Showing posts with label ERM. Show all posts
Showing posts with label ERM. Show all posts

AI Governance Frameworks For Risk Managers

 

Corporate environments are adopting autonomous systems at a pace that outstrips traditional oversight mechanisms. Engineering teams ship automated workflows daily. Business units integrate external models into core operations without formal review. The resulting environment creates massive blind spots for risk professionals. You cannot manage what you cannot see, and you certainly cannot audit what you do not understand. The era of treating artificial intelligence as a mere productivity enhancement is over. It is now a foundational component of enterprise architecture. This shift demands a complete rethinking of control environments.

Risk managers, compliance officers, and cybersecurity experts must transition from passive observers to active architects of machine behavior. The theoretical debates about future capabilities no longer matter. The immediate reality involves managing current deployments that process sensitive data, execute financial transactions, and interact directly with customers. Professionals who master this transition will define the next decade of corporate governance. Those who fail will preside over catastrophic compliance failures and severe reputational damage.

This guide provides a direct, actionable blueprint for securing autonomous systems. We will explore five essential pillars of modern risk management. These pillars move beyond basic policy documents. They focus on the practical implementation of controls, the integration of global standards, and the strategic career positioning of governance leaders. You will learn how to validate machine outputs, secure third-party integrations, assign legal accountability, capture institutional context, and manage the hidden costs of automated code generation.

The Risk Management Blueprint: A Practitioner's Guide to Quantitative GRC

 

Risk management has a credibility problem. Not because the profession lacks talent, but because color-coded heat maps, ordinal scoring matrices, and quarterly dashboard reviews were never built to change decisions. They exist to document that a compliance process took place. Executive teams know this. They react accordingly by treating risk departments as corporate overhead instead of strategic assets.

I wrote this book to help my peers turn that dynamic around.

After 25 years leading risk functions and advising executive boards across complex multinational companies, I needed a manual that actually bridges advanced quantitative methods with the daily decisions that determine business outcomes. That drive is why The Risk Management Blueprint hit #9 among the most sold risk management books in the weeks after publishing.

At 867 pages, it gives practitioners a single unified methodology across every major risk domain, covering AI systems, cyber exposure, financial cash flows, sustainability transitions, and human behavior. The framework rests on probability theory, financial modeling, and decision science so you can swap subjective scores for numbers that stand up in the boardroom.

You can preview the first four chapters and access the book here: https://amzn.to/4ciag1F

This is not a textbook. It does not spend the majority of its pages diagnosing what is broken in the profession before gesturing toward improvement in a final chapter. More than 70 percent of the book's total length is allocated to domain applications and advanced analytical infrastructure, meaning the bulk of every page is spent on how to build, calibrate, and apply quantitative and predictive risk models across the decisions that actually shape organizational outcomes.

The Risk Management Blueprint for Quantitative and Predictive Models by Prof. Hernan Huwyler, MBA CPA CAIO | Quantitative Risk Management, Predictive Analytics, Probabilistic Risk Models, Monte Carlo Simulation, Financial Risk Modeling, Enterprise Risk Management, Operational Risk, Cyber Risk, AI Risk Management, Risk Analytics, Loss Distributions, Value at Risk, Expected Shortfall, Risk Exposure, Risk-Adjusted Decision Making, Automated Risk Controls and Agentic AI


SOC 2 Is Not Security: A Critical Guide for GRC Managers

Let us be direct. SOC 2 is not a security certification. It is an attestation report issued under AICPA standards in which a licensed public accounting firm expresses an opinion on whether a service organization controls met the selected trust services criteria. The report does not declare that your product is safe. It does not certify that your penetration test was rigorous. It does not prove that your attack surface is small or that your customers are protected from a breach. It states that management described a system, selected criteria, asserted controls, and the auditor found those controls suitably designed and, for a Type II report, operating effectively during the specified period.

That distinction matters more than many teams are willing to admit. The report can create a polished artifact that procurement teams accept, but the underlying controls may still be thin, poorly scoped, or disconnected from the technical reality of the product. The phrase SOC 2 is the audit version of trust me bro became popular for a reason. When the PDF is stronger than the security program, the market starts rewarding documentation rather than operational resilience. As a GRC leader, your job is to reverse that sequence. Build the controls, operate them, collect evidence continuously, and let the SOC 2 report fall out as a byproduct rather than serving as the starting point.

This guide walks through the exact gaps that make SOC 2 incomplete as a security signal, how to read a report without wasting your review cycle, how to build a security-first program that makes SOC 2 the output, how to use continuous assurance strategically, and how to govern vendors that hand you a SOC 2 report and expect instant approval. The focus is practical because the risk owner in the room rarely needs another abstract debate. You need a method for using SOC 2 as one piece of evidence among many.

The article is intended for a global audience. SOC 2 is a US-origin AICPA attestation product, but it is now exchanged across borders by cloud providers, software vendors, data processors, and AI product teams. It often sits alongside ISO/IEC 27001, NIST Cybersecurity Framework, CIS Controls, GDPR, HIPAA, NIS2, and emerging AI governance obligations. That means the underlying discipline remains the same. Understand the limitations, own the controls, and never outsource your risk judgment to a report.

 

The Quantitative Revolution In Enterprise Risk Management

Traditional risk management has reached an inflection point where intuition and qualitative heat maps no longer suffice for navigating complex, interconnected business environments. The modern governance, risk, and compliance director faces a paradox: organizations generate more data than ever before, yet decision makers remain plagued by uncertainty about the very risks that could derail strategic objectives. This gap between information availability and decision quality stems from reliance on uncalibrated expert judgment, measurement of irrelevant variables, and risk models that violate fundamental mathematical principles. The solution lies not in abandoning human expertise, but in rigorously calibrating it through quantitative methods that transform subjective opinions into defensible, mathematically sound probability assessments.

Organizations that master these quantitative techniques gain a decisive competitive advantage. They allocate capital more efficiently by focusing measurement budgets on variables that actually influence decisions. They avoid catastrophic failures by identifying cascade risks and common-mode vulnerabilities before they materialize. They build organizational resilience through models that reflect physical reality rather than statistical convenience. This transformation requires risk professionals to develop new competencies in probability theory, information economics, and computational modeling. The following techniques represent the distilled wisdom of decades of research in decision science, behavioral economics, and quantitative risk analysis. Each method addresses a specific failure mode in traditional risk management, providing practical tools that GRC directors can implement immediately to elevate their organization's risk maturity from descriptive to predictive to prescriptive.

Machine Learning Predictive Risk Modeling for GRC Professionals

AI Use Cases for Risk Management

Machine learning fundamentally transforms risk management from a reactive, sample based discipline into a proactive, population wide surveillance system. The traditional operational model, where risk professionals manually review periodic samples, apply static heuristic rules, and generate retrospective reports, cannot scale to match the velocity, volume, and complexity of modern business transactions. Machine learning enabled systems continuously monitor entire populations of transactions, access requests, supplier relationships, and control events. These systems identify subtle patterns and emerging risks that consistently escape rigid rule based systems. This paradigm shift does not eliminate the need for human expertise. Rather, it repositions risk professionals from data processors to strategic decision makers who focus their judgment on exceptional cases, ambiguous signals, and high consequence approvals. Organizations that successfully implement this model achieve what was previously impossible. They gain comprehensive risk visibility without proportional increases in headcount, enabling the risk function to scale with business growth rather than becoming an operational bottleneck.

