How can we help you?

Early lessons from Ultra Electronics

The introduction of the UK’s failure to prevent fraud offence (FTPF) on 1 September 2025 under the Economic Crime and Corporate Transparency Act 2023 marked a significant shift in corporate criminal liability, placing a proactive obligation on organisations to take steps to prevent fraud committed for their benefit. 

As discussed in our earlier insight - The Countdown is on: Failure to Prevent Fraud Offence will come into force on 1 September 2025 the FTPF regime represents a move away from reactive enforcement towards a model focused on systems, controls and corporate culture. Yet, nearly a year on from implementation, the offence remains untested in the courts, with no reported prosecutions or Deferred Prosecution Agreements (DPAs).

In this context, analysis must necessarily be taken from elsewhere. The most instructive approach is to examine how the analogous failure to prevent bribery offence is currently being enforced. The Ultra Electronics DPA, approved on 1 May 2026, provides a timely and valuable case study; offering a practical lens through which the future of the FTPF regime can be understood.

Facts

The Ultra Electronics (Ultra) DPA followed an eight year investigation by the Serious Fraud Office (SFO), initially triggered by the company’s self-reporting of suspected corruption in 2018. 

The case concerned the Ultra's use of intermediaries to pursue public sector contracts in Oman and Algeria, including a contract worth up to £200 million with the Omani Ministry of Transport and Communications. The SFO concluded that Ultra had failed to prevent bribery, contrary to section 7 of the Bribery Act 2010, as a result of compliance framework deficiencies. 

Under the DPA:

  • Ultra agreed to pay a £10 million penalty, together with £4.8 million in investigation costs;
  • It accepted responsibility for failing to prevent bribery;
  • It undertook to report annually to the SFO for three years on the effectiveness of its compliance programme. 

Notably, the relevant conduct predated Ultra’s change in ownership and leadership, yet liability nonetheless attached to the corporate entity.

Beyond bribery: why Ultra matters

Although Ultra is a failure to prevent bribery case rather than a fraud case, its broader significance lies in what it reveals about the operation of the “failure to prevent” model in practice.

The failure to prevent fraud offence was designed to mirror this framework: liability attaches where an associated person commits wrongdoing with the intention of (directly or indirectly) benefitting the organisation, unless the organisation can demonstrate that it had reasonable preventative procedures in place. In both contexts, the emphasis is not on attributing fault to senior management, but on assessing the adequacy of corporate systems and controls.

In the absence of enforcement under the fraud regime itself, Ultra therefore functions as a contemporary proxy, providing insight into how prosecutors are likely to approach the new FTPF offence.

Systems, not individuals

A central feature of the Ultra DPA is the absence of any requirement to establish senior management knowledge or involvement. Liability arose from the company’s failure to prevent misconduct by those acting on its behalf, in circumstances where its procedures were insufficient. 

This reflects a broader shift in enforcement focus. Corporate criminal liability is no longer anchored primarily in the actions of the “directing mind and will”, but in the organisation’s ability to identify and mitigate risk.

As we noted in New corporate fraud prevention obligations: Key considerations this creates a materially different compliance landscape. For the purposes of the FTPF offence, organisations must look beyond traditional internal fraud controls and address the risk of outward-facing misconduct; particularly conduct designed, even indirectly, to benefit the business.

Ultra demonstrates that where those systems are found wanting, liability will follow, regardless of whether wrongdoing can be traced to senior leadership.

The centrality of DPAs

Ultra also reinforces the continued importance of Deferred Prosecution Agreements as the primary mechanism for resolving corporate crime.

Rather than proceeding to trial, the SFO secured:

  • A substantial financial penalty;
  • Formal acceptance of wrongdoing;
  • Ongoing compliance monitoring and reporting obligations. 

This approach reflects a clear preference for outcomes which combine punishment with reform, and which incentivise cooperation.

For the FTPO offence, it is likely that early enforcement will follow a similar pattern. As discussed in Fraud: what lies ahead for 2026, 2026 represents the first full year of enforceability for the offence. In practice, initial cases are more likely to result in DPAs than contested prosecutions, allowing regulators to establish expectations and shape corporate behaviour without the uncertainty of early test litigation.

Cooperation, remediation and outcome

The Ultra case further highlights the significance of corporate cooperation and remediation. The company’s decision to self-report, coupled with its engagement with the SFO and improvements to its compliance framework, were central to the resolution of the case. 

However, cooperation did not eliminate liability. The company remained subject to a substantial penalty and ongoing obligations.

The implication is clear: cooperation may influence the form of enforcement, favouring a DPA over prosecution, but it does not remove exposure altogether. For organisations navigating the new fraud regime, this underscores the importance of:

  • Early identification and escalation of issues;
  • Proactive engagement with regulators;
  • Meaningful and demonstrable remediation.

The enduring risk of historical conduct

One of the most striking aspects of Ultra is its timeline. The underlying conduct dated back several years, yet the case was only resolved in 2026 following a protracted investigation. 

This highlights a critical feature of “failure to prevent” enforcement: it is often retrospective and long-running.

For the FTPF offence, this carries an important warning. While the offence only captures conduct from September 2025 onwards, organisations should not assume that enforcement risk is immediate or short-lived. Instead, exposure may crystallise years after the relevant conduct, particularly in complex cases involving multiple jurisdictions or intermediaries.

A template for future fraud enforcement

Taken together, Ultra provides a clear insight into the likely trajectory of the FTPF regime.

In practical terms, it suggests that future cases will:

  • Focus on systemic weaknesses in governance and controls;
  • Involve extensive investigations and long timeframes;
  • Be resolved primarily through DPAs rather than prosecution;
  • Require ongoing compliance monitoring and reform.

This aligns closely with the broader policy objective underpinning the offence, as explored in our earlier articles: to drive a cultural shift within organisations, embedding fraud prevention as a core operational and strategic priority.

Conclusion

Ultra Electronics DPA provides a contemporary and highly relevant illustration of how the 'failure to prevent' model is applied in practice.

Its significance lies not in its subject matter, but in its method. By focusing on systems rather than individuals, favouring negotiated resolution over litigation, and emphasising remediation alongside punishment, Ultra offers a blueprint for future enforcement.

As the FTPF regime moves from implementation to active use, organisations would be well advised to treat Ultra not as an isolated bribery case, but as an early indication of the standards, expectations and consequences that are likely to define this new era of corporate fraud liability.

Whilst the FTPF offence has been in force for almost a year, it is not too late to ensure your organisation has robust fraud prevention practices in place to reduce the risk of corporate criminal liability. If you would like any advice on your fraud risk management strategy, assistance with a review of fraud policies and procedures or fraud prevention training, please contact Emily Sharples