Get legal help for your business.

Get legal help for your business.

Get In Touch

Section 17A Anti-Bribery: The Adequate Procedures Defence for Government Contractors

Published :

Published :

Last Update:

Last Update:

Governance

Governance

Operation

Operation

By

By

AKMAL SAUFI MOHAMED KHALED

AKMAL SAUFI MOHAMED KHALED

Section 17A of the Malaysian Anti-Corruption Commission Act 2009 makes a company criminally liable when a person associated with it corruptly gives or offers a bribe to win or keep business for the company. The only defence in the section is proving the company had adequate procedures in place to prevent that conduct. On conviction the fine is not less than ten times the value of the gratification or RM1 million, whichever is higher — a floor, not a ceiling. This guide covers what the section reaches, what the five T.R.U.S.T. principles in the Government's Guidelines on Adequate Procedures require, what a defensible framework contains and what drives its cost, and where government contractors carry exposure that other commercial organisations do not.

Most boards first look properly at Section 17A when a tender document asks for evidence of an anti-bribery management system, or when a buyer's due diligence request list arrives with "adequate procedures" on it. By that point the question is no longer whether to build a framework. It is whether one can be built, operated and evidenced quickly enough to be worth anything.

What does Section 17A actually make your company liable for?

Section 17A(1) provides that a commercial organisation commits an offence if a person associated with it corruptly gives, agrees to give, promises or offers any gratification to any person, whether for that person's benefit or another's, with intent to obtain or retain business for the organisation, or to obtain or retain an advantage in the conduct of the organisation's business.

Two features matter commercially. First, the offence is committed by the organisation itself — the prosecution does not have to show the board knew, approved or turned a blind eye. Second, the recipient does not have to be a public official; Section 17A reaches private-sector bribery on the same terms. The section was inserted by the Malaysian Anti-Corruption Commission (Amendment) Act 2018 and came into force on 1 June 2020.

Who counts as a "commercial organisation" and a "person associated with" it?

Section 17A(8) defines a commercial organisation as: a company incorporated under the Companies Act 2016 carrying on a business in Malaysia or elsewhere; a company wherever incorporated carrying on a business or part of a business in Malaysia; a partnership under the Partnership Act 1961 or a limited liability partnership under the Limited Liability Partnerships Act 2012 carrying on a business in Malaysia or elsewhere; or a partnership wherever formed carrying on a business or part of a business in Malaysia.

Two adjacent questions usually come up at the same point in this process: see government and state land agreements in malaysia and privatisation agreement and extension of term for how each is handled.

There is no turnover threshold, no headcount threshold and no carve-out for small companies. A two-director private limited company bidding for a state agency contract sits inside the definition on the same footing as a listed group.

A person is "associated with" a commercial organisation if that person is a director, partner or employee, or is a person who performs services for or on behalf of the organisation. That second limb is where most real exposure sits. It reaches agents, distributors, sales intermediaries, consultants, subcontractors and joint venture partners — the population a company screens least, and the one most often used precisely because it sits outside the organisation's own controls.

What are the penalties under Section 17A?

Who is exposed

Exposure on conviction

Provision

The commercial organisation

Fine of not less than ten times the sum or value of the gratification, where it is capable of being valued or is of a pecuniary nature, or RM1 million, whichever is higher. The section sets a minimum, not a maximum.

s.17A(2)

The commercial organisation, where the gratification cannot be valued

The RM1 million floor applies.

s.17A(2)

Custodial exposure

Imprisonment for a term not exceeding 20 years, or the fine, or both. A company cannot be imprisoned, so in practice this limb operates against the individuals caught by the deeming provision.

s.17A(2)

Directors, controllers, officers, partners, and anyone concerned in the management of the organisation's affairs at the time of the offence

Deemed to have committed the same offence. To escape, the individual must prove the offence was committed without his consent or connivance and that he exercised the due diligence to prevent it that he ought to have exercised.

s.17A(3)

The deeming provision in Section 17A(3) is a separate defence from the adequate procedures defence, with a different test. The organisation defends itself by proving adequate procedures. An individual defends himself by proving both absence of consent or connivance and personal due diligence. A framework that exists on paper but which the individual took no steps to operate helps neither.

What is the adequate procedures defence, and what must you prove?

Section 17A(4) provides that it is a defence for the commercial organisation to prove that it had in place adequate procedures to prevent persons associated with it from undertaking the conduct in question. The burden sits on the organisation, not the prosecution.

