Michael PollittGuestCatou MasserGuestSimon StiggeirGuestESG Voices HostHost
Jens MoormannGuestAnd Jens, based on your experience helping clients with this type of legislation, what are some of the best ways that private sector firms can practice good governance as the directive is implemented across the EU? And how should ESG considerations be factored into this process?

It's about fostering the right culture to make sure that the framework is also effective.

It involves establishing, of course, formalized programs that clearly define roles and responsibilities and also the necessary oversight.

It also means that we should have risk assessments and monitoring activities in place and regularly conducted.

However, most importantly, good governance requires creating a structure that effectively engages employees and also relevant stakeholders, ensuring that they are not only aware of the framework but also understand it is important and are committed to upholding it.

With the new corporate liability clause introduced in the Directive, the importance of establishing clear reporting lines, defining roles and responsibilities, and maintaining oversight has significantly increased.

The Directive introduces indeed a concept of persons in leading position, making corporate liability applicable to nobody when the crime is committed, but also when a failure to properly supervise by such a person enables the crime.

Do we have a clear understanding of who these individuals are across all our EU entities we operate in? Do we have the rights and responsibilities in place and defined? And furthermore, do they have the necessary resources, training and systems in place to effectively fulfill their oversight obligations? The new directive highlights the difference between having a compliance program in place and actually governing for an integral team.

I believe the question has shifted from do we have a policy to can we prove that the framework works and is effective? It is also important for me to note that under the new directive, the existence of a compliance program serves as a mitigating factor rather than a defense, as is the case under the UK Bribery Act.

While it may reduce the weight of the sentence, it also in itself does not affect liability.

As our UK expert, Simon also explained that the key challenge is not necessarily to build a new compliance program from scratch, but to demonstrate that existing anti-bribery and corruption frameworks are effectively being governed, monitored and adapted to this evolving regulatory landscape.

And I would add to that that just in terms of how private sector firms can practice good governance in light of the new directive, the OECD actually did a study last year assessing the effectiveness of anti-blogging corruption compliance programs in the private sector.

And I won't go through all the details, but one of the most surprising things about that study to me was how unsurprising the results were.

All of the companies that they consulted as part of that study referred to the importance of internally reporting anti-bribery and corruption compliance information to those in a position of governance.

And that squares with a lot of our experience helping clients to align with the UK Bribery Act and the guidance on the UK Bribery Act over the last 15 years.

There's a very old expression here, what gets measured gets managed, which seems apposite.

that people in a governance role need information that will allow them to take ownership of the anti-bribery and corruption program for better or for worse.

And that means recognizing good practice, but also calling out any areas where risks are still too high.

Because we've seen an increase in corporate legislation across Europe over the past five years with the CSRD, the CSDD, the EUFLR, et cetera, we've also seen an increase in the information being reported to boards and executive committees on ethics and compliance risk.

So a primary challenge for ethics and compliance teams aiming to establish good governance based on the new EU directive on combating corruption will be to cut through that noise and ensure that leadership are getting only the most relevant information.

That could include, for example, areas of the organisation where bribery and corruption awareness or oversight is limited, with the potential to invoke fines linked to a lack of supervision or control if a bribe is paid.
Building on that, one lesson we've, I suppose, learned from helping clients respond to anti-corruption legislation over the years is that compliance programmes themselves are really the problem.
Most large organisations already have policies, training and due diligence processes and things like reporting mechanisms well established.
And Jens, based on your experience helping clients with this type of legislation, what are some of the best ways that private sector firms can practice good governance as the directive is implemented across the EU? And how should ESG considerations be factored into this process?

It's about fostering the right culture to make sure that the framework is also effective.

It involves establishing, of course, formalized programs that clearly define roles and responsibilities and also the necessary oversight.

It also means that we should have risk assessments and monitoring activities in place and regularly conducted.

However, most importantly, good governance requires creating a structure that effectively engages employees and also relevant stakeholders, ensuring that they are not only aware of the framework but also understand it is important and are committed to upholding it.

With the new corporate liability clause introduced in the Directive, the importance of establishing clear reporting lines, defining roles and responsibilities, and maintaining oversight has significantly increased.

The Directive introduces indeed a concept of persons in leading position, making corporate liability applicable to nobody when the crime is committed, but also when a failure to properly supervise by such a person enables the crime.

Do we have a clear understanding of who these individuals are across all our EU entities we operate in? Do we have the rights and responsibilities in place and defined? And furthermore, do they have the necessary resources, training and systems in place to effectively fulfill their oversight obligations? The new directive highlights the difference between having a compliance program in place and actually governing for an integral team.

I believe the question has shifted from do we have a policy to can we prove that the framework works and is effective? It is also important for me to note that under the new directive, the existence of a compliance program serves as a mitigating factor rather than a defense, as is the case under the UK Bribery Act.

While it may reduce the weight of the sentence, it also in itself does not affect liability.

As our UK expert, Simon also explained that the key challenge is not necessarily to build a new compliance program from scratch, but to demonstrate that existing anti-bribery and corruption frameworks are effectively being governed, monitored and adapted to this evolving regulatory landscape.

And I would add to that that just in terms of how private sector firms can practice good governance in light of the new directive, the OECD actually did a study last year assessing the effectiveness of anti-blogging corruption compliance programs in the private sector.

And I won't go through all the details, but one of the most surprising things about that study to me was how unsurprising the results were.

All of the companies that they consulted as part of that study referred to the importance of internally reporting anti-bribery and corruption compliance information to those in a position of governance.

And that squares with a lot of our experience helping clients to align with the UK Bribery Act and the guidance on the UK Bribery Act over the last 15 years.

There's a very old expression here, what gets measured gets managed, which seems apposite.

that people in a governance role need information that will allow them to take ownership of the anti-bribery and corruption program for better or for worse.

And that means recognizing good practice, but also calling out any areas where risks are still too high.

Because we've seen an increase in corporate legislation across Europe over the past five years with the CSRD, the CSDD, the EUFLR, et cetera, we've also seen an increase in the information being reported to boards and executive committees on ethics and compliance risk.

So a primary challenge for ethics and compliance teams aiming to establish good governance based on the new EU directive on combating corruption will be to cut through that noise and ensure that leadership are getting only the most relevant information.

That could include, for example, areas of the organisation where bribery and corruption awareness or oversight is limited, with the potential to invoke fines linked to a lack of supervision or control if a bribe is paid.
Building on that, one lesson we've, I suppose, learned from helping clients respond to anti-corruption legislation over the years is that compliance programmes themselves are really the problem.
Most large organisations already have policies, training and due diligence processes and things like reporting mechanisms well established.
The rest of this transcript — segmented and speaker-labeled, so you land on the exact moment something was said
Search every transcript — by keyword, by phrase, or by meaning, across every show Radar indexes
Trends — what is surging across podcasts, measured against its own baseline
Alerts — when a name you follow appears in a newly indexed episode
No account is needed to search Radar.