Global Advice Network
| Borgergade 111 | DK - 1300 Copenhagen K
|
|
|
|
How to Conduct Post-Acquisition Compliance Integration in AfricaAcquiring a company in Africa creates an opportunity to strengthen governance, improve controls, and align operations with a wider group compliance framework. It can also expose the buyer to inherited risks involving public procurement, customs, licensing, agents, charitable contributions, employment practices, financial reporting, and third-party relationships. A post-acquisition compliance integration should therefore begin immediately after closing, while preserving evidence and maintaining business continuity. The aim is not to impose a distant headquarters model without adaptation. It is to establish consistent minimum standards while accounting for the target’s country, industry, ownership structure, operating environment, and relationships with government institutions. The process should combine legal analysis, operational testing, employee engagement, and sustained monitoring. A written plan with clear owners and deadlines helps the acquiring company distinguish urgent misconduct issues from longer-term improvements. Establish Scope And GovernanceThe first step is to define the target’s legal and operational perimeter. Confirm which subsidiaries, branches, joint ventures, warehouses, representative offices, and dormant entities have been acquired. Map the countries where the target earns revenue, sources goods, hires staff, uses intermediaries, or interacts with public officials. A company incorporated in one African country may still face compliance exposure across several markets. Create an integration steering group with representatives from compliance, legal, finance, internal audit, procurement, human resources, information security, and business leadership. The group should report to a senior executive or board committee with authority to approve urgent controls, suspend risky relationships, and allocate resources. Local management should have a defined role because headquarters may not understand customary practices, regulatory expectations, or operational constraints in the target market. Preserve the target’s records before changing systems or deleting duplicate files. Secure emails, accounting data, contracts, expense claims, tender documents, gifts and hospitality registers, investigation files, and communications with agents. A legal hold may be necessary where there are signs of misconduct or possible regulatory enforcement. Access should be limited, documented, and consistent with applicable privacy and employment laws. Reassess Risk Through Local EvidenceThe buyer should perform a post-closing risk assessment rather than relying solely on due diligence completed before the transaction. Pre-acquisition reviews are often limited by time, restricted data access, or incomplete management representations. After closing, the company can inspect source documents, interview employees, test transactions, and compare reported practices with actual operations. Assess risks by country and activity. Relevant factors may include the use of customs brokers, licensing consultants, politically connected partners, distributors, security providers, and recruitment agents. Public-sector sales, infrastructure projects, extractive industries, healthcare, telecommunications, transport, and defense-related activities often require enhanced review because they involve permits, concessions, tenders, inspections, or state-owned customers. Country information should inform the assessment without replacing transaction-level evidence. A country risk profile can help identify areas for investigation, while the target’s own contracts, payment data, and complaints reveal how risk operates in practice. For a useful example of country-specific compliance research, consult the India country snapshot as a model for organizing regulatory, institutional, and business-environment information. The assessment should rank issues by likelihood, impact, and urgency. A questionable facilitation payment connected to an active government tender requires immediate action. An outdated gifts policy may be less urgent but still important to remediate before employees continue using inconsistent practices. Every finding should have an owner, a risk rating, supporting evidence, and a target completion date. Test Third Parties And Financial ControlsThird-party relationships are frequently the most significant source of inherited anti-bribery risk. Build a complete register of agents, consultants, distributors, customs intermediaries, freight companies, security providers, community liaison firms, suppliers, and subcontractors. Reconcile the register against the general ledger, vendor master file, procurement records, and bank payments. Missing or inactive vendors can reveal weak onboarding controls. Review how each intermediary was selected, who approved the appointment, what services were delivered, and whether compensation is proportionate to the work. Pay particular attention to vague scopes of work, unusually high commissions, cash payments, offshore bank accounts, requests for payment to unrelated entities, and relationships involving public officials or their relatives. Contracts should include anti-corruption representations, audit rights, termination provisions, and requirements to maintain accurate records. Financial testing should cover payments that may disguise improper benefits. Sample commissions, rebates, charitable donations, sponsorships, travel expenses, petty cash, supplier credits, and marketing costs. Compare invoices with evidence of performance and investigate round-dollar payments, split invoices, manual journal entries, expedited approvals, and transactions posted to generic accounts. Controls should prevent staff from bypassing procurement or creating vendors without independent verification. Sanctions screening must be part of this review. A target can create legal exposure through restricted customers, suppliers, banks, vessels, goods, or owners even where no bribe is involved. The sanctions compliance impact should be assessed alongside anti-bribery controls, export restrictions, and payment screening because these systems often rely on the same third-party data and escalation channels.
