ABC Frameworks & Extraterritorial Laws

Anti-bribery and corruption controls are often described as policies about gifts, intermediaries and public officials. In a bank, that description is too narrow. A mature ABC framework is a connected operating system that begins with the legal entity and jurisdiction in which the bank acts, identifies how people or third parties could offer, request, conceal or transmit an improper advantage, controls the business event before money moves, records the transaction accurately, detects unusual behaviour after the event and preserves enough evidence for an independent reviewer to reconstruct what happened.

The difficult part is that bribery risk is rarely contained within one country. A relationship manager may sit in one jurisdiction, an agent in another, a state-owned customer in a third and a payment may be booked by a bank entity elsewhere. Several legal frameworks can be relevant at the same time, but they do not have identical definitions, jurisdictional tests, offences, defences or enforcement approaches. A bank therefore needs both a global policy baseline and a legally controlled jurisdiction overlay. It should never reduce the problem to a single global threshold or assume that compliance with one country's law resolves every other legal question.

This chapter uses the United Nations Convention against Corruption and the OECD anti-bribery framework as global anchors, then explains the practical impact of two influential national regimes: the United States Foreign Corrupt Practices Act and the United Kingdom Bribery Act 2010. The purpose is educational, not legal advice. The operative rule for a transaction always depends on the relevant legal entity, people, conduct, facts, jurisdiction and effective date.

Global standards, national legal overlays and bank controls must be connected without treating one jurisdiction as universal.

The simplest mental model

A useful ABC mental model has three layers.

The first layer is prohibited or risky conduct. Someone gives, offers, promises, requests or receives something of value in order to influence a decision, obtain an improper advantage, reward improper performance or distort a legitimate business outcome. The benefit may be cash, but it can also be travel, hospitality, a job, a donation, a discount, confidential information, a contract, a favour for a family member or another economic or non-economic advantage. The facts and the applicable law decide whether conduct is unlawful; the bank's policy may deliberately be stricter than the legal minimum.

The second layer is jurisdiction and legal perimeter. The bank must ask which entity, person and conduct create a legal nexus. A U.S. issuer, a UK-incorporated company, a foreign subsidiary, an employee travelling abroad, an intermediary or a transaction touching a particular territory can create different questions. Currency, customer nationality or country risk alone should not be used as a substitute for legal analysis.

The third layer is control evidence. Before approving a risky event, the bank needs enough information to establish the legitimate purpose, parties, value, approvals, conflicts, public-official connections and payment route. Afterwards it needs accurate books and records, retained evidence, monitoring and a route to investigate concerns. The control should show not only that a form was completed but why the decision was reasonable.

That gives a practical sequence:

conduct risk -> legal nexus -> due diligence -> approval -> payment and recording -> monitoring -> investigation -> remediation.

The sequence is important because different control failures create different consequences. A weak third-party review can allow an inappropriate intermediary to be appointed. A weak payment control can allow a legitimate contract to be used for an unexplained transfer. A weak accounting control can conceal what the payment actually represented. A weak investigation process can prevent the bank from learning whether the failure was isolated or systemic.

Global architecture: UNCAC and the OECD framework

The United Nations Convention against Corruption provides the broadest global reference point. It addresses prevention, criminalisation and law enforcement, international cooperation, asset recovery and technical assistance. It requires States Parties to address bribery of national public officials and foreign public officials, and it also contains provisions concerning the private sector, accounting standards and liability of legal persons. The Convention is implemented through national law, so a bank should use it as an international architecture rather than treat the treaty text as a direct replacement for domestic obligations.

The OECD Anti-Bribery Convention has a narrower but highly important focus: combating bribery of foreign public officials in international business transactions. The OECD's 2021 Anti-Bribery Recommendation complements the Convention with expectations around detection, enforcement, corporate compliance, reporting, public procurement and international cooperation. For a multinational bank this matters because client activity, advisory mandates, trade, lending, payments and third-party relationships can all expose the institution to international business transactions where public-official corruption risk is relevant.

Neither framework means that every interaction with government is suspicious. Banks routinely serve ministries, public agencies, state-owned enterprises, central banks, municipalities and public-sector employees. The control objective is to identify circumstances in which value, influence, decision-making and an improper advantage may intersect, and to apply proportionate controls without treating lawful public-sector activity as inherently corrupt.

What bribery means operationally

Banks should avoid defining bribery only as a brown envelope of cash. The operational question is whether an advantage is being used to induce, reward or influence conduct in a way that is prohibited by the applicable law or bank policy.

That broad view captures recurring risk patterns. A consultant may receive a success fee that appears commercially excessive for the work performed. A relationship team may be asked to fund travel that contains little genuine business content. A recruitment request may involve a senior official's relative with no ordinary hiring process. A charitable contribution may be directed by a customer decision-maker toward an organisation linked to that person's family. A procurement officer may seek entertainment while a tender is active. A vendor may submit vague invoices for “market development” without evidence of deliverables.

These facts are not automatic proof of bribery. They are indicators that the business purpose and decision process need stronger evidence. The control should distinguish an allegation, a risk factor and a legal conclusion. Mixing them creates both false accusations and weak investigations.

Public-sector and private-sector bribery

Some laws focus heavily on bribery involving public officials, while others also criminalise commercial or private-sector bribery. The UK Bribery Act's general offences cover improper performance of a relevant function or activity and are not restricted to foreign public officials. The FCPA's anti-bribery provisions are specifically concerned with corrupt payments to foreign officials, foreign political parties or officials, political candidates and certain other covered recipients to obtain or retain business or secure an improper advantage.

For a bank, the distinction matters because an ABC programme normally covers a wider risk universe than a single statute. Vendor kickbacks, procurement conflicts, sales inducements and employee misconduct can create serious legal, conduct, fraud and reputation exposure even where the FCPA's foreign-official element is absent.

The U.S. Foreign Corrupt Practices Act: what a bank should understand

The FCPA contains two main control families that should be kept distinct.

The anti-bribery provisions prohibit covered persons and entities from corruptly offering, paying, promising to pay or authorising the payment of money or anything of value to a covered foreign-official recipient for a prohibited business purpose. Jurisdiction can arise through categories such as issuers and domestic concerns, and in certain circumstances through conduct by foreign persons or businesses while in U.S. territory. The exact statutory analysis belongs to qualified legal counsel; operational systems should preserve the facts that make that analysis possible.

The accounting provisions apply to issuers and include requirements concerning books and records and internal accounting controls. These provisions are not merely a duplicate of the anti-bribery offence. A bank subject to them needs records that accurately and fairly reflect transactions and dispositions of assets, together with a system of internal accounting controls designed to provide reasonable assurance over authorised transactions, accounting and accountability for assets.

This distinction is useful in investigations. A payment may raise questions about the accuracy of its accounting description even before investigators can determine whether the anti-bribery elements are met. Conversely, a correctly recorded payment can still raise anti-bribery concerns if the purpose or recipient is improper. The control architecture therefore needs both conduct analysis and accounting evidence.

“Anything of value” and indirect payments

A compliance workflow should not restrict the risk field to cash. Travel, employment, gifts, charitable contributions, discounts, entertainment or benefits delivered through another person can all require review depending on the facts. It should also capture indirect routes. An intermediary, distributor, consultant, joint-venture partner or other third party can create risk where value is routed through that party to a covered recipient.

This is why third-party due diligence should not stop at sanctions and PEP screening. The bank should understand ownership, competence, services, remuneration, selection rationale, public-official connections, subcontractors, payment destination, contract terms and evidence of actual performance. A clean screening result is not evidence that the commercial relationship is legitimate.

