Skip to main content
Category: Anti-Bribery and Corruption

Bribery Risk Assessment

Also known as: Bribery and Corruption Risk Assessment, Anti-Bribery Risk Assessment, Anti-Corruption Risk Assessment
Simply put

A bribery risk assessment is a structured review an organization carries out to identify and understand where it may be exposed to bribery or corruption. It looks at factors such as the countries and markets in which the organization operates, the nature of its business dealings, and its relationships with third parties like agents, consultants, contractors, and vendors. The goal is to help the organization see where bribery is more likely to occur so it can decide how to respond.

Formal definition

A bribery risk assessment is a systematic evaluation conducted by an organization to identify, analyze, and understand its exposure to bribery and corruption risk, typically considering factors such as the likelihood of corrupt conduct arising in particular activities (for example, public bidding or procurement processes), geographic and market exposure, and risks associated with third parties such as agents, consultants, contractors, and vendors. It is generally executed as a defined, often step-by-step process and may be supported by tools such as questionnaires or external risk indices to gauge the propensity for bribery in a given jurisdiction or business context. As a matter of practice it usually operates as a component of an organization's broader anti-bribery and anti-corruption compliance program; the specific methodology, scope, and any obligation to perform it depend on the applicable legal regime, sector, and entity type, and are not defined uniformly across jurisdictions or frameworks. This entry is educational and does not constitute legal, audit, or compliance advice.

Why it matters

Bribery and corruption exposure is rarely evenly distributed across an organization. It tends to concentrate in particular activities, markets, and relationships, such as public bidding or procurement processes where corrupt conduct is more likely to arise, or in dealings with third parties like agents, consultants, contractors, and vendors who act on the organization's behalf. A bribery risk assessment matters because it gives an organization a structured way to see where that concentration exists rather than treating all parts of the business as equally exposed. Without this understanding, controls may be applied uniformly and inefficiently, leaving higher-risk areas under-protected and lower-risk areas over-burdened.

The assessment also functions as a foundation for the rest of an anti-bribery and anti-corruption compliance program. Decisions about due diligence on third parties, training, monitoring, and controls are generally more defensible and better targeted when they flow from a documented evaluation of where bribery is more likely to occur. In practice, the propensity for bribery can vary significantly by jurisdiction and business context, which is why some organizations draw on tools such as external risk indices designed to help firms assess the propensity for government bribery and its associated business risk.

It is important to recognize the limits of this entry. Whether an organization is obligated to perform a bribery risk assessment, and the methodology and scope it should use, depend on the applicable legal regime, sector, and entity type, and are not defined uniformly across jurisdictions or frameworks. This entry is educational and does not constitute legal, audit, or compliance advice.

Who it's relevant to

Chief Compliance Officers and Compliance Teams
Compliance functions typically own the design and execution of the bribery risk assessment as part of the broader anti-bribery and anti-corruption program. They generally coordinate the methodology, select supporting tools such as questionnaires or risk indices, and use the results to prioritize third-party due diligence, training, and monitoring. Accountability for how the assessment is scoped and acted upon usually sits within this function, subject to management and board oversight.
General Counsel and In-House Legal
Legal teams are often involved in conducting or reviewing preliminary corruption risk assessments, including those focused on third parties such as agents, consultants, contractors, and vendors. They help interpret how the applicable legal regime bears on the organization's exposure and on whether and how an assessment should be performed, given that obligations vary by jurisdiction, sector, and entity type.
Risk Officers and Enterprise Risk Functions
Where bribery and corruption is treated as a risk domain within the enterprise risk picture, risk functions may contribute to analyzing likelihood and exposure across markets and activities. Their role is generally to integrate bribery risk findings into the organization's wider risk management view rather than to own the compliance program itself; the division of responsibilities between risk and compliance depends on how the organization structures its functions.
Boards and Audit or Risk Committees
Boards and their relevant committees typically hold an oversight role, satisfying themselves that management has a credible process for identifying bribery exposure and responding to it. This is generally an oversight duty rather than an operational one; the board does not usually conduct the assessment but may review its scope, findings, and how management has acted on them.
Internal Auditors and Assurance Functions
Assurance functions may evaluate whether the bribery risk assessment process is designed appropriately and operating as intended, and whether resulting controls are working. Their focus is generally on providing independent assurance over the process rather than performing it, preserving the separation between those who own the activity and those who assure it.
Business Units Operating in Higher-Exposure Contexts
Units engaged in activities such as public bidding or procurement, or operating in markets with higher assessed propensity for bribery, are often the subject of the assessment and a source of the information it relies on. They typically complete questionnaires and support due diligence on the agents, consultants, contractors, and vendors they engage.

