01 September 2026
Regulators are done with tick-box training. Is your LMS ready?
If you oversee compliance training, two UK updates from the last 12 months should be on your radar – along with their precursor from Washington – because together they signal what regulators now expect a genuine compliance programme to look like. And training sits right at the heart of both.
The US sets a higher bar
The US Department of Justice updated its Evaluation of Corporate Compliance Programs guidance in September 2024, the document prosecutors use to decide whether a company's compliance efforts were genuine or just paperwork. It asks three questions:
1. Is the programme well designed?
2. Is it properly resourced and empowered?
3. Does it work in practice?
The update sharpened expectations around emerging technology risk (including AI), how seriously organisations take confidential reporting and whistleblower protection, and – critically for L&D – how training is tailored, measured, and proven to change behaviour rather than just logged as "complete."
The UK is catching up fast and pointing straight at the DOJ
This isn't just a US story. The UK's Economic Crime and Corporate Transparency Act 2023 (ECCTA) introduced a new corporate offence, failure to prevent fraud, which came into force on 1 September 2025. Large organisations can now be held criminally liable if an employee or "associated person" commits fraud intended to benefit the business, unless the organisation can show it had "reasonable procedures" in place to stop it.
The Home Office's guidance sets out six principles those procedures need to be built on – the same six principles that already underpin the Bribery Act 2010's "adequate procedures" defence and the Criminal Finances Act's rules on facilitating tax evasion:
- Top-level commitment
- Risk assessment
- Proportionate, risk-based procedures
- Due diligence
- Communication and training
- Monitoring and review
Then, in November 2025, the Serious Fraud Office refreshed its own guidance on evaluating a corporate compliance programme and explicitly referenced the DOJ's framework as a benchmark. Legal commentators have called this a clear sign of convergence: the UK is still principle-based rather than prescriptive, but the direction of travel is unmistakably towards the DOJ's more structured, evidence-led model. One thing both regulators agree on is this: having a policy document is not the same as having a compliance programme. What matters is whether people know it, follow it, and can be shown to have done so.
A word on scope: ECCTA's failure to prevent fraud offence only catches "large organisations" – those meeting two of three thresholds (250+ employees, £36m+ turnover, £18m+ balance sheet). If that's not you, don't relax: the Bribery Act 2010 and the Criminal Finances Act 2017 apply to organisations of any size, with the same "adequate/reasonable procedures" defence structure. Most mid-market and smaller UK businesses are still fully exposed under those two, though not (yet) under ECCTA.
What this means for compliance officers and L&D leads
The message from both UK and US regulators is the same: training and quality records are now direct evidence in how your organisation's compliance culture is judged. Here's what to check:
1. Is training risk-based, not blanket? Regulators want to see that high-risk roles and functions get deeper, more targeted training than everyone else, not the same 20-minute module for every employee regardless of exposure. If your LMS can't segment learners by role, risk level, or business unit and assign different content accordingly, that's a gap.
2. Can you prove people understood it, not just clicked through it? Completion rates alone won't satisfy a prosecutor or the SFO. You need evidence that training was engaged with: assessments, scenario-based learning, and a record of who struggled and what happened next.
3. Are your policies accessible, searchable, and genuinely used? Both frameworks ask whether employees can find and understand policies (including across languages and locations), and whether you track which policies get looked at, and by whom.
4. Is your reporting mechanism trained, not just published? A confidential reporting line nobody knows how to use, or is too scared to use, doesn't count. Training needs to cover how and when to raise concerns, and reinforce anti-retaliation protections explicitly.
5. Do managers have real oversight, or is L&D chasing everyone alone? Regulators increasingly expect middle management to reinforce compliance standards, not just central compliance teams. That means managers need visibility of their own team's progress and a role in follow-up.
6. Does your training keep pace with new and emerging risk, including AI? Both the DOJ and the Home Office now explicitly flag technology risk. If your training library hasn't been reviewed since new tools, new fraud typologies, or new regulatory guidance landed, it's stale – and staleness is now something regulators actively probe.
