Global Advice Network | Borgergade 111 | DK - 1300 Copenhagen K
E-Mail: info@business-anti-corruption.org | Phone: (+45) 60 88 10 44

Navigating anti-corruption laws in the Middle East

Expanding into the Middle East can expose a company to several legal systems at the same time. A subsidiary may be incorporated under local law, controlled by a parent company subject to the U.S. Foreign Corrupt Practices Act (FCPA) or UK Bribery Act, and operating through agents who work across multiple jurisdictions. A transaction involving a state-owned customer can create additional exposure even when the payment appears commercially ordinary.

The central difficulty is rarely finding a single rule. It is identifying which rules apply to each person, payment, intermediary, contract, and business decision. Local anti-bribery statutes, international conventions, sanctions regimes, procurement requirements, and corporate policies may overlap without using identical definitions or enforcement standards.

This makes a documented risk-based process essential. The anti-corruption resources available through the Business Anti-Corruption Portal can help companies compare country risks, review compliance terminology, and build a stronger foundation for market-entry decisions.

Why legal conflicts arise

Anti-corruption laws conflict because they regulate similar conduct through different legal concepts. One jurisdiction may prohibit bribery of public officials, while another also criminalizes commercial bribery between private companies. A benefit that is treated as an unlawful inducement under a parent company’s policy may be viewed locally as a customary hospitality expense, though local custom does not automatically make it lawful.

The definition of a public official is another frequent source of uncertainty. Employees of ministries are usually obvious examples, but staff at government-controlled companies, sovereign wealth entities, hospitals, universities, ports, and utilities may also create risk. Under the FCPA and UK Bribery Act, a company may face scrutiny for conduct involving entities that are not ministries in the narrow sense.

Enforcement reach can extend beyond the country where an event occurred. A U.S. issuer may face FCPA exposure because of a dollar-denominated payment, an email routed through U.S. systems, or conduct involving an employee or agent connected to the United States. A UK company can face liability under the UK Bribery Act, including for failure to prevent bribery by associated persons. Local enforcement authorities may investigate the same conduct under domestic criminal or commercial laws.

Map the full legal exposure

A useful legal analysis starts with the transaction rather than the country name. Identify the selling entity, contracting entity, parent company, employees involved, source of funds, bank locations, customer ownership, intermediaries, and delivery sites. This reveals whether a deal in one Middle Eastern country also touches another country’s anti-corruption or sanctions laws.

The corporate structure deserves close attention. A regional headquarters in the United Arab Emirates may manage operations in Saudi Arabia, Qatar, Bahrain, Oman, Kuwait, Jordan, or Egypt. Each subsidiary may have separate licensing, employment, procurement, and accounting obligations. A group-wide policy can create a common minimum standard, but it cannot replace local legal analysis.

Companies should also distinguish between legal requirements and internal controls. A local law may permit a narrow category of hospitality, while company policy prohibits it for all public-sector contacts. That stricter rule can be appropriate if it is clearly communicated, consistently enforced, and supported by an approval system that employees can realistically use.

A country risk profile is only a starting point. The actual risk level depends on the industry, government touchpoints, use of agents, customs exposure, licensing requirements, tendering practices, and the history of enforcement in the relevant market. Energy, defense, infrastructure, healthcare, telecommunications, extractive industries, and public construction typically require deeper review.

Compare rules before setting one standard

The safest approach is to create a conflict matrix for the jurisdictions that may regulate the transaction. The matrix should record the rule, the people covered, the prohibited conduct, available exceptions, recordkeeping expectations, enforcement authority, and the company control that will address the risk.

Issue Local Middle Eastern law FCPA UK Bribery Act Practical control
Public-sector bribery Varies by country and may cover domestic or foreign officials Prohibits corrupt payments to foreign officials for business advantage Prohibits bribery of public officials and private persons Pre-approval and documented business purpose
Private-sector bribery Often addressed through criminal, commercial, or employment provisions Generally outside the core foreign-official offense, though books-and-records rules may apply Covers active and passive commercial bribery Apply controls to public and private counterparties
Facilitation payments Treatment differs; local practice does not establish legality Narrow statutory exception is limited and risky in application No general exception Prohibit routine facilitation payments
Hospitality and gifts May be accepted within limits, policies, or sector rules Permitted only when reasonable, bona fide, and not corruptly intended Must be reasonable and proportionate, with intent central Set monetary thresholds and official-contact restrictions
Books and records Accounting and corporate records rules may apply Accurate books and adequate internal controls are key Corporate failure-to-prevent risk makes procedures important Keep complete, timely supporting documentation

The company should normally adopt the strictest defensible standard where rules differ, especially for facilitation payments, cash benefits, public tenders, charitable contributions, and dealings with government-controlled entities. That does not mean ignoring local law. It means using a control framework that prevents employees from having to make fine legal distinctions under commercial pressure.

Legal review should be refreshed when a law changes, a new distributor is appointed, ownership of a customer changes, or the business enters a regulated sector. The portal’s legal disclaimer is also relevant when using general online information: country materials support risk assessment, but they do not replace advice from qualified counsel on a specific transaction.

Control third parties and local partners

Third-party risk is often the most important issue in regional expansion. Commercial agents, government-relations consultants, customs brokers, distributors, sponsors, joint-venture partners, and subcontractors may interact with officials more frequently than company employees. Their local knowledge can be valuable, yet it can also conceal inflated commissions, undisclosed relationships, or payments routed through multiple entities.

