Global Advice Network | Borgergade 111 | DK - 1300 Copenhagen K
E-Mail: info@business-anti-corruption.org | Phone: (+45) 60 88 10 44

How Compliance Shapes M&A Due Diligence in Australia

In a merger or acquisition, the compliance officer helps determine whether a target is worth buying, what risks should be reflected in the valuation, and which safeguards must be in place before completion. The role extends well beyond checking policies in a data room. It involves testing how the business operates in practice, identifying hidden liabilities, and translating legal, ethical and reputational concerns into clear deal advice.

For Australian buyers, this work can span a listed company in Sydney, a family-owned manufacturer in Melbourne, a resources venture in Perth, or a technology target with suppliers and agents across Asia. Local expectations under the Corporations Act, Australia’s foreign bribery laws, sanctions regimes, privacy rules and anti-money laundering requirements must be considered alongside the laws of every country where the target operates.

Set The Mandate Before Access Begins

The compliance officer should help establish the scope of due diligence before the transaction team begins reviewing documents. That scope should reflect the target’s industry, ownership structure, countries of operation, government exposure, use of intermediaries, licensing obligations and history of regulatory contact. A business selling medical equipment to state hospitals requires a different review from a software company selling subscriptions directly to consumers.

Early involvement also prevents compliance from becoming a late-stage approval function. The officer can define information requests covering the code of conduct, gifts and hospitality registers, whistleblower reports, internal investigations, audit findings, distributor agreements, beneficial ownership records, sanctions screening and training completion. Missing documents are themselves informative. A target that cannot produce a reliable register of agents or public-sector clients may have a control weakness even if no misconduct has yet been proven.

The review should be risk-based rather than evenly distributed across every document. Particular attention belongs on markets with weak enforcement, high public-sector interaction or opaque ownership. It also belongs on transactions involving politically exposed persons, customs brokers, freight forwarders, consultants, joint venture partners and local sponsors. The compliance officer coordinates with legal, finance, tax, cybersecurity and human resources teams so that a bribery concern is not considered in isolation from accounting or operational evidence.

Test The Integrity Of The Target

Policies provide a starting point, not a conclusion. The officer should compare written controls with behaviour demonstrated in payment records, email samples, expense claims, tender files and interviews. A sophisticated code of conduct has limited value if sales staff describe facilitation payments as normal, managers approve unusual commissions without review, or employees avoid the whistleblower channel because they do not trust its confidentiality.

The culture review should examine how the target handles gifts, travel, sponsorships and charitable contributions. This is especially important for an Australian company acquiring a business in an Asian market, where hospitality customs may be commercially significant but still create an improper influence risk. Guidance on gift-giving in Asia can help deal teams distinguish respectful business etiquette from benefits that could affect a procurement decision or breach a customer’s rules.

Interviews should include people outside senior management. Procurement staff, finance controllers, regional sales managers and former compliance personnel often reveal whether approval processes are bypassed in practice. The officer should look for recurring patterns: round-dollar invoices, vague descriptions such as “market support”, commissions paid soon after contract awards, unusual urgency around onboarding a supplier, and requests to pay into accounts unrelated to the contracting party.

Australian buyers should also consider whether the target’s culture can be integrated after completion. A business operating from Brisbane may have a direct and informal management style, while an acquired sales office in Southeast Asia may rely heavily on relationship-based networks. Cultural differences do not excuse misconduct, but an integration plan that ignores them may drive questionable practices underground.

Follow The Money And The Third Parties

Third-party relationships are often the most difficult part of acquisition due diligence. Agents, distributors, customs intermediaries, consultants and joint venture partners may act on the target’s behalf without being visible in its organisational chart. The compliance officer should map these relationships, identify who selected and approved each party, examine compensation, and test whether services can be evidenced.

Screening should cover sanctions, watchlists, politically exposed person databases, adverse media, ownership and litigation. It should be repeated when a relationship continues after completion, because ownership and risk status can change. A practical resource on sanctions and watchlists is relevant when an Australian buyer inherits suppliers, customers or agents across multiple jurisdictions.

