8.5.2 - Controls and due diligence for controlled organizations and business associates : Evaluating associates' anti-corruption controls
ISO 37001
The ISO 37001 Anti-Bribery Management Systems standard, instituted by the International Organization for Standardization in 2016, directs organizations globally in fortifying their anti-corruption frameworks. This standard is pivotal for both private and public entities of any size, focusing on active prevention, detection, and management of bribery risks.
How to Answer the Question
To assess if uncontrolled business associates have adequate anti-corruption controls in place, organizations should follow these steps:
1. Risk Assessment :
- Conduct initial and ongoing risk assessments of business associates to identify the level of corruption risk they may pose. This includes analyzing the business environment, the sector in which the associate operates, and the jurisdiction's corruption perception.
- For detailed guidelines on conducting risk assessments, refer to the [International Anti-Corruption Academy](https://www.iaca.int).
2. Due Diligence Procedures :
- Implement comprehensive due diligence processes that examine the associates' commitment to anti-corruption. This includes reviewing their past compliance records, reputation analysis, and financial stability.
- Utilize resources such as the [Global Infrastructure Anti-Corruption Centre (GIACC)](https://giaccentre.org) for guidance on corruption risk assessments.
3. Verification of Controls :
- Verify the existence and effectiveness of the associates' internal anti-corruption controls, policies, and training programs. This could involve requesting documentation, conducting interviews with key personnel, and, where possible, site visits.
- For a framework on verification processes, consult [Transparency International’s Anti-Bribery Guidance](https://www.antibriberyguidance.org).
Why It's Important
Understanding the robustness of business associates' anti-corruption controls is vital because:
- Mitigates Risks : Ensures that the organization is not indirectly involved in corrupt practices through its associates, thereby protecting against legal and reputational damage.
- Ensures Compliance : Helps maintain compliance with international anti-corruption regulations such as the UK Bribery Act and the US Foreign Corrupt Practices Act.
- Promotes Ethical Business Practices : Supports a culture of integrity and ethical behavior across the business network.
The [OECD’s guidelines on corporate governance](https://www.oecd.org) provide further insights into promoting ethical conduct among associates.
Examples
- Example A :
- Context : A multinational corporation partners with a local supplier in a high-risk jurisdiction.
- Action : The corporation conducts a detailed risk assessment followed by extensive due diligence, including financial audits and compliance checks.
- Outcome : The process identifies gaps in the supplier's anti-corruption measures, leading to the implementation of stronger controls and regular monitoring, aligning with best practices as recommended by the [Agence Française Anticorruption](https://www.agence-francaise-anticorruption.gouv.fr).
- Example B :
- Context : An IT firm outsources software development to a third-party developer.
- Action : The firm utilizes a third-party service to conduct background checks and reviews the developer’s existing anti-corruption policies and training records.
- Outcome : The review confirms the adequacy of the developer's anti-corruption controls, allowing the IT firm to proceed with the partnership confidently, supported by ongoing compliance reviews as outlined in [ISO 37001 Anti-Bribery Management Systems](https://www.iso.org/standard/65034.html).
These approaches illustrate effective strategies for evaluating and ensuring that business associates have adequate anti-corruption controls, crucial for maintaining a compliant and ethical business environment.