Crisis Management and Investigations Circular (Q3 2026)

Clear-cut insights and horizon-scanning for businesses and their advisors

Crisis Management and Investigations Circular (Q3 2026)

We regularly organise sessions to help clients “war game” how they would respond to a crisis and handle any subsequent investigation.  If you are interested in attending one of our mock investigation sessions, or if you would be interested in a session tailored specifically for your organisation, please let us know by registering your interest.

register your interest

Overview

Welcome to the third edition of Travers Smith's Crisis Management and Investigations Circular, providing a bite-size round-up of recent developments in the world of crisis management and investigations.

In this edition, we will cover:

  1. the key recommendations arising from the second report of Jonathan Fisher KC's Independent Review of Disclosure and Fraud Offences;

  2. the SFO's Annual Report for 2025-26, and reflections following the conclusion of the long-running ENRC litigation;

  3. the FCA's second "Enforcement Watch", and our observations following the decision by the Upper Tribunal to uphold Crispin Odey's ban from the financial services industry; and

  4. recent employment law developments, including reflections on the Fair Work Agency's (FWA) first Delivery Plan, and a brief reminder of the new rules surrounding third party harassment, which come into force on 30 October 2026.

The quarter in the round

Fraud in the Digital Age: the Fisher Review, and the failure to prevent fraud offence one year on

The failure to prevent fraud offence under section 199 of ECCTA reached its one-year anniversary on 1 September. There has still been no reported prosecution. At the same time, the most substantial review of the UK's fraud response in a generation has concluded that the new offence does not go far enough.

On 14 July, the Home Office published Fraud in the Digital Age, the second report of Jonathan Fisher KC's Independent Review of Disclosure and Fraud Offences. The report makes 47 recommendations, three of which are of particular significance for corporates:

  • A "platform" offence (Recommendation 2): the report recommends the creation of a new corporate criminal offence for providers of regulated "user-to-user services" under the Online Safety Act 2023 who fail to prevent fraud on their platforms. The new offence would be expressly modelled on section 199. Fisher argues that a new offence is needed because section 199 bites only where an "associated person" commits fraud for the organisation's benefit. It therefore does not extend to fraud committed by platform users, even where the platform monetises the resulting traffic (for example, through advertising revenue). As with section 199, the new duty would be to implement reasonable prevention procedures rather than imposing strict liability.

  • An anti-fraud levy (Recommendation 3): the levy would be imposed on digital and communications infrastructure providers (including social media platforms), and be administered by Ofcom, in an attempt to rebalance a system in which banks currently carry the cost of reimbursing victims of fraud.

  • Whistleblower incentivisation (Recommendations 15 to 18): the report endorses legislative provision for the SFO to reward whistleblowers, supported by new offences for harassing or intimidating whistleblowers. We suggested in the first edition of the Circular that this policy would survive Nick Ephgrave's departure from the agency, and this is the clearest indication yet that it will.

The Review also proposes expanded SFO information-sharing and extraterritorial notice powers, maximum sentences of 20 years' imprisonment for the most serious fraud and money laundering offences (up from the current statutory maximum of 10-14 years of imprisonment for these offences), and the extension of DPAs to individuals (which are currently reserved for corporates).

Spotlight on the SFO

The SFO's recently published Annual Report paints the picture of an agency that has built "strong momentum" and "delivered operational results" following a year of increased enforcement activity. However, that message is at risk of being overshadowed by the final chapter in the long-running ENRC litigation, which has placed the agency under significant scrutiny over allegations of impropriety in the conduct of its investigation.

The SFO's Annual Report for 2025-26

The SFO published its Annual Report and Accounts for 2025-26 on 16 July, covering the year to 31 March 2026 (the second year of its five-year strategy).

The Annual Report suggests that the agency is operating at greater intensity than in recent years. The SFO reports an active caseload of around 120 cases, including approximately 40 criminal cases (up from 35 in the previous period). It has announced five new cases and closed one, charged ten suspects, conducted seven searches across 24 premises and arrested 14 individuals.

