What Is Construction Fire Safety?
Learn construction fire safety, including fire hazards, risk assessments, prevention, emergency preparedness, hot work, electrical safety, and workplace training.
France’s Sapin II Law strengthens anti-corruption rules and gives AFA power to fine and monitor companies. Beyond penalties, it can cause reputational and operational risks. With PNF oversight, compliance is now a strategic priority. Companies need risk mapping, strong controls, and third party checks to stay compliant and stable.
France significantly strengthened its anti-corruption regime with the introduction of the Sapin II Law (Law No. 2016-1691), adopted in December 2016 and fully implemented in 2017. The legislation aims to improve transparency in business practices, strengthen corruption prevention mechanisms, and align France with international anti-corruption standards such as the UK Bribery Act and the US Foreign Corrupt Practices Act (FCPA).
Under Sapin II, companies operating in France must implement robust internal systems designed to detect and prevent bribery, influence peddling, and other corruption-related offences. The law particularly targets large organisations that may face higher corruption risks due to complex supply chains and international operations.
The primary objective of Sapin II is to prevent corruption before it occurs by requiring companies to establish structured compliance programmes. These programmes typically include a code of conduct, corruption risk assessments, internal whistleblowing systems, due-diligence procedures for third parties, and ongoing monitoring of compliance controls.
The law mainly applies to companies headquartered in France with more than 500 employees and annual revenue exceeding €100 million, as well as their subsidiaries. These organisations must implement eight mandatory anti-corruption measures designed to identify and mitigate corruption risks.
One of the most significant changes introduced by Sapin II was the creation of the Agence Française Anticorruption (AFA). This government body is responsible for monitoring corporate compliance programmes and ensuring that organisations implement effective anti-corruption controls.
The AFA conducts audits of companies, assesses the quality of their compliance programmes, and may refer cases to its sanctions committee if deficiencies are identified. In addition to enforcement activities, the agency also issues compliance guidelines and supports both public and private entities in improving their anti-corruption frameworks.
Sapin II does not only apply to corporations; it also places responsibility on senior management. Boards of directors, chief executives, and compliance officers may be held accountable if a company fails to implement required anti-corruption measures.
As a result, compliance has shifted from being a purely legal concern to a strategic governance responsibility, requiring active oversight from senior leadership.
The enforcement of Sapin II involves several authorities and procedural mechanisms designed to investigate and resolve corruption cases efficiently.
The AFA has the authority to conduct compliance audits and investigations to verify whether companies have implemented the mandatory anti-corruption measures required by the law. If significant deficiencies are found, the agency may initiate enforcement proceedings before its sanctions committee.
These investigations typically examine risk assessments, internal controls, training programmes, and third-party due-diligence processes.
When suspected corruption offences are identified, cases may be handled by the Parquet National Financier (PNF), France’s specialised financial prosecutor. The PNF investigates complex financial crimes such as bribery, corruption, and tax fraud involving corporate actors.
The prosecutor works alongside enforcement authorities to determine whether criminal proceedings should be initiated.
Sapin II also introduced the Convention Judiciaire d’Intérêt Public (CJIP), a settlement mechanism similar to deferred prosecution agreements used in other jurisdictions. Through this procedure, a company suspected of corruption can resolve the case without a criminal conviction by agreeing to pay a fine, compensate victims, and implement a compliance programme monitored by the AFA.
CJIPs encourage corporate cooperation with authorities and enable faster resolution of complex corruption investigations.
The Sapin II framework includes several enforcement tools designed to penalise non-compliance and deter corruption.
Companies that fail to implement required anti-corruption measures may face administrative fines of up to €1 million, depending on the severity of the breach.
In cases involving proven corruption offences, penalties can be significantly higher and may reach millions of euros or multiples of the illicit gains obtained.
Senior managers can also face personal sanctions if they fail to ensure compliance with Sapin II obligations. Individuals may be fined up to €200,000 and, in serious corruption cases, may face criminal prosecution and imprisonment.