The integration of machine learning into governance, risk, and compliance frameworks aligns directly with the core principles of ISO 31000, which emphasizes that risk management must be dynamic, iterative, and responsive to change. Static controls are inherently blind to novel threats and evolving business environments. By embedding predictive analytics into the risk management lifecycle, organizations transition from merely documenting historical failures to actively preventing future exposures. This requires a fundamental rethinking of the risk operating model. The strongest operating model does not seek to replace the risk professional. Instead, it automates the predictable, prioritizes the unusual, and reserves human judgment for material, ambiguous, or consequential decisions. This symbiotic relationship between human expertise and machine scale forms the foundation of modern, resilient risk management.

  

How to Stop Producing Risk Registers Nobody Uses

Enterprise Risk Management programs fail in the same quiet way. They produce polished registers, colorful heat maps, and quarterly reports that look impressive in board packs. Then the organization makes its next major capital allocation, acquisition, or vendor choice using a single-page summary with one projected number and zero reference to the risk framework that consumed thousands of hours to build.

I've watched this pattern destroy the credibility of risk functions across industries. The risk team works hard. Stakeholders get interviewed. Likelihood and impact get scored. And none of it touches the actual decisions that determine whether the organization wins or loses. The gap between risk reporting quality and decision quality is where ERM programs go to die.

This article addresses that gap directly. It provides a stage-by-stage implementation approach for building an ERM program that changes how your organization decides, plans, and allocates resources. Every recommendation comes from field-tested practice, not theory. If your ERM program currently produces documents that live in SharePoint between annual reviews, this post shows you how to fix that.

 

Skills for Compliance Officers, Risk Managers, and Auditors

7 Career Capabilities That Will Separate Compliance Officers Who Thrive in 2026 From Those Who Get Replaced by Algorithms

ING just announced 1,250 job cuts in its compliance operations. ABN Amro plans to replace 35% of its AML division with AI. The Dutch audit office published a report questioning whether the €1.4 billion the banking sector spends annually on anti-money laundering checks actually produces effective outcomes.

Read that last sentence again. The government auditor is asking whether the entire manual compliance model works.

This is not a future scenario. This is happening now, across multiple banks, in one of Europe's most regulated markets. And it raises a question that every compliance officer, risk manager, and internal auditor should be asking themselves today: if my primary value comes from executing manual processes that AI can do faster and more consistently, what exactly is my professional future?

The answer depends entirely on skills. Not certifications. Not years of experience. Skills.

I have spent the last fifteen years working with compliance functions across financial services, industrials, and technology companies. The pattern I see repeating is consistent: the professionals who can quantify risk, challenge AI outputs, and translate regulatory complexity into financial terms the business can act on are becoming more valuable every quarter. The ones who built careers around checklist execution, manual alert processing, and qualitative risk scoring are watching their roles disappear. Sometimes gradually. Sometimes overnight.

This post identifies the seven skills that will define professional survival and advancement in compliance, risk, and audit roles through 2026 and beyond. Each one is grounded in what I see organizations actually hiring for, paying premiums for, and struggling to find.


 

Risk Workshops That Improve Decisions

Most risk workshops fail for a simple reason. They confuse documentation with decision support. Teams gather experienced people in a room, collect a long list of concerns, assign broad scores, and leave with a register that looks complete. What they often do not leave with is a sharper understanding of which uncertainties matter most, which scenarios require deeper analysis, and what management should do next. The process produces artifacts, but not always insight.

That gap matters. Risk is the effect of uncertainty on objectives, and risk management should be integrated into governance, strategy, planning, and decision-making, not treated as a separate administrative exercise. Risk management should support value creation, preservation, and realization by informing choices under uncertainty. A workshop that does not improve a decision, refine a treatment decision, or guide further analysis has limited value no matter how polished the documentation appears.

A well-run risk workshop has a narrower and more useful purpose. It helps participants identify credible risk scenarios, distinguish plausible exposures from noise, structure uncertainty around objectives, and determine where analysis will improve a management decision. It creates shared understanding before quantitative assessment, treatment planning, or escalation. In practical terms, it is a disciplined mechanism for focusing organizational attention.

That is the standard worth aiming for. Not a more colorful discussion. Not a longer register. Better judgment.


 

How to Use Large Language Models Securely in Risk Management, Compliance, Cybersecurity, and Audit

 

A compliance officer asked an LLM to analyze a vendor contract for GDPR obligations. The prompt included the full contract text. The contract contained employee names, personal email addresses, salary data from an embedded compensation schedule, and a confidential arbitration clause. All of it went into a third-party API. The compliance officer received a helpful analysis. The organization received a data privacy incident.

Nobody planned for this. The compliance officer was doing good work. The tool produced a useful output. And the organization now had regulated personal data sitting in an external system with no data processing agreement, no retention controls, and no way to request deletion.

That is the paradox of LLMs in GRC. The same capability that makes them powerful for regulatory analysis, risk assessment, and audit automation makes them dangerous when deployed without guardrails. An LLM will process whatever you feed it. It does not distinguish between public regulatory text and confidential personal data. It does not know that the regulation it cited does not exist. It does not understand that the risk score it generated was influenced by training data biases that systematically underweight emerging market vendors.


 

AI for GRC: 10 Use Cases Every Risk and Compliance Team Can Deploy in 90 Days

A compliance analyst at a mid-tier financial institution spent 14 hours last week reading regulatory updates. She flagged three items as potentially relevant to her business. She missed two others that directly affected the firm's cloud outsourcing arrangements. One of those triggered an enforcement action against a peer institution six weeks later.

That story repeats across thousands of GRC teams every week. The volume of regulatory change, vendor risk signals, control evidence, and incident data has exceeded human processing capacity. Not because the people lack skill. Because the volume is physically impossible to cover manually with the rigor the work demands.

AI changes this equation. Not by replacing human judgment, but by compressing the time between a risk signal appearing and a qualified human evaluating it. The 10 use cases in this post are not theoretical. GRC leaders at financial institutions, technology companies, and manufacturing firms are running three to five of these today, cutting manual hours by 30-60% while improving coverage across the full risk population.

Each use case includes the practical workflow, the authoritative framework it maps to, and the implementation path you can follow starting this week.


 

AI Governance Essentials

Why AI Deployment Now Requires Governance, Not Just Engineering

Artificial intelligence deployment has moved well beyond a technical exercise. What was once framed primarily as model development, application hosting, and iterative improvement now sits squarely within the remit of governance, risk management, compliance, and internal audit. That shift reflects regulatory change, market expectations, and a more mature understanding of how AI systems create both value and exposure across the enterprise.

The original draft focused heavily on product iteration, deployment mechanics, and general technology trends. Those topics matter, but in a professional GRC context they are incomplete unless anchored in accountability, risk ownership, control design, performance monitoring, and assurance. AI systems are not governed effectively merely because they are deployed through modern engineering practices such as CI/CD or MLOps. They require a structured governance model that aligns with recognized frameworks such as ISO/IEC 42001, NIST AI RMF 1.0, COSO Enterprise Risk Management, the IIA Global Internal Audit Standards, and applicable legal obligations including the EU AI Act, privacy laws, sector regulations, and financial reporting requirements where AI affects significant processes.

A practical governance perspective begins with one foundational point. AI is not a single risk category. It is a capability that can introduce, amplify, or obscure multiple risk types at once, including operational risk, model risk, legal risk, compliance risk, information security risk, privacy risk, conduct risk, third-party risk, and reputational risk. In many organizations, this is where governance breaks down. The enterprise treats AI as an innovation program when it should also be treated as a governed business capability subject to the same rigor applied to other material systems and processes.

This distinction matters because controls that are adequate for conventional software may be insufficient for AI-enabled systems. A deterministic business rule can usually be traced to fixed logic. A machine learning model may change behavior as a result of retraining, data drift, feature changes, prompt changes, or vendor model updates. A generative AI application may also produce variable outputs for the same input. For GRC professionals, that means control design must account for non-determinism, data dependency, explainability constraints, and lifecycle volatility.

