Skip to main content
Category: Anti-Bribery and Corruption

Anti-Bribery Policy

Also known as: Anti-Bribery and Anti-Corruption Policy, ABAC Policy, Anti-Corruption Policy
Simply put

An anti-bribery policy is a company's internal document that sets out its rules against bribery and corruption, prohibiting both the giving and the receiving of bribes to gain or keep a business advantage. It typically forbids offering, promising, giving, requesting, or accepting improper payments in dealings with both government officials and private parties. Such a policy helps a business support compliance with applicable anti-bribery laws and reduce its exposure to corruption-related risk.

Formal definition

An anti-bribery policy is a formal internal governance instrument, generally adopted and overseen by the board or a designated committee and implemented by management and the compliance function, that establishes prohibited conduct, controls, and expectations relating to bribery and corruption. Policies of this type commonly prohibit the offering, promising, giving, requesting, agreeing to receive, or accepting of bribes or other improper payments across public-sector interactions (with government officials) and private-sector business dealings, and typically apply to officers, directors, and employees, with scope often extended to third parties acting on the entity's behalf. Such policies are internal standards intended to operationalize and support compliance with applicable anti-bribery and anti-corruption laws; the specific legal obligations, extraterritorial reach, and enforcement consequences vary by jurisdiction, sector, and entity type, and the precise obligations depend on the governing law and the facts. This entry is educational and not legal, audit, or compliance advice.

Why it matters

Bribery and corruption expose an organization to serious legal, financial, and reputational consequences. Because many anti-bribery regimes prohibit both the giving and the receiving of bribes to gain or retain a business advantage, an entity can face exposure whether its personnel offer improper payments or accept them. A documented anti-bribery policy is a foundational way for a business to signal that such conduct is prohibited and to help protect itself against these risks, though a policy alone does not guarantee compliance or immunize an entity from enforcement.

The risk is not confined to a single type of counterparty. Corruption exposure can arise in interactions with government officials and, in many programs, in purely private-sector business dealings as well. The prohibited conduct is typically broad, extending beyond completed payments to the offering, promising, requesting, or agreeing to receive improper benefits. This breadth means that a policy addressing only public-sector bribery may leave meaningful gaps depending on the entity's operations and the governing law.

The precise legal obligations, extraterritorial reach, and enforcement consequences vary by jurisdiction, sector, and entity type, and depend on the facts and the governing law. An anti-bribery policy is an internal standard intended to operationalize and support compliance with applicable laws; it is not a substitute for tailored legal, audit, or compliance advice.

Who it's relevant to

Boards and designated committees
The board or a committee it designates typically adopts the anti-bribery policy and holds oversight responsibility for the entity's approach to bribery and corruption risk. This is an oversight duty rather than an operational one; the board sets the tone and reviews the program without administering day-to-day controls.
Chief compliance officers and the compliance function
Compliance functions generally implement the policy through controls, training, and monitoring, and translate its prohibitions into practical procedures for personnel and third parties. They also help ensure the policy addresses the relevant counterparties, including both government officials and private-sector parties, as appropriate to the entity's operations.
General counsel and legal teams
Legal teams help ensure the internal policy supports compliance with the anti-bribery and anti-corruption laws that apply to the entity. Because obligations, extraterritorial reach, and enforcement consequences vary by jurisdiction, sector, and entity type, legal advisors assess which laws govern a given set of facts and how the policy should reflect them.
Officers, directors, and employees
Anti-bribery policies typically apply directly to officers, directors, and employees, defining the conduct expected of them in business dealings. Personnel are generally the primary audience for the policy's prohibitions and any associated training.
Internal auditors and assurance functions
Assurance functions may test whether the policy's controls are designed appropriately and operating effectively, providing independent evaluation of the anti-bribery program. This role is distinct from the compliance function that owns and implements the controls.
Third parties acting on the entity's behalf
The scope of many anti-bribery policies extends beyond the entity's own personnel to agents and other third parties acting on its behalf, since corruption risk can arise through intermediaries. Whether and how third-party obligations apply depends on the policy's stated scope and the governing law.

Inside Anti-Bribery Policy

Statement of Prohibited Conduct
A clear articulation of what the policy prohibits, typically covering the offering, promising, giving, requesting, or accepting of bribes involving both public officials and private parties. The precise scope of prohibited conduct depends on the applicable anti-bribery and anti-corruption laws in the jurisdictions where the entity operates.
Scope and Applicability
A definition of who is bound by the policy, which commonly extends to directors, officers, employees, and in many cases third parties acting on the entity's behalf such as agents, intermediaries, and business partners. The extent of third-party coverage generally reflects the enforcement risk associated with the relevant laws.
Facilitation Payments and Gifts/Hospitality Provisions
Guidance on the entity's position toward facilitation payments and toward the giving or receiving of gifts, hospitality, and entertainment. Treatment varies because some legal regimes prohibit facilitation payments outright while others provide limited exceptions; the policy should state the entity's chosen standard rather than assume a universal rule.
Roles, Responsibilities, and Governance
Allocation of accountability across the board (or a relevant committee) for oversight, senior management for implementation and setting tone, and the compliance function for administering, monitoring, and advising on the policy. These are distinct functions and the policy should not conflate oversight duties with operational ownership.
Risk Assessment Linkage
A connection to the entity's bribery and corruption risk assessment, which typically informs where controls are focused based on factors such as geography, sector, transaction type, and use of third parties. This links the policy to the broader risk management process rather than treating it as a standalone document.
Reporting Channels and Non-Retaliation
Mechanisms for raising concerns, including confidential or anonymous reporting where permitted, together with a commitment against retaliation for good-faith reports. Available channels and protections generally depend on jurisdictional requirements and the entity's own arrangements.
Training, Communication, and Certification
Provisions for communicating the policy, delivering training to relevant personnel, and in some cases obtaining periodic acknowledgment or certification of compliance.
Consequences and Enforcement
A statement that breaches may result in disciplinary action and, potentially, legal consequences, reinforcing that the policy is intended to be applied consistently.

