Skip to main content
Category: Anti-Bribery and Corruption

Corruption Risk Assessment

Also known as: CRA, Anti-Bribery and Corruption Risk Assessment, ABC Risk Assessment, Fraud and Corruption Risk Assessment
Simply put

A corruption risk assessment is a structured process an organisation uses to understand where it is exposed to bribery and corruption, and how serious those risks are. It helps identify the specific situations where corruption could occur, evaluate how significant each risk is, and determine what controls are needed to reduce them. It is a tool to support better decision-making and governance rather than a one-time compliance formality.

Formal definition

A corruption risk assessment is a structured, repeatable process to identify, evaluate, and prioritise an entity's exposure to bribery and corruption risks, typically as a component of a broader anti-bribery and corruption or corruption risk management program. Practitioner approaches commonly follow a sequence of steps such as establishing the assessment scope and process, identifying corruption risks, rating those risks (generally by reference to likelihood and impact), identifying existing and mitigating controls, and assessing residual exposure to inform remediation. In many organisations the exercise is owned and conducted by management or the compliance function as a management tool for improving governance, with results informing board and committee oversight; its rigor, methodology, and legal significance vary by jurisdiction, sector, and entity type. In some public-sector and government contexts it is combined with fraud risk assessment. This entry is educational and not legal, audit, or compliance advice.

Why it matters

Bribery and corruption exposure is rarely uniform across an organisation. It concentrates in particular jurisdictions, business lines, transaction types, and points of interaction with public officials or third-party intermediaries. Without a structured assessment, an organisation risks allocating compliance resources on the basis of assumption rather than evidence, over-controlling low-risk activities while leaving genuine exposures unmanaged. A corruption risk assessment gives management and the board a defensible, documented basis for understanding where the entity is most vulnerable and why.

Who it's relevant to

Chief Compliance and Ethics Officers
The compliance function typically owns and conducts the corruption risk assessment as a component of a broader anti-bribery and corruption program. The results guide where to concentrate controls, due diligence, training, and monitoring, and provide a documented, defensible basis for those decisions.
Boards and Audit or Risk Committees
Those charged with governance rely on the assessment's output to exercise oversight, testing whether the anti-bribery and corruption program is proportionate to the entity's actual exposure. The board's role is generally oversight rather than conducting the assessment itself, which is typically a management responsibility.
General Counsel and Legal Teams
Legal advisers help frame the scope of the assessment and interpret its findings in light of applicable anti-bribery and corruption obligations, which vary by jurisdiction and sector. They also help ensure that identified risks and remediation are addressed in a manner consistent with the entity's legal environment.
Internal Audit and Assurance Functions
Assurance providers may evaluate the design and operating effectiveness of controls identified through the assessment, and may review whether the assessment methodology itself is sound and applied consistently. Their role is to provide independent assurance rather than to own the operational risk-rating exercise.
Public-Sector and Government Bodies
In many public-sector contexts the corruption risk assessment is described as a management tool for improving governance of a specific institution, department, or agency, and is often combined with fraud risk assessment. Approaches and requirements differ from those in the private sector and vary by jurisdiction.

Inside CRA

Scope and Perimeter Definition
Identification of the business units, geographies, functions, third-party relationships, and transaction types to be assessed. Scope typically reflects the entity's footprint and the corruption risk regimes to which it may be exposed; the appropriate perimeter depends on facts, jurisdiction, and the entity's structure.
Risk Identification
The process of cataloguing potential corruption schemes and exposures, such as bribery of public officials, commercial bribery, facilitation payments, improper gifts and hospitality, conflicts of interest, and misuse of intermediaries. Identification generally draws on internal data, prior incidents, and knowledge of the operating environment.
Inherent Risk Rating
An assessment of corruption risk before considering the effect of controls, typically evaluated across likelihood and impact as separate dimensions. Inherent risk should not be conflated with residual risk.
Control Evaluation
Consideration of the anti-corruption controls in place and how they mitigate identified risks. This generally distinguishes control design (whether a control is capable of addressing the risk) from operating effectiveness (whether it functions as intended in practice).
Residual Risk Rating
The level of corruption risk remaining after accounting for the mitigating effect of existing controls. Comparing residual risk against the entity's risk appetite and tolerance helps surface areas needing further attention.
Risk Appetite and Tolerance Alignment
Reference to the board-approved risk appetite and the tolerances set for corruption-related exposures, used to evaluate whether residual risk levels are acceptable. Risk appetite, tolerance, and capacity are distinct concepts and should not be treated interchangeably.
Prioritization and Remediation Planning
Ranking of risks to focus resources and defining remediation actions, owners, and timelines where residual risk exceeds acceptable levels. Ownership of remediation typically sits with management in the relevant business or function.
Documentation and Reporting
A record of the methodology, findings, and conclusions, together with reporting to appropriate governance bodies. Compliance generally facilitates the assessment, while the board or a designated committee typically exercises oversight.

Common questions

Answers to the questions practitioners most commonly ask about CRA.

