Skip to main content
Category: Anti-Bribery and Corruption

Failure to Prevent Bribery

Also known as: Section 7 offence, Corporate offence of failing to prevent bribery
Simply put

Failure to prevent bribery is a type of corporate criminal offence that holds an organisation liable when a person connected to it (such as an employee, agent, or overseas representative) pays a bribe to win or keep business for that organisation. Unlike traditional bribery charges, the organisation can be prosecuted even if its leadership did not know about or authorise the bribe. Whether such an offence applies, and to whom, depends on the specific law in each jurisdiction.

Formal definition

Failure to prevent bribery is a corporate criminal offence under which a commercial organisation may be held liable where a person 'associated' with it bribes another person intending to obtain or retain business or a business advantage for the organisation. Under section 7 of the UK Bribery Act 2010, this is a strict-liability-style offence subject to a statutory defence that the organisation had 'adequate procedures' in place designed to prevent associated persons from engaging in bribery; UK government guidance published under the Act sets out the policy behind the offence and assists organisations in assessing such procedures. Comparable 'failure to prevent foreign bribery' offences exist in other jurisdictions, for example, Australia enacted such an offence via the Crimes Legislation Amendment (Combatting Foreign Bribery) Act 2024 (inserting section 70.5A into the Criminal Code), but the precise scope, defences, and definition of 'associated person' or 'associate' vary by jurisdiction and statute. This entry is educational and does not constitute legal, audit, or compliance advice; the application of any such offence turns on the facts, the relevant jurisdiction, and professional judgment.

Why it matters

The failure to prevent bribery offence shifts the compliance burden in a fundamental way: an organisation can face corporate criminal liability for a bribe paid by an associated person even where its leadership neither knew of nor authorised the conduct. This changes the risk calculus for boards and compliance functions, because liability does not depend on proving that senior management directed or was aware of wrongdoing. Under the UK model, the practical protection available to an organisation is the statutory 'adequate procedures' defence, which places the burden on the organisation to demonstrate that it had appropriate anti-bribery controls in place, making the design and operating effectiveness of a compliance programme directly relevant to legal exposure.

Enforcement of this type of offence is not merely theoretical. As of May 2025, the UK Serious Fraud Office was reported to be prosecuting a UK-based insurance broker for failing to prevent its overseas agents from bribing, illustrating that the offence reaches conduct by third-party representatives operating abroad. This underscores why organisations with international operations, agents, or intermediaries treat third-party risk as a central compliance concern.

The concept is also spreading beyond the UK. Australia enacted a comparable 'failure to prevent foreign bribery' offence through the Crimes Legislation Amendment (Combatting Foreign Bribery) Act 2024, which inserted section 70.5A into the Criminal Code. However, the precise scope of any such offence, the availability and formulation of defences, and the definition of who counts as an 'associated person' or 'associate' vary by jurisdiction and statute. Organisations should not assume that the UK framework applies uniformly elsewhere; the analysis turns on the relevant law, the facts, and professional judgment.

Who it's relevant to

Boards and audit or risk committees
Because the offence can attach to the organisation regardless of whether directors knew of the bribe, boards and their committees have a strong interest in overseeing the adequacy of the anti-bribery programme. Their role is generally oversight, satisfying themselves that management has designed and maintained appropriate controls, rather than operating the controls themselves. The strength of these procedures can be directly relevant to the availability of a defence under regimes such as the UK Act.
Chief compliance officers and compliance teams
Compliance functions typically own the design, implementation, and monitoring of the anti-bribery procedures that underpin any 'adequate procedures'-style defence. This includes third-party due diligence, training, risk assessment, and controls over agents and intermediaries. Given that reported enforcement has involved bribery by overseas agents, compliance teams generally focus closely on third-party and cross-border risk.
General counsel and legal advisers
Legal teams assess the organisation's exposure under the specific offence that applies in each relevant jurisdiction, because the scope of the offence, the defences available, and the definition of an 'associated person' or 'associate' vary by statute. They also advise on how the organisation would demonstrate the adequacy of its procedures if challenged, and manage engagement with enforcement authorities such as the UK Serious Fraud Office.
Internal audit and assurance functions
Assurance functions typically provide independent evaluation of whether anti-bribery controls are not only well designed but also operating effectively in practice. This independent testing supports the board's oversight and helps the organisation understand whether the procedures it relies on would withstand scrutiny.
Organisations with international operations or third-party representatives
Commercial organisations that use agents, intermediaries, or overseas representatives to obtain or retain business face heightened relevance, since the offence can be triggered by conduct of associated persons acting on the organisation's behalf, including abroad. The extent of exposure depends on which jurisdictions' laws apply and the facts of the relationship.

