Skip to main content
Category: Ethics and Culture

Anti-Corruption Policy

Also known as: Anti-Bribery and Anti-Corruption Policy, Anti-Bribery and Corruption Policy, ABAC Policy, Global Anti-Corruption and Anti-Bribery Policy
Simply put

An anti-corruption policy is an internal document that sets out an organization's rules against bribery and other corrupt practices in its business dealings. It typically prohibits offering, promising, giving, requesting, or accepting anything of value to improperly gain or keep a business advantage, and it applies to conduct involving both government and private-sector parties. The policy states expected standards of conduct for employees and, in many cases, associated third parties.

Formal definition

An anti-corruption policy is a compliance instrument that establishes principles and prohibitions governing an organization's conduct with respect to bribery and corruption. Such policies commonly prohibit improper payments in both public- and private-sector dealings, forbidding the offering, promising, or giving of anything of value, as well as the accepting or receiving of bribes, to gain or retain a business advantage. They are frequently designed to support conformance with applicable anti-corruption legislation, for example, laws referenced in the evidence such as the U.S. Foreign Corrupt Practices Act and the UK Bribery Act (described in one source as effective from July 2011, which prohibits companies and their employees from accepting, receiving, and/or failing to prevent bribery). Applicability varies by jurisdiction, industry, and the organization's operating footprint; the specific legal obligations, extraterritorial reach, and enforcement authorities depend on the governing statutes and the entities involved. As a policy, it articulates required standards of conduct and expectations; it is distinct from the underlying laws it seeks to address and from the operational controls, due diligence procedures, and monitoring or assurance activities that implement and test adherence to it. This entry does not cover implementation specifics, control design, third-party due diligence procedures, tooling, or legal advice.

Why it matters

Corruption exposes an organization to legal, financial, and reputational consequences that can extend across the jurisdictions in which it operates. Anti-corruption statutes such as the U.S. Foreign Corrupt Practices Act and the UK Bribery Act reach conduct involving bribery and improper payments, and some of these laws carry extraterritorial effect, meaning that an organization's obligations may not be confined to the country in which it is headquartered. An anti-corruption policy gives an organization a documented, internally endorsed standard against which employee and, in many cases, third-party conduct can be measured, and it signals the organization's stated commitment to lawful business dealings.

The scope of exposure is broad because prohibited conduct commonly extends to both public- and private-sector dealings and to both sides of a corrupt transaction, offering or giving a bribe as well as requesting or accepting one. A policy that articulates these prohibitions helps establish expected standards of conduct before a decision point arises, rather than leaving individual employees to interpret ambiguous situations on their own. Because enforcement authorities, penalties, and the precise legal tests vary by governing statute and by the entities involved, the policy also serves to translate a patchwork of external obligations into a single internal expectation.

As a compliance instrument, an anti-corruption policy is distinct from the laws it addresses and from the controls, due diligence, and monitoring that give it operational effect. Its value therefore depends on the surrounding program: a stated prohibition sets expectations but does not by itself detect or prevent misconduct. Organizations typically treat the policy as the foundational statement of principle that the broader anti-bribery and corruption program is designed to support and enforce.

Who it's relevant to

Compliance Officers
Compliance officers typically own the drafting, maintenance, and communication of the anti-corruption policy and are responsible for aligning it with applicable anti-corruption legislation across the organization's operating jurisdictions. They also connect the policy to the broader anti-bribery and corruption program, including the due diligence and monitoring activities that implement it.
Legal and Regulatory Specialists
Legal and regulatory specialists advise on how statutes such as the U.S. Foreign Corrupt Practices Act and the UK Bribery Act apply to the organization, including questions of extraterritorial reach and the differing legal tests across jurisdictions. They help ensure the policy's prohibitions are consistent with the governing laws it is designed to address.
Employees and Associated Third Parties
Anti-corruption policies commonly set the standards of conduct expected of employees and, in many cases, extend expectations to associated third parties acting on the organization's behalf. These groups are the primary audience for the policy's prohibitions on offering, giving, requesting, or accepting anything of value to improperly gain or retain a business advantage.
Internal Auditors and Assurance Functions
Internal auditors and other assurance functions independently assess whether conduct adheres to the policy and whether the supporting controls operate effectively. Their role is distinct from management's ownership of the policy: they evaluate and test adherence rather than design or enforce the underlying controls.
Governance Bodies and Senior Management
Boards and senior management set the tone and endorse the organization's stated commitment to preventing corrupt business practices. They are typically accountable for approving the policy and for overseeing that the program supporting it is resourced and functioning.

Inside Anti-Corruption Policy

Policy Statement and Prohibited Conduct
A clear articulation of the organization's stance against corruption, typically prohibiting bribery, kickbacks, facilitation payments (where restricted), and both offering and receiving improper advantages. The scope commonly extends to public officials and private-sector counterparties, and often addresses direct and indirect conduct through third parties.
Scope and Applicability
A statement of who is covered, which may include employees, officers, directors, and in many cases agents, intermediaries, and business partners acting on the organization's behalf. Applicability frequently depends on jurisdiction, sector, and the reach of laws with extraterritorial effect, so the covered population should be defined in context rather than assumed universal.
Gifts, Hospitality, and Entertainment Provisions
Guidance distinguishing acceptable business courtesies from improper inducements, commonly including thresholds, approval requirements, and recording expectations. These provisions typically vary by jurisdiction and organizational risk appetite rather than following a single universal standard.
Third-Party and Due Diligence Expectations
Requirements addressing corruption risk arising through intermediaries, agents, distributors, and joint venture partners, often supported by risk-based due diligence and contractual protections. This is a governance and risk-management interface within the policy, as third-party conduct is a frequently cited exposure.
Roles, Responsibilities, and Governance
An allocation of decision rights and accountability, which may reference oversight by senior management or the board, ownership by a compliance function, and escalation paths. This component reflects the governance pillar by clarifying who directs, owns, and monitors the program.
Reporting, Escalation, and Non-Retaliation
Mechanisms for raising concerns, including confidential or anonymous channels where available, together with protection against retaliation. The specific requirements and legal protections commonly differ by jurisdiction.
Training, Monitoring, and Disciplinary Consequences
Provisions supporting awareness, ongoing monitoring of adherence, and consequences for violations. These describe how the policy is operationalized and enforced, though implementation specifics fall outside the policy document itself.

