Anti-Corruption Policy in Banks: A Complete IIBF Ethics Guide
A working anti-corruption policy in banks is now a supervisory expectation, not an optional add-on, given how much of India's banking stress traces back to sanctioning decisions and vendor relationships that bypassed proper controls. IIBF's Ethics in Banking paper tests this area closely, because it sits at the intersection of law, internal governance and everyday branch conduct. This guide walks through the legal foundation, the practical controls, and the exam-relevant frameworks candidates must know cold.
⚖️ Legal Foundations: Prevention of Corruption Act and Bank Officials
The Prevention of Corruption Act, 1988 is the primary criminal-law backbone for corruption offences involving public servants, and officials of public sector banks fall squarely within its definition. The Prevention of Corruption (Amendment) Act, 2018 reshaped the law in ways every ethics candidate should remember: it narrowed the vague "criminal misconduct" clause down to two specific categories, added Section 8 making the bribe-giver directly liable (not just the taker), and introduced Section 9, which for the first time fixes liability on a "commercial organisation" whose associated persons pay a bribe to obtain business — with an "adequate procedures" defence modelled on the UK Bribery Act, 2010.
A separate but critical safeguard, Section 17A, requires prior approval before any investigating agency can inquire into a decision a public servant took in discharge of official duty — a protection meant to stop routine credit or supervisory decisions from being criminalised after the fact, while still allowing genuine corruption to be pursued. Private-sector banks are not "public servants" under the Act's core provisions, but Section 8 and Section 9 reach them too, alongside RBI's own fit-and-proper and internal-control expectations. This legal layer is exactly the kind of regulatory grounding covered in Ethics, Financial Services and Regulation (Chapter 4A).
💡 Exam Tip: Remember the three 2018-amendment numbers together — Section 8 (bribe-giver liable), Section 9 (commercial organisation liable), Section 17A (prior approval safeguard). IIBF questions often test which section does what.
| Provision | PC Act, 1988 (Original) | PC (Amendment) Act, 2018 |
|---|---|---|
| Bribe-giver liability | ❌ Not an explicit standalone offence | ✅ Section 8 — criminal offence for giving a bribe |
| Commercial organisation liability | ❌ Not covered | ✅ Section 9 — corporate offence, "adequate procedures" defence |
| Prior approval for investigation | ❌ No such safeguard | ✅ Section 17A — approval needed for official-duty decisions |
| "Criminal misconduct" definition | Broad, subjective, multiple limbs | ✅ Narrowed to two specific, objective categories |
| Trial timelines | Not specified | ✅ Two-year target for trial completion |

🎁 Gifts, Hospitality and Conflict Situations
Most bank anti-corruption policies begin at the point where ethics and everyday business courtesy overlap: gifts, hospitality, and sponsored travel from customers, vendors or intermediaries. A well-drafted policy sets a clear monetary threshold below which a token gift can be accepted without formality, requires disclosure in a gift register above that threshold, and mandates outright refusal or deposit with the bank of anything that could be seen as influencing a decision — loan sanctioning, procurement award, or vendor empanelment in particular.
The policy also has to address subtler conflict situations: an employee's relative working for a borrower firm, a director's business interest in a supplier being evaluated, or festive-season hospitality from a builder whose project the bank is financing. Banks typically require employees to file periodic conflict-of-interest declarations and recuse themselves from any decision where a personal or family interest exists. This is the practical, day-to-day face of the ethical culture that Building an Ethical Organization (Chapter 11) describes as depending on tone from the top rather than rulebooks alone.
Where the gift or hospitality policy fails in practice, it is usually not because the rule was missing but because staff were never trained to recognise a "grey area" situation until it had already become a reportable one — which is precisely why induction and refresher ethics training carries as much weight in audits as the written policy document itself.

🕵️ Corruption Risk Areas in Banking Operations
An effective anti-corruption policy in banks is built around a risk map, not a generic circular. The highest-risk zones consistently identified across Indian banking are: credit sanctioning and renewal (where discretion over pricing, collateral valuation or waiver of covenants can be monetised), procurement and vendor empanelment, cash-handling and locker operations, and KYC or documentation shortcuts taken to push an account or loan through quickly.
