Anti-Bribery and Corruption Policy: Scope, Controls, and Reporting

An anti-bribery and corruption policy has to do three things at once: define what conduct is forbidden, bind everyone connected to the organization to those rules, and build the controls, reporting channels, and response procedures that regulators expect to see when something goes wrong. Get any of those three wrong and the policy stops functioning as a defense. Under the UK Bribery Act, a company whose associated person pays a bribe is strictly liable unless it can prove “adequate procedures” were in place;1Legislation.gov.uk. Bribery Act 2010 – Section 72Office of the Law Revision Counsel. 15 US Code 78dd-2 – Prohibited Foreign Trade Practices by Domestic Concerns3Office of the Law Revision Counsel. 18 US Code 3571 – Sentence of Fine The sections below cover what the document itself must contain.

Conduct the Policy Must Prohibit

At its core, the policy forbids offering, promising, or giving anything of value to influence a decision or gain an unfair business advantage. That language has to be broad enough to cover obvious cash payments and subtler forms of corruption like kickbacks, where a portion of a contract payment is funneled back to whoever steered the deal. It also has to name the categories that most often disguise a bribe: gifts, travel, entertainment, and charitable donations.

The prohibitions apply to everyone connected to the organization: officers, directors, employees, contractors, temporary staff, and any third party acting on the company’s behalf. Corruption law does not respect org charts, and liability regularly flows from an agent’s conduct to the company that engaged them.

Facilitating payments — small sums paid to speed routine government actions like visa processing or mail delivery — are the one area where the two dominant frameworks disagree. The FCPA carves out a narrow exception for non-discretionary actions a government official is already required to perform. The UK Bribery Act offers no such exception. Because most multinational companies need to comply with both, a well-drafted policy prohibits facilitating payments across the board to meet the stricter standard. Any company that wants to preserve the FCPA exception for specific operations should document those circumstances carefully and require senior approval before any such payment is made.

Do not narrow the policy to foreign or public officials only. Commercial bribery between private parties can be prosecuted federally through the Travel Act when interstate commerce is involved, carrying up to five years in prison.4Office of the Law Revision Counsel. 18 US Code 1952 – Interstate and Foreign Travel or Transportation in Aid of Racketeering Enterprises Bribing a purchasing manager at a private company to win a contract is a federal criminal risk, and the policy needs to say so.

Gifts, Hospitality, and Business Expenses

Business relationships involve meals, event tickets, and small gifts, and no serious anti-bribery framework expects those to disappear. The policy’s job is to draw a bright line between a working lunch and an attempt to buy influence. Expenses should be proportionate to the business relationship, openly documented, and never timed to coincide with a pending decision that could benefit the giver.

Most policies set a dollar threshold — commonly in the $50 to $100 range — below which gifts can be given or accepted without prior approval, with anything above the threshold requiring written authorization from a supervisor or compliance officer. The number matters less than the discipline around it. If nobody enforces it, it becomes decorative language that will not help in an investigation. During active bidding or procurement cycles, the safest approach is a complete blackout on gifts and hospitality to anyone involved in the selection process.

Every permitted expense should be recorded with enough detail to survive an audit: who was involved, the business purpose, the amount, and any approvals obtained. That documentation directly supports the FCPA’s affirmative defense for reasonable business expenditures related to product promotion or contract performance.

Charitable and Political Contributions

Donations and sponsorships are a well-documented vehicle for disguised bribery. A company donates to a charity controlled by a foreign official’s family, or sponsors an event that primarily benefits a decision-maker, and the payment never appears as a bribe in any ledger. The FCPA treats charitable and political contributions as “anything of value,” and enforcement actions have targeted donations made to organizations connected to officials who were evaluating the donor’s business proposals.