Effective AI governance therefore starts with a simple but often neglected question. What decision, action, or business process is the AI system influencing, and what is the consequence if it fails or behaves unexpectedly? This framing is more useful than beginning with the underlying algorithm. It allows leaders to assess impact on customers, employees, financial reporting, safety, privacy, regulatory obligations, and organizational objectives.


 

Prof. Hernan Huwyler, MBA, CPA, CAIO: AI Governance, Risk & Compliance Executive | Speaker, Trainer & Advisor

 

I am an AI Risk Manager and Governance, Risk, and Compliance (GRC) executive dedicated to empowering business leaders to achieve strategic objectives through robust AI governance, digital compliance, and responsible AI frameworks. With over two decades of global executive experience spanning four continents, I specialize in guiding Fortune 500 organizations toward financial success and operational excellence by transforming regulatory pressure into a competitive advantage -1.

Tips and example on assurance mapping


Post by Prof. Hernan Huwyler, MBA, CPA, CAIO
AI GRC Director | AI Risk Manager | Quantitative Risk Lead
Speaker, Corporate Trainer and Executive Advisor
Top 10 Responsible AI and Risk Management by Thinkers360

Risk is a pervasive force across all business activities. Every strategic and operational decision depends on producing reliable information about the probability and impact of different outcomes. Assurance services exist to enhance the quality and credibility of this information, enabling leadership to make well-founded decisions with confidence.

The AICPA Special Committee on Assurance Services, commonly known as the Elliott Committee, articulated this principle in its 1997 report, establishing that assurance improves the reliability of information for decision makers. Since then, the scope of assurance has expanded well beyond statutory financial reporting to encompass ESG disclosures, cybersecurity attestations, data privacy compliance, and emerging areas such as AI governance.

The Institute of Internal Auditors defines assurance as the objective examination of evidence for the purpose of providing an independent assessment of governance, risk management, and control processes. This assessment adds credibility to both financial and non-financial information, from audited financial statements to environmental and social reports. In practical terms, assurance delivers the confidence that what needs to be controlled is actually being controlled.

Boards bear ultimate responsibility for ensuring that robust internal control arrangements exist across the entire organization, making assurance a first-order governance obligation rather than a purely operational concern.

Most corporate governance frameworks reinforce this expectation. The UK Corporate Governance Code, NYSE listing requirements, King IV in South Africa, and the EU Corporate Sustainability Reporting Directive all require the board to attest to the effectiveness of internal control and risk management systems. In the United States, SOX Section 404 specifically mandates that management assess and report on the effectiveness of internal controls over financial reporting.

Without a structured approach to coordinating assurance across these requirements, boards risk blind spots, redundant coverage, and misallocated resources. These are precisely the conditions that erode stakeholder trust and invite regulatory scrutiny.

What Is an Assurance Map and Why It Matters

An assurance map is a visual coordination tool that links assurance activities from all providers to the risks threatening organizational objectives. Structured as a matrix, it plots key risks or sequential process steps along the vertical axis against assurance activities along the horizontal axis.

The assurance activities are typically organized according to the IIA Three Lines Model, which was updated in 2020 to replace the former Three Lines of Defense terminology. Under this model, the first line consists of operational management, which owns and manages risk and controls. The second line encompasses risk management, compliance, and other oversight functions that provide expertise, monitoring, and challenge. The third line is internal audit, which delivers independent and objective assurance. Some organizations extend the framework to incorporate external audit and regulatory or board-level oversight as additional assurance layers, though these extensions fall outside the IIA formal model.

The strategic value of an assurance map lies in four dimensions. First, it provides board-level visibility through a consolidated, single-page view of risk coverage across the enterprise. Second, it promotes consistency by establishing a common methodology and language for management, oversight, and reporting. Third, it fosters cross-functional collaboration by making interdependencies between departments visible and actionable. Fourth, it drives cost efficiency by revealing redundancies and enabling reallocation of assurance resources toward areas of genuine exposure.

Keys to Making Decisions on Assurance

Assurance mapping is only as valuable as the decisions it informs. The following principles are critical to leveraging these maps effectively.

Identify Gaps and Eliminate Redundancies

The primary objective of assurance mapping is to detect areas where assurance is absent or unnecessarily duplicated across departments. A well-constructed map reveals the true level of oversight for each risk area, enabling leadership to reduce low-value and redundant efforts while strengthening coverage where it is most needed.

Standardize the Risk Methodology

For assurance mapping to deliver a coherent enterprise-wide view, the underlying risk methodology must be standardized. This includes the risk taxonomy, exposure modeling, and risk appetite thresholds. A common risk language is what enables meaningful coordination and interaction between business owners and assurance providers across all three lines. Without standardization, the map becomes a patchwork of incompatible assessments rather than a reliable decision-making tool.

Align Assurance Effort to Risk Exposure

Link the risk exposure of each process to its current assurance coverage to determine whether assurance costs are proportionate to the organization's risk tolerance. This is the practical application of the concept of reasonable assurance. When excessive assurance concentrates on a single process, leadership should investigate the root causes, such as historical incidents, regulatory mandates, or organizational inertia, before redistributing controls and responsibilities.

Update Governance Documents

When assurance programs are combined or activities reassigned, the governing documents must reflect these changes. This includes organizational policies, the internal audit charter, and departmental mandates. The assurance map is a coordination and visualization tool. It is not a policy instrument in itself and should not be treated as one.

Maintain Information Flow Across All Lines

Consolidating or reassigning assurance responsibilities does not eliminate the need for information sharing. Even when a department no longer directly assures a process, it should continue to receive relevant reporting about the reliability of related controls and the quality of associated outputs. Effective remediation depends on transparent communication of issues and action plans across all functions involved.

Leverage Technology for Continuous Assurance

Modern GRC platforms and data analytics capabilities enable real-time monitoring and continuous assurance, moving organizations beyond periodic point-in-time assessments. Integrating automated controls, exception-based reporting, and interactive dashboards into the assurance map strengthens both coverage and responsiveness. Organizations that embed technology into their assurance architecture gain a significant advantage in the speed and reliability of their risk oversight.

An Assurance Map in Practice

To illustrate the concept, consider a simplified financial month-end closing process at a company operating on SAP. The process-based map below plots process steps and their associated risks along the vertical axis against assurance providers organized by the Three Lines Model along the horizontal axis. It consolidates controls from each line to assess the extent and adequacy of coverage, designed for alignment with SOX Section 404 requirements and the COSO Internal Control Integrated Framework.




  

Each cell in the map reflects the quality and depth of evidence provided by the relevant assurance function, assessed according to three levels.

H stands for High Assurance. Assurance is detailed and performed on a recurring cycle. The depth of audit evidence reduces residual risk to an acceptable level, for example by maintaining low material misstatement risk in accounting processes. Controls are in place and adequately mitigate identified risks. Policies are documented and communicated throughout the organization. IT and business intelligence tools automate controls and flag exceptions for follow-up. Performance metrics are actively monitored by management.

M stands for Medium Assurance. Assurance is not performed on a regular cycle. Controls are not in place to cover all relevant risks. Policies are incomplete or not fully communicated to the responsible parties. Manual controls that could be automated remain in their current state, increasing the likelihood of human error.

L stands for Low Assurance. Little or no assurance is provided over the process. Significant concerns exist regarding the adequacy of controls relative to the risk profile. Few governing policies are documented or enforced.