Facilitation payments: a narrow U.S. issue, not a global permission

The FCPA contains a narrow exception relating to facilitating or expediting payments for certain routine governmental actions. That feature is frequently misunderstood. It does not create a global permission for “small payments,” and another country's law may prohibit the same conduct. The UK Bribery Act does not provide an equivalent exception. A multinational bank therefore should not encode a simple value threshold below which facilitation payments are automatically allowed.

A safer global policy is often to prohibit such payments except where local policy and legal guidance recognise a tightly controlled situation such as immediate threats to health or safety. Any exceptional payment should have a defined escalation route, contemporaneous evidence and accurate accounting. The legal and policy basis should be version-controlled because rules and internal standards can change.

DOJ 2025 enforcement guidelines

The U.S. Department of Justice issued Guidelines for Investigations and Enforcement of the FCPA in June 2025. They guide federal prosecutors in enforcement decision-making. A bank should treat them as current enforcement context, not as a rewrite of the statute's legal elements. Architecture and policy teams should keep statutory rules, regulatory obligations, enforcement guidance and internal risk appetite as separate rule types with their own effective dates and owners.

That distinction prevents a common design error: turning a policy document into a hard-coded legal rule without preserving what authority it represents.

FEPA and the demand side of foreign bribery

The Foreign Extortion Prevention Act complements the U.S. framework by addressing the demand side: certain foreign officials who corruptly demand, seek, receive, accept or agree to receive or accept things of value in specified circumstances. For banks, FEPA reinforces a broader investigative lesson. A corruption case may involve not only the party offering value but also a public official or network seeking it. Case models should therefore support multiple roles rather than assume there is always one “payer” and one passive recipient.

The UK Bribery Act 2010

The UK Bribery Act provides another influential model but it should not be blended mechanically with the FCPA.

Section 1 addresses offering, promising or giving a financial or other advantage in circumstances connected to improper performance. Section 2 addresses requesting, agreeing to receive or accepting such an advantage. Section 6 creates a specific offence concerning bribery of foreign public officials. Section 7 creates a corporate offence where a relevant commercial organisation fails to prevent bribery by a person associated with it who intends to obtain or retain business or a business advantage for the organisation.

The Section 7 model has major programme implications because it directs attention toward the organisation's preventive procedures and the conduct of associated persons. The statutory defence is that the organisation had adequate procedures designed to prevent such bribery.

The Ministry of Justice guidance groups the adequate-procedures framework around six principles: proportionate procedures, top-level commitment, risk assessment, due diligence, communication including training, and monitoring and review. These principles are useful beyond the UK as programme-design questions, but their legal significance under Section 7 should remain explicitly UK-scoped.

The Bribery Act has no general facilitation-payment exception. That difference alone shows why a global bank cannot use a single U.S.-derived rule for all entities.

Extraterritoriality: build a jurisdiction map, not a country blacklist

“Extraterritorial” means that a law can reach conduct with connections beyond the country's physical borders under the jurisdiction tests set by that law. It does not mean that every global transaction is automatically subject to every well-known anti-bribery statute.

A robust bank process captures the facts needed for legal analysis:

QuestionWhy it matters operationally
Which bank legal entity is acting?Incorporation, listing status, business presence and regulatory perimeter can matter.
Which employee, agent or associated person acted?Nationality, employment, agency and role can affect analysis.
Where did relevant conduct occur?Meetings, approvals, communications, payment steps and use of territory can matter.
Who received or was intended to receive the advantage?Public-official status, commercial role and indirect beneficiaries can change the legal question.
What business outcome was sought?Business retention, award, licence, regulatory action, procurement or another advantage may be relevant.
What other local laws apply?The transaction can be legal under one framework and prohibited under another.
What was the effective law and policy at the time?Historical investigations must use the rule version applicable to the event.

A bank should resolve entity, person, conduct and territorial nexus before selecting a legal or policy route.

A jurisdiction engine should not make final legal conclusions from simplistic fields such as payment currency. For example, the use of U.S. dollars can be important in some legal and sanctions contexts, but it should not be coded as automatic proof that FCPA jurisdiction exists. The system should collect evidence and route the matter to the appropriate legal and compliance owner.

Where ABC risk appears across the banking lifecycle

ABC risk can arise long before a payment alert.

During market entry and business development, a bank may use introducers, lobbyists, consultants or local advisers to obtain licences, identify clients or build public-sector relationships. The risk is not the use of an intermediary itself; it is whether the intermediary has a legitimate role, appropriate competence, transparent ownership, reasonable remuneration and a defensible selection process.

During client onboarding and relationship management, risks can arise where beneficial owners, controllers, decision-makers or connected parties are public officials or have influence over public contracts. PEP screening can provide useful information but it is not identical to the legal definition of a public official under anti-bribery laws. A state-owned enterprise employee, for example, may require a different legal analysis from a conventional PEP category. The data model should not collapse the concepts.

During procurement, employees may receive offers of hospitality, rebates, personal benefits or future employment from vendors. Procurement controls therefore need competitive bidding, conflict disclosure, segregation of duties, vendor due diligence and transparent exceptions.

During product approval, credit and advisory activity, a customer or intermediary may seek unusual fees, side agreements, accelerated approvals or payments to unrelated parties. The ABC team should connect with credit, legal, operations and financial-crime teams rather than operate as a detached register.

During payment execution, the bank may see a vague invoice, offshore beneficiary, split payment, cash request, unrelated account, round amount or description inconsistent with the contract. None is conclusive alone. The payment control should compare the instruction with the approved commercial arrangement and route exceptions before release where feasible.

During accounting and expense processing, the description used in the ledger matters. “Consulting,” “marketing,” “miscellaneous,” “travel” or “commission” can conceal weak evidence if they are accepted without documentation. Accurate books and records are a control outcome, not clerical housekeeping.

During monitoring and investigations, changes in vendor bank account, repeated threshold-adjacent gifts, unusual expense clustering, high commissions, government-touchpoint timing or employee-vendor relationships can create a case for review. Good detection combines context rather than treating one threshold as proof of misconduct.

Third-party corruption risk

Intermediaries are important because they create distance between the bank and the person actually interacting with a decision-maker. That distance can be commercially legitimate, but it can also hide who performs the work, who receives value and why a payment is being made.

A high-quality third-party review should answer practical questions. What service is required? Why can the bank not perform it itself? How was the party selected? Who owns and controls it? Does it have employees and capability consistent with the service? Is the fee reasonable for the market and scope? Is compensation contingent on obtaining a government decision or contract? Is the party connected to a public official or customer decision-maker? Does it use subcontractors? Where will money be paid? What evidence will prove performance?

The decision should be risk-based. A long-established technology vendor providing commodity services is different from a newly formed consultant receiving a large success fee to influence a government tender. The risk model should explain the difference rather than assign both the same generic “medium risk” score.

Contract controls can include defined services, fee schedules, audit rights, anti-bribery representations, subcontractor restrictions, invoice requirements, termination rights and cooperation clauses. Contract language does not replace due diligence, but it creates enforceable expectations and improves later investigation evidence.

Gifts, entertainment and hospitality

Gifts and hospitality controls work best when they evaluate context rather than value alone. Amount thresholds are useful for routing, but a low-value benefit can still be problematic if offered repeatedly, during a tender, to an official with direct decision authority, or through family members. Conversely, ordinary modest hospitality can be legitimate when transparently connected to a business event and consistent with local policy.

A useful register captures giver, recipient, employer, public-official or decision-maker connection, business purpose, event, value, cumulative value, timing, approver and supporting evidence. Aggregation matters: ten small events can create a different risk from one isolated event.

Pre-approval is especially important when public officials, procurement decisions or active regulatory matters are involved. The system should be able to block or escalate submissions with missing fields rather than allow approval through free-text workarounds.

Charitable contributions, sponsorships and community spending

A donation can create corruption risk where a decision-maker directs value to an organisation linked to that person, where the recipient lacks genuine charitable activity, or where timing coincides with a licence, tender or enforcement decision. The same applies to sponsorship and community investment.

