Skip to main content
Category: Anti-Bribery and Corruption

UK Bribery Act

Also known as: Bribery Act 2010, UK Bribery Act 2010
Simply put

The UK Bribery Act 2010 is an Act of the UK Parliament and the country's main anti-corruption law, covering the criminal law relating to bribery. It generally defines a bribe as an advantage given to influence a person in carrying out their duties, and it creates offences relating to both giving and receiving bribes. The Act also encourages commercial organisations to put procedures in place to prevent bribery.

Formal definition

The Bribery Act 2010 (c. 23) is a statute of the Parliament of the United Kingdom that makes provision about offences relating to bribery. It sets out criminal offences that typically include bribing another person, being bribed, and connected conduct, and it is generally regarded as the UK's principal anti-corruption legislation. Under the Act, a bribe is broadly characterised as an advantage offered or given to improperly influence a person in the carrying out of their functions. The Act is accompanied by government guidance (including Ministry of Justice guidance published as the Act came into force) intended to help commercial organisations understand the legislation and the procedures they can adopt to prevent bribery. This entry summarises the Act at a high level based on the cited sources; specific offence elements, defences, penalties, and the extent of extraterritorial application depend on the precise statutory provisions and the facts of a given matter, and this is educational information rather than legal advice.

Why it matters

The UK Bribery Act 2010 is generally regarded as the United Kingdom's principal anti-corruption legislation, covering the criminal law relating to bribery. For organisations, its significance lies in how broadly it characterises a bribe, as an advantage offered or given to improperly influence a person in the carrying out of their functions, and in the fact that it creates criminal offences relating to both the giving and the receiving of bribes. This means that bribery risk is not an abstract reputational concern but a matter of potential criminal liability that boards and compliance functions are expected to take seriously.

A distinctive feature of the Act, and a key reason it matters for commercial organisations, is that it encourages them to put procedures in place to prevent bribery. Alongside the Act, the government published guidance (including Ministry of Justice guidance released as the Act came into force) intended to help commercial organisations understand the legislation and the sorts of procedures they can adopt to manage bribery risk. This links the criminal law directly to the design of an organisation's internal compliance controls, making anti-bribery procedures a governance and compliance priority rather than solely a legal-technical question.

The practical importance of the Act therefore extends across the organisation: it shapes how compliance programmes are designed, how third-party relationships are assessed, and how boards and management demonstrate that they have taken bribery prevention seriously. The specific offence elements, available defences, penalties, and the extent of extraterritorial application depend on the precise statutory provisions and the facts of a given matter, so organisations typically seek qualified legal advice when applying the Act to their circumstances.

Who it's relevant to

Boards and audit or risk committees
Directors and the committees that support them typically hold oversight responsibility for the organisation's overall approach to bribery risk. While the board does not usually run day-to-day compliance activities, it generally has an interest in satisfying itself that management has put appropriate anti-bribery procedures in place, given that the Act encourages commercial organisations to adopt such procedures and creates criminal offences relating to bribery.
Chief compliance officers and compliance functions
Compliance functions are typically responsible for designing, implementing, and monitoring the procedures an organisation adopts to prevent bribery. The government guidance accompanying the Act, including the Ministry of Justice guidance, is directly relevant to this work, as it is intended to help commercial organisations understand the legislation and the sorts of preventive procedures they can put in place.
General counsel and legal advisers
Because the Bribery Act is primary criminal legislation, legal advisers are central to interpreting how its offences and provisions apply to a specific organisation and set of facts. Determining the precise offence elements, potential defences, penalties, and extraterritorial reach depends on the statutory provisions and the circumstances, which generally calls for qualified legal judgment.
Internal auditors and assurance providers
Assurance functions may be asked to evaluate whether an organisation's anti-bribery procedures are appropriately designed and operating as intended. This provides independent input on how effectively the preventive measures encouraged by the Act and its accompanying guidance have been embedded, distinct from the compliance function that owns and operates those procedures.
Commercial organisations and their management
The Act specifically encourages commercial organisations to put procedures in place to prevent bribery, and the accompanying guidance is aimed at helping them do so. Management is typically responsible for operating these procedures across the business, including in relationships and activities that may expose the organisation to bribery risk.

Inside UK Bribery Act

General offences of bribery
The Act generally addresses both offering, promising or giving a bribe (active bribery) and requesting, agreeing to receive or accepting a bribe (passive bribery), covering conduct by individuals and organisations.
Bribery of foreign public officials
A distinct offence typically concerned with bribing officials of foreign governments or public bodies to obtain or retain business or a business advantage. Practitioners should verify the precise scope against the statutory text and jurisdiction-specific facts.
Corporate failure to prevent bribery
The Act is generally understood to create a corporate offence where a commercial organisation fails to prevent bribery committed by an associated person on its behalf. This is a strict-liability-style provision subject to a defence discussed below; confirm applicability to a specific entity type and facts.
Adequate procedures defence
For the corporate failure-to-prevent offence, an organisation may generally have a defence where it can demonstrate it had adequate procedures in place designed to prevent bribery. The threshold is fact-specific and assessed against the organisation's risk profile.
Extraterritorial reach
The Act is generally regarded as having significant extraterritorial application, potentially capturing organisations that carry on business in the relevant jurisdiction regardless of where the conduct occurred. The precise reach depends on statutory wording and facts, and legal advice should be sought.

