Why this matters
ICA identified the EU Anti-Corruption Directive as a defining 2026 compliance development. The direction of travel is toward greater consistency in offences, liability and enforcement across European jurisdictions.
Risk assessment
Multinationals should assess corruption exposure by jurisdiction, business model, government interaction, intermediaries, procurement, gifts and hospitality, sponsorship, charitable giving and mergers and acquisitions.
Third parties
Agents, distributors, introducers and consultants remain central corruption risks. Due diligence should examine ownership, competence, commercial rationale, remuneration and the legitimacy of services provided.
Controls and evidence
Effective programmes should connect risk assessment to approval thresholds, contracting, payment controls, training, monitoring and investigation. A policy that is disconnected from actual commercial processes will provide limited protection.
Cross-border consistency
Groups should establish common minimum standards while preserving the ability to address stricter local rules. Governance should identify who owns exceptions and how local deviations are reported centrally.
Conclusion
The emerging EU framework should encourage firms to treat anti-corruption compliance as an operating system rather than a code of conduct. The strongest programmes will integrate risk assessment, third-party governance, financial controls and investigation data.
Practical actions for compliance leaders
- Assign clear ownership and document decision rights.
- Test control effectiveness using actual case outcomes rather than policy completion alone.
- Escalate ambiguous or high-consequence cases to appropriately skilled reviewers.
- Track exceptions, quality assurance findings and recurring root causes.
Related reading
See Governance, Risk and Compliance, Corporate Governance and Regulatory Compliance.
About the author
Jonas Adam Mohamed Osman Abdelghafour writes about governance, risk and compliance, anti-money laundering, financial crime prevention, sanctions, customer due diligence, AI governance, model risk and regulatory risk. See About and Qualifications.
Source and editorial context
This is original analysis informed by a current compliance theme highlighted by the International Compliance Association. No affiliation with or endorsement by ICA is claimed or implied.
Frequently asked questions
Why this matters?
ICA identified the EU Anti-Corruption Directive as a defining 2026 compliance development. The direction of travel is toward greater consistency in offences, liability and enforcement across European jurisdictions.
What should risk leaders know about risk assessment?
Multinationals should assess corruption exposure by jurisdiction, business model, government interaction, intermediaries, procurement, gifts and hospitality, sponsorship, charitable giving and mergers and acquisitions.
What should risk leaders know about third parties?
Agents, distributors, introducers and consultants remain central corruption risks. Due diligence should examine ownership, competence, commercial rationale, remuneration and the legitimacy of services provided.
What should risk leaders know about controls and evidence?
Effective programmes should connect risk assessment to approval thresholds, contracting, payment controls, training, monitoring and investigation. A policy that is disconnected from actual commercial processes will provide limited protection.
What should risk leaders know about cross-border consistency?
Groups should establish common minimum standards while preserving the ability to address stricter local rules. Governance should identify who owns exceptions and how local deviations are reported centrally.