Since June 29, 2026, a firm can be convicted of a criminal offense it did not commit – because one of its senior managers did. That is the effect of section 250 of the Crime and Policing Act 2026 (CPA), which introduced a universal senior manager attribution test. If a senior manager commits any criminal offense under UK law within the scope of their authority, the organization commits that offense too. The regime is already live. Firms that have not yet acted are operating under it without the appropriate protections in place.

Scope of the New Regime

The regime is not limited to economic crime. It spans the full range of UK criminal law – fraud, data protection, financial sanctions, market misconduct and beyond. Unlike the “failure to prevent” offenses under the Bribery Act 2010 or the Economic Crime and Corporate Transparency Act 2023, there is no defense of adequate or reasonable procedures. And for most offenses newly in scope, no deferred prosecution agreement (DPA) pathway exists. This is significant: where DPA-eligible offenses allow for a negotiated resolution, attribution under section 250 leads straight to trial – conviction or acquittal, with no middle ground.

Why Private Credit is Exposed

For private credit managers, the exposure is immediate. The “senior manager” definition is functional – it captures heads of origination, portfolio management, credit, compliance, risk and finance, regardless of board membership. The test also reaches offshore: a Luxembourg or Cayman GP whose senior managers run borrower due diligence from London or approve UK-connected credit decisions can be caught. The only exception is where all relevant conduct occurred outside the United Kingdom and the organization itself would not have committed the offense. Given the hands-on involvement of senior individuals typical of private credit platforms – from deal approval through portfolio monitoring to workout – the risk of criminal attribution is real.

Parallel Regulatory Risk

Criminal prosecution may also run alongside parallel regulatory enforcement – for instance, by the Financial Conduct Authority, the Information Commissioner’s Office or the Competition and Markets Authority. That dual-track exposure creates immediate operational complexity: legal privilege strategies must be coordinated across both proceedings; disclosure to one authority may be compellable by another; and settlement of the regulatory track will rarely resolve the criminal one. Firms need a joined-up response framework from the outset, not two siloed workstreams reacting in real time.

What to Do Now

The exposure is not theoretical. If a head of credit knowingly obtained personal data from a borrower’s systems without that borrower’s consent during a workout last month, the firm itself may already face strict criminal liability under the Data Protection Act 2018 – not through any institutional failing, but by operation of the new attribution rule. The time to act is now. Firms should be conducting risk assessments across the offenses most relevant to their activities, mapping their senior manager population by actual decision-making responsibility across fund structures and putting clear escalation protocols in place for when issues arise.