Skip to main content
Category: Anti-Bribery and Corruption

Adequate Procedures

Also known as: Adequate Procedures Defence
Simply put

"Adequate procedures" refers to the anti-bribery measures a company can put in place to help prevent bribery being committed on its behalf. Under the UK Bribery Act 2010, if a company can show it had adequate procedures in place, this can serve as a defence against a charge that it failed to prevent bribery. What counts as adequate is not a fixed checklist and generally depends on the organisation's specific circumstances.

Formal definition

Under the UK Bribery Act 2010, "adequate procedures" is the statutory defence available to a commercial organisation charged with the corporate offence of failing to prevent bribery; the organisation bears the burden of proving that it had procedures in place designed to prevent associated persons from committing bribery on its behalf. The defence is referenced in section 7(2) of the Act. The concept is principles-based rather than prescriptive, meaning what is "adequate" is assessed against the organisation's particular risk profile and circumstances rather than a uniform standard; published guidance exists to help organisations understand and implement appropriate anti-bribery controls. This entry addresses the UK Bribery Act regime specifically and is educational rather than legal or compliance advice; application depends on the facts, the organisation's circumstances, and professional judgment.

Why it matters

The "adequate procedures" defence is significant because it directly shapes how a commercial organisation manages its exposure to the corporate offence of failing to prevent bribery under the UK Bribery Act 2010. Where an organisation is charged with this offence, the availability of the defence means that the quality and design of its anti-bribery programme becomes central to whether it can avoid liability. Importantly, the burden rests on the organisation to prove that it had procedures in place designed to prevent associated persons from committing bribery on its behalf, which makes documented, well-designed controls a matter of practical importance rather than an optional exercise.

Because the concept is principles-based rather than a fixed checklist, what qualifies as "adequate" generally depends on the organisation's particular risk profile and circumstances. This means there is no single template that guarantees compliance; a set of procedures that is proportionate for one organisation may be insufficient for another operating in a higher-risk sector or geography. Published guidance exists to help organisations understand and implement appropriate anti-bribery controls, but ultimately the assessment turns on the facts and requires professional judgment.

For governance and compliance professionals, the defence reinforces that anti-bribery efforts are not simply about having a policy on paper but about being able to demonstrate that procedures were genuinely designed to address the organisation's specific bribery risks. This entry addresses the UK Bribery Act regime specifically and is educational rather than legal or compliance advice.

Who it's relevant to

Chief Compliance Officers
Compliance leaders are typically responsible for designing, implementing, and maintaining the anti-bribery procedures on which the defence depends. Because adequacy is assessed against the organisation's specific risk profile, they generally need to ensure procedures are proportionate, documented, and capable of being evidenced should the organisation ever need to rely on the section 7(2) defence.
General Counsel and Legal Advisers
Legal teams advise on the scope and application of the failure-to-prevent offence and the availability of the adequate procedures defence. Given that the organisation bears the burden of proving the defence, they play a key role in interpreting how the principles-based standard applies to the organisation's particular facts and circumstances.
Boards and Audit or Risk Committees
Directors and their committees hold oversight responsibility for the organisation's approach to bribery risk, though the operational implementation of procedures generally sits with management. They typically seek assurance that anti-bribery controls are designed appropriately for the organisation's risk profile, without themselves owning the day-to-day execution of those procedures.
Internal Audit and Assurance Functions
Assurance providers may be called upon to assess whether anti-bribery procedures are designed effectively and operating as intended. Because adequacy depends on the organisation's circumstances rather than a fixed checklist, their evaluations generally consider whether controls are proportionate to the identified bribery risks.

Inside Adequate Procedures

Top-Level Commitment
A demonstrable commitment from senior management and, where relevant, the board to prevent the conduct in question and to foster a culture in which such conduct is unacceptable. This is typically described as tone from the top and is a foundational element in many anti-bribery compliance frameworks.
Risk Assessment
A periodic, informed, and documented assessment of the nature and extent of the risks the organisation is exposed to. The assessment generally considers factors such as country, sector, transaction, business opportunity, and business partnership risks, and its findings inform the design of proportionate procedures.
Proportionality
The principle that procedures should be proportionate to the risks faced and to the nature, scale, and complexity of the organisation's activities. What is adequate for a large multinational will generally differ from what is adequate for a smaller enterprise; this is a fact-specific judgment rather than a fixed checklist.
Due Diligence
Risk-based due diligence procedures applied to persons who perform or will perform services for or on behalf of the organisation, in order to mitigate identified risks. The depth of due diligence is typically calibrated to the level of assessed risk.
Communication and Training
Steps to ensure that policies and procedures are embedded and understood throughout the organisation, generally through internal and external communication and proportionate training. This supports the operating effectiveness of controls, not merely their design.
Monitoring and Review
Ongoing monitoring and review of procedures, with improvements made as necessary. This reflects the expectation that adequate procedures are not static but respond to changes in the risk profile and to lessons learned.

Common questions

Answers to the questions practitioners most commonly ask about Adequate Procedures.