7. Are third parties and new acquisitions brought into the fold quickly? Post-acquisition compliance training gaps are a specifically named area of scrutiny in the DOJ's update. If onboarding a new site or business takes months to get onto your compliance training, that's a live risk.
8. Can you produce audit-ready evidence in minutes? When a regulator, auditor, or court says, "prove it," you need exportable, timestamped completion and comprehension records, not a scramble through spreadsheets.
9. Is your programme reviewed and refreshed on a cycle? Both frameworks explicitly reward organisations that update their training as lessons are learned – from their own near-misses and from incidents elsewhere in their sector. A training programme that hasn't changed in two years is exactly what both regulators are trained to spot.
Where Breeio fits
As an efficient, easy-to-use LMS platform for professional development and easy-to-prove compliance, this is precisely the territory Breeio LMS was built for.
A few ways Breeio supports the checklist above:
Risk-based, blended assignment. Breeio lets you build individual learning pathways by role, site, or risk profile, automatically assigning e-learning modules, face-to-face and virtual classroom sessions so high-risk teams get more than a generic module.
Compliance training with automatic renewals. Mandatory and recurring training is scheduled and re-triggered automatically, with detailed compliance reporting behind it, so nothing quietly lapses.
Manager visibility built in. Breeio’s “My Team” area brings line managers into the platform, with role-based reporting and automated reminders on their own team's progress. Oversight doesn't rely on L&D chasing every individual.
Audit-ready reporting on demand. Real-time analytics and exportable compliance evidence mean you can answer "prove it" in minutes, not weeks, whether the audience is a regulator, an auditor, or your board.
A content library that evolves. With access to thousands of courses from dozens of content partners, plus Acteon's in-house instructional design team, your training content can be refreshed as new risks – from AI governance to fraud typologies – emerge, rather than sitting untouched for years.
Genuinely used policies and comms. Breeio's built-in communication platform and intuitive, mobile-first design, along with clear engagement tracking on policies and other resources helps you ensure policies are read and acknowledged – because a policy nobody reads is not a defence.
A partner, not just software. Breeio is built by Acteon, drawing on more than 45 years of experience in learning and behaviour change, which means your compliance training strategy – not just the platform underneath it – has expert support behind it.
Regulators on both sides of the Atlantic are converging on the same conclusion: a compliance programme is only as good as the evidence you can produce that it works. If your current LMS leaves you guessing, that's worth fixing before you're asked to prove it.
Want to see how Breeio would hold up against your own compliance checklist? Book a demo or download the Breeio fact sheet.
Sources:
U.S. Department of Justice, Criminal Division. Evaluation of Corporate Compliance Programs (Updated September 2024). https://www.justice.gov/criminal/criminal-fraud/page/file/937501
UK Home Office. Economic Crime and Corporate Transparency Act 2023: Guidance to Organisations on the Offence of Failure to Prevent Fraud (6 November 2024). https://www.gov.uk/government/publications/offence-of-failure-to-prevent-fraud-introduced-by-eccta/economic-crime-and-corporate-transparency-act-2023-guidance-to-organisations-on-the-offence-of-failure-to-prevent-fraud-accessible-version
UK Serious Fraud Office. SFO Guidance on Evaluating a Corporate Compliance Programme (26 November 2025). https://www.gov.uk/government/publications/sfo-guidance-on-evaluating-a-corporate-compliance-programme
Skadden, Arps, Slate, Meagher & Flom LLP. "Key Updates to the DOJ's Evaluation of Corporate Compliance Programs" (September 2024). https://www.skadden.com/insights/publications/2024/09/key-updates-to-the-dojs-evaluation-of-corporate-compliance-programs
Clyde & Co. "SFO Guidance on Evaluating a Corporate Compliance Programme" (28 November 2025). https://www.clydeco.com/en/insights/2025/11/sfo-guidance-on-evaluating-a-corporate-compliance
A&O Shearman. "UK SFO New Corporate Compliance Guidance — What It Means for In-House Legal Teams" (2025). https://www.aoshearman.com/en/insights/ao-shearman-on-investigations/uk-sfo-new-corporate-compliance-guidance---what-it-means-for-in-house-legal-teams