Global Advice Network
| Borgergade 111 | DK - 1300 Copenhagen K
|
|
|
|
Understanding the UK Bribery Act’s Adequate Procedures DefenceThe UK Bribery Act 2010 places a demanding responsibility on companies that benefit from business conducted in the United Kingdom. Under Section 7, an organisation can be prosecuted when an associated person bribes another person to obtain or retain business, or a business advantage, for the organisation. The company does not need to have authorised, known about, or benefited directly from the misconduct. The principal safeguard is the adequate procedures defence. A commercial organisation may avoid liability if it proves that, at the time of the offence, it had adequate procedures designed to prevent persons associated with it from bribing. This is a defence to corporate liability, rather than a general exemption from the Bribery Act. Adequacy is judged against the organisation’s actual risk, size, structure, markets, and business model. A policy copied from another company will carry little weight if employees do not understand it, third parties bypass it, or management cannot show that controls operate in practice. The strongest compliance programmes connect written rules with evidence, accountability, and regular review. What The Defence Actually RequiresSection 7 creates a form of strict corporate liability for failure to prevent bribery. The prosecution must establish that an associated person committed bribery intending to obtain or retain business or a business advantage for the organisation. It does not have to prove that senior management knew about the bribe or that the organisation itself made the payment. The organisation must then demonstrate, on the balance of probabilities, that it had adequate procedures intended to prevent such conduct. “Adequate” does not mean perfect or capable of stopping every unlawful act. It means proportionate and reasonably designed to address the risks the company faced. A small domestic business and a multinational operating through agents in high-risk markets should not be expected to maintain identical controls. The underlying bribery may involve offering, promising, or giving an advantage under Section 1, or bribing a foreign public official under Section 6. Facilitation payments remain prohibited, even when locally customary or described as small administrative payments. Hospitality and promotional expenditure are assessed according to purpose, value, frequency, transparency, and surrounding circumstances rather than by a single universal monetary threshold. Identifying Associated PersonsAn associated person is someone who performs services for or on behalf of the organisation. The category is deliberately broad and may include employees, subsidiaries, agents, distributors, consultants, brokers, joint venture partners, contractors, and suppliers. A person’s formal job title or contractual label does not determine the outcome; the substance of the relationship matters. Companies should therefore map how business is won, delivered, and supported. A sales intermediary who introduces a company to a ministry, a customs broker who handles import clearances, and a local partner that secures licences may each create exposure. The risk increases where compensation depends on success, services are poorly defined, ownership is opaque, or the intermediary has close links to public officials. A contract cannot transfer statutory risk to a third party. Anti-bribery warranties, audit rights, termination clauses, and payment controls are useful, but they do not replace due diligence and oversight. The company must be able to show why it selected the intermediary, what checks it performed, what services were delivered, and how payments were approved. This is especially important when an intermediary facilitates access to public decision-makers. Guidance on the risks of third-party introductions can help compliance teams distinguish legitimate relationship management from arrangements that conceal influence payments or improper access. Applying The Six Guiding PrinciplesThe UK Ministry of Justice guidance organises adequate procedures around six principles. First, procedures should be proportionate to the bribery risks and to the organisation’s characteristics. Second, senior management must demonstrate top-level commitment through decisions, resources, incentives, and personal conduct. A statement from the board has limited value if revenue targets reward employees for ignoring red flags. Third, the organisation should conduct periodic, informed, and documented risk assessments. These should consider countries, sectors, transactions, government interaction, business partners, payment structures, and the effectiveness of existing controls. A country risk rating is a starting point, not a substitute for transaction-level analysis. A business operating in India, for example, can use a country risk profile alongside checks on the specific state authority, partner, licence, and payment arrangement involved. Fourth, due diligence should be proportionate and risk-based. Screening a low-risk supplier may require basic identity and ownership checks, while appointing a politically connected agent in a high-risk market may require enhanced investigation, references, beneficial ownership verification, and senior approval. Fifth, companies should communicate policies and provide training suited to the audience, including remote teams and relevant third parties. Sixth, monitoring and review should test whether controls remain effective as the business, market, and legal environment change. These principles work as a connected system. Risk assessment should determine due diligence; due diligence should influence contract terms and approval levels; training should reflect actual scenarios; monitoring should identify gaps; and management should respond to findings. Treating the principles as six separate documents can create the appearance of compliance without meaningful prevention. Evidence That Procedures Are AdequateAn enforcement authority will assess the quality of the programme through contemporaneous evidence. Useful records show what the organisation knew, what it decided, who approved the decision, and why the control was proportionate. They also show whether the company followed its own process when commercial pressure was high.