Controls should establish the recipient's legal status, ownership or control where relevant, purpose, expected use of funds, connections to customers or officials, selection process, payment account and post-payment evidence. The bank should avoid assuming that “charitable” means low risk.

Recruitment and internships

Employment can be an advantage. Recruitment controls should therefore identify requests linked to public officials, customers, vendors or important commercial decisions. The safest design preserves ordinary merit-based recruitment and requires exceptions to be transparent and independently approved.

The relevant question is not whether an applicant has a politically connected relative. It is whether the hiring decision is being used to influence or reward another person's action. That distinction protects both the bank and applicants from unfair treatment.

Mergers, acquisitions and successor risk

M&A creates a special challenge because the acquiring bank can inherit businesses, third parties, books, records and historical conduct that were not designed to its control standard. Due diligence should examine high-risk markets, government-facing revenue, third-party populations, investigations, whistleblowing, internal audit findings, payment practices and accounting controls.

Post-acquisition integration should not stop at policy distribution. The bank needs a timed plan to migrate third parties, approval workflows, payment controls, training, monitoring, records and reporting. Where historical issues are identified, legal counsel should determine investigation and disclosure obligations under the relevant regime.

A six-layer ABC control architecture

A useful architecture separates six layers.

1. Business event capture. The system records the request: third party, gift, donation, recruitment, contract, payment, expense or other event. Mandatory fields establish who, what, why, value, jurisdiction and timing.

2. Risk enrichment. Data is enriched with ownership, public-official indicators, PEP data, adverse information, geography, sector, employee conflicts, customer context and previous approvals. Each source should have provenance and refresh date.

3. Rule and policy evaluation. The platform applies the correct rule set for the bank entity, event type, jurisdiction and effective date. Legal requirements and internal policy thresholds should be identifiable separately.

4. Human decision and escalation. The workflow sends the case to the correct approver and prevents self-approval. High-risk or ambiguous cases reach ABC compliance or legal. Reasons and evidence are mandatory.

5. Execution and accounting. Approved values and recipients flow to procurement, accounts payable, expense, HR or payment systems. Changes after approval trigger revalidation. Ledger descriptions and supporting documents reflect the real purpose.

6. Monitoring, investigation and feedback. Post-event analytics look for cumulative patterns, control bypass, repeated exceptions, bank-account changes, employee-vendor links and policy breaches. Confirmed weaknesses feed back to risk assessments and controls.

ABC controls should connect business request, due diligence, approval, payment, accounting, monitoring and investigation.

Data and system touchpoints

A multinational bank may hold ABC-relevant data across CRM, customer due diligence, vendor management, procurement, contract lifecycle management, accounts payable, expense platforms, HR, travel systems, payment hubs, general ledger, whistleblowing systems, investigations platforms and data warehouses. The risk is not only missing data but incompatible identifiers.

If the vendor platform identifies Horizon Advisory Ltd, accounts payable uses a vendor number, payments store only an IBAN or account number, and the case system records an abbreviated name, investigators need a reliable way to join those records. Master data and relationship identifiers are therefore financial-crime controls.

A useful event model includes:

  • business event ID and event type;
  • bank legal entity and business line;
  • employee/requestor and approver identities;
  • third-party/customer/counterparty identifiers;
  • ownership and connected-party relationships;
  • public-official/PEP indicators with source and classification;
  • jurisdiction facts and applicable rule versions;
  • amount, currency, payment account and payment date;
  • contract, invoice, expense or recruitment evidence;
  • approval status and decision reason;
  • accounting code and narrative;
  • monitoring alerts, cases and remediation actions.

The model should be effective-dated. An ownership relationship, official role or policy threshold can change. A later investigation must reconstruct what the bank knew and what rule applied at the time of the event.

Screening, monitoring and detection

ABC detection is broader than name screening. Sanctions and PEP data can provide useful context, but corruption schemes frequently involve unlisted intermediaries or people who do not match a conventional PEP definition.

Potential monitoring patterns include unusually high commissions, payments to accounts in unrelated countries, duplicate invoices, vague service descriptions, round-dollar consulting fees, split payments, frequent bank-account changes, payments before contract execution, repeated manual overrides, gifts clustered around procurement decisions, employee-vendor address matches or donations linked to customer decision-makers.

The system should combine signals. A high commission alone may be commercially justified. A high commission to a newly formed intermediary with no staff, an official connection and a request for payment to an unrelated offshore account deserves stronger review.

Detection models also need negative evidence and segmentation. A global rule calibrated for investment-banking advisory fees may generate nonsense when applied to commodity vendors. Thresholds should be explainable, tested and reviewed.

Alert to case to investigation

An ABC alert should begin with a clearly stated concern, not a predetermined conclusion. The investigator needs to know what triggered the case, which event is affected and what question must be answered.

A strong investigation builds a chronology. It identifies how the relationship began, what approvals were given, who interacted with whom, what service was expected, what actually happened, which payments moved, how those payments were recorded and what changed over time.

Evidence may include contracts, tender files, due-diligence reports, invoices, emails, chat records, travel data, expense claims, HR records, payment details, accounting entries, vendor master changes and interview notes. Collection must respect employment law, privacy, secrecy, privilege and cross-border data restrictions. Legal counsel should direct legally sensitive collection and disclosure decisions.

The investigator should distinguish:

  • fact — something supported by evidence;
  • allegation — a claim that still needs testing;
  • indicator — a fact that increases concern but does not prove misconduct;
  • inference — a reasoned conclusion drawn from evidence;
  • legal conclusion — a determination reserved for the appropriate legal authority.

That discipline reduces confirmation bias and makes case files defensible.

Investigations should preserve the chronology from business opportunity through third-party engagement, payment, accounting, detection and outcome.

ABC and AML: connected but not identical

Bribery can generate criminal proceeds and therefore intersect with money laundering, suspicious transaction reporting and customer-risk management. But an ABC case and an AML case answer different questions.

ABC asks whether the bank, its staff or connected parties may have offered, requested, authorised, concealed or facilitated an improper advantage, and whether preventive controls operated. AML asks whether money or assets may represent criminal proceeds, terrorist financing or another suspicious activity under the applicable legal framework. A case may require both workstreams, but one should not automatically substitute for the other.

If an ABC investigation identifies suspicious payments through a customer's account, the matter may need an AML referral. The AML team then applies its own legal standard for SAR/STR decisioning. The ABC investigator should not promise a filing outcome or tell the subject that a suspicious activity report is being considered.

Roles and governance

ABC governance works when decision rights are explicit.

The board or senior governing body sets risk appetite and expects credible oversight. Senior management owns implementation and resources. Business leaders own the conduct of their teams and the legitimacy of business events. Procurement, finance, HR and operations own key preventive controls. ABC compliance sets standards, advises on higher-risk cases, monitors the programme and challenges the first line. Legal interprets law and manages privileged or enforcement-sensitive matters. Investigations teams establish facts. Internal audit provides independent assurance.

A global committee should not become the place where every routine event is approved. Governance should be proportional and delegated, with clear escalation for public-official interactions, high-risk intermediaries, unusual payment structures, senior-management conflicts, investigations and policy exceptions.

ABC governance should separate business ownership, compliance challenge, legal interpretation, investigation and independent assurance.

Customer and operational impact

Strong ABC controls can create friction. A legitimate payment may be delayed while the bank confirms the invoice or recipient. A vendor may be asked for ownership information that feels intrusive. A customer may face questions about public-sector relationships. Employees may experience approval steps for travel or hospitality.

The answer is not to remove controls, but to make them predictable and risk-based. Low-risk routine activity should move efficiently. High-risk exceptions should receive specialist review. Customer-facing teams should explain information requests neutrally without accusing the customer or vendor of corruption.

