Europe · Investigations and protection of business

Building an effective anti-corruption compliance system

Erich Rath10 min read

Mainstream

Building an Anti-Bribery & Anti-Corruption (ABAC) system is not about implementing a code of ethics and a set of policies. It is the creation of a living mechanism for protecting business and its managers.

The question is not whether you have anti-corruption procedures in place. The main question is whether your system can withstand real regulatory scrutiny, prevent bribery and protect the company and top officials from multimillion-dollar fines and criminal liability.

An effective ABAC system starts with three fundamental things:

  • A deep understanding of the real corruption risks of a particular business.
  • A clear definition of applicable extraterritorial and local laws.
  • Provable performance of controls at all levels – from the board of directors to the line manager for procurement.

If these three components are not worked out, the company will have a beautiful compliance package that will crumble at the first check or, worse, at a real incident.

When a business needs an ABAC system

Building or restarting an anti-corruption compliance system becomes critical if:

  • The company enters markets with high levels of corruption;
  • foreign investment is being attracted or M&A is being prepared;
  • business interacts with government agencies and officials;
  • a wide network of agents, distributors and intermediaries is used;
  • Previous audits have identified red flags
  • a request from a correspondent bank or payment system;
  • In the company there was an incident related to suspicion of a bribe;
  • considering a public offering or private equity fund requiring compliance due diligence;
  • The industry has already undergone high-profile anti-corruption investigations;
  • Management is aware of personal risks under the FCPA, UK Bribery Act or local anti-corruption legislation.

The mistake most companies make

Many companies start with the question:

What code of ethics and policies should we adopt?

That's the wrong first step.

The right question is:

What is the map of our real corruption risks and where should the control system be as strict as possible?

Sometimes the main risk zone is not gifts to officials, but fictitious agency contracts in a third country. Sometimes, it is possible to obtain licenses through consultants with non-transparent functions. Sometimes it is a joint venture with a partner who solves issues informally.

An effective ABAC system is not built on templates, but on specific business processes that can be used to bribe.

Step 1. Corruption Risk Assessment (Risk Assessment)

The first thing to do is not write policy, but map risks honestly.

Key elements of evaluation:

  • Geographical markets and the Corruption Perceptions Index
  • Interaction with Public Officials (PEPs)
  • use of intermediaries, agents, consultants, lobbyists;
  • obtaining licenses, permits, quotas;
  • Customs clearance and logistics;
  • participation in public tenders and procurement;
  • Corporate hospitality, gifts, sponsorship;
  • charitable contributions;
  • M&A transactions and risk inheritance;
  • Cash payments and non-standard financial transactions.

Without an individual risk map, the control system will shoot blindly.

Step 2. Identify applicable anti-corruption legislation

The legal framework dictates the standards and limits of liability.

The requirements must be clearly understood:

  • FCPA (USA) – extraterritorial action, liability for the actions of third parties;
  • UK Bribery Act – the strict liability of the company, offense of failure to prevent bribery;
  • local anti-corruption legislation of the country of presence;
  • industry regulation (for example, in pharmaceuticals, oil and gas, defense);
  • requirements of international financial institutions and banks (Wolfsberg, FATF);
  • sanctions regimes that affect interaction with certain counterparties.

The error at this stage leads to the system conforming to the internal perception of “good tone” but not to protect against extraterritorial persecution.

Step 3. Develop and implement policies and procedures

Only on the basis of the risk map and the legal framework are the documents created:

  • Anti-corruption policy and code of conduct;
  • Gifts, hospitality and hospitality policies;
  • policy of interaction with public officials;
  • due diligence policy of counterparties;
  • the procedure for escalation and obtaining approvals for high-risk operations;
  • provisions on conflict of interest;
  • the policy of charitable contributions and sponsorship;
  • the procedure for reporting violations (whistleblowing);
  • Measures of responsibility for violation of anti-corruption rules.

Documents should be written in the language of business, not the language of law. If a policy cannot be understood and executed, it is useless.

Step 4. Implementing mandatory due diligence of third parties

The main vector of corruption risks is the actions of intermediaries.

It shall be checked:

  • beneficial owners of the counterparty;
  • business reputation and presence of red flags;
  • communication with public officials;
  • structure of remuneration and validity of commissions;
  • the actual volume of services provided;
  • payment details and money routes;
  • anti-corruption clauses in treaties;
  • The right to audit and terminate the contract in case of violation of the ABAC policy.

Due diligence should not be a formal collection of questionnaires. It is a reputational and financial analysis that stops a questionable relationship before a problem arises.

