Skip to main content
Category: Anti-Bribery and Corruption

Anti-Corruption Monitoring and Review

Also known as: Anti-Bribery and Corruption Monitoring and Review, ABC Monitoring and Review, Monitoring and Reviewing Anti-Corruption Procedures
Simply put

Anti-corruption monitoring and review is the ongoing process an organisation uses to check whether its measures for preventing and detecting bribery and corruption are actually working, and to update them when needed. It involves gathering information about how controls operate day to day and periodically stepping back to evaluate whether the overall programme remains effective. This is one component of a broader anti-corruption framework of laws, policies, controls, and business practices, and specific expectations vary by jurisdiction, sector, and entity type.

Formal definition

Anti-corruption monitoring and review refers to the activities by which an organisation tracks the operation of its anti-bribery and corruption (ABC) procedures and periodically evaluates their continued adequacy and effectiveness. In practice it spans two distinct roles: first-line monitoring, in which operational management embeds and checks controls within business processes it owns; and second-line oversight, in which risk and compliance functions independently assess, challenge, and report on control design and operating effectiveness. Under the Three Lines Model these are separate responsibilities, and independent assurance (for example, internal audit as a third-line function) is distinct again. Monitoring typically produces evidence on whether controls are designed appropriately and operating as intended, while review (often periodic) evaluates whether the programme should be revised in light of changes in risk, business activity, regulation, or identified deficiencies. The scope, frequency, and formality of these activities generally depend on the organisation's assessed corruption risk, applicable legal requirements and non-binding guidance in the relevant jurisdictions, and the professional judgement of those responsible. This entry is educational and does not constitute legal, audit, or compliance advice.

Why it matters

Anti-corruption controls are only as valuable as their real-world performance. A policy that exists on paper but is not embedded, understood, or enforced offers little protection against bribery and corruption risk, and may create a false sense of assurance. Monitoring and review are the mechanisms by which an organisation gathers evidence about whether its procedures are actually operating as intended and remain fit for purpose as the business, its risk profile, and the regulatory environment change over time.

Corruption risk is not static. New markets, third-party relationships, acquisitions, product lines, or changes in law can shift where exposure sits, and controls designed for one set of circumstances may become inadequate. Periodic review allows an organisation to identify these gaps and revise its programme before deficiencies become failures. Many anti-corruption regimes and non-binding guidance frameworks treat ongoing monitoring and periodic review as an expected feature of a credible compliance programme, though the specific expectations vary by jurisdiction, sector, and entity type.

Monitoring and review also support accountability and evidence. When an organisation can demonstrate that it tracked how its controls operated, evaluated their effectiveness, and acted on identified weaknesses, it is better positioned to show that its anti-corruption framework was more than a formality. This entry is educational and does not constitute legal, audit, or compliance advice; whether any particular monitoring approach meets applicable requirements depends on the facts, the relevant jurisdictions, and professional judgement.

Who it's relevant to

Boards and board committees
Boards and relevant committees generally hold an oversight role in relation to the anti-corruption programme rather than an operational one. Monitoring and review outputs provide the information they need to satisfy themselves that management has designed and is operating adequate procedures and is acting on identified deficiencies. The board typically sets the tone and seeks assurance; it does not usually perform monitoring itself.
Operational management (first line)
Management owns the business processes in which anti-corruption controls are embedded, and is responsible for first-line monitoring, checking that controls within its own areas are in place and functioning day to day. This is distinct from the independent oversight performed by risk and compliance functions.
Compliance and risk functions (second line)
Risk and compliance functions typically provide second-line oversight, independently assessing and challenging the design and operating effectiveness of anti-corruption controls and reporting on them. They often coordinate periodic review of the programme's continued adequacy, though the extent of their remit varies by organisation, jurisdiction, and entity type.
Internal audit and assurance providers (third line)
Internal audit, acting as a third-line function, provides independent assurance over the anti-corruption framework, including the monitoring and review activities carried out by the first and second lines. This assurance role is distinct from the monitoring performed by management and the oversight performed by compliance and risk.
General counsel and legal advisers
Legal advisers help interpret how applicable anti-corruption laws and non-binding guidance across relevant jurisdictions bear on the design and evaluation of monitoring and review. Because requirements vary by jurisdiction, sector, and entity type, legal input is often central to determining what a credible programme should include, though specific determinations depend on the facts and professional judgement.

