ANTI-BRIBERY OR CORRUPTION POLICY

Document Reference BAC-ACAB-2025-001
Version 1.0
Effective Date 1 July 2025
Approved By Board of Directors, BAC Education Group
Review Cycle Every Two (2) Years
Classification Official / Internal

DOCUMENT CONTROL

Version Date Description Prepared By Approved By
1.0 01/07/2025 Initial Issue Group Finance & Compliance Office Board of Directors

DOCUMENT DISTRIBUTION

Copy No. Institution Copy Holder Date Issued
1 BAC Education Group (Group Level) Group Chief Executive Officer 01/07/2025
2 Brickfields Asia College Principal / Chief Executive 01/07/2025
3 IACT College Principal / Chief Executive 01/07/2025
4 Reliance College Principal / Chief Executive 01/07/2025
5 Veritas University College Vice Chancellor / President 01/07/2025
6 UNIMY Vice Chancellor / President 01/07/2025

Anti-Corruption and Anti-Bribery Policy Statement

BAC Education Group (the ‘Group’) comprises five distinguished higher education institutions: Brickfields Asia College, IACT College, Reliance College, Veritas University College, and UNIMY (the University of Malaysia International Youth). Together, these institutions serve thousands of students and employ hundreds of staff across Malaysia.

The Group is committed to upholding the highest standards of ethical conduct, academic integrity, professional responsibility and good governance in all its activities. This Policy Statement outlines the overarching framework of procedures and processes that can be considered to be the anti-bribery policy of the Group.

The Group takes a zero tolerance approach to, and does not in any way condone bribery.

1. OUTLINE

  1. This Anti-Corruption and Anti-Bribery Policy Statement is applicable to all staff members and stakeholders vis-à-vis internal and external dealings in their course of duty.
  2. This Policy Statement is based on Guidelines (MACC Guidelines) pursuant to subsection (5) of section 17A of the Malaysian Anti-Corruption Commission Act 2009 (Act 694) (“MACC Act 2009”), as stated in the Malaysian Anti-Corruption Commission (Amendment) Act 2018 (“MACC Amendment Act 2018”) which generally mirrors the UK Ministry of Justice guidelines for the UK Bribery Act 2010.
  3. Offences under the MACC Act 2009, including but not limited to active and passive bribery or facilitation payments, by employees of the Group constitute gross misconduct under the conduct procedure. The conduct of persons associated with the Group will be regulated via their contracts with the Group which will similarly prohibit offences under the Act.
  4. In addition to any internal procedures, the Group will report suspected cases to the relevant authorities.
  5. The Group’s Financial, HR and other procedures have been designed to inhibit financial and contractual impropriety; in response to the introduction of the new guidelines, has undertaken a number of additional actions including updating a number of Financial Procedures and policies to make explicit reference to this Policy Statement.
  6. Malaysia’s guidelines follow an easy-to-remember and extremely apt acronym: T.R.U.S.T.
    1. T: Top level commitment
    2. R: Risk assessment
    3. U: Undertake control measures
    4. S: Systematic review, monitoring and enforcement
    5. T: Training and communication

The main aim of this Policy Statement is to impress on staff and stakeholders the importance of developing and embedding T.R.U.S.T in their role, responsibilities and interactions.