This personal liability increases pressure on executives to prioritise anti-corruption governance.
Authorities may require companies to implement or strengthen their compliance programmes under external supervision. Monitoring is often conducted by the AFA, which evaluates whether the company successfully improves its internal anti-corruption controls over a specified period.
Anti-corruption enforcement in France has intensified over the past decade as regulators seek to align the country with global transparency standards. Sapin II expanded the powers of enforcement agencies, introduced stricter corporate compliance obligations, and created new mechanisms for investigating and settling corruption cases.
In addition, growing international scrutiny of corporate governance, stronger whistleblower protections, and increased cooperation between regulators have led to more investigations and enforcement actions. As a result, anti-corruption compliance has become a central concern for companies operating in France, influencing strategic business decisions ranging from partnerships to international expansion.
Since the adoption of the Sapin II law in 2016, France has significantly strengthened its anti-corruption enforcement regime. The law introduced stronger corporate accountability, established the Agence Française Anticorruption (AFA), and created the Convention judiciaire d’intérêt public (CJIP) settlement mechanism. This framework allows prosecutors to impose large financial penalties and compliance obligations on companies involved in corruption or influence-peddling cases.
Real enforcement cases demonstrate that Sapin II penalties can affect far more than legal compliance. They influence how companies structure governance, manage partners, and assess international risks.
Several high-profile cases show that corruption involving foreign markets is a major trigger for enforcement actions. For example, French authorities and international regulators jointly penalised major institutions involved in bribery schemes linked to foreign state entities. In one widely cited case, a global bank paid hundreds of millions of euros in combined penalties following bribery involving Libyan officials.
Another example involves a CJIP agreement concluded with the company Surys in 2025. The company agreed to pay over €18 million in a public-interest fine, along with compensation to a foreign government affected by corrupt practices. The settlement also required a multi-year compliance programme supervised by the AFA.
These cases show that corruption risks are no longer limited to domestic transactions. French enforcement authorities increasingly cooperate with international regulators, meaning misconduct in overseas operations can result in significant penalties in France.
A recurring theme in enforcement actions is the absence of effective internal compliance systems. Sapin II requires large companies to implement corruption-prevention measures such as risk mapping, internal controls, and whistleblower channels. When these systems are weak or poorly implemented, regulators often view it as evidence of governance failure.
In several CJIP settlements, authorities specifically assessed whether companies had adequate compliance programmes before the misconduct occurred. Companies that failed to demonstrate meaningful preventive measures faced larger penalties or stricter monitoring requirements. This has reinforced the idea that compliance is not simply a legal formality; it is now a core element of corporate governance.
Another common factor behind Sapin II cases is poor oversight of intermediaries such as agents, consultants, or local partners. In international business environments, companies often rely on intermediaries to secure contracts or navigate regulatory systems. However, these relationships create corruption risks if due diligence and monitoring are insufficient.
Investigations frequently reveal that bribery payments are channelled through third-party brokers or consultants acting on behalf of the company. For this reason, regulators now emphasise third-party integrity checks, ongoing monitoring, and clear contractual obligations regarding anti-corruption compliance.
Companies that fail to manage these relationships carefully may face enforcement actions even if senior executives were not directly involved in the misconduct.
When businesses think about regulatory penalties, they often focus only on the financial fine. In reality, Sapin II enforcement actions generate a wide range of additional costs that can affect long-term business performance.
Corporate investigations into corruption allegations can last several years and involve complex cross-border evidence gathering. Companies often hire external legal teams, forensic accountants, and compliance experts to conduct internal investigations and negotiate settlements with prosecutors. These costs can easily reach millions of euros before any regulatory fine is imposed.
Many CJIP agreements require companies to implement enhanced anti-corruption controls under the supervision of the AFA for up to three years. During this period, organisations must fund audits, compliance programme upgrades, employee training, and regular reporting to regulators.
These monitoring obligations can significantly increase operational costs while forcing organisations to restructure internal processes.
