MACC Section 17A Explained: What Adequate Procedures Mean and How ISO 37001 Proves It
MACC Section 17A creates automatic criminal liability for any commercial organisation in Malaysia when an associated person commits corruption on its behalf. The only statutory defence is proof that the organisation had adequate procedures in place. ISO 37001:2025, the international anti-bribery management system standard, provides the documented, independently audited structure that the Malaysian Anti-Corruption Commission, Malaysian courts, and procurement bodies recognise as evidence of those procedures. This article explains what Section 17A requires, what adequate procedures means in legal and operational terms, and how ISO 37001 certification supports organisations in demonstrating compliance. Businesses of all sizes should also understand why ISO 37001 Is Becoming Essential for SMEs, as anti-bribery controls are increasingly expected by regulators, customers, investors, and procurement bodies, not just large corporations.

What Is MACC Section 17A and Who Does It Apply To?
MACC Section 17A is a strict liability corporate offence under the MACC Act 2009 that applies to all commercial organisations registered or operating in Malaysia, and has been in force since 1 June 2020. Under Section 17A(1), a commercial organisation commits a criminal offence if any associated person, including directors, partners, employees, and agents who perform services on behalf of the organisation, promises or gives a bribe to obtain or retain business. The organisation does not need to have known about the act. Liability attaches automatically.
The penalties are severe. Under Section 17A(2), a convicted commercial organisation faces a fine of not less than ten times the value of the bribe or RM1,000,000, whichever is higher, and up to twenty years imprisonment, or both. Under Section 17A(3), senior personnel including directors, controllers, officers, and partners are personally deemed to have committed the same offence, unless each individually proves they exercised due diligence to prevent it.
In our experience, most Malaysian companies only discover their Section 17A exposure when they receive a compliance questionnaire from a GLC or government-linked procurement body, or when a competitor is publicly named in a MACC investigation. At that point, the question is no longer whether adequate procedures are a good idea. It is whether yours would hold up to scrutiny today.
What Are Adequate Procedures Under MACC Section 17A?
Adequate procedures under MACC Section 17A are the documented, implemented, and actively enforced anti-corruption controls that a commercial organisation must prove were genuinely in place when an associated person committed corruption. The critical requirement in Section 17A(4) is that procedures must be ‘in place’, meaning genuinely operational, not just written down. A policy document that was never communicated, monitored, or enforced will not satisfy the defence.
The burden of proof sits entirely with the organisation. The prosecution does not need to disprove the existence of adequate procedures. The company must affirmatively prove they existed and were operational. This is a strict liability offence, which means intent is irrelevant. Only the adequacy of the procedures matters as a defence.
The Prime Minister’s Department issued the Guidelines on Adequate Procedures in December 2018 under Section 17A(5) of the MACC Act. These guidelines are not exhaustive legal requirements, but Malaysian courts use them as the primary benchmark for assessing adequacy. Any organisation that cannot demonstrate clear alignment with the Guidelines faces a very difficult defence in any Section 17A prosecution.
What Are the Five TRUST Principles for Adequate Procedures?
The five TRUST principles are Top-level commitment, Risk assessment, Undertake control measures, Systematic review and monitoring, and Training and communication. These five principles form the framework set out in the Prime Minister’s Department Guidelines on Adequate Procedures, issued in December 2018 under Section 17A(5), and are the benchmark Malaysian courts apply to assess whether a company’s procedures were genuinely adequate. Organisations can use an ISO 37001 audit checklist to evaluate whether their anti-bribery management system effectively incorporates the TRUST principles and is adequately prepared for certification and regulatory scrutiny.
- Top-level commitment. The board and senior management must actively champion the anti-corruption programme, not simply endorse a policy document. This requires board-level reporting on corruption risks, publicly available anti-corruption commitments, and demonstrable management involvement in reviewing programme effectiveness at least annually.
- Risk assessment. A documented corruption risk assessment must be conducted at least every three years, covering all business activities, third-party relationships, and high-risk functions such as procurement, government liaison, and project tendering. It must be updated whenever the business or its operating environment changes materially.
- Undertake control measures. Practical, proportionate controls must be implemented based on the risk assessment results. These include due diligence procedures for associated persons and third parties, gifts and hospitality policies, separation of duties in procurement, and confidential whistleblowing channels that allow reporting without fear of retaliation.
- Systematic review, monitoring and enforcement. The anti-corruption programme must be subject to regular internal and external audits to verify that controls are actually working. The PM’s Guidelines specifically recognise external audit by an ISO 37001 certified auditor as a best practice review mechanism under this principle.
- Training and communication. Documented anti-corruption training must be delivered to all staff and business associates, proportionate to their role and their exposure to corruption risk. Training records must be maintained and available for review at any time.
How Does ISO 37001 Prove Adequate Procedures Under Section 17A?
ISO 37001:2025 proves adequate procedures under Section 17A by providing a clause-by-clause anti-bribery management framework that maps directly to all five TRUST principles, and is specifically recommended in the PM’s Department Guidelines as a best practice for demonstrating compliance. ISO 37001:2025 is the current version of the standard, replacing ISO 37001:2016 on 28 February 2025.