2. OBJECTIVE

  1. The objective of these MACC Guidelines is to assist relevant stakeholders in understanding what are the adequate procedures that should be implemented to prevent the occurrence of corrupt practices in relation to their business activities.
  2. These MACC guidelines have been formed on the basis of five principles which may be used as reference points for any anti-corruption policies, procedures and controls the organisation may choose to implement towards the goal of having adequate procedures as required under the above statutory provision.
  3. The provision of section 17A under the MACC Act 2009, establishes the principle of a commercial organisation’s criminal liability (corporate liability) for the corrupt practices of its employees and/ or any person(s) associated with the commercial organisation in cases where such corrupt practices are carried out for the organisation’s benefit or advantage.
  4. The commercial organisation may be liable whether or not its top level management and/or representatives had actual knowledge of the corrupt acts of its employees and/or associated persons.
  5. The aim of this provision is to foster the growth of a business environment that is free of corruption, and to encourage all commercial organisations to take the reasonable and proportionate measures to ensure their businesses do not participate in corrupt activities for their advantage or benefit.
  6. These measures should take the form of policies and procedures, with training, communication and enforcement to ensure they are effective.
  7. In the event that a commercial organisation is found liable under Section 17A of the MACC Act, the provision provides that the organisation having adequate procedures can raise it as a defence against corporate liability.
  8. In this regard the organisation must prove that the necessary procedures were in place to prevent its employee(s) and/or associated persons from undertaking corrupt practices in relation to its business activities.
  9. Under subsection (5) of section 17A MACC Act 2009, the Minister is required to issue guidelines relating to adequate procedures which are designed to be principle-based and for general application by any commercial organisation of any size and industry. The guidelines have been reproduced herein and adopted under this Policy Statement.
  10. These guidelines are not intended to be prescriptive and it should not be assumed that “one-size-fits-all”. They should be applied practically, in proportion to the scale, nature, industry, risk and complexity.
  11. If a corruption incident should occur, it would be a matter for the courts to decide whether the commercial organisation truly established the necessary safeguards which should have prevented the offence from happening. When making a decision, the judiciary is likely to take into account the particular facts and circumstances of the case, including the existence of an organisation’s policies and procedures and manner of their implementation.
  12. However, by implementing these adequate procedures, companies can gain confidence that they have established a suitable defence which can be used to protect both the commercial organisation and top management from liabilities now arising from the MACC Amendment Act 2018.

3. ADEQUATE PROCEDURES PRINCIPLES: T. R. U. S. T.

3.1 Principle I: Top Level Commitment

  1. The top level management is primarily responsible for ensuring that the commercial organisation:
    1. practices the highest level of integrity and ethics;
    2. complies fully with the applicable laws and regulatory requirements on anti-corruption;
    3. effectively manages the key corruption risks of the organisation.
  2. The top level management must be able to provide assurance to its internal and external stakeholders that the organisation is operating in compliance with its policies and any applicable regulatory requirements. This may include establishing the organisation’s “tone from the top” (i.e. the organisation’s general stance against the use of corrupt practices in relation to its business activities), and spearheading the organisation’s efforts to improve upon the effectiveness of its corruption risks management framework, internal control system, review and monitoring, and training and communication.
  3. Thus, for this purpose, commercial organisations should carry out the following:
    1. establish, maintain, and periodically review an anti-corruption compliance programme which includes clear policies and objectives that adequately address corruption risks;
    2. promote a culture of integrity within the organisation;
    3. issue instructions on communicating the organisations’ policies and commitments on anti-corruption to both internal and external parties;
    4. encourage the use of any reporting (whistleblowing) channel in relation to any suspected and/or real corruption incidents or inadequacies in the anti-corruption compliance programme;
    5. assign and adequately resource a competent person or function (which may be external to the organisation) to be responsible for all anti-corruption compliance matters, including provision of advice and guidance to personnel and business associates in relation to the corruption programme;
    6. ensure that the lines of authority for personnel tasked with responsibility for overseeing the anti-corruption compliance programme are appropriate; and
    7. ensure that the results of any audit, reviews of risk assessment, control measures and performance are reported to all top level management, including the full Board of Directors, and acted upon.

3.2 Principle II: Risk Assessment

A corruption risk assessment should form the basis of an organisation’s anti-corruption efforts. As such, the commercial organisation should conduct corruption risk assessments periodically and when there is a change in law or circumstance of the business to identify, analyse, assess and prioritise the internal and external corruption risks of the organisation. This risk assessment should be used to establish appropriate processes, systems and controls approved by the top level management to mitigate the specific corruption risks the business is exposed to.

  1. For this purpose, it is recommended that a comprehensive risk assessment is done every three years, with intermittent assessments conducted when necessary. The assessment may include the following:
    1. opportunities for corruption and fraud activities resulting from weaknesses in the organisation’s governance framework and internal systems/ procedures;
    2. financial transactions that may disguise corrupt payments;
    3. business activities in countries or sectors that pose a higher corruption risk;
    4. non-compliance of external parties acting on behalf of the commercial organisation regarding legal and regulatory requirements related to anti-corruption. Note that, given the wide definition of an associated person, a commercial organisations can be liable for the acts of such third parties; and
    5. relationships with third parties in its supply chain (e.g. agents, vendors, contractors, and suppliers) which are likely to expose the commercial organisation to corruption.
  2. The risk assessment for corruption can be done on a stand-alone basis, but is recommended that the assessment be incorporated into the general risk register of the commercial organisation.

