Anti-Bribery Outsourcing
Definition
Anti-Bribery Outsourcing
Anti-bribery outsourcing is the practice of extending a company’s anti-corruption controls to the agents, contractors and service providers acting on its behalf. Liability follows the relationship rather than the payroll, so a partner’s bribe becomes your problem.
Most corruption enforcement involves an intermediary rather than a direct payment by an employee.
That pattern is not accidental. Companies use local agents precisely where they lack knowledge, and lacking knowledge is exactly what creates exposure.
Prosecutors have adapted accordingly — they now read third party management as a proxy for whether a compliance programme is real.
Key takeaways
- Third party relationships are the dominant channel in corruption enforcement.
- Due diligence must be risk based, documented and repeated rather than one-off.
- Contract terms should describe the services, the payment basis and the audit right.
- Onboarding diligence without ongoing monitoring is treated as an incomplete programme.
How it works
Enforcement agencies assess third party management as a distinct component of a compliance programme. The United States Department of Justice states that a well-designed programme should apply risk-based due diligence to its third-party relationships.
The expected questions are specific. Prosecutors ask whether contract terms describe the services performed, whether the third party is actually doing the work, and whether its compensation is commensurate with that work in that industry and region.
Audit rights get their own test — investigators ask whether the company has the right to analyse a third party’s books and accounts, and whether it has ever exercised that right.
| Programme element | What is assessed |
|---|---|
| Business rationale | Why this intermediary was needed at all |
| Risk-based diligence | Depth proportionate to country, sector and role |
| Contract terms | Services described, payment justified, audit right present |
| Ongoing monitoring | Whether risk management continues after onboarding |
| Red flag handling | What happened to concerns diligence actually raised |
| Rejected parties | Whether failed candidates are blocked from re-entry |
The last row catches many programmes out — companies reject a candidate for cause, then hire the same firm through a different business unit eighteen months later.
Guidance in the United Kingdom sets out six principles for procedures designed to prevent bribery: proportionality, top-level commitment, risk assessment, due diligence, communication and monitoring and review.
Examples
The arrangements that create exposure rarely look exotic at the point of signature. Each case below involves a control that both parties assumed the other one owned.
An engineering firm appoints a customs broker in a high-risk market. The broker’s facilitation payments become the firm’s problem, because the broker was acting to obtain an advantage for it.
A medical device company pays a distributor an unusually high margin. The margin has no commercial explanation, which is precisely the compensation mismatch investigators look for.
A software vendor uses a reseller to win public sector contracts. Diligence at onboarding was thorough, but nobody repeated it across four years of renewals in a changing political environment.
A mining group’s joint venture partner handles all permitting. The group holds audit rights on paper and has never used them, which reads as a control that exists only in the contract.
Related terms
Anti-corruption vocabulary overlaps with general supplier governance, and the overlap hides the differences. The entries here map the neighbourhood, so you can tell which rule applies.
- ISO 37001: the anti-bribery management system standard, certifiable and system focused.
- Compliance outsourcing: contracting the compliance function rather than extending controls to suppliers.
- Compliance officer: the role that owns the programme internally.
- Vendor management outsourcing: the supplier programme this discipline sits inside.
- Risk outsourcing: moving risk activity out, which never moves the underlying exposure.
- Regulated outsourcing: outsourcing inside a supervised sector, where the bar is higher again.
- Multi vendor outsourcing: several providers at once, which multiplies the diligence burden.
FAQ
Can we be liable for a partner we do not control?
Yes. Liability generally attaches where the third party acted to obtain or retain business or an advantage for you, regardless of the control relationship.
How much diligence is enough?
It scales with risk. Country, sector, public sector exposure and the intermediary’s role all raise the required depth, and the reasoning should be recorded.
Do audit rights matter if we never use them?
They matter less than you think. Investigators specifically ask whether the right has been exercised, so an unused clause is weak evidence.
Should diligence be repeated?
Yes. Programmes are assessed on whether risk management continues through the life of the relationship rather than stopping at onboarding.
Does certification protect us?
It supports a defence without creating one. A management system certificate describes design, while enforcement examines operation.
What is the single most common failure?
Hiring a party that previously failed diligence, through a different unit that never saw the original file.
Compare verified partners in the Outsource Accelerator directory and shortlist partners whose third party programme is more than a policy.







Independent




