A Sapin II programme should combine formal governance with practical controls. Core elements include a code of conduct, whistleblowing channels, risk mapping, third-party due diligence, accounting controls, employee and manager training, disciplinary measures, and internal controls. The strongest programmes treat these as a connected system, not a checklist, and keep the risk map and monitoring processes current as the business changes.
How to structure Sapin II anti-corruption controls as a programme
A Sapin II programme works best when the controls reinforce one another. The code of conduct sets expectations, the whistleblowing channel creates intake, risk mapping focuses attention, third-party due diligence extends that discipline outward, accounting controls and internal controls detect irregular behaviour, and training plus disciplinary measures make the programme usable in day-to-day operations. The question is not whether each item exists, but whether they operate as a managed system with ownership, review cadence, and evidence of follow-through.
That system view matters because compliance teams often overbuild policies and underbuild operating rhythm. A programme that is documented but not refreshed, or that treats due diligence, accounting review, and monitoring as separate workstreams, usually becomes brittle when business models, geographies, intermediaries, or payment flows change. Current guidance is strongest when the risk map drives control intensity and the programme can show that findings feed back into remediation.
- Use the code of conduct to define prohibited conduct and escalation thresholds.
- Route whistleblowing, investigations, and remediation through a clear ownership model.
- Keep third-party due diligence, accounting controls, and monitoring aligned to the risk map rather than to a fixed annual checklist.
- Retain evidence that training, reviews, and disciplinary follow-up actually occurred.
For a control-structure benchmark, many teams map the programme to a formal management-system pattern such as ISO/IEC 27001:2022 Information Security Management and its companion control guidance in ISO/IEC 27002:2022 Information Security Controls, because both push governance, control ownership, and continuous improvement rather than one-off policy publication.
What makes a Sapin II programme operationally credible
Operational credibility comes from making the programme testable. A credible design has a current risk map, documented review of third parties and intermediaries, accounting controls that are actually sampled, training that reaches both employees and managers, and disciplinary measures that are applied when rules are breached. The programme should also distinguish between policy ownership and operational execution, because the people writing the standard are not always the ones who can verify invoices, approvals, gifts, hospitality, commissions, or unusual payments.
The most common weakness is fragmentation. Anti-corruption programmes fail when legal, compliance, finance, procurement, and HR each hold a piece of the design but no one owns the control chain end to end. Sapin II expectations are better met when the programme shows how a concern travels from detection to investigation to remediation, and how lessons learned change the next risk assessment. That makes the programme auditable in a practical sense, not just in a policy sense.
- Make one function accountable for the control framework and another accountable for control testing.
- Update the risk map when markets, entities, agents, distributors, or payment channels change.
- Test whether accounting controls can detect the specific corruption patterns your business actually uses.
- Use training records and case handling records as evidence of implementation, not as a substitute for it.
Where the programme extends to third parties and channels with elevated exposure, the control logic is similar to vendor-risk and trust-boundary governance in SOC 2 Trust Services Criteria (AICPA) and CSA Cloud Controls Matrix, where responsibility, monitoring, and evidence are expected to hold across internal and external dependencies.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
ISO/IEC 27001:2022 provides the primary governance reference for this topic.
| Framework | Control / Reference | Relevance |
|---|---|---|
| ISO/IEC 27001:2022 | A.5.2 — Anti-bribery and Corruption Policies | Sapin II programme structure depends on formal governance and policy control. |
| A.5.15 — Access Control | Programme monitoring and approvals need controlled access and accountable workflows. | |
| Recommendation — Align anti-corruption governance to documented policy ownership and review. Restrict approval and review rights to accountable control owners. | ||
Practitioner Guidance
What to prioritise: Treat the risk map as the programme engine, not a compliance artifact. If it does not drive third-party reviews, accounting tests, and training scope, it is not doing the real work the regulator expects.
What to verify: Check that each core control has an owner, a review cadence, and a retained evidence trail. If you cannot show when the control was last tested and what changed as a result, the programme will look static even if the documents are complete.
Common mistake: Teams often overemphasise policy drafting and underemphasise monitoring quality. Sapin II expectations are better met by a connected operating model than by a long list of disconnected controls.
Practitioner takeaway: The standard is not satisfied by coverage alone, it is satisfied by a control system that learns, refreshes, and proves that corruption risks are being managed as the business evolves.
Related resources from NHI Mgmt Group
- How should compliance teams structure an AML programme that actually adapts to changing risk?
- How should compliance teams structure a verification and anti-fraud knowledge hub so it stays useful to practitioners?
- How should security teams structure a NIST compliance programme so it improves resilience instead of becoming a paperwork exercise?
- How should crypto businesses in Malaysia structure their compliance programme to meet licensing, AML, and Travel Rule obligations?
Deepen Your Knowledge
Reviewed and updated by the NHIMG editorial team on September 23, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org