A UK client asking more questions before paying you is not new suspicion of you personally. As of this year, it is often a large company protecting itself from a criminal charge it did not have to worry about before.
Under the UK’s Economic Crime and Corporate Transparency Act 2023, a new “failure to prevent fraud” offense came into force on 1 September 2025. It makes a large organization criminally liable if an “associated person,” an employee, agent, subsidiary, or service provider acting on its behalf, commits fraud intending to benefit the organization or its clients. Prosecutors do not need to show that company directors or senior managers knew anything about it. The only defense is proving the organization had “reasonable procedures” in place to prevent the fraud. There is no cap on the fine.
What the law does
Before this offense existed, holding a large UK company criminally responsible for fraud usually meant proving that someone at the top, a director or senior manager, knew about it or directed it. That was hard to prove and rarely happened. The new offense removes that requirement. If an associated person commits a specified fraud offense for the organization’s benefit, the organization is on the hook unless it can show it had reasonable fraud prevention procedures in place. The UK Home Office’s own guidance on this offense spells out exactly that liability chain, and confirms the offense applies to large incorporated bodies, subsidiaries, and partnerships.

In May 2026, the Home Office published an updated Fraud Strategy Framework covering 2026 to 2029, signaling a sharp enforcement uplift going into the offense’s first full year in force. The expectation now is that large organizations run whistleblowing channels, fraud-prevention training, and real oversight as standard practice, not as something to bolt on after an incident.
Why this matters if you invoice a large UK client
The offense itself only applies to large organizations, but the ripple effect reaches every supplier, freelancer, and subcontractor who sends them an invoice. A large client now has a direct legal incentive to tighten its own invoice-approval and vendor-verification procedures, because sloppy internal controls that let fraud slip through can expose the client to criminal liability, not just a bad debt.
That is the mechanism worth understanding. It is not that your client suddenly doubts you. It is that the law now makes it their problem, not just yours, if their own verification procedures are weak enough to let a fraudulent invoice or a spoofed bank-detail change through. Expect stricter vendor onboarding, more confirmation calls before a bank-detail change is accepted, and more scrutiny on invoices that look inconsistent or unfamiliar.
Who counts as an “associated person”
The offense casts a wide net over who can trigger it on an organization’s behalf.
That breadth is exactly why large organizations are extending their new caution outward to contractors and suppliers, not just internal staff. A service provider acting for the organization falls inside the same liability chain as an employee does.
What “reasonable procedures” looks like in practice
The Home Office guidance sets out six principles for reasonable fraud prevention procedures: top-level commitment, risk assessment, proportionate prevention procedures, due diligence, communication and training, and monitoring and review. On the invoice-and-payment side, that comes down to a few concrete checks.
| Control area | What the guidance expects | What it looks like on an invoice or payment |
|---|---|---|
| Vendor verification | Due diligence before onboarding a new supplier | Confirming business registration and a consistent invoice history, not just an email address |
| Bank-detail changes | A second verification channel for unexpected changes | A phone call to a known number or a verified portal update, never an email alone |
| Invoice consistency | Documentation that is traceable and predictable | Sequential invoice numbers, matching business details, a stable payable link every time |
| Monitoring and review | Ongoing checks, not a one-time approval | Flagging invoices that break pattern, such as a new account number or a different sender |
None of this is about catching you out. It is the checklist a large client’s finance team now has to run through to stay inside the “reasonable procedures” defense, and a freelancer whose invoicing already looks like the right-hand column sails through it without friction.
Make your own invoicing easy to verify
The suppliers who feel this law the least are the ones whose invoicing was already clean before it existed: the same invoice number format every time, the same business details, a payment link that does not change client to client. There is nothing to double-check because there is nothing inconsistent to flag.
A BillyPaid invoice gives you that consistency automatically: sequential numbering, your business and client details filled in the same way every time, and one payable link that stays stable across every invoice you send. When a client’s new due-diligence checklist runs down your invoice, it should have nothing to catch.