Three points a board should be clear about:

  • "Adequate procedures" is not defined in the Act. Adequacy is decided on the facts of the case, judged against the organisation's own risk profile. What is adequate for a domestic services firm is not adequate for a contractor bidding for state infrastructure work through agents.

  • The Guidelines are guidance, not a safe harbour. Section 17A(5) requires the Minister to issue guidelines relating to the procedures in subsection (4). The Guidelines on Adequate Procedures were issued by the Prime Minister's Department on 4 December 2018. Following them is strong evidence. It is not a statutory immunity.

  • The defence is judged as at the time of the conduct. Procedures put in place after an investigation begins do not retrospectively supply the defence. This is the single most important timing point in the section, and the reason a framework is worth building before there is a reason to.

What do the five T.R.U.S.T. principles require?

The Guidelines on Adequate Procedures organise the expected controls under five principles, given the acronym T.R.U.S.T.

Principle

What the Guidelines expect

What it has to look like in evidence

T — Top Level Commitment

Top management is responsible for the organisation practising the highest level of integrity and ethics: establishing and periodically reviewing the anti-corruption policy, appointing competent personnel to oversee it, encouraging whistleblowing, and ensuring audit and risk assessment findings reach the board and are acted on.

Board-approved policy, a named accountable officer, board minutes recording that findings were tabled and what was decided.

R — Risk Assessment

A comprehensive corruption risk assessment at least once every three years, with intermittent assessments whenever necessary — covering governance weaknesses, transactions capable of disguising corrupt payments, higher-risk jurisdictions and sectors, and relationships with third parties in the supply chain such as agents, vendors, contractors and suppliers.

A dated risk register mapping risks to owners and controls, and evidence of the review cycle actually running.

U — Undertake Control Measures

Controls proportionate to the risks identified: a general anti-bribery and anti-corruption policy; conflicts of interest; gifts, entertainment, hospitality and travel; donations and sponsorships including political donations; facilitation payments; financial controls with separation of duties and approving powers; a trustworthy whistleblowing channel; and record-keeping.

Written policies with thresholds and approval routes, registers that are actually populated, third-party due diligence files, and anti-bribery clauses in third-party contracts.

S — Systematic Review, Monitoring and Enforcement

Regular internal and/or external review of the effectiveness of the anti-corruption policies, a defined monitoring programme, continual improvement, and disciplinary action against personnel who breach the policies. The Guidelines contemplate an external audit by a qualified and independent third party — an MS ISO 37001 auditor is the example given — at least once every three years.

Audit reports, a monitoring plan with scope and frequency, and a record of enforcement action actually taken.

T — Training and Communication

Training programmes and continuing communication with personnel and business associates on the policies, the reporting channels, and the consequences of non-compliance. The anti-corruption policy should be publicly available and communicated to personnel and business associates.

Attendance records, induction and role-specific training content, dated communications, and the policy visible externally.

The pattern across all five is the same: the Guidelines care less about whether a document exists than about whether the organisation can show the control was operating. Third-party screening is the clearest example — a control measure under "U", a risk category under "R", and where the associated-person limb bites hardest. It is also a standard line item in a buyer's compliance review, as our guide to due diligence in mergers and acquisitions sets out.

Do government contractors carry additional exposure?

Yes — not because Section 17A treats them differently, but because the procurement regime layers further requirements on top of it, and because the consequences of an allegation reach your eligibility to bid, not just your criminal exposure.

  • Integrity Pact in government procurement. The Integrity Pact is set out in Treasury circular Pekeliling Perbendaharaan PK 1.6 — Integriti Dalam Perolehan Kerajaan, in force 1 June 2022 and amended with effect from 1 April 2023, which consolidated the requirement first introduced by Surat Pekeliling Perbendaharaan Bil. 10 Tahun 2010. Under it bidders and successful bidders sign declarations that they have not offered and will not offer any inducement in connection with the procurement, and that they will report any solicitation. Breaching that declaration is a contractual and procurement matter in its own right, separate from any prosecution — a bid can be rejected, a contract can be exposed to termination, and the contractor can face action under government procurement rules.

  • Mandatory MS ISO 37001 for G7 construction contractors. CIDB has announced mandatory MS ISO 37001:2016 anti-bribery management system certification for Grade G7 contractors, issued as Pekeliling CIDB Bil. 1/2026. The mandate and its G7 scope are confirmed on CIDB's own announcement. Industry commentary reports that it applies to new SPKK applications and renewals from 1 January 2027 — confirm the commencement date and scope against the circular or with CIDB before relying on either. For a G7 contractor this converts anti-bribery compliance from a legal risk question into a licensing condition.