Operational metrics should therefore measure both risk and service: approval ageing, payment holds, exception rates, repeat requests, incomplete evidence, investigation backlog, control overrides, customer complaints and remediation time. A fast process with poor evidence is not effective; a technically perfect process that routinely blocks legitimate activity is not sustainable.

Common failure modes

ABC programmes fail in recognisable ways.

One is policy without system linkage. Employees complete a due-diligence questionnaire, but accounts payable can later send money to a different bank account without re-checking approval.

Another is screening as due diligence. A vendor has no sanctions or PEP hit, so the relationship is treated as safe despite weak capability, unusual fees or opaque ownership.

A third is threshold gaming. Gifts or expenses are split below approval limits because controls look only at individual events rather than cumulative value.

A fourth is jurisdiction flattening. A global policy hard-codes one country's legal definitions into every entity and loses local legal requirements.

A fifth is inaccurate accounting. Generic ledger descriptions make it impossible to understand the true purpose of payments.

A sixth is uncontrolled exceptions. Business pressure creates verbal approvals that bypass the recorded workflow.

A seventh is investigation without remediation. A case is closed after individual misconduct is addressed, but the control weakness that allowed it remains.

What a business analyst should specify

A BA should avoid requirements such as “the system shall comply with anti-bribery laws.” That statement is not testable.

A buildable requirement identifies the event, fields, rule source, actor, decision, evidence and exception. For example: when a third-party engagement is created for a government-facing service, the workflow must capture service description, selection rationale, ownership, official connections, fee basis, subcontractors and proposed payment countries; it must apply the legal-entity policy version effective on the request date; and it must prevent activation until the required approval is recorded.

Another requirement might state that accounts payable may release a third-party invoice only when the vendor, bank account, contract, approved fee basis and invoice evidence match an active approved relationship; a material mismatch must create a controlled exception rather than silently update the master record.

Architects then translate this into services, identifiers, rule versioning, workflow states, audit events and integration contracts. Testers prove the design with positive, negative, boundary, missing-data, changed-data, historical-rule and access-control cases.

What good looks like

A mature bank can answer five questions quickly:

  1. What business event are we controlling?
  2. Which legal entities, people and jurisdictions matter?
  3. What evidence supports the commercial purpose and approval?
  4. Did the payment and accounting match what was approved?
  5. Can we reconstruct the decision and learn from exceptions later?

When those questions are joined, ABC becomes more than annual training. It becomes an auditable control system that connects law, business conduct, third parties, money movement, accounting, investigations and governance.

Operational deep dive: turning extraterritorial law into a bank control

The difficult part of an ABC programme is not writing the global prohibition. The difficult part is deciding what happens when facts cross legal entities, jurisdictions, business lines and systems. A bank may have a global policy that prohibits bribery, but the operational workflow still has to answer which entity owns the risk, which law may apply, who can approve the activity, which records must be retained and what should happen if the facts change after approval.

This deep dive focuses on that operating problem.

Build a jurisdiction map before you build rules

A common delivery mistake is to begin with workflow screens and approval thresholds. The safer sequence is to build a legal and policy map first.

For each significant ABC regime, the bank should maintain structured metadata covering the legal source, effective date, covered persons and entities, prohibited conduct, relevant jurisdictional hooks, key definitions, statutory defences or exceptions, accounting obligations, enforcement authority, recordkeeping implications and internal policy treatment. The metadata should be owned by legal or compliance rather than hard-coded by a technology team.

The rule engine should then use facts to route a case to the correct overlay.

For example, a third-party engagement connected with a public-sector mandate might have the following facts:

  • the contracting bank entity is incorporated in Country A;
  • its parent is an issuer in the United States;
  • the business is partly conducted through a UK branch;
  • the third party is incorporated in Country B;
  • the relevant official works for a state-owned enterprise in Country C;
  • the fee is paid from Country D;
  • meetings and approvals occurred in several countries.

A weak system asks, “Which country is the payment going to?” A stronger system asks, “Which legal nexuses are present, and which approved legal owner must assess them?”

The output may be multiple applicable overlays rather than one.

Effective dating

The jurisdiction table should be effective-dated. Laws, guidance and enforcement policies change. Definitions are amended. new offences enter into force. Enforcement agencies publish guidance. A transaction approved in 2024 may need to be reviewed under the rules that applied in 2024, not under a 2026 policy version.

The same requirement applies to internal policy. If the bank changes its hospitality threshold or third-party risk model, the historical case should preserve which version applied at the time.

This means the data model needs:

ruleSetId, jurisdiction, legalEntity, effectiveFrom, effectiveTo, sourceReference, policyVersion, decisionOwner, controlAction and supersededBy.

A system that stores only the latest value cannot reliably support investigations or audit.

Distinguish public-official classification from PEP screening

PEP screening is useful but not equivalent to public-official analysis.

A politically exposed person framework is designed primarily for AML and corruption-risk due diligence. A bribery statute may use a different definition of public official or foreign official. Employees of state-owned or state-controlled enterprises can require particular analysis. Public international organisations can be relevant. A person may be a public official for an anti-bribery law even if the bank's PEP data provider does not classify the person as a PEP.

The architecture should therefore maintain distinct concepts:

  • pepStatus
  • publicOfficialIndicator
  • stateOwnedEntityIndicator
  • publicInternationalOrganisationIndicator
  • officialRelationshipEvidence
  • classificationSource
  • classificationDate
  • legalInterpretationRequired

This avoids a false negative where a clean PEP screen is treated as proof that no public-official risk exists.

It also avoids a false positive. A PEP status does not mean the person is corrupt. It is a risk factor requiring proportionate handling.

Third-party due diligence should test purpose, not only identity

Most banks can screen a third party for sanctions, PEPs and adverse media. That is necessary but insufficient for ABC.

A good third-party review tests the commercial logic of the relationship.

The reviewer should understand why the business cannot perform the service itself, why the third party was selected, how the fee was determined, what deliverables will be produced, whether the third party will interact with officials, whether subcontractors are allowed, and whether the payment destination matches the contractual relationship.

A consultant with no employees, no relevant experience and a 10 percent success fee on a public-sector mandate should not be cleared merely because its beneficial owner is not on a watchlist.

The strongest controls connect due diligence to the later payment. At payment time, the system should verify that the third party remains approved, the contract is active, the invoice matches the contracted service, required deliverables exist, bank-account details are consistent, and the payment does not exceed approved fee structures.

If due diligence and accounts payable are separate control universes, an ABC programme can fail after a perfect onboarding review.

Books and records are an evidence system

Accounting accuracy is not just a finance concern. It is part of the ABC control environment.

A payment description should allow a reasonable reviewer to understand what the payment was for. Generic descriptions such as “consulting,” “marketing support,” “miscellaneous service” or “special fee” are not automatically improper, but they are weak evidence when the underlying service is not linked.

A mature system stores or links:

  • contract and statement of work;
  • invoice;
  • purchase order where applicable;
  • service evidence;
  • approval;
  • third-party due-diligence status;
  • business sponsor;
  • cost centre;
  • general-ledger account;
  • beneficiary bank details;
  • payment reference;
  • related opportunity or mandate;
  • exception or legal-review reference.

The bank should be able to move from the ledger entry to the business event and back again.

That traceability supports the FCPA accounting-control framework for issuers, but it also provides good practice under broader anti-corruption frameworks.

Facilitation payments: do not build a loophole engine

Facilitation payments are a classic example of why a global programme needs legal layering.

The FCPA contains a narrow exception relating to facilitating or expediting payments for routine governmental action. The UK Bribery Act does not contain an equivalent exception. Other countries vary, and a bank's internal policy may prohibit the practice even where a narrow legal exception exists.

The technology design should therefore not include a simple button labelled “facilitation payment allowed.”

