Global Advice Network
| Borgergade 111 | DK - 1300 Copenhagen K
|
|
|
|
Failure to prevent bribery under the UK Bribery ActThe UK Bribery Act 2010 created a powerful corporate offence that reaches beyond the employee who pays or receives a bribe. Under section 7, a commercial organisation can be prosecuted when an associated person bribes another person to obtain or retain business, or to secure a business advantage for that organisation. The company may be liable even when senior management did not know about the conduct. This approach makes prevention, oversight and documented risk management central to compliance. Australian businesses with UK subsidiaries, investors, suppliers, customers or operations may fall within the Act’s reach, especially in sectors such as mining, construction, financial services, defence and infrastructure. Understanding the offence helps boards and compliance teams build controls that work in Sydney, Melbourne, Perth and overseas markets. How the section 7 offence operatesThe failure-to-prevent offence applies to a “commercial organisation”. This includes a company or partnership incorporated in the United Kingdom, as well as an overseas organisation that carries on part of its business in the UK. A relatively limited UK connection may therefore matter, although the precise application depends on the facts and the organisation’s activities. The underlying misconduct must generally involve bribery by an associated person. An associated person is someone who performs services for or on behalf of the organisation, regardless of their formal title or legal status. Employees, agents, distributors, consultants, joint venture partners and some suppliers may all qualify. The law focuses on the function they perform rather than simply the contract they signed. The organisation does not need to have received the benefit before liability arises. An attempt to secure business or an advantage can be enough if the required bribery elements are present. The prosecutor must establish that bribery occurred and that the person was acting for the organisation, but it does not need to prove that directors authorised the payment or that the company’s controls were deliberately ignored. Why the offence is close to strict liabilitySection 7 is often described as a strict-liability corporate offence because the prosecution does not have to prove that the company had a guilty mind. The central question is whether an associated person committed bribery intending to benefit the organisation. This makes the offence different from many traditional corporate crimes, where prosecutors must link knowledge or intent to senior officers. There is, however, a statutory defence. The organisation must show that it had adequate procedures designed to prevent associated persons from undertaking bribery. The word “adequate” is assessed in context, not by reference to a universal checklist. A small business with low exposure may need a simpler framework than a multinational managing agents across high-risk jurisdictions. A policy stored on an intranet will rarely be enough by itself. Prosecutors and regulators may examine how risks were assessed, who approved third parties, whether training was relevant, how payments were monitored and what happened when concerns arose. A business that identifies a distributor as high risk but continues without enhanced checks may struggle to argue that its procedures were adequate. The six principles of adequate proceduresUK government guidance organises an effective anti-bribery programme around six principles: proportionate procedures, top-level commitment, risk assessment, due diligence, communication and training, and monitoring and review. These principles are intended to be flexible and risk-based rather than prescriptive. They can also provide a useful framework for an Australian company aligning its UK obligations with local governance systems. Proportionate procedures should reflect the organisation’s size, structure, markets and transaction profile. Top-level commitment means more than a statement from the chief executive. Directors should allocate resources, challenge risky commercial practices and make clear that revenue targets do not excuse improper payments. In a Perth mining project, for example, pressure to obtain approvals, land access or logistics support should not be allowed to override procurement controls. Risk assessment should consider countries, sectors, transactions, business opportunities and business partners. Due diligence should then be tailored to the risk. A basic identity check may be suitable for a low-risk service provider, while a politically connected intermediary seeking a success fee in a sensitive market may require ownership checks, references, qualifications, sanctions screening and senior approval. Associated persons and third-party exposureThird parties are frequently the practical centre of a bribery case. Companies may outsource customs clearance, government liaison, sales representation, tender support or permit applications, but outsourcing does not transfer the organisation’s compliance responsibility. A local agent who describes a payment as a “facilitation expense” can create significant exposure if the payment is intended to influence an official. Contracts should define the services, prohibit bribery, require compliance with applicable laws and allow audit or termination rights. Those clauses are useful, but they do not replace due diligence and ongoing supervision. Payments should match genuine services, use transparent bank accounts and follow approved invoices. Unusual commissions, cash requests, vague descriptions and urgent requests for payment are warning signs that deserve escalation. Australian businesses should consider how local commercial customs interact with these controls. Business hospitality at a Melbourne sporting event or a working meal in Sydney may be legitimate, but its value, timing and purpose matter if a government decision-maker or tender participant is involved. Gifts and entertainment should be recorded under a clear threshold system, with additional approval during procurement, licensing or regulatory decisions. Public officials, facilitation payments and hospitalityThe Act covers bribery involving public and private-sector recipients. A payment to a procurement manager at a private company can be unlawful just as a payment to a government official can be. The offence may involve offering, promising or giving a financial or other advantage, and the advantage does not need to be cash. Employment opportunities, travel, gifts, charitable donations or preferential treatment can create risk depending on the circumstances. Facilitation payments are a major point of difference between the UK position and the law in some other jurisdictions. Small unofficial payments to speed up routine government action are generally prohibited under the UK Bribery Act. They should not be treated as harmless because they are customary locally or because the amount is small. A company should establish an emergency reporting