Compliance Program Guidance
Companies must create and implement anti-corruption policies and procedures to meet their legal compliance obligations and mitigate corruption risks. Corruption creates potential criminal, civil and business consequences. Implementing adequate procedures can help manage these risks while creating a competitive business advantage.
Compliance is not just common sense – it's good business sense:
|
Liability
Corruption offences are costly. Criminal and civil penalties can cost your company millions and result in tough prison sentences.
|
Opportunity
Business partners and suppliers are increasingly required to document their anti-corruption compliance programs or risk losing contracts.
|
Reputation
Your company’s reputation is its most valuable asset. Corruption investigations can harm business opportunities.
|
Blacklisting
Companies convicted of corruption offences can be excluded from bidding on contracts. The EU, the World Bank and others blacklist convicted companies.
|
Navigate the compliance steps using the icons:
Steps:
Proportionality
Your policies and procedures for preventing bribery should be proportionate to the size, nature and complexity of your business activities. This starts with the code of conduct and requires an understanding of your geographic scope, industry sector, products and services, government interactions, third-party agents and customers. Your company should implement risk assessment procedures and address specific risk areas (e.g., the judiciary and public procurement). Policies and procedures should outline responsibility for the compliance system, internal controls, auditing practices, documentation practices and disciplinary procedures. Assistance and reporting channels should be outlined. Responsibility for the overall compliance program should be assigned to a person with adequate authority, autonomy and sufficient resources to ensure effective implementations, and company policies and procedures should apply to all company personnel.
Sample Code of Conduct
Top-Level Commitment
Support from top management for your anti-corruption policies fosters a culture of integrity in which bribery is unacceptable. Demonstrating top-level commitment for preventing corruption involves internal and external communication of your policies and top management’s involvement in developing the corruption-prevention procedures. This may include top management setting prevention policies; assigning management to create, implement and monitor procedures; and keeping these under regular review. The commitment of top-management involves formalising the company's anti-corruption position in an available written document.
Sample Anti-Corruption Policy
Risk Assessment
Your company must focus most on managing the most serious corruption risks. Performing a comprehensive risk assessment identifies and weights risks that help define your priorities. An effective risk assessment involves working together with those familiar with your company’s processes and sales channels.
Sample Risk Assessment Template
|
Geographical Risks
The Portal’s country profiles are a good starting point for your country-level assessments. The information networks for each profiled country provide local contacts that can assist you in conducting your own research. This process should provide a good indication of the nature and levels of corruption in these countries, including relevant regulations.
|
Sectors and Products
Your market sector may entail a higher risk of corruption than others. Sectors dependent on large-scale government contracts or tightly controlled licences can be subject to corruption risks; companies operating in these sectors are exposed to a higher risk of their agents or subcontractors committing a corruption offense on their behalf.
|
Representatives
The less control your company has on its representatives, the higher the risk of corruption. Your risk assessments should identify current and anticipated future representatives. Different types of representatives have different risk profiles and include third-party agents, consultants and joint venture business partners.
|
|
Corruption Types
Your company should evaluate its risks for the various forms of corruption. Does your company risk encountering big-value kickback payments, or small-value bribery or facilitation payments? Does your company give gifts or donations, and could these be seen as a corrupt influence on their recipients?
|
Keep Records
Document your compliance activities, including your risk assessments. This will demonstrate your commitment to fighting corruption, facilitate potential cooperation with authorities, help establish possible legal defences, and demonstrate compliance to your business partners.
|
Define Priorities
Your risks should be evaluated for likelihood, impact and velocity. And tools can be used to help visualise your assessments to distinguish risk levels. Remember, your compliance activities should be proportionate to your risks!
|
Due Diligence
Companies risk criminal and civil liability for corruption offences committed on their behalf, including management, employees and third parties. Third parties present a higher risk because there is a lower-degree of control over third parties compared to employees. When conducting business through third parties (agents, consultants, joint ventures, etc.), you should conduct a heightened-level of scrutiny or due diligence.
Sample Due Diligence Tools
Communication & Training
Your policies and procedures should be communicated and understood throughout your company and by key stakeholders. This may include communicating with and training external stakeholders, such as suppliers and contractors. These activities should be documented to help meet your compliance demands, especially your code of conduct and anti-corruption policy. Effective communication and training may take many forms, including e-learning courses, traditional on-site training, e-mail and intranet communications, and electronic and physical policy signings.
Sample Training Procedure Template
Sample E-Learning Course
Monitoring & Review
Your anti-corruption policies and procedures should be monitored and reviewed continuously to account for changes in risks and the effectiveness of your procedures. This process should be reflected in changes being made as necessary. Access to data (such as financial records) and complaint channels and proxies (such as key performance indicators - KPIs) help you to monitor and review your policies and procedures. Evaluation findings should be reported to your top management, commonly the board of directors, who are ultimately responsible for the compliance system. Finally, your annual report should disclose the level of implementation of the compliance system to inform stakeholders.