Skip to main content
Category: Anti-Bribery and Corruption

Extortion

Also known as: Shakedown, Exaction
Simply put

Extortion is the practice of obtaining money, property, or some other benefit from a person or group through the wrongful use of force, threats, violence, fear, or coercion. It is distinct from legitimate negotiation because it relies on unlawful pressure rather than voluntary agreement. In many jurisdictions it is treated as a criminal offense, though the precise elements depend on the applicable law.

Formal definition

Extortion generally refers to the unlawful obtaining of money, property, or anything of value from another party through the wrongful use of actual or threatened force, violence, fear, or other coercion, as distinguished from legitimate negotiation methods. In the United States, conduct of this nature may be prosecuted under federal statutes such as the Hobbs Act, which addresses extortion accomplished by the wrongful use of actual or threatened force, violence, or fear; specific statutory elements, thresholds, and jurisdictional reach vary by statute and jurisdiction. For governance and compliance purposes, extortion is a form of financial crime that organizations typically address through anti-bribery and anti-corruption controls, fraud risk management, and related compliance monitoring, with accountability for control design and operating effectiveness sitting with management and independent assurance provided by functions such as internal audit. This entry is educational and not legal, audit, or compliance advice; whether particular conduct constitutes extortion is a fact-specific and jurisdiction-specific determination requiring professional judgment.

Why it matters

Extortion sits at the intersection of financial crime, corruption, and physical or reputational threat, which makes it a distinct concern for governance and compliance programs. Because it involves obtaining money, property, or other benefit through the wrongful use of force, threats, fear, or coercion rather than voluntary agreement, it can expose organizations to both criminal liability and operational harm. Whether particular conduct meets the legal definition of extortion is a fact-specific and jurisdiction-specific determination, and the precise elements vary by the applicable law.

Who it's relevant to

Chief Compliance Officers
Compliance leaders typically address extortion risk through anti-bribery and anti-corruption controls, fraud risk management, and compliance monitoring. Because the distinction between a coercive extortion demand and other financial crimes can be difficult to draw in practice, compliance functions are generally responsible for ensuring the organization has clear escalation and response procedures, though whether specific conduct is unlawful is a fact-specific and jurisdiction-specific determination.
General Counsel and Legal Teams
Legal functions assess whether particular conduct may constitute extortion under the applicable law. In the United States, for example, conduct of this nature may be prosecuted under federal statutes such as the Hobbs Act, which addresses extortion accomplished by the wrongful use of actual or threatened force, violence, or fear. Statutory elements, thresholds, and jurisdictional reach vary, so legal analysis depends on the governing statute and the specific facts.
Chief Risk Officers
Risk leaders typically consider extortion within the organization's broader financial crime and fraud risk profile. This includes assessing where coercive demands are more likely to arise given the organization's operations and geographies, and how such exposure is reflected in the risk assessment. The design of responsive controls sits with management, with the appropriate treatment depending on the facts.
Internal Auditors
Internal audit generally provides independent assurance over whether the controls management has designed to address extortion and related financial crime risks are operating effectively. This assurance role is distinct from management's ownership of control design and operating effectiveness, and audit's scope is typically to evaluate rather than to operate those controls.
Boards and Audit or Risk Committees
Boards and their committees typically exercise oversight of the organization's financial crime and compliance risk framework, including how management identifies and responds to coercive demands. This oversight role is distinct from the operational responsibility for designing and running controls, which sits with management.

Inside Extortion

Demand backed by coercion
Extortion typically involves obtaining money, property, services, or some advantage through threats, intimidation, or the wrongful use of actual or threatened force, coercion, or misuse of position. The coercive element distinguishes it from ordinary commercial negotiation.
Relationship to bribery
In many anti-corruption frameworks and statutes, extortion is treated as related to but distinct from bribery. Bribery generally involves an offer or inducement to secure improper advantage, while extortion generally involves a demand under threat. The line can be fact-dependent, particularly where a party claims payment was demanded rather than offered.
Public and private sector dimensions
Extortion can involve public officials abusing authority (for example, demanding payment to perform or refrain from an official act) or private parties. Whether a given demand constitutes extortion under law depends on the applicable statute, jurisdiction, and facts.
Governance and compliance relevance
For organizations, extortion is generally addressed within anti-corruption and anti-bribery compliance programs, third-party risk management, and fraud risk assessments. Accountability for setting the control framework typically sits with management, with board or audit/risk committee oversight of program effectiveness.
Facilitation payment considerations
Some legal regimes distinguish demands for small facilitation or 'grease' payments from other forms of extortion, and treatment varies significantly by jurisdiction and statute. Whether such payments are permitted, prohibited, or subject to narrow exceptions depends on the specific law that applies.

Common questions

Answers to the questions practitioners most commonly ask about Extortion.