Common questions

Answers to the questions practitioners most commonly ask about Anti-Bribery Policy.

Does having an anti-bribery policy on paper mean an organization is protected from bribery-related liability?
No. A written policy is generally only one component of an anti-bribery program, not a defense in itself. Under many anti-bribery regimes, enforcement authorities and courts typically look for evidence that a program is operating effectively in practice, through risk assessment, training, monitoring, due diligence on third parties, and enforcement of consequences, rather than merely documented. A policy that exists but is not embedded, tested, or applied is sometimes described as a 'paper program' and may carry limited weight. Whether any given program mitigates liability depends on the applicable law, jurisdiction, and specific facts, and this entry is educational rather than legal advice.
Is an anti-bribery policy only relevant to interactions with government or public officials?
Not necessarily. While some statutes focus primarily on the bribery of foreign or domestic public officials, other regimes address commercial (private-to-private) bribery as well. The scope of prohibited conduct depends on the specific laws that apply to the entity, its sector, and the jurisdictions in which it operates. Many organizations therefore design policies that address both public and private bribery to account for the range of laws they may be subject to. Organizations generally should confirm the reach of the particular regimes applicable to them rather than assume coverage is limited to dealings with officials.
Who within an organization typically owns and oversees the anti-bribery policy?
Accountability is generally distributed across roles rather than held by any single function. The board, or a designated committee such as audit or a dedicated risk or ethics committee, typically holds oversight responsibility and sets the tone from the top. Management, often the compliance function under a chief compliance officer, working with legal, usually owns the design, implementation, and day-to-day operation of the policy. Business units generally bear first-line responsibility for applying controls in their activities, while internal audit or another assurance function may independently evaluate whether the program is designed and operating effectively. The precise allocation varies by entity type, size, and governance structure.
How should an organization approach third parties and intermediaries under an anti-bribery policy?
Third parties such as agents, distributors, consultants, and joint-venture partners are commonly treated as a significant bribery risk area because conduct by an intermediary may create exposure for the organization under some regimes. Programs typically address this through risk-based due diligence proportionate to the relationship, contractual provisions (for example, representations, audit rights, and termination clauses), and ongoing monitoring. The depth of diligence generally scales to factors such as the country risk, the nature of the engagement, and the third party's interaction with officials. Specific requirements depend on applicable law and are a matter for the organization's own judgment and professional advice.
What practical elements are commonly included to make an anti-bribery policy operational rather than merely documented?
Beyond the policy statement itself, organizations frequently include a risk assessment to identify where bribery exposure is greatest; role-appropriate training and communication; clear guidance on higher-risk areas such as gifts, hospitality, facilitation payments, charitable and political contributions, and third-party dealings; defined approval and record-keeping requirements; a reporting or whistleblowing channel with protection against retaliation; and mechanisms for investigation and consistent enforcement of consequences. Periodic review and testing help confirm the controls remain relevant. The appropriate mix depends on the organization's risk profile, sector, and applicable frameworks.
How can an organization assess whether its anti-bribery policy is working effectively?
Assessment generally distinguishes between whether controls are well designed and whether they operate effectively over time. Common approaches include periodic risk reassessment, monitoring of transactions and higher-risk categories such as gifts and hospitality, tracking of training completion and awareness, review of third-party due diligence, analysis of reports received through whistleblowing channels, and independent evaluation by internal audit or an assurance function. Findings typically feed back into policy updates and remediation. Effectiveness is a matter of ongoing evaluation and professional judgment, and metrics should be interpreted in the context of the organization's specific circumstances rather than treated as definitive proof of compliance.

Common misconceptions

Having a written anti-bribery policy is sufficient to demonstrate compliance and manage the risk.
A policy is only one component of an anti-bribery program. Under many frameworks and enforcement approaches, the effectiveness of controls in operation, ongoing risk assessment, training, monitoring, and enforcement matter alongside the document itself. Control design without evidence of operating effectiveness is generally not treated as adequate.
The board is responsible for implementing and administering the anti-bribery policy day to day.
The board or a designated committee typically holds an oversight role, while implementation, administration, and monitoring generally sit with management and the compliance function. Attributing operational execution to the board, or oversight to management, misstates how accountability is usually allocated.
One anti-bribery policy will satisfy legal requirements everywhere the entity operates.
Anti-bribery and anti-corruption obligations vary by jurisdiction, sector, and entity type, including differing treatment of facilitation payments and third-party conduct. A policy generally needs to reflect the specific requirements applicable to the entity rather than assume a single universal standard.

Best practices

Ground the policy in a documented bribery and corruption risk assessment so that controls and coverage are proportionate to the entity's actual exposure across geographies, sectors, and third-party relationships.
Clearly delineate roles so that board or committee oversight, management implementation, and compliance function administration are distinct and each is held accountable for its own responsibilities.
State the entity's specific position on facilitation payments, gifts, and hospitality rather than relying on general language, and confirm that position against the requirements of each relevant jurisdiction.
Extend the policy to relevant third parties acting on the entity's behalf and support this with appropriate due diligence and contractual measures where warranted by the risk.
Maintain confidential reporting channels with non-retaliation protections, and periodically test whether the policy's controls are operating effectively, not merely well designed.
Reinforce the policy with targeted training, periodic communication, and, where appropriate, acknowledgment or certification, and treat entries and provisions as educational rather than a substitute for legal, audit, or compliance advice.