top of page

How to Draft an Anti-Bribery and Anti-Corruption Compliance Policy for an Indian Company

  • Writer: Kaustav Chowdhury
    Kaustav Chowdhury
  • 4 hours ago
  • 6 min read

Drafting an effective Anti-Bribery and Anti-Corruption (ABAC) compliance policy is a fundamental governance requirement for any Indian company, particularly those with government-facing operations, regulated sector exposure, or international business activities. The primary legislation governing bribery and corruption in India is the Prevention of Corruption Act, 1988, as amended by the Prevention of Corruption (Amendment) Act, 2018, which introduced corporate criminal liability for bribe-giving under Section 9. Companies with international operations must also consider the U.S. Foreign Corrupt Practices Act (FCPA) and the UK Bribery Act 2010, which have extraterritorial reach. The Companies Act, 2013, through Section 447 on fraud and Section 177(9) on vigil mechanisms, further reinforces the need for a documented anti-corruption framework. This guide provides a step-by-step approach to drafting an ABAC policy that satisfies Indian legal requirements and aligns with international best practices.


Step 1: Map All Applicable Anti-Corruption Laws

The first step in drafting an ABAC policy is to identify every statute and regulation that creates anti-corruption obligations for your company. In India, the Prevention of Corruption Act, 1988 (PCA) is the cornerstone statute. The 2018 Amendment brought two critical changes: Section 8 now makes giving a bribe to a public servant a direct criminal offence (previously only abetment was covered), and Section 9 introduces liability for commercial organisations whose associated persons give bribes to obtain or retain business. The only defence available to a commercial organisation under Section 9 is demonstrating that it had adequate procedures in place to prevent bribery.


Beyond the PCA, your mapping exercise must include Section 447 of the Companies Act, 2013, which criminalises corporate fraud with imprisonment of up to ten years. The Prevention of Money Laundering Act, 2002 (PMLA) covers proceeds of corruption as predicate offences. If the company operates internationally, the FCPA applies to any company issuing securities in the United States or operating through US jurisdictions, while the UK Bribery Act applies to companies with any commercial presence in the United Kingdom. The policy preamble should explicitly list all applicable statutes and their key provisions to establish the legal foundation for the compliance programme.


Step 2: Draft the Policy Statement and Define Scope

The policy statement should be a clear, unambiguous declaration that the company prohibits all forms of bribery and corruption, whether involving public officials or private sector counterparties. It should state that the policy applies to all directors, officers, employees, and any person acting on behalf of the company, including agents, consultants, distributors, and joint venture partners. The scope section must specify that the policy covers both direct and indirect payments, including facilitation payments (sometimes called grease payments), which are prohibited under Indian law even though some foreign jurisdictions treat them as exceptions.


The policy should define key terms such as bribe, public servant (as defined under Section 2(c) of the PCA), undue advantage, commercial organisation, and associated person. The definition of public servant under the PCA is broad and includes any person in the service or pay of the government, local authority, corporation, or government company. Your definitions should be comprehensive enough to cover all possible scenarios while remaining accessible to non-legal readers across the organisation.


Step 3: Specify Prohibited Conduct and Identify Red Flags

The policy must contain a detailed list of prohibited conduct. This includes offering, promising, or giving any payment, gift, hospitality, or thing of value to a public servant or private party to influence official action or secure an improper business advantage. It also covers accepting bribes, making payments through intermediaries, and creating or maintaining false books and records to conceal improper payments. The policy should set clear monetary thresholds for gifts and hospitality, requiring prior approval above a stated amount and prohibiting gifts that could reasonably be perceived as intended to influence a decision or secure a benefit.


A red flags section should alert employees and compliance teams to common indicators of potential corruption. These include requests for payments to be made in cash or to third-party accounts, unusually high commission rates for agents or consultants, use of intermediaries with no clear business justification, last-minute changes in payment recipients, requests to issue invoices in a different name or jurisdiction, and any request to make a payment in a country with no connection to the underlying transaction. The policy should require employees to report any red flag to the compliance officer immediately.


Step 4: Establish Third-Party Due Diligence Procedures

One of the highest risk areas for bribery is the use of third parties, including agents, consultants, customs brokers, and sub-contractors. Section 9 of the PCA as amended makes the company liable if an associated person (which includes anyone performing services for or on behalf of the company) gives a bribe. The policy must therefore mandate risk-based due diligence on all third parties before engagement. The due diligence process should include background checks, review of beneficial ownership, assessment of connections to public officials, verification of business legitimacy, and a written compliance certification from the third party.


For high-risk engagements, such as those involving government-facing intermediaries or operations in sectors known for corruption risk, enhanced due diligence should be required. This includes site visits, reference checks, and periodic reassessments at defined intervals. All third-party agreements must contain anti-corruption representations, audit rights, and termination clauses for policy violations. The company should maintain a central register of all third-party engagements subject to ABAC due diligence, with periodic reporting to the compliance committee or audit committee.


Step 5: Set Up Reporting Channels, Whistleblower Protection, and Training

The ABAC policy must establish accessible and confidential reporting channels for suspected violations. Section 177(9) of the Companies Act, 2013 requires listed companies and prescribed classes of companies to establish a vigil mechanism that allows directors and employees to report genuine concerns. The policy should specify how reports can be made (for example, through a dedicated email, a compliance hotline, or a secure online portal), who receives and investigates reports, and how confidentiality is maintained throughout the process. Retaliation against any person reporting in good faith must be expressly prohibited, with clear consequences for retaliatory conduct.


Training is the operational backbone of any ABAC programme. The policy should mandate annual anti-corruption training for all employees, with enhanced training for those in high-risk roles such as procurement, sales, government relations, and finance. New employees should complete ABAC training within their first 30 days. The policy should also require annual compliance certifications from all employees and directors confirming that they have read, understood, and complied with the policy throughout the year. Finally, the board or a designated compliance committee should review the ABAC policy at least annually and update it to reflect changes in law, enforcement trends, and the company's evolving risk profile.


Common Drafting Mistakes and Compliance Pitfalls

  • Failing to address facilitation payments explicitly, leaving a gap that employees may interpret as tacit permission to make small payments to expedite routine government services

  • Limiting the policy scope to employees only and excluding agents, consultants, and other third parties who pose the highest bribery risk under Section 9 of the PCA

  • Setting gift and hospitality thresholds without a pre-approval or disclosure process, making the thresholds difficult to monitor and enforce in practice

  • Not aligning the whistleblower mechanism with Section 177(9) of the Companies Act, resulting in a vigil mechanism that exists on paper but lacks practical reporting channels

  • Omitting the adequate procedures defence framework under Section 9 of the PCA, which requires documented evidence that the company had effective anti-corruption procedures at the time of the alleged offence

  • Treating the ABAC policy as a static document and failing to conduct periodic risk assessments or update the policy in response to new enforcement actions, regulatory changes, or shifts in the company's business operations


Related Reading

Comments


bottom of page