Australia’s foreign bribery framework no longer focuses only on whether a company directly authorised a corrupt payment. Since 8 September 2024, a corporation can face criminal liability when an associate bribes a foreign public official for the corporation’s profit or gain, unless the corporation proves that it had adequate procedures designed to prevent the conduct.
That change matters because bribery risk often sits outside head office. It may arise through a sales agent, distributor, customs broker, consultant, subsidiary or contractor operating in a market where informal payments are treated as routine. Distance from the transaction is no longer a workable compliance strategy.
The practical question is now: can the business demonstrate that its prevention framework was proportionate, active and effective?
What Changed in Australia?

The Crimes Legislation Amendment (Combatting Foreign Bribery) Act 2024 inserted section 70.5A into the Criminal Code Act 1995. The new corporate offence commenced on 8 September 2024.
A covered body corporate may commit the offence where an associate commits the Australian foreign bribery offence, or engages in equivalent conduct outside Australia, for the corporation’s profit or gain. The corporation may be convicted even if the associate has not been separately convicted.
Prosecutors do not need to prove that the board or senior executives directed, approved or knew about the bribery. The underlying bribery conduct must still be established, but absolute liability applies to specified corporate elements under section 70.5A.
A company may therefore have honest directors and still be exposed because someone performing services on its behalf used an improper benefit to secure a permit, retain a government contract or influence a state-owned customer.
Who Can Be an “Associate”?
The definition is broad. It can include an officer, employee, agent, contractor, subsidiary, controlled entity or another person performing services for or on behalf of the corporation.
A third party does not need an “agent” label to create risk. Investigators may examine what the party was engaged to do, who benefited from the arrangement, how the party was paid, what oversight existed and whether the commercial relationship was genuine.
Consider an Australian engineering company that hires a local “business development adviser” for an overseas public tender. The adviser has no detailed scope of work, receives a large success fee and requests payment to an unrelated offshore account.
If the adviser bribes a procurement official to help the Australian company win the tender, the company may face section 70.5A exposure even though no employee made the payment.
Similar risks can arise through freight forwarders, visa facilitators, lobbyists, permit consultants, joint venture participants and acquisition targets. The Australian Government’s adequate-procedures guidance gives particular attention to the proper selection, onboarding, contracting, payment and supervision of third parties.
What Is a Foreign Public Official?

The definition extends beyond ministers and departmental officers. It includes employees or officials of foreign governments, public international organisations and foreign public enterprises. It can also cover legislators, judges, candidates for public office, people performing official duties under foreign law and certain intermediaries.
This matters where governments own or control major businesses. A manager working for a state-owned energy, transport, health or telecommunications enterprise may be a foreign public official even when the transaction appears to be an ordinary commercial arrangement.
Businesses should therefore identify government ownership and control during customer and counterparty due diligence. Job titles alone are unreliable.
How Far Does the Offence Reach?
For Australian corporations, the offence can apply to relevant conduct by an associate inside Australia and to conduct outside Australia that would amount to foreign bribery if it occurred here. The associate does not need to be Australian.
The offence can also apply to certain foreign corporations where the relevant associate conduct occurs inside Australia.
This reflects how cross-border transactions work. A payment may be arranged in one country, approved in another, routed through a third and intended to influence an official elsewhere.
Compliance reviews must therefore follow the transaction and service relationship rather than stopping at corporate or national boundaries.
Penalties and Enforcement Risk
The maximum corporate fine is the greatest of:
-
100,000 penalty units;
-
three times the value of the benefit where that value can be determined; or
-
10 per cent of annual turnover for the relevant period where the benefit cannot be determined.
Foreign-bribery proceeds may also be restrained and forfeited under proceeds-of-crime legislation. A case can bring investigation expenses, loss of financing or contracts, management disruption, contractual disputes and long-term reputational harm.
The OECD’s January 2026 enforcement dataset, covering matters through 31 December 2024, records that parties to the Anti-Bribery Convention had collectively sanctioned at least 752 natural persons and 315 legal persons through criminal proceedings for foreign bribery.
Australia was listed with seven natural persons and three legal persons sanctioned in criminal foreign-bribery cases over the reporting period.
Those figures do not predict how many prosecutions will occur under section 70.5A. They do show that foreign bribery is increasingly addressed through international enforcement cooperation rather than as a purely local offence.
The Adequate-Procedures Defence
A corporation is not liable under section 70.5A if it proves that it had adequate procedures designed to prevent associates from engaging in foreign bribery. The company carries the legal burden and must establish the defence on the balance of probabilities.
