Skip to main content
Category: Anti-Corruption and AML

Adequate Procedures Defense

Also known as: Adequate Procedures
Simply put

The adequate procedures defense is a legal argument available to a company under the UK Bribery Act 2010. If a company is accused of failing to prevent bribery, it may avoid liability by proving that it had put suitable anti-bribery controls in place to stop employees, agents, and other associated persons from paying bribes. This is a jurisdiction-specific concept under UK law and is not a universal protection; whether procedures are considered adequate depends on the facts, and legal questions should be confirmed with qualified counsel.

Formal definition

Under the UK Bribery Act 2010, the adequate procedures defense is a statutory defense to the corporate offense of failing to prevent bribery, whereby a commercial organization may prove that it had adequate procedures in place designed to prevent associated persons from engaging in bribery. In practice, 'adequate procedures' refers to the anti-bribery controls a business implements to prevent employees, agents, and other associated persons from committing bribery. The defense reflects a good-faith standard in which the organization must demonstrate proportionate, preventive measures rather than merely nominal policies. This defense is specific to the UK jurisdiction; commentators have discussed analogous concepts in relation to the U.S. FCPA, but the FCPA does not currently provide an equivalent codified defense. Whether procedures qualify as adequate is fact-dependent and a matter for legal determination, and this entry is educational rather than legal advice.

Why it matters

The adequate procedures defense is significant because it shapes how commercial organizations approach anti-bribery compliance under the UK Bribery Act 2010. Because the corporate offense of failing to prevent bribery can attach liability to an organization for the conduct of its associated persons, the availability of this defense creates a direct incentive for companies to design, implement, and maintain genuine preventive controls rather than nominal policies. The defense reflects a good-faith standard: an organization seeking to rely on it must be able to demonstrate that it took proper precautions throughout the business.

For compliance and ethics teams, the concept matters as a design objective as much as a legal argument. Whether procedures qualify as adequate is fact-dependent and ultimately a matter for legal determination, which means the strength of any potential defense rests on how controls are actually implemented and evidenced, not merely on their existence on paper. This encourages organizations to treat anti-bribery controls as living components of a program that can withstand scrutiny.

It is important to recognize the limits of this concept. The adequate procedures defense is specific to UK law and is not a universal protection. Commentators have discussed analogous ideas in relation to the U.S. FCPA, but the FCPA does not currently provide an equivalent codified defense. Because these questions touch on legal liability and vary by jurisdiction, organizations should confirm their specific position with qualified counsel; this entry is educational and not a substitute for legal advice.

Who it's relevant to

Compliance officers and anti-bribery program managers
Those responsible for designing and maintaining anti-bribery controls should understand that the adequacy of procedures depends on how they are implemented and evidenced, not simply on their existence. This concept helps frame why preventive, proportionate measures are prioritized over nominal policies, though whether procedures qualify as adequate is ultimately a legal determination.
Legal and audit teams
Legal and audit functions engage directly with this defense when assessing a UK Bribery Act 2010 exposure or advising on liability for associated persons. They evaluate whether controls could support a good-faith showing, while recognizing that the concept is jurisdiction-specific to UK law and has no equivalent codified defense under the U.S. FCPA.
Organizations with international operations
Businesses whose operations, agents, or associated persons fall within the scope of the UK Bribery Act 2010 should be aware of this defense as a UK-specific concept. Because analogous ideas exist in commentary on other regimes but do not carry the same codified status elsewhere, organizations should confirm their position across jurisdictions with qualified counsel.
Learning and development staff
Those building anti-bribery training should understand that a training module alone does not establish adequate procedures; training is one component within a broader set of preventive controls that an organization would rely on when demonstrating good faith. Training content should reflect that adequacy is fact-dependent and jurisdiction-specific.

Inside Adequate Procedures Defense

Statutory Basis
The adequate procedures defense arises under the UK Bribery Act 2010, specifically in relation to the Section 7 corporate offence of failing to prevent bribery. It is a jurisdiction-specific concept and does not automatically apply under other anti-bribery regimes such as the U.S. FCPA.
Affirmative Defense Structure
It operates as a defense a commercial organization may raise once the failure-to-prevent offence is otherwise established, requiring the organization to show it had adequate procedures in place designed to prevent associated persons from engaging in bribery. The burden of demonstrating adequacy rests with the organization.
Reference to Government Guidance
The UK government has published guidance describing principles relevant to procedures intended to prevent bribery. These principles are commonly cited as a reference point for what may constitute adequate procedures, though the guidance is advisory rather than a rigid checklist and does not itself have binding statutory force.
Program Components Referenced
Procedures typically span multiple distinct program elements, such as risk assessment, policies, due diligence, communication and training, and monitoring, rather than any single component. Training is one part of a broader system and does not by itself constitute adequate procedures.
Proportionality Assumption
Adequacy is generally assessed in proportion to the bribery risks the organization faces and the nature, scale, and complexity of its activities. What is adequate for one organization may not be adequate for another.