  • Reputational and eligibility consequences run ahead of any conviction. An open investigation, a raid, or a charge against a director is disclosable in tender submissions, in listed-company counterparty onboarding, and in financing and acquisition due diligence. Those consequences arrive years before a verdict does.

Contractors working through local partners or facilitators to secure approvals, permits or introductions are exposed on the associated-person limb whether or not the recipient is a public officer.

What goes into an adequate procedures framework, and what drives the cost?

A framework capable of supporting the Section 17A(4) defence is a documented system plus the operating record that shows it ran. In practice the build covers:

  • A corruption risk assessment mapped to the business — functions, geographies, counterparty types, and the transaction points where value can be moved.

  • The core policy set: anti-bribery and anti-corruption; gifts, entertainment, hospitality and travel; donations, sponsorships and political contributions; conflicts of interest; facilitation payments.

  • Third-party due diligence: a risk-tiered screening process for agents, distributors, subcontractors and consultants, and anti-bribery, audit and termination clauses in their contracts.

  • Financial controls: approval limits, separation of duties, and payment controls at the points the risk assessment flagged.

  • A whistleblowing channel with a defined route to the board, and protection for the reporter.

  • Training and communication, with attendance records, and induction and role-specific content for higher-risk roles.

  • Monitoring, review, board reporting and enforcement — including the disciplinary route, which is normally delivered through your employment agreements and handbook.

What drives the cost. Headcount and number of operating sites; the number and type of third parties in the chain; whether the organisation deals with public bodies, GLCs or statutory bodies; group structure and any overseas operations; the state of the existing policy set; and whether MS ISO 37001 certification is required, which adds an accredited certification body's audit cycle on top of the legal build. A single-entity business with a clean policy base and few intermediaries is a materially smaller exercise than a multi-entity contractor group operating through agents.

What you need to provide. The organisation chart and approval matrix; a list of agents, distributors, subcontractors and consultants; procurement and payment approval limits; existing policies and the employee handbook; the current tender and government contract list; any past incident, complaint or whistleblowing records; and board and audit committee terms of reference. The risk assessment cannot be done credibly without these, and the quality of this input is the main determinant of how long the build takes.

Sequencing. The risk assessment comes first, because it determines which controls are proportionate — policies drafted before the assessment produce a generic pack that is hard to defend as "adequate" for your risk profile. Where certification is required, the framework must be built and operating before an accredited audit can be scheduled, so the certification deadline works backwards into when the legal build has to start.

What does doing nothing actually cost?

The fine floor under Section 17A(2) is the visible number, but it is rarely the largest one. The costs that arrive first are commercial: a tender that cannot be submitted because the anti-bribery evidence pack does not exist; a G7 renewal that cannot be made; an acquisition or financing that stalls because the buyer's compliance review flags an unaddressed Section 17A exposure — precisely the kind of finding covered in our guide to red flags in legal due diligence, and one that transfers to the buyer on a share purchase.

There is also a structural point about timing. Because the defence is assessed as at the time of the conduct, the value of a framework is fixed on the day it starts operating and cannot be recovered afterwards. An organisation that begins building after the first MACC letter arrives has spent the money and still has no defence for the period that matters. That makes this a scheduling question more than a budgeting one.

Frequently Asked Questions

Does Section 17A apply to small companies?

Yes. The definition of "commercial organisation" in Section 17A(8) contains no turnover, headcount or revenue threshold. It captures companies incorporated under the Companies Act 2016, partnerships and limited liability partnerships. What changes with size is what counts as adequate, not whether the section applies.

Does Section 17A apply to foreign companies?

Yes. Section 17A(8) expressly includes a company wherever incorporated that carries on a business or part of a business in Malaysia, and a partnership wherever formed in the same terms. A foreign group with Malaysian operations is within the section.

Is ISO 37001 certification the same as having adequate procedures?

No. Certification to MS ISO 37001 is evidence that a management system meeting the standard exists and has been audited; it is not a statutory safe harbour, and adequacy under Section 17A(4) is decided by the court on the facts. Separately, certification can be a licensing requirement in its own right — CIDB has made MS ISO 37001 certification mandatory for Grade G7 contractors under Pekeliling CIDB Bil. 1/2026. The reported commencement is 1 January 2027, for new SPKK applications and renewals; confirm that against the circular itself before acting on the date.

