Skip to main content
Category: Anti-Bribery and Corruption

Bribery and Corruption Fraud

Also known as: Bribery and Corruption, Corruption Schemes
Simply put

Bribery and corruption fraud involves the misuse of a position of power, influence, or resources for personal gain, often through the offering, giving, or accepting of a bribe in exchange for a favor or action. Corruption is generally described as dishonest or fraudulent conduct by those in positions of power, while bribery is one common form it takes. These practices are typically unethical and, in many jurisdictions, illegal, though the specific legal treatment varies by jurisdiction and sector.

Formal definition

Bribery and corruption fraud refers to a category of occupational and financial crime schemes in which individuals abuse entrusted power, influence, or resources for private benefit. Corruption is characterized as dishonest or fraudulent behavior by persons in positions of power, of which bribery, the corrupt solicitation, payment, or acceptance of a private favor in exchange for official or business action, is a principal form. In the fraud-examination context, corruption schemes represent a distinct scheme category alongside asset misappropriation and financial statement fraud; according to the ACFE's Occupational Fraud 2026: A Report to the Nations, corruption schemes account for 45% of reported fraud cases with a median loss of $150,000. Whether specific conduct constitutes a legal offense depends on the applicable anti-bribery and anti-corruption laws of the relevant jurisdiction; this entry is educational and not legal or compliance advice.

Why it matters

Bribery and corruption fraud undermines the integrity of both public institutions and private enterprises by substituting private advantage for legitimate decision-making. According to the ACFE's Occupational Fraud 2026: A Report to the Nations, corruption schemes account for 45% of reported occupational fraud cases, with a median loss of $150,000. Its prevalence relative to other scheme categories makes it a significant concern for boards, management, and assurance functions alike, even though the median loss figure alone does not capture the reputational, regulatory, and operational consequences that often accompany such conduct.

Who it's relevant to

Boards and Audit Committees
Directors exercising oversight responsibilities generally have an interest in understanding the organization's exposure to corruption risk and the adequacy of the anti-bribery and anti-corruption program. Oversight typically involves challenging management on the design of controls and the tone at the top, rather than performing operational compliance activities directly. The extent and nature of these duties vary by jurisdiction and entity type.
Chief Compliance and Ethics Officers
Compliance functions generally own the design, implementation, and monitoring of anti-bribery and anti-corruption policies, third-party due diligence, and related training. Because corruption schemes represent a distinct fraud category and account for a substantial share of reported occupational fraud cases, these professionals often focus on prevention and detection controls tailored to the organization's risk profile.
Fraud Examiners and Internal Auditors
Assurance and investigative professionals may treat corruption as a discrete scheme category alongside asset misappropriation and financial statement fraud. Their work typically includes assessing whether controls are both well designed and operating effectively, and investigating suspected schemes. Their role is providing independent assurance and examination rather than owning day-to-day compliance operations.
Risk Officers
Risk functions generally support the assessment of bribery and corruption as an enterprise risk, considering both likelihood and impact and how residual exposure compares against the organization's risk appetite. Because whether conduct is unlawful varies by jurisdiction and sector, risk assessments often account for the specific legal and operating environments in which the organization does business.

Inside Bribery and Corruption Fraud

Bribery
The offering, promising, giving, requesting, or receiving of something of value to improperly influence the actions of an individual in a position of trust or authority. Bribery can involve public officials or private-sector counterparties, and many jurisdictions treat these two contexts under distinct legal standards.
Corruption
A broader category of abuse of entrusted power or position for private gain, which may include bribery as well as related conduct such as embezzlement, kickbacks, and conflicts of interest. The precise scope of what constitutes corruption typically depends on the applicable jurisdiction and statute.
Facilitation payments
Small payments made to expedite routine, non-discretionary government actions. Their legal treatment varies by jurisdiction; some regimes prohibit them outright while others provide a narrow exception, so entities should not assume a uniform rule applies.
Third-party and intermediary risk
Exposure arising from agents, distributors, consultants, and other intermediaries acting on an entity's behalf. In many enforcement regimes an organization can face liability for improper payments made by third parties, making due diligence on these relationships a common area of focus.
Books and records / internal controls
Requirements under certain anti-corruption regimes for accurate financial recordkeeping and adequate internal accounting controls. These provisions are generally distinct from the anti-bribery prohibition itself and may apply independently.
Adequate procedures / compliance defense
Under some frameworks an organization may mitigate or defend against liability by demonstrating it maintained reasonable and proportionate anti-corruption procedures. The availability and design of such a defense depend on the specific legal regime.

Common questions

Answers to the questions practitioners most commonly ask about Bribery and Corruption Fraud.