A safer workflow asks:

  1. Is there a demand for value connected to an official act?
  2. Is there an immediate threat to health or safety?
  3. Is the payment already prohibited by policy?
  4. Which laws and entities may apply?
  5. Has legal or compliance approved any exceptional treatment?
  6. How will the payment be accurately recorded?
  7. Is post-event escalation required?

Emergency payments made under duress or immediate safety threats should have a dedicated route because the evidential and legal analysis differs from a payment made for commercial convenience.

The system should preserve the circumstances rather than force staff to disguise the payment under another expense category.

Gifts and hospitality: context beats threshold

A threshold is useful for workflow routing, but it is not a definition of bribery.

Consider two cases. In the first, an employee hosts three private-sector clients for a modest meal after a routine service review. In the second, an employee provides repeated hospitality just below the approval threshold to a procurement official during a tender. The second pattern is more concerning despite each individual event being low value.

The data model should therefore support aggregation by recipient, employee, business opportunity, public-sector entity and time period.

Useful detection patterns include:

  • repeated events just below approval levels;
  • multiple employees entertaining the same official;
  • hospitality during a live tender, licence or inspection;
  • family travel;
  • luxury or leisure-heavy events with weak business content;
  • reimbursement through another employee;
  • retrospective approval;
  • manual override of recipient classification;
  • recurring exceptions for the same business sponsor.

Again, these patterns are indicators, not proof.

Donations and sponsorships: identify indirect benefit

A charitable payment can be legitimate and socially valuable. Risk increases when an official or decision-maker requests it, when the beneficiary is controlled by a connected person, when the donation is timed around a business decision, or when the organisation cannot explain how funds will be used.

The control should capture:

  • who proposed the donation;
  • whether a customer, official or intermediary requested it;
  • beneficiary ownership and governance;
  • connection to current business;
  • payment destination;
  • purpose and budget;
  • approval;
  • evidence of use where risk warrants it.

If a public official asks the bank to donate to a foundation chaired by a family member while the bank is bidding for a mandate, the system should join those facts.

Recruitment: a benefit can be non-cash

Employment and internships can be things of value. That does not mean hiring a relative of an official is automatically unlawful. The risk turns on intent, process integrity and business context.

The bank should preserve evidence that hiring criteria were applied consistently, qualifications were assessed, the decision was independent, compensation was normal, and the process was not used as consideration for business.

High-risk referral sources can be flagged in recruitment systems without making the relationship visible more broadly than privacy law and internal policy permit.

Investigating an ABC concern

An ABC investigation should begin with an allegation statement that is specific enough to test. “Possible corruption” is too broad. A better statement might be:

A relationship manager allegedly caused the bank to pay an introducer a success fee, knowing that part of the fee would benefit an employee of a state-owned client in return for a mandate.

That allegation identifies actors, value, intermediary, recipient, purpose and business outcome.

The investigation plan can then identify evidence:

  • engagement approval;
  • third-party due diligence;
  • ownership information;
  • contract and fee terms;
  • invoices and payments;
  • communications;
  • expense records;
  • meeting records;
  • public-official or state-ownership analysis;
  • opportunity pipeline;
  • accounting entries;
  • prior similar relationships;
  • whistleblower or interview evidence.

Investigators should build a chronology. Timing often reveals the relationship between value and business decisions more clearly than a document-by-document review.

A useful timeline might show:

Tender announced -> introducer engaged -> unusual fee increase -> official meeting -> hospitality -> mandate awarded -> invoice issued -> payment split -> donation request -> payment to new account.

The sequence does not prove bribery, but it creates testable questions.

Legal privilege and cross-border evidence

Multinational investigations can involve legal privilege, employment law, data-protection restrictions, bank secrecy and cross-border transfer rules. These issues vary significantly by jurisdiction.

The workflow should therefore have an early trigger for legal advice where an investigation may require employee communications, device data, sensitive personal data or cross-border document transfer.

Technology teams should not assume that a central investigation platform can ingest every record globally. Some evidence may need to remain in jurisdiction, be redacted, or be accessed through controlled review.

The case record should distinguish:

  • source evidence;
  • legal analysis;
  • privileged material;
  • interview notes;
  • system-generated alerts;
  • investigator conclusions.

Access controls should follow those categories.

From investigation to remediation

Closing the allegation is not the end of the control lifecycle.

If the investigation identifies a weak third-party approval process, the bank should determine whether the issue is isolated or systemic. That may require a lookback, rule change, contract remediation, retraining, disciplinary action, vendor termination, accounting correction or reporting analysis.

Root-cause categories can include:

  • policy design;
  • unclear ownership;
  • system gap;
  • data-quality issue;
  • override abuse;
  • training failure;
  • supervision failure;
  • deliberate circumvention;
  • weak third-party governance;
  • inadequate finance control.

The action owner and due date should be stored separately from the investigation outcome. Otherwise a closed case can hide an open control weakness.

Management information that reveals risk

A dashboard that says “97 percent of gifts approved within SLA” may look healthy while hiding concentration around a high-risk public-sector client.

Better MI combines volume, risk and outcome.

Examples include:

  • high-risk third parties by business line and country;
  • overdue enhanced due diligence;
  • percentage of high-risk third parties paid before full approval;
  • government-related opportunities with third-party involvement;
  • gifts and hospitality concentrated around live tenders;
  • repeat policy exceptions by sponsor;
  • vendor payments to countries unrelated to the contract;
  • investigations involving books-and-records issues;
  • control overrides;
  • post-acquisition remediation ageing;
  • audit findings repeated across entities.

Trend interpretation should be documented. A sudden drop in hotline allegations may require investigation, not celebration.

What a defensible file looks like

A reviewer who was not present at the time should be able to answer five questions from the record:

What happened? The business event and risk trigger are clear.

Which rules applied? Policy and legal overlays are dated and identifiable.

What evidence was reviewed? Sources are linked and provenance is clear.

Who decided what? Decision rights and approvals are explicit.

What happened afterwards? Payment, monitoring, remediation and review outcomes are recorded.

That is the operational meaning of an auditable ABC framework.

Advanced practice: architecture, controls and testing for a multinational bank

This supplement converts the legal and operational model into delivery requirements. It is written for business analysts, architects, product owners, developers, testers and control owners who need to build an ABC capability without pretending that software can determine bribery law by itself.

Start with the event model

ABC systems often fail because they are designed as forms rather than as events.

A form captures a snapshot. An event model captures what changed, when it changed, who changed it and which control should respond.

Important events can include:

  • third party proposed;
  • due diligence initiated;
  • ownership changed;
  • public-official connection identified;
  • risk rating changed;
  • contract approved;
  • gift or hospitality requested;
  • donation requested;
  • payment instruction created;
  • bank account changed;
  • invoice submitted;
  • policy exception requested;
  • investigation opened;
  • legal overlay changed;
  • remediation action closed.

Each event should carry an identifier, timestamp, source system, legal entity, business owner and correlation key so it can be linked to the underlying relationship.

This is especially important where several systems participate. A procurement platform may approve a vendor, a due-diligence platform may approve the risk, and a payment platform may execute the invoice. Without a common third-party identifier, the bank cannot reliably prove that the paid vendor is the approved vendor.

Design an ABC entity graph

A graph view can materially improve corruption investigations because relationships matter.

Useful nodes include:

  • bank legal entity;
  • employee;
  • customer;
  • public-sector entity;
  • public official;
  • third party;
  • beneficial owner;
  • charity or foundation;
  • vendor;
  • payment account;
  • business opportunity;
  • contract;
  • invoice;
  • payment;
  • gift or hospitality event.

Useful edges include:

  • owns;
  • controls;
  • employed by;
  • related to;
  • introduced by;
  • approved by;
  • paid to;
  • requested by;
  • linked to opportunity;
  • subcontracted to;
  • beneficiary of.