3.3 Principle III: Undertake Control Measures

  1. The commercial organisation should put in place the appropriate controls and contingency measures which are reasonable and proportionate to the nature and size of the organisation, in order to address any corruption risks arising from weaknesses in the organisation’s governance framework, processes and procedures. These should include the following items:
    • (a) Due diligence
      The commercial organisation should establish key considerations or criteria for conducting due diligence on any relevant parties or personnel (such as Board members, employees, agents, vendors, contractors, suppliers, consultants and senior public officials) prior to entering into any formalised relationships. Methods may include background checks on the person or entity, a document verification process, or conducting interviews with the person to be appointed to a key role where corruption risk has been identified.
    • (b) Reporting channel
      The commercial organisation should:
      • (i) establish an accessible and confidential trusted reporting channel (whistleblowing channel), which may be used anonymously, for internal and external parties to raise concerns in relation to real or suspected corruption incidents or inadequacies of the anti-corruption programme. For smaller organisations, the reporting channel can be as simple as a dedicated e-mail address;
      • (ii) encourage persons to report, in good faith, any suspected, attempted or actual corruption incidents;
      • (ii) establish secure information management system to ensure the confidentiality of the whistle-blower’s identity and the information reported; and
      • (iv) prohibit retaliation against those making reports in good faith.
  2. Furthermore, the commercial organisation should establish policies and procedures to cover the following areas:
    1. a general anti-bribery and corruption policy or statement;
    2. conflicts of interest;
    3. gifts, entertainment, hospitality and travel;
    4. donations and sponsorships, including political donations;
    5. facilitation payments;
    6. financial controls, such as separation of duties and approving powers or multiple signatories for transactions;
    7. non-financial controls, such as a separation of duties and approving powers or a pre-tendering process;
    8. managing and improving upon any inadequacies in the anti-corruption monitoring framework; and
    9. record keeping for managing documentation related to the adequate procedures.
  3. In this regard, the organisation’s policies should be:
    • (i) endorsed by top level management;
    • (ii) kept up-to-date;
    • (iv) publicly and/or easily available; and
    • (iv) suitable for use where and when needed.

3.4 Principle IV: Systematic Review, Monitoring and Enforcement

  1. The top level management should ensure that regular reviews are conducted to assess the performance, efficiency and effectiveness of the anti-corruption programme, and ensure the programme is enforced. Such reviews may take the form of an internal audit, or an audit carried out by an external party.
  2. The reviews should form the basis of any efforts to improve the existing anti-corruption controls in place in the organisation.
  3. For this purpose, the commercial organisations should consider the following:
    1. plan, establish, implement and maintain a monitoring programme, which covers the scope, frequency, and methods for review;
    2. identify the competent person(s) and/or establish a compliance function to perform an internal audit, in relation to the organisation’s anti-corruption measures;
    3. conduct continual evaluations and improvements on the organisation’s policies and procedures in relation to corruption;
    4. consider an external audit (for example MS ISO 37001 auditors) by a qualified and independent third party at least once every three years to obtain assurance that the organisation is operating in compliance with its policies and procedures in relation to corruption;
    5. monitor the performance of personnel in relation to any anti-corruption policies and procedures to ensure their understanding and compliance with the organisation’s stance in their respective roles and functions; and
    6. conduct disciplinary proceedings against personnel found to be non-compliant to the programme.

