top of page

How to Implement an Anti-Bribery Compliance Programme for Indian Corporates Under the Prevention of Corruption Act

Writer: Kaustav Chowdhury
Kaustav Chowdhury
Aug 15
6 min read

The Prevention of Corruption (Amendment) Act, 2018 introduced Section 9, which for the first time establishes direct corporate liability for bribery offences in India. A commercial organisation can now face prosecution and fines if any person associated with it bribes a public servant to obtain or retain business. The law also provides a statutory defence: if the organisation can prove that it had "adequate procedures" in place to prevent bribery, it can avoid liability.

This guide provides a step-by-step framework for Indian corporates seeking to implement an anti-bribery compliance programme that satisfies the adequate procedures defence and aligns with international best practices under the UK Bribery Act 2010 and the US Foreign Corrupt Practices Act (FCPA).

Understanding Section 9: Corporate Liability for Bribery

Section 9 of the Prevention of Corruption Act, 1988 (as substituted by the 2018 Amendment) creates a specific offence for commercial organisations. If any person associated with a commercial organisation gives or promises an undue advantage to a public servant to obtain or retain business, the organisation itself becomes criminally liable. The term "person associated" is broadly defined to include employees, agents, subsidiaries, and any person who performs services for the organisation. Directors or officers who consented to or connived at the offence, or whose neglect contributed to it, can also be held personally liable under Section 10.

The Adequate Procedures Defence

The proviso to Section 9 offers a statutory defence: a commercial organisation will not be guilty if it proves that it had adequate procedures designed to prevent persons associated with it from undertaking bribery. However, the Act does not define "adequate procedures." Section 9 mandates the Central Government to prescribe guidelines in consultation with stakeholders, but as of 2026 these guidelines have not been formally published. In the absence of official guidance, Indian corporates should look to the six principles outlined in the UK Ministry of Justice guidance under the Bribery Act 2010 to structure their compliance programmes.

Step 1: Secure Top-Level Commitment

The foundation of any effective anti-bribery programme is visible commitment from the board and senior management. Under Principle 2 of the UK Bribery Act guidance, top-level management must foster a culture in which bribery is never acceptable. In practice, this means:

  • The board should formally adopt an anti-bribery policy and communicate a zero-tolerance stance on corruption.

  • A senior executive or chief compliance officer should be designated with direct responsibility for overseeing the programme.

  • Anti-bribery compliance should feature as a standing agenda item in board and audit committee meetings.

  • The board should allocate adequate financial and human resources to the compliance function.

This commitment is also relevant under Section 134(5) of the Companies Act, 2013, which requires directors to confirm in the Directors' Responsibility Statement that proper systems are in place to ensure compliance with all applicable laws and that such systems are adequate and operating effectively.

Step 2: Conduct a Bribery Risk Assessment

A thorough risk assessment forms the backbone of a proportionate compliance programme. Under Principle 3 of the UK Bribery Act guidance, organisations must assess their exposure to bribery risks. Key factors to evaluate include:

  • Country risk: operations or dealings in jurisdictions with high corruption indices.

  • Sector risk: industries such as infrastructure, mining, defence, and pharmaceuticals carry elevated bribery risks.

  • Transaction risk: public procurement, licensing, permits, and customs clearances present frequent corruption touchpoints.

  • Business partnership risk: reliance on agents, consultants, distributors, and joint venture partners who interact with government officials.

  • Internal risk: weaknesses in financial controls, procurement processes, or gift and hospitality management.

The risk assessment should be documented, reviewed at least annually, and updated whenever the organisation enters new markets or undergoes structural changes.

Step 3: Draft and Adopt Anti-Bribery Policies

Based on the risk assessment, organisations should develop clear, written policies that address the identified risks. An effective anti-bribery policy should cover:

  • A clear prohibition on bribes, facilitation payments, and improper payments of any kind.

  • Rules governing gifts, hospitality, and travel expenses, with monetary thresholds and approval procedures.

  • Guidelines on political and charitable contributions to prevent them from serving as conduits for bribery.

  • Procedures for accurate record-keeping, ensuring all payments are properly documented and authorised.

  • Consequences for policy violations, including disciplinary action and referral to law enforcement.

These policies should be accessible to all employees and business partners, and reviewed regularly. Companies should integrate anti-bribery policies with their existing compliance frameworks, including those required under the BRSR Value Chain Reporting Requirements.

Step 4: Implement Due Diligence Procedures

Due diligence is essential for mitigating bribery risks associated with third parties. Under Principle 4 of the UK Bribery Act guidance, organisations must apply proportionate and risk-based due diligence to persons who perform services for the organisation. Practical measures include:

  • Screening third parties against sanctions lists, debarment databases, and adverse media before engagement.

