8.2 - Due diligence : Assessment of corruption risk

ISO 37001

The ISO 37001 Anti-Bribery Management Systems standard, instituted by the International Organization for Standardization in 2016, directs organizations globally in fortifying their anti-corruption frameworks. This standard is pivotal for both private and public entities of any size, focusing on active prevention, detection, and management of bribery risks.

How to Answer the Question

When addressing how an organization plans, implements, reviews, and controls processes to meet the requirements of the anti-corruption management system, consider these steps:

1.   Planning  :

  -   Define Objectives  : Start by defining clear anti-corruption objectives aligned with the organization's overall strategy and compliance requirements.

  -   Risk Assessment  : Conduct thorough risk assessments to tailor the processes to the specific risks identified at various organizational levels.

2.   Implementation  :

  -   Process Design  : Design processes that address the identified risks and incorporate controls to mitigate these risks.

  -   Resource Allocation  : Ensure adequate resources are allocated, including training and technological support.

3.   Review and Monitoring  :

  -   Continuous Monitoring  : Establish continuous monitoring mechanisms to ensure processes are functioning as intended.

  -   Regular Reviews  : Conduct regular reviews of the processes to assess effectiveness and make necessary adjustments.

4.   Control  :

  -   Adjustments and Improvements  : Implement controls for making necessary adjustments based on feedback and changing conditions.

  -   Documentation and Evidence  : Maintain comprehensive documentation to support compliance and facilitate audits.

For further guidance on establishing and maintaining these processes, resources such as the [ISO 37001 Anti-Bribery Management Systems](https://www.iso.org/standard/65034.html) can provide valuable insights.

Why It's Important

The importance of planning, implementing, reviewing, and controlling anti-corruption processes within an organization includes:

-   Ensuring Compliance  : Helps ensure compliance with legal standards and international anti-corruption regulations.

-   Building Integrity  : Strengthens the integrity and transparency of the organization’s operations.

-   Preventing Corruption  : Proactively prevents corruption and bribery through effective management and control of internal and external risks.

Examples

-   Example A  :

 -   Context  : A global financial institution implements a new anti-corruption process in response to updated international bribery laws.

 -   Action  : The institution conducts an enterprise-wide risk assessment, updates its compliance procedures, and introduces a sophisticated monitoring system.

 -   Outcome  : Enhanced detection of potential bribery activities and improved compliance with international anti-corruption regulations.

-   Example B  :

 -   Context  : A manufacturing company identifies a high risk of corruption in its supply chain.

 -   Action  : It develops specific anti-corruption training for its procurement team and establishes strict vendor screening processes.

 -   Outcome  : Reduced corruption risks in the supply chain and stronger partnerships with vendors committed to ethical business practices.

For detailed case studies and more on how companies can effectively manage anti-corruption processes, consider visiting the [Agence Française Anticorruption](https://www.agence-francaise-anticorruption.gouv.fr) and reviewing their guidelines.