Step 5. Provide top tone and real learning

The system of control does not work without the commitment of senior management.

Training should:

  • targeted (board of directors, management, sales, procurement, finance);
  • practical – on cases and examples from the industry;
  • regular, not one-time, when hiring;
  • with mandatory documentation of passage;
  • Include a mechanism for testing knowledge and understanding of red flags.

The tone above is not confirmed by statements, but by compliance resources and the real consequences for violations.

Step 6. Configure communication channels and whistleblowing mechanism

Without a working channel for reporting violations, the system loses feedback.

It is necessary to ensure:

  • guarantee of confidentiality and protection from reprisals;
  • the possibility of anonymous treatment;
  • several channels (hotline, email, specialized platform);
  • clear rules for the consideration of communications;
  • maintaining statistics and feedback to the applicant (within permissible limits);
  • protection of the applicant in accordance with local law.

If employees do not trust the channel, the company will learn about the bribe of the latter.

Step 7. Establish financial and operational control

Control should be built into processes, not exist separately.

Key elements:

  • Checking payments for red flags;
  • mandatory confirmation of the reality of services before payment;
  • control of gifts, representation costs, limits;
  • limits of powers and mandatory coordination of high-risk operations;
  • through the registration of interaction with officials (government touchpoints log);
  • Regular reconciliation of accounting data and control of non-standard entries;
  • prohibition of cash payments or their maximum limitation with documentation.

The CFO and Chief Accountant are key allies of the compliance function.

Step 8. Monitor, audit and verify the effectiveness of the system

The ABAC system must be tested in practice.

The format of the inspections may include:

  • regular internal audit of compliance controls;
  • Independent external assessment of the system for compliance with the FCPA/UK Bribery Act;
  • Mystery shopping and transaction analysis
  • selective audit of specific business units;
  • analysis of the use of intermediaries and agents;
  • testing of knowledge of employees;
  • Analysis of whistleblowing messages and response to them.

The regulator does not assess the availability of policies, but their real performance. This needs to be documented.

Step 9. Ensure prompt and adequate response to violations

The incident is a test of the maturity of the system.

The response protocol should include:

  • immediate recording and preservation of evidence;
  • involvement of a legal adviser with the privilege of an attorney-client;
  • Resolving the issue of informing the regulator (self-disclosure);
  • isolation of the problem from current activities;
  • Internal investigation with documentation of root causes;
  • the application of sanctions to the guilty, regardless of position;
  • Adjust the controls to prevent recurrence.

Quick and professional response can significantly reduce the risks of liability of the company and its officials.

Step 10. Updating and improving the system

Markets, laws and business models are changing. The monitoring system must adapt.

The improvement cycle includes:

  • Annual risk reassessment;
  • updating policies for new products and markets;
  • feedback from business units;
  • Incident analysis and near misses;
  • Consideration of changes in law enforcement practice;
  • Increase the maturity of the compliance function.

The static system is dying. An effective system is a continuous process.

Formal vs. Effective ABAC System

CriteriaFormal systemReal control system
BasisPattern politicsRisk map of a particular business
Due diligenceCheck-box questionnaireSubstantive analysis of beneficiaries and transaction structure
TrainingOne-time, generalRegular, role-playing, with testing
Control of paymentsPost-factual reconciliationPreliminary compliance control of high-risk transactions
Whistleblowingformal boxA working channel with real protection of the applicant
Response to the incidentFinding the blameInvestigation, elimination of the cause and self-reporting if necessary
The resultFolder of documents for the reportAbility to protect business and management in audit

Common mistakes in building an ABAC system

1. Start with policies, not risk assessments: A system that is not tied to real processes does not catch violations.

2. The risks of an international trader and a local developer are fundamentally different.

3. Formal collection of documents does not reveal a hidden connection with the official.

4. If the first person demonstrates double standards, the system does not work.

5. An employee who does not understand the “red flags” will miss a bribe in a standard operation.

6. The leaking of information about whistleblower kills trust and the flow of messages.

7. Do not test the system before checking the weakness of controls, the company should not learn from the subpoena.

8. The cost of an effective system is always less than possible penalties and damage to reputation.

9. Anything that is not documented does not exist for the regulator.

10. Ignore post-incident analysis Without correcting the root causes, the incident will happen again.

Checklist: Is your ABAC system ready for testing?