Inside Failure to Prevent Bribery

Corporate Offence Structure
A 'failure to prevent bribery' offence is typically framed as a corporate criminal offence in which the organisation itself can be liable where a person associated with it commits bribery intending to benefit the organisation. It generally does not require proof that the directing mind of the company knew of or authorised the conduct, distinguishing it from traditional identification-based corporate liability. The precise elements depend on the jurisdiction and statute in question.
Associated Persons
Liability commonly turns on the conduct of persons 'associated with' the organisation, a category that under some statutes is defined broadly to include employees, agents, subsidiaries, and other parties performing services for or on behalf of the organisation. The scope of who qualifies varies by regime and can be fact-dependent.
Adequate or Reasonable Procedures Defence
Such offences are typically paired with a defence available to an organisation that can demonstrate it had procedures in place designed to prevent bribery by associated persons. The threshold is described differently across regimes (for example, 'adequate procedures' or 'reasonable procedures'), and whether procedures meet the standard is generally a question of fact and judgment rather than a fixed checklist.
Jurisdictional Scope and Examples
The concept is most closely associated with the corporate offence in the UK Bribery Act 2010, and comparable 'failure to prevent foreign bribery' offences have been enacted in other jurisdictions, for example, Australia's Crimes Legislation Amendment (Combatting Foreign Bribery) Act 2024, which inserted a failure-to-prevent offence into the Criminal Code. The reach, extraterritorial application, and available defences differ by statute, and organisations should assess exposure against the specific laws applicable to them.
Guidance on Preventive Procedures
Regulators and governments often publish non-binding guidance describing principles that reasonable or adequate anti-bribery procedures may reflect, commonly including proportionate procedures, top-level commitment, risk assessment, due diligence, communication and training, and monitoring and review. This guidance is generally advisory rather than a binding legal standard and does not guarantee a successful defence.
Accountability and Ownership
Preventing bribery is generally a management responsibility executed through the compliance function and business lines (first and second lines), with the board or a relevant committee exercising oversight of the anti-bribery programme. Internal audit or another assurance function typically provides independent assurance over the design and operating effectiveness of controls. These roles are distinct and should not be conflated.

Common questions

Answers to the questions practitioners most commonly ask about Failure to Prevent Bribery.