The graph should not assign guilt. Its purpose is to surface connections that are difficult to see in separate tables.

For example, a charity may appear low risk until the graph shows that its chair is related to an official involved in a current mandate and that the donation was requested by the same consultant receiving a success fee.

Separate risk scoring from legal decisions

A risk score is a prioritisation tool. It should not be the legal conclusion.

A third-party risk model might use:

  • country risk;
  • public-sector interaction;
  • commission structure;
  • ownership transparency;
  • service type;
  • adverse information;
  • subcontracting;
  • payment destination;
  • government licences;
  • historical control issues.

The score can route the case to standard or enhanced due diligence. It should not say “FCPA applies” or “UK Bribery Act violation” unless a qualified legal decision process has made that determination.

Architecture should therefore use separate objects:

  • riskAssessment;
  • legalNexusAssessment;
  • policyDecision;
  • transactionDisposition;
  • investigationOutcome.

This separation prevents downstream teams from treating a compliance score as a legal fact.

Rules need provenance

Every automated rule should have an owner and source.

A rule record should explain:

  • what the rule detects;
  • why the rule exists;
  • which policy or risk assessment supports it;
  • who approved it;
  • which data fields it uses;
  • effective date;
  • threshold rationale;
  • expected false-positive behaviour;
  • review date;
  • test cases;
  • fallback behaviour when data is missing.

This matters because corruption controls can drift into folklore. A threshold created years earlier can become treated as law even though it was only an internal routing limit.

High-risk third-party acceptance criteria

A business requirement should be testable. “Perform enhanced due diligence” is too vague.

A stronger set of acceptance criteria can state:

  1. A third party cannot reach approved-high-risk status until beneficial ownership, service purpose, fee basis, public-official connections, adverse information, sanctions/PEP screening and approval evidence are complete.
  2. Missing mandatory evidence routes the case to pending-information, not approved.
  3. A high-risk approval has an expiry date.
  4. A bank-account change after approval triggers revalidation before payment.
  5. A change in beneficial ownership triggers event-driven review.
  6. A third party cannot be paid if its due-diligence status is expired, suspended or rejected unless a documented emergency override exists and is independently approved.
  7. The payment system records the due-diligence status and approval identifier used at execution time.
  8. Overrides are reported to compliance MI and cannot be approved by the business sponsor alone.

These requirements can be tested.

Payment controls and exception handling

The normal payment path should be predictable:

invoice -> contract match -> third-party status -> service evidence -> approval -> accounting coding -> beneficiary validation -> payment.

The exception path needs equal design attention.

An exception might arise because:

  • a critical payment is due while due diligence is being renewed;
  • a bank account has changed;
  • an invoice exceeds contracted fees;
  • a public-sector opportunity has accelerated;
  • service evidence is incomplete;
  • a legal hold is in place;
  • a potential official connection is unresolved.

The workflow should state who can override, what evidence is mandatory, how long the override lasts, and what post-event review is required.

Avoid permanent override flags. An override should be a dated decision with a defined scope.

Monitoring design

ABC monitoring should combine transactional and non-transactional data.

Third-party monitoring

Possible indicators include:

  • commission significantly different from peers;
  • success fee associated with public-sector business;
  • payment to a different legal entity or country;
  • multiple bank-account changes;
  • invoice splitting;
  • rapid payment after mandate award;
  • vague service descriptions;
  • repeated exceptions;
  • subcontractor payments not disclosed in due diligence.

Expense monitoring

Possible indicators include:

  • repeated hospitality just below approval limits;
  • multiple employees entertaining the same recipient;
  • unusual weekend or resort locations;
  • family travel;
  • retrospective approvals;
  • expenses around tender milestones;
  • manual category changes.

Recruitment monitoring

Possible indicators include:

  • candidate referral by public official or client decision-maker;
  • qualification waiver;
  • non-standard compensation;
  • accelerated process;
  • hiring near a business decision.

Donation monitoring

Possible indicators include:

  • request by official;
  • beneficiary connected to customer decision-maker;
  • unusual payment destination;
  • donation outside normal strategy;
  • timing close to licence, tender or inspection.

None of these should create an automatic accusation. They create a review.

Testing the programme

ABC testing should include positive, negative, boundary and failure-mode scenarios.

Positive tests

A positive test should confirm that a known high-risk pattern triggers the expected control.

Examples:

  • a high-risk agent with government interaction and an unresolved owner is blocked from approval;
  • a payment to a suspended third party is stopped;
  • repeated hospitality below threshold is aggregated and escalated;
  • a bank-account change triggers revalidation;
  • a public-official referral is visible to the appropriate recruitment-control team.

Negative tests

Negative tests confirm that legitimate activity is not unnecessarily disrupted.

Examples:

  • a low-risk vendor renewal with complete evidence proceeds without high-risk escalation;
  • normal client hospitality outside a tender period follows standard approval;
  • a public-sector customer is not treated as suspicious merely because of state ownership;
  • a legitimate charity with no official connection can be approved under the normal workflow.

Boundary tests

Test exactly at and around thresholds. If approval changes at 500 units, test 499, 500 and 501. Then test repeated 499-unit events to see whether aggregation catches threshold avoidance.

Missing-data tests

Remove a critical field and verify the system fails safely. If thirdPartyRiskStatus is unavailable, does payment proceed silently? If the official-classification service is down, is there a documented fallback?

Temporal tests

Use historical dates. Confirm the workflow applies the policy version in force at the transaction date. Test a third party whose risk rating changed between approval and payment.

Access-control tests

Ensure the business sponsor cannot approve its own high-risk exception. Ensure investigators cannot alter source evidence. Ensure privileged material is restricted.

Audit-trail tests

Change a decision, owner or risk factor and verify both the previous and new values remain reconstructable.

Non-functional requirements

ABC systems handle sensitive data and can affect important transactions. Non-functional requirements matter.

Availability: payment or procurement dependencies need defined fallback behaviour.

Latency: real-time payment systems may not be the right place for deep ABC due diligence. Preventive controls should often occur earlier in the lifecycle.

Security: investigation data, whistleblower information and legal advice require restricted access.

Retention: retention periods depend on law, regulation, litigation hold and bank policy. Do not hard-code one global period.

Explainability: a reviewer should understand why a workflow escalated.

Observability: control failures should create technical alerts and operational incidents, not disappear as generic errors.

Change control: risk-rule changes need testing, approval and versioning.

M&A and successor risk

Mergers and acquisitions deserve a dedicated integration plan.

Pre-acquisition review should identify:

  • public-sector business;
  • agents and consultants;
  • high-risk countries;
  • commission structures;
  • unresolved investigations;
  • accounting-control weaknesses;
  • government licences;
  • whistleblower themes;
  • unusual donations and sponsorships.

The level of diligence depends on access and deal structure. In some transactions, full data is unavailable before closing. The bank should document what could and could not be reviewed.

Post-close, the acquiring group should implement a risk-based integration plan. Typical actions include:

  • extending the code and ABC policy;
  • screening and risk-rating third parties;
  • testing books and records;
  • reviewing high-risk payments;
  • training exposed employees;
  • migrating approval workflows;
  • addressing known misconduct;
  • escalating potential disclosure or reporting issues to legal.

Successor-liability analysis is jurisdiction-specific. The FCPA Resource Guide provides U.S. guidance, but the bank should not convert U.S. acquisition concepts into a universal global rule.

Assurance: prove effectiveness, not existence

An auditor should not be satisfied merely because a control exists in a procedure.

For each key control, assurance should ask:

  • Is it designed to address the identified risk?
  • Is it implemented in every in-scope entity?
  • Does it operate consistently?
  • Are exceptions controlled?
  • Is evidence complete?
  • Does the control catch known scenarios?
  • Are false positives proportionate?
  • Are failures remediated?
  • Does management information reveal deteriorating performance?

