Global Advice Network | Borgergade 111 | DK - 1300 Copenhagen K
E-Mail: info@business-anti-corruption.org | Phone: (+45) 60 88 10 44

Managing Compliance When Laws Pull in Different Directions

Operating across borders can expose a company to several legal systems at once. A payment, gift, data transfer, hiring decision, or interaction with a public official may be permitted in the country where it occurs but restricted by the company’s home jurisdiction. The reverse can also happen: local rules may require conduct that creates risk under an extraterritorial anti-bribery, sanctions, accounting, or export-control regime.

Managing compliance when a country’s laws conflict with your home jurisdiction requires more than selecting whichever rule is less demanding. Companies need to identify the applicable obligations, understand where they overlap, document the reasoning behind decisions, and establish controls that employees and business partners can follow in practice.

A sound program also recognizes that legal analysis depends on facts. Ownership structures, the status of an official, the source of funds, the role of an intermediary, and the purpose of a payment can change the risk assessment. Country research, specialist advice, and well-maintained internal records are essential parts of responsible cross-border operations.

Identify The Legal Conflict Early

The first step is to describe the conflict precisely. “Local practice” is not a legal category, and “head office policy” may contain several different standards. Determine whether the issue concerns a direct contradiction, a stricter home-country prohibition, an obligation imposed by local law, or uncertainty caused by incomplete information.

For example, a host country might allow modest hospitality for government officials while the company’s home law prohibits anything intended to influence an official decision. A local regulation could require records to remain within the country, while privacy rules in the home jurisdiction restrict international transfers. An employment rule may require a benefit that creates tax, accounting, or sanctions concerns elsewhere.

Create a short legal conflict memorandum for each material issue. It should identify the countries involved, the relevant laws, the transaction or conduct at issue, the people responsible, and the potential consequences. The Business Anti-Corruption Portal can support initial country research through its risk profiles, legislation guidance, training resources, and compliance vocabulary.

Do not treat a conflict as resolved merely because local counsel says the conduct is customary. Custom, administrative tolerance, written law, regulator guidance, and court precedent have different weight. The compliance team should preserve the source of each conclusion and record any assumptions that could later change.

Map Exposure Across Jurisdictions

A company should map the legal connections that may bring a transaction within the reach of more than one jurisdiction. Relevant connections can include incorporation, listing, banking, employees, subsidiaries, agents, servers, investors, government contracts, and the citizenship or location of individuals involved.

This analysis is especially important for anti-bribery and corruption risks. A payment made by a foreign subsidiary may still create exposure for a parent company if the parent knew, approved, ignored, or failed to supervise the conduct. Third-party activity can also create liability when an intermediary acts for the company and the surrounding facts suggest that warning signs were overlooked.

Build a jurisdiction matrix that compares the main requirements rather than placing laws in separate files. It should cover prohibited conduct, facilitation payments, gifts and hospitality, charitable contributions, political activity, books and records, reporting duties, privacy, sanctions, whistleblower protection, and cooperation with authorities.

Risk area Host-country question Home-jurisdiction question Practical response
Gifts and hospitality What benefits are lawful and customary? Is the benefit prohibited regardless of local custom? Apply the stricter approval threshold and document purpose, value, and recipient
Facilitation payments Are small payments tolerated or recognized in law? Are they prohibited by anti-bribery rules or company policy? Prohibit them unless a genuine emergency and formal exception process applies
Data transfers Must records remain locally or follow specific consent rules? Can personal or investigative data be transferred abroad? Use approved transfer mechanisms, access controls, and local retention procedures
Third parties Are agents licensed or commonly used? Could their conduct expose the parent or listed company? Conduct risk-based due diligence, contract controls, training, and monitoring
Reporting and investigations Are there secrecy, labor, or notification requirements? Are disclosure, preservation, or cooperation duties triggered? Coordinate local counsel, privacy specialists, investigators, and senior management

The matrix should distinguish legal obligations from internal standards. A company may voluntarily ban conduct that local law permits because the practice creates unacceptable reputational, accounting, or enforcement risk. That decision is legitimate, but employees should be told that the restriction comes from company policy as well as, or instead of, legislation.

Apply The Highest Defensible Standard

When requirements conflict, companies commonly use a “highest applicable standard” approach. This means applying the rule that offers the strongest protection against corruption, fraud, sanctions violations, conflicts of interest, or inaccurate records, unless doing so would itself violate a mandatory local requirement.

The approach should not be mechanical. A stricter home policy cannot authorize the company to ignore host-country employment, privacy, tax, licensing, or reporting duties. If a local law requires a disclosure or restricts an investigation method, the organization may need a specially designed process rather than a simple refusal to comply.

Escalation is appropriate when the conflict affects a government contract, regulated activity, sensitive personal data, national security, customs, or a payment involving a public official. Legal counsel should assess whether a lawful alternative exists, such as changing the payment route, using a different service provider, limiting data access, obtaining a permit, or restructuring the transaction.

Anti-bribery standards also need careful treatment. The United States Foreign Corrupt Practices Act and the United Kingdom Bribery Act are not identical, and a payment that seems defensible under one narrow exception may remain risky under another. Guidance on lobbying expense rules illustrates why companies should examine the legal status and purpose of a cost rather than rely on its label.