Two themes are worth drawing out for businesses:

  • Disclosure: we reported in the first edition of the Circular on the e-discovery failures that have dogged the agency in recent years. The Annual Report confirms that the SFO's review of 66 historic convictions run on its legacy Autonomy platform was completed in March 2026, and states that no material was found casting doubt on the safety of any past conviction. A separate issue identified in November 2025, affecting approximately 20 cases, remains under review.

  • Technology: the Annual Report confirms the establishment of an AI Steering Group and continued use of Technology Assisted Review, and notes that the SFO's first case management system is due to be rolled out during 2026-27. Consistent with the ambitions in the Business Plan we covered in the last edition of the Circular, the direction of travel is clear, even if the detail is thin: the Annual Report says little about which tools are in use, for what purposes, or what safeguards apply. However, businesses under investigation should potentially expect faster and more efficient investigative processes.

ENRC-SFO settlement

On 2 September, the SFO announced that proceedings between Eurasian Natural Resources Corporation Limited (ENRC), the Director of the SFO, Dechert LLP and its former partner, David Neil Gerrard, had concluded following a confidential out-of-court settlement.

The background to the case is well known amongst lawyers. In summary, the SFO investigated ENRC between 2013 and 2023 over suspected bribery and corruption connected to mining assets in the Democratic Republic of Congo and elsewhere. The SFO closed its investigation without charges for want of sufficient admissible evidence. ENRC brought a civil claim against its former lawyers in 2017 and against the SFO in 2019. The court found the SFO was in breach of its duties, including by engaging with and taking unauthorised information between 2011 and 2013. The court also found that, but for this conduct, the investigation would not have opened.

ENRC sought damages of approximately $168m, comprising some $76m in costs attributed to the investigation and around $90m in increased borrowing costs. A damages hearing took place earlier this year and a settlement was reached before judgment was handed down.

Following the settlement, the SFO's Director of Legal Services, Matthew Wagstaff, said that the agency is confident the conduct in question could not be repeated today, and that it has "overhauled how we operate with stronger governance, independent oversight and clearer safeguards".

Given that the litigation absorbed six years of the SFO's resources and management time, and resulted in it very likely having to pay a significant sum to ENRC[1], it is possible that this case could have a chilling effect on the agency's willingness to pursue future investigations, at least without concrete and reliable evidence. 

The FCA in focus

Enforcement Watch 2

The FCA published the second edition of its Enforcement Watch on 7 July. Where the first Enforcement Watch (reported in the first edition of the Circular) gave a broad overview of the FCA's enforcement operations, the second focuses on a single theme – the supervision and enforcement of the "Consumer Duty". The Consumer Duty sets the standard of care that regulated firms should provide to retail consumers.

The publication confirms that the number of live investigations by the FCA into potential Consumer Duty breaches has risen to 11 (from the six reported in the first edition). These span a range of industries, including insurance, pensions, wealth management, consumer investments, peer-to-peer lending and claims management.

The most striking feature of the latest Enforcement Watch is the distinction the FCA draws between its "assertive supervision" and its enforcement action. The regulator will exercise its "assertive supervision" when it has concerns regarding a firm's compliance with the Consumer Duty. Its "assertive options" range from a conversation with the offending firm, to the imposition of requirements on that firm. Where these interventions are sufficient to address the harm, there may be no need for a formal enforcement investigation by the FCA.

However, the regulator explains that where potentially serious misconduct may already have occurred, enforcement action may follow even after the immediate risk has been remedied. The practical message for regulated firms is clear: remediation does not draw a line under the underlying misconduct. Nevertheless, the number of live investigations (11) being pursued by the FCA is still very low, when compared to the number of supervisory interventions (382) made by the regulator during the last financial year. This is consistent with the FCA shifting away from active enforcement to a more targeted form of regulatory supervision.

