Several jurisdictions have adopted corporate offences of failing to prevent misconduct by associated persons, with a defence where the organisation had adequate procedures in place.
Structure. The offence is committed where a person associated with the organisation commits the underlying conduct intending to benefit it. Corporate intent is not required, which makes prosecution far easier than under identification doctrines.
Associated persons defined broadly — employees, agents, subsidiaries and service providers performing services for the organisation.
The defence. That the organisation had in place procedures proportionate to its risk, designed to prevent the conduct. The burden is on the organisation.
Guidance principles. Proportionate procedures; top-level commitment; risk assessment; due diligence on associated persons; communication including training; and monitoring and review.
Extension. These offences have been extended in some jurisdictions beyond bribery to tax evasion facilitation and to fraud, with the same defence structure.
Practical consequence. The compliance programme is not merely mitigation; it is the defence. Documentation of the risk assessment and of the procedures’ operation is what establishes it, and a programme that exists on paper without evidence of operation will not.