Australia's Criminal Code now holds your company liable if you can't prove you tried to prevent bribery. The Crimes Legislation Amendment (Combatting Foreign Bribery) Act 2024, effective September 2024, introduces "failure to prevent" liability. This means your organization faces prosecution not just for committing bribery, but for lacking adequate procedures to stop it.
This checklist guides you through compliance requirements under section 70.5 of the Criminal Code. If you operate in Australia, employ Australian citizens abroad, or have Australian subsidiaries, these requirements apply to you.
Prerequisites
Before starting this checklist, confirm:
- Jurisdictional scope: Identify all entities covered under the law (Australian constitutional corporations, Territory-registered entities, and their associates worldwide).
- Associate mapping: Document everyone who qualifies as an "associate" under the expanded definition: officers, employees, agents, contractors, subsidiaries, and anyone performing services for or on behalf of your organization.
- Senior management commitment: Ensure your executive team understands that penalties for companies can reach 100,000 penalty units (U.S. $21 million), or three times the benefit value, or 10% of annual turnover, whichever is greater.
Compliance Checklist
1. Establish documented anti-bribery policies that define prohibited conduct
Reference: Criminal Code Act 1995, section 70.5
Your policy must explicitly prohibit bribing foreign public officials, including authorized intermediaries, public company employees, and officials of foreign organizations. The policy should cover all associates, not just direct employees.
Good looks like: A written policy that defines "foreign public official" using the Criminal Code's nine categories, distributed to all associates with documented acknowledgment, and reviewed annually by legal counsel.
2. Implement bribery risk assessment procedures tied to transaction risk levels
Reference: Adequate procedures indicator, Risk assessment and due diligence
You need a repeatable process that evaluates bribery risk before engaging in transactions involving foreign officials. The assessment should consider jurisdiction corruption indices, transaction value, government touchpoints, and associate involvement.
Good looks like: A risk scoring matrix that assigns high/medium/low ratings to proposed transactions, with mandatory escalation thresholds requiring legal review before proceeding. Each assessment is documented with the date, assessor, risk factors identified, and mitigation controls applied.
3. Conduct due diligence on third parties before engagement
Reference: Adequate procedures indicator, Third-party oversight
Before appointing agents, consultants, or intermediaries who will interact with foreign officials on your behalf, verify their credentials, ownership structure, and track record. This applies especially when the third party has been recommended by a government contact.
Good looks like: A due diligence file for each third party containing: beneficial ownership verification, past engagement history, references from non-governmental clients, and written confirmation they understand your anti-bribery policy. High-risk third parties undergo enhanced due diligence including financial background checks.
4. Build contractual protections into associate agreements
Reference: Adequate procedures indicator, Robust culture of integrity (disciplinary action clause)
Every contract with officers, employees, agents, contractors, and subsidiaries must include anti-bribery clauses with termination rights for violations.
Good looks like: Standard contract language that requires compliance with the Criminal Code, grants you audit rights over the associate's bribery controls, and allows immediate termination if bribery occurs. Contracts specify that the associate is responsible for their own sub-contractors' compliance.
5. Implement accounting controls that detect irregular payments
Reference: Adequate procedures indicator, Pro-compliance conduct
Your financial systems must flag transactions that could mask bribes: excessive commissions, payments to unfamiliar jurisdictions, vague invoice descriptions, or payments to third parties requested by government officials.
Good looks like: General ledger coding that separates government-related transactions, automated alerts for payments above thresholds to high-risk jurisdictions, and mandatory supporting documentation (meeting notes, service descriptions, approval chains) for any payment involving a foreign official.
6. Resource your compliance function adequately
Reference: Adequate procedures indicator, Anti-bribery compliance function
Your compliance team needs sufficient budget, headcount, and authority to investigate concerns and escalate issues to the board without management interference.
Good looks like: A compliance function with a direct reporting line to the audit committee, documented annual budget discussions where compliance can request additional resources for bribery prevention, and a written charter that grants compliance the authority to halt transactions pending investigation.
7. Conduct regular evaluations of control effectiveness
Reference: Adequate procedures indicator, Robust culture of integrity
You must periodically test whether your anti-bribery controls actually work. This isn't a paper review, it's operational testing.
Good looks like: Annual control testing that includes: sample review of due diligence files for completeness, interviews with associates about their understanding of prohibited conduct, transaction testing to verify accounting controls flagged suspicious payments, and gap analysis comparing your program against the five adequate procedures indicators.
8. Train all associates on bribery recognition and reporting
Reference: Adequate procedures indicator, Pro-compliance conduct
Everyone who could encounter a bribery situation must know what it looks like and what to do. This includes recognizing indirect requests (gifts, hospitality, employment offers to relatives).
Good looks like: Role-specific training delivered within 30 days of engagement, with scenarios relevant to each associate's function. Training completion is tracked, and associates must pass a comprehension assessment. Annual refresher training is mandatory, with updated content reflecting recent enforcement actions or policy changes.
9. Establish senior management oversight mechanisms
Reference: Adequate procedures indicator, Robust culture of integrity
Your executives must demonstrate active involvement in the anti-bribery program, not just policy approval. This means regular reporting, escalation protocols, and visible enforcement.
Good looks like: Quarterly compliance reports to the executive team and board covering: new high-risk transactions assessed, due diligence findings, control test results, and investigation outcomes. Senior management reviews and approves all high-risk third-party engagements before contracts are signed.
10. Document disciplinary actions for policy violations
Reference: Adequate procedures indicator, Robust culture of integrity
When associates breach anti-bribery terms, you must take action and record it. Inconsistent enforcement undermines your entire program.
Good looks like: A confidential registry of violations, investigations, and disciplinary outcomes (termination, contract cancellation, financial penalties). The registry demonstrates that consequences are proportional to severity and applied consistently across the organization.
Common Mistakes
Assuming only direct employees are covered: The associate definition now includes contractors, agents, and subsidiaries. Your controls must extend to everyone performing services for you.
Treating this as a one-time compliance project: The law requires ongoing evaluation and monitoring. A program built in 2024 and never updated won't satisfy the adequate procedures defense.
Copying another company's program without risk assessment: Your controls must align with your specific risk profile. A mining company operating in high-risk jurisdictions needs different controls than a software company with minimal government interaction.
Failing to resource compliance adequately: If your compliance function repeatedly requests additional budget or headcount to address bribery risks and is denied, that becomes evidence against you in a prosecution.
Next Steps
If you've completed this checklist, you have the foundation for an adequate procedures defense. Now focus on sustainability:
- Schedule your first annual control effectiveness evaluation within 12 months.
- Build bribery risk assessment into your standard transaction approval workflow.
- Establish metrics: number of high-risk transactions assessed, percentage of associates trained, due diligence completion rates, control deficiencies identified and remediated.
The "failure to prevent" offense shifts the burden to you. The prosecution doesn't need to prove you knew about the bribery, only that you lacked adequate procedures to prevent it. Your documented, tested, and continuously improved program is your only defense.