Are we liable for what our agent or subcontractor does?

You can be. A person who performs services for or on behalf of the organisation is an associated person under Section 17A, so an agent, distributor or subcontractor who offers a bribe with intent to obtain or retain business or an advantage for you can trigger the organisation's liability. Third-party due diligence and contractual anti-bribery obligations are the controls the Guidelines expect against this risk.

Can a director be personally liable if he did not know about the bribe?

Section 17A(3) deems directors, controllers, officers, partners and persons concerned in the management of the organisation's affairs at the time to have committed the offence. The individual must prove the offence was committed without his consent or connivance and that he exercised the due diligence he ought to have exercised. Lack of knowledge alone does not answer the second limb.

How often should the corruption risk assessment be refreshed?

The Guidelines on Adequate Procedures contemplate a comprehensive risk assessment at least once every three years, with intermittent assessments whenever circumstances require — a new market, a new intermediary model, a restructuring, or an incident. The Guidelines also contemplate an external audit by a qualified and independent third party, such as an MS ISO 37001 auditor, at least once every three years.

Does Section 17A only apply to bribing government officers?

No. Section 17A(1) refers to gratification given or offered to "any person". Commercial bribery between private parties, undertaken to win or keep business for the organisation, falls within the section on the same terms.

Putting the framework in place before you need it

Because the adequate procedures defence is judged as at the time of the conduct, the useful time to build is before there is a reason to. Legal That Works advises Malaysian businesses on a Section 17A anti-bribery compliance framework (ABMS) — risk assessment, policy set, third-party due diligence, controls over gifts, hospitality and donations, training, whistleblowing, and the monitoring and record-keeping that make the framework evidenced rather than merely stated. Where the board also wants the surrounding governance record checked, that work sits alongside a corporate governance health check. If you are bidding for government or GLC work, or carry a G7 registration, speak to us with the tender or renewal deadline in hand so the build can be sequenced against it.

This article is for general information only and does not constitute legal advice. Every transaction and every set of facts is different. Obtain specific advice from a qualified adviser before acting on any part of it.

Related guides

Disclaimer

The content provided on this website is intended for general informational and educational purposes only. It does not constitute legal advice, nor should it be relied upon as a substitute for professional consultation with a qualified lawyer. Every legal matter is unique, and you are strongly encouraged to seek tailored legal advice from a licensed legal practitioner before taking any action based on the information available here.

While we endeavour to ensure the accuracy and timeliness of the content, ASCOLAW and its affiliates make no representations or warranties of any kind, express or implied, about the completeness, accuracy, reliability, suitability or availability of the information contained on this website. Any reliance you place on such information is strictly at your own risk.

Author

AKMAL SAUFI MOHAMED KHALED

Managing Partner & Founder

Akmal leads Legal That Works and ASCO LAW with sharp commercial sense and digital flair—guiding founders through deals, governance, and automation. He blends law, tech, and strategy to deliver clarity, growth, and real impact for ambitious business owners.

Akmal leads Legal That Works and ASCO LAW with sharp commercial sense and digital flair—guiding founders through deals, governance, and automation. He blends law, tech, and strategy to deliver clarity, growth, and real impact for ambitious business owners.

Practice Area

Commercial

Corporate

Government

Business Function

Governance

Governance

Operation

Operation

Need help with your business?

Submit the contact form

Go through a discovery session with our lawyer

We will come out with a proposal to assist you.

Need help with your business?

Submit the contact form

Go through a discovery session with our lawyer

We will come out with a proposal to assist you.

Legal That Works logo

Legal That Works (Messrs Akmal Saufi & Co) is a Malaysian business friendly legal services firm providing services across multiple industries and practice area fuelling business growth and ambition.

All rights reserved. © Legal That Works is a legal service by Messrs Akmal Saufi & Co (Registration No. 00020004166). 2014-2026
Regulated by the Malaysian Bar Council under the Legal Profession Act 1976.

Legal That Works logo

Legal That Works (Messrs Akmal Saufi & Co) is a Malaysian business friendly legal services firm providing services across multiple industries and practice area fuelling business growth and ambition.

All rights reserved. © Legal That Works is a legal service by Messrs Akmal Saufi & Co (Registration No. 00020004166). 2014-2026

Regulated by the Malaysian Bar Council under the Legal Profession Act 1976.