How to Build a Corporate Compliance Programme From Scratch

11 min read

A corporate compliance programme is not a folder of policies. In UK law it is a defence, and it only works if it was built in the right order and can be evidenced after the event. Three separate criminal offences now turn on whether an organisation had adequate or reasonable procedures in place, and the newest of them has been in force since 1 September 2025. This guide sets out what those offences require, the six principles that run through all of them, and the sequence to build in.

It sits alongside our guides to corporate governance, how to write a code of conduct and the UK Bribery Act.

Why the law changed the shape of compliance

Until 2011 a company was generally only criminally liable if someone senior enough to be its directing mind and will was personally culpable. That made prosecutions of large organisations very hard, because the more layers a company had, the further the misconduct sat from the boardroom.

Parliament's answer was the failure to prevent model. Instead of proving the board knew, the prosecution proves that an associated person committed the underlying offence intending to benefit the organisation. Liability then follows automatically unless the organisation proves it had the required procedures. There are now three of these offences in UK law:

  • Failure to prevent bribery, section 7 of the Bribery Act 2010, in force since 1 July 2011. Defence: adequate procedures. No size threshold.
  • Failure to prevent the facilitation of tax evasion, sections 45 and 46 of the Criminal Finances Act 2017, covering both UK and foreign tax evasion, in force since September 2017. Defence: reasonable prevention procedures. No size threshold.
  • Failure to prevent fraud, under the Economic Crime and Corporate Transparency Act 2023, in force since 1 September 2025. Defence: reasonable fraud prevention procedures. Applies to large organisations only.

Alongside these, ECCTA widened the identification doctrine in December 2023, so an organisation can now be criminally liable for economic crimes committed by a senior manager acting within the scope of their authority, not only by the board. A senior manager is someone playing a significant role in decision making about, or in managing, the whole or a substantial part of the organisation's activities. That reaches a long way down a large company.

What counts as a large organisation

The failure to prevent fraud offence applies to organisations meeting two or more of these three tests:

  • more than 250 employees
  • more than £36 million turnover
  • more than £18 million in total assets

The tests are applied across the group, so a small UK subsidiary of a large parent is inside the offence even though it would fail all three tests on its own. If you are close to the thresholds, build as though you are over them, because growth is not a defence and the tests are reassessed rather than fixed at incorporation.

The six principles, and why they repeat

The most useful thing about the UK regime is that the government has published guidance for each offence, and the guidance says almost the same thing three times. The Ministry of Justice guidance on adequate procedures, HMRC's guidance on tax evasion facilitation, and the Home Office guidance on fraud published in November 2024 all set out six principles:

  1. Top level commitment. The board owns it, visibly.
  2. Risk assessment. Documented, periodic, specific to your business.
  3. Proportionate, risk based procedures. Controls sized to the risks you found.
  4. Due diligence. On the people and organisations acting for you.
  5. Communication, including training. So the procedures reach the people who face the risk.
  6. Monitoring and review. Evidence that the programme works and adapts.

The practical consequence is that you do not need three programmes. You need one framework with three risk registers running through it. A business that builds separate bribery, tax and fraud regimes ends up with three sets of training nobody completes.

Step 1: risk assessment, before anything else

This is the step most organisations skip, and skipping it undermines everything after it. Without a risk assessment you cannot show why your procedures are proportionate, and proportionality is the whole test.

A workable assessment covers four things. Where you operate, including any jurisdiction where facilitation payments are normal or enforcement is weak. Who acts for you: agents, distributors, introducers, consultants, joint venture partners, anyone who can bind you or be seen to speak for you. What your people are paid to do, because commission structures, aggressive sales targets and bonus gateways are the single most common fraud driver named in the Home Office guidance. And where money and decisions move: procurement, payments, discounts, rebates, expenses, gifts and hospitality.

Write it down, date it, name who did it, and record what you decided not to do and why. The negative findings are as valuable as the positive ones when you have to explain your programme to an investigator two years later.

Step 2: top level commitment that is visible outside the boardroom

Commitment is judged by evidence, not intention. Board minutes that record a discussion of the risk assessment. A named director or committee accountable for the programme. A statement from the chief executive that appears somewhere employees actually see, and is repeated. Budget and headcount that match the stated priority.

The test that matters is whether anyone in the business has ever seen leadership turn down revenue on compliance grounds. If not, the programme is a document rather than a culture, and staff will read it that way.

Step 3: proportionate procedures, and only the ones you can justify

The core policy set for most organisations is smaller than the compliance industry suggests:

  • A code of conduct that states the standards in plain language.
  • An anti-bribery and corruption policy, including a clear prohibition on facilitation payments, which are illegal under UK law with no exception.
  • Gifts and hospitality rules with a threshold and a register.
  • A third party policy covering how agents and intermediaries are appointed, paid and reviewed.
  • A conflicts of interest policy and register.
  • A whistleblowing policy with a route that does not run through the person most likely to be implicated.
  • A fraud policy setting out the controls over the specific fraud risks your assessment identified.