The governance case for assurance mapping

In the United States, boards oversee risk management and internal control, while management is responsible for establishing, maintaining, and assessing those controls. This governance distinction is important. It would be inaccurate to say that boards directly operate or certify every control across the enterprise. Their role is to oversee whether the organization has an effective system of internal control and risk management, and whether that system is supported by credible reporting and challenge.

That oversight burden has grown significantly. Public companies face Sarbanes Oxley requirements for internal control over financial reporting. Regulated sectors face heightened scrutiny over operational resilience, model risk, privacy, third party dependencies, and cyber controls. Sustainability reporting is also increasing expectations around governance, controls, and attestable data. As complexity rises, boards and executive committees need a clearer and more integrated view of assurance coverage.

Recognized frameworks support this approach. The Institute of Internal Auditors Three Lines Model clarifies the roles of management, oversight functions, and internal audit. The COSO Internal Control Integrated Framework remains the leading basis for evaluating the design and effectiveness of internal control. COSO Enterprise Risk Management links risk oversight to strategy and performance. ISO 31000 provides a widely accepted foundation for risk management principles and governance. Together, these frameworks reinforce the same point. Assurance should be coordinated, risk based, and tied to decision making.

How Assurance Mapping Creates Management Value

The strongest reason to implement assurance mapping is not administrative efficiency. It is better risk oversight.

A well designed assurance map helps leadership answer questions that are often difficult to resolve through fragmented reporting. Which enterprise risks receive strong and recurring challenge. Which critical processes depend too heavily on self assessment or management judgment. Where are multiple teams reviewing the same controls with similar methods. Which material risks are supported by evidence based assurance and which rely on assumptions. Where does remediation stall because findings remain within one function instead of moving through a common governance process.

These insights matter because organizations rarely fail due to a total absence of controls. More often, they fail because risk ownership is unclear, challenge is inconsistent, and fragmented assurance gives leadership a false sense of confidence.

What a Strong Assurance Map Should Include

A useful assurance map begins with the business objectives, risk universe, and critical processes that matter most to the enterprise. The goal is not to map everything. The goal is to make visible the quality and sufficiency of assurance where failure would materially affect performance, compliance, resilience, or reporting integrity.

The structure usually starts with a defined scope such as financial reporting, cybersecurity, third party risk, privacy, revenue, procurement, product quality, or end to end operational processes. For each area, the map should identify the principal risks, the key controls or oversight mechanisms, the functions providing assurance, the nature of that assurance, the frequency of review, the degree of independence, the quality of evidence, and the current assessment of coverage.

This does not require an overly complex model. In fact, one of the most common mistakes is overengineering the framework to the point that it becomes difficult to maintain. The best assurance maps are disciplined, comparable, and practical enough to support real decisions.

 

From Assurance Mapping to Strategic Confidence

Assurance mapping is not an end in itself. It is a means of translating fragmented risk oversight into boardroom confidence and organizational resilience. When executed with disciplined methodology, standardized risk language, and genuine cross-functional commitment, it becomes one of the most powerful tools available to the GRC leader.

The goal is never to eliminate risk entirely. The goal is to ensure that the organization's assurance architecture is proportionate to its risk profile, coordinated across all lines, and transparent to the stakeholders who depend on it. In an era of expanding regulatory expectations, proliferating risk domains, and heightened scrutiny from investors and regulators alike, the organizations that master assurance coordination will be the ones that earn and sustain trust.



Get the latest in corporate governance, risk, and compliance on Twitter

Combining internal audits with anti-corruption compliance monitoring


 
Internal Audit Automatic queries tax haven countries Specific anti-bribery controls bribery risk map extra-territorial anti-corruption legislation compliance payments payments Hernan Huwyler

Post by Prof. Hernan Huwyler, MBA, CPA, CAIO
AI GRC Director | AI Risk Manager | Quantitative Risk Lead
Speaker, Corporate Trainer and Executive Advisor
Top 10 Responsible AI and Risk Management by Thinkers360

Why Detecting Concealed Payments Has Become A Board Level Priority

Detecting illegal payments concealed in accounting records remains a top priority for both internal audit and anti-bribery compliance functions. Corruption risk is a significant and growing concern for global organizations, driven by an expanding web of extraterritorial anti-corruption legislation. The U.S. Foreign Corrupt Practices Act, the UK Bribery Act 2010, France's Sapin II, and Brazil's Clean Company Act all impose obligations that extend well beyond domestic borders, creating overlapping enforcement regimes that demand coordinated internal controls.

Enforcement activity continues to intensify. The U.S. Department of Justice and the Securities and Exchange Commission have collectively imposed billions of dollars in FCPA-related penalties over the past decade. Whistleblower programs, particularly under the Dodd-Frank Act, have created powerful financial incentives for individuals to report suspected violations directly to regulators, with the SEC Whistleblower Program having awarded over two billion dollars since its inception. These dynamics make it essential for organizations to detect and prevent improper payments before they surface externally.

Identifying illegal payments hidden in accounting records is no longer a narrow compliance exercise. It is a core governance issue that sits at the intersection of anti bribery compliance, financial controls, internal audit, third party risk management, and investigations. For global companies, the stakes are high. Enforcement authorities continue to pursue cases under extra territorial anti corruption laws, whistleblower activity has increased, and regulators now expect companies to demonstrate not only that they have policies in place, but that they can identify and respond to suspicious transactions in practice.

Improper payments are rarely recorded as bribes. They are usually disguised as legitimate business expenses. In many cases, they appear as commissions, consulting fees, rebates, customs charges, facilitation arrangements, marketing support, travel expenses, charitable contributions, or vendor payments that appear ordinary on the surface. In more sophisticated schemes, illegal payments are concealed through inflated invoices, success fee arrangements with vague deliverables, layered subcontracting, shell entities, or payment flows involving offshore accounts and unrelated jurisdictions.

That is why anti bribery risk cannot be addressed through policy language alone. It requires a control architecture capable of identifying transactions that are technically booked within approved accounting categories but are economically inconsistent with the underlying business purpose.

Why Accounting Records Remain Central To Anti Bribery Detection

Under major anti corruption enforcement regimes, including the US Foreign Corrupt Practices Act, the integrity of books and records remains a central issue. Companies can face enforcement not only for improper payments themselves, but also for failures in internal accounting controls and the maintenance of inaccurate records. This is one of the most important practical realities in anti bribery compliance. Illegal payments are often detected not from direct evidence of intent, but from inconsistencies in documentation, approval logic, service validation, pricing patterns, vendor onboarding, or payment behavior.

For that reason, the most effective anti bribery programs do not separate ethics risk from financial control design. They treat accounting data, procurement data, third party due diligence, and approval workflows as connected evidence streams.

Why Improper Payments Are Difficult To Detect

Improper payments are deliberately designed to evade detection. The most straightforward schemes disguise bribes as legitimate business expenses such as agent commissions, third-party fees, consulting charges, or reimbursed travel and entertainment costs. More sophisticated arrangements involve inflated invoices, deceptive commission structures, fictitious services, and the use of complex webs of intermediaries, shell companies, and offshore bank accounts.

Under the FCPA, even when a substantive bribery charge cannot be proven, organizations face significant liability for books and records violations and failures to maintain adequate internal accounting controls. This means that the quality of accounting records and the integrity of the control environment are themselves compliance obligations, not merely audit concerns.

Mapping The Risk Factors Behind Improper Payments

Effective corruption risk assessment requires evaluating the full environment surrounding each transaction rather than relying on a single risk indicator. Organizations that anchor their bribery risk maps exclusively to country-level corruption indices, such as the Transparency International Corruption Perceptions Index, miss the broader transactional context that drives actual exposure.

A robust risk mapping framework balances four dimensions.

