Ask an HR manager whether the company has done anti-bribery and corruption (ABC) training and the answer is usually yes: a one-hour awareness session, an attendance sheet, perhaps an online quiz. Ask what a procurement executive was taught that a receptionist was not, and the answer is usually silence.

That second question is the one that matters. Under MACC Section 17A, a company can be liable for corruption committed by its employees or associated persons, and its one defence is proving it had adequate procedures in place. Training is one of the five principles those procedures are judged on. A generic session everyone sat through once proves attendance. It does not prove the company prepared each person for the bribery risk their role actually carries.

This guide sets out what the official guidelines ask of ABC training, what to cover at each level of the organisation, and the records to keep so the training counts when it is tested.

What the official guidelines actually require

The Guidelines on Adequate Procedures, issued by the Prime Minister's Department under subsection (5) of Section 17A on 4 December 2018 (official text), set out five principles known as T.R.U.S.T. The last of them, Principle V: Training and Communication, is where ABC training lives. In summary, it asks the organisation to:

  • Train and communicate on four areas: the anti-corruption policy, training itself, the reporting channel, and the consequences of non-compliance (para 4.5.1).
  • Publish the policy and communicate it to all personnel and business associates, not only staff (para 4.5.2).
  • Plan the communication: what key points, to whom, how, over what timeframe, and in which languages (para 4.5.3).
  • Train employees and business associates adequately, "especially in relation to their role" (para 4.5.5).
  • Use formats that fit, including induction programmes, role-specific training tailored to the corruption risks of the position, in-house courses, and web-based programmes (para 4.5.6).

Two things stand out. First, the guidelines are principle-based and deliberately not "one-size-fits-all" (para 3.4): they do not prescribe a course length, a syllabus or a refresher interval. Second, the phrase that recurs is role. The expectation is proportionate training matched to risk, which a single company-wide session cannot meet on its own.

Why one awareness session is not enough

Training is judged alongside the other four principles, and it depends on them. The guidelines expect a corruption risk assessment (Principle II). If yours has found that sales staff deal with government-linked customers, or that site managers handle permits and inspections, the training has to address those exact situations. Otherwise the risk assessment and the training contradict each other on paper.

In practice, the gaps that make a training programme hard to defend are common ones:

  • Everyone received the same content, regardless of exposure.
  • Business associates were never trained or even told the policy exists.
  • The whistleblowing channel was mentioned but never explained: who receives a report, whether it can be anonymous, and what protection the reporter gets.
  • Nothing was refreshed after the policy, the risk assessment or the business changed.
  • Records show attendance only, with no content, no assessment and no link to the risk it addressed.

What to cover: a three-tier model

A practical way to meet the "role-specific" expectation is to train in three tiers. Everyone gets the foundation; higher-exposure roles get more on top of it.

Tier Who What they need beyond the tier above
1. Foundation All employees, at induction and on refresh What Section 17A means for them personally; the company's policy on gifts, hospitality, donations and facilitation payments; how to recognise a bribe or a red flag; how and where to report; what happens if they breach the policy
2. High-exposure roles Procurement, sales and business development, finance and payments, site or project managers, licensing and permits, anyone dealing with public officials Scenario practice for their actual situations: split tenders, kickbacks, inflated invoices, "consultancy fees" routed through agents, conflicts of interest, political and charitable contributions, third-party due diligence and when to escalate
3. Leadership and control functions Directors, senior management, compliance and integrity officers, internal audit, legal and company secretarial Personal exposure of directors and management under Section 17A; what top-level commitment has to look like in evidence; commissioning and reading the risk assessment; overseeing investigations and whistleblower protection; monitoring and review of the whole programme

Business associates such as agents, distributors, contractors and consultants who act for the company should receive, at minimum, the policy and the reporting channel, with training proportionate to the risk they carry on your behalf.

Three details that separate real training from box-ticking

1. Use your own cases, not generic ones. A case built from your industry's real pressure points (a customs clearance delay, a tender evaluation, a request from an inspector) is remembered and applied. A generic Western compliance video is not.

2. Train in the language people work in. Para 4.5.3 explicitly raises the language of communication. For a Malaysian workforce, that often means Bahasa Melayu materials, and sometimes Mandarin or Tamil, for the foundation tier, even if leadership sessions run in English.

