Compliance Program Guidance

Companies must create and implement anti-corruption policies and procedures to meet their legal compliance obligations and mitigate corruption risks. Corruption creates potential criminal, civil and business consequences. Implementing adequate procedures can help manage these risks while creating a competitive business advantage.

Compliance is not just common sense – it's good business sense:

Liability

Corruption offences are costly. Criminal and civil penalties can cost your company millions and result in tough prison sentences.

Opportunity

Business partners and suppliers are increasingly required to document their anti-corruption compliance programs or risk losing contracts.

Reputation

Your company’s reputation is its most valuable asset. Corruption investigations can harm business opportunities.

Blacklisting

Companies convicted of corruption offences can be excluded from bidding on contracts. The EU, the World Bank and others blacklist convicted companies.

Navigate the compliance steps using the icons:

Compliance System Proportional Procedures

Compliance System Top-Level Commitment

Compliance System Risk Assessment

Your company's policies and procedures must be proportionate your individual corruption risks. Your company's top management should show visible support for the company's compliance activities. Your company should perform periodic assessments of its internal and external risks.
Compliance System Due Diligence Compliance System Communication & Training Compliance System Monitoring & Review
You should take a risk-based approach before engaging others to represent your company. Your company's policies and procedures must be communicated and understood. Your company should continuously track its risks and review its policies and procedures for effectiveness.

Steps:

Proportionality

Your policies and procedures for preventing bribery should be proportionate to the size, nature and complexity of your business activities. This starts with the code of conduct and requires an understanding of your geographic scope, industry sector, products and services, government interactions, third-party agents and customers. Your company should implement risk assessment procedures and address specific risk areas (e.g., the judiciary and public procurement). Policies and procedures should outline responsibility for the compliance system, internal controls, auditing practices, documentation practices and disciplinary procedures. Assistance and reporting channels should be outlined. Responsibility for the overall compliance program should be assigned to a person with adequate authority, autonomy and sufficient resources to ensure effective implementations, and company policies and procedures should apply to all company personnel.

Sample Code of Conduct

Top-Level Commitment

Support from top management for your anti-corruption policies fosters a culture of integrity in which bribery is unacceptable. Demonstrating top-level commitment for preventing corruption involves internal and external communication of your policies and top management’s involvement in developing the corruption-prevention procedures. This may include top management setting prevention policies; assigning management to create, implement and monitor procedures; and keeping these under regular review. The commitment of top-management involves formalising the company's anti-corruption position in an available written document.

Sample Anti-Corruption Policy

Risk Assessment

Your company must focus most on managing the most serious corruption risks. Performing a comprehensive risk assessment identifies and weights risks that help define your priorities. An effective risk assessment involves working together with those familiar with your company’s processes and sales channels.

Sample Risk Assessment Template

Geographical Risks

The Portal’s country profiles are a good starting point for your country-level assessments. The information networks for each profiled country provide local contacts that can assist you in conducting your own research. This process should provide a good indication of the nature and levels of corruption in these countries, including relevant regulations.

Sectors and Products

Your market sector may entail a higher risk of corruption than others. Sectors dependent on large-scale government contracts or tightly controlled licences can be subject to corruption risks; companies operating in these sectors are exposed to a higher risk of their agents or subcontractors committing a corruption offense on their behalf.

Representatives

The less control your company has on its representatives, the higher the risk of corruption. Your risk assessments should identify current and anticipated future representatives. Different types of representatives have different risk profiles and include third-party agents, consultants and joint venture business partners.

Corruption Types

Your company should evaluate its risks for the various forms of corruption. Does your company risk encountering big-value kickback payments, or small-value bribery or facilitation payments? Does your company give gifts or donations, and could these be seen as a corrupt influence on their recipients?

Keep Records

Document your compliance activities, including your risk assessments. This will demonstrate your commitment to fighting corruption, facilitate potential cooperation with authorities, help establish possible legal defences, and demonstrate compliance to your business partners.

Define Priorities

Your risks should be evaluated for likelihood, impact and velocity. And tools can be used to help visualise your assessments to distinguish risk levels. Remember, your compliance activities should be proportionate to your risks!

Due Diligence

Companies risk criminal and civil liability for corruption offences committed on their behalf, including management, employees and third parties. Third parties present a higher risk because there is a lower-degree of control over third parties compared to employees. When conducting business through third parties (agents, consultants, joint ventures, etc.), you should conduct a heightened-level of scrutiny or due diligence.

Sample Due Diligence Tools

Communication & Training

Your policies and procedures should be communicated and understood throughout your company and by key stakeholders. This may include communicating with and training external stakeholders, such as suppliers and contractors. These activities should be documented to help meet your compliance demands, especially your code of conduct and anti-corruption policy. Effective communication and training may take many forms, including e-learning courses, traditional on-site training, e-mail and intranet communications, and electronic and physical policy signings.

Sample Training Procedure Template
Sample E-Learning Course

Monitoring & Review

Your anti-corruption policies and procedures should be monitored and reviewed continuously to account for changes in risks and the effectiveness of your procedures. This process should be reflected in changes being made as necessary. Access to data (such as financial records) and complaint channels and proxies (such as key performance indicators - KPIs) help you to monitor and review your policies and procedures. Evaluation findings should be reported to your top management, commonly the board of directors, who are ultimately responsible for the compliance system. Finally, your annual report should disclose the level of implementation of the compliance system to inform stakeholders.