Companies involved in corruption scandals may also face indirect financial consequences. Government agencies and large corporations often reassess supplier relationships after enforcement actions. In some cases, companies under investigation may be excluded from public procurement opportunities or international development projects until compliance systems are strengthened.
Financial penalties are often only one part of the impact. Sapin II enforcement actions frequently lead to serious reputational damage that affects investor relations, partnerships, and long-term market positioning.
When corruption investigations become public, investors often view the company as a governance risk. Share prices may decline, and lenders may demand stronger compliance assurances before extending financing.
CJIP settlements and major corruption investigations are typically announced publicly by authorities. Media coverage can amplify reputational damage and attract scrutiny from regulators in other jurisdictions.
Business partners may reconsider joint ventures or commercial agreements with companies under investigation. Multinational corporations increasingly require suppliers to demonstrate strong anti-corruption compliance before entering into contracts.
Initially, Sapin II obligations targeted larger organisations, particularly those with at least 500 employees and significant revenue. However, enforcement trends show that mid-sized companies are increasingly affected.
Global supply chains, international expansion, and reliance on intermediaries expose many companies to corruption risks even if they are not multinational giants. As French regulators continue to strengthen anti-corruption enforcement, companies of all sizes must integrate compliance into their strategic decision-making.
French regulators frequently identify similar governance failures during investigations under the Sapin II anti-corruption framework. The law requires companies that meet certain thresholds to implement structured anti-corruption compliance programmes designed to prevent and detect bribery and influence peddling. When organisations fail to implement these measures effectively, regulators such as the Agence Française Anticorruption (AFA) may impose sanctions or require corrective compliance monitoring.
Three weaknesses appear repeatedly in regulatory assessments.
Corruption risk mapping is considered the foundation of the Sapin II compliance system. Companies must identify, analyse, and prioritise corruption risks based on their geographic presence, industry sector, and operational structure. This process helps organisations understand where bribery risks are most likely to occur and what controls are necessary to mitigate them.
When companies fail to maintain a structured risk map, regulators often conclude that the compliance programme is ineffective. Without a risk-based assessment, organisations cannot determine which departments, projects, or markets require stronger monitoring. As a result, corruption risks may remain undetected in areas such as international procurement, government contracting, or intermediary relationships.
An internal whistleblowing or alert system is another mandatory element of the Sapin II compliance framework. Employees must have a secure mechanism to report suspected misconduct, including bribery, influence peddling, or conflicts of interest.
Companies that fail to establish transparent reporting channels often struggle to detect misconduct early. Without safe reporting mechanisms, employees may hesitate to raise concerns internally, allowing unethical practices to continue unchecked. Regulators increasingly view weak reporting systems as a governance failure because effective whistleblowing frameworks are central to early detection of corruption risks.
Training is another core pillar of the Sapin II compliance programme. Managers and employees who operate in higher-risk roles must receive regular anti-corruption training so they can identify risky situations and understand the organisation’s code of conduct. One example of such training can be the Sapin II Compliance & Anti-Corruption Course by French Compliance Institute.
Where training programmes are absent or poorly implemented, companies often struggle to demonstrate that staff understand anti-corruption obligations. Regulators interpret this gap as a sign that compliance policies exist only on paper rather than being embedded in the organisation’s culture.
Many corruption cases originate not within the company itself but through its external partners. As a result, Sapin II requires organisations to conduct due diligence on third parties, including suppliers, intermediaries, and customers.
Sales agents and consultants are frequently involved in corruption cases because they interact directly with public officials or procurement authorities. If a company fails to evaluate the integrity and background of these intermediaries, it may become legally responsible for bribery committed on its behalf.
Joint ventures present another major compliance risk. When companies collaborate with partners in foreign markets, differences in governance standards may create opportunities for corruption. Regulators expect companies to assess the compliance culture of potential partners before entering such partnerships.
Global supply chains also create corruption exposure. Payments to suppliers, distributors, or subcontractors may conceal bribery schemes or illegal commissions if adequate monitoring is not in place. For this reason, Sapin II encourages companies to perform ongoing third-party due diligence and maintain transparent records of financial transactions.
