Global Advice Network | Borgergade 111 | DK - 1300 Copenhagen K
E-Mail: info@business-anti-corruption.org | Phone: (+45) 60 88 10 44

Building a Corruption Risk Map for Construction and Infrastructure

Construction and infrastructure projects combine large budgets, complex supply chains, public decision-making and long delivery timelines. These conditions create opportunities for bribery, bid rigging, conflicts of interest, fraud, facilitation payments, collusion and the misuse of political influence. A corruption risk map helps a company identify where exposure is concentrated and decide which controls deserve the greatest attention. Learn more about Corruption In The Waste Management Sector Contracts And Tipping Fees Eee1.

The map should do more than rank countries by perceived corruption. A project in a relatively low-risk jurisdiction can still face serious exposure through an opaque subcontractor, an aggressive agent, weak procurement controls or a politically connected landowner. Conversely, a high-risk location may be manageable when the company applies robust governance, transparent tendering and effective oversight.

A useful risk assessment combines geographic, commercial, operational and relationship-based information. It should follow the project from feasibility and permitting through procurement, construction, commissioning, operation and contract closeout. The result is a practical management tool that informs due diligence, approval decisions, monitoring and escalation.

Define The Project’s Risk Universe

Begin by mapping the full project ecosystem. Include the project owner, government agencies, regulators, lenders, investors, engineering firms, general contractors, consultants, suppliers, local partners, brokers, customs intermediaries and community representatives. Any party that can influence a decision, control information or receive project funds belongs in the initial risk universe.

Next, divide the project into stages and decision points. Land acquisition, environmental approvals, zoning, tender design, bid evaluation, contract award, change orders, milestone certification, payment approval, inspection and acceptance all create different corruption vulnerabilities. A map that focuses only on the bidding stage will overlook risks that emerge after a contract has been signed.

The assessment should also identify the assets and benefits at stake. These may include access to public land, licenses, construction materials, development rights, financing, tax treatment, waste disposal arrangements or future maintenance contracts. The higher the commercial value and discretion attached to a decision, the more carefully the associated control environment should be examined.

Combine Geographic And Transaction Factors

Country risk profiles are a useful starting point, but they should never become the entire assessment. Consider the quality of public procurement institutions, enforcement of anti-bribery laws, judicial independence, transparency of beneficial ownership information, customs practices, political stability and the prevalence of informal payments. Local and regional conditions may differ significantly from national averages.

Transaction-level factors often provide a more accurate picture of immediate exposure. A project may be vulnerable because a ministry has broad discretion, a municipal official controls permits, or a state-owned enterprise is both the purchaser and the regulator. Emergency procurement, sole-source contracting and compressed tender timelines can reduce transparency even where formal laws appear strong.

Map the interaction between external and internal factors. For example, weak public disclosure becomes more serious when a company uses a success-fee consultant to obtain a license. A high-risk intermediary becomes an urgent concern when payments are routed through multiple jurisdictions or when the intermediary refuses to disclose beneficial ownership. Risk increases through combinations, rather than through isolated facts alone.

Score Exposure Across The Project Lifecycle

A consistent scoring model makes judgments more transparent. Rate each risk according to likelihood and impact, then adjust the result for the strength of existing controls. Likelihood may reflect the frequency of similar misconduct, the level of discretion involved, the number of intermediaries and the quality of documentation. Impact may include financial loss, criminal liability, debarment, project cancellation, safety consequences and reputational damage.

Use evidence to support each rating. Relevant information may include audit findings, whistleblower reports, procurement exceptions, unusual payment requests, media investigations, court records, sanctions data and interviews with project personnel. Avoid relying on vague statements such as “the country is corrupt.” A clear record should explain the specific event, actor, process or control weakness that creates the exposure.

The following framework can help teams create a comparable view of typical pressure points:

Project area Common corruption exposure Warning indicators Priority controls
Feasibility and land Bribery for land access, zoning or approvals Unexplained urgency, informal requests, related land sellers Approval register, conflict checks, documented valuations
Tender design Tailored specifications, bid leakage or collusion One bidder fits requirements unusually well Independent review, market testing, sealed submissions
Contractor selection Kickbacks, false qualifications or favoritism Undisclosed relationships, weak competition Beneficial ownership checks, committee scoring, audit rights
Construction delivery Inflated invoices, substitution and false progress claims Repeated variations, missing materials, unverifiable milestones Site verification, segregation of duties, invoice testing
Agents and consultants Bribes disguised as commissions or success fees Vague services, cash requests, offshore accounts Risk-based due diligence, written scope, payment controls
Waste and materials Tipping-fee fraud, illegal disposal or diverted supplies Unlicensed operators, inconsistent weight records Chain-of-custody logs, approved vendors, independent inspections
Closeout and operation Improper acceptance, maintenance favoritism Pressure to certify incomplete work Technical sign-off, retention controls, post-award review

Scoring should be reviewed at defined gates rather than treated as a one-time exercise. A new subcontractor, political transition, financing change, serious incident or major variation can alter the profile. Keep the original rating and the updated rating so management can see whether controls are reducing exposure or merely shifting it.

Examine Procurement, Intermediaries And Payments

Procurement deserves detailed analysis because construction contracts frequently involve technical specifications that can be manipulated without attracting immediate attention. Warning signs include requirements that mirror one supplier’s product, unusually narrow qualification criteria, unexplained prequalification decisions, repeated disqualifications, identical bid language and limited access to tender information.

Large infrastructure projects also create opportunities for hidden compensation. A contractor may pass funds through a consultant, joint venture partner, supplier or charitable contribution. Teams should understand how kickback schemes can be concealed within inflated prices, fictitious services, rebates, subcontracting arrangements or change orders. Payment review must therefore connect invoices to contracts, deliverables, ownership and the commercial rationale for each charge.