The difference between a paper programme and an effective programme is observable behaviour.

BA requirements that prevent common failures

The following requirement patterns are particularly valuable:

Correlation: Every high-risk third-party payment must be traceable to the approved third-party record and contract.

Historical state: Risk status, rule version and approval evidence must be preserved as of the transaction date.

Segregation: A business sponsor cannot both request and finally approve a high-risk exception.

Revalidation: Material changes in ownership, bank account, service, country or public-official connection must trigger review.

Explainability: Every automated escalation must expose the data factors and rule version that generated it.

Fail-safe design: Missing mandatory risk data must not silently default to low risk.

Exception expiry: Overrides must expire automatically and require reapproval if still needed.

Case linkage: Investigations must link to the originating transaction, third party, opportunity and accounting entry where available.

Remediation linkage: A substantiated control failure cannot be closed without either a remediation action or a documented rationale that no remediation is required.

These requirements are simple enough to test and strong enough to matter.

The architect's final question

The most useful architecture test is this:

If a regulator asked two years later why this payment was made, could the bank reconstruct the business purpose, third-party status, legal overlay, approval, invoice, service evidence, accounting entry, payment and subsequent monitoring from controlled data?

If the answer is no, the ABC system is not finished.

Practice close: decision checklist, failure modes and quality criteria

This section turns the chapter into a compact operating reference. It is not a substitute for legal advice or the bank's jurisdiction-specific policy.

Before approving a government-facing third party

A reviewer should be able to answer the following questions in plain language.

Purpose: Why is the third party needed, and what will it actually do?

Selection: Who proposed it? Was it referred by a customer, official or decision-maker?

Ownership: Who ultimately owns and controls it? Are there official, state-entity or employee connections requiring review?

Capability: Does it have the people and experience to perform the stated service?

Compensation: Is the fee commercially reasonable? Is it a success fee? Are expenses and commissions clear?

Government interaction: Will it contact officials, regulators, customs, licensing bodies, state-owned enterprises or public international organisations?

Subcontracting: Can it use subcontractors, and must they be approved first?

Payment: Will money go to the contracting entity's own account in an expected jurisdiction?

Evidence: What deliverables will prove the service was performed?

Approval: Is the final decision independent from the sponsor who benefits from winning the business?

A reviewer who cannot answer these questions should not hide uncertainty inside a low risk score.

Before releasing a high-risk payment

The payment-control layer should confirm current third-party approval, contract and invoice alignment, service evidence, beneficiary-account validity, accurate accounting coding and any required enhanced approval. A bank-account change or suspension should trigger revalidation before release.

The purpose is not to duplicate due diligence. It is to confirm that the facts on which approval depended have not broken.

When a potential bribery concern is raised

Preserve the allegation in the reporter's own words where possible. Limit distribution. Assess conflicts. Identify immediate payment or evidence-preservation actions. Engage legal early where privilege, cross-border data, employment law or reporting may be relevant.

Do not casually confront subjects before evidence is secured. Do not label a customer or official corrupt in broadly visible systems. Do not rewrite the original alert after facts change. Do not use an AML conclusion as a substitute for ABC analysis.

Quality criteria for a completed ABC case

A high-quality case demonstrates traceability, chronology, evidence provenance, jurisdiction discipline, balanced reasoning, explicit decision ownership, separate outcomes for policy/control/legal issues, and owned remediation for systemic weaknesses.

Failure-mode table

FailureWhy it mattersBetter design
PEP screen treated as public-official determinationDefinitions differ and data can be incompleteKeep separate official-classification evidence
Success fee approved because it is “market practice”Local custom is not a legal defenceTest purpose, fee and official interaction
Gift threshold used as a safe harbourRepeated low-value benefits can still create riskAggregate by recipient and opportunity
Third party approved indefinitelyOwnership and services changeEffective-dated approval and event review
Due diligence disconnected from paymentRestricted parties can still be paidEnforce live status before release
Generic ledger descriptionsWeakens reconstructionLink entry to contract, invoice and evidence
One global jurisdiction flagHides different legal nexusesMaintain versioned jurisdiction overlays
Investigation closes before remediationControl weakness survivesSeparate case closure from issue closure

BA acceptance criteria

A product owner should expect the design to meet these minimum conditions:

  1. Mandatory data has a defined source, owner and validation rule.
  2. Workflow states distinguish pending, approved, rejected, suspended, expired and exception-approved.
  3. High-risk exceptions require independent approval.
  4. Rule and policy versions are stored with decisions.
  5. Historical values are not overwritten.
  6. Payment controls consume current third-party status where required.
  7. Missing risk data fails to a controlled state rather than low risk.
  8. Alerts expose the factors and rule version that triggered them.
  9. Case systems preserve source evidence and audit history.
  10. Metrics identify overrides, ageing, repeated exceptions and remediation gaps.
  11. Sensitive evidence supports jurisdiction-appropriate access restrictions.
  12. Test data includes legitimate public-sector business to prove the control does not equate government exposure with wrongdoing.

Minimum test pack

Test an ordinary low-risk vendor, a high-risk government-facing introducer, repeated sub-threshold hospitality during a tender, an official-referred but qualified candidate, a vendor bank-account change, a risk-service outage, a historical transaction under an older policy version and a state-owned-enterprise employee who is not identified as a PEP.

For each scenario, verify both the risk outcome and the customer or business impact. A control that catches high-risk patterns but blocks legitimate business indiscriminately is not well designed.

Final control statement

A bank can describe its ABC framework as effective only when the prohibition, legal overlay, preventive controls, payment and accounting controls, investigation process and remediation loop work together.

The practical standard is simple:

Know who is acting, know why value is moving, know which legal entities and rules may apply, preserve the evidence, separate risk indicators from legal conclusions, and make every important decision reconstructable.

Masterclass case: the public-sector mandate, the introducer and the hidden benefit

This is a composite teaching case. It does not describe a real bank or enforcement action. The purpose is to show how facts that look ordinary in isolation can become significant when they are joined across third-party due diligence, public-sector relationships, expenses, accounting and payments.

The business opportunity

Northshore Bank Group is a multinational bank. Its parent is listed in the United States. It has a UK-incorporated subsidiary and operations in several other countries.

A corporate banking team is competing for a multi-year cash-management and bond-services mandate from Metro Infrastructure Authority, a state-owned entity in Country Z. The potential revenue is material but not transformational.

The local relationship manager proposes using Horizon Strategic Advisory, a small consultancy. Horizon claims it can help the bank “navigate stakeholders” and improve the proposal. The consultancy requests a success fee equal to 4 percent of first-year revenue if the mandate is won.

The relationship manager says that local competitors use similar advisers and that there is no time for a lengthy review.

The first control signals

Third-party onboarding identifies the following facts:

  • Horizon was incorporated eighteen months earlier.
  • It has two employees.
  • Its website lists broad “government relations” experience but few named engagements.
  • The beneficial owner is a former employee of Metro Infrastructure Authority.
  • Adverse-media searches do not identify corruption allegations.
  • The beneficial owner is not listed as a PEP by the bank's provider.
  • The proposed fee is higher than fees for comparable strategic advisers.
  • The service description is “stakeholder alignment and strategic access.”

None of these facts proves bribery.

A weak process would say: sanctions clear, PEP clear, adverse media clear, therefore approve.

A stronger process asks why the bank needs the adviser, what deliverables will be produced, why the fee is percentage-based, whether the owner has current official connections and whether “strategic access” means legitimate market advice or influence over decision-makers.

The due-diligence team requests further information.

A new relationship appears

The business sponsor explains that Horizon was recommended by the deputy procurement director of Metro Infrastructure Authority.

