In today's business environment, compliance has moved from a purely voluntary initiative to a firm legal requirement. International anti-corruption legislation and standards such as ISO 37001 (anti-bribery management systems) require organisations to develop and implement measures to prevent corruption.
Requirements have only grown stricter: a wide range of companies must now maintain an internal compliance policy, appoint a responsible person (a compliance officer) and carry out an annual assessment of corruption risks.
The legal essentials. Anti-corruption law obliges organisations to take measures to prevent corruption - a direct legal mandate to build a compliance system. For public-procurement contractors, state-owned companies and natural monopolies, having an internal compliance policy has become mandatory.
A well-designed anti-corruption policy is not a mere formality: when courts assess an organisation's culpability, the decisive factor is whether the company adopted comprehensive anti-corruption mechanisms. Naturally, executives face the question: how do you build an effective control system without overdoing it?
A risk-based approach: control what truly matters
The first step toward a balanced system is adopting a Risk-Based Approach. The idea is simple: resources go to the most vulnerable areas rather than to blanket checks on everyone.
The risk formula. Corruption risk is defined as the probability of a corruption event multiplied by the scale of potential harm. Most processes carry a low level of risk and do not require intensive control.
How to put a risk-based approach into practice:
Analyse your business processes and pinpoint areas of heightened vulnerability: procurement, work with contractors, dealings with government authorities, and personnel decisions.
Sort the identified risks by their potential severity. In practice, most processes carry a low level of risk and do not require intensive control.
Concentrate your main control procedures on high-risk areas, and limit the rest to basic monitoring.
Keep documented records of all identified risks and update them regularly.
This approach prevents resources from being spread too thin and gives management a clear picture of where control is genuinely needed and where employees can be relied upon.
The risk of a box-ticking approach. A token anti-corruption policy offers no protection. When assessing an organisation's culpability, courts consider whether comprehensive mechanisms were adopted. An empty risk register, a policy with no training, and the absence of a secure whistleblowing channel are typical weaknesses that auditors will spot first.
Practical steps toward a balanced compliance control system
To build a system that is both effective and humane, we recommend the following plan of action. These are the six building blocks of internal control:
| Block | What to implement | Why |
|---|---|---|
| 1. Internal policies | An anti-corruption policy and a code of ethics as internal documents | An anti-corruption policy is a set of principles, procedures and measures for preventing and stopping corruption-related offences |
| 2. Accountability | A unit or officer with the authority and resources to act | A clear area of responsibility for anti-corruption compliance |
| 3. Training | Training sessions and information materials | Explaining anti-corruption requirements to employees |
| 4. Integration | Embedding measures into real working processes | Tailoring to the company's specifics rather than existing for show |
| 5. Audit | Regular review and updating of the policy | The system evolves with the business and stays effective |
| 6. Whistleblower protection | Confidential channels with protection from retaliation | Safe reporting of violations without fear of reprisal |
An anti-corruption policy is a set of interconnected principles, procedures and measures aimed at preventing and stopping corruption-related offences.- OECD anti-bribery guidance
We will help you build compliance around your specifics
The consulting firm G-Invest conducts compliance audits, develops anti-corruption policies and internal regulations, trains staff and builds risk-based control systems - focused on genuinely high-risk areas rather than blanket surveillance. We support M&A deals with anti-corruption due diligence of counterparties and work directly with owners and top management.
Frequently asked questions
What is anti-corruption compliance, and is it mandatory for every company?
Anti-corruption compliance is a system of internal controls and procedures designed to meet the requirements of anti-corruption law and to prevent corruption-related offences in an organisation's activities. Anti-corruption legislation and standards such as ISO 37001 require all organisations to develop and adopt measures to prevent corruption, which is a direct legal mandate to build a compliance system. For state-owned companies and natural monopolies, having an internal compliance policy has become a mandatory requirement.
How can a small company with a limited budget implement anti-corruption compliance?
Small and medium-sized businesses do not need a bloated team of compliance officers. It is enough to implement the minimum necessary elements: develop an anti-corruption policy, appoint a responsible person (this can be a part-time employee), provide basic staff training, and introduce simple mechanisms for identifying conflicts of interest and reporting violations. The key is to record the measures adopted in the company's internal documents, since courts assessing an organisation's culpability take into account the very fact that anti-corruption mechanisms exist.
What anti-corruption measures should a company's anti-corruption policy include?
A modern anti-corruption system includes several key elements: 1) designating the units and individuals responsible for countering corruption; 2) developing an anti-corruption policy, ethical standards and codes of conduct; 3) implementing mechanisms to prevent and resolve conflicts of interest; 4) regular employee training; 5) assessing and auditing corruption risks; 6) cooperating with law enforcement. The measures should be tailored to the company's specifics and integrated into real business processes.
How do you build a culture of compliance and ethics rather than just formal control?
A culture of compliance rests on several principles: complete clarity and transparency of the rules for employees; leadership setting a personal example in upholding ethical standards; an incentive system that rewards achieving results the right way; safe channels for reporting violations without fear of reprisal; and recognising and rewarding integrity on a par with performance. In organisations with a mature ethical culture, people understand not only what is forbidden but also how to do things right.
Where can I commission the implementation of a compliance system and the development of an anti-corruption policy?
The consulting firm G-Invest provides a full range of compliance services: conducting compliance audits, developing anti-corruption policies and internal regulations, training staff, and building risk-based control systems. G-Invest works directly with company owners and top management, offering pragmatic solutions tailored to each business's specific needs.