  • Verifying the identity, ownership, and reputation of agents, consultants, and intermediaries.

  • Assessing whether third-party compensation is reasonable and commercially justified.

  • Including anti-bribery representations, warranties, and audit rights in third-party contracts.

  • Conducting enhanced due diligence for high-risk engagements involving government-facing intermediaries.

Due diligence records should be maintained for at least the duration of the business relationship and for a reasonable period thereafter.

Step 5: Roll Out Training and Communication

Policies are effective only when understood and applied consistently. Under Principle 5 of the UK Bribery Act guidance, organisations must embed their anti-bribery policies through internal and external communication. Key steps include:

  • Conducting mandatory anti-bribery training for all employees, with tailored sessions for high-risk roles such as procurement, sales, and government relations.

  • Providing training to third parties, including agents and joint venture partners, on the organisation's anti-bribery expectations.

  • Using case studies and scenario-based exercises to help personnel recognise bribery red flags.

  • Issuing periodic communications from senior management reinforcing ethical business practices.

  • Documenting training attendance to demonstrate compliance efforts.

The MCA Corporate Mitra Scheme 2026 may provide additional training support for MSMEs looking to build internal compliance capacity.

Step 6: Establish Reporting Channels and Whistleblower Protections

An effective reporting mechanism is critical for early detection of bribery. Organisations should establish confidential channels through which employees and third parties can report suspected violations without fear of retaliation. This requirement intersects with multiple legal obligations:

  • Section 177(9) of the Companies Act, 2013 mandates that every listed company and prescribed classes of companies establish a vigil mechanism for directors and employees to report genuine concerns. For a detailed guide, see How to Set Up a Vigil Mechanism Under Section 177(9).

  • Regulation 22 of the SEBI (Listing Obligations and Disclosure Requirements) Regulations, 2015 requires listed entities to formulate a vigil mechanism that provides adequate safeguards against victimisation and allows direct access to the chairperson of the audit committee in appropriate cases.

  • The vigil mechanism policy must be disclosed on the company's website, and the audit committee must oversee its functioning.

Reporting channels may include dedicated hotlines, email addresses, or web-based platforms. The organisation should establish clear procedures for investigating reports, with defined timelines and escalation protocols.

Step 7: Set Up Monitoring and Review Mechanisms

Under Principle 6 of the UK Bribery Act guidance, organisations must monitor and review their anti-bribery procedures and make improvements where necessary. Effective monitoring should include:

  • Regular internal audits of anti-bribery controls, including transactional testing of high-risk payments.

  • Periodic review of the risk assessment to reflect changes in operations or the regulatory environment.

  • Analysis of whistleblower reports and tracking of investigation outcomes.

  • Benchmarking the programme against evolving regulatory expectations and industry best practices.

  • Engaging independent external auditors to provide objective assessments of programme effectiveness.

Intersection with PMLA and Companies Act Obligations

Anti-bribery compliance does not exist in isolation. The Prevention of Money Laundering Act, 2002 (PMLA) treats offences under the Prevention of Corruption Act as predicate offences. Any money generated through bribery constitutes "proceeds of crime" under the PMLA, exposing both the bribe-giver and the recipient to prosecution for money laundering. The Supreme Court in Directorate of Enforcement v. Padmanabhan Kishore confirmed that a bribe-giver is connected to the proceeds of crime and can face PMLA prosecution. The 2018 amendments to the PMLA also included "fraud" under the Companies Act as a predicate offence, bringing corporate fraud within the scope of money laundering law.

Section 134(5)(c) of the Companies Act, 2013 requires directors to confirm in the Directors' Responsibility Statement that proper care has been taken to maintain adequate accounting records and to prevent and detect fraud. An anti-bribery programme directly supports this obligation by establishing controls that prevent and detect corrupt payments.

Companies should also ensure their compliance programmes account for data protection obligations when handling whistleblower reports and investigation records. For guidance on related data handling requirements, see How to Comply with Personal Data Breach Notification Under DPDP Act.

Key Takeaways

Implementing an anti-bribery compliance programme is no longer optional for Indian corporates. Section 9 of the Prevention of Corruption Act creates direct corporate liability, and the adequate procedures defence provides the only statutory pathway to avoid conviction. While formal government guidelines remain pending, companies that adopt a structured programme built on internationally recognised principles will be best positioned to demonstrate adequate procedures. By securing board commitment, assessing risks, establishing clear policies, conducting due diligence, training personnel, creating reporting channels, and maintaining ongoing monitoring, Indian corporates can protect both the organisation and its stakeholders from the consequences of bribery.

Comments


bottom of page