Products / DefenceFile
DefenceFile
ECCTA failure-to-prevent-fraud defence-file layer for large UK organisations. In development
What it does
The Economic Crime and Corporate Transparency Act 2023 introduced a failure-to-prevent-fraud offence that came into force in September 2025. Large UK organisations — those meeting at least two of: £36m+ turnover, £18m+ balance sheet, 250+ employees — can now face criminal liability if an associated person commits a fraud that benefits them, unless they can demonstrate that reasonable fraud-prevention procedures were in place. The defence is available, but it must be evidenced.
DefenceFile is the operating layer that makes building and maintaining that evidence file manageable. It structures the process end to end: scope screening to identify which employees, agents and subsidiaries are associated persons in scope; attestation cycles that collect signed declarations from those persons without requiring them to log in; evidence ingestion for the prevention-procedure documents, training records and policy approvals that underpin the defence; a human review queue for items that require sign-off; statutory deadline tracking so the board is alerted before review windows close; and export packs formatted for audit and regulatory review.
DefenceFile does not provide legal advice and does not replace external counsel. It is the operational infrastructure that sits alongside a legal programme — the file-keeping, the workflow, and the audit trail that demonstrate procedures are not just written but running.
Who it's for
General counsel, compliance and legal operations teams at large UK organisations that are in scope for the ECCTA failure-to-prevent-fraud offence and need a structured, auditable way to operate their prevention procedures — rather than managing the process through email chains and shared drives.
Frequently asked questions
- Does DefenceFile provide legal advice?
- No. DefenceFile is an operational tool, not a legal service. It structures the process of building and maintaining a defence file; the legal programme and risk assessment should be led by qualified counsel.
- How does DefenceFile handle associated-person attestations?
- Attestation requests are sent via email with a zero-login response flow — associated persons can submit their declarations without creating an account. Responses are logged with timestamps and stored in the evidence pack.
- What evidence does DefenceFile store?
- DefenceFile ingests policy documents, training completion records, board minutes, risk assessments, attestation logs and any other materials that form part of the prevention-procedure evidence pack.
- Is DefenceFile suitable for organisations outside the large-organisation threshold?
- The ECCTA offence does not apply to organisations below the threshold, but many choose to build equivalent procedures voluntarily. DefenceFile is designed for the full compliance programme regardless of whether it is legally mandated.
- When will it be available?
- DefenceFile is in development. Register interest at defencefile.co.uk or email [email protected] for early access.
Current status
In development. Built by Theo Chavannes and operated by Chavannes Ltd. Register interest at defencefile.co.uk.