Global Advice Network
| Borgergade 111 | DK - 1300 Copenhagen K
|
|
|
|
Managing the compliance risks of hiring a politically exposed person as a consultantHiring a politically exposed person (PEP) as a consultant can give a company access to valuable expertise, local knowledge, and institutional relationships. It can also create serious corruption, bribery, conflicts of interest, sanctions, procurement, and reputational risks. The fact that a PEP is qualified does not make the engagement improper, but it does require a higher standard of review. A PEP may be a current or former senior public official, a political party leader, a senior executive at a state-owned enterprise, or a close family member or known associate of such an individual. Definitions vary between jurisdictions, and some laws distinguish between domestic and foreign PEPs. Companies must therefore assess the person, the proposed services, and the legal environment before signing a contract. The central compliance question is whether the consultancy has a legitimate business purpose and whether its structure could be used to influence a public decision improperly. A well-documented process should show why the person was selected, what work will be performed, how fees were calculated, and which safeguards will prevent payments from becoming disguised bribes. Why a PEP consultancy requires enhanced scrutinyA PEP appointment can expose a company to heightened bribery and corruption risk because the individual may retain influence over public officials, regulators, ministries, political parties, or state-owned businesses. Even after leaving office, a former official may continue to control access, shape decisions, or benefit from longstanding relationships. The risk may remain significant for years, depending on local law and the person’s continuing influence. The role itself can create the appearance of an improper arrangement. A vague advisory mandate, a large success fee, or a request to “open doors” can suggest that the consultant is being paid for access rather than expertise. This concern becomes stronger when the company is seeking a public contract, license, tax ruling, permit, concession, investigation outcome, or regulatory approval. Companies should also consider indirect exposure. A consultant may pass part of the fee to a family member, political organization, intermediary, or another adviser. A payment that appears commercially reasonable on paper may still create liability if the company knew, or should have known, that it would fund an improper benefit. The site disclaimer should be considered when using general country or legal information, since local advice may be necessary for a specific engagement. Assessing the person and the proposed assignmentThe first stage is a documented risk assessment. It should identify the consultant’s current and former public positions, decision-making authority, government relationships, business interests, family connections, and known associates. Screening should cover sanctions lists, politically exposed person databases, adverse media, court records, debarment lists, corporate registries, and credible investigative sources. The company should separately assess the proposed work. A consultant providing technical research, market analysis, or industry training may present a different risk profile from someone tasked with government relations or public procurement support. The assessment should explain the business need, the expected deliverables, the relevant country risks, and whether the engagement overlaps with matters in which the PEP has influence. A risk classification can help determine the approval level and control requirements. High-risk factors may include a current public office, authority over a company’s project, links to a state-owned customer, involvement in licensing or procurement, opaque ownership structures, a request for cash or offshore payment, and compensation based on the outcome of a government decision. Several moderate risks may combine to create a high-risk engagement.
The company should record both positive and negative findings. A clean database search does not prove that the relationship is safe, while a historical political role does not automatically make the person unsuitable. The decision should reflect the totality of the circumstances and be revisited if the assignment, government counterpart, or political context changes. Performing due diligence before appointmentEnhanced due diligence should begin before any promise of engagement is made. The consultant should complete a detailed questionnaire covering identity, employment history, public positions, directorships, beneficial ownership, family relationships, political affiliations, other clients, conflicts of interest, and prior allegations of misconduct. Information should be verified through independent sources rather than accepted solely on the consultant’s declaration. The company should confirm how the consultant was identified and selected. A transparent competitive process is preferable to a personal referral from a government official or business partner. If the consultant is uniquely qualified, the file should explain the specific expertise that cannot reasonably be obtained elsewhere. Procurement, compliance, and the relevant business sponsor should be able to understand the selection without relying on undocumented personal knowledge. Background checks should be proportionate but meaningful. They may include searches in local-language sources, review of corporate filings, examination of litigation and regulatory enforcement, verification of academic and professional credentials, and checks on companies owned or controlled by the consultant. Where information is difficult to obtain, the company should document the limitation and consider whether the remaining uncertainty is acceptable. Consent, privacy, and data protection rules must also be respected. PEP screening involves personal information, and companies should define who can access the records, how long they will be retained, and how inaccurate information can be challenged. A compliance process that disregards privacy obligations can create a separate legal and reputational problem. Structuring the engagement and compensationThe consultancy agreement should describe the services in precise, verifiable terms. It should identify deliverables, deadlines, reporting lines, permitted locations, restrictions on subcontracting, recordkeeping duties, and the boundaries of any contact with public officials. Terms such as “provide strategic access,” “support relationships,” or “facilitate approvals” should