Due diligence should match the risk. Basic screening may cover ownership, registration, sanctions, litigation, adverse media, and qualifications. Higher-risk reviews should examine beneficial owners, government connections, political exposure, references, proposed compensation, bank details, conflicts of interest, and the reason the intermediary is needed. A refusal to provide ownership information or a request for payment to a personal or unrelated account should trigger escalation.

Written contracts need more than a general compliance clause. They should describe the services, require accurate invoices, prohibit sub-agents without approval, provide audit and information rights, restrict cash payments, require compliance with applicable anti-bribery laws, and allow suspension or termination for misconduct. Compensation should be commercially reasonable, paid to a verified account in the contracting party’s name, and supported by evidence of actual work.

Joint ventures create a separate challenge because the parent company may not control daily activity. Governance documents should define appointment rights, compliance reporting, investigation procedures, approval thresholds, training duties, and access to records. Minority investors should consider whether board rights and information rights are sufficient to identify and respond to improper payments.

Manage gifts, facilitation payments, and public dealings

Gift and hospitality rules should be specific enough for employees to apply during a business meeting, site visit, conference, or religious holiday. A policy can set value limits, prohibit cash and cash equivalents, require advance approval for public officials, and restrict travel for spouses or unrelated guests. It should also address frequency, timing, luxury venues, tender periods, and benefits provided through a third party.

The intention and context of a benefit matter as much as its value. A modest meal during a technical meeting may present limited risk, while a similar meal immediately before a license decision may appear intended to influence an official. Repeated low-value benefits can create the same concern as a single expensive item. Every approval should record who attended, their roles, the business purpose, the value, and whether a pending decision was involved.

Facilitation payments deserve a clear group position. Some legal systems may treat small payments for routine administrative action differently from larger bribes, but the distinction can be difficult to apply and may conflict with the UK Bribery Act or corporate policy. Prohibiting such payments is generally easier to communicate and audit. If an employee faces an immediate threat to health or safety, the policy should explain the reporting and documentation process rather than leaving the employee without guidance.

Public procurement requires enhanced controls. Employees should avoid informal promises, undisclosed meetings, success fees tied to official decisions, and contact with competitors about bids. Charitable donations, sponsorships, internships, and community investments connected to an official’s request should receive independent review, particularly where the recipient is linked to a licensing, tender, customs, or inspection decision.

Build evidence into daily operations

A compliance program becomes credible through records. Finance teams should be able to trace a payment from approval to invoice, contract, proof of service, bank transfer, and accounting entry. Vague descriptions such as “government relations,” “special services,” or “miscellaneous expenses” make it difficult to distinguish legitimate work from concealed benefits.

Approval workflows should reflect actual business speed. If employees cannot obtain a response before a client meeting or permit deadline, they may bypass the process. Regional compliance teams can establish service levels, emergency escalation routes, pre-approved categories, and a central register for gifts, hospitality, donations, sponsorships, and third-party engagements.

Training should be tailored to roles and location. Sales staff need practical guidance on tenders and customer entertainment. Procurement teams need instructions on supplier selection and conflicts of interest. Finance staff need red-flag examples involving split invoices, unusual commissions, round-sum payments, and requests for cash. Senior managers and board members need to understand personal exposure, oversight duties, and escalation expectations.

A confidential reporting channel should be available in languages employees understand and should protect against retaliation. Reports involving senior executives, government officials, or major intermediaries should be assessed independently. Investigations should preserve evidence, define scope, document decisions, and consider whether disclosure or corrective action is required under applicable law.

Practical priorities for a defensible expansion

A company entering one or more Middle Eastern markets can focus its first implementation phase on these measures:

  • Prepare a jurisdiction-and-transaction matrix covering local law, parent-company statutes, sanctions, procurement rules, and sector requirements.
  • Identify government touchpoints, including state-owned enterprises, licensing bodies, customs authorities, hospitals, universities, and public utilities.
  • Complete risk-based due diligence before appointing agents, distributors, consultants, sponsors, or joint-venture partners.
  • Prohibit cash benefits and routine facilitation payments, with a documented process for safety-related incidents and urgent escalation.
  • Test books and records through targeted reviews of commissions, hospitality, donations, sponsorships, and unusual third-party invoices.

These controls work best when ownership is assigned. The regional business leader can own implementation, legal can interpret local requirements, compliance can oversee risk assessments and training, finance can test transactions, and procurement can enforce third-party standards. Clear accountability prevents anti-corruption responsibilities from becoming a general expectation with no operational owner.

Management should measure whether controls work in practice. Useful indicators include the percentage of high-risk third parties reviewed before engagement, approval turnaround time, overdue training, exceptions granted, payment records lacking support, hotline reports, and remediation status. A small number of well-chosen metrics can reveal whether a policy is understood or merely published.

Turn legal analysis into market readiness

Conflicting anti-corruption laws should be treated as a design issue for market entry, not as a problem to address after a contract is signed. Companies that map jurisdictional exposure, apply consistent minimum standards, investigate third parties, and preserve reliable records are better positioned to respond when a regulator, auditor, partner, or employee raises a concern.

Begin with the next proposed market or transaction. Document the parties, officials, intermediaries, payments, approvals, and applicable laws; obtain jurisdiction-specific advice where the facts require it; and convert the findings into training, contract language, approval controls, and audit tests. A disciplined compliance framework can support responsible growth while giving commercial teams clear boundaries for operating across the region.

copyright © Global Advice Network