Payment testing should connect contracts to invoices, purchase orders, bank accounts and proof of delivery. The officer should investigate payments routed through offshore entities, split invoices below approval thresholds, cash withdrawals, success fees that lack a measurable service, and rebates that do not match contract terms. In a resources transaction involving Western Australia or Queensland, this may include examining contractors that assist with land access, local approvals, logistics or government-facing negotiations.

The assessment should also cover modern forms of misconduct that may not appear in conventional anti-bribery reviews. Conflicts of interest, undisclosed side businesses, misuse of confidential information, procurement collusion and inappropriate gambling can affect decision-making and financial controls. Where the target’s business model includes gaming, payments or high-volume digital transactions, the compliance officer may need to assess exposure to fraud and gambling-related harm, including risks discussed in material on online gambling practices.

Turn Findings Into Deal Decisions

A compliance finding becomes useful when it is translated into a decision. The officer should classify issues according to severity, likelihood, financial impact, remediability and the people or entities involved. A missing annual training record may require a manageable remediation plan. Evidence that senior executives authorised bribes to win government contracts could affect price, warranties, disclosure obligations, completion conditions and the decision to proceed at all.

The analysis should distinguish known misconduct from indicators requiring further investigation. A red flag is not proof, but it should lead to a proportionate response. That response might include forensic accounting, targeted email review, interviews with former employees, expanded third-party checks or a request for records held outside the data room. The compliance officer should document the rationale for each step so that the board can understand both the risk and the limits of the evidence.

Deal documents should reflect material findings. Possible protections include specific indemnities, escrow arrangements, purchase price adjustments, compliance representations, disclosure schedules, termination rights and conditions requiring remediation before closing. Contract language cannot erase historical misconduct, but it can allocate financial risk and create leverage for obtaining information that the target previously withheld.

The officer’s responsibilities continue after signing. If the buyer inherits the target’s contracts, employees and operations, it may also inherit the consequences of past conduct and the need to report or remediate it. Pre-completion planning should therefore cover access to reporting channels, retention of relevant records, authority for investigations, suspension of risky payments, integration of third-party approval systems and communication with regulators where appropriate.

Practical Priorities For The Deal Team

A disciplined process helps the compliance officer keep a transaction moving while giving decision-makers a reliable picture of exposure. The following priorities are particularly useful for Australian acquisitions:

  • Set a written risk-based scope covering countries, sectors, public-sector dealings, third parties, beneficial ownership and historic investigations.
  • Test actual conduct through payment analytics, contracts, interviews, whistleblower data and samples of gifts, travel and sponsorship expenses.
  • Escalate unexplained commissions, offshore payments, opaque ownership, sanctions concerns and management resistance to document requests.
  • Convert material findings into price, indemnity, escrow, warranty, closing-condition and post-completion requirements.
  • Prepare a first-100-days compliance plan covering training, reporting channels, third-party controls, records and regulatory engagement.

The board or investment committee should receive a concise report that separates facts, assumptions, unresolved questions and recommended actions. It should explain how the risk could affect revenue, licences, government contracts, financing, reputation and integration costs. This format is more useful than a long inventory of policy documents because it connects compliance findings to the commercial decision.

The compliance officer should also preserve independence. In smaller Australian businesses, the same person may be expected to support the deal team, manage operational risk and advise the board. Clear escalation rights and direct access to directors are essential where executives involved in the transaction may have an interest in minimising uncomfortable findings. External counsel, forensic specialists or specialist investigators can provide additional independence when the issues are serious or cross-border.

The most effective approach treats due diligence as a process of informed risk acceptance, not a search for a perfectly clean target. Every acquisition carries uncertainty, but uncertainty can be reduced through focused testing, credible evidence and enforceable protections. Before signing, the buyer should complete a documented review of the highest-risk third parties and unresolved payment anomalies, then place the agreed controls and remedies into the transaction documents.

copyright © Global Advice Network