Nikhil Rathi spoke at the FCA financial crime conference on 14 May 2026, setting the operational tone for the FCA’s 2026/27 work programme priority “Fighting financial crime”. The failure-to-prevent-fraud offence in the Economic Crime and Corporate Transparency Act 2023 has already been in force since 1 September 2025; this is not a 2026 go-live. If you run AML, fraud, sanctions or payments operations in a UK firm, the work now is evidence, information-sharing and reasonable procedures — not another commencement date.
Rathi’s speech is how the FCA wants the system to work this year: earlier information-sharing, more technology in detection, and joint work with the NCA rather than each firm sitting on its own org chart. He pointed to ECCTA information-sharing powers, data fusion with the NCA, and a June start for wider sharing of FCA intelligence data with law enforcement — beginning with over 5,000 records via the Police National Database. Selected banks are piloting action plans against nine shared economic crime priorities published with the NCA.
The 2026/27 work programme lists the same priority in writing: flagship conference; detect and disrupt; online safety; partner engagement; organised crime; more proportionate KYC on smaller transactions; proactive AML assessments for higher-risk firms; sanctions systems and controls; and market abuse. Use the live work programme page. Do not treat a guessed publication day as part of this briefing.
Failure to prevent fraud is already live. The Home Office is clear: the offence came into effect on 1 September 2025. Guidance was last updated on 10 October 2025 to use “subsidiary undertaking” as in the legislation, rather than “subsidiary”. A 2026 financial-crime programme that still talks as if the offence is incoming is behind the statute.
| Business type / activity | What is in play | Immediate operational task | Official reference |
|---|---|---|---|
| UK banks and dual-regulated groups | Work programme priority 4; Rathi information-sharing and NCA action-plan pilots | Named owner for private-to-private sharing; map where you sit on the nine economic crime priorities | Rathi, 14 May 2026; FCA annual work programme 2026/27 |
| Payments firms and directed PSPs | Same FCA financial-crime remit, plus APP reimbursement already in force | Keep reimbursement operations live; do not wait for a 2026 fraud “go-live” | Work programme priority 4; later PSR review news dated 1 July 2026 |
| Cryptoasset firms on the MLRs | Gateway, promotions and financial-crime systems and controls | File quality on the authorisations gateway; financial-crime MI that would survive an early intervention | Rathi (gateway as first line of defence); work programme |
| Large organisations in scope of failure to prevent fraud (FS and non-FS) | ECCTA s.199 offence already in force | Confirm s.201 large-organisation status; evidence reasonable fraud-prevention procedures | Home Office guidance; Home Office news, 1 September 2025 |
| Parent undertakings and groups | s.201 does not itself apply to a parent undertaking; s.202 of the same Act does | Run the group test as well as the solo test; keep the 10 October 2025 “subsidiary undertaking” wording in policies | ECCTA 2023; Home Office guidance (updated 10 October 2025) |
| Legal, accountancy and TCSP perimeter (future AML supervisor change) | Work programme records the Government’s intention to make the FCA the AML supervisor for those sectors | Watch the legislation; do not treat this as a 2026 perimeter switch | Work programme 2026/27, “Anti-money laundering (AML) supervisory reform” |
Operational tip: For the failure-to-prevent-fraud size test, use the statute’s words. Under s.201 a relevant body is a large organisation only if it satisfied two or more of: turnover more than £36 million; balance sheet total more than £18 million; number of employees more than 250, in the financial year preceding the year of the fraud offence. Do not rewrite “balance sheet total” as “total assets”.
| Step | Action | What operational staff must deliver | Official reference |
|---|---|---|---|
| 1 | Confirm the failure-to-prevent-fraud perimeter | s.201 two-of-three test using balance sheet total; group position under s.202 if you are a parent; list of subsidiary undertakings using the 10 October 2025 wording | ECCTA s.201; Home Office guidance, last updated 10 October 2025 |
| 2 | Map associated persons | Employees, agents and other associated persons who could commit a specified fraud intending to benefit the organisation | Home Office guidance; Home Office news, 1 September 2025 |
| 3 | Refresh the fraud risk assessment | Specified fraud offences, dishonest sales, hidden information, market misconduct — against actual business lines, not a generic list | Home Office guidance; Home Office news (examples) |
| 4 | Evidence the six principles | Top-level commitment, risk assessment, proportionate procedures, due diligence, communication including training, monitoring and review — with owners and dates | Home Office statutory guidance; GRT failure-to-prevent-fraud diagnostic |
| 5 | Stand up ECCTA information-sharing | Legal basis, partners, what you will share, what you will not, and an audit trail | Rathi, 14 May 2026 |
| 6 | Align AML, fraud, sanctions and market-abuse MI with priority 4 | One financial-crime dashboard the board can read against the work programme themes, including higher-risk AML assessments and sanctions controls | Work programme 2026/27, “4. Fighting financial crime” |
| 7 | Payments: keep APP reimbursement live | Sending/receiving process, consumer standard of caution, five-business-day clock — already in force. Later: read the PSR 1 July 2026 Frontier review news without “fixing” Q1 versus Q2 | PSR news, 1 July 2026; GRT PSR APP diagnostic |
| 8 | Evidence pack for early intervention | File quality, risk ratings and promotions warnings. Later: Chambers, 17 June 2026, on enforcement that does not always produce a headline | Chambers, 17 June 2026 |
GRT Consulting supports operational teams with:
Start with the free diagnostics if you need a first cut: failure to prevent fraud and PSR APP reimbursement.
Contact us for a focused readiness review: T: +44 20 3695 9251 E: info@grtconsult.com Web: grtconsult.com
Sources