Inside Bribery Risk Assessment

Scope and Business Profiling
Definition of the organizational units, geographies, business lines, and third-party relationships covered by the assessment. Profiling typically considers factors such as sector, countries of operation, interaction with public officials, use of intermediaries, and transaction types that may elevate exposure to bribery and corruption risk.
Risk Identification
The systematic cataloguing of bribery and corruption risk scenarios, such as facilitation payments, improper hospitality and gifts, third-party or agent conduct, charitable and political contributions, and interactions with government officials. This step identifies where and how bribery risk could arise without yet judging its significance.
Inherent Risk Evaluation
Assessment of the level of bribery risk before considering the effect of controls, generally by weighing likelihood against potential impact. This distinguishes gross exposure from the residual position and helps prioritize where controls matter most.
Control Assessment (Design and Operating Effectiveness)
Evaluation of anti-bribery controls such as due diligence, approval workflows, gifts and hospitality registers, training, and monitoring. It is generally important to assess both whether controls are designed appropriately and whether they operate effectively in practice, as these are distinct questions.
Residual Risk Determination
The level of bribery risk remaining after accounting for the mitigating effect of existing controls, assessed against the organization's risk appetite and tolerance to identify areas requiring further action.
Prioritization and Remediation Planning
Ranking of identified risks and definition of remediation actions, ownership, and timelines. Accountability for executing remediation typically sits with management, while assurance functions may test outcomes and the board or a committee provides oversight.
Documentation and Refresh Cadence
A record of the methodology, inputs, judgments, and conclusions, together with a defined schedule or triggers for periodic refresh. Documentation supports the ability to demonstrate a reasoned, evidence-based approach where relevant to regulators or auditors.

Common questions

Answers to the questions practitioners most commonly ask about Bribery Risk Assessment.

