8.5.2 - Controls and due diligence for controlled organizations and business associates : Evaluating associates' anti-corruption controls
ISO 37001
The ISO 37001 Anti-Bribery Management Systems standard, instituted by the International Organization for Standardization in 2016, directs organizations globally in fortifying their anti-corruption frameworks. This standard is pivotal for both private and public entities of any size, focusing on active prevention, detection, and management of bribery risks.
How to Answer the Question
To assess if uncontrolled business associates have adequate anti-corruption controls in place, organizations should follow these steps:
1. Risk Assessment :
- Conduct initial and ongoing risk assessments of business associates to identify the level of corruption risk they may pose. This includes analyzing the business environment, the sector in which the associate operates, and the jurisdiction's corruption perception.
- For detailed guidelines on conducting risk assessments, refer to the [International Anti-Corruption Academy](https://www.iaca.int).
2. Due Diligence Procedures :
- Implement comprehensive due diligence processes that examine the associates' commitment to anti-corruption. This includes reviewing their past compliance records, reputation analysis, and financial stability.
- Utilize resources such as the [Global Infrastructure Anti-Corruption Centre (GIACC)](https://giaccentre.org) for guidance on corruption risk assessments.
3. Verification of Controls :
- Verify the existence and effectiveness of the associates' internal anti-corruption controls, policies, and training programs. This could involve requesting documentation, conducting interviews with key personnel, and, where possible, site visits.
- For a framework on verification processes, consult [Transparency International’s Anti-Bribery Guidance](https://www.antibriberyguidance.org).
Why It's Important
Understanding the robustness of business associates' anti-corruption controls is vital because:
- Mitigates Risks : Ensures that the organization is not indirectly involved in corrupt practices through its associates, thereby protecting against legal and reputational damage.
- Ensures Compliance : Helps maintain compliance with international anti-corruption regulations such as the UK Bribery Act and the US Foreign Corrupt Practices Act.
- Promotes Ethical Business Practices : Supports a culture of integrity and ethical behavior across the business network.
The [OECD’s guidelines on corporate governance](https://www.oecd.org) provide further insights into promoting ethical conduct among associates.
Examples
- Example A :
- Context : A multinational corporation partners with a local supplier in a high-risk jurisdiction.
- Action : The corporation conducts a detailed risk assessment followed by extensive due diligence, including financial audits and compliance checks.
- Outcome : The process identifies gaps in the supplier's anti-corruption measures, leading to the implementation of stronger controls and regular monitoring, aligning with best practices as recommended by the [Agence Française Anticorruption](https://www.agence-francaise-anticorruption.gouv.fr).
- Example B :
- Context : An IT firm outsources software development to a third-party developer.
- Action : The firm utilizes a third-party service to conduct background checks and reviews the developer’s existing anti-corruption policies and training records.
- Outcome : The review confirms the adequacy of the developer's anti-corruption controls, allowing the IT firm to proceed with the partnership confidently, supported by ongoing compliance reviews as outlined in [ISO 37001 Anti-Bribery Management Systems](https://www.iso.org/standard/65034.html).
These approaches illustrate effective strategies for evaluating and ensuring that business associates have adequate anti-corruption controls, crucial for maintaining a compliant and ethical business environment.
Also in
Operation and planning
- 8.1 - Operation and planning : Planning and control of anti-corruption processes
- 8.2 - Due diligence : Assessment of corruption risk
- 8.3 - Financial controls : Financial controls against corruption
- 8.4 - Non-financial controls : Non-financial controls against corruption
- 8.5.1 - Controls and due diligence for controlled organizations and business associates : Enforcement of anti-corruption system for associates
- 8.6 - anti-bribery commitments : Commitment of business associates to prevent corruption
- 8.7 - Gifts, donations and benefits : Procedures against improper benefits
- 8.8 - Managing inadequate anti-bribery controls : Handling unmanageable corruption risks
- 8.9 - Raising concerns : Facilitating corruption reporting
- 8.9 - Raising concerns : Confidentiality of reporting process
- 8.9 - Raising concerns : Allowance for anonymous reports
- 8.9 - Raising concerns : Protection against retaliation for reporting
- 8.9 - Raising concerns : Establishing a corruption concern point of contact
- 8.9 - Raising concerns : Familiarizing personnel with reporting procedures
- 8.10 - Investigating and dealing with cases of bribery : Investigating reported corruption concerns
- 8.10 - Investigating and dealing with cases of bribery : Actions required upon discovering corruption
- 8.10 - Investigating and dealing with cases of bribery : Empowering investigators
- 8.10 - Investigating and dealing with cases of bribery : Ensuring cooperation in investigations
- 8.10 - Investigating and dealing with cases of bribery : Reporting investigation outcomes to compliance
- 8.10 - Investigating and dealing with cases of bribery : Confidentiality of investigation results
- 8.10 - Investigating and dealing with cases of bribery : Independence of investigators