Intermediary due diligence should be proportionate to risk, but it must be substantive. Verify ownership, qualifications, reputation, government connections, litigation, sanctions exposure, previous work and the legitimacy of the proposed service. Agreements should define deliverables, prohibit improper payments, require accurate records, permit audits and allow termination for compliance breaches. Compensation should match market value and be paid through transparent banking channels to the contracting entity.

Payment controls should track the entire flow of money. Separate procurement, receipt, invoice approval and payment authorization. Require evidence for mobilization advances, retention releases, variation claims and expense reimbursements. Extra scrutiny is appropriate for cash payments, third-party accounts, unusual currencies, offshore recipients, round-sum invoices and requests to split payments below approval thresholds.

Map Political, Regulatory And Community Pressure

Infrastructure is closely linked to government decisions, so political exposure requires its own category. Officials may influence permits, public tenders, land allocation, tariffs, financing or enforcement. A risk map should identify politically exposed persons, state-owned enterprises, public officials’ relatives and entities that appear to act as informal representatives.

Political contributions, sponsorships and charitable donations can create the appearance of a trade for influence, particularly near a tender, permit decision or contract renewal. Companies operating in the Middle East and other regions with strong government-business relationships should conduct a focused review of political contribution risks, including local law, recipient transparency, approval requirements and links to public procurement.

Community relations can also generate corruption risk. A project may need land access, local hiring, security services or compensation arrangements. Payments to community representatives should be documented, lawful and directed to legitimate recipients. A company should distinguish genuine community investment from benefits offered to secure consent, suppress complaints or obtain preferential treatment.

Regulatory pressure is another source of exposure. Inspectors may control safety certificates, environmental approvals, customs releases and operating licenses. Build an inventory of all official interactions, assign responsible employees, prohibit unofficial cash payments and retain records of meetings and submissions. Where engagement with officials is frequent, rotate responsibilities or introduce a second-person review.

Make Controls Visible And Actionable

A risk map has value only when it leads to ownership and action. Assign each major risk to a named business owner, compliance contact and escalation route. The owner should know which controls apply, what evidence must be retained and which events require immediate notification. Generic responsibility assigned to “management” usually results in delayed decisions.

Use a control library linked to specific risks. Measures may include tender committees with independent members, conflict-of-interest declarations, vendor screening, approval thresholds, technical site inspections, data analytics, hotline access, contract audit rights and targeted training. Controls should address both prevention and detection. A signed policy is preventive in theory, but invoice testing, whistleblower reporting and surprise inspections help identify misconduct in practice.

Monitoring should use practical indicators. Track single-bid tenders, repeated awards to the same supplier, abnormal bid pricing, contract amendments, accelerated payments, unexplained delays, high-risk expenses, unusual donations and complaints involving officials or subcontractors. Indicators do not prove corruption, but clusters of anomalies should trigger review.

  • Reassess high-risk projects at every major procurement, payment and contract-variation stage.
  • Link third-party screening depth to ownership opacity, government contact, service type and payment structure.
  • Require documented approval for donations, sponsorships, facilitation-sensitive expenses and emergency procurement.
  • Test whether site records, delivery notes, invoices and milestone certificates describe the same work.
  • Give employees, contractors and communities a confidential channel for reporting concerns without retaliation.

Training should reflect the situations employees actually face. Procurement officers need guidance on collusion and bid confidentiality; project managers need instruction on variations and progress certification; finance teams need warning signs for disguised commissions; local staff need clear rules for interactions with inspectors and customs officials. Scenario-based learning is more effective than a general statement that bribery is prohibited.

Keep The Map Current Through Project Change

Construction risks evolve as the project moves from design to delivery. A new concession partner may introduce different political connections. A delay may create pressure to bypass approval procedures. A natural disaster may justify emergency procurement while also increasing fraud exposure. A change in government can alter permit expectations, enforcement priorities and relationships with state-owned entities.

Set review triggers in advance. These should include major contract amendments, new joint ventures, changes in beneficial ownership, entry into a new province, serious allegations, regulatory investigations, payment irregularities and the appointment of politically connected representatives. The assessment should be updated when these events occur, not only during an annual compliance cycle.

Information should flow between project controls and enterprise compliance. Audit findings, hotline cases, due diligence results and procurement analytics should feed into the map. Senior leaders need a concise view of the highest residual risks, overdue actions and decisions requiring escalation. Project teams need enough detail to act without waiting for a lengthy central review.

A mature risk map also records accepted risks and the reasons for acceptance. Some exposure cannot be eliminated, but it can be reduced, monitored or transferred through contractual protections and insurance. Documenting the decision prevents risk acceptance from becoming an informal excuse for ignoring warning signs.

Turn The Assessment Into Project Decisions

Use the completed map to decide whether to enter a market, select a partner, approve a tender, proceed with a payment or pause a transaction. The strongest programs connect risk ratings to clear consequences: enhanced due diligence for high-risk intermediaries, executive approval for sensitive engagements, independent testing for major contracts and escalation when controls fail.

A construction company can make corruption risk management part of ordinary project discipline rather than a separate compliance exercise. Build the map before commitments are made, update it when circumstances change and use evidence to challenge optimistic assumptions. Apply the same method across countries and project types while adapting controls to local law and operational realities.

Download relevant country guidance, review the project’s highest-risk decision points and assign owners for each action this week. A living corruption risk map gives boards, project leaders and compliance teams a shared basis for protecting public funds, preserving delivery schedules and making infrastructure investment more trustworthy.

copyright © Global Advice Network