Answers to the questions practitioners most commonly ask about CRA.
Is a corruption risk assessment the same thing as an anti-corruption compliance program?
No. A corruption risk assessment is a diagnostic activity that identifies, analyzes, and prioritizes the bribery and corruption risks an organization faces; it is one input into a broader anti-corruption compliance program, not the program itself. The program typically also includes policies, controls, training, due diligence, monitoring, and investigation processes. Many enforcement authorities and guidance sources treat a periodic, documented risk assessment as a foundational element that should inform, but not replace, the design of those other program components. Ownership generally sits with the compliance function, though risk identification requires input from the business, and board or committee oversight of the program is common. This entry is educational and not legal or compliance advice.
Does completing a corruption risk assessment mean the organization has reduced its actual corruption risk?
Not by itself. A risk assessment measures and prioritizes exposure; it does not, on its own, change the underlying level of risk. The distinction between inherent risk (before controls) and residual risk (after controls operate as intended) matters here: the assessment helps an organization understand where inherent risk is concentrated and whether existing controls appear adequate, but risk is typically reduced only when the resulting findings drive changes to controls, resources, or business practices, and when those controls are operating effectively, not merely well designed. An assessment that is not acted upon generally leaves residual risk unchanged. Whether any particular level of residual risk is acceptable depends on the organization's risk appetite and its own judgment.
How often should a corruption risk assessment be performed?
There is generally no single mandated frequency; practice varies by jurisdiction, sector, and entity type. Many organizations conduct a comprehensive assessment periodically and refresh it when significant changes occur, such as entry into a new market or higher-risk geography, a new acquisition, a change in business model, use of new third-party intermediaries, or a material regulatory development. Some guidance frameworks describe corruption risk assessment as an ongoing rather than a one-time exercise. The appropriate cadence for a specific organization depends on its risk profile and is ultimately a matter of professional judgment; this is not a fixed rule.
Who should be involved in conducting the assessment?
In many organizations the compliance function owns and coordinates the process, but meaningful input typically comes from the business units, legal, finance, internal audit, procurement, and personnel with knowledge of local operations and third-party relationships, because they hold the practical knowledge of where risks arise. Assurance functions such as internal audit may provide independent evaluation of the process or its outputs rather than performing the operational assessment. The board or a designated committee generally exercises oversight of the anti-corruption program as a whole. The precise allocation of roles depends on the organization's structure and its own governance arrangements.
What risk factors are commonly considered when scoping a corruption risk assessment?
Commonly considered factors include the countries and markets in which the organization operates, the nature of its interactions with government officials or state-owned entities, the use of third-party intermediaries and agents, the sectors and transaction types involved, the presence of high-value or licensing-dependent activities, and the strength of existing controls. Assessments generally evaluate both the likelihood of a corruption event and its potential impact, keeping those two dimensions distinct rather than combining them prematurely. The relevant factors depend on the specific business; this list is illustrative and not exhaustive, and does not substitute for tailored professional analysis.
How should the results of a corruption risk assessment be documented and used?
Documentation typically records the scope, methodology, risks identified, the basis for how they were rated, and the resulting prioritization, along with any planned remediation and responsible owners. Contemporaneous, well-reasoned documentation is often viewed favorably because it can demonstrate that the assessment was a considered process. The results are generally used to inform the design and calibration of controls, allocate compliance resources toward higher-risk areas, shape third-party due diligence and training, and report to management and the board or relevant committee. How findings are treated, retained, and shared may raise legal and privilege considerations that depend on jurisdiction and circumstances; this entry is educational and not legal or compliance advice.