Before a regulatory review or a major transaction, 15 questions must be answered:

  1. Has the company’s corruption risks been assessed?
  2. Are applicable anti-corruption laws defined in all jurisdictions of the presence?
  3. Have policies and codes of conduct been approved by the board?
  4. Is there a real due diligence of all high-risk intermediaries?
  5. Are the results of the checks of counterparties documented?
  6. Are all high-risk employees being trained?
  7. Is there evidence of training and testing?
  8. Does the whistleblowing channel work with the applicant's protection?
  9. Is there a pre-registration of red flag payments?
  10. Is there a record of interaction with government officials?
  11. Has an independent audit been conducted on the performance of the ABAC system over the past 2 years?
  12. Is there a protocol for responding to an incident, including a self-report decision?
  13. Is all compliance decisions and approvals documented?
  14. Are there anti-corruption clauses and audit rights in the contracts with intermediaries?
  15. Can the company prove to the regulator that the system is working?

What is a strong ABAC system: five levels of protection

A strong control system is built on five levels:

1. Risk Intelligence: A deep understanding of the risks of a particular business and their dynamics.

2. Governance & Policies: Clear rules approved by top management and a provable tone from above.

3. Operational Controls: Built into business processes of due diligence, auditing and financial controls.

4. Detection & Response: Working whistleblowing channels, auditing and the ability to conduct rapid internal investigations.

5. Continuous Improvement: Regular reassessment, error correction, and adaptation to new realities.

If a company cannot demonstrate all five levels of performance, its system remains paper-based and the risks are unacceptable.

FAQ

Anti-Bribery & Anti-Corruption is a system of measures to prevent, detect and suppress corruption and bribery in the company’s activities.

Key laws are the FCPA (USA), the UK Bribery Act (UK), as well as local anti-corruption legislation of the countries of presence. Many of them have extraterritorial effects.

Can you just go with the code of ethics? Regulators and courts do not assess the availability of a document, but the provable performance of the control system. The code without support by procedures, training and auditing does not protect.

Primary due diligence is carried out before the beginning of the relationship, then with a set frequency depending on the level of risk, as well as when the “red flags” appear.

Immediately ensure the safety of evidence, involve a lawyer with privilege, conduct an internal investigation and assess the need for self-disclosure to the regulator. Inaction exacerbates responsibility.

Is the company personally responsible for corruption? Under the FCPA and UK Bribery Act, officials can be criminally liable, including jail time and heavy fines. The “I didn’t know” principle doesn’t work in the absence of adequate procedures.

The cost depends on the size of the business, geography and complexity of risks. But this investment is always less than fines, forfeiture of profits, reputational damage and criminal prosecution.

How is internal compliance audit different from external assessment?Internal audit is part of the management system. An external independent assessment provides an objective slice needed for a board, investors or a demonstration to a regulator.

A decision on self-disclosure is made immediately after a serious breach is identified, taking into account jurisdictional requirements, the degree of involvement of management and the availability of a cooperation program. Procrastination can deprive the company of protection.

It is possible, but the risk is high, to create a formal rather than an effective system. An experienced lawyer-consultant helps to correctly assess risks, build privileged protection and prepare the company for possible verification.

Related services

  • Corporate Investigations, Regulatory Investigations & Business Integrity
  • Anti-Bribery, Anti-Corruption & Corporate Compliance
  • White-Collar Defense & Regulatory Enforcement
  • Cross-Border Due Diligence & Business Partner Screening
  • Internal Investigations & Incident Response
  • Sanctions, Export Controls & International Compliance

Related material

  • How to conduct anti-corruption due diligence of the counterparty without formalities
  • FCPA and UK Bribery Act: Extraterritorial risks to business
  • Whistleblowing in an international company: How to Create a Trusted Channel
  • What to do when finding a bribe: practical protocol for business
  • Assessment of corruption risks: Guide to Business Owners
  • Compliance audit vs. real verification: How not to fail the regulatory exam
  • How to Protect Top Management from Personal Responsibility for Corruption

Conclusion

Building an effective Anti-Bribery & Anti-Corruption system is not about buying templates or a one-time promotion. It is the construction of a living defense mechanism based on real business risks, not formal requirements.

Successful protection during verification is not laid when the agenda comes, but when the company honestly assesses its vulnerabilities, implements working controls and is able to prove their effectiveness.

Regulators are increasingly asking not “do you have a policy” but “show how it works.” A company that is ready to answer this question with documentation and demonstration of real cases preserves the value of the business, the reputation and freedom of its managers.

Have a question about the topic of this article?

Write to us and we will respond within one business day.