Does the 'failure to prevent bribery' offence require the organisation itself to have paid or intended a bribe?
No. A common misconception is that the organisation must have knowingly participated in or intended the bribery. The offence is typically structured as a form of strict or corporate liability that can arise where a person associated with the organisation commits bribery intending to benefit it, regardless of whether the organisation's directors or senior management knew of or authorised the conduct. The prosecution generally need not prove intent or knowledge on the part of the organisation. The organisation's protection typically lies in a statutory defence, commonly framed as having 'adequate procedures' or 'reasonable procedures' in place to prevent bribery, rather than in an absence of intent. The precise formulation, and whether the defence is 'adequate' or 'reasonable', depends on the specific jurisdiction and statute, so this entry is educational and not legal advice.
Is this offence something only large multinationals need to worry about?
Not necessarily. Another misconception is that the offence applies only to major multinationals. In many jurisdictions where such an offence exists, it can apply to organisations of a range of sizes and can have extraterritorial reach, for example, capturing conduct connected to an organisation that carries on business in the relevant jurisdiction even where the bribery occurs elsewhere. Whether a particular organisation is within scope depends on how the legislation defines the relevant entity, the associated persons whose conduct is attributed, and the jurisdictional nexus required. Smaller organisations are sometimes expected to have proportionate procedures rather than none. The application to any specific entity is fact- and jurisdiction-dependent.
Who within the organisation owns responsibility for the anti-bribery procedures that support the defence?
Responsibility is typically shared across lines but distinct by function. The board or a relevant committee generally holds oversight responsibility, setting the tone and satisfying itself that an anti-bribery programme exists and is functioning. Management (the first line) generally owns the design and day-to-day operation of the controls and procedures. A compliance function (often part of the second line) typically designs the anti-bribery framework, provides policies, training and advice, and monitors compliance. Internal audit or an equivalent assurance function (third line) may provide independent assurance over the design and operating effectiveness of the procedures. The board should avoid assuming operational duties, and management should not treat the existence of a policy alone as discharging its control responsibilities. Exact allocation depends on the organisation's structure and governance arrangements.
What is generally expected of 'adequate' or 'reasonable' procedures?
Guidance associated with these offences commonly describes procedures as principles-based rather than prescriptive, meaning what is expected is proportionate to the bribery risk the organisation faces. Frequently referenced principles include proportionality of procedures to risk, top-level commitment, risk assessment, due diligence on associated persons, communication and training, and monitoring and review. These are typically articulated in non-binding guidance rather than as a fixed statutory checklist, and satisfying them is a matter of judgement on the facts. Because the standard is contextual, procedures that are adequate for one organisation may not be for another. Organisations should consider obtaining tailored legal advice on how the standard applies to them.
How does risk assessment feed into designing anti-bribery procedures?
A bribery risk assessment typically informs the scope and rigour of the procedures, so that resource and control intensity are directed to areas of higher inherent risk. Practitioners generally distinguish inherent risk (the exposure before controls, driven by factors such as sector, geography, use of intermediaries, and interactions with public officials) from residual risk (the exposure remaining after controls are applied). The assessment usually considers both likelihood and impact separately. The output helps management design proportionate controls and helps the board and compliance function evaluate whether residual bribery risk sits within the organisation's stated risk appetite. Methodologies vary, and the assessment is a matter of professional judgement rather than a fixed formula.
How can an organisation gain assurance that its procedures work, not just that they exist on paper?
Assurance generally requires testing both control design and operating effectiveness, which are distinct. A well-designed procedure that is not consistently operated will not necessarily support a defence. Organisations commonly obtain assurance through management monitoring in the first line, compliance monitoring and testing in the second line, and independent review by internal audit or external specialists in the third line. Evidence such as due diligence records, training completion, gift and hospitality registers, and third-party contract clauses is often reviewed to test whether controls operate as intended. Whether such assurance would satisfy a court assessing an 'adequate' or 'reasonable' procedures defence is ultimately a matter for the relevant legal process and depends on the facts and jurisdiction; this entry is educational and not legal, audit, or compliance advice.

Common misconceptions

A company can only be liable for bribery if senior management or the board knew about or approved it.
A defining feature of failure-to-prevent offences is that, in many formulations, the organisation can be liable for bribery by an associated person without proof that senior management knew of or authorised the conduct. Corporate liability may arise even where leadership was unaware, which is precisely why the concept differs from traditional identification-based liability.
Having an anti-bribery policy on paper is enough to satisfy the defence.
The defence typically depends on procedures that are adequate or reasonable in substance, which is generally assessed as a question of fact. A written policy that is not embedded, risk-based, communicated, and monitored may not meet the standard. Control design and operating effectiveness are distinct, and both may be relevant.
This offence operates identically everywhere.
Failure-to-prevent bribery is a jurisdiction-specific concept. The elements, the definition of associated persons, the applicable defence, and extraterritorial reach vary between statutes such as the UK Bribery Act 2010 and Australia's 2024 offence. Organisations must evaluate their exposure against the specific laws that apply to them rather than assume uniformity.

Best practices

Conduct a documented, periodically refreshed bribery risk assessment that considers the jurisdictions, sectors, transaction types, and third-party relationships to which the organisation is exposed, and use it to prioritise controls proportionately.
Determine which specific failure-to-prevent regimes apply to the organisation given its footprint and associated persons, and obtain qualified legal advice on scope, extraterritorial reach, and the applicable defence standard rather than assuming a single global rule.
Extend due diligence and contractual anti-bribery controls to associated persons, including agents, intermediaries, and subsidiaries, recognising that the organisation's exposure can flow from their conduct.
Evidence top-level commitment and clear accountability: assign management ownership of the anti-bribery programme, provide the board or relevant committee with regular oversight information, and preserve independent assurance over the programme.
Test both the design and the operating effectiveness of anti-bribery controls, and retain documentation of training, communication, monitoring, and remediation so the organisation can demonstrate procedures in practice, not only on paper.
Review and update procedures in response to changes in law, business activities, and risk assessment findings, treating adequacy or reasonableness as an ongoing standard rather than a one-time exercise.