Does having a written compliance policy mean an organisation automatically has 'adequate procedures'?
No. A written policy is only one element and, on its own, is generally insufficient. The 'adequate procedures' concept, most closely associated with the UK Bribery Act as a defence to the corporate offence of failing to prevent bribery, typically looks at whether prevention measures are proportionate, embedded, and operating in practice, not merely documented. Adequacy is assessed on the facts of each case and depends on the organisation's size, sector, and risk profile. Whether procedures qualify as a defence is ultimately a matter for a court and legal judgement, so this should not be treated as legal advice.
Are 'adequate procedures' a fixed checklist that applies identically to every organisation?
No. There is no universal, one-size-fits-all checklist. Guidance associated with the concept is typically principles-based and risk-driven, meaning what is adequate for a large multinational may differ substantially from what is adequate for a small enterprise with limited exposure. The emphasis is generally on proportionality to the bribery risks an organisation actually faces. Because adequacy is fact- and jurisdiction-dependent, procedures should be tailored rather than copied from a template, and professional judgement is required.
Which function should own the design and operation of anti-bribery procedures?
Accountability generally sits with the board and senior management for setting the tone and overseeing that procedures exist and function, while day-to-day design and operation typically rest with management, often supported by the compliance function. Under a three-lines model, first-line management owns and operates the controls, the second-line compliance function may set standards and monitor, and internal audit may provide independent assurance over design and operating effectiveness. The board's role is generally oversight rather than operational execution; these responsibilities should be defined clearly to avoid gaps.
How does a risk assessment inform what procedures are needed?
A risk assessment is typically treated as the foundation for proportionate procedures. It generally involves identifying where bribery exposure arises, for example across markets, sectors, transactions, business partners, and intermediaries, and evaluating likelihood and impact so that controls can be focused where inherent risk is highest. The output usually shapes decisions on due diligence, controls, training, and monitoring. Assessments are commonly revisited periodically and when circumstances change, since risk profiles evolve; the specifics depend on the organisation's own facts and judgement.
What role does due diligence on third parties play?
Third-party relationships, such as agents, distributors, and other intermediaries, are frequently a significant source of bribery exposure, so proportionate, risk-based due diligence is generally regarded as an important element. This typically means applying greater scrutiny to higher-risk relationships and jurisdictions, and considering contractual protections and ongoing monitoring rather than a one-time check. The appropriate depth of due diligence depends on the assessed risk, and organisations should apply their own judgement rather than a uniform standard.
How can an organisation demonstrate that its procedures are operating effectively, not just designed on paper?
Demonstrating operating effectiveness generally requires evidence that controls function in practice over time, not merely that they were designed. Organisations typically rely on monitoring and review, testing, records of training completion and due diligence, escalation and speak-up mechanisms, and periodic reassessment as risks change. Internal audit or another independent function may provide assurance over both control design and operating effectiveness. Maintaining documentation and evidence of these activities is generally important, though whether they would be considered adequate in a given matter is a fact-specific question and not something this entry can resolve.

Common misconceptions

Having a written anti-bribery policy in place means an organisation automatically has adequate procedures.
A documented policy addresses control design but not necessarily operating effectiveness. Adequacy generally depends on whether procedures are proportionate to assessed risk and are communicated, embedded, and reviewed in practice. Whether procedures are adequate in a given case is typically a fact-specific determination and, ultimately, a matter for a court or the relevant authority to assess.
Adequate procedures is a universal, one-size-fits-all standard that applies identically to every organisation and jurisdiction.
The concept is rooted in specific anti-bribery legislation and associated guidance, and its precise application varies by jurisdiction, sector, and entity type. The principle of proportionality means what counts as adequate differs with the organisation's size, complexity, and risk exposure; requirements and terminology may differ or not exist at all in other legal regimes.
Responsibility for adequate procedures rests entirely with the compliance function.
Top-level commitment is generally described as a duty of senior management and, where appropriate, the board, while day-to-day operation of controls typically sits with management across the business. Compliance often designs, coordinates, and monitors the programme, but accountability for tone and oversight is distinct from the operational ownership of individual controls.

Best practices

Conduct and document a periodic, risk-based assessment that considers relevant country, sector, transaction, and business-partner risks, and use its findings to justify the scope of your procedures.
Calibrate procedures to the organisation's assessed risk, size, and complexity rather than adopting a generic template, and retain a record of the proportionality reasoning behind key design choices.
Secure visible top-level commitment from senior management and the board, and separate that oversight responsibility from management's operational ownership of individual controls so accountability is clear across functions.
Apply due diligence to third parties and intermediaries on a risk-sensitive basis, deepening scrutiny where the assessed risk is higher and documenting the rationale for the approach taken.
Communicate policies and deliver proportionate training so procedures are embedded in practice, and periodically test operating effectiveness rather than relying on the existence of written controls alone.
Monitor and review procedures on an ongoing basis, updating them in response to changes in the risk profile, and confirm the current statutory and guidance position in the relevant jurisdiction with qualified counsel, as this entry is educational and not legal, audit, or compliance advice.