← All postsHow-to

Anti bribery policy: the register matters more than the wording

An anti bribery policy is judged on what the company does, not what the document says. The clauses that matter, the registers behind them, and the grey areas.

How-toA

An anti bribery policy states that your company does not offer or accept improper advantages, and sets out how people are supposed to behave when the situation is not obvious. Every company that has one believes it is enough. The problem is that in the jurisdictions with real teeth, the defence available to an organisation is not "we had a policy" but "we had adequate procedures" — and procedures means the registers, the training, the due diligence and the evidence that someone looked, not the PDF on the intranet.

What an anti bribery policy has to cover

  • A plain statement of prohibition covering both offering and receiving, and covering third parties acting on your behalf.
  • Gifts and hospitality: a value threshold, an approval rule above it, and a requirement to record regardless.
  • Facilitation payments — small payments to speed up a routine act — which are lawful in some jurisdictions and criminal in others, so state your position explicitly rather than staying silent.
  • Political and charitable donations, which are the most common route by which a legitimate payment becomes a problem.
  • Third parties: agents, distributors, consultants and introducers, who are how most enforcement cases actually arise.
  • How to raise a concern, cross-referenced to your whistleblowing policy, and an unambiguous statement that raising one will not be held against the person.

The procedures behind the document

  1. A risk assessment naming the countries, sectors and intermediaries where your exposure actually is — a generic policy applied to an untested risk picture is the classic finding.
  2. Due diligence on third parties before appointment, proportionate to that risk, and repeated rather than done once.
  3. A gifts and hospitality register that people actually use, which requires the threshold to be realistic and the entry to take under a minute.
  4. Training aimed at the roles that face the risk, not an annual click-through for everyone.
  5. Top-level commitment that is visible — an approval recorded at board level, and a policy reissued with a date rather than one written in 2017.
  6. Monitoring and review, with the review evidenced even when nothing changed.

The commercial pressure is the real test. Almost every case begins with someone under a deadline in a market they do not understand, using a local agent nobody diligenced, being told this is simply how things work here. A policy that does not give that person a fast, named route to ask before acting has not addressed the situation where it matters.

The grey areas people ask about

  • A modest meal with a client is usually fine; the same meal during a live tender is not, because timing changes what it looks like.
  • Hospitality at a sporting event is judged on proportion, frequency and whether the host attends — not on the ticket price alone.
  • A gift declined politely and recorded is stronger evidence of a working culture than one that was never offered.
  • Payments demanded by officials for routine services put staff in a genuinely difficult position; the policy should say that personal safety comes first and the payment must be reported afterwards.
  • Charitable donations requested by a customer are a bribery risk wearing a respectable coat, and should go through the same approval as hospitality.

Where the policy and the evidence live

Ettex Docs holds the policy itself with version history, so you can show which text was in force when — a question that arrives only when something has gone wrong, and one that a file called policy-final-v3 cannot answer. The registers belong beside it rather than inside it: gifts, hospitality, third-party due diligence and training completion are records with dates, not paragraphs. The supplier onboarding file is where the third-party checks should already sit. Ettex does not provide legal advice and the rules differ sharply by jurisdiction — what is lawful facilitation in one country is a criminal offence in another, and your policy has to name which regimes bind you.

Frequently asked

Does a small company need one?

If you have third parties acting for you, sell into higher-risk markets, or bid for public contracts, yes — and the last of those often makes it a procurement requirement regardless of size. The document can be two pages; the registers behind it are what take effort.

What value threshold should we set for gifts?

Low enough that it is a real control and high enough that people do not route around it. What matters more is that everything is recorded regardless of value, because the pattern across a year is more revealing than any single item.

Are we responsible for what an agent does?

In several major regimes, yes — liability extends to associated persons acting on your behalf, including where you did not know. That is precisely why third-party due diligence is the part of the programme worth spending the money on.

EP
Written by Elena P.

Part of the Ettex team — writing about product, engineering and the future of work.

More posts
Get the best of the Ettex blogProduct news, guides and tips — straight to your inbox, no spam.