“Adequate” does not mean perfect. The Attorney-General’s Department guidance on adequate procedures recognises that an incident does not automatically make a company’s controls inadequate.
A court will consider the circumstances, including whether the procedures were proportionate to the risks and effective in practice.
There is no universal checklist or automatic safe harbour. A small exporter dealing with private customers in lower-risk markets will not need the same framework as a resources company using agents to obtain licences and negotiate with state-owned enterprises.
Size matters, but exposure matters more.
The Australian guidance identifies six central elements: a control environment that prevents foreign bribery, responsibility at top-management level, risk assessment, communication and training, reporting, and monitoring and review.
These are not decorative policy headings. A company must show how they operate in the real business.
Building Procedures That Work
Conduct a Specific Bribery Risk Assessment
A generic enterprise risk register is rarely enough. The assessment should identify where the business interacts with foreign officials, uses intermediaries, seeks permits, participates in public procurement, operates in higher-risk sectors or provides gifts, travel, sponsorships and donations.
Country risk is relevant, but it should not be the only factor. Businesses should also consider their industry, transaction types, customers, payment arrangements, use of public-sector contacts and reliance on third parties.
The risk assessment should involve employees who understand how work is actually won and delivered. Local sales staff, finance teams, procurement personnel, project managers and logistics employees often see risks that head office misses.
Document the risk ratings, existing controls, control owners and review dates. Refresh the assessment before entering a new country, acquiring a business, appointing a distributor or pursuing a major government tender. The Australian guidance treats risk assessment as the foundation for designing proportionate controls.
Control the Third-Party Lifecycle
Due diligence should begin before appointment and continue throughout the relationship.
Establish a genuine business rationale, verify ownership and reputation, identify government connections, understand the proposed services and compare compensation with the market value of those services.
Contracts should describe deliverables, prohibit bribery, require accurate records, control subcontracting and allow suspension or termination. A signed anti-bribery clause is not enough when the underlying arrangement remains suspicious.
Review invoices against completed work. Investigate changed bank accounts, unusual expenses, high commissions, upfront payments and transfers to jurisdictions unrelated to the service.
Higher-risk parties need closer supervision and more frequent review. Due diligence should also be revisited when ownership, management, service scope or payment instructions change.
Strengthen Financial and Non-Financial Controls
Many bribery schemes become visible through payment details rather than explicit admissions.
Warning signs include vague consulting fees, rounded invoices, split payments, cash requests, reimbursements without receipts, payments to personal accounts and transfers unrelated to the location of the service.
Finance staff need authority to stop and escalate a transaction without being overruled simply because a sales target or contract deadline is approaching.
Approval rules should reflect risk, not merely dollar value. A small payment made to accelerate government action can create more exposure than a large payment to a legitimate supplier.
Controls should also cover gifts, hospitality, travel, political contributions, charitable donations, sponsorships, recruitment requests and community investment. Each needs a legitimate purpose, approval route and accurate record.
Train for Real Decisions
Annual training that only defines bribery will not prepare staff for a customs official requesting an “expediting fee,” an agent demanding urgent cash or a public customer asking the company to employ a relative.
Role-based training should use realistic scenarios and clear escalation steps.
Directors need to understand oversight and resourcing. Sales teams need rules for intermediaries and hospitality. Finance staff need payment red flags. Procurement teams need due-diligence triggers. Managers need to know how to respond without punishing the person who raised the concern.
Keep evidence of who was trained, when the training occurred, which risks it covered and how non-completion was handled. The Government guidance recommends training tailored to the risks identified through the company’s assessment process.
Create Trusted Reporting and Investigation Processes
A reporting channel fails when employees expect retaliation, delay or silence.
Reporting options should be accessible to employees and, where appropriate, contractors and business partners. Overseas operations may require local-language channels and communication methods that employees can use safely.
Reports require prompt triage by suitably independent personnel. Investigation scope, evidence preservation, reporting lines, findings and remediation should be documented.
Serious allegations may require immediate legal advice and consideration of reporting to the Australian Federal Police.
Trend analysis is also important. Several minor complaints about the same distributor, manager or payment type may expose a pattern that no single report reveals.
Monitor, Test and Improve
A policy can look complete while failing in practice.
Monitoring may include transaction testing, third-party file reviews, employee interviews, hotline trend analysis and targeted audits of higher-risk markets.
Boards should receive meaningful information rather than a simple statement that training is complete. Useful reporting explains where exposure has changed, which controls failed, whether concerns were investigated promptly and whether remediation occurred.
