Global Advice Network | Borgergade 111 | DK - 1300 Copenhagen K
E-Mail: info@business-anti-corruption.org | Phone: (+45) 60 88 10 44

Building one compliance framework after a merger

An acquisition creates a legal and operational relationship before it creates a unified organisation. The acquired business may have its own anti-bribery rules, approval limits, whistleblower channels, gifts register, third-party screening process and records retention schedule. These arrangements can continue operating after the transaction closes unless management deliberately brings them together.

A sound post-acquisition integration of compliance policies and procedures protects the buyer from inheriting unknown misconduct and helps employees understand which rules apply. It also gives the combined business a defensible record of how it identified risks, made decisions and addressed weaknesses during the transition.

The work is broader than copying the acquiring company’s policy library into a new intranet. It involves comparing legal obligations, testing whether controls operate in practice, preserving evidence, assigning ownership and deciding where local procedures remain necessary. A policy that is clear in Melbourne may need different implementation in a sales office in Mumbai, a mining operation near Perth or a distributor serving Queensland customers.

The most effective programme is risk-based and staged. It starts with facts gathered during due diligence, moves through a documented gap assessment, and ends with monitoring that shows whether the new framework is being followed. Employees should experience the process as practical guidance rather than a sudden collection of unfamiliar restrictions.

Set the mandate and preserve the evidence

The board or senior executive team should issue a written integration mandate before policies are rewritten. It should identify the executive sponsor, the compliance lead, legal advisers, business owners and the date by which key controls must be aligned. The mandate should also clarify which policies apply immediately, which remain temporarily in force and who can approve exceptions.

Preserving records is an early priority. Secure copies of the target’s policies, training logs, investigation files, gifts and hospitality registers, distributor contracts, government interaction records and approval trails. Include emails and other documents relevant to known allegations. A buyer should avoid altering or destroying inherited records while trying to tidy the new organisation’s systems.

The integration team should establish a decision log. Record the source of each policy, the reason for adopting or rejecting it, unresolved legal issues and the person responsible for closing each action. This creates an audit trail for the board and helps prevent the same question being reconsidered by different workstreams.

Australian companies should connect this mandate to existing obligations under the Corporations Act 2001, the Criminal Code Act 1995 provisions concerning foreign bribery and, where relevant, the Modern Slavery Act 2018. Businesses covered by financial crime obligations may also need to consider the Anti-Money Laundering and Counter-Terrorism Financing Act 2006 and guidance from AUSTRAC.

Build a risk-based gap assessment

Begin with a control inventory rather than a policy comparison. Map how the acquired business actually sells, buys, hires, pays and interacts with public officials. Review high-risk markets, agents, customs brokers, consultants, joint ventures, donations, sponsorships, charitable contributions and cash-intensive activities. Compare the written rules with transaction samples and interviews.

A country profile can support this exercise, especially where the target operates through local partners or government-facing intermediaries. For example, the India risk snapshot can help the team frame questions about public procurement, licensing, facilitation payments and local enforcement conditions. It should inform enquiries rather than replace local legal advice or transaction-level due diligence.

Rate each gap according to the likelihood and impact of misconduct, the exposure created by the acquisition and the time required to remediate it. A missing approval for low-value office supplies is different from weak controls over a customs agent paid to accelerate imports. The assessment should distinguish between a policy gap, a design gap and an operating failure.

Give urgent attention to red flags that could trigger personal or corporate liability. These may include unexplained commissions, payments routed through unrelated accounts, unusually vague consulting agreements, government-connected counterparties, incomplete beneficial ownership information and resistance to audit rights. Where facts suggest possible misconduct, preserve independence and escalate for a privileged legal assessment rather than burying the issue in routine integration tasks.

Decide what becomes common and what stays local

A combined business needs a clear hierarchy of documents. A group-wide code of conduct and core anti-corruption policy should establish common principles, prohibited conduct, reporting duties, investigation standards and disciplinary expectations. Supporting procedures can then explain how those principles operate in procurement, sales, finance, human resources and third-party management.

Local addenda are useful when legislation, language, licensing practice or market conditions differ. They should supplement the group standard, not quietly contradict it. If local law imposes a stricter rule, the stricter requirement should normally prevail. If a local custom conflicts with the group’s prohibition on facilitation payments or undisclosed benefits, the custom should not be treated as an exception.

The Australian business environment illustrates why a single global document is rarely sufficient. A company with offices in Sydney and Melbourne may also manage mining suppliers in Perth, infrastructure contractors in Brisbane and regional distributors using different procurement practices. The same approval matrix may need local ownership, while the underlying prohibition on bribery, falsified books and retaliation remains consistent.

