The EU's Anti-Bribery and Corruption directive took effect on May 31. If you're reading this in mid-2026, your window to demonstrate compliance is closing fast. The directive doesn't just tighten enforcement; it introduces cross-border cooperation mechanisms that make gaps in your anti-bribery and corruption controls visible to regulators across multiple jurisdictions. You can't patch this together with spreadsheets and annual policy attestations anymore.
What You Need Before Starting
Before building your compliance program, gather these assets:
Documentation inventory
- Current anti-bribery and corruption policy (if you have one)
- Existing third-party due diligence procedures
- Gift and entertainment tracking mechanisms
- Current training completion records
- Any previous internal audit reports covering bribery risk
Technical infrastructure
- Access to your GRC platform (or budget approval to procure one)
- Integration capability with your HR system for training tracking
- API access to financial systems for transaction monitoring
- Document management system with version control
Stakeholder alignment
- Executive sponsor identified (typically General Counsel or Chief Compliance Officer)
- Budget allocation for technology, training, and external due diligence services
- Cross-functional team: Legal, Finance, Procurement, HR, Internal Audit
- Agreement on risk appetite for third-party relationships in high-risk jurisdictions
Baseline risk assessment
- List of all jurisdictions where you operate
- Corruption Perceptions Index scores for those jurisdictions
- Inventory of government-facing roles and transactions
- Third-party population segmented by risk category
Step-by-Step Implementation
Week 1-2: Configure your obligations library
Map the directive's requirements into your GRC platform as regulatory obligations. Break it down:
- Obligation: Implement due diligence procedures for third parties in high-risk jurisdictions
- Obligation: Establish whistleblower protection mechanisms compliant with cross-border reporting requirements
- Obligation: Maintain transaction-level documentation for government interactions
- Obligation: Conduct risk-based training with completion tracking
For each obligation, assign an owner, link it to existing controls (if any), and flag gaps where you need new controls.
Week 3-4: Design your control framework
Build controls that address the directive's enforcement cooperation requirements. Cross-border cooperation means regulators will share findings, so your controls need consistent application across all EU operations.
Entity-level control example: "The organization maintains a board-approved anti-bribery and corruption policy reviewed annually and distributed to all employees and third parties."
Process-level control example: "Procurement conducts enhanced due diligence on all third parties operating in jurisdictions with Corruption Perceptions Index scores below 50, including beneficial ownership verification and ongoing monitoring."
Automated control example: "The expense management system flags and routes for manual review any gift, meal, or entertainment transaction exceeding €100 involving a government official."
Configure key control indicators in your GRC dashboard:
- Percentage of high-risk third parties with completed due diligence (target: 100%)
- Days to complete due diligence from contract initiation (target: <30)
- Training completion rate for employees in government-facing roles (target: 100% within 60 days of hire or role change)
- Number of whistleblower reports received and resolved (trend metric)
Week 5-8: Implement third-party due diligence workflow
This is where most organizations stumble. The directive's cross-border cooperation provisions mean a compliance failure at a distributor in one member state can trigger scrutiny of your entire third-party network.
Configure your workflow:
Risk tiering: Automatically score third parties based on jurisdiction, transaction value, government interaction, and services provided. Use your GRC platform's automated risk scoring if available.
Due diligence triggers: Set up automated alerts when Procurement creates a vendor record or modifies an existing relationship. Route to Compliance for review before contract execution.
Documentation requirements: For high-risk third parties, require:
- Beneficial ownership disclosure
- Anti-bribery and corruption policy acknowledgment
- Certification of no pending investigations
- References from other clients
- Financial stability verification
Ongoing monitoring: Schedule annual re-screening of all high-risk third parties. Configure automated alerts for adverse media mentions or sanctions list additions.
Week 9-10: Build your incident response structure
The directive's enforcement mechanisms require rapid response capability. Configure your information security incident management process to handle corruption allegations:
- Intake mechanism: Dedicated whistleblower hotline with multi-language support covering all EU jurisdictions where you operate
- Severity level criteria: Define what constitutes a material incident requiring board notification and potential regulatory disclosure
- Investigation workflow: Assign roles (Legal leads investigation, Internal Audit validates findings, HR manages personnel actions)
- Documentation requirements: Maintain investigation files with timeline, evidence, conclusions, and remediation actions
- Regulatory notification procedure: Define thresholds and approval process for voluntary disclosures
Week 11-12: Deploy training and communications
Don't send a generic e-learning module. Target your training:
- Government-facing roles: Scenario-based training covering gift rules, facilitation payments, and documentation requirements
- Procurement team: Deep dive on due diligence procedures and red flags
- Finance team: Transaction monitoring and expense review protocols
- Executives: Board-level briefing on directive requirements and organizational exposure
Configure your learning management system to track completion and send automated reminders. Link training records to your GRC platform so you can report on compliance program effectiveness.
Validation: How to Verify It Works
Run these tests before you consider yourself compliant:
Control testing
- Pull a sample of 25 new third-party relationships from the past quarter. Verify due diligence completion before contract execution for 100% of high-risk relationships.
- Review expense reports from government-facing employees. Confirm flagging and approval workflow functioned for transactions exceeding your threshold.
- Test whistleblower hotline by submitting an anonymous test report. Verify intake, routing, and acknowledgment within your defined timeframe.
Cross-border consistency check
- If you operate in multiple EU member states, pull control testing results from each jurisdiction. Your control effectiveness should not vary by country.
Dashboard validation
- Verify your key control indicators populate automatically from source systems. Manual data entry introduces error and won't scale.
Gap analysis
- Compare your control framework against the directive's requirements. You should have at least one control mapped to each regulatory obligation. Flag any obligations without controls as high-priority gaps.
Maintenance and Ongoing Tasks
Compliance isn't a project; it's a program. Schedule these recurring activities:
Monthly
- Review key control indicators for adverse trends
- Process new third-party due diligence requests
- Distribute updated training to new hires in covered roles
Quarterly
- Test a sample of controls and document results in your GRC platform
- Review open whistleblower investigations for resolution status
- Update risk assessment for any new jurisdictions or business lines
Annually
- Refresh your risk-based audit planning to cover anti-bribery and corruption controls
- Review and update your anti-bribery and corruption policy
- Re-screen all high-risk third parties
- Report to the board on program effectiveness, incidents, and remediation actions
As needed
- Monitor for directive amendments or enforcement guidance from EU regulators
- Update your obligations library and control framework when requirements change
- Conduct root cause analysis after any control failure or incident
The directive's emphasis on cross-border cooperation means your compliance posture is only as strong as your weakest jurisdiction. Build consistency into your controls from the start, automate where possible, and maintain audit trails that will withstand regulatory scrutiny across multiple member states.