The policy should require that all charitable contributions be reviewed and approved through a designated channel before any commitment is made. The review should verify that the recipient is legitimate, that no government official with influence over the company’s business has a financial interest in the charity, and that the contribution is documented in detail. Political contributions carry similar risks and typically warrant the same level of scrutiny, particularly in jurisdictions where the line between government and private enterprise is blurred.

Third-Party Due Diligence

Agents, consultants, distributors, and joint venture partners represent the single largest area of corruption risk for most organizations. When a third party pays a bribe on your behalf, the company faces liability even if no one at headquarters knew about it. Pre-engagement due diligence is not optional.

Before hiring any intermediary who will interact with government officials or handle significant business on your behalf, the policy should require a background check covering the party’s ownership structure, any history of corruption allegations, political connections, and financial health. Red flags that should trigger deeper investigation include:

  • Vague invoice descriptions like “marketing services” or “special commissions” without supporting documentation.
  • Unusual payment requests, such as funds routed to offshore accounts, paid in cash, or directed to a different entity than the one under contract.
  • Commission rates or consulting fees that significantly exceed market norms for the service provided.
  • Ownership or close family ties between the third party and a government official who can influence your business.

Contracts with third parties should include anti-corruption clauses granting the company the right to audit the intermediary’s books and terminate the relationship immediately if a violation is discovered. Those clauses are not just protective language for litigation. They create the framework for ongoing monitoring, which regulators expect to see when evaluating the adequacy of a compliance program.

Acquisitions and Inherited Liability

When a company acquires another business, it can inherit liability for corrupt acts the target committed before closing. Pre-acquisition due diligence should include a corruption risk assessment, and any issues discovered should be factored into deal terms. If problems surface after closing, the DOJ’s Corporate Enforcement Policy creates a path forward: companies that voluntarily disclose the inherited misconduct, cooperate fully, and remediate the problems are presumptively eligible for a declination of prosecution.5U.S. Department of Justice. Criminal Division Corporate Enforcement and Voluntary Self-Disclosure Policy The company still has to disgorge profits from the violation, but avoiding prosecution is materially better than facing criminal charges for someone else’s misconduct.

Books, Records, and Internal Controls

The FCPA’s accounting provisions require publicly traded companies to keep books and records that accurately reflect all transactions, and to maintain internal controls sufficient to ensure that assets are used only as management authorizes.6Office of the Law Revision Counsel. 15 US Code 78m – Periodical and Other Reports These provisions operate independently from the anti-bribery rules. A company can violate the books-and-records requirement without anyone proving a bribe was paid, simply by failing to record a transaction accurately.

Financial systems have to be designed to prevent off-the-books funds and to flag accounting entries that do not match the underlying transaction. Bribes are routinely disguised as consulting fees, travel reimbursements, or commissions. Internal controls should require that every payment has a legitimate business justification, that descriptions match the actual service provided, and that payments above set thresholds receive independent approval.

The statutory standard is “reasonable assurance,” not perfection, defined as the level of detail and assurance that would satisfy a prudent official managing their own affairs.6Office of the Law Revision Counsel. 15 US Code 78m – Periodical and Other Reports Regulators do not expect every irregularity to be caught, but they do expect a system designed to catch them and periodically tested. An organization that discovers a control weakness during an internal audit and fixes it promptly is in a far better position than one that never looked.

Reporting Channels and Whistleblower Protection

A policy that prohibits corruption but provides no safe way to report it is incomplete. Employees need clear instructions on how to raise concerns, and credible assurance that doing so will not cost them their job.

Under the Sarbanes-Oxley Act, publicly traded companies and their affiliates are prohibited from retaliating against employees who report conduct they reasonably believe violates federal fraud laws or SEC regulations. Protected activity includes reporting to a federal agency, a member of Congress, or a supervisor within the company. An employee who experiences retaliation can file a complaint with the Department of Labor within 180 days and is entitled to reinstatement, back pay with interest, and reasonable attorney fees if they prevail.7Occupational Safety and Health Administration. Sarbanes-Oxley Act (SOX) The right to those remedies cannot be waived by any employment agreement or predispute arbitration clause.

