No Result
View All Result
SUBSCRIBE | NO FEES, NO PAYWALLS
MANAGE MY SUBSCRIPTION
NEWSLETTER
Corporate Compliance Insights
  • Home
  • About
    • About CCI
    • CCI Magazine
    • Writing for CCI
    • Career Connection
    • NEW: CCI Press – Book Publishing
    • Advertise With Us
  • Explore Topics
    • See All Articles
    • Compliance
    • Ethics
    • Risk
    • FCPA
    • Governance
    • Fraud
    • Internal Audit
    • HR Compliance
    • Cybersecurity
    • Data Privacy
    • Financial Services
    • Well-Being at Work
    • Leadership and Career
    • Opinion
  • Vendor News
  • Library
    • Download Whitepapers & Reports
    • Download eBooks
    • New: Living Your Best Compliance Life by Mary Shirley
    • New: Ethics and Compliance for Humans by Adam Balfour
    • 2021: Raise Your Game, Not Your Voice by Lentini-Walker & Tschida
    • CCI Press & Compliance Bookshelf
  • Podcasts
    • Great Women in Compliance
    • Unless: The Podcast (Hemma Lomax)
  • Research
  • Webinars
  • Events
  • Subscribe
Jump to a Section
  • At the Office
    • Ethics
    • HR Compliance
    • Leadership & Career
    • Well-Being at Work
  • Compliance & Risk
    • Compliance
    • FCPA
    • Fraud
    • Risk
  • Finserv & Audit
    • Financial Services
    • Internal Audit
  • Governance
    • ESG
    • Getting Governance Right
  • Infosec
    • Cybersecurity
    • Data Privacy
  • Opinion
    • Adam Balfour
    • Jim DeLoach
    • Mary Shirley
    • Yan Tougas
No Result
View All Result
Corporate Compliance Insights
Home Fraud

SFO’s ‘Cast-Iron Guarantee’ on Self-Reporting Comes With Fine Print

Promised predictability in corporate resolutions still leaves room for miscalculation

by Ben Boorer
July 7, 2025
in Fraud
corporate self reporting collage concept revised

The UK Serious Fraud Office has offered its clearest commitment yet to companies considering self-disclosure, but the devil remains in the details. Secretariat’s Ben Boorer dissects the SFO’s new guidance promising deferred prosecution agreement negotiations for qualifying self-reporters, revealing persistent uncertainties around investigation timing, disclosure expectations and undefined “exceptional circumstances” that could undermine the agency’s “cast-iron guarantee.” 

The Economic Crime and Corporate Transparency Act (ECCTA), coming into force in September, is set to reshape the UK’s corporate compliance landscape. A key focus of ECCTA is preventing fraud across various underlying offenses and holding organizations accountable for the actions of both their internal teams and external partners. The pivotal aspect of ECCTA is the “failure to prevent fraud” offense, which requires organizations to implement adequate procedures to prevent and detect fraud, including due diligence on third parties, robust internal controls and regular employee training.

Against this backdrop, in April, the UK Serious Fraud Office (SFO), one of the agencies that led the call for the “failure to prevent fraud” offense, issued new guidance on corporate self-reporting. This guidance states, for the first time, that a company can expect an invitation to negotiate a deferred prosecution agreement (DPA) rather than face criminal prosecution if it self-reports suspected wrongdoing and provides full cooperation to the SFO, in line with the guidance. SFO Director Nick Ephgrave described this as a “cast-iron guarantee,” and it is clear that this commitment from the SFO aims to encourage companies to report wrongdoing proactively, a sentiment that aligns with the broader preventive focus of ECCTA.

Ephgrave predicts that DPAs will return “with a bit of a vengeance” after tailing off in recent years. Introduced in 2014, DPAs were designed to radically alter the UK’s checkered record on tackling wrongdoing by companies. The incentive for businesses to self-report, disclose relevant evidence and accept the case against them (together with other conditions) is that they get to draw a line under the matter, avoid criminal sanctions, contain reputational damage and move on. In return, the SFO considers that the company has been held accountable, the investigation is concluded more efficiently and the Treasury benefits from the fine paid.

