UK Bribery Act and Anti-Bribery Compliance for Business
Anti-Bribery in Brief
- Bribery Act 2010 - active and passive bribery, bribing a foreign public official, failure to prevent
- Adequate procedures defence under section 7
- ISO 37001 gives a recognised framework
What the Bribery Act Covers
The Bribery Act 2010 is the principal anti-bribery legislation in the UK and one of the most extra-territorial pieces of legislation of its kind anywhere - it reaches UK organisations wherever in the world the bribery takes place, and non-UK organisations carrying on any part of their business in the UK. It is a short piece of legislation with very broad reach. It creates four offences: bribing another person (Section 1), being bribed (Section 2), bribery of foreign public officials (Section 6), and the corporate offence of failure to prevent bribery (Section 7). It is the last one that creates the strict liability position most organisations need to think about.
Under Section 7, a commercial organisation is guilty of an offence if a person associated with it bribes another person intending to obtain or retain business or a business advantage for the organisation. The only defence is that the organisation had adequate procedures in place to prevent bribery. There is no minimum size threshold and no upper limit on penalties - convictions have included unlimited fines and director disqualification.
"Associated person" is wider than employees. It includes contractors, agents, intermediaries, joint venture partners and anyone performing services for or on behalf of the organisation. The procedures the organisation puts in place need to cover all of these, not just direct staff.
Bribery in Day-to-Day Operations
Bribery in practice rarely looks like a brown envelope full of cash. The more common cases involve disproportionate hospitality, lavish gifts, fees paid to consultants whose role is to "help things along" with a foreign official, charitable donations made in suspicious circumstances, or facilitation payments to speed up routine government services. Facilitation payments are explicitly prohibited under the Act, even where they are common practice in another jurisdiction.
Most bribery in normal businesses is not what folk picture. It is the supplier sending a member of staff to a sporting event when a contract is being negotiated. It is the £200 bottle of whisky at Christmas to the procurement manager. It is the consultant on retainer in a country where decisions are taken in a particular way. None of these are obviously corrupt - they are normal business behaviours that become bribery the moment they are intended to influence a decision improperly. The test is intent, not the size of the gift.
When I audit anti-bribery, I look for four pieces of evidence. A current anti-bribery policy with top management visibly behind it. A risk assessment that has actually been done - not a generic template but one that reflects the organisation's exposures. A gifts and hospitality register with entries in it, because an empty register is a sign nobody is using it rather than evidence of a clean operation. And due diligence records on associated persons - particularly third parties used in higher-risk territories or sectors.
What I do not expect to see is perfection. I expect to see an organisation that has thought about its risks and put proportionate controls in place. The Section 7 defence is adequate procedures, not perfect procedures.
For organisations certified to ISO 37001, the anti-bribery management system is the formal answer to Section 7. The standard sets out the leadership, risk assessment, policy, due diligence, financial controls, training and monitoring activities that together demonstrate adequate procedures. Most organisations do not need the full certified standard - the same elements scaled appropriately for the organisation's risk are what proportionate compliance looks like.
The Six Principles of Adequate Procedures
The Ministry of Justice guidance to the Bribery Act 2010 sets out six principles that adequate procedures should be built around. These are the framework most organisations use to demonstrate compliance, and the same framework underpins ISO 37001:
- Proportionate procedures - the response should match the bribery risk the organisation faces and the size and nature of its business
- Top-level commitment - leadership visibly establishes a culture in which bribery is unacceptable
- Risk assessment - the organisation periodically assesses where its exposure lies, by territory, sector, transaction type, business partner and other relevant factors
- Due diligence - proportionate checks on associated persons before engaging them
- Communication and training - the policy is communicated to all those who need to know about it, with training proportionate to the risk
- Monitoring and review - procedures are reviewed and improved over time, including in response to changes in risk
Failure to Prevent - The Wider Pattern
The Section 7 corporate offence in the Bribery Act 2010 was the first of a series. The same pattern - strict corporate liability with an "adequate" or "reasonable" procedures defence - now appears in:
- Section 7 Bribery Act 2010 - failure to prevent bribery
- Sections 45 and 46 of the Criminal Finances Act 2017 - failure to prevent the facilitation of UK and foreign tax evasion
- Section 199 of the Economic Crime and Corporate Transparency Act 2023 - failure to prevent fraud, in force from 1 September 2025 for large organisations
Organisations meeting the bar for one tend to meet the bar for the others, since the underlying control framework is the same. The anti-bribery policy and risk assessment will normally extend naturally to cover tax evasion and fraud prevention, with sector and transaction-type specifics added as needed.
