An effective anti-bribery programme is assessed on three questions: is it well designed, is it adequately resourced and empowered, and does it work in practice.
Risk assessment driving the programme, updated as the business changes, covering countries of operation, government touchpoints, third-party channels, transaction types and industry.
Policies and procedures accessible in the languages of the workforce, covering gifts and hospitality, facilitation payments, charitable and political contributions, third-party engagement, and books and records.
Training targeted at the population facing the risk, with attendance and comprehension evidenced.
Third-party management with risk-based diligence, contract terms, payment controls and ongoing monitoring.
Mergers and acquisitions diligence and post-acquisition integration, including audits and training within a defined period.
Reporting channels and investigation capability.
Incentives and discipline — compensation structures that do not reward results without regard to how they were achieved, and consistent discipline.
Testing. Transaction testing, audits of high-risk operations, and data analytics on payments, expenses and third-party invoices.
Continuous improvement. Evidence that the programme changed in response to findings is what distinguishes a real programme from a paper one.