5.2 - Anti-bribery policy : Compliance function authority

ISO 37001

How to Answer the Question

To effectively address how the anti-corruption policy defines the authority and independence of the compliance function, focus on these aspects:

-   Position and Authority:   Detail where the compliance function is positioned within the organizational hierarchy, emphasizing its direct access to the board or senior management, which underscores its authority and importance.

-   Independence:   Describe the measures that ensure the compliance function operates independently, such as provisions for its autonomous decision-making and unhindered access to all necessary company information and resources.

-   Roles and Responsibilities:   Clarify the specific roles and responsibilities assigned to the compliance function, including the authority to investigate, audit, and enforce compliance across the organization.

For a practical understanding of setting up such a governance structure, refer to guidelines from the [Agence Française Anticorruption](https://www.agence-francaise-anticorruption.gouv.fr).

Why It's Important

The clear definition of authority and independence for the compliance function is critical because:

-   Ensures Effectiveness:   Independent and well-empowered compliance functions are more effective at detecting and addressing corruption without interference.

-   Builds Credibility:   An independent compliance function enhances the credibility of the organization's anti-corruption efforts both internally and externally.

-   Supports Compliance:   It supports comprehensive compliance with legal requirements and ethical standards by having the authority to act decisively.

Insights on compliance structures can be further explored at [OECD’s Corporate Anti-corruption Compliance Drivers and Mechanisms](https://www.oecd.org).

Examples

-   Example A:  

 -   Context:   A financial institution has established a compliance office that reports directly to the audit committee of the board, ensuring it has the necessary authority and independence to oversee anti-corruption measures.

 -   Resources Deployed:   Regular training sessions for the compliance team, dedicated investigation unit.

 -   Outcome:   Effective handling of compliance issues with several high-risk transactions identified and mitigated.

 Additional information on compliance reporting structures can be found in [UNODC’s Guide on Anti-Corruption Policies](https://www.unodc.org).

-   Example B:  

 -   Context:   A multinational corporation has integrated its compliance function within its risk management framework, giving it autonomy to operate across all business units globally.

 -   Resources Deployed:   State-of-the-art compliance software, direct reporting lines to the CEO.

 -   Outcome:   Streamlined compliance processes and reduced incidents of bribery and corruption.

Learn more about integrating compliance functions from [International Anti-Corruption Academy’s Standards and Guidelines](https://www.iaca.int).