Skip to content

Evidence request lists

UK Bribery Act 2010

Evidence request list. 20 controls, 20 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 12 September 2026. Published by The Art of Service.

Bribery Act Sections 1 to 6: Offences

Section 1
Offence of Bribing Another Person

It is an offence to offer, promise, or give a financial or other advantage to induce improper performance.

Artefacts an auditor will ask for
  • Documented procedure addressing offence of bribing another person
  • Evidence of executive or risk owner approval
  • Operational records demonstrating execution
  • Independent assurance or review report
Where this commonly fails
  • Procedure exists but execution inconsistent
  • Owner accountability not codified
  • Review cadence missed or undocumented
  • Coverage gaps for in scope entities or systems
Section 3
Function or Activity to Which Bribe Relates

Defines the relevant functions including public functions, business activities, and employment duties.

Artefacts an auditor will ask for
  • Documented procedure addressing function or activity to which bribe relates
  • Evidence of executive or risk owner approval
  • Operational records demonstrating execution
  • Independent assurance or review report
Where this commonly fails
  • Procedure exists but execution inconsistent
  • Owner accountability not codified
  • Review cadence missed or undocumented
  • Coverage gaps for in scope entities or systems
Section 4
Improper Performance Test

Performance is improper if it breaches a relevant expectation of good faith, impartiality, or trust.

Artefacts an auditor will ask for
  • Anti bribery and corruption policy
  • Gifts and hospitality register
  • Third party due diligence records
  • Training completion records for high risk roles
Where this commonly fails
  • Register thresholds not enforced
  • Intermediary due diligence shallow
  • No targeted training for sales or procurement
  • Whistleblowing channel underused
Section 6(3)
Influence and Business Advantage

The offence requires intent to influence the official to obtain or retain business or a business advantage.

Artefacts an auditor will ask for
  • Documented procedure addressing influence and business advantage
  • Evidence of executive or risk owner approval
  • Operational records demonstrating execution
  • Independent assurance or review report
Where this commonly fails
  • Procedure exists but execution inconsistent
  • Owner accountability not codified
  • Review cadence missed or undocumented
  • Coverage gaps for in scope entities or systems
Section 6(5)
Definition of Foreign Public Official

Includes any person holding legislative, administrative, or judicial positions or performing public functions.

Artefacts an auditor will ask for
  • Anti bribery and corruption policy
  • Gifts and hospitality register
  • Third party due diligence records
  • Training completion records for high risk roles
Where this commonly fails
  • Register thresholds not enforced
  • Intermediary due diligence shallow
  • No targeted training for sales or procurement
  • Whistleblowing channel underused

Bribery Act Sections 10 to 15: Prosecution, Penalties and Jurisdiction

Section 10
Consent to Prosecution

No prosecution may be instituted without the consent of the DPP or Director of the SFO.

Artefacts an auditor will ask for
  • Consent capture mechanism design records
  • Consent log with timestamp and purpose linkage
  • Withdrawal workflow evidence
  • Privacy notice version aligned to consent text
Where this commonly fails
  • Bundled consent across distinct purposes
  • Withdrawal not as easy as granting consent
  • Records lack granularity per processing purpose
  • Children consent thresholds not enforced
Section 11
Penalties for Individuals

Individuals face up to 10 years imprisonment on indictment and unlimited fines for bribery offences.

Artefacts an auditor will ask for
  • Legal register tracking enforcement risk
  • Counsel opinion on liability exposure
  • Self disclosure decision records
  • Insurance coverage evidence
Where this commonly fails
  • Legal register not refreshed for new enforcement actions
  • Director and officer awareness thin
  • Self disclosure protocols undefined
  • Cooperation credit strategy absent
Section 11(3)
Penalties for Organisations

Organisations convicted of bribery offences or failure to prevent bribery face unlimited fines.

Artefacts an auditor will ask for
  • Legal register tracking enforcement risk
  • Counsel opinion on liability exposure
  • Self disclosure decision records
  • Insurance coverage evidence
Where this commonly fails
  • Legal register not refreshed for new enforcement actions
  • Director and officer awareness thin
  • Self disclosure protocols undefined
  • Cooperation credit strategy absent
Section 12
Territorial Jurisdiction

Offences apply to acts committed in the UK or abroad by persons with a close connection to the UK.

Artefacts an auditor will ask for
  • Legal register tracking enforcement risk
  • Counsel opinion on liability exposure
  • Self disclosure decision records
  • Insurance coverage evidence
Where this commonly fails
  • Legal register not refreshed for new enforcement actions
  • Director and officer awareness thin
  • Self disclosure protocols undefined
  • Cooperation credit strategy absent
Section 13
Defence for Intelligence Services

Conduct necessary for the proper exercise of intelligence service functions is a defence.