Is a bribery risk assessment the same thing as the company's enterprise risk management (ERM) process?
No. A bribery risk assessment is a compliance-owned, focused exercise that identifies and evaluates exposure to bribery and corruption across a specific set of factors (such as geographies, third parties, transaction types, and interactions with public officials). ERM, by contrast, is a broader, typically management-led process addressing the full portfolio of enterprise risks under a framework such as COSO ERM or ISO 31000. The two are related and should feed one another, but they are not interchangeable: a bribery risk assessment is generally one input into, or a specialized subset of, the wider risk picture. In many organizations the compliance function owns the bribery assessment while risk management coordinates ERM, and the board or an appropriate committee provides oversight of both. Which functions own which activity depends on the entity's structure and governance design.
Does conducting a bribery risk assessment reduce or eliminate the underlying bribery risk?
No. A risk assessment identifies, analyzes, and prioritizes exposure; it does not by itself change the level of risk. It is important here to distinguish inherent risk (the exposure before controls) from residual risk (the exposure remaining after controls operate). A bribery risk assessment principally helps an organization understand inherent risk and evaluate whether existing controls are appropriately designed and operating, but the actual reduction of risk comes from the controls, training, due diligence, monitoring, and remediation that the assessment informs. Treating the assessment as a mitigation in itself is a common misconception. The assessment is a diagnostic and prioritization tool, not a control.
How often should a bribery risk assessment be performed?
There is no single mandated frequency that applies universally; the appropriate cadence depends on the entity's size, sector, geographic footprint, risk profile, and any applicable expectations. Many organizations conduct a periodic full assessment (for example on a recurring cycle) supplemented by interim reviews triggered by significant changes such as entering a new market, a merger or acquisition, onboarding high-risk third parties, or changes in the regulatory environment. Guidance associated with anti-bribery frameworks generally frames risk assessment as an ongoing, dynamic activity rather than a one-time event. Organizations should document their rationale for whatever frequency they adopt. This is a matter of professional judgment and not legal advice.
Who should own and who should oversee the bribery risk assessment?
In many organizations, day-to-day responsibility for designing and executing the bribery risk assessment sits with the compliance function, often with input from legal, internal audit, finance, and business units that hold relevant operational knowledge. Management is typically accountable for implementing the resulting controls and remediation. The board, or a designated committee such as an audit or risk committee, generally provides oversight, reviewing the methodology, results, and management's response, rather than performing the assessment itself. Be careful not to attribute the board's oversight duty to management, or management's operational duty to the board. Assurance functions such as internal audit may provide independent evaluation of the process. The precise allocation depends on the entity's governance structure and any applicable requirements.
What factors are typically evaluated in a bribery risk assessment?
Assessments commonly consider factors such as the countries and markets in which the organization operates, the nature and frequency of interactions with government or public officials, the use of third parties (agents, intermediaries, distributors, consultants), sectors known for elevated corruption exposure, the nature of transactions (licenses, permits, tenders), gifts and hospitality practices, and charitable or political contributions. Assessors generally analyze both likelihood and impact for identified scenarios, keeping these two dimensions distinct, and evaluate whether existing controls address the identified exposures. The specific factors relevant to any organization vary by its business model, footprint, and risk profile, so the list should be tailored rather than applied mechanically.
How should the results of a bribery risk assessment be documented and used?
Results are typically documented in a way that shows the methodology used, the risks identified, how they were prioritized, and the actions planned in response, supporting both internal decision-making and the ability to demonstrate a considered, risk-based approach. Outputs generally inform the design and enhancement of controls, the intensity of third-party due diligence, targeted training, monitoring plans, and resource allocation, with higher-risk areas receiving greater attention. When assessing controls, it is useful to distinguish control design (whether a control is capable of addressing the risk) from operating effectiveness (whether it works as intended in practice). Clear documentation also supports board and committee oversight. This entry is educational and not legal, audit, or compliance advice; specific documentation expectations depend on jurisdiction, sector, and professional judgment.

Common misconceptions

A bribery risk assessment is a one-time exercise that can be completed and shelved.
Bribery risk is dynamic and typically changes with new markets, products, third parties, and regulatory developments. Assessments are generally treated as periodic or event-driven activities that are refreshed to remain current, rather than a single static document.
Having anti-bribery policies and controls in place means residual bribery risk is eliminated.
Controls reduce but rarely eliminate risk. The distinction between inherent and residual risk matters: residual risk is what remains after controls are applied, and its acceptability depends on the organization's risk appetite and on whether controls are both well designed and operating effectively.
The bribery risk assessment is owned and performed by the board.
Conducting the assessment and managing the underlying risks is generally a management responsibility, often coordinated by the compliance function. The board or a designated committee typically provides oversight and challenge rather than performing the operational assessment itself.

Best practices

Base the assessment on the organization's actual risk profile, its geographies, sectors, third-party relationships, and points of interaction with public officials, rather than on a generic template.
Assess inherent risk and residual risk separately, and evaluate controls for both design adequacy and operating effectiveness rather than assuming a documented control is functioning.
Clearly assign ownership so that management drives identification and remediation while the board or a committee exercises oversight, keeping accountability distinct across the lines of defense.
Document the methodology, inputs, judgments, and conclusions so the reasoning behind risk ratings can be explained and revisited.
Establish a defined refresh cadence and event-based triggers, such as entering new markets or onboarding significant intermediaries, so the assessment stays current.
Evaluate residual risk against a clearly articulated risk appetite and tolerance, and prioritize remediation where residual exposure exceeds acceptable levels.