FCPA, UK Bribery Act, PCA India, ISO 37001, and Building an Effective ABMS
Anti-bribery and corruption (ABAC) risk management has become a critical compliance imperative for Indian businesses, driven by three converging forces: the extraterritorial reach of the US Foreign Corrupt Practices Act (FCPA), which applies to any company with a US-listed parent, US operations, or US dollar-denominated transactions; the UK Bribery Act 2010, which applies even more broadly (including to “associated persons” — agents, intermediaries, and business partners — of companies with UK connections); and India’s own Prevention of Corruption Act, 1988 (PCA) and its 2018 Amendment, which introduced liability for commercial organisations. Pune’s business ecosystem — which includes subsidiaries of US and European MNCs in Hinjewadi and Magarpatta, export-oriented manufacturers in Chakan and Bhosari who do business with US and UK customers, government contractors bidding for Maharashtra state and central government projects, and listed companies subject to SEBI’s corporate governance requirements — has a significant ABAC exposure that many organisations underestimate until a violation triggers enforcement action or reputational damage.
N D Savla & Associates in Baner, Pune, provides Anti-Bribery and Corruption Risk services: ABAC risk assessment covering all business functions, development and implementation of Anti-Bribery Management Systems (ABMS) aligned with ISO 37001, third-party due diligence programmes for agents and intermediaries, anti-bribery policy development, training for management and staff, and investigation support when a potential bribery or corruption incident is identified. Our ABAC practice integrates with our forensic technology solutions, corporate intelligence services, and corporate governance advisory to provide comprehensive anti-corruption support.
Anti-Bribery Risk by Business Function
| Business Function | Typical Bribery / Corruption Risks | Anti-Bribery Controls |
|---|---|---|
| Sales & Business Development | Commissions to agents or intermediaries who pass on payments to government officials to secure contracts; gifts and entertainment to procurement officers exceeding permitted thresholds | Third-party due diligence on agents and intermediaries; gift and hospitality register; commission cap and documentation policy |
| Procurement | Kickbacks from vendors to procurement officers; splitting of purchase orders to avoid approval thresholds; preferred vendor selection without competitive tendering; personal benefits received from supplier relationships | Segregation of duties; competitive tendering for all above-threshold purchases; vendor onboarding due diligence; whistle-blower mechanism |
| Regulatory Approvals & Licences | Facilitation payments to speed up government approvals (factory licences, environmental clearances, building permits, GST registrations); payments to avoid inspections or enforcement | Zero-tolerance facilitation payment policy; documentation of all regulatory interactions; legal counsel for all regulatory approvals |
| Customs & Imports | Payments to customs officials to under-assess duty, clear delayed shipments, or ignore non-compliant imports | Authorised Courier Bank (ACB) / customs broker audit; all customs transactions documented; duty computation independently verified |
| Human Resources | Payments for favourable outcome in labour court proceedings; payments to inspectors during PF/ESIC audits; ghost employees on payroll | Payroll audit; HR compliance audit; independent representation in all labour disputes; PF/ESIC reconciliation |
| Finance & Accounting | Off-books payments (slush funds); inflated expense claims; vendor invoice fraud; cheque forgery; manipulation of financial statements to hide bribery payments | Bank payment controls; dual-authorisation for all significant payments; expense voucher audit; surprise cash count; forensic accounting review |
The Legal Framework — FCPA, UK Bribery Act, and PCA India
US Foreign Corrupt Practices Act (FCPA)
The FCPA (enacted 1977, significantly strengthened by DOJ/SEC enforcement from 2000s) prohibits US issuers (companies listed on US stock exchanges), US domestic concerns (US companies and citizens), and any person acting within the US from paying bribes to “foreign officials” to obtain or retain business. The FCPA’s reach for Indian companies is extensive: any Indian subsidiary of a US-listed parent is an “issuer” subject to the FCPA and its books and records provisions; any Indian company that makes a corrupt payment through a US bank or through the US financial system has US nexus; any Indian company with SEC-registered American Depositary Receipts (ADRs) is subject to the FCPA. The books and records provisions of the FCPA require US issuers to maintain accurate accounting records — which means that off-books bribe payments appearing as legitimate business expenses in the books are a separate FCPA violation even if no government official was bribed directly. FCPA enforcement actions against Indian companies and their subsidiaries have produced some of the largest corporate corruption fines in history.
