Join our Newsletter — 33% off our NHI Course
Home FAQ Foundations & NHI Taxonomy How should compliance teams structure an anti-corruption programme…
Foundations & NHI Taxonomy

How should compliance teams structure an anti-corruption programme to meet Sapin II expectations?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated September 23, 2026 Domain: Foundations & NHI Taxonomy

A Sapin II programme should combine formal governance with practical controls. Core elements include a code of conduct, whistleblowing channels, risk mapping, third-party due diligence, accounting controls, employee and manager training, disciplinary measures, and internal controls. The strongest programmes treat these as a connected system, not a checklist, and keep the risk map and monitoring processes current as the business changes.

How to structure Sapin II anti-corruption controls as a programme

A Sapin II programme works best when the controls reinforce one another. The code of conduct sets expectations, the whistleblowing channel creates intake, risk mapping focuses attention, third-party due diligence extends that discipline outward, accounting controls and internal controls detect irregular behaviour, and training plus disciplinary measures make the programme usable in day-to-day operations. The question is not whether each item exists, but whether they operate as a managed system with ownership, review cadence, and evidence of follow-through.

That system view matters because compliance teams often overbuild policies and underbuild operating rhythm. A programme that is documented but not refreshed, or that treats due diligence, accounting review, and monitoring as separate workstreams, usually becomes brittle when business models, geographies, intermediaries, or payment flows change. Current guidance is strongest when the risk map drives control intensity and the programme can show that findings feed back into remediation.

  • Use the code of conduct to define prohibited conduct and escalation thresholds.
  • Route whistleblowing, investigations, and remediation through a clear ownership model.
  • Keep third-party due diligence, accounting controls, and monitoring aligned to the risk map rather than to a fixed annual checklist.
  • Retain evidence that training, reviews, and disciplinary follow-up actually occurred.

For a control-structure benchmark, many teams map the programme to a formal management-system pattern such as ISO/IEC 27001:2022 Information Security Management and its companion control guidance in ISO/IEC 27002:2022 Information Security Controls, because both push governance, control ownership, and continuous improvement rather than one-off policy publication.

What makes a Sapin II programme operationally credible

Operational credibility comes from making the programme testable. A credible design has a current risk map, documented review of third parties and intermediaries, accounting controls that are actually sampled, training that reaches both employees and managers, and disciplinary measures that are applied when rules are breached. The programme should also distinguish between policy ownership and operational execution, because the people writing the standard are not always the ones who can verify invoices, approvals, gifts, hospitality, commissions, or unusual payments.

The most common weakness is fragmentation. Anti-corruption programmes fail when legal, compliance, finance, procurement, and HR each hold a piece of the design but no one owns the control chain end to end. Sapin II expectations are better met when the programme shows how a concern travels from detection to investigation to remediation, and how lessons learned change the next risk assessment. That makes the programme auditable in a practical sense, not just in a policy sense.

  • Make one function accountable for the control framework and another accountable for control testing.
  • Update the risk map when markets, entities, agents, distributors, or payment channels change.
  • Test whether accounting controls can detect the specific corruption patterns your business actually uses.
  • Use training records and case handling records as evidence of implementation, not as a substitute for it.

Where the programme extends to third parties and channels with elevated exposure, the control logic is similar to vendor-risk and trust-boundary governance in SOC 2 Trust Services Criteria (AICPA) and CSA Cloud Controls Matrix, where responsibility, monitoring, and evidence are expected to hold across internal and external dependencies.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

ISO/IEC 27001:2022 provides the primary governance reference for this topic.

FrameworkControl / ReferenceRelevance
ISO/IEC 27001:2022A.5.2 — Anti-bribery and Corruption PoliciesSapin II programme structure depends on formal governance and policy control.
A.5.15 — Access ControlProgramme monitoring and approvals need controlled access and accountable workflows.
Recommendation — Align anti-corruption governance to documented policy ownership and review. Restrict approval and review rights to accountable control owners.

Practitioner Guidance

What to prioritise: Treat the risk map as the programme engine, not a compliance artifact. If it does not drive third-party reviews, accounting tests, and training scope, it is not doing the real work the regulator expects.

What to verify: Check that each core control has an owner, a review cadence, and a retained evidence trail. If you cannot show when the control was last tested and what changed as a result, the programme will look static even if the documents are complete.

Common mistake: Teams often overemphasise policy drafting and underemphasise monitoring quality. Sapin II expectations are better met by a connected operating model than by a long list of disconnected controls.

Practitioner takeaway: The standard is not satisfied by coverage alone, it is satisfied by a control system that learns, refreshes, and proves that corruption risks are being managed as the business evolves.

Deepen Your Knowledge

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Reviewed and updated by the NHIMG editorial team on September 23, 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org