Practical Controls in Most Organisations
The control framework that satisfies the Act for most non-high-risk organisations covers:
- An anti-bribery policy, signed off by top management and communicated through the staff handbook and induction
- A gifts and hospitality register, with thresholds for declaration and approval
- A bribery risk assessment, reviewed periodically and after significant changes
- Due diligence on third parties, scaled to the risk - light-touch for low-risk UK suppliers, more involved for agents in higher-risk territories or sectors
- Whistleblowing arrangements that allow concerns to be raised confidentially
- Training proportionate to roles - basic awareness for all staff, more detailed for sales, procurement and senior managers
- Sign-off processes for charitable and political donations
- Disciplinary action for breaches, made explicit in the staff handbook
International Context
Although the Bribery Act 2010 is UK legislation, organisations operating internationally also need to be aware of:
- The US Foreign Corrupt Practices Act 1977 (FCPA), which has similar reach for US-connected entities
- The OECD Anti-Bribery Convention, which has driven similar legislation in 40+ signatory countries
- Local anti-corruption laws in territories of operation - some require additional record-keeping or registration steps
Where multiple regimes apply, the practical answer is to design controls to the highest applicable standard. The Bribery Act standard will typically meet or exceed most others.
Practical Advice
For most organisations, the anti-bribery framework is built from the policy, the risk assessment and the gifts and hospitality register, supported by the staff handbook content and the third-party due diligence approach in the procurement process. The ISO 37001 toolkit provides the documented elements that together demonstrate adequate procedures under Section 7.
Where the organisation operates in higher-risk sectors - construction, defence, extractives, pharmaceuticals - or in higher-risk territories, the depth of due diligence and the frequency of review should be scaled accordingly.
| alphaZ document | How to use it |
|---|---|
| ISO 37001 Anti-Bribery Toolkit | The full anti-bribery management system toolkit, aligned with ISO 37001. Includes the policy, risk assessment template, gifts and hospitality register, due diligence framework and supporting procedures. |
| P-10 Anti-Bribery and Corruption Policy | The standalone anti-bribery policy where the full toolkit is more than the organisation needs. Sets out the prohibition on bribery, gifts and hospitality rules, reporting obligations and consequences of breach. |
| ER9 Legal Register | The legal register entry for the Bribery Act 2010 sits here, with the Criminal Finances Act 2017 and the Economic Crime and Corporate Transparency Act 2023 alongside as the related strict-liability offences. |
| F-IMS23 Opportunities and Risks Register | Where bribery risk is recorded as part of the wider risk picture, with the controls in place to mitigate it referenced from the register. |
Note: subscribers to alphaZ documents can download all of the documents above as part of the subscription.
Frequently Asked Questions
Yes, with no minimum size threshold. A sole trader, a partnership and a multinational are all caught by the same Act. The procedures expected are proportionate to the size and risk of the business - a small UK consultancy would not be expected to have the same controls as a global engineering firm operating in higher-risk territories - but the Section 7 corporate offence applies equally. The phrase used in the Ministry of Justice guidance is "adequate procedures", and what is adequate scales with risk.
No. Reasonable and proportionate hospitality offered as part of normal business relationships is not bribery. The legal test is whether the gift or hospitality is intended to induce improper performance of a function or activity. A modest business lunch with a long-standing supplier is not bribery; a £2,000 weekend trip offered to the procurement decision-maker during a tender is. Most organisations set internal thresholds - typical examples are a declaration requirement above £25 to £50 and an approval requirement above £100 to £250 - to put a clear line in place rather than relying on individual judgement.
Most organisations do not. Certification to ISO 37001 is a useful demonstration of anti-bribery controls for organisations operating in higher-risk sectors or for those tendering for contracts that require it. For a typical SME, the Section 7 defence of adequate procedures is met by following the same six principles the standard is built on, without going through formal certification. The documented evidence - policy, risk assessment, register, due diligence records, training records - is what counts.
Facilitation payments - small payments to officials to secure or speed up routine actions they are already obliged to perform - are prohibited under the Bribery Act 2010, with no exception. This is stricter than the US Foreign Corrupt Practices Act 1977, which has a narrow facilitation payment exception. UK organisations operating internationally need to apply the UK position even where local practice differs, and should give staff travelling to higher-risk territories specific guidance on what to do if asked for one. Genuine duress - payments made under threat of safety, for example - is treated differently and should be reported promptly.
The three sit on the same control framework. Anti-bribery, anti-fraud and anti-money laundering all rely on the same elements - tone from the top, risk assessment, due diligence, financial controls, training, whistleblowing and monitoring - so a well-designed framework satisfies all three with the policy and risk content extended to cover each. The strict-liability corporate offences for these (Section 7 Bribery Act 2010, Section 45/46 Criminal Finances Act 2017, Section 199 Economic Crime and Corporate Transparency Act 2023) all use the same "reasonable procedures" defence concept.
UK Legislation
- Bribery Act 2010
- Criminal Finances Act 2017
- Economic Crime and Corporate Transparency Act 2023
- Money Laundering, Terrorist Financing and Transfer of Funds (Information on the Payer) Regulations 2017
- Proceeds of Crime Act 2002