Build Controls Around Real Decisions

A policy is useful only when it helps an employee make a decision under time pressure. Translate legal analysis into practical controls: approval thresholds, prohibited categories, required documents, escalation contacts, payment restrictions, and examples that reflect local business conditions.

Controls should be proportionate to risk. A low-value commercial hospitality expense may require a standard register entry, while an interaction involving a procurement official, customs officer, state-owned enterprise, or politically exposed person may require prior legal approval. The same approach applies to donations, sponsorships, charitable projects, internships, discounts, and emergency payments.

Third-party controls deserve particular attention because an intermediary can create a conflict between local commercial expectations and home-country compliance requirements. Before engagement, assess ownership, qualifications, government connections, compensation, services, payment accounts, and the business rationale. Contracts should include audit rights, accurate invoicing requirements, anti-corruption commitments, training obligations, and termination rights.

Training must explain why a rule exists and what to do when a local manager says that “everyone does it.” Employees need a safe channel for seeking guidance, a clear non-retaliation commitment, and an emergency process for situations involving threats to health or safety. Genuine emergencies should be narrowly defined and reviewed after the event.

Make Judgments Traceable

A defensible compliance program shows how a decision was made. Keep records of due diligence, approvals, legal advice, risk assessments, invoices, correspondence, monitoring results, and remediation. Records should be sufficiently detailed for an independent reviewer to understand the facts available at the time.

Documentation is particularly important where the company decides to permit an activity that would normally be restricted. The file should state the local legal requirement or business necessity, the alternatives considered, the controls imposed, the approving authority, and the duration of the exception. An exception should expire or be reconsidered when the facts change.

Accounting controls are a core part of this process. A legitimate expense can still create risk if it is recorded inaccurately, split into smaller payments, described vaguely, or charged to an unrelated budget. Finance teams should be able to identify unusual vendors, round-dollar payments, urgent requests, duplicate invoices, cash transactions, and expenses lacking a clear business purpose.

Investigations should be coordinated across legal, compliance, internal audit, human resources, privacy, and information security functions. Preserve relevant material lawfully, limit access to sensitive data, avoid promises about confidentiality that cannot be kept, and determine whether local reporting or cooperation duties apply.

Give Teams And Partners Clear Boundaries

Local teams often face the practical pressure created by conflicting legal systems. Headquarters may issue a broad prohibition without explaining how it applies to a customs clearance, licensing meeting, community project, or state-owned customer. Local staff may then improvise, creating inconsistent decisions and hidden risk.

Assign responsibility through a clear governance model. Country managers can identify operational facts, compliance officers can assess policy implications, legal counsel can interpret the law, and senior management can approve significant residual risk. No individual should be expected to resolve a cross-border conflict without access to the right expertise.

Communication should be adapted to language, role, and local conditions. Short scenario-based training is usually more effective than a general lecture. Explain prohibited payments, acceptable hospitality, escalation routes, recordkeeping, retaliation protections, and how to respond when a partner requests an unusual commission or reimbursement.

Business partners should receive the same practical message. Include compliance expectations in onboarding, require certification where appropriate, and monitor higher-risk relationships after appointment. A signed clause is not a substitute for reviewing invoices, checking services delivered, testing payment patterns, and responding to warning signs.

Maintain A Living Cross-Border Program

Laws and enforcement priorities change, and a company’s risk can change even faster. New ownership, expansion into a regulated sector, a government tender, an acquisition, a whistleblower report, or a change in banking arrangements may require the jurisdiction matrix and controls to be reassessed.

Set review triggers rather than relying only on an annual calendar. Revisit policies after a significant legal development, enforcement action, internal investigation, acquisition, or change in the company’s use of agents. Country risk profiles should be refreshed periodically, but local management should also report emerging practices and pressure points throughout the year.

Use monitoring to test whether controls work in reality. Review samples of gifts, hospitality, charitable payments, commissions, customs expenses, and high-risk vendors. Compare policy requirements with payment data, approval records, and employee concerns. A control that produces repeated exceptions may be poorly designed, misunderstood, or deliberately bypassed.

Practical priorities for the next review cycle include:

  • Create a jurisdiction matrix for anti-bribery, privacy, sanctions, employment, tax, and reporting obligations.
  • Establish a documented escalation route for conflicts involving officials, sensitive data, or mandatory local conduct.
  • Apply risk-based due diligence and ongoing monitoring to agents, distributors, consultants, and other intermediaries.
  • Align accounting controls with compliance policies so that lawful expenses are also recorded accurately.
  • Test employee understanding through realistic scenarios and track whether guidance is reaching local teams.

A cross-border compliance program is strongest when it combines legal precision with operational clarity. The goal is not to eliminate every difference between jurisdictions, which is rarely possible, but to ensure that the company recognizes those differences, chooses a defensible course, and can explain its decision later.

Review the countries, transactions, and third parties that create the greatest tension between local requirements and home-country standards. Then convert the findings into documented procedures, targeted training, and measurable oversight so that responsible compliance becomes part of daily business rather than an emergency response.

copyright © Global Advice Network