6.1 Bribery + corruption — UKBA, FCPA, adequate procedures
▼UK Bribery Act 2010 — the four offences syllabus 1.1
| Section | Offence |
|---|---|
| s.1 | Offering / promising / giving a bribe (active) |
| s.2 | Requesting / agreeing / accepting a bribe (passive) |
| s.6 | Bribery of foreign public officials |
| s.7 | Corporate offence — failure of commercial organisation to prevent bribery |
Max individual sentence: 10 years imprisonment + unlimited fine. Corporate: unlimited fine + reputational damage + potential public-contract exclusion.
UKBA s.7 — the corporate "failure to prevent" offence syllabus 1.2
The most significant innovation of the UKBA: strict-liability corporate offence where an associated person (employee, agent, subsidiary) bribes to secure business for the firm.
Only defence: "adequate procedures" to prevent bribery — see §1.3.
Extraterritorial reach: applies to any organisation that carries on business (or part of business) in the UK, regardless of where the bribery took place.
Adequate procedures — the six principles syllabus 1.3
Ministry of Justice guidance on the s.7 defence sets out six principles:
- Proportionate procedures — risk-based, proportionate to size + risk
- Top-level commitment — board + senior management visibly committed
- Risk assessment — periodic, documented
- Due diligence — on associated persons (third parties, agents)
- Communication + training
- Monitoring + review
These principles are also the template for the s.7 defence pattern replicated in the CFA 2017 tax CCO and the ECCT 2023 failure-to-prevent-fraud offence.
US Foreign Corrupt Practices Act (FCPA) 1977 syllabus 1.4
Two prongs:
- Anti-bribery — prohibits offering / paying anything of value to foreign officials to obtain / retain business
- Accounting — books + records + internal controls requirements (applies to SEC issuers)
Enforced by: DOJ (criminal) + SEC (civil, for issuers). Extraterritorial reach: US persons + US issuers + foreign persons acting within US territory. Recent enforcement often via Deferred Prosecution Agreements (DPAs).
UKBA vs FCPA — key differences syllabus 1.5
| Aspect | UKBA | FCPA |
|---|---|---|
| Coverage | Public + private sector | Foreign public officials only |
| Facilitation payments | NOT permitted | Narrow exception (limited to small routine payments) |
| Corporate strict-liability | s.7 offence | Piercing corporate veil case-by-case |
| "Adequate procedures" defence | Yes | Compliance programme = mitigation, not defence |
| Extraterritorial reach | Any UK-nexus business | US persons + US-issuer accounting |
Gifts + hospitality controls syllabus 1.6
Modest gifts + hospitality aren't automatically bribery — but firms need controls to distinguish. Typical policy features:
- Value threshold (e.g. ≤£100 per gift / occasion) below which pre-approval not required
- Pre-approval required above threshold
- Absolute prohibition on gifts/hospitality to/from public officials during decision-critical periods (tender, licensing, regulatory review)
- Register of gifts + hospitality received / given
- Enhanced controls for higher-risk relationships (foreign officials, key clients)
6.2 Fraud — categories, APP scams, ECCT
▼Fraud — the categories syllabus 2.1
UK Fraud Act 2006 — three principal offences (s.1):
- Fraud by false representation (s.2)
- Fraud by failing to disclose information (s.3)
- Fraud by abuse of position (s.4)
Common typologies:
- Payment fraud (card fraud, cheque fraud)
- Investment fraud (Ponzi, boiler room)
- Identity fraud
- Insurance fraud
- Mortgage fraud
- Business email compromise (BEC) — see §6.6
- Internal fraud (see §6.2 below)
APP scams — the UK response syllabus 2.2
Authorised Push Payment (APP) scams — customer is deceived into authorising a payment to a fraudster (impersonating bank, police, HMRC, contractor, romantic interest).
Scale: UK Finance reported £485m stolen via APP scams in 2022, £460m in 2023 — persistent large-scale problem.
Regulatory response — PSR mandatory reimbursement effective October 2024:
- Payment firms (both sending + receiving) must reimburse victims (subject to caps + limited defences)
- Reimbursement cap: £415k per claim (raised from initial £85k proposal)
- Consumer standard of caution defence (limited)
UK ECCT 2023 — failure-to-prevent-fraud syllabus 2.3
Economic Crime and Corporate Transparency Act 2023 introduces a new corporate offence: failure to prevent fraud committed by employees / agents for the organisation's benefit. In force Sept 2025.
Scope: large organisations only — meets 2 of 3 tests:
- >250 employees
- >£36m turnover
- >£18m total assets
Defence: "reasonable procedures" (identical pattern to UKBA s.7 + CFA 2017 CCO). See [[Ch 7]] for the full ECCT summary.
