Global Advice Network
| Borgergade 111 | DK - 1300 Copenhagen K
|
|
|
|
How to Craft an Anti-Corruption Policy Without a Legal DepartmentA small company does not need a large legal function to create a credible anti-corruption policy. It needs clear standards, practical procedures, accountable decision-making, and a method for documenting what happens when a risk appears. A well-designed policy gives employees a reliable way to act when a customer, supplier, intermediary, or public official creates pressure to pay an improper benefit. The most effective policy is written for the company’s actual operations. A local retailer, an export business, a construction contractor, and a software provider will face different corruption risks. Their policies should therefore reflect their markets, third parties, payment processes, government touchpoints, and available resources rather than copy a multinational’s lengthy compliance manual. A lean compliance framework can be managed by an owner, operations manager, finance lead, or another trusted employee. The person responsible does not need to provide legal opinions on every issue. Their role is to coordinate risk assessment, preserve records, arrange training, escalate concerns, and obtain specialist advice when a situation exceeds the company’s knowledge. Start With A Practical Risk AssessmentBefore writing rules, map where corruption could enter the business. Review how the company wins contracts, obtains permits, imports goods, pays vendors, uses agents, recruits staff, and interacts with public authorities. Consider both direct bribery and less obvious benefits, such as excessive hospitality, charitable donations linked to a decision-maker, employment for a relative, or unexplained “facilitation” fees. Speak with employees who handle sales, procurement, finance, logistics, and government-facing work. Their experience will reveal pressure points that may not appear in accounting records. Review past incidents, rejected payments, unusual discounts, cash transactions, and complaints. Country risk profiles and sector information can add useful context, especially when the company operates across borders. Rank risks according to likelihood and potential impact. A simple scale—low, medium, and high—may be sufficient if the criteria are defined. High-risk situations could include using an unfamiliar intermediary to obtain a public contract, making payments through a third-party account, or operating where permits depend heavily on discretionary decisions. The assessment should state who owns each risk and when it will be reviewed. Define Rules That Employees Can ApplyThe policy should begin with a direct prohibition: employees and representatives may not offer, promise, authorize, request, or accept anything of value to improperly influence a business or official decision. “Anything of value” should include money, gifts, travel, meals, discounts, jobs, donations, sponsorships, loans, and personal favors. Use plain language and examples so that staff do not have to interpret abstract legal concepts under pressure. Set specific rules for gifts and hospitality. The policy can require legitimate business purpose, reasonable value, transparency, and prior approval above a stated threshold. Prohibit benefits during active tenders, inspections, licensing decisions, contract awards, or other sensitive proceedings. A register should record the date, recipient, value, purpose, provider, and approval for gifts, meals, travel, and entertainment. Facilitation payments should be prohibited unless an employee faces an immediate threat to health or safety. The policy should explain how to report such a demand and how to record any payment made under duress. Political contributions, charitable donations, sponsorships, and hiring referrals deserve separate controls because they can be used to reward decision-makers indirectly. Accounting rules are equally important. Every transaction must be recorded accurately and supported by appropriate documentation. Prohibit off-book accounts, false invoices, vague descriptions, split payments designed to avoid approval, and payments to personal accounts without a documented exception. Finance staff should have authority to pause a suspicious transaction rather than process it simply because a senior employee requested it. Assign Ownership Without Creating A Legal FunctionA policy fails when everyone is responsible in theory and no one is responsible in practice. Appoint a policy owner with enough independence, access, and authority to raise concerns. In a small company, this may be the finance manager or operations director, provided that the person can escalate an allegation involving a senior executive to the owner, board, or an external adviser. Divide duties across existing roles. Finance can monitor payments and maintain registers. Procurement can conduct supplier checks. Business leaders can approve higher-risk relationships. Human resources can include policy requirements in onboarding and disciplinary processes. Senior management should approve the policy, communicate its importance, and apply the same standards to high-performing employees and well-connected partners. Create an approval matrix that reflects the company’s size. It might require two approvals for payments above a threshold, enhanced review for public-sector customers, and written authorization before appointing an intermediary. The matrix should identify substitutes for absences and prohibit an employee from approving their own expense or a transaction benefiting a close associate. The following lean structure can help a small organization assign responsibility without hiring a full-time lawyer:
