SFO Updates its Approach to the Evaluation of Corporate Compliance Programmes

The UK Serious Fraud Office (SFO) has released a revised Guidance on Evaluating a Corporate Compliance Programme (hereinafter – Guidance).

6 min
Hand choosing documents

According to the Guidance, the SFO may evaluate a corporate compliance programme in the following circumstances:

1) When deciding whether to prosecute a corporate entity in accordance with the SFO-CPS Corporate Prosecution Guidance.

In this context, the prosecutor must assess the appropriateness of prosecuting a corporate entity both (a) by reference to the evidential stage and (b) by reference to the public interest stage of the Full Code Test. A public interest factor tending in favour of prosecution is that “the offending took place at a time when the company had an ineffective compliance programme in place”. Conversely, public interest factors tending against prosecution include situations where senior management demonstrates a genuinely proactive approach, including the taking of “remedial action” (for example, improvements to the compliance programme), or where the organisation has a “genuinely proactive and effective compliance programme”.

2) When deciding whether it is appropriate to enter into a Deferred Prosecution Agreement (DPA) in accordance with the DPA Code of Practice.

When considering whether it would be in the public interest to resolve a case by way of a DPA rather than by prosecution, the prosecutor will take into account that:

  • a public interest factor tending in favour of prosecution is where “the offending took place at a time when the organisation had no, or an ineffective, compliance programme, and the organisation has since been unable to demonstrate significant improvements to its compliance programme”;
  • public interest factors tending against prosecution include cooperation with law enforcement authorities and a “genuinely proactive” approach demonstrated by the organisation’s senior management following the discovery of the offending, including the taking of remedial action, as well as the existence of a proactive compliance programme at the time of the offending and at the time of reporting, which nevertheless proved ineffective in the particular circumstances.

The DPA Code of Practice also expressly states that “the existence of a genuinely proactive and effective compliance programme is an important factor in deciding whether a DPA is appropriate”.

For the purposes of assessing an organisation’s compliance culture and compliance programme, the prosecutor may engage external experts or other external resources, including for the analysis of information contained in the organisation’s self-report.

3) When assessing compliance with DPA compliance obligations and/or conducting monitoring in the context of a DPA.

Pursuant to the Crime and Courts Act 2013, a DPA may impose an obligation on an organisation to “implement a compliance programme or to make changes to an existing compliance programme relating to corporate policies and/or employee training”. The DPA Code of Practice provides that the terms of a DPA must be tailored to the particular circumstances of the case and must be fair, reasonable and proportionate to the offending. Accordingly, a prosecutor considering the use of a DPA must assess whether it is appropriate to include such compliance-related terms, be prepared to justify them before the court and, if included, be able to assess the organisation’s compliance with those obligations over the duration of the DPA.

A DPA may also provide for independent monitoring. Where it is decided that monitoring should form part of the DPA terms, it will be necessary to assess the appropriate scope and content of the monitoring programme, to take into account relevant external guidance and standards on compliance programmes, and to recognise that one of the key responsibilities of the monitor is to “advise on necessary compliance improvements designed to reduce the risk of repetition of the conduct which is the subject of the DPA”.

4) Where an organisation seeks to rely on the defence of having “adequate procedures” in relation to an offence of failure to prevent bribery under section 7 of the Bribery Act 2010.

Reliance on this defence requires an assessment of whether the organisation’s procedures were “adequate”, rather than an assessment of the “compliance programme” as such. Although the burden of proof rests with the organisation and is to be discharged on the balance of probabilities, the likelihood of successfully establishing this defence remains an important factor when considering the evidential sufficiency for a decision to prosecute the organisation (see section 1 above).

The Ministry of Justice has published statutory guidance on procedures that relevant commercial organisations can put in place to prevent bribery (Bribery Act 2010: Guidance to Help Commercial Organisations Prevent Bribery). That guidance sets out six principles which should be taken into account when designing such procedures:

  • proportionate procedures, aligned to the bribery risks faced by the organisation, that are clear, practical, accessible, effectively implemented and enforced;
  • top-level commitment to preventing bribery and to fostering an appropriate culture within the organisation;
  • periodic, informed and documented assessment of bribery risks;
  • due diligence on associated persons, applying a proportionate and risk-based approach;
  • communication (including training) to ensure that bribery prevention policies and procedures are embedded and understood throughout the organisation;
  • monitoring and review of bribery prevention procedures, with improvements made where necessary.

5) Where an organisation seeks to rely on the defence of having “reasonable procedures” in relation to an offence of failure to prevent fraud under section 199 of the Economic Crime and Corporate Transparency Act 2023 (ECCTA).

Under that provision, an organisation may have a defence if, at the time the offence was committed, it had reasonable procedures in place to prevent fraud, or if it can demonstrate that it was unreasonable in the particular circumstances to expect it to have any such procedures.

As in section 4 above, the assessment in this context focuses on the “reasonableness” of the procedures rather than on the compliance programme as a whole. The burden of proof rests with the organisation, but the likelihood of successfully meeting the balance of probabilities standard is a significant factor when assessing evidential sufficiency for the purposes of a prosecution decision.

The UK Home Office has published statutory guidance on procedures that relevant organisations can implement to prevent fraud (Economic Crime and Corporate Transparency Act 2023: Guidance to Organisations on the Offence of Failure to Prevent Fraud). Under this guidance, such procedures are based on principles which largely mirror those in the Bribery Act Guidance:

  • top-level commitment to preventing fraud, fostering an appropriate organisational culture, and the rejection of profits derived from fraudulent conduct;
  • a fraud risk assessment that is dynamic, documented and regularly reviewed;
  • proportionate procedures aligned to the identified fraud risks faced by the organisation, which are clear, practical, accessible, effectively implemented and enforced;
  • due diligence on associated persons, applying a proportionate and risk-based approach;
  • communication (including training) to ensure that fraud prevention policies and procedures are embedded and understood at all levels of the organisation;
  • monitoring and review of fraud prevention procedures, taking into account the outcomes of investigations, whistleblowing reports and relevant sectoral information, with procedures updated where necessary.

6) Where the existence and nature of a compliance programme is a material factor in determining the level of sanctions.

The Sentencing Council Fraud, Bribery and Money Laundering Offences Definitive Guideline provides for the assessment of an organisation’s compliance arrangements when determining sentence.

In particular, in cases under section 7 of the Bribery Act (failure to prevent bribery), “high culpability” includes the presence of “a culture of wilful disregard of the commission of offences by employees or agents and a failure to put in place effective systems and controls”. “Lesser culpability” applies where “some effort has been made to put bribery prevention measures in place but these are insufficient to amount to a defence”. In addition, as an alternative approach to assessing harm, courts may consider “the likely cost avoided by failing to put in place appropriate bribery prevention measures”.

Although this Guideline has not yet been updated to reflect the newly introduced offence of failure to prevent fraud, the Guidance notes that it can be expected that the culpability factors applicable to that offence will be similar to those applied in failure to prevent bribery cases.

Compliance Responsibility