Harmonize Policies And ReportingA group compliance program should establish a common baseline for anti-bribery, conflicts of interest, gifts and hospitality, charitable giving, political activity, procurement, third-party management, books and records, and whistleblowing. The buyer should compare its global policies with the target’s existing documents and identify conflicting rules, missing procedures, and impractical requirements. Policies need local implementation guidance. A monetary threshold for gifts may be stated in a group currency, while employees operate in local currency and face different customary practices. A policy should explain approval routes, documentation standards, exceptions, and prohibited conduct in language employees can apply during a procurement meeting, border inspection, licensing process, or community engagement. Where the target has no dedicated legal or compliance team, management should provide clear ownership rather than treating the gap as an excuse for delay. Practical guidance on crafting an anti-corruption policy can help establish a workable baseline, including reporting channels, approval responsibilities, disciplinary consequences, and recordkeeping expectations. The reporting system should be accessible to employees, contractors, and third parties. Offer multiple channels, such as a web form, telephone line, email address, and designated local contact, while protecting confidentiality as far as the law permits. Define triage rules for allegations involving senior executives, public officials, financial fraud, retaliation, sanctions, or threats to personal safety. Investigations should be independent, documented, and consistent with labor, privacy, and evidence requirements in each relevant country. Remediate Workforce And OperationsEmployees will determine whether the integrated program works in practice. Communicate the new standards before introducing complex controls, explaining why the acquisition changes reporting lines, approvals, vendor processes, and investigation procedures. Messages should come from both group leadership and respected local managers. Training should use realistic examples involving customs clearance, public tenders, facilitation requests, travel, hospitality, hiring, and distributor commissions. Training should be risk-based rather than identical for every employee. Sales and government-relations teams need scenario-based instruction on interactions with officials. Procurement staff need guidance on bid integrity, conflicts, vendor ownership, and emergency purchases. Finance teams need instruction on invoice review, payment controls, and suspicious accounting descriptions. Directors and senior managers should understand personal liability, oversight duties, escalation expectations, and the consequences of retaliation. Review incentives and performance targets. Aggressive revenue goals, unofficial cash budgets, or bonuses based solely on contract awards can undermine written policies. Add compliance objectives to management evaluations and require certification for high-risk roles. Disciplinary action should be predictable and proportionate, applying to senior personnel as well as junior employees. Priorities For The First 100 Days
Operational controls should be embedded into existing workflows. Procurement software can require beneficial ownership information and compliance approval. Finance systems can block payments to unverified accounts or sanctioned parties. Contract templates can include audit and termination rights. These measures are more effective when they are simple enough for local teams to use consistently. Monitor, Document And SustainIntegration is complete only when controls operate reliably over time. Establish a monitoring plan based on the target’s risk profile, with more frequent testing for public-sector revenue, third-party commissions, cash-intensive operations, and jurisdictions with complex licensing or customs processes. Internal audit may conduct thematic reviews, while compliance performs periodic testing of approvals, training completion, hotline cases, and vendor files. Track measurable indicators such as overdue due diligence, unusual payment patterns, unresolved investigations, training completion, gifts exceeding thresholds, vendor exceptions, and repeat audit findings. Metrics should be presented to senior management in a way that supports decisions rather than creating a false impression of precision. A low number of reports may indicate a healthy culture, or it may show that employees do not trust the reporting channel. Document decisions and remediation evidence. Keep records of risk assessments, interviews, approvals, training attendance, investigation outcomes, disciplinary action, policy acknowledgments, and third-party reviews. Clear documentation helps demonstrate reasonable oversight to regulators, auditors, lenders, insurers, and future transaction partners. It also allows the organization to distinguish isolated misconduct from systemic control failure. The board or a designated committee should receive regular updates until critical issues are closed. Significant allegations, government inquiries, sanctions concerns, or evidence of books-and-records violations should be escalated promptly through the appropriate legal and compliance channels. Where misconduct is confirmed, consider disclosure, restitution, contract termination, employee discipline, control redesign, and cooperation with authorities based on the facts and applicable law. A successful integration creates a durable local compliance function rather than a temporary acquisition project. Continue refreshing country and sector risk assessments, reviewing third parties at renewal, testing controls, updating training, and consulting employees about practical obstacles. Use the first year after closing to establish a repeatable model that can support future acquisitions across African markets. Begin with a documented risk assessment, secure the evidence, and appoint accountable owners for each control gap. Then convert findings into tested procedures, trained employees, reliable reporting, and board-level oversight. A disciplined post-acquisition program protects the investment while giving the combined business a credible foundation for responsible growth. |