Screen Third Parties And Business PartnersThird-party risk often exceeds the company’s direct employee risk. Agents, distributors, customs brokers, consultants, local partners, and subcontractors may interact with officials or customers on the company’s behalf. A written contract cannot eliminate this exposure if the company ignores warning signs or rewards results without examining how they were achieved. Use a risk-based due diligence process. For a low-risk vendor, basic identity, ownership, services, bank details, and sanctions screening may be enough. A high-risk intermediary may require beneficial ownership information, relevant experience, references, conflicts-of-interest disclosures, adverse media checks, and an explanation of compensation. Check whether the proposed fee is commercially reasonable and linked to documented services. Record the reason for selecting the third party, who approved the relationship, what checks were completed, and when they should be repeated. Red flags include requests for cash, vague descriptions of services, unusual urgency, refusal to identify owners, close connections to officials, success fees for obtaining permits, and requests to pay a different person or account. Contracts should include anti-bribery commitments, audit and information rights, accurate invoicing requirements, training expectations, termination rights, and an obligation to notify the company about investigations or ownership changes. These provisions are useful only when the company monitors performance and responds to breaches. A high-risk partner should not be retained simply because replacing it would be inconvenient. Establish Safe Reporting And Response ProceduresEmployees need a safe route to raise concerns before a questionable payment becomes a regulatory or reputational crisis. Provide at least two reporting channels, such as a dedicated email address and a direct contact outside the employee’s management line. Explain that reports may concern attempted bribery, retaliation, falsified records, undisclosed conflicts, suspicious third-party requests, or pressure to bypass controls. Confidentiality should be protected as far as possible, while the policy should avoid promising absolute secrecy. Retaliation against a person who raises a concern in good faith must be prohibited. The company should keep a restricted case log showing the allegation, date received, risk rating, assigned reviewer, actions taken, evidence collected, and outcome. When a report arrives, preserve relevant emails, invoices, messages, contracts, and accounting entries. Separate fact-finding from assumptions, interview people fairly, and document the reasons for each decision. Consider whether a payment should be paused, whether a third party should be suspended, and whether financial records need correction. Serious matters may require independent legal or forensic assistance. Employees working abroad should receive scenario-based guidance for direct demands from officials. The resource on responding to bribe requests can help turn a general prohibition into practical steps: stay calm, decline clearly, avoid promises, record the details, leave safely where necessary, and report the incident promptly. Train Staff And Keep EvidenceTraining should be short, regular, and connected to actual decisions. New employees should receive the policy during onboarding, while higher-risk personnel should complete additional sessions on gifts, third parties, public procurement, expenses, and reporting. A short scenario about an agent asking for a “special fee” may teach more than several pages of legal terminology. Require employees to acknowledge that they received and understood the policy. Keep attendance records, completed assessments, policy acknowledgments, gift registers, due diligence files, approval forms, and investigation records in an organized location with access controls. Documentation demonstrates that the company’s procedures operate in practice, not merely on paper. Review the policy at least annually and after a major expansion, acquisition, enforcement event, regulatory change, or significant incident. Ask whether approval thresholds remain realistic, whether employees know how to report concerns, and whether third-party checks are being completed consistently. A procedure that causes constant delays may be ignored, while one that is too flexible may create uncontrolled discretion. External resources can help a company identify gaps without building a legal department. The Business Anti-Corruption Portal’s contact service provides a route for seeking further information when a company needs help locating relevant compliance material or understanding a country-specific issue. For businesses operating in Ukraine, reviewing Ukraine’s liability laws can also illustrate why corporate exposure, individual conduct, and internal controls must be considered together. Keep The Framework Proportionate And CredibleA small company should resist the temptation to promise controls it cannot operate. A concise policy with four reliable mechanisms—accurate books, third-party screening, approval controls, and protected reporting—will be stronger than an impressive document that employees never read. Each rule should have an owner, a form or record where appropriate, and a defined response when someone breaches it. Use the following actions to make the framework workable:
A credible anti-corruption policy grows with the company. Begin with the risks that could cause the greatest harm, document the controls that are actually being used, and expand the framework as new countries, contracts, employees, and partners are added. Put the policy into operation by assigning ownership, briefing staff, screening current high-risk partners, and testing one payment or approval process from start to finish. Consistent implementation will give the company a defensible compliance foundation, even without an in-house legal department. |