This update provides a summary of enforcement action, new legislation and consultations and how these may impact you or your business.

Now in force: Corporate criminal liability has changed. The “senior manager” rules under the Crime and Policing Act 2026 came into force on 29 June 2026. Now, organisations can be held criminally responsible for an offence committed by a senior manager acting within their actual or apparent authority, not just for economic crimes under the ECCTA 2023. Unlike the failure to prevent fraud offence, there is no “reasonable procedures” defence. If the conditions for attribution are met, the fact that an organisation had compliance policies and procedures in place does not, of itself, provide a defence. The SFO’s November 2025 guidance on corporate compliance makes clear that written policies alone won’t satisfy the reasonable procedures defence. 

What this means for you: This is no longer just an economic crime issue. Organisations should identify now who may fall within the statutory definition of a “senior manager” and consider the criminal risks arising from the areas they actually manage or make significant decisions about. 

Coming into force: Harassment is becoming increasingly relevant to corporate criminal risk. From 30 October 2026, the employment duty will be stricter. Employers must take all reasonable steps to prevent sexual harassment and will also have a duty to prevent harassment of employees by third parties, such as clients, customers or contractors. As outlined above, the Crime and Policing Act now allows offences committed by a senior manager to be attributed to the organisation where that person was acting within the actual or apparent scope of their authority. How that test will apply in cases involving personal misconduct is likely to be highly fact-sensitive. 

What you should do: ensure harassment allegations involving anyone who could meet the “senior manager” test are escalated into your criminal risk and compliance reporting lines, not handled solely as a personnel matter and that board-level oversight of these incidents is documented. 

Also on the horizon: The end of CQC’s Single Assessment Framework. As flagged in a previous edition, CQC’s move away from a single framework is now underway. Following the “Better regulation, better care” consultation, CQC is transitioning to sector-specific frameworks. The proposed changes include moving back towards a more detailed question-based assessment structure and moving away from the current scoring-led approach to ratings. Frameworks are being finalised, with implementation expected later this year. 

What this means for providers: The five key questions are staying therefore providers should continue to maintain clear, current and auditable evidence demonstrating the quality and safety of service.

Enforcement spotlight: The cost of environmental and public health failures is significant. On 2 June 2026, South West Water was fined ยฃ1.853 million after a Drinking Water Inspectorate prosecution over the 2024 Brixham cryptosporidium outbreak, which resulted in up to 39,000 consumers being subject to a boil-water notice. This case comes a backdrop of increasing environmental enforcement. The Environment Agencyโ€™s biggest ever criminal operation, covering more than 2,000 sewage treatment works remains ongoing.

Related proceedings also demonstrate that regulatory risk does not necessarily end with the underlying environmental breach. Last month, the Environment Agency commenced criminal proceedings against Southern Water and a number of former employees, including its former CEO involving allegations of manipulation of the testing regime.

There is an increasing focus on individual accountability. The Water (Special Measures) Act 2025 was introduced against a background of regulators reporting difficulties obtaining evidence where investigations had been obstructed. Under the act, water company executives can face up to two years’ imprisonment for offences involving the obstruction of regulatory investigations. 

What you should know: The wider lesson extends beyond the water sector. Poor handling of an investigation can create additional exposure for both organisations and individuals.

If any of the above raises a question about your organisation’s governance responsibilities or enforcement exposure, I would be happy to help, please contact: Harold and McCormack Law.

Shared for general information purposes only and does not constitute legal advice. It is recommended that specific professional advice is sought before acting on any of the information given. Please contact us for specific advice on your circumstances.

Cyber Essentials certification is a UK government backed security standard that demonstrates an organisation has implemented the key technical controls needed to protect against the most common cyber threats.

This field is for validation purposes and should be left unchanged.
Name(Required)