Bribery Act 2010 (c. 23) with the Ministry of Justice guidance on adequate procedures (section 9)
SmartSuite provides the system for managing controls, evidence, mappings, assessments, and reporting. Framework text may require a separate license unless explicitly provided.
Overview
The Bribery Act 2010 is an Act of the UK Parliament, given Royal Assent on 8 April 2010 and in force from 1 July 2011, that makes provision about offences relating to bribery. It creates general offences of bribing another person (section 1) and being bribed (section 2), a separate offence of bribery of foreign public officials (section 6), and a corporate offence of failure of commercial organisations to prevent bribery by persons associated with them (section 7).
The Act is enforced in England and Wales by the Serious Fraud Office and the Crown Prosecution Service, with consent to prosecution required under section 10, and it has territorial reach under section 12 to conduct outside the United Kingdom by persons with a close connection to the UK and to commercial organisations that carry on business or part of a business in the UK. Section 9 required the Secretary of State to publish guidance on procedures that relevant commercial organisations can put in place to prevent bribery, and the Ministry of Justice published that guidance in 2011.
Commercial organisations implement the Act by adopting adequate procedures built on the six principles in the Ministry of Justice guidance: proportionate procedures, top-level commitment, risk assessment, due diligence, communication including training, and monitoring and review. Under section 7 it is a defence for the organisation to prove that it had in place adequate procedures designed to prevent persons associated with it from undertaking bribery.
Why it Matters
Section 7 makes a commercial organisation strictly liable for bribery by its employees, agents, subsidiaries, and other associated persons anywhere in the world, with adequate procedures as the only defence. Penalties under section 11 include imprisonment of up to ten years for individuals and unlimited fines, and the Act applies to any organisation that carries on business in the UK, wherever the bribery occurs.
Key benefits include:
- Establish the section 7 defence
Put in place and evidence adequate procedures designed to prevent bribery by associated persons, the only defence to the corporate offence.
- Manage global exposure
Cover conduct outside the UK by employees, agents, and subsidiaries that section 12 brings within the Act.
- Set expectations from the top
Demonstrate top-level commitment to preventing bribery and a culture in which bribery is never acceptable.
- Apply proportionate, risk-based controls
Scale procedures to the bribery risks the organisation faces and to the nature, scale, and complexity of its activities.
- Control third parties
Apply due diligence to persons who perform services for or on behalf of the organisation, including agents, intermediaries, and joint ventures.
How it Works
Sections 1 to 5 define the general offences and the improper performance and expectation tests that decide whether an advantage is a bribe. Section 6 covers bribery of a foreign public official to obtain or retain business. Section 7 creates the corporate offence for relevant commercial organisations, section 8 defines an associated person as one who performs services for or on behalf of the organisation, and section 9 requires guidance on preventing bribery. Sections 10 to 15 address consent to prosecution, penalties, territorial application, defences for certain bribery offences, and liability of corporate officers and partnerships.
Organisations implement the Act by running a bribery risk assessment, adopting an anti-bribery policy and procedures approved by the board, conducting due diligence on agents, intermediaries, and business partners, controlling gifts, hospitality, donations, and facilitation payments, training staff and associated persons, providing reporting channels, and monitoring and reviewing the procedures. The Ministry of Justice guidance explains each of the six principles with commentary and case studies and stresses that procedures should be proportionate rather than a fixed checklist.
SmartSuite operationalizes the Act by holding the six principles and the section 7 defence as a requirement set linked to the risk assessment, policies, third-party due diligence, gifts and hospitality registers, training records, and monitoring reviews, with owners, dates, and an audit trail that evidences adequate procedures.
Key Elements
- General bribery offences (sections 1 and 2)
Offering, promising, or giving an advantage, or requesting, agreeing to receive, or accepting one, in connection with the improper performance of a relevant function or activity.
- Bribery of foreign public officials (section 6)
Offering, promising, or giving an advantage to a foreign public official to influence them in their official capacity in order to obtain or retain business or a business advantage.
- Failure to prevent bribery (section 7)
A relevant commercial organisation is guilty if an associated person bribes another intending to obtain or retain business or an advantage for the organisation, unless it proves it had adequate procedures.
- Associated persons (section 8)
Any person who performs services for or on behalf of the organisation, including employees, agents, and subsidiaries, determined by all the relevant circumstances.
- Six principles of adequate procedures (section 9 guidance)
Proportionate procedures, top-level commitment, risk assessment, due diligence, communication including training, and monitoring and review.
- Penalties and prosecution (sections 10 and 11)
Prosecution requires the consent of the Director of Public Prosecutions or the Director of the Serious Fraud Office; individuals face up to ten years imprisonment and organisations an unlimited fine.
- Territorial application (section 12)
The offences apply to conduct outside the UK by persons with a close connection to the UK, and section 7 applies to any organisation carrying on business or part of a business in the UK.
Framework Scope
The Act applies to individuals and to bodies corporate and partnerships that are incorporated or formed in the United Kingdom or that carry on a business or part of a business there, wherever the bribery takes place. It covers bribery in both the public and private sectors and is implemented by legal, compliance, procurement, sales, and finance functions in organisations of every size, with the guidance stressing proportionality for smaller organisations.
Framework Objectives
Parliament enacted the Bribery Act to make provision about offences relating to bribery and to give the UK a modern, consolidated anti-bribery law.
Replace the earlier common law and statutory bribery offences with clear general offences of bribing and being bribed.
Criminalise the bribery of foreign public officials in line with the UK's international commitments.
Make commercial organisations liable for failing to prevent bribery by their associated persons.
Encourage organisations to adopt adequate procedures by making them the defence to the corporate offence.
Extend the offences to conduct abroad by persons and organisations connected to the UK.
Provide guidance, through section 9, on the procedures organisations can put in place to prevent bribery.
Framework in Context
The Bribery Act is the UK counterpart of the U.S. Foreign Corrupt Practices Act, and organisations subject to both align their programmes to the six Ministry of Justice principles and the DOJ's compliance program expectations at once. Its adequate procedures map to the anti-bribery management system in ISO 37001 and the compliance management system in ISO 37301, and to the seven requirements of USSG §8B2.1, while UK-regulated firms connect it to their FCA and PRA systems and controls obligations.
Common Framework Mappings
Organisations map the section 7 defence and the six principles to the anti-corruption laws, management system standards, and compliance program benchmarks their programme must also satisfy so that one set of procedures and evidence serves all of them.
Mapped frameworks include:
FCPA
DOJ ECCP
USSG §8B2.1
ISO 37001:2016
ISO 37301:2021
ISO 31000:2018
COSO IC 2013
UK GDPR
SOX
OCEG Red Book 3.5
IIA Three Lines Model
- ClassificationCategoryAnti-Bribery and CorruptionDomainRisk ManagementFramework FamilyOther
- Regulatory ContextTypeRegulationLegal InstrumentAct of ParliamentSectorCross-SectorIndustryCross-Industry
- Region / PublisherRegionUnited KingdomRegion DetailUnited KingdomPublisherUK Parliament; guidance by the Ministry of Justice (MoJ)
- VersioningVersionBribery Act 2010 (c. 23); MoJ guidance published 2011Effective DateJuly 1, 2011Issue DateApril 8, 2010 (Royal Assent)
- AdoptionAdoption ModelRegulatory ComplianceImplementation ComplexityHigh
- Official ReferenceOpen Link in New TabSource
License included / downloadable: Yes
The Act is published on legislation.gov.uk and the Ministry of Justice guidance on GOV.UK under the Open Government Licence, and the offences and six principles are included with the platform as a requirement set.
Framework text is licensed by its publisher and is included only where stated above.
How SmartSuite Supports UK Bribery Act
SmartSuite provides the system for managing controls, evidence, mappings, assessments, and reporting.
For the Bribery Act, SmartSuite holds the six principles and the section 7 defence as a requirement set linked to the bribery risk assessment, policies, third-party due diligence, gifts and hospitality registers, training records, and monitoring reviews, so adequate procedures are evidenced with owners, dates, and an audit trail.
Offences and Six Principles Library
Hold the Act's offences, the section 7 defence, and the six principles of adequate procedures as structured requirements linked to your policies and controls.
Ownership, Cadence, and Accountability
Assign board, compliance, and business owners to each principle, set review cycles, and record top-level commitment and policy approvals.
Evidence Collection and Audit Trail
Attach risk assessments, due diligence files, gifts and hospitality approvals, and training completions with timestamps and reviewers.
Monitoring, Review, and Testing
Plan monitoring and internal reviews of the procedures, document findings, and track remediation to closure.
Third-Party and Associated Person Due Diligence
Link agents, intermediaries, distributors, and joint ventures to risk-based due diligence and contractual anti-bribery terms.
Board and Regulator Reporting
Produce dashboards by principle and business unit showing procedure status, open cases, and remediation for the board and, where needed, prosecutors.
Related frameworks

