Global Advice Network
| Borgergade 111 | DK - 1300 Copenhagen K
|
|
|
|
Understanding controlling companies in anti-corruption enforcementAnti-corruption laws increasingly look beyond the legal entity that pays a bribe. They examine the corporate group, ownership structure, decision-making arrangements, and individuals who direct business activity. A company that appears separate on paper may still be treated as controlled by a parent, investor, state body, or beneficial owner for enforcement purposes. This issue matters to multinational groups, private equity investors, joint ventures, franchise networks, and companies that rely on agents or distributors. Control can create responsibility for the conduct of subsidiaries and affiliates, influence expectations for compliance oversight, and affect how regulators interpret failures in due diligence, accounting, or internal controls. The concept is rarely determined by one factor alone. Share ownership may be important, but practical authority, board appointments, contractual rights, financial dependence, and the ability to direct operations can be equally significant. Businesses therefore need a structured method for identifying control and managing the risks that follow from it. What control means in a corporate groupA controlling company is generally an entity that has the power to determine, or materially influence, another company’s management, policies, or business decisions. In many jurisdictions, control is presumed when one company owns a majority of voting rights. That presumption can also arise when a parent can appoint most directors, control shareholder votes, or determine the composition of governing bodies. Legal definitions vary across anti-bribery statutes, company law, securities regulation, and accounting standards. Some regimes focus on voting power, while others consider actual influence. A company with a 40 percent stake may exercise effective control if the remaining shares are widely dispersed and no other investor can challenge its decisions. Control may also exist without majority ownership. A long-term management agreement, veto rights over budgets, exclusive financing arrangements, or contractual authority to appoint senior executives may give one party decisive influence. The analysis should therefore examine how the relationship operates in practice rather than relying only on an organization chart. Why control matters to enforcement agenciesRegulators use corporate control to determine whether misconduct can be attributed beyond the immediate offender. A parent may face scrutiny when a subsidiary pays an improper commission, hides a facilitation payment in its books, or uses a politically connected intermediary. The parent’s exposure often depends on its knowledge, involvement, compliance program, and ability to prevent or detect the conduct. A controlling company can also create risk through weak supervision. Even when senior parent executives did not authorize a bribe, enforcement authorities may ask whether they ignored warning signs, failed to provide appropriate controls, or allowed a high-risk subsidiary to operate outside group standards. Inadequate oversight can support allegations involving books and records, internal controls, conspiracy, aiding and abetting, or failure to cooperate. The degree of responsibility is shaped by the applicable law. Some countries impose direct corporate liability for employees and representatives. Others apply an identification doctrine, requiring proof that senior managers were involved. Certain laws recognize liability for failing to prevent bribery, making the existence and operation of an effective compliance system especially important for controlling entities. Assessing ownership, influence, and practical authorityA risk assessment should begin with the formal structure. Companies should identify direct and indirect shareholders, voting arrangements, beneficial owners, board rights, subsidiaries, affiliates, joint ventures, and entities under common ownership. The review should include minority investments where special rights give an investor unusual influence over strategy or management. The next step is to test practical authority. Questions may include:
Operational dependence can be especially revealing. A subsidiary may have its own directors but rely on the parent for treasury, procurement, legal services, information technology, and third-party selection. Such arrangements can increase the parent’s ability to prevent misconduct and make regulators less receptive to claims that it had no connection to local operations.
