4.5.3 - Existing Controls
ISO 37001
Understanding how and when your organization reviews its bribery risk assessments is key to ensuring the effectiveness of your anti-bribery management system.
How to Answer This Question
1. Define the Review Schedule : Clarify how often the bribery risk assessments are conducted. This should be at regular intervals or when significant changes occur in the organization or its environment that could impact the risk landscape.
2. Identify Trigger Events : Specify which circumstances or changes in the business environment trigger an off-cycle review of the bribery risks. This can include changes in law, operational shifts, entering new markets, or partnerships.
Why It’s Important
- Dynamic Risk Management : Regular and event-triggered reviews ensure that the organization’s approach to managing bribery risks remains relevant and effective against the backdrop of a changing corporate and regulatory environment.
- Compliance Assurance : Staying compliant with laws like the UK Bribery Act or the Foreign Corrupt Practices Act requires an adaptive risk management strategy that can only be achieved through regular reviews.
- Protect Reputation : Proactively managing and updating risk assessments helps prevent bribery incidents that could lead to financial penalties and damage to the organization's reputation.
Examples
- Example A: Multinational Corporation
- Context : Operates in multiple countries with varying corruption risk levels.
- Review Strategy : Annual reviews aligned with fiscal planning and immediate assessments when entering new markets or when significant legal changes occur.
- Outcome : Maintains compliance and adapts bribery prevention measures to reflect current risks.
- Example B: Small to Medium Enterprise (SME)
- Context : Operates primarily in low-risk environments but occasionally contracts with foreign governments.
- Review Strategy : Biennial reviews with additional assessments triggered by new government contracts.
- Outcome : Ensures that new engagements do not introduce unmitigated bribery risks, preserving business integrity and compliance.
For further reading on how to effectively review bribery risk assessments and adapt to changing circumstances, explore resources such as:
- Anti-Bribery Guidance | Transparency International : [Learn more about risk assessment](https://www.antibriberyguidance.org)
- PwC Australia's Guidelines : [Assessing the risk of bribery and corruption](https://www.pwc.com.au/pdf/assessing-the-risk-of-bribery-and-corruption-oct2016.pdf)
Regularly reviewing your bribery risk assessments in response to both scheduled timelines and specific trigger events ensures that your anti-bribery measures are robust, relevant, and capable of protecting your organization against bribery risks.