UK GDPR is the United Kingdom regulation governing processing, protection, and privacy rights of personal data.

The Sarbanes-Oxley Act requires public companies to maintain reliable financial reporting and robust internal controls to prevent fraud.

COSO ICFR guides organizations in designing and evaluating internal controls to ensure reliable financial reporting and regulatory compliance.

ISO 31000 provides guidelines for identifying, assessing, and managing organizational risks to improve resilience and decision-making.

PRA SS1/21 sets the Prudential Regulation Authority's expectations for how UK banks and insurers identify important business services, set impact tolerances, and stay within them.

FCA PS21/3 and SYSC 15A require UK-regulated firms to identify important business services, set impact tolerances, map and test their resilience, and self-assess against them.
Frequently Asked Questions For UK Bribery Act
Four: bribing another person (section 1), being bribed (section 2), bribery of a foreign public official (section 6), and failure of a commercial organisation to prevent bribery by an associated person (section 7).
The Act received Royal Assent on 8 April 2010 and came into force on 1 July 2011.
A relevant commercial organisation is guilty of an offence if a person associated with it bribes another person intending to obtain or retain business or a business advantage for the organisation. It is a defence for the organisation to prove that it had adequate procedures in place designed to prevent such conduct.
The Ministry of Justice guidance issued under section 9 sets out six principles: proportionate procedures, top-level commitment, risk assessment, due diligence, communication including training, and monitoring and review. Whether procedures are adequate is decided by the court on the facts.
Under section 8, a person who performs services for or on behalf of the organisation, which can include employees, agents, subsidiaries, and contractors, determined by reference to all the relevant circumstances rather than the label of the relationship.
Yes. Section 12 extends the offences to conduct abroad by persons with a close connection to the UK, and section 7 applies to any organisation that carries on business or part of a business in the UK regardless of where the bribery occurs.
The Bribery Act covers private-sector as well as public-sector bribery, includes being bribed, has no exception for facilitation payments, and imposes strict corporate liability under section 7 with adequate procedures as the defence, whereas the FCPA focuses on bribery of foreign officials and on books and records and internal controls of issuers.
SmartSuite holds the six principles and the section 7 defence as a requirement set linked to the bribery risk assessment, policies, third-party due diligence, gifts and hospitality registers, training records, and monitoring reviews. Compliance teams use it to evidence adequate procedures and report to the board.
Manage controls, risks, evidence, and audits in one platform designed for modern governance, risk, and compliance.