Is bribery and corruption only a concern for companies operating in high-risk foreign markets?
No. While cross-border operations, use of third-party intermediaries, and certain sectors and geographies typically elevate exposure, bribery and corruption risk can arise in domestic dealings as well, including interactions with public officials, procurement, licensing, and even commercial (private-to-private) relationships. The relevance of foreign versus domestic conduct depends on the applicable laws, which vary by jurisdiction. Some anti-bribery regimes reach conduct extraterritorially and cover both public and commercial bribery, while others are narrower. Organizations generally assess exposure based on their own facts, markets, counterparties, transaction types, and regulatory footprint, rather than assuming risk is confined to particular regions. This entry is educational and not legal advice; scoping should reflect the specific laws that apply to the entity.
Does bribery require an actual cash payment or a completed transaction to be a problem?
Not necessarily. Under many anti-bribery regimes, the offer, promise, or authorization of an improper advantage can be sufficient, regardless of whether a payment is ultimately made or the intended benefit is obtained. The advantage in question is also not limited to cash; depending on the applicable law, it may include gifts, hospitality, travel, employment, charitable or political contributions, or other things of value used to improperly influence a decision. Because definitions, thresholds, and available defenses differ across jurisdictions and frameworks, whether particular conduct crosses a legal line is a fact-specific determination. This entry describes general concepts and is not a substitute for legal analysis of a specific matter.
Which function should own the anti-bribery and corruption program, and where does oversight sit?
Accountability typically differentiates by line. Management generally owns the design and operation of anti-bribery controls, policies, due diligence, approvals, training, and monitoring, as a first- and second-line responsibility, with the compliance function often coordinating the program and providing second-line challenge. Internal audit, as a third-line assurance function, typically evaluates whether controls are designed appropriately and operating effectively, without owning them. The board or a designated committee (such as audit or a dedicated risk or ethics committee, depending on the entity) generally holds oversight responsibility, setting tone from the top and monitoring the program rather than executing it. The precise allocation varies by entity type, size, and governance structure; this entry does not prescribe a single model.
How should third-party and intermediary bribery risk be managed in practice?
Organizations commonly apply risk-based due diligence to third parties such as agents, distributors, consultants, and joint venture partners, calibrating the depth of review to factors like the counterparty's role, geography, sector, and interaction with public officials. Typical measures include screening, understanding beneficial ownership and reputational red flags, documented risk rating, contractual anti-corruption representations and audit or termination rights, and ongoing monitoring or periodic re-review rather than a one-time check. Management generally owns these processes as a control activity, while compliance may set standards and provide challenge. The appropriate intensity is a matter of judgment based on the entity's risk assessment and applicable legal expectations, which differ across regimes.
How are gifts, hospitality, and facilitation payments typically addressed within a program?
Many programs set clear internal policies defining acceptable and prohibited gifts and hospitality, often using proportionality, transparency, and approval thresholds, supported by a register for higher-value or higher-risk items. Treatment of facilitation payments (small payments to expedite routine government actions) varies significantly by jurisdiction, some legal regimes prohibit them outright while others may recognize limited exceptions, so organizations should align policy with the specific laws that apply to them rather than assuming a universal rule. Whether a particular payment is permissible is fact- and jurisdiction-dependent; this entry describes general approaches and is not legal advice on any specific arrangement.
How can a program's effectiveness be assessed rather than assumed from the existence of a policy?
A written policy evidences control design but does not, on its own, demonstrate operating effectiveness. Assessing effectiveness typically involves testing whether controls actually function in practice, for example, reviewing whether due diligence was performed and documented, whether approvals were obtained, whether training reached relevant personnel, and whether exceptions or red flags were escalated and addressed. Distinguishing inherent risk from residual risk after controls, and evaluating both design and operating effectiveness, is generally part of this analysis. Internal audit or comparable assurance functions commonly perform independent evaluation, while management monitors controls day to day. The appropriate scope and methods depend on the entity's risk profile and applicable frameworks; this entry is educational and not audit or compliance advice.

Common misconceptions

Anti-bribery laws only apply to payments made to foreign government officials.
Depending on the jurisdiction and statute, prohibitions may extend to domestic officials and to purely commercial (private-to-private) bribery. The scope varies by regime, so practitioners should confirm which conduct is captured under the laws applicable to their operations rather than assuming a foreign-official-only standard.
Having a written anti-corruption policy is sufficient to protect the organization.
A policy is typically only one element. Many frameworks distinguish control design from operating effectiveness, meaning that documented procedures must also be implemented, monitored, and enforced in practice. A policy that exists on paper but is not operating effectively generally provides limited protection.
Preventing bribery and corruption is solely the compliance function's responsibility.
Accountability is generally shared across the three lines. Management (first line) owns and operates day-to-day controls, the compliance function (second line) sets policy and monitors, and internal audit (third line) provides independent assurance, while the board provides oversight. Attributing the entire responsibility to one function misstates how accountability is typically distributed.

Best practices

Conduct a risk assessment that considers inherent bribery and corruption exposure across markets, sectors, and transaction types before evaluating residual risk after controls, and refresh it as the business or its geographic footprint changes.
Apply risk-based due diligence to third parties and intermediaries, including agents, distributors, and consultants, and document the basis for onboarding and ongoing monitoring decisions.
Design and test controls for both design adequacy and operating effectiveness, rather than relying on the existence of a written policy alone.
Clarify roles across the three lines so that management owns operational controls, compliance monitors and advises, internal audit provides independent assurance, and the board or a designated committee retains oversight.
Confirm the specific legal requirements applicable to each jurisdiction and entity type in which the organization operates, since the treatment of facilitation payments, commercial bribery, and available compliance defenses varies, and seek qualified legal advice on fact-specific questions.
Maintain accurate books and records and adequate internal accounting controls, recognizing these obligations may apply independently of the anti-bribery prohibition under certain regimes.