Common questions

Answers to the questions practitioners most commonly ask about UK Bribery Act.

Does the UK Bribery Act only apply to companies based in the United Kingdom?
No. A common misconception is that the Act reaches only UK-incorporated entities operating domestically. In practice, the legislation generally has a broad extraterritorial dimension: certain offences can be committed by individuals or organisations with a connection to the UK regardless of where the conduct occurred, and the corporate offence of failing to prevent bribery can apply to commercial organisations that carry on business, or part of a business, in the UK even if they are incorporated elsewhere. The precise scope depends on the facts, the specific offence in question, and how the relevant provisions apply to a given entity, so organisations should treat this as a matter for professional legal advice rather than assume geography alone determines exposure. This entry is educational and not legal advice.
Is the corporate 'failure to prevent bribery' offence the same as being found guilty of paying a bribe?
No. These are distinct concepts that are often conflated. Being liable for actively giving, offering, or accepting a bribe is different from the separate corporate offence concerned with an organisation's failure to prevent bribery carried out on its behalf. The latter typically focuses on whether an organisation had procedures in place, rather than on proving the organisation itself intended to bribe. Because the two rest on different elements and different considerations, they should not be treated as interchangeable. How each applies in a specific situation depends on the facts and is a question for qualified legal counsel.
What role should the board play in overseeing an organisation's anti-bribery arrangements?
Boards generally hold an oversight responsibility rather than an operational one. That typically means setting the tone from the top, satisfying themselves that management has established proportionate anti-bribery arrangements, and receiving assurance on how those arrangements are working, without themselves running the day-to-day controls. The design, implementation, and operation of specific procedures usually sit with management, while independent assurance may be provided by internal audit or another assurance function. The appropriate allocation of these duties depends on the organisation's size, structure, and governance framework, and on applicable legal and professional requirements.
Who within an organisation typically owns anti-bribery procedures, and how does that differ from assurance over them?
Ownership and assurance are separate. Management generally owns and operates anti-bribery procedures as part of the first and second lines of defence, for example, business units performing controls and a compliance function designing and monitoring them. Assurance functions such as internal audit typically provide independent evaluation of whether those procedures are designed appropriately and operating effectively, but do not own the controls themselves. Keeping these responsibilities distinct helps avoid the conflict that arises when the same function both operates and independently assures a control. The exact structure varies by entity type and sector.
How might an organisation approach assessing bribery risk in a proportionate way?
Organisations commonly begin with a risk assessment that considers where bribery exposures may arise, such as jurisdictions of operation, use of third parties and intermediaries, sectors, and transaction types, before designing controls. It can be useful to distinguish inherent exposure (before controls) from residual exposure (after controls are applied), and to focus effort where risk is greatest rather than applying uniform measures everywhere. What counts as proportionate depends on the organisation's size, nature, and circumstances, and on any applicable guidance and legal requirements. This is a matter for the organisation's own judgment and professional advice.
What is the difference between designing an anti-bribery control and demonstrating that it operates effectively?
Control design and operating effectiveness are distinct considerations. Design concerns whether a procedure, if it works as intended, would adequately address the identified bribery risk, for example, a third-party due diligence process on paper. Operating effectiveness concerns whether the control actually functions consistently in practice over time, evidenced by records, testing, and monitoring. A well-designed procedure that is not applied consistently may still leave exposure. Assurance activity generally examines both dimensions, and the evidence relied upon depends on the control and the organisation's own approach.

Common misconceptions

Anti-bribery compliance is solely a legal or compliance function responsibility.
Effective anti-bribery arrangements typically span the three lines: management (first line) owns and operates controls in the business, compliance (second line) sets policy and monitors, and internal audit (third line) provides independent assurance. The board or its relevant committee generally retains oversight, not day-to-day operational, responsibility. Accountability should be mapped explicitly rather than assumed to rest with one function.
Having a written anti-bribery policy is enough to establish a defence.
A policy document alone is generally insufficient. The adequate procedures concept is fact-specific and typically concerns whether procedures are proportionate to risk and effective in operation, not merely designed on paper. This mirrors the distinction between control design and operating effectiveness.
The Act only affects organisations located in the relevant jurisdiction.
The Act is generally understood to have extraterritorial features that can capture organisations carrying on business there even where conduct occurs elsewhere. Whether a specific entity is in scope depends on the statutory wording, entity type, and facts, and warrants qualified legal analysis.

Best practices

Conduct and periodically refresh a bribery risk assessment that considers the organisation's markets, sectors, third-party relationships and transaction types, so that procedures can be shown to be proportionate to actual risk.
Distinguish control design from operating effectiveness: document procedures clearly and separately test whether they operate as intended, retaining evidence of both.
Clarify roles and accountability across the three lines, with the board or a designated committee exercising oversight and management owning day-to-day controls, and confirm this allocation is documented.
Apply risk-based due diligence to associated persons such as agents, intermediaries and business partners, given the corporate failure-to-prevent exposure.
Provide targeted training and clear communication channels, including a route to raise concerns, and monitor uptake and effectiveness rather than assuming completion equals understanding.
Obtain qualified legal advice on the Act's scope and extraterritorial reach for the specific entity type and facts, treating this entry as educational rather than legal, audit or compliance advice.