Skip to main content
Category: Ethics and Culture

Anti-Bribery and Corruption

Also known as: ABC, Anti-Bribery and Anti-Corruption, ABAC, Anti-Bribery and Corruption Compliance
Simply put

Anti-Bribery and Corruption (ABC) refers to the measures an organization puts in place to prevent bribery, corruption, and related improper practices. Bribery involves offering, promising, giving, requesting, or accepting something of value to gain or keep a business advantage, and anti-bribery laws prohibit both paying and receiving such bribes. Organizations commonly adopt policies, codes of conduct, and controls to help detect and deter this conduct.

Formal definition

Anti-Bribery and Corruption compliance is a domain within the compliance pillar comprising the organizational policies, controls, and processes designed to prevent, detect, and respond to bribery, corruption, improper payments, and the laundering of corrupt proceeds. It typically encompasses conduct in which a person or entity offers, promises, gives, requests, agrees to, receives, or accepts a bribe to gain or retain a business advantage, addressing both the demand and supply sides of bribery. In practice ABC programs are often implemented through anti-bribery policies and codes of conduct that set expectations for employees and third parties. The specific legal obligations, prohibited conduct, and enforcement mechanisms vary by jurisdiction and are not detailed in this entry; this entry does not constitute legal advice or address implementation specifics, tooling, or the requirements of any particular statute.

Why it matters

Anti-Bribery and Corruption compliance sits within the compliance pillar because it concerns adherence to external laws prohibiting bribery and corruption, as well as internal policies and codes of conduct that set expectations for employees and third parties. Bribery and corruption expose an organization to legal, financial, and reputational harm, and anti-bribery laws commonly prohibit both the paying and the receiving of bribes, addressing both the supply and demand sides of the conduct. Because these obligations vary by jurisdiction, the specific prohibited conduct and enforcement mechanisms an organization faces depend on where and how it operates.

Bribery and corruption are widely regarded as unethical and inconsistent with the values and codes of conduct that many organizations adopt. Improper payments, and the laundering of the proceeds of such conduct, can arise across a range of business relationships, including those involving third parties, which is why organizations commonly extend their expectations beyond direct employees. An anti-bribery policy is one mechanism that can help an organization deter and detect this conduct and articulate the standards it expects.

Because anti-bribery obligations differ across jurisdictions and sectors, a program that is adequate in one context may not satisfy the requirements applicable in another. Organizations therefore typically treat ABC not as a one-time policy statement but as an ongoing area of compliance that requires clear expectations, defined controls, and mechanisms to respond when concerns arise. This entry does not constitute legal advice and does not address the requirements of any particular statute.

Who it's relevant to

Compliance officers
Compliance officers are commonly responsible for designing, maintaining, and monitoring ABC policies and codes of conduct, and for ensuring that expectations for employees and third parties are clearly articulated. The specific obligations they must address depend on the jurisdictions and sectors in which the organization operates.
Governance professionals and boards
Those setting the organization's values and code of conduct have an interest in ABC because bribery and corruption are widely regarded as unethical and inconsistent with such standards. They typically set the tone and expectations under which ABC programs operate, while leaving implementation to management functions.
Internal auditors and assurance functions
Assurance functions may independently evaluate whether ABC controls and processes are designed and operating as intended. Their role is to provide objective assurance over the anti-bribery controls rather than to manage or operate those controls, preserving the independence distinction between assurance and management activities.
Employees and third parties
Employees are commonly expected to operate consistently with anti-bribery policies, and organizations frequently extend related expectations to third parties acting on their behalf. Both the supply side and the demand side of bribery are addressed, so expectations may cover both offering and accepting improper advantages.

Inside ABC

ABC Policy and Code of Conduct
A formally adopted policy setting out the organization's prohibition of bribery and corruption, typically defining prohibited conduct such as offering, promising, giving, requesting, or receiving improper advantages, and clarifying expectations for employees, officers, and often third parties acting on the organization's behalf.
Risk Assessment
A structured evaluation of where bribery and corruption exposure may arise, commonly considering factors such as jurisdiction, sector, use of intermediaries, interactions with public officials, and transaction types. It typically informs the design and prioritization of controls rather than guaranteeing that risks are eliminated.
Due Diligence on Third Parties
Risk-based checks performed on agents, intermediaries, distributors, and business partners, because organizations may face exposure for corrupt acts committed on their behalf. The depth of due diligence commonly varies with the assessed risk of the counterparty and relationship.
Controls on Gifts, Hospitality, and Facilitation Payments
Policies and procedures governing gifts, entertainment, travel, charitable and political contributions, and, where relevant, facilitation payments. Treatment of facilitation payments may differ across jurisdictions and legal regimes, so the applicable rules depend on context.
Training and Communication
Awareness and role-specific training intended to help personnel recognize and respond to bribery and corruption risks, often targeted to higher-risk roles and functions.
Reporting and Whistleblowing Channels
Mechanisms enabling individuals to raise concerns, commonly on a confidential or anonymous basis, together with protections against retaliation where applicable under relevant law or policy.
Monitoring, Review, and Recordkeeping
Ongoing activities to test the operation of ABC controls, maintain books and records, and periodically review the program's continued suitability. This is a management activity distinct from independent assurance over the program.
Governance and Oversight
The allocation of decision rights and accountability for the ABC program, which in many organizations involves senior management ownership and board or committee oversight, reflecting the governance dimension of the topic.