While DPAs are well-established in the UK, they have not significantly improved enforcement against corporate misconduct. A major issue is the consistent failure to secure convictions against individuals accused of being the “bad actors” in cases where a company has entered into a DPA. These prosecutions often result in “not guilty” verdicts or trial collapses. 

The SFO’s new guidance aims to tackle this by clarifying the benefits to the company of self-reporting, thereby revitalizing the DPA mechanism.

serious fraud office website
Fraud

The Carrot and the Stick: UK’s SFO Clarifies Self-Reporting Benefits for Corporate Offenders

by Jonathan Armstrong and Vivien Yanni Gan
May 5, 2025

New director promises faster investigations and clearer outcomes for organizations that proactively disclose bribery offenses

Read moreDetails

Key points & uncertainties

The SFO’s new guidance clearly defines the self-reporting process. Once a company has self-reported, the SFO will respond within 48 hours of submission. The SFO then commits to confirming, within six months, whether an investigation will commence, with the DPA agreed upon within a further six months. In principle, the entire process could be completed within a year and two days, offering a more predictable resolution for companies facing a potential SFO investigation, especially considering ECCTA’s broader liability.

A core element of the guidance is the SFO’s guarantee of a DPA offer to companies that self-report and cooperate. This represents a substantial shift in removing ambiguity and reinforces the SFO’s approach to pragmatic outcomes ahead of less certain court-administered justice. One of the prerequisites for access to this more certain approach is that the SFO advises against “forum shopping,” where companies may seek to report through other agencies or jurisdictions. Self-reporting must be made directly, and only, to the SFO, not through another agency.

Despite the clarity on process, some uncertainties remain. One is the extent of an internal investigation expected before self-reporting. The SFO does not require a full investigation, and it notes that failing to self-report within a “reasonable time” (which remains undefined) would be viewed negatively. However, it also recognises that a responsible company may need to investigate to understand the nature and scope of the potential offense. If there is direct evidence of wrongdoing, the expectation is that companies will self-report shortly after discovery. Balancing this timeline will be challenging, especially under ECCTA’s emphasis on prevention.

Another point of ambiguity relates to the disclosure expectations. While the SFO outlines extensive requirements, including potentially privileged material, it also cautions against providing excessive or irrelevant data. Without a complete internal investigation, knowing what to submit may be difficult. A cautious approach of over-disclosure may now be seen as counterproductive and should be evaluated carefully.

Ephgrave’s “cast iron guarantee” is also subject to “exceptional circumstances,” which are not defined. This creates a gray area where companies might overestimate the protection a DPA provides, even in serious cases. The exception could hinder widespread uptake of DPAs.

Finally, the guidance states that companies may still qualify for a DPA even if they do not self-report, provided they offer exemplary cooperation once wrongdoing is uncovered. This could reduce the direct incentive to self-report, encouraging some companies to delay or gamble on not being discovered. It introduces complexity into decision-making at a time when ECCTA creates broader risks for noncompliance.


Tags: Serious Fraud Office (SFO)
Previous Post

A Crossroads for the SFO

Next Post

Regulatory Pullback Amplifies Need for Strategic Risk Controls

Ben Boorer

Ben Boorer

Ben Boorer is a director in the investigations practice at Secretariat, a specialty consulting firm. He leads investigations into fraud, asset misappropriation, financial misreporting, bribery and corruption and asset tracing in criminal and civil environments. These investigations are typically cross-border in nature, originating in developing and emerging markets, and he has worked extensively throughout Europe, Africa, the Middle East and other offshore jurisdictions.

Related Posts

uk serious fraud office logo

A Crossroads for the SFO

by Neil Swift
July 7, 2025

Failure-to-prevent offenses and DPA reforms have armed prosecutors, but securing individual convictions has proven difficult

serious fraud office website

The Carrot and the Stick: UK’s SFO Clarifies Self-Reporting Benefits for Corporate Offenders

by Jonathan Armstrong and Vivien Yanni Gan
May 5, 2025

New director promises faster investigations and clearer outcomes for organizations that proactively disclose bribery offenses

uk parliament building

Your Liability for Fraud: Are You Looking the Right Way?

by Mark Hunting
January 31, 2025

Changes to UK regulation make companies responsible for third parties’ fraudulent conduct

executive meeting room empty seats

UK Corporate Crime Law Puts ‘Senior Managers’ in the Hot Seat

by Ben Boorer
January 23, 2025

As Britain’s landmark economic crime law takes effect later this year, organizations face expanded liability and unclear guidance on compliance

Next Post
chess strategy

Regulatory Pullback Amplifies Need for Strategic Risk Controls

No Result
View All Result

Privacy Policy | AI Policy

Founded in 2010, CCI is the web’s premier global independent news source for compliance, ethics, risk and information security. 