Is extortion the same thing as bribery under an anti-corruption program?
No. Although both are frequently addressed within the same anti-corruption policies, they are conceptually distinct. Bribery generally involves offering, promising, or giving something of value to improperly influence a recipient, whereas extortion typically involves obtaining something of value through coercion, threats, or abuse of position. A payment demanded under duress raises different analytical and legal considerations than a voluntary corrupt inducement. That said, the precise definitions, defenses, and treatment of coerced payments vary by jurisdiction and by the specific statute or framework applied, so the distinction should be assessed against the governing law and the entity's own policies. This entry is educational and not legal advice.
Does classifying a payment as extortion automatically excuse the entity from liability because it was coerced?
Not necessarily. The existence of coercion or a threat does not, by itself, guarantee a defense or exemption. Whether a coerced payment is treated differently from a proactive bribe depends on the applicable law, the nature and immediacy of the threat, how the entity responded, and whether the payment was properly documented and reported. Some frameworks and statutes distinguish payments made under genuine duress from those made to gain a business advantage, but the availability and scope of any such distinction differ across jurisdictions and are fact-specific. Entities should not assume protection and should seek qualified legal advice on the particular circumstances.
How should employees report a suspected extortion demand, and who owns the response?
Reporting mechanisms are typically defined in the entity's anti-corruption policy, whistleblowing procedures, or incident escalation protocols, and often include reporting to a manager, the compliance function, or a confidential channel. Management generally owns the operational response and first-line handling of an incident, the compliance function commonly supports investigation and policy interpretation, and the board or a relevant committee typically retains oversight of how significant incidents are managed. The specific routing depends on the entity's structure, so employees should follow the documented procedures applicable to them. Where legal exposure is involved, involving legal counsel early is generally advisable.
What controls do organizations typically put in place to detect and deter extortion?
Common controls include clear policies prohibiting improper payments, training that helps staff recognize coercive demands, confidential reporting channels, transaction monitoring and approval workflows, due diligence on third parties and high-risk relationships, and documentation requirements for unusual payments. The distinction between control design and operating effectiveness is relevant here: a well-designed policy provides little assurance unless it is operating as intended in practice. The appropriate mix and rigor of controls generally depend on the entity's risk assessment, sector, geographic footprint, and the demands it realistically faces, and should be calibrated accordingly.
How does extortion risk feed into an enterprise risk assessment?
Extortion is often assessed as a specific risk within the broader corruption or fraud risk categories, considering both likelihood and impact and distinguishing inherent risk from residual risk after controls are applied. Factors that commonly influence the assessment include the jurisdictions in which the entity operates, its reliance on intermediaries, interactions with public officials, and the sectors involved. The results typically inform where risk sits relative to the entity's defined risk appetite and tolerance, and where additional controls or escalation may be warranted. The methodology and thresholds are matters of the entity's own framework and professional judgment.
What documentation should an organization maintain if it encounters an extortion demand?
Organizations generally maintain records of the incident, including the nature of the demand, the individuals involved, the timeline, any threat or duress asserted, the decision-making and approvals, and the response taken, including any reporting to authorities where required or appropriate. Contemporaneous, accurate documentation supports later investigation, assurance review, and any external reporting obligations. What must be recorded and retained, and whether external disclosure is required, depends on the applicable law and the entity's policies. Legal counsel should generally be consulted on preservation, privilege, and reporting considerations, as this entry does not constitute legal advice.

Common misconceptions

Extortion and bribery are the same offense and are handled the same way.
They are generally treated as related but distinct concepts. Bribery typically centers on offering or providing an improper inducement, while extortion typically centers on demanding something under threat or coercion. Their legal treatment, defenses, and evidentiary questions can differ, and the applicable characterization depends on jurisdiction and facts.
If a payment was demanded under threat, the paying organization automatically bears no responsibility.
Being subject to a demand does not, by itself, resolve an organization's legal or compliance exposure. Treatment varies by jurisdiction and by the applicable anti-corruption regime, and outcomes can depend on the facts, how the situation was handled, and whether the response was documented and reported. This entry is educational and not legal advice; specific situations require professional judgment.
Preventing extortion is solely the board's responsibility.
Designing and operating anti-corruption controls is generally a management responsibility, while the board or a designated committee typically provides oversight of program design and effectiveness. Assurance functions such as internal audit may independently evaluate those controls. The duties differ and should not be conflated.

Best practices

Address extortion explicitly within the anti-corruption and anti-bribery compliance program rather than assuming bribery controls fully cover it, and align the program with the requirements of the jurisdictions and sectors in which the organization operates.
Provide clear escalation and reporting channels so that personnel facing a demand under threat can seek guidance and report promptly, and document how such situations are handled.
Incorporate extortion scenarios into fraud and corruption risk assessments, distinguishing inherent from residual risk once controls are considered, and reassess as third-party and geographic exposures change.
Extend third-party due diligence and contractual controls to counterparties and intermediaries where extortion risk is elevated, and monitor for red flags.
Obtain qualified legal advice on how applicable statutes treat demands, coercion, and any facilitation payment exceptions before acting, recognizing that treatment varies significantly by jurisdiction.
Ensure the board or its risk or audit committee receives sufficient reporting to exercise oversight of program effectiveness, while leaving day-to-day control design and operation with management and independent evaluation to assurance functions.