Internal fraud — rogue traders syllabus 2.4
Historic mega-losses from internal fraud (rogue traders):
- Barings Bank — Nick Leeson · $1.4bn · 1995 (bank collapse)
- Société Générale — Jérôme Kerviel · €4.9bn · 2008
- UBS — Kweku Adoboli · $2.3bn · 2011
- JPMorgan London Whale — Bruno Iksil · $6bn · 2012
Common root causes: inadequate segregation of duties, weak trade-cancellation controls, management pressure for returns, ignored risk alerts, back-office short-cuts.
6.3 Sanctions — OFAC, OFSI, screening
▼Sanctions violation — key risk exposure syllabus 3.1
Sanctions breaches typically produce the largest enforcement fines in financial crime:
- BNP Paribas — $8.9bn · 2014 (Sudan, Cuba, Iran)
- HSBC — $1.9bn · 2012 (Mexico + Iran/Sudan)
- Commerzbank — $1.5bn · 2015
- Standard Chartered — multiple settlements ~$1.7bn
- Binance — $4.3bn · 2023 (Iran, Cuba, Syria, DPRK)
US OFAC extraterritorial reach syllabus 3.2
OFAC sanctions apply to any transaction touching:
- A US person (citizen, resident, US entity)
- The US dollar (cleared through US correspondent banks)
- US-origin goods or technology
- US financial infrastructure
This is why global banks obsess about US sanctions — a wire cleared in USD pulls US jurisdiction even where neither party is US-connected. BNP Paribas' $8.9bn 2014 fine had no US party in the transactions themselves.
UK OFSI — strict liability from June 2022 syllabus 3.3
The Office of Financial Sanctions Implementation (OFSI) moved to strict-liability civil enforcement in June 2022 — under the Economic Crime (Transparency and Enforcement) Act 2022.
Impact: no need for OFSI to prove that the firm knew or had reasonable cause to know it was breaching sanctions. Mere factual breach can trigger a monetary penalty.
Raised enforcement risk substantially — post-Russia, firms need robust screening + governance around sanctions decisions.
Sanctions evasion typologies syllabus 3.4
Post-Russia (Feb 2022) has taught the industry the modern evasion playbook:
- Third-country routing — via Turkey, UAE, Kazakhstan, Kyrgyzstan (import re-export)
- Shell company networks — layers of front companies
- Ship-to-ship transfers + flag hopping — for oil, coal
- Alternative payment mechanisms — crypto, gold, informal value transfer
- Deceptive shipping practices — disabled AIS, false certificates of origin
- Family + close-associate proxies — designated person's relatives
Sanctions screening — the list universe syllabus 3.5
Firms must screen against multiple lists:
- UN — Consolidated List (binding globally)
- OFAC SDN — Specially Designated Nationals (US)
- OFSI Consolidated List — UK
- EU Consolidated Sanctions List
- Country-specific autonomous lists (Australia DFAT, Canada, Japan, Switzerland)
- Adverse-media + PEP data (industry vendors: World-Check, Dow Jones, LexisNexis, ComplyAdvantage)
Screening must be at onboarding, at each list update, and typically real-time on transactions.
6.4 Tax evasion — vs avoidance, CCO, CRS
▼Evasion vs avoidance vs planning syllabus 4.1
| Concept | Legal status | Example |
|---|---|---|
| Tax evasion | Criminal offence | Undeclared cash income · false expense claims · offshore hidden accounts |
| Tax avoidance | Legal but often disapproved | Aggressive schemes to reduce tax within letter of law |
| Tax planning | Legal + accepted | ISAs, pensions, allowances, legitimate structures |
The line between avoidance and evasion has narrowed — modern anti-avoidance rules (GAAR in UK, DAC-6 in EU) target aggressive schemes even where technically legal.
UK CFA 2017 — CCO tax offence syllabus 4.2
Criminal Finances Act 2017 introduced the Corporate Criminal Offence (CCO): failure of a corporate to prevent facilitation of tax evasion by an associated person.
Two CCOs:
- Failure to prevent facilitation of UK tax evasion
- Failure to prevent facilitation of foreign tax evasion (subject to dual criminality)
Defence: "reasonable prevention procedures" (same six-principles pattern as UKBA s.7 + ECCT).
Practical: covers any employee or agent who facilitates a customer's evasion — banks, accountants, lawyers, tax advisers all in scope.
CRS — automatic tax information exchange syllabus 4.3
Common Reporting Standard (CRS) — OECD 2014 framework for automatic exchange of financial account information between tax authorities. Signed by 110+ jurisdictions.
