Answers to the questions practitioners most commonly ask about Bribery and Corruption Fraud.
Is bribery and corruption only a concern for companies operating in high-risk foreign markets?
No. While cross-border operations, use of third-party intermediaries, and certain sectors and geographies typically elevate exposure, bribery and corruption risk can arise in domestic dealings as well, including interactions with public officials, procurement, licensing, and even commercial (private-to-private) relationships. The relevance of foreign versus domestic conduct depends on the applicable laws, which vary by jurisdiction. Some anti-bribery regimes reach conduct extraterritorially and cover both public and commercial bribery, while others are narrower. Organizations generally assess exposure based on their own facts, markets, counterparties, transaction types, and regulatory footprint, rather than assuming risk is confined to particular regions. This entry is educational and not legal advice; scoping should reflect the specific laws that apply to the entity.
Does bribery require an actual cash payment or a completed transaction to be a problem?
Not necessarily. Under many anti-bribery regimes, the offer, promise, or authorization of an improper advantage can be sufficient, regardless of whether a payment is ultimately made or the intended benefit is obtained. The advantage in question is also not limited to cash; depending on the applicable law, it may include gifts, hospitality, travel, employment, charitable or political contributions, or other things of value used to improperly influence a decision. Because definitions, thresholds, and available defenses differ across jurisdictions and frameworks, whether particular conduct crosses a legal line is a fact-specific determination. This entry describes general concepts and is not a substitute for legal analysis of a specific matter.
Which function should own the anti-bribery and corruption program, and where does oversight sit?
Accountability typically differentiates by line. Management generally owns the design and operation of anti-bribery controls, policies, due diligence, approvals, training, and monitoring, as a first- and second-line responsibility, with the compliance function often coordinating the program and providing second-line challenge. Internal audit, as a third-line assurance function, typically evaluates whether controls are designed appropriately and operating effectively, without owning them. The board or a designated committee (such as audit or a dedicated risk or ethics committee, depending on the entity) generally holds oversight responsibility, setting tone from the top and monitoring the program rather than executing it. The precise allocation varies by entity type, size, and governance structure; this entry does not prescribe a single model.
How should third-party and intermediary bribery risk be managed in practice?
Organizations commonly apply risk-based due diligence to third parties such as agents, distributors, consultants, and joint venture partners, calibrating the depth of review to factors like the counterparty's role, geography, sector, and interaction with public officials. Typical measures include screening, understanding beneficial ownership and reputational red flags, documented risk rating, contractual anti-corruption representations and audit or termination rights, and ongoing monitoring or periodic re-review rather than a one-time check. Management generally owns these processes as a control activity, while compliance may set standards and provide challenge. The appropriate intensity is a matter of judgment based on the entity's risk assessment and applicable legal expectations, which differ across regimes.
How are gifts, hospitality, and facilitation payments typically addressed within a program?
Many programs set clear internal policies defining acceptable and prohibited gifts and hospitality, often using proportionality, transparency, and approval thresholds, supported by a register for higher-value or higher-risk items. Treatment of facilitation payments (small payments to expedite routine government actions) varies significantly by jurisdiction, some legal regimes prohibit them outright while others may recognize limited exceptions, so organizations should align policy with the specific laws that apply to them rather than assuming a universal rule. Whether a particular payment is permissible is fact- and jurisdiction-dependent; this entry describes general approaches and is not legal advice on any specific arrangement.
How can a program's effectiveness be assessed rather than assumed from the existence of a policy?
A written policy evidences control design but does not, on its own, demonstrate operating effectiveness. Assessing effectiveness typically involves testing whether controls actually function in practice, for example, reviewing whether due diligence was performed and documented, whether approvals were obtained, whether training reached relevant personnel, and whether exceptions or red flags were escalated and addressed. Distinguishing inherent risk from residual risk after controls, and evaluating both design and operating effectiveness, is generally part of this analysis. Internal audit or comparable assurance functions commonly perform independent evaluation, while management monitors controls day to day. The appropriate scope and methods depend on the entity's risk profile and applicable frameworks; this entry is educational and not audit or compliance advice.