Where the transaction occurs encompasses the jurisdiction where the service is provided, the location from which payment is requested, and the domicile of the supplier. High perceived corruption jurisdictions, tax haven countries, new market sectors, and offshore locations all elevate this dimension of risk.

Who is involved examines the parties to the transaction, including public officials, politically exposed persons, small or newly established companies, new vendors without established track records, subcontractors, joint venture partners, associations, and any associated persons as defined by applicable legislation. The completeness and findings of due diligence, including any unresolved red flags, and the verification of beneficial ownership are critical elements of this assessment.

What service is provided evaluates the nature of the engagement. Consulting and advisory services, government licenses and permits, customs and logistics services, public procurement, complex or first-of-their-kind projects, and transactions where incentives or pressures exist to complete a deal on aggressive timelines all carry elevated risk.

How the service is contracted and paid focuses on the commercial and financial mechanics. The payment method, flat-fee structures versus success-based compensation, commission clauses, reimbursed expenses, upfront payments, the use of cash, and the routing of payments through jurisdictions unrelated to the underlying service are all relevant indicators.

Balancing these four dimensions provides a holistic view of corruption exposure. Organizations that assess only one or two of these factors, typically the country dimension alone, create gaps in their risk coverage that more sophisticated bribery schemes are specifically designed to exploit.

 

How Corruption Risk Should Be Assessed In Practice

Many companies still make a basic but costly mistake in corruption risk assessments. They over concentrate on country risk and assume that corruption exposure is driven primarily by geography. Geography matters, but it is only one element of the transaction risk profile. A stronger model evaluates corruption risk through the interaction of location, counterparties, business purpose, and payment mechanics.

A more complete risk view starts with where the service is delivered, where the payment is requested, where the third party is domiciled, and whether the transaction touches jurisdictions associated with weak transparency, sanctions concerns, customs complexity, or tax opacity. It also considers who is involved, including public officials, state owned entities, politically exposed persons, newly formed vendors, subcontractors, joint venture partners, customs brokers, commercial agents, and intermediaries with limited operating history or negative due diligence findings.

The nature of the service is equally important. Certain services are structurally higher risk because they are difficult to verify or can be used to justify discretionary payments. These often include consulting, licensing support, customs clearance, permit acquisition, business development, logistics support, market access work, and public procurement support. Risk also rises when a project is unusually complex, commercially pressured, fast tracked, or dependent on external approvals.

The final dimension is how the transaction is structured and paid. Payment method, fee logic, reimbursement provisions, use of advances, round sum compensation, success based compensation, vague statements of work, accelerated approvals, split invoices, foreign currency requests, or payments to accounts in unrelated jurisdictions can all materially elevate risk.

A mature corruption risk model balances all of these dimensions. It does not treat any single factor as determinative. It recognizes that a low transparency jurisdiction does not automatically make a transaction improper, and that a payment in a lower risk country may still be highly suspicious if the service cannot be substantiated or the payment structure lacks economic logic.

Why Compliance And Internal Audit Need A Shared Detection Model

Compliance and internal audit both play important but distinct roles in detecting illicit payments. Compliance typically owns anti bribery policy, third party due diligence standards, training requirements, escalation protocols, and ongoing monitoring of high risk transactions and third parties. Internal audit provides independent assurance over the design and operating effectiveness of controls, the adequacy of governance, and the consistency of execution across business units.

These roles should not be merged, but they should be coordinated. In practice, both functions rely on overlapping risk indicators, control points, and transactional evidence. If they use different definitions of bribery risk, different red flag criteria, or different scopes for testing, the result is fragmented oversight and duplicated effort. If they align on risk factors, data triggers, and control objectives, they can achieve stronger coverage with less burden on the business.

The most effective model is one in which compliance and internal audit share a common view of transaction risk, while preserving their separate mandates. Compliance performs targeted monitoring and program oversight. Internal audit independently evaluates whether the anti bribery control environment is designed and operating effectively. Each function benefits from the work of the other, but neither substitutes for the other.

A Better Way To Structure Collaborative Reviews

A practical way to coordinate anti bribery detection is to organize the review model around control design, operating effectiveness, and risk based monitoring. This structure is more useful than dividing work only by function because it aligns the assurance approach to how illicit payments actually bypass controls.

When organizations evaluate control design, they assess whether the preventive and detective control framework is capable of stopping or surfacing improper payments before they are embedded in normal accounting activity. When they evaluate operating effectiveness, they test whether those controls are consistently functioning in real transactions and whether exceptions are being challenged. When they monitor, they use data and trigger based review to identify payment behavior that warrants additional investigation or targeted audit attention.

This three part structure creates a practical bridge between governance, transaction testing, and analytics.

Evaluating Control Design Through An Anti Bribery Lens

Control design reviews should go beyond traditional financial authorization logic. They should assess whether the process architecture makes concealment difficult.

A strong design review examines segregation of duties across vendor onboarding, contract approval, service confirmation, invoice approval, master data changes, and payment release. The objective is not simply to confirm that different individuals are involved, but to ensure that the sequence of approvals creates meaningful challenge and that approval authority is appropriate to transaction risk and value.

Contracting controls also deserve close attention. Agreements with third parties should include anti corruption clauses, audit rights where appropriate, compliance with applicable laws, cooperation obligations, and termination rights tied to misconduct or control failures. It is equally important that the actual statement of work be specific enough to allow later verification of what the third party was expected to deliver.

The integrity of accounting descriptions is another underappreciated control. Accounting teams should be trained to use booking categories that reflect the economic substance of the transaction and to maintain meaningful entry descriptions. Large manual journal entries supported only by auxiliary spreadsheets, especially where line item support is missing or vague, create opportunities for concealment and should be tightly controlled.

Financial controllers and approvers should also be trained to identify anti bribery red flags in routine finance activity. This includes unusual travel and entertainment patterns, unsupported reimbursements, high risk petty cash usage, weak service confirmations, inconsistent vendor banking details, and commercially irrational pricing patterns.

Testing Operating Effectiveness Where Illegal Payments Actually Hide

Testing for operating effectiveness should focus on whether the control framework can withstand real world pressure. This means selecting transactions not only through conventional statistical sampling, but also through judgment based selection informed by known bribery risk patterns and red flags. Statistical samples are useful for some control objectives, but on their own they may miss the very transactions that merit scrutiny because corruption schemes are often low frequency, non random, and intentionally structured to look exceptional but explainable.

A stronger testing approach includes payments across multiple risk levels, with deliberate inclusion of transactions that are not necessarily high value but display unusual characteristics. These may include unnecessary intermediaries, vague consulting arrangements, success based compensation with no measurable output, emergency vendor onboarding, repeat reimbursements without adequate support, unusual discounts or rebates, or payments approved shortly before key regulatory or commercial milestones.

Third party testing is especially important. Reviews should examine whether due diligence was completed before engagement, whether red flags were resolved rather than simply documented, whether the third party had the capability to perform the service, whether beneficial ownership and control were understood, whether screening was refreshed appropriately, and whether the actual service provided can be corroborated through evidence beyond the invoice itself.

Approvals should also be tested for substance. Effective approval is not the presence of a signature in workflow. It is evidence that the approver assessed legitimacy, reasonableness, service performance, pricing, and potential conflicts of interest. If a company cannot demonstrate how an approver validated the business purpose of a payment, then the approval may have limited control value even if it was technically completed.

Using Monitoring To Surface Concealed Risk Earlier

Ongoing monitoring is one of the highest value areas in anti bribery detection because it can identify suspicious activity before it becomes systemic. The most effective monitoring models use data analytics to identify transactions and vendor behavior that deviate from expected patterns and then route those signals into compliance review, finance challenge, or internal audit follow up.