The SEC’s whistleblower program adds a financial incentive. When original information leads to an enforcement action with sanctions exceeding $1 million, the whistleblower is eligible for an award of 10 to 30 percent of the money collected.8U.S. Securities and Exchange Commission. Whistleblower Program Since the program’s launch in 2011, the SEC has paid more than $2.2 billion to 444 individual whistleblowers.9U.S. Securities and Exchange Commission. Fiscal Year 2024 Annual Report to Congress – Whistleblower Program Those numbers give real weight to internal reporting channels. If employees do not trust the company’s hotline, they have every reason to go directly to the SEC.

The policy should designate a dedicated reporting mechanism, whether that is a compliance hotline, an email address, or a third-party reporting platform, and guarantee that reports can be made anonymously where local law permits. Every report should trigger a documented investigation with a defined timeline for resolution.

Responding to a Violation

How a company responds when it discovers a potential violation is often more consequential than the violation itself. The DOJ’s Corporate Enforcement Policy establishes a presumption that companies which voluntarily self-disclose, fully cooperate, and remediate the problem will receive a declination of prosecution.5U.S. Department of Justice. Criminal Division Corporate Enforcement and Voluntary Self-Disclosure Policy The company still has to disgorge profits from the misconduct, but avoiding prosecution preserves the ability to do business with governments and avoids the cascading reputational damage of an indictment.

To qualify, the disclosure must reach the Criminal Division before the government discovers the issue on its own. The company needs to turn over all relevant facts, including information about every individual involved regardless of seniority, and take concrete remedial steps like disciplining responsible employees and fixing the compliance failures that allowed the misconduct. Even when aggravating factors are present, such as executive involvement or repeat offenses, the company can still receive a significant reduction in any fine if it meets those cooperation standards.5U.S. Department of Justice. Criminal Division Corporate Enforcement and Voluntary Self-Disclosure Policy

The policy should spell out the internal escalation process: who conducts the investigation, when outside counsel is brought in, and at what point the board is notified. Building that framework before a crisis hits prevents the panicked, ad hoc decision-making that prosecutors read as evidence of a weak compliance culture.

Adopting, Training, and Keeping the Policy Current

Before drafting, map where the corruption risk actually lives. Identify the jurisdictions where the company operates or plans to expand; the Transparency International Corruption Perceptions Index, which ranks countries on a scale of 0 (highly corrupt) to 100 (very clean), is a useful starting point.10Transparency International. Corruption Perceptions Index 2025 Legal counsel should then identify which statutes apply, keeping in mind that laws like the FCPA and the UK Bribery Act reach conduct that occurs entirely outside the enacting country’s borders.

Drafting requires concrete decisions, not just principles. Set the specific dollar thresholds for gift approvals. Define who has authority to approve expenditures above those thresholds. Choose the reporting channels and decide whether anonymous reporting will be permitted. Designate a compliance officer with genuine authority to investigate and the ability to report directly to the board without being filtered through management layers that might have an interest in suppressing bad news.

Once the policy is finalized, formal adoption by the board or senior leadership signals organizational commitment and provides the mandate for enforcement. Distribution to the entire workforce is the minimum. More important is training that walks employees through realistic scenarios: the vendor who offers to “take care of” a customs delay, the government contact who asks for a donation to a local charity before approving a permit, the joint venture partner whose invoices do not add up. Each employee should sign an acknowledgment confirming they have read and will comply with the policy, and those records should be stored permanently.11U.S. Securities and Exchange Commission. EuroDry Ltd. Code of Ethics and Anti-Bribery Policy

The policy is not a one-time document. Annual reviews should incorporate lessons from internal investigations, changes in the regulatory environment, and updates to the jurisdictions where the company does business. A policy that was adequate five years ago may have gaps today, and regulators evaluate compliance programs based on their current state, not their original design.