UK Proposal Targets Platforms for User-Committed Fraud
A new report proposes extending corporate criminal liability to online platforms that fail to prevent fraud committed by their users, a significant expansion of the 'failure to prevent' model.
A report by Jonathan Fisher KC, 'Fraud in the Digital Age,' proposes creating a new corporate criminal offense in the UK for providers of regulated user-to-user services who fail to prevent fraud committed by users on their platforms. The proposal aims to close a perceived gap in the Economic Crime and Corporate Transparency Act 2023 (ECCTA), whose 'failure to prevent fraud' offense applies only to fraud by a company's associates, not by independent third-party users.
If adopted, this would represent a material expansion of corporate criminal liability, making businesses responsible for offenses by people over whom they have no conventional control. The proposal would sit alongside the UK's new Online Safety Act 2023, which already imposes extensive regulatory duties on platforms to address illegal content, including fraud, backed by fines of up to 10% of global revenue. The government has not yet endorsed the proposal but is considering it.
Online service providers should monitor the government's response and assess how the definition of fraud committed 'on' a service and the territorial reach of any new offense could create complex, overlapping compliance obligations with the existing regulatory regime.