| name | design-anti-bribery-compliance-program |
| description | Use when a company operating internationally needs a compliance program addressing bribery and corruption risk under the FCPA, UK Bribery Act, or similar anti-corruption laws — implementing risk-based third-party due diligence, defined approval thresholds for gifts and hospitality, and a documented program structure prosecutors will actually credit, rather than a generic ethics policy with no anti-corruption-specific rigor. |
| source | U.S. Department of Justice and SEC, "A Resource Guide to the U.S. Foreign Corrupt Practices Act" (2020 update); UK Bribery Act 2010, "Adequate Procedures" guidance |
| tags | ["law","corporate","anti-bribery-compliance","fcpa","corruption-risk","third-party-due-diligence"] |
| related | ["design-conflict-of-interest-policy","design-sanctions-compliance-program","audit-related-party-transactions"] |
Design Anti-Bribery Compliance Program
Implement a compliance program addressing bribery and corruption risk under the FCPA, UK Bribery Act, or similar anti-corruption laws — risk-based third-party due diligence, defined approval thresholds for gifts and hospitality, and a documented program structure regulators will actually credit — rather than a generic ethics policy with no anti-corruption-specific rigor.
Why This Is Best Practice
Adopted by: The DOJ and SEC's joint "Resource Guide to the U.S. Foreign Corrupt Practices Act" and the UK Bribery Act's "Adequate Procedures" guidance both specify the elements regulators expect in an effective anti-corruption compliance program, and DOJ enforcement policy explicitly credits companies with a genuinely effective program (reduced penalties, declined prosecution) based on documented program elements, not merely the existence of a written policy.
Impact: The DOJ's own FCPA Corporate Enforcement Policy documents that companies with a demonstrably effective compliance program at the time of a violation — one with genuine risk-based due diligence and documented enforcement — receive materially reduced penalties or, in qualifying cases, declined prosecution altogether, compared to companies with only a nominal, undocumented policy.
Why best: A generic ethics policy stating "don't bribe anyone" provides no actual risk-based structure to catch and prevent the specific mechanisms through which bribery typically occurs — payments through third-party intermediaries, disguised as consulting fees or excessive gifts — a program specifically designed around these mechanisms (risk-tiered third-party due diligence, defined gift/hospitality thresholds, documented approval processes) is what regulators have specifically identified as distinguishing a genuinely effective program from a paper policy.
Sources: U.S. Department of Justice and Securities and Exchange Commission, "A Resource Guide to the U.S. Foreign Corrupt Practices Act," Second Edition (2020); UK Ministry of Justice, "The Bribery Act 2010: Guidance about procedures which relevant commercial organisations can put into place to prevent persons associated with them from bribing"
Steps
Step 1: Conduct a risk assessment across markets and business lines
Conduct a risk assessment identifying which markets, business lines, and functions carry the highest corruption risk — based on factors including the corruption risk profile of specific countries, the degree of interaction with government officials, and reliance on third-party intermediaries — since a uniform program applied without risk differentiation tends to under-scrutinize genuinely high-risk areas.
Step 2: Implement risk-tiered third-party due diligence
Implement due diligence on third-party intermediaries (agents, consultants, distributors, joint venture partners) scaled to their specific corruption risk — higher-risk intermediaries (operating in high-corruption-risk markets, with close government contact) warrant deeper diligence than lower-risk ones, since third-party intermediaries are the mechanism through which a large proportion of documented bribery violations actually occur.
Step 3: Define specific, quantified gift and hospitality thresholds
Define specific, quantified thresholds for permissible gifts, meals, and hospitality involving government officials or business partners, with defined approval requirements above those thresholds — a vague "use good judgment" standard provides insufficient specificity for consistent compliance across a large organization.
Step 4: Establish a documented pre-approval process for higher-risk transactions
Establish a documented pre-approval process for higher-risk transactions and payments — particularly those involving government officials, state-owned enterprises, or new third-party intermediary relationships — so higher-risk activity receives specific compliance review before proceeding, not only after-the-fact audit.
Step 5: Train employees based on their actual risk exposure and monitor ongoing compliance
Train employees on anti-corruption requirements calibrated to their actual risk exposure (sales and business development staff in high-risk markets require deeper training than employees with no external-facing role), and monitor ongoing compliance through periodic audits and updated risk assessments as the business evolves.
Rules
- Base the program's rigor on a genuine, documented risk assessment across markets and business lines — not a uniform program applied without risk differentiation.
- Apply risk-tiered due diligence to third-party intermediaries specifically, since this is the documented primary mechanism through which bribery violations typically occur.
- Define specific, quantified gift and hospitality thresholds rather than a vague "use good judgment" standard.
- Establish documented pre-approval for higher-risk transactions before they proceed, not only retrospective audit.
Examples
Risk-tiered due diligence catching a red flag: A company's risk-based third-party due diligence process flags a proposed sales agent in a high-corruption-risk market whose compensation structure (an unusually large commission with no clear services rendered) raises a specific red flag under the diligence checklist — a review that a uniform, non-risk-differentiated due diligence process applied identically to all intermediaries might have missed given the volume of lower-risk relationships also requiring review.
Documented program elements supporting reduced enforcement exposure: A company subject to an FCPA investigation is able to demonstrate a documented, genuinely operating compliance program — risk assessments, tiered due diligence records, defined approval thresholds actually applied — at the time the violation occurred. Consistent with DOJ's stated enforcement policy, this documented program is a factor in the resulting reduced penalty, compared to a company with only a written policy and no operating evidence behind it.
Common Mistakes
- Applying a uniform compliance program with no risk-based differentiation across markets and business lines — this under-scrutinizes genuinely high-risk areas while potentially over-burdening low-risk ones.
- Providing only vague "use good judgment" guidance on gifts and hospitality rather than specific, quantified thresholds — this produces inconsistent application across a large organization.
- Treating third-party intermediary relationships with the same due diligence rigor regardless of their actual corruption risk — intermediaries are the documented primary mechanism for bribery violations, warranting risk-tiered scrutiny.
- Maintaining a written policy with no genuine operating program behind it — regulators specifically credit demonstrated, documented program operation, not merely the existence of a policy document.
When NOT to Use
- For a purely domestic company with no international operations, government contact, or third-party intermediary relationships in higher-corruption-risk markets — apply program rigor proportionate to actual corruption risk exposure.
- As a substitute for the company's broader conflict-of-interest and related-party transaction practices — anti-bribery compliance addresses a specific corruption risk category; broader conflicts require the complementary practices in
design-conflict-of-interest-policy and audit-related-party-transactions.
- For determining whether specific past conduct actually violated the FCPA or Bribery Act — that determination requires case-specific legal analysis, not this program-design practice.
Legal disclaimer: This skill encodes professional best practices for educational purposes. It is not legal advice. Anti-corruption compliance carries significant criminal and civil liability exposure across multiple jurisdictions — consult licensed anti-corruption counsel before designing or implementing a compliance program.