Got a news tip? Get in touch. Want a weekly round-up in your inbox? Sign up for free. No subscription fees, no paywalls. 

Follow Us

Browse Topics:

  • CCI Press
  • Compliance
  • Compliance Podcasts
  • Cybersecurity
  • Data Privacy
  • eBooks Published by CCI
  • Ethics
  • FCPA
  • Featured
  • Financial Services
  • Fraud
  • Governance
  • GRC Vendor News
  • HR Compliance
  • Internal Audit
  • Leadership and Career
  • On Demand Webinars
  • Opinion
  • Research
  • Resource Library
  • Risk
  • Uncategorized
  • Videos
  • Webinars
  • Well-Being
  • Whitepapers

© 2025 Corporate Compliance Insights

Welcome to CCI. This site uses cookies. Please click OK to accept. Privacy Policy
Cookie settingsACCEPT
Manage consent

Privacy Overview

This website uses cookies to improve your experience while you navigate through the website. Out of these, the cookies that are categorized as necessary are stored on your browser as they are essential for the working of basic functionalities of the website. We also use third-party cookies that help us analyze and understand how you use this website. These cookies will be stored in your browser only with your consent. You also have the option to opt-out of these cookies. But opting out of some of these cookies may affect your browsing experience.
Necessary
Always Enabled
Necessary cookies are absolutely essential for the website to function properly. These cookies ensure basic functionalities and security features of the website, anonymously.
CookieDurationDescription
cookielawinfo-checbox-analytics11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Analytics".
cookielawinfo-checbox-functional11 monthsThe cookie is set by GDPR cookie consent to record the user consent for the cookies in the category "Functional".
cookielawinfo-checbox-others11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Other.
cookielawinfo-checkbox-necessary11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookies is used to store the user consent for the cookies in the category "Necessary".
cookielawinfo-checkbox-performance11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Performance".
viewed_cookie_policy11 monthsThe cookie is set by the GDPR Cookie Consent plugin and is used to store whether or not user has consented to the use of cookies. It does not store any personal data.
Functional
Functional cookies help to perform certain functionalities like sharing the content of the website on social media platforms, collect feedbacks, and other third-party features.
Performance
Performance cookies are used to understand and analyze the key performance indexes of the website which helps in delivering a better user experience for the visitors.
Analytics
Analytical cookies are used to understand how visitors interact with the website. These cookies help provide information on metrics the number of visitors, bounce rate, traffic source, etc.
Advertisement
Advertisement cookies are used to provide visitors with relevant ads and marketing campaigns. These cookies track visitors across websites and collect information to provide customized ads.
Others
Other uncategorized cookies are those that are being analyzed and have not been classified into a category as yet.
SAVE & ACCEPT
No Result
View All Result
  • Home
  • About
    • About CCI
    • CCI Magazine
    • Writing for CCI
    • Career Connection
    • NEW: CCI Press – Book Publishing
    • Advertise With Us
  • Explore Topics
    • See All Articles
    • Compliance
    • Ethics
    • Risk
    • FCPA
    • Governance
    • Fraud
    • Internal Audit
    • HR Compliance
    • Cybersecurity
    • Data Privacy
    • Financial Services
    • Well-Being at Work
    • Leadership and Career
    • Opinion
  • Vendor News
  • Library
    • Download Whitepapers & Reports
    • Download eBooks
    • New: Living Your Best Compliance Life by Mary Shirley
    • New: Ethics and Compliance for Humans by Adam Balfour
    • 2021: Raise Your Game, Not Your Voice by Lentini-Walker & Tschida
    • CCI Press & Compliance Bookshelf
  • Podcasts
    • Great Women in Compliance
    • Unless: The Podcast (Hemma Lomax)
  • Research
  • Webinars
  • Events
  • Subscribe

© 2025 Corporate Compliance Insights