Global Advice Network | Borgergade 111 | DK - 1300 Copenhagen K
E-Mail: info@business-anti-corruption.org | Phone: (+45) 60 88 10 44

Building a Pre-Acquisition Compliance Checklist for an Australian Target

Buying a company involves more than reviewing its revenue, contracts and growth forecasts. A target may carry hidden exposure from bribery, sanctions breaches, inaccurate books, unsafe supply chains, money laundering or weak data controls. These risks can become the buyer’s problem after completion, even when they originated years earlier.

A practical pre-acquisition compliance checklist gives the deal team a consistent way to test the target’s governance, policies and real-world conduct. It should combine document review, management interviews, sampling and independent verification rather than relying on a polished policy manual.

For an Australian buyer, the review should reflect both domestic obligations and overseas activity. A target based in Sydney may sell to public bodies in Southeast Asia, source from China or use distributors in the Middle East. Its compliance profile must therefore be assessed against Australian law, local requirements in relevant jurisdictions and the standards expected by lenders, investors and major customers.

Define The Risk Profile Early

Start by mapping the target’s business model, ownership, markets and points of contact with government. Record its offices, subsidiaries, agents, distributors, joint ventures and major contractors. Pay particular attention to industries with elevated exposure, including construction, mining, defence, health care, gaming, logistics, telecommunications and natural resources.

The checklist should identify whether the target bids for public contracts, obtains licences, imports controlled goods or relies on intermediaries to win business. A company operating around Perth’s mining sector may face different risks from a Melbourne software provider, while a hospitality group in Brisbane may have frequent licensing and cash-handling concerns. Risk scoring should reflect the target’s actual activities rather than applying the same questions to every acquisition.

Set review thresholds before documents arrive. For example, high-risk findings may require specialist investigation, executive approval or a price adjustment. Medium-risk findings may be handled through warranties, a remediation plan or enhanced monitoring. Clear thresholds prevent the deal team from minimising issues simply because the transaction timetable is tight.

The site disclaimer should also be considered when using external country profiles, legislation summaries or risk information: such material can support initial screening, but it does not replace advice tailored to the transaction and the target’s facts.

Examine Ownership And Governance

Verify the target’s legal identity, directors, shareholders, beneficial owners and related entities. Obtain current Australian Securities and Investments Commission records, constitutional documents, shareholder agreements, registers of interests and details of any nominee or trust arrangements. For an overseas subsidiary, obtain equivalent corporate records from the relevant jurisdiction and reconcile them with the group structure.

Look for unexplained ownership layers, recent changes in control, politically exposed persons and directors linked to government customers. Search sanctions, enforcement, debarment, insolvency and adverse media databases using consistent name variations. A beneficial owner hidden behind several companies is not automatically evidence of misconduct, but it should trigger more questions about control, source of funds and conflicts of interest.

Governance documents should include board minutes, audit committee papers, risk registers and records of compliance reporting. Ask whether the board received information about incidents, whistleblower complaints, gifts, third-party payments or regulatory correspondence. A target may have excellent written policies while its board has never reviewed whether those policies work in practice.

Check whether directors and senior managers have declared outside interests. In a smaller Australian business, personal relationships and local networks can influence procurement decisions without appearing in formal records. The checklist should test whether conflicts are disclosed, approved, recorded and revisited when circumstances change.

Review Anti-Bribery And Financial Controls

Collect the target’s anti-bribery policy, gifts and hospitality rules, political contribution controls, charitable donation procedures and facilitation payment guidance. Confirm when staff were trained, who attended and whether training covered contractors and overseas representatives. Under Australia’s Criminal Code Act 1995, bribing a foreign public official can create serious criminal exposure, and the risk may arise through an employee, consultant or joint venture partner.

Test the controls against transactions rather than merely checking that policies exist. Sample sales commissions, marketing expenses, travel claims, sponsorships, donations and petty cash payments. Compare invoices with contracts, approvals, bank records and evidence that services were actually delivered. Vague descriptions such as “government relations” or “special project costs” deserve further investigation.

Review the general ledger for unusual payments, round-dollar amounts, split invoices, payments to personal accounts and transactions routed through high-risk jurisdictions. Examine whether the target keeps accurate books and records, since disguising a bribe as consulting, advertising or a success fee can create a separate accounting problem.

Also assess segregation of duties and payment authority. Everyday controls matter: who creates a supplier, who approves an invoice, who releases a payment and who reviews bank reconciliations? A target using cloud accounting in Sydney may still have one executive able to onboard a vendor and approve a large payment without independent review.

Investigate Third Parties And Commercial Partners

Third parties often create the greatest acquisition risk because the buyer may inherit conduct it did not supervise. Obtain the target’s intermediary register and classify agents, customs brokers, freight providers, lobbyists, consultants, distributors, resellers, introducers and joint venture partners. Record each party’s ownership, location, services, compensation and government connections.

Review onboarding files for risk-based due diligence, sanctions screening, beneficial ownership checks, written contracts and approval records. Contracts should define services, fees, invoicing standards, audit rights, training requirements, termination rights and compliance obligations. Payments should be proportionate to documented work and made to an account held in the contracting party’s name.

Interview commercial and procurement staff about how third parties are selected in reality. Ask who recommended the intermediary, whether competitors use the same person and whether anyone resisted due diligence. A target may describe a consultant as essential to “opening doors” in Jakarta or Canberra, but that phrase should lead to a precise explanation of the services and contacts involved.