Is a corruption risk assessment the same thing as an anti-corruption compliance program?
No. A corruption risk assessment is a diagnostic activity that identifies, analyzes, and prioritizes the bribery and corruption risks an organization faces; it is one input into a broader anti-corruption compliance program, not the program itself. The program typically also includes policies, controls, training, due diligence, monitoring, and investigation processes. Many enforcement authorities and guidance sources treat a periodic, documented risk assessment as a foundational element that should inform, but not replace, the design of those other program components. Ownership generally sits with the compliance function, though risk identification requires input from the business, and board or committee oversight of the program is common. This entry is educational and not legal or compliance advice.
Does completing a corruption risk assessment mean the organization has reduced its actual corruption risk?
Not by itself. A risk assessment measures and prioritizes exposure; it does not, on its own, change the underlying level of risk. The distinction between inherent risk (before controls) and residual risk (after controls operate as intended) matters here: the assessment helps an organization understand where inherent risk is concentrated and whether existing controls appear adequate, but risk is typically reduced only when the resulting findings drive changes to controls, resources, or business practices, and when those controls are operating effectively, not merely well designed. An assessment that is not acted upon generally leaves residual risk unchanged. Whether any particular level of residual risk is acceptable depends on the organization's risk appetite and its own judgment.
How often should a corruption risk assessment be performed?
There is generally no single mandated frequency; practice varies by jurisdiction, sector, and entity type. Many organizations conduct a comprehensive assessment periodically and refresh it when significant changes occur, such as entry into a new market or higher-risk geography, a new acquisition, a change in business model, use of new third-party intermediaries, or a material regulatory development. Some guidance frameworks describe corruption risk assessment as an ongoing rather than a one-time exercise. The appropriate cadence for a specific organization depends on its risk profile and is ultimately a matter of professional judgment; this is not a fixed rule.
Who should be involved in conducting the assessment?
In many organizations the compliance function owns and coordinates the process, but meaningful input typically comes from the business units, legal, finance, internal audit, procurement, and personnel with knowledge of local operations and third-party relationships, because they hold the practical knowledge of where risks arise. Assurance functions such as internal audit may provide independent evaluation of the process or its outputs rather than performing the operational assessment. The board or a designated committee generally exercises oversight of the anti-corruption program as a whole. The precise allocation of roles depends on the organization's structure and its own governance arrangements.
What risk factors are commonly considered when scoping a corruption risk assessment?
Commonly considered factors include the countries and markets in which the organization operates, the nature of its interactions with government officials or state-owned entities, the use of third-party intermediaries and agents, the sectors and transaction types involved, the presence of high-value or licensing-dependent activities, and the strength of existing controls. Assessments generally evaluate both the likelihood of a corruption event and its potential impact, keeping those two dimensions distinct rather than combining them prematurely. The relevant factors depend on the specific business; this list is illustrative and not exhaustive, and does not substitute for tailored professional analysis.
How should the results of a corruption risk assessment be documented and used?
Documentation typically records the scope, methodology, risks identified, the basis for how they were rated, and the resulting prioritization, along with any planned remediation and responsible owners. Contemporaneous, well-reasoned documentation is often viewed favorably because it can demonstrate that the assessment was a considered process. The results are generally used to inform the design and calibration of controls, allocate compliance resources toward higher-risk areas, shape third-party due diligence and training, and report to management and the board or relevant committee. How findings are treated, retained, and shared may raise legal and privilege considerations that depend on jurisdiction and circumstances; this entry is educational and not legal or compliance advice.

Common misconceptions

A corruption risk assessment is a one-time exercise that satisfies a compliance obligation once completed.
A corruption risk assessment is generally treated as an ongoing, periodic process that is refreshed as the business, geographies, third-party relationships, and threat environment change. A stale assessment may no longer reflect the entity's actual exposure. Whether and how often reassessment is expected can depend on the applicable regime and the entity's circumstances.
The corruption risk assessment is owned and performed by the board.
The board or a designated committee typically exercises oversight of the anti-corruption program and reviews the assessment, but the assessment itself is generally conducted by management with support from the compliance function and, where relevant, input from assurance functions. Attributing the operational performance of the assessment to the board conflates oversight with management responsibility.
A low residual risk rating means controls have been proven effective.
A residual rating reflects an assessment of controls, but a favorable rating based only on control design does not confirm that controls operate effectively in practice. Distinguishing control design from operating effectiveness is important, and testing or assurance may be needed to support conclusions about effectiveness.

Best practices

Define the scope and perimeter explicitly at the outset, capturing high-risk geographies, business lines, transaction types, and third-party relationships relevant to the entity's footprint.
Assess inherent risk and residual risk as separate steps, and evaluate likelihood and impact as distinct dimensions rather than a single blended score.
Distinguish control design from operating effectiveness, and avoid concluding that a risk is well mitigated on the basis of design alone.
Compare residual risk against the entity's board-approved risk appetite and defined tolerances, and escalate exposures that exceed acceptable levels.
Assign remediation actions to accountable owners within management with clear timelines, and track them to completion.
Document the methodology, data sources, findings, and conclusions, and report results to the board or designated committee to support their oversight role; treat the assessment as a recurring process refreshed as circumstances change.