The goal is a continuous cycle of assessment, control, testing and improvement. This approach also reflects international practice found in the US Department of Justice’s compliance guidance and ISO 37001:2025.
A Practical Scenario
An Australian medical-device supplier enters a market where public hospitals dominate purchasing. It appoints a distributor that promises rapid product registration and strong relationships with hospital administrators.
The distributor requests a high commission, refuses to disclose its owners and submits invoices for vague “market access support.” The supplier accepts the explanation because quarterly targets are under pressure.
Later, an internal email suggests that part of the commission funded gifts and travel for hospital decision-makers.
At that point, the central questions are practical. Was the public-sector risk assessed? Was the distributor’s ownership checked? Were its commissions benchmarked? Did finance challenge the invoices? Were staff trained to recognise the warning signs? Did senior leaders reward sales without asking how the results were achieved?
A policy copied from the internet would offer little protection. A documented, risk-based program that was genuinely applied would place the company in a much stronger position.
Australia and Global Anti-Bribery Standards
Australia’s model resembles section 7 of the UK Bribery Act 2010 guidance because both frameworks use an adequate-procedures defence and address misconduct by associated persons.
The UK offence is broader in an important respect. It can cover failure to prevent certain forms of commercial bribery as well as bribery of foreign public officials. Australia’s section 70.5A is specifically connected to foreign public-official bribery.
The United States uses a different statutory model under the Foreign Corrupt Practices Act, combining anti-bribery requirements with accounting provisions for issuers rather than creating the same general failure-to-prevent offence.
In practice, the US Department of Justice’s corporate compliance evaluation guidance similarly examines risk assessment, third-party management, leadership, incentives, reporting, investigations and continuous improvement.
Companies operating across jurisdictions should build a common global framework and then add country-specific controls for issues such as facilitation payments, hospitality, accounting, privacy and disclosure.
International cooperation is also becoming more important. The OECD reported in 2026 that coordinated, multijurisdictional resolutions are playing a growing role in cross-border corruption enforcement. A matter discovered in one country may attract interest from several authorities.
Questions for Boards and Senior Managers
Boards and executives should ask where the company relies on agents, distributors, contractors or partners in dealings with foreign governments and state-owned enterprises.
They should identify relationships involving high commissions, success fees, unclear deliverables, complex ownership or unusual payment routes.
They should also ask when the bribery risk assessment was last updated, whether finance can stop a questionable payment, what evidence shows that the controls work and how concerns are escalated and remediated.
Tone from the top matters, but conduct from the top matters more.
Executives weaken the program when they waive due diligence for a valuable deal, pressure finance to release a blocked payment or reward results without considering how those results were achieved.
A Focused 90-Day Response
During the first month, assign ownership of the anti-bribery framework, map foreign-government touchpoints and identify high-risk associates. Check whether current policies, delegations and reporting lines reflect section 70.5A.
During the second month, test selected third-party files and payments. Prioritise agents, distributors, customs intermediaries, consultants, joint ventures and acquisition targets. Remediate missing ownership checks, vague scopes, unusual commissions and weak contract terms.
During the third month, deliver role-based training, test the reporting process, brief the board on material gaps and approve a monitoring plan. Preserve evidence explaining why controls were selected and how identified weaknesses were addressed.
The objective is not paperwork. It is credible evidence that the company understood its exposure and took practical action.
Common Mistakes
A code of conduct is not a complete anti-bribery program. Nor is a one-time screening exercise.
Companies also create risk when they collect due-diligence information but ignore the warning signs it reveals.
Facilitation payments present another trap. Australian law retains a narrow defence for certain minor payments connected with routine government action and subject to strict recordkeeping requirements.
However, those payments may be illegal where they occur and may breach other applicable laws. The Australian Government recommends that companies make every effort to resist them.
The most damaging mistake is allowing commercial urgency to override controls. An exception granted for a major tender may later become evidence that the compliance framework was not operating effectively.
Act Before an Incident Tests the Program
Adequate procedures are more than a courtroom defence. They help businesses select reliable partners, protect funds, improve transaction transparency and give employees a safe way to reject improper demands.
Use the Australian guidance as the primary reference point, obtain advice for the company’s circumstances and compare the framework with recognised international practice, including ISO 37001:2025. The updated international standard provides a structured framework for establishing, maintaining and improving an anti-bribery management system.
Strengthen practical awareness across your organisation with Anti-Bribery & Corruption Compliance training from Australian Compliance Training.
Help employees and managers recognise warning signs, escalate concerns and protect the business before a high-risk transaction becomes a criminal investigation.