Financial institutions report:
- Account holder name + tax residency (self-certified)
- Account balance + income (dividends, interest, sale proceeds)
- To the local tax authority, which shares with the tax authorities of the holder's residency
Key point: US does NOT participate in CRS — the US uses FATCA (bilateral treaties + 30% withholding tax on non-compliant FFIs).
6.5 Market abuse — MAR, insider dealing
▼Market Abuse Regulation (MAR) syllabus 5.1
EU / UK Market Abuse Regulation (MAR) covers three main behaviours:
- Insider dealing — trading on inside info
- Unlawful disclosure — leaking inside info
- Market manipulation — false signals, price manipulation, benchmark manipulation
Enforced in UK by FCA (civil) + prosecuted for criminal cases via CJA 1993 s.52 + FSMA. Max criminal sentence 7 years.
Insider information — the 3-part test syllabus 5.2
Information is "inside" if it is:
- Precise — specific enough to allow conclusions about price impact
- Non-public — not generally available
- Price-sensitive — likely to have significant effect on price if made public
All three must be met. Rumour + gut feel isn't inside info; a specific unannounced acquisition is.
Off-channel communications enforcement syllabus 5.3
Since 2022, US regulators (SEC + CFTC) have levied over $2bn in fines on firms for failing to preserve WhatsApp / text / personal-device business communications. Notable settlements:
- JPM 2021 — $200m (early landmark case)
- 10+ major banks · Sept 2022 — $1.8bn combined
- Additional waves 2023-24 — spread to buy-side firms
Root cause: MAR + record-keeping rules require preservation of business communications. Employees using personal devices bypassed firm surveillance + record-keeping. UK FCA parallel enforcement expected.
6.6 Cybercrime + cyber-enabled fraud
▼Modern cybercrime typologies syllabus 6.1
- Business Email Compromise (BEC) — impersonation of executive/vendor to redirect wire transfers
- Ransomware — encryption + extortion; typical demands in crypto
- Account takeover — credentials stolen via phishing / infostealer malware
- Deepfake / synthetic media fraud — voice/video impersonation of executives
- SIM-swap fraud — bypass SMS 2FA
- Supply-chain attacks — MOVEit, SolarWinds (2020) — enterprise-scale
Ransomware — the sanctions overlay syllabus 6.2
Complexity: many ransomware groups (LockBit, Conti, BlackCat) are US-designated OR linked to sanctioned jurisdictions (Russia, DPRK). Paying ransom can be a sanctions violation.
OFAC 2020 Advisory: paying ransom to a designated person may violate sanctions even where paid via intermediary — mitigating factor if firm engaged law enforcement, but no safe harbour.
6.7 Ch 6 cheat sheet
▼All the numbers + names
| Item | Answer |
|---|---|
| UKBA offences | 4 · s.1 · s.2 · s.6 · s.7 |
| UKBA s.7 defence | Adequate procedures (6 MoJ principles) |
| UKBA max sentence | 10 years imprisonment · unlimited fine |
| UKBA facilitation payments | NOT permitted |
| FCPA prongs | Anti-bribery + accounting (books/records) |
| FCPA facilitation exception | Narrow · discouraged |
| FCPA enforcers | DOJ (criminal) + SEC (civil, issuers) |
| Fraud Act 2006 | False rep · fail to disclose · abuse of position |
| APP reimbursement | PSR mandatory · Oct 2024 · £415k cap |
| ECCT failure to prevent fraud | In force Sept 2025 · large orgs |
| Rogue trader losses | Barings · SocGen · UBS · JPM Whale |
| OFAC reach | US person / USD / US goods / US infrastructure |
| UK OFSI strict liability | June 2022 |
| Sanctions lists | UN · OFAC SDN · OFSI · EU · country-specific |
| CFA 2017 CCO | Failure to prevent facilitation of tax evasion |
| CFA 2017 defence | Reasonable prevention procedures |
| CRS | OECD · 110+ jurisdictions · automatic tax info |
| FATCA | US · bilateral · 30% withholding |
| US in CRS? | NO — US uses FATCA |
| MAR behaviours | Insider dealing · unlawful disclosure · market manipulation |
| Inside info test | Precise · non-public · price-sensitive |
| UK insider dealing (CJA 1993) | Max 7 years |
| Off-channel comms fines | $2bn+ since 2022 (SEC/CFTC) |
| BEC | Business Email Compromise (impersonation fraud) |
| Ransomware sanctions | Paying designated group = sanctions risk (OFAC 2020 Advisory) |