Each of these risk areas connects to a wider control theme candidates already study separately — documentation lapses that enable corruption often show up first as the same red flags examined under fraud prevention in bank branches, since a bribe paid to bypass a control is frequently the trigger event behind a later fraud. Third-party and outsourcing relationships deserve particular scrutiny: recovery agents, DSAs and empanelled valuers operate with less direct supervision, so banks build in periodic rotation, surprise checks and independent verification of valuation reports as standard anti-corruption controls rather than optional extras.
⚠️ Common Mistake: Candidates often assume anti-corruption controls only apply to loan sanctioning. In practice, procurement, vendor empanelment and outsourced agent relationships carry equal or higher corruption risk in audit findings.

🛡️ ISO 37001 and the Anti-Bribery Management System
Beyond domestic law, a number of Indian banks and NBFCs have begun aligning their internal anti-corruption frameworks with ISO 37001, the international standard for an Anti-Bribery Management System (ABMS). ISO 37001 is voluntary — it is not an RBI-mandated certification — but it gives banks a structured, auditable model built on the same plan-do-check-act cycle used for other management-system standards.
Under an ABMS, a bank must run a documented bribery risk assessment before onboarding a vendor, agent or business associate, apply proportionate due diligence based on that risk rating, embed financial controls that make off-book payments harder to conceal, and maintain a functioning whistleblowing channel with non-retaliation protection. Top management commitment is treated as a certifiable requirement in itself, not a preamble — auditors specifically check whether senior leaders model gift and hospitality rules rather than exempting themselves.
This due-diligence discipline mirrors the broader capital-allocation rigour banks already apply elsewhere; just as a bribery risk rating gates a vendor contract, structured techniques such as risk analysis in capital budgeting gate large capital-expenditure decisions before funds are committed. For public sector banks, adoption of an ABMS complements — it does not replace — the vigilance mechanisms already mandated by government oversight.
👮 Enforcement, Disciplinary Action and Whistleblower Linkage
Detection means little without enforcement. Public sector banks route corruption complaints through internal vigilance officers, who classify complaints, decide whether a matter needs a departmental inquiry or referral to an outside investigating agency, and apply the prior-approval safeguard under Section 17A before any inquiry touches an official-duty decision. This internal machinery is what candidates study in depth under vigilance administration in banks, and it works hand in hand with the anti-corruption policy rather than as a separate system.
Disciplinary outcomes for proven corruption typically follow the bank's staff conduct regulations, ranging from censure and increment stoppage to compulsory retirement or dismissal, independent of any criminal prosecution running in parallel under the PC Act. The Public Interest Disclosure and Protection of Informers (PIDPI) resolution gives employees and citizens a route to report corruption confidentially, with identity protection built in — a linkage every ethics candidate should hold alongside the bank's own vigil mechanism.
📌 Remember: Enforcement outcomes (departmental action) and criminal prosecution under the PC Act run on separate, parallel tracks — one does not have to conclude before the other begins.
None of this replaces the values grounding that shapes conduct before a rule is even needed, a theme Indian ethos and values in banking covers from a different angle — culture as the first line of defence, controls as the second.
🧠 Practice MCQs: Anti-Corruption Policy in Banks
Q1. Which section of the Prevention of Corruption (Amendment) Act, 2018 introduced criminal liability for a "commercial organisation" that fails to prevent bribery by an associated person? (a) Section 7 (b) Section 8 (c) Section 9 (d) Section 17A
Answer: (c) — Section 9 fixes liability on commercial organisations, subject to an "adequate procedures" defence.
Q2. Which section of the amended PC Act requires prior approval before an investigating agency can inquire into a decision a public servant took in discharge of official duty? (a) Section 7 (b) Section 8 (c) Section 9 (d) Section 17A
Answer: (d) — Section 17A is the prior-approval safeguard added by the 2018 amendment.
Q3. Under an Anti-Bribery Management System aligned with ISO 37001, what must typically happen before a bank onboards a new vendor or business associate? (a) Board-only approval (b) Risk-based due diligence (c) Immediate contract signing (d) A verbal assurance of integrity
Answer: (b) — ISO 37001 requires a documented, risk-based due diligence check before onboarding.
Q4. If a bank employee demands and accepts illegal gratification to sanction a loan, this falls under which category of offence? (a) Money laundering (b) Bribery/criminal misconduct by a public servant (c) Breach of contract (d) Simple negligence
Answer: (b) — Demanding or accepting gratification to influence an official act is bribery/criminal misconduct under the PC Act.