Common questions

Answers to the questions practitioners most commonly ask about ABC.

Does having an anti-bribery and corruption policy on paper mean an organization is compliant?
No. A documented policy is only one component of an ABC programme. In many frameworks and enforcement contexts, authorities and assurance functions assess whether controls operate effectively in practice, not merely whether a policy exists. A policy that is not communicated, embedded in procedures, monitored, and enforced is commonly regarded as insufficient. The policy is a governance instrument; demonstrating adherence requires supporting standards, procedures, training, monitoring, and evidence of consistent application.
Is bribery the same as corruption, so that addressing one covers the other?
They are related but distinct. Bribery typically refers to offering, promising, giving, requesting, or accepting an undue advantage to influence a decision or action. Corruption is a broader term that can encompass bribery alongside other conduct such as abuse of entrusted power for private gain, which may include forms of fraud, embezzlement, or conflicts of interest depending on the applicable definitions and jurisdiction. An ABC programme therefore usually addresses a wider set of risks than bribery alone, and the specific scope depends on the laws and standards that apply.
How should an organization approach third-party and intermediary due diligence within an ABC programme?
Third parties such as agents, distributors, consultants, and joint-venture partners are commonly treated as a significant source of bribery and corruption exposure. Risk-based due diligence is typically applied, meaning the depth of review is scaled to the assessed risk of the relationship, considering factors such as jurisdiction, sector, the nature of interactions with public officials, and the role of the intermediary. Practices often include screening, gathering ownership and background information, obtaining contractual anti-corruption representations and audit or termination rights, and periodic reassessment. Specific requirements vary by framework, jurisdiction, and organization, and this entry does not address particular tooling or legal advice.
How can gifts, hospitality, and facilitation payments be managed under an ABC programme?
Many programmes establish standards and procedures defining acceptable limits, approval thresholds, and recording requirements for gifts and hospitality, so that legitimate business courtesies are distinguished from improper inducements. Facilitation payments, small payments to expedite routine actions, are treated differently across jurisdictions; some legal regimes prohibit them, while others may permit narrow exceptions, so the applicable law should be confirmed for each context. Registers or logs are commonly used to create an evidence trail. This entry does not provide legal advice on whether a specific payment is permissible.
How does an ABC programme allocate responsibilities across an organization's lines of defence?
Under models such as the three lines model associated with the IIA, first line management typically owns and operates day-to-day ABC controls within business processes; a second line function, often compliance or a dedicated ethics function, commonly sets standards, provides oversight, and monitors adherence; and internal audit, as a third line, may provide independent assurance over the design and effectiveness of the programme. Maintaining the independence and objectivity of assurance activities from the management activities being reviewed is important, and the precise structure depends on organization size, sector, and governance arrangements.
How can the effectiveness of an ABC programme be monitored and demonstrated?
Monitoring commonly combines ongoing management activities, such as transaction reviews, exception reporting, training completion tracking, and management of a speak-up or whistleblowing channel, with periodic independent assurance. Effectiveness is typically evidenced through documentation showing that controls are designed appropriately and operating as intended, including records of due diligence, approvals, training, investigations, and remediation. Metrics and testing results may inform reporting to senior management and the board. What constitutes adequate evidence can vary by jurisdiction, sector, and applicable framework, and specific implementation methods are outside the scope of this entry.

Common misconceptions

Having an anti-bribery and corruption policy on paper is sufficient to demonstrate compliance.
A written policy is typically only one element. Regulators and standards commonly look for a program that operates in practice, including risk assessment, proportionate controls, training, monitoring, and evidence of implementation. A policy alone does not guarantee an adequate or effective program.
Anti-bribery and corruption obligations are the same everywhere.
Requirements and enforcement expectations vary by jurisdiction, sector, and the specific laws that apply to an organization. Matters such as the treatment of facilitation payments and the scope of liability for third-party conduct can differ significantly across legal regimes.
ABC is purely a compliance matter handled by the compliance function alone.
Anti-bribery and corruption spans compliance, risk management, and governance. It involves adherence to external laws and internal policy, assessment and treatment of corruption risk, and board or senior management oversight. Controls are owned and operated by management, while independent assurance over them is a separate activity.

Best practices

Ground the program in a periodic, documented bribery and corruption risk assessment, and align the scope and intensity of controls to the risks identified.
Apply risk-based due diligence to third parties and intermediaries, recognizing that the organization may be exposed for corrupt acts committed on its behalf.
Set clear, jurisdiction-aware rules for gifts, hospitality, and facilitation payments, and confirm the applicable legal treatment for each relevant jurisdiction rather than assuming a single standard.
Deliver targeted training to higher-risk roles and functions, and maintain confidential reporting channels with protection against retaliation where applicable.
Maintain accurate books, records, and program documentation, and keep management's monitoring activities distinct from independent assurance over the program's design and operation.
Establish clear governance, with defined accountability at senior management level and appropriate board or committee oversight, and review the program's continued suitability periodically.
Promotional banner for the Penetration Report Template Kit