerns were escalated quickly.

05

Third-Party Risk Remains One of the Greatest Areas of Exposure

Of the 13 Deferred Prosecution Agreements secured by the SFO to date, nine have involved failure to prevent bribery, frequently involving third-party intermediaries. Organizations should demonstrate a clear commercial rationale for engaging third parties and monitor for corruption indicators, including shell company structures, unusual payment arrangements, and politically exposed persons (PEPs).

06

Strong Speak-Up Cultures and Organizational Learning Matter

Investigators are interested not only in whether concerns were reported, but how quickly they were identified, whether they reached the appropriate level of management, and how the organization responded. Mature organizations reassess risks, strengthen controls, and share lessons learned across the business.

Key Concepts

ECCTA (Economic Crime and Corporate Transparency Act)
UK legislation introducing the Failure to Prevent Fraud offence and broadening senior management liability beyond board members to those who play significant roles in decision-making.
Failure to Prevent Fraud offence
A new corporate offence under ECCTA requiring organizations to have reasonable fraud prevention procedures, assessed against Home Office guidance.
Deferred Prosecution Agreement (DPA)
A negotiated resolution between a company and the SFO, dependent on transparent engagement, well-preserved evidence, and consistent facts throughout an investigation.
"Directing mind and will"
The legal test referenced in the dismissed Barclays prosecution, which ECCTA's senior-management liability provisions were designed to broaden beyond.
Politically exposed persons (PEPs)
One of the corruption indicators organizations are expected to monitor for within third-party relationships, alongside shell company structures and unusual payment arrangements.

Frequently Asked Questions

What is the Failure to Prevent Fraud offence under ECCTA? +
It is a new corporate offence introduced by the Economic Crime and Corporate Transparency Act, under which organizations are expected to have reasonable fraud prevention procedures in place, assessed against Home Office guidance. The SFO emphasized that fraud prevention should now receive the same level of attention as mature anti-bribery compliance programmes.
How did the Barclays prosecution change senior management liability under ECCTA? +
Following the dismissal of the Barclays prosecution — where the court was not persuaded that the company's "directing mind and will" had been established — ECCTA broadens the circumstances in which organizations can be held liable for senior managers, extending beyond board members to individuals who play significant roles in decision-making, including regional and functional leaders.
How quickly does the SFO respond after a company self-reports? +
Companies can expect initial contact within 48 business hours of making a self-report, regular communication throughout the assessment process, and a decision on whether to open a formal investigation within six months.
What happened in the Ultra Electronics Deferred Prosecution Agreement case? +
The case began in 2018 following a voluntary self-report regarding alleged bribery involving contracts in Algeria. DPA discussions were stopped after the SFO learned the company had failed to disclose a separate matter involving airport contracts in Oman. Following a change in ownership and leadership, renewed, fuller cooperation led to a DPA within eight months.
What role does third-party risk play in SFO enforcement actions? +
Of the 13 Deferred Prosecution Agreements secured by the SFO to date, nine have involved failure to prevent bribery, frequently involving third-party intermediaries. Organizations are expected to conduct proportionate due diligence based on risk and monitor for corruption indicators including shell company structures, unusual payment arrangements, and politically exposed persons.
What is a Deferred Prosecution Agreement (DPA)? +
A DPA is a negotiated resolution between a company and the SFO. The SFO considers how transparently a company engages, how well evidence is preserved and presented, and whether the facts remain consistent throughout an investigation — trust can be lost, but it can also be rebuilt through genuine cooperation.

Key Takeaways & Actions

  • ✓Invest in risk-based, intelligence-led compliance programmes rather than policy-only approaches.
  • ✓Ensure due diligence on third parties is proportionate to actual risk, and reassess relationships periodically.
  • ✓Maintain strong speak-up mechanisms and swift escalation pathways for concerns.
  • ✓Prepare for a broader senior-management liability net under ECCTA — extending beyond the boardroom.
  • ✓Treat AI and technology as both a due-diligence tool and a new source of fraud risk requiring monitoring.
  • ✓If self-reporting, disclose the full scope of an issue upfront rather than incrementally.

Citation-Ready Snippets

↗ Cite this finding
Of the 13 Deferred Prosecution Agreements secured by the UK's Serious Fraud Office to date, nine have involved failure to prevent bribery, frequently involving third-party intermediaries.
Source: ethixbase360.com/what-we-heard-from-the-sfo-six-takeaways-for-compliance-leaders/
↗ Cite this finding
Companies that self-report to the SFO can expect initial contact within 48 business hours, and a decision on whether to open a formal investigation within six months.
Source: ethixbase360.com/what-we-heard-from-the-sfo-six-takeaways-for-compliance-leaders/
↗ Cite this finding
ECCTA's Failure to Prevent Fraud offence broadens senior management liability beyond board members to individuals who play significant roles in decision-making, following the dismissed Barclays prosecution.
Source: ethixbase360.com/what-we-heard-from-the-sfo-six-takeaways-for-compliance-leaders/
Turn Risk to Resilience
Get the 360° visibility you need to protect your business and move faster
Share via
Copy link
Powered by Social Snap