Purpose
Maintain accountable ABC governance and a current enterprise-wide assessment of bribery and corruption risk.
Preconditions
- Current business activities, jurisdictions, third parties, public-sector interactions, benefits and payment channels are available.
- Board, management, Compliance, Finance and first-line responsibilities are assigned per the manual’s three-lines-of-defense model.
Steps
| # | Action | Details | Evidence |
|---|---|---|---|
| 1 | Confirm ABC scope and roles | Confirm ABC scope, zero-tolerance principles, accountable roles (Board, Executive Management, Compliance Officer / designated ABC Officer, Finance, Department Heads, Employees, Internal Audit), escalation channels and required resources. | Governance records |
| 2 | Identify bribery and corruption risk | Identify risk across jurisdictions, business activities, public-official exposure, third parties, commissions, reimbursements, gifts, hospitality, donations, sponsorships, conflicts and periods of change or growth. | Risk identification log |
| 3 | Assess inherent and residual risk | Assess inherent risk, existing controls, control effectiveness and residual risk using the risk-based framework — corruption risk may arise through jurisdictions, third-party relationships, dealings with public officials or state-linked entities, products and services, commissions and reimbursements, gifts and hospitality, charitable or sponsorship activity, governance weaknesses, and periods of business change or growth. | Risk assessment |
| 4 | Apply enhanced controls to higher risk | Apply enhanced review, approval, documentation and monitoring to higher-risk exposure — higher-risk arrangements require enhanced review, stronger evidence of rationale, additional approvals, and closer monitoring. | Enhanced review records |
| 5 | Assign risk treatment actions | Assign treatment actions, owners and due dates for risk outside tolerance. | Risk treatment plan |
| 6 | Present risk profile to Board | Present the ABC risk profile, incidents, control effectiveness and remediation to management and the Board — the Board must receive sufficient information to assess and challenge the effectiveness of the ABC framework. | Board reporting pack |
| 7 | Review EWRA annually or on change | Review the ABC EWRA at least annually and whenever a material change occurs in law or regulation, business activities or jurisdictions, governance structure or ownership, third-party operating model, or findings from incidents, investigations, audits, or regulator feedback. | EWRA review record |
Exceptions and Escalation
Unassessed material exposure, insufficient resources, overdue high-risk treatment or an unresolved role conflict shall be escalated to management and the Board.
Records
- Approved ABC EWRA and methodology
- Risk treatment and acceptance decisions
- Governance and responsibility records
- Management and Board reporting
- Remediation tracking
Relationships
- Policy: POL-ABC-001 Anti-Bribery and Corruption Manual
- Process: PRC-FCI-001 Financial Crime and Integrity
- Control: CTRL-ABC-001 Ensure ABC Governance and EWRA Are Maintained
Assurance
Runtime effectiveness results are maintained in Odoo and assessed through the Hermes workflow tracked in ISS-HERMES-001. This note defines design, ownership, evidence expectations and testing method; it does not contain a manually maintained operation, evidence or overall effectiveness rating.
- Frequency: annual and after material change
History
- 2026-07-28: Enriched step detail with proportionality principles, risk-source taxonomy and review triggers from the full approved ABC Manual.
- 2026-07-26: Created from sections 4, 5, 7, 17, 20 and 21 of the approved ABC Manual.