Document retention is part of the control environment, not an administrative afterthought. Records should be organised so that the company can reconstruct onboarding, approvals, payments, training, and remediation. Practical guidance on retaining compliance documentation is relevant when designing retention schedules and review routines. The objective is not to produce paperwork for its own sake. Excessive forms can encourage superficial approvals, while missing records make legitimate decisions appear arbitrary. Documentation should be clear enough for an independent reviewer to understand the risk, the control applied, the exception considered, and the person accountable. Managing Third-Party And Cross-Border RiskThird-party risk is often the central issue in a Section 7 investigation because intermediaries may operate with limited supervision and strong incentives to secure results. Warning signs include requests for unusually high commissions, vague descriptions of services, urgent appointments, refusal to disclose ownership, use of personal bank accounts, or claims that normal procedures cannot be followed. A practical process begins before appointment. Identify the proposed partner and its beneficial owners, assess government connections, verify experience, obtain references, and document the business rationale. The contract should define services, compensation, records, audit access, training expectations, compliance representations, and termination rights. Payments should match documented work, be made to an account in the contracting party’s name, and receive approval through established controls. Ongoing oversight is equally important. A risk-based review may examine invoices, contact reports, deliverables, unusual expenses, government interactions, and changes in ownership or personnel. Re-screening should occur when the relationship changes, a new market or public contract is introduced, or allegations arise. A third party that passed onboarding can still become a risk later. Cross-border operations require attention to local practice without treating custom as a legal defence. Local employees may face pressure to make facilitation payments, while foreign subsidiaries may use informal agents who are familiar with administrative systems. Training should address these realities and provide a clear escalation route for refused permits, threats, extortion demands, and suspicious requests. Testing, Investigating, And Improving ControlsMonitoring should be designed to find failures that routine reporting misses. Compliance teams can sample third-party files, compare commissions with market norms, review expense claims, test approval workflows, and analyse payments for unusual timing or descriptions. Internal audit and compliance should have sufficient independence to challenge commercial teams and report significant issues to appropriate senior leaders. When a concern is raised, the response should protect evidence and avoid premature conclusions. The organisation may need to preserve emails and financial records, suspend a payment or appointment, interview relevant personnel, and assess whether the matter involves other transactions or jurisdictions. Investigations should be appropriately scoped, documented, and conducted with regard to legal privilege and data protection obligations. Remediation is part of demonstrating that procedures are effective. Depending on the findings, the company may retrain staff, strengthen approval thresholds, recover improper payments, terminate a partner, revise incentives, improve whistleblowing channels, or report the matter to authorities. Disciplinary consistency matters: senior employees and high-performing intermediaries should not receive more lenient treatment than junior staff. A compliance programme should evolve after incidents, near misses, audits, acquisitions, market entry, and regulatory developments. Reviewing controls only after a prosecution risk emerges is too late. Management information should identify trends and unresolved actions, allowing leaders to allocate resources before weaknesses become misconduct. Practical Priorities For BusinessesCompanies do not need to build a complex programme overnight, but they should be able to explain how their controls prevent bribery in the activities that matter most. A proportionate starting point includes:
The board should receive reporting that goes beyond the number of people who completed training. Useful indicators include overdue due diligence, rejected or escalated transactions, high-risk third-party concentrations, hotline matters, audit findings, and remediation age. These measures help demonstrate that top-level commitment is active rather than symbolic. The adequate procedures defence is strongest when compliance is integrated into procurement, sales, finance, human resources, legal review, and executive decision-making. It should influence who can be appointed, how payments are made, which transactions require approval, and what happens when an employee raises a concern. Use the UK Bribery Act’s six principles as a practical framework, then tailor them to the organisation’s real exposure. Build an evidence trail, challenge unexplained exceptions, review third-party relationships, and keep controls current as the business changes. A well-governed programme can reduce bribery risk while giving the organisation a credible basis for relying on the adequate procedures defence when misconduct occurs. |