Monitoring should focus on transaction types that historically present bribery and fraud exposure, including gifts, meals, entertainment, travel, sponsorships, charitable donations, political contributions where permitted by law, agent commissions, distributor rebates, consulting fees, customs and logistics charges, and manual adjustments that affect vendor balances or expense classifications.

It is also important to monitor payment destinations and methods. Payments to offshore accounts, payments in currencies that do not align with the contractual arrangement, split payments, advances, round dollar payments, unusual prepayments, credits and rebates without clear commercial support, and sudden changes in bank account details all warrant closer review.

Trend analysis can be particularly effective. Out of pattern commissions by service type, abrupt pricing increases or decreases, changes in lease or equipment related expenses, repeated invoice amounts just below approval thresholds, and recurring payments to recently created vendors can all signal elevated risk. On their own, these indicators do not prove misconduct. Their value lies in helping the organization prioritize review where the transaction logic appears economically weak or control behavior appears abnormal.

What High Performing Programs Do Differently

Organizations with stronger anti bribery detection capability do not rely on isolated controls. They connect due diligence, contracting, procurement, accounts payable, general ledger data, employee expenses, and issue management into a coherent control environment. They also understand that corruption risk overlaps with fraud risk, sanctions risk, and money laundering exposure. That overlap matters because the same transactional patterns that indicate a bribery concern may also indicate vendor fraud, collusion, false billing, or concealment of beneficial ownership.

High performing programs also avoid treating anti bribery testing as a once a year review. They use targeted analytics and focused assurance cycles that adapt as the business changes. Market entry, distributor model changes, public sector expansion, customs intensive operations, and urgent project delivery environments all create periods where transaction scrutiny should increase.

Most importantly, mature programs ensure that findings lead to response. A red flag is only useful if the organization has a clear process to investigate it, escalate it, document conclusions, and adjust controls where necessary.

Common Weaknesses That Undermine Detection

Several recurring weaknesses tend to reduce the effectiveness of anti bribery detection even in otherwise mature organizations.

One is overreliance on due diligence at onboarding without enough scrutiny of what happens after the third party is engaged. A third party may pass initial screening and still become a bribery risk through changes in ownership, personnel, subcontracting, payment structure, or business pressure.

Another is excessive dependence on form based approvals. If the approval process captures signatures but not real challenge, then improper payments can move through the system with apparent control compliance.

A third weakness is insufficient integration between compliance monitoring and internal audit assurance. If compliance identifies recurring anomalies but audit does not assess whether the underlying control design is flawed, the organization treats symptoms instead of causes. If internal audit identifies design weaknesses but compliance does not adapt monitoring to reflect those weaknesses, risk remains under observed.

A final weakness is poor accounting transparency. Ambiguous general ledger descriptions, inconsistent use of expense categories, unsupported manual journal entries, and poor vendor master governance can make even a good anti bribery program far less effective.

Final Perspective

Detecting illegal payments in accounting records requires more than vigilance and more than policy. It requires a transaction level view of corruption risk supported by control discipline, data analysis, and coordinated assurance. Companies that treat anti bribery compliance, internal audit, and financial control as separate worlds will continue to miss important signals. Companies that connect them through a shared risk model and a common evidence base will be far better positioned to prevent, detect, and respond to concealed payments.

For boards, audit committees, chief compliance officers, and heads of internal audit, the practical question is no longer whether anti bribery controls exist. The more important question is whether those controls can detect a payment that was intentionally designed to look ordinary. That is the standard that matters.

References

US Department of Justice and US Securities and Exchange Commission. A Resource Guide To The US Foreign Corrupt Practices Act

US Department of Justice. Evaluation Of Corporate Compliance Programs

Organisation For Economic Co operation and Development. Good Practice Guidance On Internal Controls, Ethics, And Compliance

International Organization for Standardization. ISO 37001 Anti Bribery Management Systems Requirements With Guidance For Use

Committee of Sponsoring Organizations of the Treadway Commission. Internal Control Integrated Framework

Institute of Internal Auditors. Global Internal Audit Standards and guidance relevant to fraud and corruption risk oversight

Association of Certified Fraud Examiners. Occupational Fraud Reports and anti fraud control guidance



Get the latest in corporate governance, risk, and compliance on Twitter

What factors define a good risk and compliance culture?



Post by Prof. Hernan Huwyler, MBA, CPA, CAIO
AI GRC Director | AI Risk Manager | Quantitative Risk Lead
Speaker, Corporate Trainer and Executive Advisor
Top 10 Responsible AI and Risk Management by Thinkers360


How To Build A Sustainable Risk And Compliance Culture Across The Enterprise

A sustainable risk and compliance culture is no longer a secondary consideration in corporate governance. It is a core determinant of how organizations make decisions, escalate concerns, manage misconduct, and respond to pressure. In practice, culture shapes whether policies are followed, whether risks are challenged early, whether employees speak up, and whether accountability is applied consistently.

This makes culture a board and executive leadership issue. The board, the CEO, the chief compliance officer, the chief risk officer, and business leadership all influence whether the organization’s stated values are translated into everyday behavior. While tone at the top remains important, employees are influenced just as much by what leadership rewards, tolerates, ignores, and investigates. In other words, culture is not built through messaging alone. It is built through management signals.

Where culture is strong, employees are more likely to act within policy, escalate concerns, challenge risky decisions, and understand the boundaries of acceptable conduct. Where culture is weak, the opposite occurs. Misconduct is rationalized, control failures are normalized, concerns go unreported, and short term performance begins to outweigh disciplined decision making.

Why Regulators And Prosecutors Care About Culture

Regulators, prosecutors, and supervisory authorities increasingly examine culture when assessing governance failures. In major enforcement matters, authorities often look beyond whether policies existed on paper and ask whether management behavior, incentives, escalation channels, and accountability structures supported compliance in practice.

This trend is evident across jurisdictions. In Spain, the discussion around corporate criminal liability has reinforced the expectation that compliance programs should foster a genuine compliance culture rather than function as a formal shield against liability. Similar thinking appears in US Department of Justice guidance, which evaluates whether a compliance program is adequately designed, applied in good faith, and working in practice.

This shift has an important implication for boards and GRC leaders. A compliance program that is technically complete but culturally weak may be viewed as ineffective. Poor culture is often inferred from recurring patterns such as commercial pressure that overrides controls, tolerance of inappropriate behavior by high performers, weak challenge from management, reluctance to escalate concerns, or inconsistent disciplinary action. These are not only cultural failures. They are governance failures.

What Actually Shapes Risk And Compliance Culture

To improve culture, organizations need a realistic view of what drives it. Culture is not simply the result of ethics training or a code of conduct. It is shaped by the interaction between formal governance mechanisms and informal behavioral norms.

Formal drivers include incentive design, performance management, role clarity, promotion criteria, policy architecture, speak up mechanisms, issue escalation processes, investigation quality, and leadership accountability. Informal drivers include trust, peer behavior, local management style, tolerance for bad news, psychological safety, and whether employees believe that raising concerns will lead to fair treatment and action.

External factors also matter. Market pressures, investor expectations, regulatory scrutiny, public attention, supply chain complexity, labor conditions, and digital transformation can all influence behavior and risk taking. This means culture cannot be managed as a static internal attribute. It evolves with the business environment and must be monitored as part of the organization’s broader governance context.

What Research Suggests About Stronger Team Culture

Research across organizational behavior, ethics, and safety culture suggests that local team conditions strongly influence how culture is experienced. Employees tend to display stronger shared norms where leadership expectations are clear, communication is active, engagement is higher, and team members trust each other and their managers.