be avoided unless they are defined in a lawful and transparent way. Compensation should reflect the actual value of the work and be supported by an independent market benchmark. A fixed fee tied to documented deliverables is generally easier to control than a commission linked to winning a public contract or obtaining a favorable government result. Payments should be made through a bank account held in the consultant’s name in the country where the consultant resides or legitimately operates, unless a documented legal and commercial reason supports another arrangement. The contract should prohibit bribery, facilitation payments, undisclosed conflicts, political contributions made on the company’s behalf, gifts to officials, and the use of unapproved intermediaries. It should grant audit rights, require invoices and supporting records, permit verification of services, and allow suspension or termination where concerns arise. The consultant should certify that the fee will not be shared improperly and that any government contact will comply with applicable law. Special care is needed when the PEP is connected to a current customer, regulator, ministry, or state-owned enterprise. The company should consider recusal, information barriers, limits on communications, and independent review of any related bid or decision. No consultant should be allowed to influence a matter in which the person has a personal, political, or financial interest. Monitoring the relationship after onboardingDue diligence is not a one-time event. A PEP’s status, political role, relationships, or legal exposure can change during the engagement. Companies should establish periodic screening and event-driven reviews when there is a change of government, a new tender, a regulatory investigation, a change in ownership, a new payment request, or credible adverse media. The business sponsor should confirm that services are actually being delivered. Reports, meeting records, research outputs, attendance logs, and other evidence should be retained with invoices. If the consultant claims to have influenced a government decision, the company should investigate the statement rather than treat it as proof of success. Monitoring should test both the substance of the work and the way the work was performed. Controls for agents and consultants should be practical enough for business teams to use. A supervisory checklist can help managers review invoices, contacts, deliverables, approvals, and warning signs consistently. The checklist should complement, rather than replace, escalation to compliance or legal personnel. Warning signs should trigger prompt review. These include requests to alter invoices, unexplained increases in fees, payments to relatives or unrelated companies, refusal to disclose beneficial ownership, pressure to bypass procurement, unexplained government access, missing deliverables, and instructions to communicate through private channels. Depending on the facts, the company may need to pause payments, preserve records, conduct an internal investigation, report concerns, or terminate the arrangement. Building a defensible approval processA robust approval process should assign responsibilities clearly. The business sponsor explains the commercial need, procurement tests value and selection, compliance assesses corruption and PEP risks, legal reviews the contract and applicable law, and senior management accepts or rejects the residual risk. No single person should be able to select the consultant, approve the fee, verify performance, and authorize payment without independent oversight. The approval file should contain the risk assessment, screening results, source documents, conflict checks, fee analysis, scope of work, contract, approvals, training records, invoices, deliverables, and monitoring reports. It should also record any exceptions and the reasons they were accepted. Clear documentation helps demonstrate that the company acted in good faith and applied a consistent standard. Training should be tailored to the people involved. Business sponsors need to recognize indirect bribery and access-based arrangements. Accounts payable teams should understand payment red flags. Managers responsible for government interaction should know when to stop a conversation and escalate it. The consultant should receive written expectations and acknowledge the company’s anti-corruption rules. The process should fit the company’s wider compliance framework, including its code of conduct, third-party due diligence program, whistleblowing channels, gifts and hospitality rules, political engagement policy, and records management controls. Country risk profiles and local legislation guidance can help identify issues that require jurisdiction-specific advice, but they should support rather than replace professional legal analysis. Practical safeguards for decision-makersThe following measures create a proportionate control framework for engaging a PEP as an external adviser:
A company should be prepared to decline the engagement when the consultant refuses reasonable due diligence, insists on secrecy, demands an excessive fee, requests payment through another person, or cannot explain the proposed services. Commercial urgency is not a sufficient reason to weaken controls, particularly when the consultant may influence a public decision. When the relationship is approved, the company should communicate the decision and its limits to everyone involved. A carefully drafted contract will fail if employees privately promise additional payments, treat the PEP as an informal fixer, or overlook missing evidence because the person is politically influential. Consistent supervision is the practical test of whether the control framework works. Companies should review their existing consultant and intermediary portfolios for similar arrangements, including relationships that began before current PEP procedures were adopted. Legacy contracts may contain vague scopes, outdated screening, or compensation terms that would not pass current standards. A structured remediation exercise can identify which relationships need renewed due diligence, revised contracts, closer monitoring, or orderly exit. The safest approach is neither automatic exclusion nor casual acceptance. It is a risk-based process that connects legitimate commercial need with verified qualifications, transparent payments, senior accountability, and continuous oversight. Put these controls into the procurement and compliance workflow before the appointment is made, and retain evidence that each decision was considered, approved, and monitored. |