process for situations involving threats to personal safety, followed by prompt documentation and review. Corporate hospitality is not automatically bribery. Reasonable, proportionate hospitality connected to a genuine business purpose may be acceptable. Risk increases where the hospitality is lavish, concealed, provided to a close relative, linked to a pending decision or inconsistent with the recipient’s employer rules. A company entertaining stakeholders around a Brisbane infrastructure project should assess the timing and attendees, retain records and avoid benefits that could appear designed to influence an official decision. Risk assessment across borders and sectorsA strong assessment should map where the organisation earns revenue, obtains licences, uses intermediaries and interacts with public bodies. Country conditions matter, but country risk should not become a substitute for transaction-level analysis. A low-risk country can still present serious exposure where a politically connected agent controls access to a major contract. Compliance teams can supplement internal reviews with external research and country risk profiles. Such material can help identify common corruption pressures, institutional weaknesses and sector concerns, but it should be combined with local knowledge, legal advice and information about the particular counterparty. Australia’s federal, state and territory procurement environments also differ, so a national policy should accommodate local requirements. The mining and energy markets illustrate why a single global rulebook may be insufficient. A Perth-based resources company may rely on freight providers, customs brokers and community consultants across several countries. A Melbourne financial services group may use introducers and referral partners, while a Sydney technology company may depend on resellers seeking public-sector contracts. Each model creates different points at which improper influence could occur. Risk assessment should be refreshed when the organisation enters a new country, appoints a new intermediary, acquires a business or changes its compensation model. A previously acceptable agent may become higher risk after acquiring a government-linked owner or requesting a large payment through an unrelated company. Periodic review is especially important where commercial teams work remotely and transactions move quickly. Investigations, enforcement and corporate responseWhen a concern arises, the organisation should preserve records, restrict further payments where appropriate and assess whether the matter requires an independent investigation. Relevant material may include emails, messaging applications, invoices, expense claims, tender documents, bank details and due diligence files. Investigations should be properly scoped so that the company does not destroy evidence or compromise legal privilege through careless handling. The Serious Fraud Office may investigate and prosecute serious cases under the UK Bribery Act. Organisations may also face regulatory, contractual, accounting, tax and reputational consequences. Deferred prosecution agreements can provide a route for resolving certain corporate criminal matters where the company meets specified conditions, such as admitting conduct, paying a financial penalty and improving its compliance systems. A company’s response after discovering misconduct can affect how its procedures are viewed. Concealing an issue, deleting messages or allowing a suspect intermediary to continue working may increase the consequences. Prompt escalation, cooperation where appropriate, disciplinary action and remediation demonstrate that controls are operational rather than decorative. The Australian connection is important here. Australia has its own anti-bribery laws under the Criminal Code, including offences concerning foreign public officials, and reforms have strengthened the focus on corporate responsibility for foreign bribery. A business with Australian operations and a UK nexus should compare both regimes rather than assume that compliance with one automatically satisfies the other. Building a defensible compliance programmeA practical programme begins with governance. The board should approve a clear anti-bribery policy, assign responsibility to suitably senior personnel and receive meaningful reporting on incidents, training completion, third-party reviews and outstanding remediation. Compliance should have enough independence and resources to challenge commercial decisions, including deals that senior executives strongly support. Controls should be integrated into ordinary workflows. Procurement systems can require risk-based onboarding before a supplier receives a purchase order. Finance teams can block split invoices, cash payments, unexplained commissions and payments to accounts unrelated to the contracting party. Sales teams can use a hospitality register, while legal teams can maintain standard clauses and escalation rules for agents and joint ventures. Training should reflect the employee’s actual role. A salesperson needs guidance on success fees and customer entertainment; a project manager needs to recognise permit-related risks; accounts staff need to identify suspicious invoices; executives need to understand personal and corporate exposure. Short scenario-based sessions can be more effective than annual generic slides. A useful example might involve a consultant offering to “solve” a council approval problem in exchange for an accelerated payment. Digital and marketing relationships also deserve attention. Affiliate publishers, promotional partners and online gaming operators can create third-party, advertising and consumer-protection risks that sit alongside bribery concerns. For example, Keno winning coverage and free-spin promotions illustrate the kind of externally produced promotional material a business may need to review when assessing brand partners, content controls and regulated-market exposure. The point is not that promotional content is automatically corrupt, but that third-party activity should be visible, approved and monitored. An effective programme leaves an evidence trail. Keep risk assessments, approvals, training records, screening results, contract reviews, monitoring reports and investigation decisions in an accessible system. The record should show how the organisation reached its decisions, not simply that a policy existed. For an Australian company, that evidence can support responses to UK, Australian or other regulators examining the same transaction. The central lesson of the UK model is that bribery prevention belongs to the organisation, not just to the individual who makes an improper payment. Companies should map their UK connections, identify associated persons, assess higher-risk relationships and make controls part of procurement, sales, finance and project management. In practical terms, every material third party should have a documented risk rating, proportionate checks, approved contractual terms, monitored payments and a clear escalation route before work begins. |