UK Bribery Act, 2010
The UK Bribery Act 2010 is in many ways more demanding than the FCPA: it covers private-sector bribery (FCPA covers only bribery of foreign officials); it covers facilitation payments (FCPA had a narrow exception for facilitation payments, which the Bribery Act does not recognise); and its “associated person” provisions create corporate criminal liability for a commercial organisation if a person “associated” with it (an agent, distributor, subsidiary, business partner) pays a bribe to obtain business for that organisation. The only defence available to a commercial organisation is to demonstrate that it had “adequate procedures” in place to prevent bribery. For Indian companies exporting to the UK, working with UK distributors, or incorporated in the UK (even as a wholly-owned subsidiary), the Bribery Act’s adequate procedures defence — essentially an Anti-Bribery Management System — is the primary risk mitigation tool.
Prevention of Corruption Act, 1988 (PCA) and the 2018 Amendment
India’s Prevention of Corruption Act, 1988 (as amended by the Prevention of Corruption (Amendment) Act, 2018) now extends criminal liability to commercial organisations (not just individual bribe-givers and recipients). The 2018 amendment introduced Section 9, which creates corporate criminal liability for an organisation where a person associated with it (a director, employee, agent, or subsidiary) gives a bribe on behalf of or for the benefit of the organisation. A commercial organisation can avoid liability under Section 9 if it can demonstrate that it had “adequate procedures” to prevent such bribery — again, essentially the same “adequate procedures” standard as the UK Bribery Act.
ISO 37001 — Anti-Bribery Management System
ISO 37001 (Anti-Bribery Management System — Requirements with Guidance for Use) is the international standard for ABMS implementation. Published in 2016 by the International Organization for Standardization, ISO 37001 specifies the requirements for an Anti-Bribery Management System that an organisation can establish, implement, maintain, and improve to prevent bribery and demonstrate its commitment to anti-bribery compliance. Key elements of ISO 37001:
- Anti-bribery policy: a written policy, approved by the top management/board, prohibiting bribery and stating the organisation’s commitment to zero tolerance
- Risk assessment: documented assessment of the bribery risks faced by the organisation across all business functions, geographies, and third-party relationships
- Due diligence on third parties: proportionate due diligence on agents, intermediaries, distributors, and other third parties through whom the organisation conducts business
- Controls: specific financial and operational controls to prevent bribery (gift and hospitality controls, facilitation payment controls, procurement controls, political contribution controls)
- Training and communication: ABAC training for all employees, with enhanced training for those in high-risk roles
- Whistleblowing mechanism: a confidential reporting channel (anonymous hotline, email, or web portal) for reporting suspected bribery without fear of retaliation
- Monitoring and review: periodic internal audits of the ABMS; independent review; management reporting on ABAC performance
- Continuous improvement: correction of identified weaknesses; updating the risk assessment and controls as the business evolves
Third-Party Due Diligence — The Agent and Intermediary Risk
The highest-risk anti-bribery exposure for Indian companies is through third parties: agents who secure government contracts on their behalf, customs brokers who clear import shipments, distributors who sell to public sector customers, and consultants who facilitate regulatory approvals. Both the FCPA and the UK Bribery Act impose liability on the principal company when an agent or intermediary pays a bribe on its behalf — even if the principal did not know and did not authorise the specific payment. This is the “wilful blindness” doctrine: a company cannot avoid FCPA/Bribery Act liability by deliberately not enquiring into what its agents are doing in jurisdictions with high corruption risk. Third-party due diligence — before appointing the agent, and periodically during the relationship — is the primary tool for managing this risk:
- Initial due diligence: background check on the proposed agent/intermediary; beneficial ownership identification; reference checks; reputation assessment; red flag screening (political connections, enforcement history, association with sanctioned parties)
- Due diligence proportionate to risk: a distributor selling consumer goods to private sector retailers requires less intensive due diligence than an agent whose mandate is to secure defence or infrastructure contracts from government officials
- Anti-bribery representations in contracts: all agent and intermediary agreements must include anti-bribery representations (the agent warrants it will not engage in bribery), audit rights (the principal can inspect the agent’s books), and termination rights (the contract can be terminated immediately if bribery is discovered)
- Ongoing monitoring: annual re-evaluation of third parties; monitoring for red flags (unusual commission requests, requests to pay cash to unnamed “consultants,” requests to structure payments through offshore accounts)
FAQs — Anti-Bribery and Corruption Risk
We are a Pune manufacturer exporting to the US. Does the FCPA apply to us?
What is the adequate procedures defence for the UK Bribery Act and India’s PCA?
Anti-Bribery & Corruption Risk
Anti-bribery and corruption risk advisory for Pune exporters, MNC subsidiaries, and government contractors.
- Phone: +91 98219 32683
- WhatsApp: +91 97650 00966
- Email: info@ndsavla.in
Monday to Saturday | 10:00 AM – 7:30 PM