Could Your Company Be Prosecuted for an Employee’s Crime? Understanding Corporate Criminal Liability Under Indonesia’s New KUHP
By Angky Banggaditya & Zaldy Saslika
Imagine an employee commits fraud, bribery, or another criminal offense while performing their job. Under Indonesia’s new Criminal Code, the question may no longer be limited to whether the employee can be prosecuted. Authorities may also ask whether the company should be held responsible.
This reflects one of the most significant developments introduced by the new KUHP: the expansion of corporate criminal liability. For businesses operating in Indonesia, understanding this change is no longer simply a legal issue. It is an important part of managing corporate risk.
The Shift: From Individual to Corporate Accountability
For a long time, when dealing with employee misconduct, the legal framework operated on a clear distinction: companies could be held civilly liable for harm caused by their employees on the grounds of Article 1367 of the Indonesian Civil Code. If an employee’s wrongdoing damaged others, the company might have to compensate them through civil remedies, such as paying damages, settling disputes, and disciplining the offender.
Criminal liability, however, remained personal to the individual employee. This reflected a foundational principle in criminal law: tiada pidana tanpa kesalahan (no punishment without fault), meaning that criminal responsibility attaches only to those who actually committed the wrongful act and possessed the necessary criminal intent.
The new KUHP changes that. Article 37B of the new KUHP provides that a corporation can now be criminally liable for acts committed by its employees. It is a departure from what we have been used to, and it is something Indonesian businesses are still grappling with.
Putting This in Context: Corporate Liability and General Crimes
Some background helps explain the significance of this development.
Under the old KUHP, the prevailing principle was straightforward: a company, as a legal entity, could not be held criminally liable for general crimes, namely, ordinary offenses prescribed under the KUHP, such as fraud, forgery, and embezzlement. Criminal liability was confined exclusively to individuals.
There was, however, an important exception. A company could be charged with a criminal offense if a specific law explicitly allowed it. Over time, Indonesia enacted a number of such laws in particular sectors, including corruption, money laundering, environmental protection, forestry, health, fisheries, etc. Within these areas, companies could be prosecuted and sanctioned in the same way as individual offenders. Outside of these laws, they could not.
This is where the new KUHP makes a meaningful difference. The change lies primarily in its scope. Previously, as mentioned, holding a company criminally liable required a specific law that made this possible. The new KUHP expands this framework by directly allowing corporate liability for general crimes. In simple terms, it broadens the range of conduct for which a company can be held criminally responsible.
Defining the Boundary of Corporate Criminal Liability
Article 48 of the new KUHP sets out five principles for determining when a corporation may be held criminally liable for misconduct committed by its employees. These are:
- The act is committed within the scope of the corporation’s business activities;
- The act is committed for the benefit of the corporation;
- The corporation fails to exercise proper supervision or implement adequate compliance mechanisms;
- The misconduct reflects corporate policy, corporate culture, or managerial negligence; and/or
- The corporation allows or tolerates conditions that enable the offense.
While the law presents these as alternative bases, in practice they are not applied equally or independently. Instead, law enforcement typically uses a two-stage approach.
Stage 1: Establishing the Corporate Link
The first two principles function as threshold requirements:
- The conduct must fall within the corporation’s business activities; and
- It must be intended to benefit the corporation, whether directly or indirectly.
If these elements are not satisfied, corporate criminal liability will generally not arise.
Stage 2: Establishing Corporate Fault
Once that link is established, authorities then consider whether the corporation itself can be considered at fault. This is assessed by looking at the remaining three principles:
- Whether there was a failure of supervision, compliance systems, or internal controls;
- Whether the misconduct reflects corporate policy, culture, or managerial negligence; or
- Whether the corporation allowed or tolerated conditions that enabled the offense.
In essence, the analysis focuses on two key questions:
Is the misconduct sufficiently connected to the corporation and did it benefit the corporation?And if so, did the company fail to prevent it through its internal systems or governance?
This practical approach is critical for understanding how the law is likely to be enforced.
What Practitioners Are Seeing in Practice
From a practical perspective, this framework provides a degree of clarity. It avoids imposing automatic liability to the corporation for every act committed by an employee. There must be a real connection between the conduct and the corporation.
At the same time, it reinforces an important message: effective compliance and corporate governance are no longer simply best practices, but they are essential safeguards against criminal exposure.
In highly regulated industries such as shipping, logistics, natural resources, and financial services, this shift is already evident. Authorities are increasing their scrutiny, and enforcement activity is beginning to intensify. As a result, boards and senior management are asking more direct and detailed questions about the strength of their compliance systems.
The Practical Implications
For companies operating in Indonesia, several key takeaways emerge.
First, compliance programs must be substantive and effective. Formal policies alone are no longer sufficient. They must be supported by effective implementation, monitoring, and enforcement.
Second, management and boards must play an active role in oversight. It is no longer enough to delegate compliance responsibilities without ensuring that appropriate systems and controls are in place.
Third, companies in higher-risk sectors should expect closer attention from regulators and law enforcement, particularly in how they structure their operations and manage risk.
A common question we hear from clients is straightforward: Are we adequately prepared under this new framework?
In many cases, the honest answer is not yet—which explains the growing demand for comprehensive compliance reviews and improvements.
Where We Go From Here
The direction is clear. The government expects corporations to take an active role in preventing criminal conduct within their organizations.
While this development is broadly consistent with global trends, it represents a significant shift in the Indonesian context. Companies that respond proactively by strengthening governance, compliance, and internal controls will be better positioned as enforcement becomes more robust.
For anyone responsible for managing corporate risk in Indonesia, now is the time to take a closer look at existing practices and ensure they meet the expectations of this new legal environment.
If you are managing corporate risk in Indonesia, this is worth a closer look at your own practices.
Angky Banggaditya
Managing Partner
angky@bnslaw.id
https://www.linkedin.com/in/angky-banggaditya-86a828b9/
Zaldy Saslika
Partner
zaldy@bnslaw.id
https://www.linkedin.com/in/zaldy-saslika-b27a6715a/