The clause-by-clause alignment is direct. ISO 37001:2025 Clause 5 (Leadership) requires top-level management to establish, communicate, and actively support the anti-bribery policy and to demonstrate commitment through regular management review. This covers the TRUST Top-level commitment principle. Clause 6 (Planning) requires a bribery risk assessment that identifies and evaluates exposure across all activities and associated persons, covering Risk assessment. Clause 8 (Operations) requires documented controls for high-risk functions, due diligence procedures for associated persons, and a confidential reporting mechanism, covering Undertake control measures. Clause 9 (Performance evaluation) requires internal audits, management reviews, and certification by an accredited external body, covering Systematic review. Clause 7 (Support) requires documented competence, awareness programmes, and training records for all relevant personnel, covering Training and communication.
An organisation that completes ISO 37001:2025 certification has, by definition, addressed every element the PM’s Guidelines require for adequate procedures. The certification process does not allow a company to simply document a system. It requires the system to be tested, operational, and verified by an independent auditor before a certificate is issued.
Is ISO 37001 Certification Enough to Satisfy MACC Section 17A?
ISO 37001 certification from a MACC-scheme accredited body is the strongest available evidence that a company meets the adequate procedures standard under Section 17A, because it provides independent third-party verification that the anti-bribery management system is genuinely operational rather than self-assessed. However, the certificate alone is not the answer. It must be backed by a system that is genuinely implemented and maintained.
Certification must come from a body accredited under the MACC scheme. Recognised certification bodies operating in Malaysia include SIRIM QAS International, SGS Malaysia, Bureau Veritas Malaysia, TUV SUD, and Lloyd’s Register Quality Assurance (LRQA). A certificate from a body without this accreditation does not carry the same evidentiary weight in a prosecution scenario.
The mandatory context is also widening. CIDB Pekeliling Bil. 1/2026 requires all Grade G7 contractors to hold valid ISO 37001 certification by 1 January 2027. Companies operating in government procurement, GLC supply chains, or large-scale construction are increasingly required to demonstrate certification as a condition of contract. The Section 17A adequate procedures defence and the commercial procurement requirement now point to the same standard.
The most consistent finding in our ISO 37001 implementation work with Malaysian companies is that the certification process uncovers gaps the organisation did not know existed. Third-party due diligence procedures that are documented but never applied. Training records that are incomplete. Whistleblowing channels that staff cannot find or do not trust. These are exactly the gaps that would undermine a Section 17A defence. The certification process identifies and closes them before they become a legal liability.
ISO 37001 Is the Clearest Path to a Defensible Adequate Procedures Position
Section 17A of the MACC Act is not a theoretical risk. It has been in force since June 2020, the penalties are severe, and the burden of proof in a prosecution sits entirely with the organisation. Adequate procedures is the only available defence, and the Malaysian courts use the PM’s Department Guidelines on Adequate Procedures as the benchmark for what adequate actually means. ISO 37001:2025 is the only internationally recognised management system standard designed specifically to meet those requirements, and certification by an accredited body is the only way to demonstrate through independent evidence that the system is real and operational. Note that ISO 37001 certification remains valid only with continued surveillance audits and recertification every three years. The current version is ISO 37001:2025; organisations certified to ISO 37001:2016 must transition by 28 February 2027.
Protect your business from bribery risks. Get ISO 37001 certified with Connext.
FAQs
What does Section 17A of the MACC Act mean for Malaysian companies?
Section 17A of the MACC Act 2009, which came into force on 1 June 2020, makes a commercial organisation criminally liable if any associated person (director, employee, or agent) commits corruption to obtain or retain business on its behalf. The organisation does not need to have known about the act. Penalties include a minimum fine of RM1,000,000 or ten times the bribe value, whichever is higher, and up to twenty years imprisonment.
What are adequate procedures under MACC Section 17A?
Adequate procedures are the documented, implemented, and actively enforced anti-corruption controls that give a commercial organisation its only defence against Section 17A liability. They must be genuinely operational. The Prime Minister’s Department Guidelines on Adequate Procedures, issued in December 2018 under Section 17A(5), set out the five TRUST principles that courts use to assess whether a company’s procedures were genuinely adequate.
What are the five TRUST principles for adequate procedures?
TRUST stands for Top-level commitment, Risk assessment, Undertake control measures, Systematic review, monitoring and enforcement, and Training and communication. These five principles are set out in the Prime Minister’s Department Guidelines on Adequate Procedures issued under Section 17A(5) of the MACC Act 2009 and serve as the court’s benchmark for assessing adequacy.
What are the penalties under Section 17A of the MACC Act?
A commercial organisation convicted under Section 17A faces a fine of not less than ten times the value of the bribe or RM1,000,000, whichever is higher, and up to twenty years imprisonment, or both. Under Section 17A(3), directors and senior management are deemed personally liable for the same offence unless they prove they exercised due diligence to prevent it.
Can ISO 37001 be used as proof of adequate procedures under MACC Section 17A?
Yes. The Prime Minister’s Department Guidelines on Adequate Procedures explicitly recommend ISO 37001 external audit as a best practice for demonstrating compliance with Section 17A. Certification from a MACC-scheme accredited body provides independent third-party verification that the anti-bribery management system is genuinely operational, which is the strongest available evidence of adequate procedures in a prosecution scenario.






