Purpose

Maintain accountable ABC governance and a current enterprise-wide assessment of bribery and corruption risk.

Preconditions

  • Current business activities, jurisdictions, third parties, public-sector interactions, benefits and payment channels are available.
  • Board, management, Compliance, Finance and first-line responsibilities are assigned per the manual’s three-lines-of-defense model.

Steps

#ActionDetailsEvidence
1Confirm ABC scope and rolesConfirm ABC scope, zero-tolerance principles, accountable roles (Board, Executive Management, Compliance Officer / designated ABC Officer, Finance, Department Heads, Employees, Internal Audit), escalation channels and required resources.Governance records
2Identify bribery and corruption riskIdentify risk across jurisdictions, business activities, public-official exposure, third parties, commissions, reimbursements, gifts, hospitality, donations, sponsorships, conflicts and periods of change or growth.Risk identification log
3Assess inherent and residual riskAssess inherent risk, existing controls, control effectiveness and residual risk using the risk-based framework — corruption risk may arise through jurisdictions, third-party relationships, dealings with public officials or state-linked entities, products and services, commissions and reimbursements, gifts and hospitality, charitable or sponsorship activity, governance weaknesses, and periods of business change or growth.Risk assessment
4Apply enhanced controls to higher riskApply enhanced review, approval, documentation and monitoring to higher-risk exposure — higher-risk arrangements require enhanced review, stronger evidence of rationale, additional approvals, and closer monitoring.Enhanced review records
5Assign risk treatment actionsAssign treatment actions, owners and due dates for risk outside tolerance.Risk treatment plan
6Present risk profile to BoardPresent the ABC risk profile, incidents, control effectiveness and remediation to management and the Board — the Board must receive sufficient information to assess and challenge the effectiveness of the ABC framework.Board reporting pack
7Review EWRA annually or on changeReview the ABC EWRA at least annually and whenever a material change occurs in law or regulation, business activities or jurisdictions, governance structure or ownership, third-party operating model, or findings from incidents, investigations, audits, or regulator feedback.EWRA review record

Exceptions and Escalation

Unassessed material exposure, insufficient resources, overdue high-risk treatment or an unresolved role conflict shall be escalated to management and the Board.

Records

  • Approved ABC EWRA and methodology
  • Risk treatment and acceptance decisions
  • Governance and responsibility records
  • Management and Board reporting
  • Remediation tracking

Relationships

Assurance

Runtime effectiveness results are maintained in Odoo and assessed through the Hermes workflow tracked in ISS-HERMES-001. This note defines design, ownership, evidence expectations and testing method; it does not contain a manually maintained operation, evidence or overall effectiveness rating.

  • Frequency: annual and after material change

History

  • 2026-07-28: Enriched step detail with proportionality principles, risk-source taxonomy and review triggers from the full approved ABC Manual.
  • 2026-07-26: Created from sections 4, 5, 7, 17, 20 and 21 of the approved ABC Manual.