The Crime and Policing Act 2026 marks a significant extension of corporate criminal liability in the UK. From 29 June 2026, a corporate body may be criminally liable where a senior manager commits a criminal offence while acting within the actual or apparent scope of their authority.
For charities, this is important because the regime is not limited to commercial companies: it can apply to charitable companies and charitable incorporated organisations, and the focus is on how authority is exercised in practice rather than job titles alone.
Key change
The Act broadens the position under the Economic Crime and Corporate Transparency Act 2023 (ECCTA 2023). Under that legislation, the statutory attribution model applied mainly to specified economic crimes committed by senior managers. In simple terms, an attribution model is the legal test used to decide when an individual’s conduct and state of mind can be treated as those of the organisation itself.
The 2026 Act extends that approach to all criminal offences, provided the senior manager was acting within the scope of their actual or apparent authority. In practical terms, this lowers the evidential barrier for prosecutors. They no longer need to show that the individual was the organisation’s “directing mind and will”. It may be enough to show that the offence was committed by a senior manager acting within the actual or apparent scope of their authority.
Who might be a senior manager in a charity?
A senior manager is assessed by reference to the substance of their role, not just their job title. In a charity context, this may include anyone who plays a significant role in making decisions about, or actually managing, a substantial part of the charity’s activities. Depending on the structure, this could include the chief executive, executive directors, senior leadership team members, heads of finance, fundraising, safeguarding, operations or services, and programme or regional leads with meaningful operational autonomy.
Why this is relevant to charities
The Act applies to bodies corporate and partnerships. It is therefore relevant to charitable companies and charitable incorporated organisations, regardless of size or turnover. It is less directly relevant to unincorporated charities, but trustees of unincorporated charities should still consider whether any connected corporate vehicles, trading subsidiaries, service companies or partnership arrangements may fall within scope.
Areas of potential charity risk
Charities should not approach the Act as only an economic crime issue. Depending on the nature of the charity’s work, possible areas of exposure may include safeguarding, health and safety, data protection, fundraising practices, employment and immigration compliance, environmental obligations, sanctions, modern slavery, reporting obligations and regulatory compliance more generally.
The risk is likely to be greater where decision-making is decentralised, where senior employees have significant operational autonomy, or where trustees rely heavily on executive teams without clear reporting, escalation and oversight arrangements.
Governance and delegation points for trustees
Trustees should consider where real decision-making authority sits within the charity, including informal or de facto authority. This means reviewing schemes of delegation, committee terms of reference, senior role descriptions and approval thresholds, particularly in areas that carry higher legal or regulatory risk. Clear reporting and escalation routes are also important so that trustees receive appropriate information about serious incidents, suspected offences and wider compliance risks.
Interaction with existing compliance programmes
Many charities will already have reviewed financial controls because of the failure to prevent fraud offence introduced by the ECCTA 2023. Those controls remain important, but the 2026 Act is wider: it is not limited to fraud or economic crime, and there is no general “adequate procedures” defence to attribution under the senior manager test.
Trustees should therefore treat this as a governance and risk-management issue, not simply a matter of having policies on file. Policies should be supported by training, supervision, escalation processes, whistleblowing channels, incident reporting and clear evidence of trustee oversight.
Trustee compliance checklist
- Confirm whether the charity or any connected corporate vehicle is in scope.
- Identify who may be a “senior manager” in practice, based on actual authority rather than job title.
- Review delegations, authority limits and reporting lines to ensure they reflect how decisions are actually made.
- Assess higher-risk areas, including safeguarding, fundraising, finance, data protection, health and safety, employment, sanctions and service delivery.
- Check that staff know when and how to escalate suspected offences, serious incidents or regulatory breaches.
- Refresh core compliance policies and ensure they are supported by training, supervision and incident reporting processes.
- Ensure board papers and minutes evidence active trustee oversight, scrutiny and follow-up.
- Add this issue to the charity’s governance calendar for periodic review.
If you would like to discuss any of the issues raised in this article or require assistance with an investigation, please contact Ed Henderson or Reshma Derasari.