Create a policy crosswalk showing each subject, the old target rule, the buyer’s standard, the final position, the legal basis and the implementation owner. Include document control information, translations and effective dates. Employees should never have to guess whether an archived target policy or a new group policy governs their next transaction.

Harmonise approvals, reporting and investigations

Operational controls make the policy credible. Align approval thresholds for gifts, hospitality, travel, donations, sponsorships, charitable contributions and political activity. Define the information required before approval, including the recipient’s role, business purpose, estimated value, attendees and relationship to a tender or regulatory decision.

Third-party due diligence should follow a consistent risk model. Collect ownership and management information, identify public officials and politically exposed persons where relevant, assess services and payment routes, and document the business rationale. Contracts should include anti-corruption representations, audit rights, training expectations, termination provisions and restrictions on subcontracting. Renewal reviews should be triggered by risk, not merely by the passage of time.

Entertainment businesses and digital platforms require particular care because marketing incentives, affiliate arrangements and payment flows can blur the line between ordinary promotion and improper influence. A review of casino cashback practices may be relevant when an acquired business uses bonuses, referral partners or customer incentives; the compliance team should test advertising claims, licensing restrictions, age controls, financial crime safeguards and approval records rather than assuming that a commercial promotion is low risk.

Reporting channels must work across the combined organisation. Decide whether employees can report anonymously, how matters are triaged, when the board or audit committee is notified and how conflicts of interest are handled. Align investigation protocols, evidence preservation, interview standards, disciplinary outcomes and protection against retaliation. Australian whistleblower protections make consistency especially important where employees, former employees and contractors may raise concerns through different channels.

Integrate people, systems and third parties

Training should follow the risk created by each role. Directors and senior managers need guidance on oversight, escalation and tone from the top. Sales teams require examples involving discounts, tenders, distributors and public officials. Procurement staff need practical instruction on conflicts, bid processes, beneficial ownership and invoice review. Finance teams should understand books-and-records risks and when an unusual payment must be stopped.

Use short, scenario-based sessions supported by a central code of conduct. A compulsory online module can establish a common baseline, while workshops address local risks and management responsibilities. Track attendance, completion, test results and overdue training in a system that can identify employees transferred from the target business. Training should be repeated when procedures change, not only at annual intervals.

Technology integration can expose gaps that policy reviews miss. Connect vendor master data, expense systems, accounts payable, case management, sanctions screening and gifts registers where appropriate. Reconcile duplicate suppliers, dormant accounts, changes to bank details and unusual payment patterns. Access controls should be redesigned so former target employees retain only the permissions required for their new roles.

External advisers may be needed for specialist questions, including cross-border investigations, employment law, privacy, sanctions or local licensing. For an acquisition with United States contacts or complex interstate issues, a resource such as The Laredo Lawyer may help identify questions for external counsel, although the integration team should confirm that any adviser has the right jurisdictional expertise for the matter.

Test the framework and keep it alive

A policy is integrated only when the business can demonstrate that people use it. Conduct targeted testing after the first 60 to 90 days, then repeat it according to risk. Sample third-party files, expense claims, tender approvals, charitable payments, recruitment agents and manual journal entries. Compare system records with policy requirements and interview employees who perform the work.

Set measurable indicators for the board or audit committee. Useful measures include overdue due diligence reviews, high-risk third parties without current approvals, exception requests, training completion, hotline reports, investigation ageing, gifts above threshold and remediation actions past due. Numbers should be interpreted carefully: a rise in reports may indicate stronger trust in the reporting channel rather than worsening conduct.

The first review should also test whether employees understand the escalation path. Ask a sample of staff how they would respond to a request for a facilitation payment, an unexplained success fee or a supplier offering hospitality during a tender. If answers differ by business unit, revise the procedure, training or management messaging.

Assign a permanent owner for every critical control and schedule an annual framework review, with additional reviews after regulatory change, entry into a new market, a serious incident or another acquisition. Australian organisations should monitor updates from regulators and consider how changes to foreign bribery enforcement, whistleblower expectations, procurement rules and supply-chain reporting affect their controls.

A practical integration file should contain the mandate, risk assessment, policy crosswalk, board reporting, training evidence, due diligence decisions, investigation records, exception approvals and testing results. This evidence demonstrates that compliance was actively managed rather than assumed. It also gives new managers a reliable starting point when responsibilities change.

The immediate next step is to appoint one executive sponsor and complete a documented inventory of the acquired business’s policies, high-risk third parties, reporting channels and open investigations within the first 30 days.

copyright © Global Advice Network