Studies have also highlighted the importance of cohesion, well being, tenure, leadership consistency, group identification, and constructive social interaction. Teams are generally more likely to follow shared standards when leaders provide clear direction, model the desired behavior, and respond consistently to problems and tradeoffs.

Some caution is necessary in interpreting this research. For example, findings that refer to smaller or less heterogeneous groups should not be taken as arguments against diversity. Diverse teams can improve challenge, innovation, and governance outcomes when supported by inclusive leadership and strong norms. The more useful lesson is that complexity requires more intentional management. Where teams are larger, more distributed, or more diverse, leadership must work harder to create clarity, trust, and consistency.

This has direct implications for compliance and risk leaders. Enterprise wide culture is always lived locally. It is shaped in business units, country teams, projects, functions, and leadership layers. That is why culture programs fail when they rely only on central messaging without reinforcing the same expectations in frontline management.

Why Culture Should Be Assessed As Part Of The Risk Framework

Leading risk frameworks recognize that organizational culture affects how risk is understood and managed. ISO 31000 emphasizes the importance of internal and external context in shaping risk management. COSO similarly links governance, ethical values, accountability, and behavior to the effectiveness of internal control and enterprise risk management.

This means culture should not be treated as an abstract concept outside the formal risk framework. It should be assessed as part of the control environment and the organization’s risk context. If risk appetite is clear on paper but ignored in decision making, that is a cultural issue. If employees fear retaliation for speaking up, that is a cultural issue. If incentive plans encourage excessive risk taking, that is both a risk management issue and a cultural one.

A credible assessment should rely on evidence, not only perception. Employee surveys can be helpful, but they should be complemented by analysis of whistleblower activity, investigation themes, misconduct trends, audit findings, control override patterns, remediation delays, turnover in sensitive roles, conduct related complaints, and board or committee reporting quality. Culture becomes measurable when the organization looks at behavioral indicators rather than values statements alone.

How To Strengthen Risk And Compliance Culture In Practice

A stronger culture is created through management design choices that reinforce responsible behavior consistently over time.

One of the most important foundations is a clear articulation of risk appetite and tolerance. Employees and managers need to understand the boundaries within which they are expected to operate across compliance, operational, financial, strategic, and conduct risks. Without this clarity, commercial pressure will often fill the gap.

Performance and cost management programs should also be reviewed through a risk lens. Organizations frequently measure efficiency and growth with precision, yet apply far less discipline to understanding losses, incidents, misconduct trends, fraud events, near misses, or control failures. A mature culture does not treat these as unfortunate side effects of performance. It treats them as management signals that require analysis and response.

Human resources policies are another major lever. Promotion criteria, performance reviews, succession decisions, and disciplinary frameworks all communicate what the organization truly values. If strong financial performance consistently outweighs control behavior, collaboration, and ethical judgment, then the culture message becomes self defeating. Open door communication, issue escalation, and confidence in speak up mechanisms should be reinforced through actual management behavior and not left as policy aspiration.

Remuneration also matters. Incentive design should not reward risk taking that depends on control bypass or weak conduct. This does not require simplistic formulas that penalize any incident. It requires a more balanced approach in which risk management, control quality, and leadership behavior influence how performance is evaluated.

Training should move beyond awareness and focus on capability. High quality training helps employees and managers recognize fraud indicators, respond to workplace incidents, handle regulatory obligations in context, manage teams responsibly, and make sound decisions under pressure. The objective is not just to inform people of the rules, but to help them act appropriately when the rules meet real world complexity.

Reporting channels are equally critical. Organizations need credible mechanisms to aggregate risk and compliance information, monitor behavioral and control indicators, escalate concerns, and support board and executive oversight. When designed well, these channels help management identify where culture is deteriorating and where interventions are needed.

A value based compliance framework also plays a central role. Policies and procedures should reinforce personal accountability, explain why requirements matter, and make clear that ethics and risk discipline are part of business performance rather than constraints outside it.

Finally, organizations should recognize that culture extends beyond employees. Suppliers, investors, clients, regulators, and other stakeholders influence conduct expectations and can also be affected by the company’s control environment. Engaging them transparently can help anticipate risks and strengthen the broader ecosystem of trust.

What High Performing Organizations Do Differently

Organizations with stronger risk and compliance cultures do not treat culture as an annual communication theme. They embed it into governance routines, leadership evaluation, decision making, issue management, and talent processes. They look for evidence of deterioration early. They challenge teams that deliver strong results through weak controls. They examine whether managers handle bad news constructively. They reinforce the expectation that speaking up is part of performance, not a disruption to it.

Most importantly, they understand that culture is tested under pressure. It is revealed when targets are at risk, when regulators ask difficult questions, when misconduct involves top performers, and when fixing a control weakness is operationally inconvenient. Those moments show whether the organization’s values are operational realities or only formal language.

Final Perspective

A sustainable risk and compliance culture does not emerge from policy statements alone. It is built when leadership behavior, incentives, governance structures, and daily management practices consistently support the standards the organization claims to value.

For boards, chief compliance officers, and chief risk officers, culture should be managed with the same discipline as any other material risk factor. It should be assessed regularly, supported by data, reinforced through accountability, and strengthened through practical interventions that shape behavior across the enterprise.

In the current regulatory environment, culture is no longer a soft issue. It is part of the control environment, part of enterprise resilience, and increasingly part of how organizations are judged when failures occur.

References

International Organization for Standardization. ISO 31000 Risk Management Guidelines

Committee of Sponsoring Organizations of the Treadway Commission. Enterprise Risk Management Integrating With Strategy And Performance

Committee of Sponsoring Organizations of the Treadway Commission. Internal Control Integrated Framework

US Department of Justice. Evaluation Of Corporate Compliance Programs

Spanish legal and prosecutorial guidance relevant to corporate compliance culture and legal entity liability



Get the latest in corporate governance, risk, and compliance on  Twitter

Why compliance is such a hot topic in Spain?

Compliance Spain España Hernan Huwyler What factors define a good risk and compliance culture?

Corporate Criminal Liability In Spain: The Evolution Of Compliance From Legal Obligation To Governance Imperative

The Introduction Of Corporate Criminal Liability Under Spanish Law

The Spanish Criminal Code was amended by Organic Law 5/2010, effective in December 2010, to introduce for the first time the criminal liability of legal persons into the Spanish legal system. This reform was subsequently expanded and refined by Organic Law 1/2015, effective in July 2015, which substantially restructured Article 31 bis and introduced a detailed set of requirements for compliance programs capable of exempting the organization from criminal liability.

Under Article 31 bis, Spanish legal entities may be held criminally responsible for offenses committed in their name or on their behalf through two distinct pathways. The first pathway addresses offenses committed by individuals authorized to make decisions on behalf of the organization, to organize the organization, or to exercise control within it, commonly understood as senior officers, directors, and legal representatives. The second pathway addresses offenses committed by individuals subject to the authority and supervision of those senior officers when the offense was made possible by the failure to exercise adequate supervision, oversight, and control over their activities. This dual-pathway structure is fundamental to understanding how the law operates, because the standard of proof and the available defenses differ depending on which pathway applies.

The criminal liability of the legal person is independent from the criminal liability of the natural person who committed the offense. A criminal proceeding against the organization does not exclude proceedings against the individual perpetrator, and vice versa. This independence means that organizations face direct criminal exposure with consequences that extend well beyond fines to include judicial intervention, suspension of activities, closure of business premises, prohibition from contracting with the public sector, and dissolution in the most serious cases.