Common questions

Answers to the questions practitioners most commonly ask about Anti-Corruption Policy.

Is having an anti-corruption policy enough to demonstrate an effective compliance program?
No. A written anti-corruption policy is typically only one element of a broader program. Regulators and enforcement guidance in many jurisdictions commonly look for evidence that the policy is operationalized through risk assessment, training, due diligence, monitoring, and enforcement. A standalone document without supporting controls and demonstrable implementation is generally viewed as insufficient. The policy states expectations; it does not by itself establish that those expectations are being met.
Does an anti-corruption policy cover the same ground as an anti-money laundering (AML) program?
Not typically. These are distinct, though sometimes overlapping, areas. An anti-corruption policy commonly addresses bribery of, or by, officials and private parties, facilitation payments, gifts and hospitality, and third-party intermediaries. AML programs concern detecting and preventing the movement of illicit funds and generally involve different obligations, such as customer due diligence and suspicious activity reporting. The applicable laws, regulators, and control sets differ, and conflating them can leave gaps in either area.
Who typically owns and approves an anti-corruption policy within an organization?
Ownership and approval arrangements vary by organization size and structure. In many organizations the policy is drafted by a compliance or legal function (commonly a second-line responsibility) and approved by senior management or the board or a board committee, reflecting governance-level accountability. Day-to-day adherence is generally a first-line responsibility of operating management and staff. Independent assurance over the policy's effectiveness is typically provided by internal audit as a third-line activity. These distinctions matter for maintaining independence and objectivity.
How is an anti-corruption policy commonly connected to third-party and intermediary risk?
Because liability for corrupt acts can, in many jurisdictions, extend to conduct by agents, distributors, consultants, and other intermediaries, anti-corruption policies commonly reference risk-based due diligence on third parties, contractual anti-corruption provisions, and ongoing monitoring. The specific obligations and the extent of third-party liability depend on the applicable law and enforcement regime. This entry does not address the design of a particular due-diligence process, which involves implementation specifics beyond its scope.
How do organizations typically keep an anti-corruption policy current?
Policies are commonly reviewed on a periodic basis and on the occurrence of triggering events, such as changes in applicable laws, entry into new markets or jurisdictions, significant organizational change, or lessons learned from incidents or investigations. A defined review cadence and version control help demonstrate that the policy is maintained. The appropriate frequency varies by risk profile, jurisdiction, and sector, and this entry does not prescribe a specific interval.
How is adherence to an anti-corruption policy commonly monitored and evidenced?
Monitoring approaches vary, but organizations commonly use a combination of employee attestations, targeted training completion records, review of gifts and hospitality or conflict-of-interest disclosures, transaction and expense monitoring, and reporting or whistleblowing channels. Evidence of enforcement, including consistent disciplinary action, is often considered relevant to effectiveness. These are management and compliance activities; independent testing of whether the controls operate as intended is generally an assurance activity performed separately. Specific tooling and testing methods are outside the scope of this entry.

Common misconceptions

An anti-corruption policy only concerns bribery of government officials.
While bribery of public officials is a central concern in many legal regimes, anti-corruption policies commonly also address commercial (private-sector) bribery, kickbacks, and improper advantages, depending on the applicable laws and the organization's risk profile. The precise scope varies by jurisdiction.
Having an anti-corruption policy demonstrates compliance and prevents corruption.
A policy is a governance instrument that states expectations; it does not by itself guarantee outcomes. In many frameworks a policy is expected to be supported by controls, due diligence, training, monitoring, and enforcement. Assurance over the policy's operation is distinct from the policy itself and from management's execution of it.
Facilitation payments are treated the same everywhere, so one global rule suffices.
The treatment of facilitation payments differs across jurisdictions, with some legal regimes prohibiting them and others permitting narrow exceptions. Organizations commonly adopt a defined position in context rather than assuming a single universal rule applies.

Best practices

Define the covered population and geographic and sectoral scope explicitly, accounting for laws with extraterritorial reach rather than assuming universal application.
Establish clear ownership and governance, allocating decision rights, senior or board-level oversight, and escalation paths so accountability for the program is unambiguous.
Apply risk-based due diligence to third parties, intermediaries, and business partners, supported by contractual protections addressing corruption risk.
Set defined, context-appropriate thresholds and approval and recording requirements for gifts, hospitality, and entertainment, aligned to the organization's risk appetite and applicable law.
Provide confidential reporting channels with non-retaliation protection, reflecting the protections available in the relevant jurisdictions.
Support the policy with training, ongoing monitoring, and defined disciplinary consequences, and keep independent assurance over the program separate from the management activities being reviewed.
Application Security Isn’t Optional Anymore.