Artefacts an auditor will ask for
  • Documented procedure addressing defence for intelligence services
  • Evidence of executive or risk owner approval
  • Operational records demonstrating execution
  • Independent assurance or review report
Where this commonly fails
  • Procedure exists but execution inconsistent
  • Owner accountability not codified
  • Review cadence missed or undocumented
  • Coverage gaps for in scope entities or systems
Section 14
Senior Officer Consent or Connivance

Senior officers of organisations are personally liable if bribery is committed with their consent or connivance.

Artefacts an auditor will ask for
  • Consent capture mechanism design records
  • Consent log with timestamp and purpose linkage
  • Withdrawal workflow evidence
  • Privacy notice version aligned to consent text
Where this commonly fails
  • Bundled consent across distinct purposes
  • Withdrawal not as easy as granting consent
  • Records lack granularity per processing purpose
  • Children consent thresholds not enforced
Section 15
Deferred Prosecution Agreements

Organisations may enter deferred prosecution agreements as an alternative to trial for bribery offences.

Artefacts an auditor will ask for
  • Legal register tracking enforcement risk
  • Counsel opinion on liability exposure
  • Self disclosure decision records
  • Insurance coverage evidence
Where this commonly fails
  • Legal register not refreshed for new enforcement actions
  • Director and officer awareness thin
  • Self disclosure protocols undefined
  • Cooperation credit strategy absent

Bribery Act Sections 7 to 9: Failure to Prevent and Adequate Procedures

Section 7(2)
Adequate Procedures Defence

Defence is available if the organisation had adequate procedures in place to prevent bribery.

Artefacts an auditor will ask for
  • Operating procedures register
  • SOP review cadence evidence
  • Approval workflow records
  • Deviation log with root cause
Where this commonly fails
  • SOPs out of date versus current practice
  • Deviations rarely logged
  • Approvals retrofitted
  • Version control inconsistent
Section 8
Definition of Associated Person

An associated person performs services for the organisation including employees, agents, and subsidiaries.

Artefacts an auditor will ask for
  • Documented procedure addressing definition of associated person
  • Evidence of executive or risk owner approval
  • Operational records demonstrating execution
  • Independent assurance or review report
Where this commonly fails
  • Procedure exists but execution inconsistent
  • Owner accountability not codified
  • Review cadence missed or undocumented
  • Coverage gaps for in scope entities or systems
Section 9
Guidance on Adequate Procedures

Secretary of State must publish guidance on procedures organisations can put in place to prevent bribery.

Artefacts an auditor will ask for
  • Operating procedures register
  • SOP review cadence evidence
  • Approval workflow records
  • Deviation log with root cause
Where this commonly fails
  • SOPs out of date versus current practice
  • Deviations rarely logged
  • Approvals retrofitted
  • Version control inconsistent

Due Diligence

UKBRIBE-3
Due Diligence on Third Parties

Per Bribery Act 2010 Principle 4: due diligence on third parties + agents + business partners + ongoing monitoring.

Artefacts an auditor will ask for
  • UK Bribery evidence for UKBRIBE-3
Where this commonly fails
  • adequate procedures + DD partial

Monitoring

UKBRIBE-5
Monitoring, Review, Reporting

Per Bribery Act 2010 Principle 6: monitoring + review + reporting including whistleblower investigations + SFO cooperation + DPA (Deferred Prosecution Agreement).

Artefacts an auditor will ask for
  • UK Bribery evidence for UKBRIBE-5
Where this commonly fails
  • adequate procedures + DD partial

Risk Assessment

UKBRIBE-1
Section 7 Strategic Risk Assessment and Adequate Procedures

Per UK Bribery Act 2010 Section 7: failure to prevent bribery offence. Implement adequate procedures defense. Requirements include (a) Proportionate procedures + (b) Top-level commitment + (c) Risk assessment + (d) Due diligence + (e) Communication + Training + (f) Monitoring + Review.

Artefacts an auditor will ask for
  • UK Bribery evidence for UKBRIBE-1
Where this commonly fails
  • adequate procedures + DD partial

Top-Level Commitment

UKBRIBE-2
Top-Level Commitment and Governance

Per Bribery Act 2010 Principle 2: top-level commitment + board oversight + governance + accountability.

Artefacts an auditor will ask for
  • UK Bribery evidence for UKBRIBE-2
Where this commonly fails
  • adequate procedures + DD partial

Training

UKBRIBE-4
Communication, Training, Awareness

Per Bribery Act 2010 Principle 5: communication + training + awareness including role-based + onboarding + refresher + whistleblowing.

Artefacts an auditor will ask for
  • UK Bribery evidence for UKBRIBE-4
Where this commonly fails
  • adequate procedures + DD partial
Assembled from the framework's own control set. Every line traces to a control in the graph, so this pack is regenerated rather than written, and stays current as the graph does.

Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the UK Bribery Act 2010 framework page.