Q5. A bank's gift and hospitality policy under its anti-corruption framework typically requires employees to: (a) Accept all gifts silently (b) Disclose gifts and, above a set threshold, decline or deposit them (c) Return all courtesy items regardless of value (d) Report gifts only above ₹1 crore
Answer: (b) — Disclosure plus a monetary threshold is the standard control, not a blanket ban or an unrealistically high reporting bar.
Want chapter-wise mock tests with 100+ MCQs? Start practising free →
❓ Frequently Asked Questions
What is the difference between a whistleblower policy and an anti-corruption policy in a bank?
A whistleblower or vigil mechanism is the reporting channel for concerns of any kind, including corruption. An anti-corruption policy sets out the preventive controls specific to bribery — gift limits, due diligence, sanctions. The two are designed to work together, not as substitutes for each other.
Does the Prevention of Corruption Act apply to private-sector bank employees?
Private bank staff are not "public servants" under the Act's core provisions, but Section 8 (bribe-giving) and Section 9 (commercial organisation liability) apply broadly across sectors. Private banks also carry separate RBI-driven fit-and-proper and internal-control obligations.
Is ISO 37001 certification mandatory for Indian banks?
No. ISO 37001 is a voluntary international standard for an anti-bribery management system. Adoption is a governance choice some banks make to demonstrate compliance-culture maturity; it is not an RBI-mandated certification.
How are corruption complaints against public sector bank officials investigated?
Complaints are first routed through the bank's internal vigilance machinery, which classifies them and decides on departmental inquiry or referral to an external agency, always subject to the Section 17A prior-approval safeguard for official-duty decisions.
Building the habit before the exam
An anti-corruption policy in banks only works when candidates can connect the legal provisions, the practical controls and the enforcement machinery into one picture — exactly how IIBF questions test this paper. For the wider set of Ethics in Banking topics, browse the Ethics in Banking hub, check current regulatory developments at IIBF news and updates, and read the Central Vigilance Commission's own guidance at cvc.gov.in for the government's primary framework on preventing corruption in public institutions.
Prefer revising from a printed book?
Chapter-wise books with MCQs after every chapter — minimal pages, complete coverage, delivered anywhere in India. Every book has a free sample to read first.
132 pages · 225 MCQs
Learning Sessions · Ashish Sir
188 pages · 435 MCQs
Learning Sessions · Ashish Sir
117 pages · 236 MCQs
Learning Sessions · Ashish Sir
Learning Sessions · Ashish Sir
118 pages · 299 MCQs
Learning Sessions · Ashish Sir
Learning Sessions · Ashish Sir
Learning Sessions · Ashish Sir
Learning Sessions · Ashish Sir
115 pages · 255 MCQs
Learning Sessions · Ashish Sir
Learning Sessions · Ashish Sir
334 pages · 936 MCQs
Learning Sessions · Ashish Sir
Learning Sessions · Ashish Sir
115 pages · 344 MCQs
Learning Sessions · Ashish Sir
107 pages · 240 MCQs
Learning Sessions · Ashish Sir
90 pages · 150 MCQs
Learning Sessions · Ashish Sir
Learning Sessions · Ashish Sir
131 pages · 672 MCQs
Learning Sessions · Ashish Sir
221 pages · 831 MCQs
Learning Sessions · Ashish Sir
128 pages · 524 MCQs
Learning Sessions · Ashish Sir
107 pages · 445 MCQs
Learning Sessions · Ashish Sir
148 pages · 478 MCQs
Learning Sessions · Ashish Sir
151 pages · 465 MCQs
Learning Sessions · Ashish Sir
148 pages · 375 MCQs
Learning Sessions · Ashish Sir
216 pages · 895 MCQs
Learning Sessions · Ashish Sir
109 pages · 300 MCQs
Learning Sessions · Ashish Sir
104 pages · 360 MCQs
Learning Sessions · Ashish Sir
82 pages · 297 MCQs
Learning Sessions · Ashish Sir
151 pages · 600 MCQs
Learning Sessions · Ashish Sir
98 pages · 282 MCQs
Learning Sessions · Ashish Sir
Quick quiz on this topic
5 exam-style questions from our free test bank — check yourself before you move on.
Practice this topic
Take a free mock test, download chapter PDFs, or watch a video class — all included on iibf.store.