3. Make reporting concrete. Staff should leave knowing exactly how to raise a concern and what protection they have. If your channel is not yet designed properly, fix that first. See our guide to building a whistleblower policy aligned to ISO 37002.

The evidence to keep

If the company ever has to rely on the adequate-procedures defence, it must prove the procedures were in place (para 3.3). For training, keep a file that answers five questions:

  1. Who was trained, and when? Attendance records by name, role and date, including business associates.
  2. What were they taught? The actual materials and version, not just a course title.
  3. Why that content for that role? A short note linking each tier to the risks in your corruption risk assessment.
  4. Did they understand it? Assessment results or acknowledgement forms.
  5. Is it kept current? A refresh plan, and evidence that training was updated when the policy, risk assessment or business changed.

Companies pursuing ISO 37001 certification will find the standard formalises much of this: its awareness-and-training requirements expect training proportionate to each role's bribery risk, at planned intervals, with documented records. If certification is on your roadmap, see what ISO 37001 certification costs in Malaysia and how trained internal staff reduce that bill.

In-house, public course or e-learning?

Each format has a place, and most companies end up combining them:

  • E-learning suits the foundation tier: it scales across shifts and sites, and completion data is recorded automatically.
  • Public courses can work for a single compliance officer who needs grounding, but the content cannot use your risk assessment or your cases.
  • In-house training is the natural fit for the high-exposure and leadership tiers, because the scenarios can be built on your own processes and discussed confidentially. That confidentiality matters when the subject is where your company is exposed.

For a fuller comparison, read in-house vs public training and e-learning vs live online vs onsite.

Funding ABC training with your HRD Corp levy

Anti-corruption and governance training can be funded through the HRD Corp levy when it is delivered under the HRD Corp Claimable Courses scheme. Our Anti-Corruption & Governance program is HRD Corp claimable for eligible employers. The grant application is made on e-TRiS; since 15 June 2026 HRD Corp requires it to be approved at least 14 days before training starts, so plan to apply about three weeks ahead. Our e-TRiS grant application guide walks through the steps. Eligibility and approval are decided by HRD Corp, so no provider can guarantee a claim.

Where Megabyte fits

The Anti-Corruption & Governance program is delivered in-house, at your premises anywhere in Malaysia, including Kuala Lumpur and Cyberjaya, and customised to your own risk profile, sector and roles. It is led by K. Sudhagaran Stanley, a former Deputy CEO of the Center to Combat Corruption and Cronyism (C4 Center) who has trained organisations from Intel and BMW to Maybank and EPF. Coverage spans Section 17A adequate procedures, ISO 37001 and ISO 37002, and can be combined with AML and PDPA modules.

Not sure which tiers you need? Tell us what policies, risk assessment and reporting channel you already have, and we will recommend the coverage that closes the gap.

Frequently asked questions

Is anti-bribery and corruption training mandatory in Malaysia?

No law sets a specific training course as mandatory. However, the Guidelines on Adequate Procedures issued under Section 17A of the MACC Act list training and communication as one of the five principles of adequate procedures, which is a company's only defence to corporate liability for corruption. In practice, a company with no role-appropriate training would struggle to show its procedures were adequate.

Who in the company needs anti-bribery training?

All employees should receive foundation training on the policy, red flags and how to report. Roles with higher exposure, such as procurement, sales, finance, and anyone dealing with public officials, need scenario-based training for their situations. Directors, senior management and control functions need training on their own oversight duties. Business associates acting for the company should at least receive the policy and reporting channel.

How often should anti-corruption training be refreshed?

The official guidelines do not set a fixed interval. Refresh training when the anti-corruption policy, the risk assessment or the business changes, and on a regular planned cycle in between. Companies pursuing ISO 37001 are expected to train at planned intervals and keep records.

Is anti-bribery and corruption training HRD Corp claimable?

It can be, when delivered as an HRD Corp claimable course by a registered training provider to an eligible employer. Megabyte's Anti-Corruption & Governance program is HRD Corp claimable. The grant must be approved at least 14 days before training begins, so apply about three weeks ahead. Approval is decided by HRD Corp.

Can anti-bribery training be delivered in-house in Kuala Lumpur or Cyberjaya?

Yes. Megabyte delivers the Anti-Corruption & Governance program in-house at client premises across Malaysia, including Kuala Lumpur and Cyberjaya, with content built around the company's own risk assessment and roles.