Every one of those should trace back to a line in the risk assessment. If it does not, either the risk assessment is incomplete or the policy is decoration.

Step 4: due diligence on associated persons

The failure to prevent offences attach to conduct by associated persons, so this is where the exposure actually sits. Due diligence should be risk tiered rather than uniform: light touch checks for a low risk UK supplier, enhanced checks for an overseas agent paid on commission in a high risk market.

Ask who ultimately owns the counterparty, whether any owner is a public official or related to one, what the commission rate is and whether it is commercially explicable, and who introduced the relationship. Put anti-bribery, anti-facilitation and audit clauses in the contract, and record the check even when it comes back clean. An unrecorded check is, evidentially, no check.

Step 5: communication and training people will remember

Annual click-through modules satisfy an audit and change almost nothing. Training that works is short, role specific and built around real decisions: what a salesperson does when a client asks for a personal payment to sign, what a finance clerk does with an invoice that does not match the purchase order, what a manager does when a team member reports a concern.

Train the associated persons too where the risk justifies it. An agent in a high risk market who has never been told your standards is a gap that no internal training programme closes.

Step 6: monitoring, review and the evidence trail

A programme that is never tested cannot be shown to be reasonable. Monitoring means sampling the gifts register rather than merely maintaining it, testing whether due diligence was actually performed on a sample of new suppliers, reviewing whistleblowing reports for themes, and re-running the risk assessment when the business changes.

Review triggers are worth naming in advance: entering a new market, acquiring a business, launching a commission based product, a near miss, an incident at a competitor. Each of those changes the risk picture, and a programme dated three years ago will be judged against the business as it is now.

The failures that come up again and again

Policies written before the risk assessment. The order is not cosmetic. Procedures that cannot be traced to an identified risk cannot be shown to be proportionate.

A whistleblowing line that reports to the wrong person. If concerns route to the head of the function most likely to be implicated, the channel will go quiet, and silence will later be read as absence of concerns rather than absence of trust.

Incentives that pull against the code. A commission scheme with a cliff edge at the year end creates exactly the pressure the fraud offence was written about. Compliance and reward design are the same conversation.

No record. The defence is evidential. Undated policies, untracked training, unminuted board discussions and unrecorded due diligence all fail at the point they are needed most.

Where to start this month

If you have nothing, do these four things in order. Run and document a risk assessment covering bribery, tax evasion facilitation and fraud. Take it to the board and minute the discussion. Write the two or three policies the assessment actually justifies. Then train the roles that face the risks you identified, and diarise the review.

The government's own guidance is short and worth reading in the original: the Ministry of Justice guidance on adequate procedures under the Bribery Act and the Home Office guidance on the failure to prevent fraud offence.

Frequently Asked Questions

What is a corporate compliance programme?

It is the set of procedures, controls, training and oversight a business uses to stop its own people and its associated persons committing offences on its behalf, and to prove it tried. In the UK the phrase has a specific legal weight, because three separate criminal offences give an organisation a defence if it can show it had adequate or reasonable procedures in place. The programme is that evidence.

Which UK laws require a compliance programme?

No law requires one in so many words. Three create a strong incentive: section 7 of the Bribery Act 2010, which has an adequate procedures defence; sections 45 and 46 of the Criminal Finances Act 2017 on failure to prevent the facilitation of tax evasion, which has a reasonable prevention procedures defence; and the failure to prevent fraud offence under the Economic Crime and Corporate Transparency Act 2023, in force since 1 September 2025, which has a reasonable procedures defence. In each case, no procedures means no defence.

Does the failure to prevent fraud offence apply to small companies?

The offence itself applies to large organisations, defined as those meeting two or more of three tests: more than 250 employees, more than £36 million turnover, and more than £18 million in total assets. Smaller companies are outside it, but they are still fully inside the Bribery Act and the Criminal Finances Act, neither of which has a size threshold, and a small subsidiary of a large group is caught through the group.

What does proportionate actually mean?

It means the size of the procedure should match the size of the risk, and that you should be able to show your working. A UK-only design agency with no public sector clients and no overseas agents does not need the third party due diligence regime a construction group with Middle East joint ventures needs. What both need is a documented risk assessment explaining why they landed where they did.

Who should own the programme?

Someone senior enough to say no to revenue. In a small company that is usually a director; in a larger one a compliance lead reporting to the board or the audit committee. What matters is that the owner is not the same person whose targets the programme constrains, and that the board sees the programme's output rather than hearing that it exists.

How long does it take to build one?

A credible first version for a mid-sized UK business is a matter of months, not years, and the sequence matters more than the speed. Risk assessment first, then the policies the risk assessment justifies, then training, then the monitoring that proves it works. A polished policy suite written before any risk assessment is the most common way to spend six months and end up with no defence.