Corporate Criminal Offence (CCO): HMRC Increasing Enforcement Activity

HMRC is taking a more active approach to enforcement using the UK corporate criminal offences for failure to prevent the facilitation of tax evasion

The UK corporate criminal offences for failure to prevent the facilitation of tax evasion were introduced in Part 3 of the Criminal Finances Act 2017. They make organisations criminally liable where an associated person criminally facilitates tax evasion, subject to a “reasonable procedures” defence.

Many organisations will have engaged with CCO compliance as a theoretical risk, treating it as another regulatory layer addressed once and then largely set aside.

HMRC is now taking a more active approach. It has made clear that it views the legislation as a means of driving behavioural change in sectors it considers to be at higher risk of economic crime, rather than simply a tool for isolated prosecutions.

The most recent published figures indicate that HMRC is progressing at least one prosecution, alongside a number of live investigations and cases under review. These span multiple sectors, including waste management.


Key points

  • HMRC is using the CCO legislation in practice, including pursuing investigations and at least one prosecution.
  • The legislation is intended to influence behaviour in sectors where facilitation risk is considered material.
  • Exposure commonly arises through third parties acting on behalf of the business, rather than direct conduct.
  • A policy alone is not sufficient: the defence depends on whether procedures are effective in practice.
  • CCO compliance must be kept under review and updated to reflect changes in business activities, industry risks and identified issues.
CCO compliance in the waste sector

HMRC has also signalled that it intends to use the legislation more actively in the waste sector. In parallel, HMRC and environmental regulators have increased their focus on landfill tax compliance and waste‑related risks, including targeted campaigns aimed at businesses whose activities form part of the waste supply chain.

For businesses operating in exposed sectors — particularly those that rely on third‑party supply chains, subcontracting, agents or complex operational flows — CCO compliance should not be approached as a box‑ticking exercise. A desktop review followed by placing a template policy on file is unlikely to be sufficient. A policy, however well drafted, will not provide a defence if it is not reflected in how the organisation operates in practice. The question is whether the business has properly identified its risks and implemented proportionate measures to address them.

What this means in practice

In practice, the principal exposure is not the absence of a policy, but that procedures have not kept pace with the way the business operates. In sectors such as waste and landfill, where activities depend on multiple parties and where classification, documentation and operational practices are central, that gap can arise readily.

CCO compliance needs to be grounded in a current and realistic understanding of the business. That includes where decisions are taken in practice, how third parties are engaged and supervised, and where commercial pressures may create risk. Procedures need to reflect those realities and to operate day‑to‑day, not just in principle.

It is also important that compliance is treated as ongoing. Changes in business structure, the introduction of new activities, or the use of new counterparties can alter the risk profile materially. Procedures that were appropriate at one point may no longer be sufficient. Regular review is therefore necessary to ensure that the framework remains aligned with the organisation’s actual operations.

In addition, issues identified through internal review, audit work or operational experience should feed back into the control framework. Incidents and near‑misses are often the clearest indicators of where procedures are not operating as intended. An organisation that can demonstrate that it has identified and addressed such issues will be in a stronger position than one relying on static documentation.

Against that background, CCO compliance is more properly viewed as part of core governance rather than a one‑off exercise. The focus is less on whether a policy exists and more on whether the organisation can demonstrate that it has considered its exposure and implemented controls that remain appropriate as the business evolves.

Number of live Corporate Criminal Offences investigations - GOV.UK

Corporate offences for failing to prevent criminal facilitation of tax evasion - GOV.UK