That fact changes the risk assessment.

The deputy procurement director is involved in the mandate evaluation. Horizon's beneficial owner is not related to the official, but records show they worked together at the authority for several years.

The case is escalated to ABC compliance.

Compliance does not reject the relationship automatically. It asks for a clearer statement of work, evidence of market-rate pricing, confirmation of whether Horizon will interact with procurement officials, and contractual commitments prohibiting improper payments and undisclosed subcontracting.

Horizon resists disclosing its planned contacts, saying its network is confidential.

The business argues that asking more questions could cause the bank to lose the deal.

This is a classic pressure point: commercial urgency versus control completeness.

The hospitality event

While due diligence remains open, the relationship manager submits an expense request for dinner with three Metro officials and two Horizon representatives.

The per-person amount is just below the business unit's enhanced-approval threshold.

The expense system sees a compliant amount and routes it for normal manager approval.

However, an aggregation rule identifies that the same relationship manager hosted one of the Metro officials twice in the previous month. The third event falls within the active tender period.

The case is sent to ABC compliance.

Again, hospitality itself is not proof of bribery. The significance comes from timing, repeated contact, pending third-party concerns and the official's role in the procurement process.

Compliance declines the planned dinner and reminds the team that business hospitality during a live public tender requires enhanced review under policy.

The third-party contract changes

A week later, Horizon accepts a fixed fee instead of the 4 percent success fee. That is positive, but a new clause allows Horizon to use “specialist local partners” without naming them.

Procurement rejects the clause and requires prior written approval for subcontractors.

Horizon eventually names one subcontractor: Delta Community Services, a local company described as providing research and logistics.

The bank's ownership data shows that Delta is owned by the sister of the deputy procurement director.

This does not automatically establish that the deputy official benefits from Delta. It does, however, create a clear conflict and indirect-benefit concern.

Compliance pauses the engagement and sends the facts to legal.

Jurisdiction mapping

Legal does not begin by asking which law is “strongest.” It maps the facts.

Potential U.S. questions arise because the group parent is an issuer and the accounting-control environment may be relevant to the issuer. The FCPA anti-bribery analysis would require detailed facts about covered persons, corrupt intent, foreign-official status, acts in furtherance and business purpose.

Potential UK questions arise because a UK group entity is involved in the business and the group has a UK presence. The Bribery Act analysis includes the general offences, foreign-public-official provisions and possible section 7 considerations depending on which relevant commercial organisation and associated-person relationships are established.

Country Z's domestic anti-corruption law also applies to local conduct and must be assessed by local counsel.

The bank does not conclude that every law definitely applies. It identifies plausible nexuses and assigns qualified legal owners.

This is what an extraterritorial-control framework should do.

The hidden invoice

Before the engagement is formally rejected, accounts payable receives an invoice from Horizon for “market research services” equal to one quarter of the proposed fixed fee.

The invoice references a purchase-order number that was created when the third-party request was first initiated.

The accounts-payable system does not have the current compliance status because the integration runs overnight and the suspension occurred that morning.

The invoice passes the automated three-way match.

A payment clerk notices that the beneficiary bank account is in Country Y rather than Country Z. The clerk raises an exception instead of releasing the payment.

This manual intervention prevents execution.

The case now reveals a system-design weakness: third-party status was not consumed in real time at payment.

The investigation

Legal and compliance open an investigation.

Investigators preserve:

  • the third-party onboarding file;
  • business emails and approved messaging channels;
  • procurement records;
  • expense submissions;
  • opportunity-management records;
  • contracts;
  • invoices;
  • payment instructions;
  • ownership data;
  • public-source information;
  • interview records.

The chronology shows that the relationship manager knew Horizon had been recommended by the procurement official before submitting the initial due-diligence request but did not include that information.

Messages also show the relationship manager asking Horizon whether it could “take care of local expectations.” Horizon replied that it could “make sure the right community people are satisfied.”

The language is ambiguous. Investigators do not treat it as a confession. They ask who the “community people” were and what “satisfied” meant.

Further evidence shows that Horizon planned to pay Delta for unspecified “community liaison.” There is no documented deliverable.

The investigation finds no executed payment by the bank to Horizon or Delta. It nevertheless identifies serious control and conduct concerns.

Outcomes

The bank decides not to engage Horizon and withdraws the proposed third party.

The relationship manager is subject to disciplinary review for incomplete disclosure and attempts to progress an unapproved intermediary.

Finance reviews whether any costs related to the attempted engagement were booked and confirms the pending invoice was not posted as an expense.

Procurement blocks Horizon and Delta pending any future central review.

ABC compliance opens remediation actions:

  1. real-time propagation of third-party suspension status to accounts payable;
  2. mandatory capture of who recommended a high-risk third party;
  3. enhanced review of subcontractors;
  4. aggregated hospitality monitoring during tenders;
  5. clearer success-fee controls for government-facing intermediaries.

Legal assesses whether any reporting, disclosure or regulator engagement is required under applicable law. That decision is not automated and is not assumed in the teaching case.

The public-sector client is not accused. The deputy procurement director is not labelled corrupt. The bank records facts and internal control decisions without publishing unsupported conclusions.

What the case teaches

The case demonstrates why ABC risk is relational.

No single fact was decisive:

  • a former state-entity employee;
  • a success fee;
  • a referral;
  • hospitality;
  • a subcontractor;
  • a related owner;
  • a vague invoice;
  • a foreign bank account.

The risk became clearer when the bank connected them.

It also shows why screening alone is inadequate. Every named party could have returned a clean sanctions result and still created an ABC concern.

The decisive controls were:

  • purpose-based due diligence;
  • conflict and ownership analysis;
  • aggregation of hospitality;
  • subcontractor transparency;
  • payment exception handling;
  • chronology-based investigation;
  • independent escalation.

Legal lessons

The case should not be used to teach that an FCPA or Bribery Act offence definitely occurred. A criminal-law conclusion depends on statutory elements and evidence that this hypothetical deliberately does not resolve.

Instead, it teaches the difference between risk control and legal adjudication.

The bank can refuse a third party under its risk appetite without proving a crime.

The bank can discipline an employee for policy breaches without concluding that bribery occurred.

The bank can remediate a payment-control gap even where no payment was made.

And the bank can preserve possible legal questions for qualified counsel rather than embedding them into a rules engine.

Architecture lessons

The near miss also produces concrete technical requirements.

The third-party platform needs event-driven status publishing.

Accounts payable needs to consume suspension events before payment release.

The opportunity system should identify public-sector tenders and expose that state to hospitality and third-party workflows.

The third-party form should capture referral source and intended official interaction.

Ownership and relationship data should support link analysis without treating family connection as guilt.

The investigation platform should correlate the third party, subcontractor, employee, client, opportunity, expenses, invoice and payment.

This is how legal risk becomes buildable architecture.

Testing the remediation

The remediation is not complete when code is deployed.

Testers should seed scenarios where:

  • a vendor is suspended seconds before invoice release;
  • a subcontractor is added after initial approval;
  • hospitality occurs below threshold but aggregates above risk tolerance;
  • a public-sector tender status changes after expenses are booked;
  • beneficiary account details change;
  • the recommendation source is an official;
  • the opportunity is cancelled and controls should de-escalate appropriately.

The bank should confirm both prevention and customer impact. Controls should stop the high-risk path without blocking ordinary low-risk vendors.

The final judgement

The most important lesson is that ABC controls protect decision integrity.

They are not designed to prove that every unusual payment is corrupt. They are designed to make it difficult to hide improper influence inside normal banking processes, and to ensure that when risk appears, the bank can reconstruct what happened and respond proportionately.

References and further reading

The sources below are public, authoritative materials used for the legal and control framework in this chapter. They should be read with the law and guidance applicable to the bank's own legal entities and facts.