Avenlor
Home / Insights / Governance
Governance

Anti-Bribery and Corruption Compliance

A bribery exposure rarely announces itself as bribery. It looks like a generous gift, a fast-tracked approval, or a facilitation fee nobody wants to call by its name. A program that works is the one built before any of that happens — not the one assembled after a regulator asks why it didn't exist.

Avenlor ConsultingGovernance & Internal Controls8 min read

Most companies already have a line in their code of conduct that says bribery is prohibited. That line has never stopped a bribe. What stops one is a set of specific, everyday controls — who can approve what, what a gift limit actually is in riyals, what due diligence happens before an agent is engaged — applied consistently enough that an employee under pressure has a clear answer instead of a judgment call.

In Saudi Arabia, the National Anti-Corruption Commission (Nazaha) has made enforcement visible and public in a way that changes the calculus for boards: this is no longer a theoretical risk assessed once a year and filed away. For companies with cross-border operations, government-facing licensing or procurement, or third-party agents acting on their behalf, exposure runs under more than one regulatory regime at once.

Why this sits above "we have a policy"

A policy document proves the company knew the rules. It does nothing to prove the company followed them, and a regulator's first question after any allegation is not "did you have a policy" — it's "show me the approval trail." Companies that fail this test usually didn't lack a policy; they lacked the operating discipline to leave evidence the policy was actually applied.

The question a regulator asks first is never "did you have a policy" — it's "show me the approval trail."

Mapping where the exposure actually is

Bribery risk is not evenly distributed across a business. It concentrates in a handful of predictable places: interactions with government officials over licensing, permitting, customs, or tax; procurement processes where a vendor has something to gain from a specific outcome; and — the single most underestimated channel — agents, distributors, and other third parties acting on the company's behalf, whose conduct can create liability for the company even when nobody at the company authorized it. A useful exercise is mapping every point where an employee or intermediary can influence a government or commercial decision in the company's favor, then asking what controls exist at that exact point today.

The controls that do the work

1. A gifts-and-hospitality policy with a real number attached

"Use good judgment" is not a control — it's the absence of one. A workable policy states a specific value threshold, requires disclosure above it, and prohibits gifts entirely around active tenders, licensing decisions, or government interactions. The threshold matters less than having one that's enforced consistently.

2. Third-party due diligence before the relationship starts

Agents, distributors, consultants, and other intermediaries who deal with government bodies or win business on the company's behalf are the highest-risk channel precisely because their conduct is harder to see. Due diligence — ownership screening, sanctions and adverse-media checks, and a documented business rationale for the relationship — belongs before the contract is signed, not after a problem surfaces.

3. A record of every approval that's easy to reconstruct later

The companies that come through an investigation cleanly are the ones that can produce, on request, who approved a specific payment, gift, or engagement, on what basis, and when. This is a control-documentation discipline as much as a compliance one — the same evidentiary standard that internal and external auditors already expect.

4. No facilitation payments — and a plan for the moment someone asks for one

A blanket no-facilitation-payments policy is only useful if frontline staff know what to do the moment they're actually asked for one. That means a clear, pre-agreed escalation path — who to call, what to say, what gets documented — decided before the situation happens, not improvised in the moment under pressure.

Where oversight actually happens

The audit committee should see, at minimum, a summary of gifts and hospitality disclosures, third-party due diligence exceptions, and any facilitation-payment incidents — not to micromanage individual cases, but to confirm the controls are operating as designed. A credible whistleblowing channel is often where a bribery concern first becomes visible, since the employees closest to a questionable payment are rarely the ones with the authority to stop it on their own.

Why family and founder-led businesses are not exempt

It's easy to assume anti-bribery programs are a listed-company concern. In practice, family businesses with agents, distributors, or joint-venture partners operating on their behalf carry exactly the same third-party exposure — often with less formal oversight to catch it early. As these businesses expand across borders or bring in outside investors, the absence of a documented program becomes a specific, quantifiable item in due diligence, not just a reputational soft spot.

What an anti-bribery and corruption program needs

  • A risk map identifying exactly where government and high-value commercial interactions occur
  • A gifts-and-hospitality policy with a real, enforced value threshold
  • Third-party due diligence completed before, not after, an agent or intermediary is engaged
  • A documented approval trail for payments, gifts, and third-party engagements
  • A firm no-facilitation-payments position, with a pre-agreed escalation path
  • Regular reporting to the audit committee, and a whistleblowing channel employees actually trust

None of this eliminates the risk of a single bad decision by a single employee. What it does is remove the excuse — the absence of a clear policy, a defined limit, or a documented process — that turns one person's poor judgment into the company's exposure.

Building or reviewing an anti-bribery program?

We design risk-mapped compliance frameworks — gifts and hospitality controls, third-party due diligence, and audit-committee reporting — built to hold up under real scrutiny.

Discuss your mandate →

Read next

Whistleblowing and Speak-Up Channels → The Audit Committee: The Board's Line of Sight →

This article is general guidance on governance practice and does not constitute legal, audit, or regulatory advice. Requirements depend on your circumstances and the applicable regulations at the time; obtain professional advice for your specific engagement.