3.5 Principle V: Training and Communication

  1. The commercial organisation should develop and disseminate internal and external training and communications relevant to its anti-corruption management system, in proportion to its operation, covering the following areas:
    1. policy;
    2. training;
    3. reporting channel; and
    4. consequences of non-compliance.
  2. Communication of Policies
    1. The organisation’s anti-corruption policy should be made publicly available, and should also be appropriately communicated to all personnel and business associates.
    2. When planning strategies for communicating the organisation’s position on anti-corruption, the organisation should take into account what key points should be communicated, to whom they should be communicated, how they will be communicated, and the timeframe for conducting the communication plan. The organisation should also consider what languages the materials will be communicated in.
    3. The communication and related training (please see below for more training modes) of the organisation’s policies may be conducted in a variety of formats and mediums. These may include, but are not limited to:
      1. messages on the organisation’s intranet or website;
      2. emails, newsletters, posters;
      3. code of business conduct and employee’s handbooks;
      4. video seminars or messages; and
      5. town-hall sessions.
  3. Training
    1. The commercial organisation should provide its employees and business associates with adequate training to ensure their thorough understanding of the organisation’s anti-corruption position, especially in relation to their role within or outside the commercial organisation.
    2. The training may be conducted in a variety of formats, including but not limited to:
      1. induction programs featuring anti-corruption elements;
      2. role-specific training, which is tailored to corruption risks the position is exposed to;
      3. corporate training programs, seminars, videos and in-house courses;
      4. intranet or web-based programs;
      5. town hall sessions;
      6. retreats; and
      7. out-reach programs.

4. FURTHER QUIDELINES

  1. Whilst there have not been clear guidelines on performing due diligence exercise on suppliers as required under the UK ACT, this is not to be interpreted as an area of lesser importance in the Malaysian context under the MACC guidelines. Also this is a serious element where the Group deals with UK and EU based entities and in this regards, stakeholders shall consider the following:-
  2. One only have to think about doing due diligence on persons who will actually perform services for you, or on your behalf. Someone who simply supplies goods to you is unlikely to do that. It is very unlikely, therefore, that you will need to consider doing due diligence on persons further down a supply chain.
  3. Where one decides to undertake due diligence, how much is needed to be done will depend on your risk assessment. If you assess the risk as low then all you may need to do is satisfy yourself that people performing services for you (for example, an agent) are genuine and someone you can trust to do your business without bribing. You could do this by making enquiries with business contacts, local chambers of commerce or business associations or via the internet for example.
  4. Where you think the risks are higher, then you may need to do more. You might ask your agent for a CV, financial statements or accounts, and other references. You might then follow those up to ensure they are genuine. The aim is to satisfy yourself that the person that is to represent your organisation can be trusted not to use bribery on your behalf, but this does not necessarily require sophisticated and costly techniques. Personal contact, allowing you to assess the person for yourself, can be very helpful.
  5. Can I provide hospitality, promotional or other business expenditure under the Act? Yes. The Government does not intend that genuine hospitality or similar business expenditure that is reasonable and proportionate be caught by the Act, so you can continue to provide bona fide hospitality, promotional or other business expenditure. In any case where it was thought the hospitality was really a cover for bribing someone, the authorities would look at such things as the level of hospitality offered, the way in which it was provided and the level of influence the person receiving it had on the business decision in question. But, as a general proposition, hospitality or promotional expenditure which is proportionate and reasonable given the sort of business you do is very unlikely to engage the Act. So you can continue to provide tickets to sporting events, take clients to dinner, offer gifts to clients as a reflection of your good relations, or pay for reasonable travel expenses in order to demonstrate your goods or services to clients if that is reasonable and proportionate for your business.
  6. What about facilitation payments? Facilitation payments, which are payments to induce officials to perform routine functions they are otherwise obligated to perform, are bribes. There was no exemption for such payments under the previous and the present laws. As was the case under the old law, prosecutors will carefully consider all the facts and surrounding circumstances of cases which come to their attention to assess whether a payment amounts to a bribe and, if so, whether a prosecution is in the public interest. You can continue to pay for legally required administrative fees or fast-track services. These are not facilitation payments.
  7. One key similarity between the UK guidance and Malaysia’s guidelines is the concept of proportionality. Essentially, in order for a compliance program to be proportionate in the UK, Malaysia, or anywhere in the world, it would need to look very different for a multinational bank than for a small, local retailer. A notable difference, however, is that the UK sets proportionality as its’ very first principle, while Malaysia notes that proportionality underlies the entire program.

SIGN-OFF & BOARD APPROVAL

This Anti-Corruption and Anti-Bribery Policy was reviewed, approved and adopted by the Board of Directors of BAC Education Group as well as all related Public Higher Education Institution (PHEI) and shall be open for review on 1 June 2027