Inside Anti-Corruption Monitoring and Review

First-line monitoring (management)
Ongoing, embedded checks performed by operational management and process owners who own and manage anti-corruption risks day to day. Under the widely used Three Lines Model, this first-line activity typically includes transaction reviews, due diligence checks on third parties, gift and hospitality approvals, and controls over facilitation payments, executed as part of running the business.
Second-line oversight (compliance/risk)
Independent oversight, challenge, and coordination provided by the compliance and risk functions. In the second line, these functions typically design the anti-corruption program framework, set monitoring standards, aggregate results, escalate issues, and report on the effectiveness of controls, without owning the underlying operational activities.
Third-line assurance (internal audit)
Objective assurance over the design and operating effectiveness of anti-corruption controls, typically delivered by internal audit reporting functionally to the audit committee. This line does not manage or oversee the program operationally; it provides independent evaluation.
Board and committee oversight
The board, often through an audit or risk committee, generally holds a non-delegable duty to oversee the adequacy of the anti-corruption program and the tone at the top. Oversight is distinct from the operational execution owned by management.
Control design vs. operating effectiveness
Monitoring and review typically assess both whether controls are appropriately designed to address bribery and corruption risk and whether they operate effectively over time. These are separate evaluations and should not be treated as interchangeable.
Inherent vs. residual risk assessment
Reviews generally consider inherent corruption risk (before controls) and residual risk (after controls), informing where monitoring resources are concentrated, such as high-risk jurisdictions, sectors, or intermediary relationships.
Third-party and intermediary review
A common focus area given that corruption risk frequently arises through agents, distributors, and consultants; typically includes risk-based due diligence, contractual controls, and periodic re-screening.
Metrics, testing, and reporting
Structured indicators, sample-based testing, and periodic reporting used to evidence that the program functions as intended and to support escalation of exceptions to appropriate governance bodies.

Common questions

Answers to the questions practitioners most commonly ask about Anti-Corruption Monitoring and Review.