The target’s customer and supplier screening should also be tested against sanctions and export-control obligations. For businesses trading through ports such as Melbourne or Fremantle, verify controls over customs declarations, brokers, restricted goods and unusual routing. A clean supplier questionnaire is insufficient if no one investigates inconsistent ownership or a sudden request to change the payment destination.

Assess Sector-Specific And Australian Obligations

Build a legal register covering the target’s industry, locations and regulated activities. Australian areas may include the Corporations Act 2001, the Criminal Code, the Anti-Money Laundering and Counter-Terrorism Financing Act 2006, privacy legislation, competition law, workplace obligations and modern slavery reporting requirements. The checklist should note licences, regulators, reporting dates, investigations, enforceable undertakings and outstanding notices.

If the target provides designated services such as financial, remittance, digital currency or gambling-related services, determine whether it is registered with AUSTRAC and whether its AML/CTF program operates effectively. Review customer identification, suspicious matter reports, transaction monitoring, staff training and independent evaluations. A policy that has never been tested against actual customer activity is a material weakness.

Gaming and online entertainment transactions deserve careful scrutiny because marketing, payment processing, age verification and licensing rules can vary by jurisdiction. A recent casino deal example may be useful as a prompt for examining how commercial promotions, platform arrangements and regulatory expectations intersect, but it should not be treated as a substitute for transaction-specific analysis.

For larger groups, review Modern Slavery Act reporting, supplier mapping and remediation records. A target sourcing uniforms, electronics or promotional goods through Asian factories should be able to explain how it identifies forced-labour risks and responds to allegations. Check whether the company’s public statements match procurement records and whether senior management owns the reporting process.

Test Culture, Reporting And Investigation History

Request the whistleblower policy, hotline data, investigation files, disciplinary records and records of complaints involving bribery, fraud, harassment, conflicts or retaliation. Australian whistleblower protections under the Corporations Act make the handling of eligible disclosures especially important. Review whether reports can be made confidentially, whether recipients are trained and whether concerns are escalated to the board or audit committee.

Do not focus only on the number of reports. A target with no complaints may have a healthy culture, or employees may believe reporting is unsafe or pointless. Compare hotline activity with staff turnover, exit interviews, audit findings, employee surveys and regulatory correspondence. Look for repeated allegations involving the same manager, vendor or sales territory.

Interview a sample of employees from finance, sales, procurement, operations and compliance. Ask how gifts are approved, what happens when a customer requests an unofficial payment and whether employees can refuse questionable instructions. In Australian workplaces, informal communication through Teams, email and personal messaging can reveal how decisions are actually made, so preservation and review protocols should cover relevant business records.

Check whether investigations were independent, documented and resolved consistently. Red flags include missing files, unexplained settlements, destroyed records, retaliation claims and disciplinary action that differs according to seniority. The buyer should understand not only what happened, but also whether the target corrected the control failure that allowed it to happen.

Convert Findings Into Deal Protections

Classify findings by severity, evidence and potential impact. A missing policy is different from proof that an employee paid a public official, while an isolated historical issue may differ from an active scheme involving senior management. Estimate possible fines, remediation costs, lost licences, contract termination, debarment, tax consequences, reputational damage and management distraction.

For unresolved issues, decide whether to investigate before signing, require remediation before completion or proceed with contractual protection. The sale agreement may include specific warranties, indemnities, disclosure schedules, escrow arrangements, purchase price adjustments and conditions precedent. These provisions should describe the known risk accurately rather than relying on broad generic compliance warranties.

Obtain legal advice on privilege, document preservation and mandatory reporting. Do not instruct target employees to conduct informal searches that could alter evidence or create confusion over ownership of investigation materials. If a serious concern emerges, establish a small response team with defined authority, secure records and a documented decision path.

The checklist should end with an integration plan. Assign owners, deadlines and measures for policy alignment, training, third-party re-screening, accounting controls, hotline access and regulatory notifications. A buyer may need to suspend a risky intermediary, refresh customer due diligence or separate payment approval duties on the first day of ownership.

Record Evidence And Make The Checklist Usable

A useful checklist is an evidence register, not a long questionnaire. For each control area, include the request, responsible reviewer, documents received, interviews completed, risk rating, unresolved questions and recommended action. Use consistent labels such as complete, incomplete, not applicable and requires investigation, with an explanation for every exception.

Keep a secure data room structure that separates corporate records, policies, transaction samples, third-party files, investigations and personal information. Limit access according to role and preserve an audit trail. Privacy obligations should be considered when collecting employee records, customer information and whistleblower material, particularly where data crosses Australian state or international borders.

Create a red-flag summary for the investment committee and a detailed remediation schedule for operational teams. Senior decision-makers need a clear view of the risks that could change valuation or transaction structure, while compliance staff need enough detail to act. Include confidence levels where evidence is incomplete, because an unverified management assurance should not be presented as a resolved issue.

External specialists can help with forensic accounting, sanctions screening, sector regulation and country-risk research. The compliance support team may also be a useful source for directing general enquiries about available anti-corruption resources, while responsibility for legal conclusions remains with the buyer’s appointed advisers.

A strong checklist should survive the transaction timetable and remain useful after completion. Revisit it at signing, completion and the first post-acquisition review, recording which risks were accepted, transferred or remediated.

The practical takeaway is to connect every checklist question to evidence, ownership and a decision: investigate, fix, protect contractually or decline the deal.

copyright © Global Advice Network