Common questions

Answers to the questions practitioners most commonly ask about Adequate Procedures Defense.

Is the adequate procedures defense available under the U.S. Foreign Corrupt Practices Act (FCPA)?
No. The adequate procedures defense is a feature of the UK Bribery Act, where it can serve as a defense to the offense of a commercial organization failing to prevent bribery. It is jurisdiction-specific. The FCPA does not provide an equivalent statutory affirmative defense based on having adequate procedures, though the existence of a compliance program may be considered by U.S. authorities in other ways, such as in charging or resolution decisions. Because this concept turns on the law of a specific jurisdiction, its application should be confirmed with qualified legal counsel.
Does simply having a compliance program automatically establish an adequate procedures defense?
No. The defense generally turns on whether the procedures in place were adequate and proportionate to the bribery risks the organization faced, not merely on whether a program existed on paper. A code of conduct, training modules, or written policies are individual components and do not, on their own, establish the defense. Whether procedures qualify as adequate depends on implementation, context, and the specific facts, and any determination is ultimately a matter for legal assessment rather than something a program can guarantee in advance.
How does an organization assess whether its procedures are proportionate to its bribery risk?
Proportionality is generally approached through a documented risk assessment that identifies the organization's exposure to bribery across factors such as sectors, jurisdictions, transaction types, business relationships, and use of third parties or intermediaries. The procedures are then designed to address the risks identified. A risk assessment is one component of a broader program and is intended to support the case that procedures are matched to actual risk, though it does not by itself demonstrate adequacy. This is an educational overview and not a substitute for legal advice on a specific organization's obligations.
What role does top-level commitment play in supporting the defense?
Demonstrable commitment from senior management to preventing bribery is generally regarded as a supporting element, intended to establish that a culture opposing bribery is fostered throughout the organization. This may include leadership communications, allocation of resources, and visible engagement with the program. Such commitment is one factor among several and is not sufficient on its own; its weight depends on how it is implemented and evidenced. It does not guarantee that procedures will be found adequate.
How should an organization handle third parties and intermediaries in its procedures?
Because bribery risk is often associated with agents, intermediaries, and other third parties acting on an organization's behalf, procedures commonly include due diligence proportionate to the assessed risk, contractual provisions, and ongoing monitoring of those relationships. Due diligence and monitoring are distinct components rather than a single control, and their scope is generally expected to reflect the level of risk each relationship presents. The specific approach that satisfies legal expectations varies by circumstance and should be confirmed with qualified counsel.
How can an organization evidence that its procedures are operating and not just documented?
Organizations generally maintain records of activities such as risk assessments, due diligence, training delivery and completion, communications, and monitoring and review of the procedures over time. Monitoring and auditing functions are separate from training and policy components and are intended to test whether procedures work in practice and to inform updates. Maintaining such evidence is generally regarded as supporting the case that procedures are more than paper, though it does not by itself guarantee any particular legal outcome. This overview is educational and not a substitute for professional legal advice.

Common misconceptions

Having a code of conduct or completing anti-bribery training establishes the adequate procedures defense.
Training and a code of conduct are individual components of a broader compliance program. The defense concerns whether the organization's overall procedures were adequate and proportionate to its risks; no single element is treated as sufficient on its own, and effectiveness depends on implementation and context.
The adequate procedures defense applies to bribery and corruption matters generally, including under U.S. law.
This is a defense specific to the Section 7 failure-to-prevent offence under the UK Bribery Act. It is jurisdiction-specific and should not be assumed to apply under other frameworks such as the FCPA, which has a different statutory structure.
Following the published guidance guarantees the defense will succeed.
The government guidance is principles-based and advisory, not a binding checklist that confers legal protection. Whether procedures are adequate is a fact-specific determination, and no set of procedures can guarantee a successful defense or the prevention of misconduct.

Best practices

Design anti-bribery procedures proportionate to the specific bribery risks, scale, and complexity of the organization, rather than adopting a generic template.
Treat training as one component of a broader system that also includes risk assessment, policies, due diligence, communication, and monitoring, do not rely on any single element.
Document the rationale, scope, and implementation of procedures so the organization can demonstrate what was in place and why, should the defense need to be raised.
Use the UK government guidance principles as a reference point while recognizing it is advisory, and adapt procedures to the organization's actual circumstances.
Periodically review and update procedures as risks, operations, and associated-person relationships change, and confirm any specific statutory or effective-date details against primary sources.
Engage qualified legal counsel on UK Bribery Act matters, since availability and sufficiency of the defense are fact-specific and this entry is educational rather than legal advice.