Is anti-corruption monitoring the same thing as an internal audit of the anti-corruption program?
No. These are related but distinct activities owned by different functions, and conflating them obscures where accountability sits. Ongoing anti-corruption monitoring is typically embedded in day-to-day operations by the business (first line) and overseen by the compliance function (second line), which designs monitoring routines, tracks metrics, and reviews control performance on a continuous or periodic basis. Internal audit, as a third-line assurance function, provides independent and objective evaluation of whether the anti-corruption controls and the monitoring activities themselves are designed appropriately and operating effectively. In other words, second-line monitoring is part of running and overseeing the program, while third-line auditing assures stakeholders about that program from a position of organizational independence. The precise allocation of these responsibilities varies by entity size, sector, and structure, and smaller organizations may combine roles; this entry is educational and not a substitute for tailored professional advice.
Does having an anti-corruption monitoring and review process guarantee compliance with applicable anti-bribery laws?
No. Monitoring and review are components of a program that may support compliance, but they do not by themselves establish it, and no framework or process guarantees a compliant outcome. Anti-bribery and anti-corruption obligations arise from binding law that varies by jurisdiction and can turn on specific facts, conduct, and enforcement discretion. Voluntary frameworks and guidance may inform what a monitoring program looks like, but adopting them is generally not itself a legal requirement and does not immunize an organization from liability. Monitoring is best understood as a mechanism to detect issues, test control effectiveness, and inform improvement rather than a compliance certification. Whether a program meets legal expectations in a given jurisdiction is a matter for qualified legal counsel; this entry does not provide legal, audit, or compliance advice.
What is typically monitored under an anti-corruption program?
The specific scope depends on the organization's risk profile, sector, and geographic footprint, but monitoring commonly covers areas identified as higher risk in the underlying risk assessment. These often include third-party and intermediary relationships, gifts, hospitality and entertainment, charitable and political contributions, facilitation payments where relevant, sponsorships, and interactions with government officials or state-owned entities. Monitoring may also track completion of due diligence, training, and certifications, as well as exceptions or overrides to established controls. What is in scope should be driven by where the greatest inherent corruption risk lies and by the effectiveness of existing controls, and it should be documented so that coverage and rationale are clear. This is a general description; the appropriate scope for any organization requires its own facts and judgment.
How do organizations distinguish control design from operating effectiveness when reviewing anti-corruption controls?
These are two separate questions that reviews should address distinctly. Assessing control design asks whether a control, if it operates as intended, would be capable of preventing or detecting the corruption risk it is meant to address; a poorly designed control cannot be effective no matter how consistently it is performed. Assessing operating effectiveness asks whether the control actually functioned as designed over the relevant period, typically evidenced through testing, sampling, or review of records. A control can be well designed but fail in operation, or operate consistently yet be poorly designed for the risk. Monitoring by the compliance function and independent testing by assurance functions both generally consider these dimensions separately, because remediation differs depending on which is deficient. How this is applied depends on the organization's methodology and the judgment of the professionals involved.
How often should anti-corruption monitoring and review be performed?
There is generally no single mandated frequency; the appropriate cadence depends on the organization's risk profile, the nature of the control being monitored, and any applicable expectations in the relevant jurisdiction or sector. Higher-risk areas, such as certain third-party relationships or operations in higher-risk markets, are typically subject to more frequent or continuous monitoring, while lower-risk areas may be reviewed periodically. Some monitoring is embedded and ongoing in first-line operations, whereas broader program reviews and independent assurance activities may occur on a defined cycle. Frequency should be risk-based and revisited when circumstances change, such as after a significant incident, acquisition, or shift in regulatory expectations. The right frequency is ultimately a matter of professional judgment informed by the organization's specific facts.
Who receives the results of anti-corruption monitoring, and what is the board's role?
Reporting lines depend on the organization's governance structure, but a general pattern separates management's operational responsibilities from the board's oversight duty. Monitoring results are typically consolidated and analyzed by the compliance function, which reports to senior management and, on a periodic basis, to the board or a designated committee such as an audit or risk committee. Management is generally responsible for acting on findings, remediating deficiencies, and operating the controls, while the board's role is oversight: satisfying itself that a credible program exists, that risks are being identified and addressed, and that it receives sufficient, candid information to exercise that oversight. Independent assurance from the third line may report to the board or committee to reinforce objectivity. The board generally does not perform the monitoring itself. Exact arrangements vary by jurisdiction, listing status, and entity type, and this description is educational rather than prescriptive.

Common misconceptions

Anti-corruption monitoring is a second-line, management-owned activity.
Under the widely accepted Three Lines Model, management is the first line and owns day-to-day monitoring of the controls it operates. Compliance and risk sit in the second line, providing independent oversight and challenge. Conflating these lines misattributes accountability.
A single global framework or statute makes anti-corruption monitoring uniformly mandatory in the same form everywhere.
Legal requirements and expectations vary by jurisdiction, sector, and entity type. Some regimes impose binding obligations while others rely on guidance or codes reflecting best practice. Whether, how, and to what extent monitoring is required depends on the applicable legal framework and the facts.
Testing that controls exist confirms the program is effective.
Confirming control design is not the same as testing operating effectiveness. A control can be well designed yet fail in practice, so monitoring generally needs to evaluate whether controls actually operate as intended over a period.

Best practices

Clarify accountability using the Three Lines Model: assign day-to-day monitoring to first-line management, oversight and program design to second-line compliance/risk, and independent assurance to internal audit, and document who owns each activity.
Adopt a risk-based approach that distinguishes inherent from residual risk and concentrates monitoring on higher-risk areas such as third-party intermediaries, high-risk jurisdictions, and transactions involving public officials.
Assess both control design and operating effectiveness rather than confirming only that a control exists, using sample-based testing and clear evidence to support conclusions.
Confirm that the applicable legal and regulatory requirements are identified for each relevant jurisdiction and entity type, distinguishing binding obligations from voluntary guidance, and update monitoring scope as those requirements change.
Establish clear escalation and reporting paths so that exceptions and material issues reach the appropriate governance body, with the board or a relevant committee positioned to oversee program adequacy without assuming operational duties.
Treat findings as inputs to continuous improvement by feeding monitoring and review results back into risk assessments, control updates, and training, and by tracking remediation to completion.