The Landmark Supreme Court Interpretation

The Supreme Court of Spain addressed the scope and requirements of corporate criminal liability in several significant rulings during the years following the 2010 reform. Among the early landmark decisions, STS 154/2016 of the Criminal Chamber in plenary session established foundational interpretive principles regarding the standard of proof, the role of compliance programs as a defense, and the conditions under which an organization could be exempted from liability. The Court emphasized that the mere existence of a compliance program is insufficient and that the program must be effective in practice, proportionate to the risks of the organization, and subject to genuine oversight.

Organizations should verify the specific case details, penalties, and Supreme Court rulings relevant to their sector through the jurisprudence database of the Consejo General del Poder Judicial, as the body of case law on corporate criminal liability continues to develop and as significant decisions have addressed diverse offense categories including fraud, tax offenses, money laundering, and environmental crimes.

The Legal Foundation For Compliance Programs

The 2010 reform responded to domestic and international pressure to hold corporate entities accountable for criminal offenses facilitated by deficient organizational structures and inadequate internal controls. The underlying legal concept, often referred to in Spanish doctrine as culpabilidad por defecto de organización or organizational culpability through defect of organization, assigns liability not on the basis that the organization intended to commit a crime but on the basis that its failure to implement effective compliance and oversight measures made the commission of the offense possible.

The 2015 reform under Organic Law 1/2015 substantially strengthened the compliance framework by introducing Article 31 bis paragraph 5, which sets out the specific elements that a compliance program must contain to provide a basis for exemption from criminal liability. These elements include the identification of activities within whose scope offenses that must be prevented are likely to be committed, the establishment of protocols and procedures that give concrete expression to the process of forming the organization's will and of decision-making and execution in relation to those activities, the allocation of appropriate financial resources to prevent the commission of offenses, the obligation to report potential risks and noncompliance to the compliance oversight body, the establishment of a disciplinary system that adequately sanctions noncompliance with the program's measures, and the periodic verification and modification of the program when relevant infringements of its provisions are detected or when changes occur in the organization, its control structure, or its activities that make such modifications necessary.

The compliance oversight function must be entrusted to a body within the organization, often referred to as the órgano de cumplimiento or compliance body, with autonomous powers of initiative and control. In organizations authorized to present abbreviated accounts under applicable accounting standards, the compliance oversight function may be performed directly by the governing body. This provision acknowledges the practical constraints of smaller organizations while maintaining the requirement for effective oversight.

The Interpretive Guidance Of The Fiscalía General Del Estado

Circular 1/2016 of the Fiscalía General del Estado provides the authoritative prosecutorial guidance for evaluating the effectiveness of compliance programs under Article 31 bis. This Circular explicitly distinguishes between programs that constitute a genuine expression of the organization's compliance culture and those that exist as superficial instruments designed solely to obtain an exemption from criminal liability. In Spanish compliance practice, the latter are commonly described as cumplimiento cosmético, (make up compliance, paper compliance), a concept equivalent to what English-language practitioners refer to as paper compliance or window-dressing.

The Circular establishes that prosecutors should evaluate not only whether the program contains the formal elements required by Article 31 bis paragraph 5 but whether the program is genuinely implemented, adequately resourced, effectively supervised, and demonstrably responsive to identified risks and incidents. This standard of evaluation is substantively aligned with the approach taken by the U.S. Department of Justice in its Evaluation of Corporate Compliance Programs, which similarly assesses whether compliance programs function effectively in practice rather than merely existing on paper.

The Expanding Scope Of Compliance In Spain

During the decade following the 2010 reform, the scope of compliance in Spain evolved significantly along several dimensions. The focus expanded from criminal offense prevention alone to encompass business ethics, organizational integrity, and stakeholder trust more broadly. The orientation shifted from exclusively external regulatory compliance to include internal compliance with organizational policies, codes of conduct, and values. And the ownership of compliance responsibilities moved beyond the legal department to involve internal audit, external auditors, boards of directors, risk management functions, information technology and security teams, and specialized compliance professionals.

The offenses expressly mentioned in the Criminal Code that can trigger corporate criminal liability represent a defined catalogue, following the numerus clausus principle, meaning that only the specific offense categories enumerated in the Code can give rise to organizational liability. These categories include, among others, bribery and corruption, tax fraud and offenses against the tax authority, market manipulation and insider trading, fraud and economic crimes, environmental offenses, offenses against personal data and privacy, money laundering and the financing of terrorism, and intellectual property infringement. The enumerated categories represent general compliance risk domains that apply across sectors and industries.

These risks can be managed through alignment with recognized international and national standards. ISO 37301, published in 2021, establishes the requirements for compliance management systems and replaced the former ISO 19600, which was a guidance standard rather than a requirements standard and has since been withdrawn. ISO 37001 provides the framework for anti-bribery management systems. ISO 31000 establishes the principles and guidelines for enterprise risk management, including the identification and assessment of compliance risks as part of the organization's internal context. At the national level, UNE 19601, published by the Spanish standardization body AENOR, provides a certifiable standard specifically designed for criminal compliance management systems under Spanish law and is widely adopted by Spanish organizations seeking to demonstrate the rigor and completeness of their compliance programs. Complementing these frameworks, effective compliance programs should include comprehensive codes of ethics, robust whistleblowing and reporting mechanisms aligned with the protections now required under EU Directive 2019/1937 on whistleblower protection and its Spanish transposition through Ley 2/2023, and risk-based internal controls proportionate to the organization's exposure.

The Rise Of The Chief Compliance Officer In Spain

The broad scope of criminal compliance obligations and the significant reputational and financial risks associated with corporate criminal liability created substantial demand for professionals capable of managing the design, implementation, and ongoing operation of compliance programs. The chief compliance officer emerged as a critical governance role across all types of organizations regardless of size or sector, including multinational corporations operating in Spain, domestic subsidiaries of foreign groups, political parties, trade unions, foundations, and professional sports organizations.

The professionalization of the compliance function in Spain led to the creation of ASCOM (Asociación Española de Compliance) and other professional associations including the World Compliance Association, which provide platforms for practitioners to share methodologies, develop professional standards, and promote the adoption of internationally recognized compliance frameworks. These associations have contributed significantly to raising the standard of compliance practice in Spain and to building the professional identity of the compliance function as distinct from and complementary to the legal, audit, and risk management disciplines.

The Path From Cosmetic Compliance To Genuine Governance

Spanish organizations have moved progressively from the early adoption of compliance programs motivated primarily by liability avoidance toward the development of programs that serve as genuine instruments of organizational governance and ethical culture. This transition remains incomplete, and the maturity of compliance programs varies significantly across sectors, company sizes, and organizational cultures.

The transition from cosmetic compliance to effective compliance requires a fundamental shift in how organizations conceive of the compliance function. Effective programs require professionals with a distinctive profile that combines legal knowledge with the ability to translate regulatory requirements into practical behavioral expectations, to design and implement risk-based and cost-effective preventive controls, and to build organizational cultures in which ethical conduct is reinforced by incentive structures, communication practices, and leadership behavior rather than imposed solely through rules and sanctions.

This challenge is not unique to Spain. Every jurisdiction that has introduced corporate criminal liability or enhanced compliance expectations faces the same transition from formal program adoption to genuine program effectiveness. What distinguishes the Spanish experience is the speed of the evolution, the breadth of the criminal offense catalog, the specificity of the compliance program requirements in Article 31 bis paragraph 5, and the interpretive rigor introduced by Circular 1/2016. Together, these elements have created a compliance environment that demands both technical sophistication and cultural commitment.

The organizations that navigate this transition successfully will be those that treat compliance not as a legal risk mitigation exercise but as a core component of corporate governance, strategic planning, and organizational sustainability.


Get the latest in corporate governance, risk, and compliance on  Twitter