Crispin Odey FCA ban upheld by the Upper Tribunal

Crispin Odey's ban from the financial services industry has been upheld by the Upper Tribunal, which has found he lacked integrity. Readers will recall that Mr Odey was fined £1.83m by the FCA and banned from the financial services industry in March 2025, following findings by the regulator that he had deliberately sought to frustrate disciplinary processes initiated by Odey Asset Management (OAM) into his conduct. The FCA also concluded that Mr Odey had lacked candour and was not a fit and proper person to perform regulated activities.

The background to the case concerned allegations of misconduct and inappropriate behaviour by Mr Odey towards female employees, which first came to light following investigations undertaken by OAM's executive committee (ExCo) in early 2021. The ExCo issued a formal written warning to Mr Odey, which he accepted and signed. It then came to light that Mr Odey may have acted towards a member of staff in a way which breached the written warning. A second investigation was launched (and a hearing convened) by the ExCo in late 2021.

The FCA found that Mr Odey then embarked on a sustained campaign to interfere with OAM's internal disciplinary processes. Mr Odey's interventions included: (i) pressuring and threatening OAM's ExCo to discontinue its investigation; (ii) using his powers as ultimate majority shareholder to reconstitute the ExCo on two occasions; (iii) appointing himself in place of the ExCo; and (iv) communicating directly with clients in a way that presented an inaccurate and misleading impression about the circumstances of the changes to the ExCo. These actions brought the internal disciplinary process to a halt.

Mr Odey denied that he acted without integrity, adding that there were very good reasons that justified his removal of the ExCos, because he believed that neither was able to conduct the disciplinary process fairly. Mr Odey further argued that: (a) as majority owner, he was fully entitled to take the actions he took, and where the firm faced an "existential crisis", these were actions he reasonably considered to be in the best interests of the firm; and (b) had he not intervened, the ExCo would have incorrectly reached the decision that they should dismiss him, and this would result in the closure of the firm.

The Upper Tribunal upheld the FCA's decision, although it reduced Mr Odey's fine to £1.53m. In doing so, the Tribunal noted that Mr Odey was "motivated by his own self-interest and self-preservation so as to avoid accountability" and that his asserted beliefs "could not form a reasonable basis for his extraordinary actions which we are satisfied lacked integrity".

The Upper Tribunal's judgment comes just two weeks after the FCA's new rules on non-financial misconduct ("NFM", which we reported in the first edition of the Circular) came into force. While the Upper Tribunal's decision focused on the governance and disciplinary issues at OAM, its findings touch upon many of the problems that the NFM rules are intended to address. We considered the NFM rules in further detail in our briefing: New FCA guidance on non-financial misconduct.

Employment law reforms – reflections on the Fair Work Agency's first Delivery Plan and reminder of the new third-party harassment duty

Reflections on the FWA's first delivery plan

The FWA, which launched on 7 April, has published its Year 1 Delivery Plan for 2026-27. The Delivery Plan sets out the FWA's priorities, activities and performance measures for its first year of operation.

The Delivery Plan identifies three interdependent goals:

  1. Operational delivery: the FWA will focus on maintaining and improving its enforcement activity, expanding its reach and working with partner agencies to maximise impact.

  2. Institutional foundations: the FWA will build the internal capability needed to absorb National Minimum Wage enforcement from HMRC – a transfer that is expected to take place in 2027 – and prepare for the additional duties it will assume under the Employment Rights Act 2025.

  3. Technology and process: the FWA will invest in digital tools and AI to improve its detection and enforcement capabilities, and will simplify its guidance and systems for both businesses and workers.

The Delivery Plan confirms that this is a year of transition for the FWA. In-house legal and compliance teams should consider putting in place a protocol for responding to FWA inquiries and carefully review their compliance with employment law, and maintain a watching brief as to how the FWA's priorities and activities develop going forwards.

Third party harassment

As flagged in the first edition of the Circular, from 30 October 2026 employers will be liable for harassment of employees by third parties (including customers and clients) during the course of their employment.

The duty to take reasonable steps to prevent sexual harassment will also be strengthened to a duty to take "all" reasonable steps.

Businesses that have not already done so should review their harassment policies and risk assessments ahead of the new rules coming into force.

Back To Top Back To Top chevron up