Liability across subsidiaries and affiliatesA subsidiary is usually a separate legal person, and that separation remains relevant. A parent is not automatically liable for every act of a subsidiary merely because it owns the entity. Enforcement agencies generally examine the parent’s conduct, knowledge, authority, and failures rather than treating ownership as conclusive proof of liability. Risk rises when parent personnel participate in decisions connected to the misconduct. Examples include approving a questionable distributor, setting unrealistic sales targets, directing payments through a risky intermediary, or receiving reports about suspicious transactions without taking action. The parent may also face exposure when it consolidates financial reporting but lacks controls capable of identifying improper payments. Joint ventures and minority investments require careful calibration. A company may not have enough power to impose its full compliance program, yet it may still have rights to access records, appoint an audit committee member, review third parties, or require investigation of allegations. Those rights should be exercised consistently. A company that negotiates strong oversight powers but never uses them may create an unfavorable record. Transactions involving government-linked businesses demand additional diligence. The compliance implications of state-owned enterprise relationships are particularly important because employees of a state-owned or state-controlled entity may be treated as public officials under applicable anti-bribery laws. Ownership analysis should therefore identify state influence, public functions, procurement relationships, and politically exposed individuals. Compliance duties for controlling companiesA parent or other controlling entity should build a compliance framework that reflects the risk profile and autonomy of each business unit. A single global policy may establish a common baseline, but implementation often needs to vary by country, industry, government interaction, and third-party exposure. High-risk subsidiaries may require enhanced approval, transaction testing, and direct reporting to group compliance personnel. Governance documents should clearly assign responsibility. Board committees, general counsel, compliance officers, internal audit, finance teams, and local management need defined roles for risk assessment, training, investigations, remediation, and escalation. Ambiguous accountability can allow warning signs to circulate without anyone being responsible for acting on them. Monitoring should be proportionate but real. Useful measures include testing distributor commissions, reviewing charitable and sponsorship payments, checking unusual expense claims, screening beneficial owners, and analyzing journal entries. Parent companies should track whether subsidiaries complete training, perform due diligence, close audit findings, and discipline personnel who violate policy. Documentation is part of the control environment, not an administrative afterthought. A company should preserve the reasoning behind risk ratings, approvals, exceptions, investigations, and remediation decisions. Practical guidance on retaining compliance documentation can help groups create records that demonstrate what they knew, what they decided, and how they followed up. Managing control in complex structuresPrivate equity sponsors, investment funds, and institutional investors often hold significant influence without managing daily operations. Their risk assessment should distinguish passive investment from active control. Board representation, reserved matters, operational support, executive secondment, and integration into group systems can all increase the expectation of oversight. Franchising, licensing, and distribution arrangements create a different challenge. The principal may lack formal control over the counterparty but can still face reputational and legal risk if the relationship involves government customers, customs officials, permits, or public tenders. Contracts should address anti-bribery standards, audit rights, training, records, subcontractors, and termination. A company should also plan for changes in control. Acquisitions can bring inherited liabilities, incomplete records, weak local controls, or third parties that would not meet the buyer’s standards. Pre-acquisition diligence should examine investigations, hotline reports, commission structures, government dealings, and prior compliance certifications. Post-acquisition integration should then prioritize high-risk activities and preserve relevant evidence. When a company loses control, it should document the change and reassess its obligations. A divestment, dilution, restructuring, or governance amendment may alter legal responsibility, but it does not erase historic exposure. Records, cooperation duties, audit rights, and ongoing contractual commitments may continue after the corporate relationship changes. Building a defensible oversight programA defensible program connects ownership analysis with daily controls. It should show that the company identified where it had authority, assessed the risks created by that authority, and applied oversight that was suitable for the circumstances. Policies without evidence of implementation will carry limited weight in an investigation. Practical oversight can include quarterly risk certifications from subsidiaries, targeted audits, centralized approval for high-risk intermediaries, and escalation of government-facing transactions. Training should explain how local employees can report concerns and what happens after a report is made. The objective is to create reliable channels for information, rather than simply distribute written policies. The following actions help companies translate the concept of control into consistent compliance practice:
Senior management should review whether the organization’s stated control model matches reality. If a parent claims that a subsidiary is independent but routinely approves its payments, appoints its executives, and directs its third-party relationships, the formal description will be difficult to defend. Clear governance and accurate records reduce that inconsistency. Companies should also revisit control assessments after acquisitions, leadership changes, new government contracts, changes in ownership, and major compliance incidents. Anti-corruption exposure is dynamic, and a structure that seemed low risk at the time of investment may become much more integrated later. Understanding who controls a company is essential to understanding who must prevent, detect, and respond to corruption. Organizations that map influence carefully, supervise proportionately, and document their decisions are better positioned to manage parent-subsidiary liability and demonstrate credible compliance to regulators. Review your corporate structure, authority arrangements, and oversight records now. Use the findings to update risk assessments, strengthen group controls, and ensure that every entity with meaningful influence has a clearly defined role in preventing bribery. |