A recurring theme in enforcement actions is the failure of senior management to provide effective oversight of compliance systems.
The governing body of a company is expected to support anti-corruption compliance and allocate sufficient resources to maintain it. Regulators increasingly emphasise that compliance programmes must receive active oversight from senior leadership rather than being delegated entirely to legal or compliance departments.
In some organisations, compliance programmes exist primarily to satisfy regulatory requirements. Policies may be documented but rarely implemented in day-to-day operations. Such “paper compliance” programmes are often identified during regulatory audits.
Regulators also expect companies to maintain detailed records of their compliance activities. These records include risk assessments, training sessions, due-diligence checks, and internal investigations. Without proper documentation, organisations cannot demonstrate that they took reasonable steps to prevent corruption.
Sapin II enforcement has made anti-corruption governance a strategic business issue rather than merely a legal obligation. Companies that fail to integrate compliance considerations into business decisions—such as selecting partners, entering new markets, or approving large transactions—face higher regulatory and reputational risks.
In practice, this means that executives must evaluate corruption exposure alongside financial and operational considerations. Decisions regarding mergers, partnerships, or supply chain expansion increasingly require due diligence that addresses anti-corruption risk. Organisations that embed compliance into strategic planning are better positioned to avoid enforcement actions and protect their long-term reputation in regulated markets.
Even organisations with compliance policies can face enforcement action when anti-corruption controls exist only on paper. Regulators in France increasingly focus on how companies implement and monitor compliance programmes rather than whether policies simply exist. Many investigations begin when regulators discover weaknesses in governance, documentation, or internal controls.
One frequent trigger for investigations is management’s failure to respond to early indicators of misconduct. These warning signs may include unusual payment requests, excessive commissions to intermediaries, unexplained consulting contracts, or conflicts of interest involving public officials. When such signals are ignored, regulators often view it as evidence of weak internal oversight. Under the Sapin II framework, companies are expected to proactively detect and prevent corruption risks through structured monitoring systems and internal reporting channels.
Third-party relationships are among the most common corruption risk areas. Intermediaries, suppliers, agents, or joint-venture partners may expose companies to bribery risks if proper due diligence is not conducted. Sapin II requires organisations to implement risk-based assessments before establishing or maintaining business relationships. These assessments should analyse the partner’s ownership structure, geographic exposure, reputation, and potential links to corruption cases. If a company fails to perform these checks, regulators may conclude that the organisation neglected its obligation to prevent corruption within its supply chain.
Another common mistake is weak documentation of compliance processes. Even when controls exist, companies must demonstrate that they are actively applied and monitored. Without clear documentation of policies, training, investigations, and risk assessments, organisations may struggle to prove their compliance efforts during regulatory reviews.
Sapin II requires certain companies operating in France to implement a comprehensive anti-corruption compliance system designed to detect and prevent bribery or influence-peddling. The French Anti-Corruption Agency (AFA) has identified several key measures that organisations must implement within their compliance framework.
Risk mapping is a core element of the Sapin II framework. Companies must identify and evaluate corruption risks across their activities, business sectors, and geographical markets. This process enables organisations to prioritise high-risk areas and develop targeted policies and internal controls to mitigate them. The risk map should be updated regularly as the company expands or enters new markets.
Sapin II requires organisations to establish internal whistleblowing mechanisms that allow employees to report suspected misconduct confidentially. Such systems encourage early detection of unethical behaviour and protect individuals who report violations of the company’s code of conduct. These reporting channels are a critical tool for identifying corruption risks before they escalate into legal violations.
Compliance programmes must also include ongoing monitoring and evaluation procedures. Internal audits, accounting controls, and compliance reviews help organisations verify that anti-corruption policies are functioning effectively. Continuous monitoring allows companies to detect irregular transactions or suspicious patterns that could indicate bribery or fraud.
Documentation is one of the most important elements in proving compliance with Sapin II requirements. Managers should maintain detailed records of corruption risk assessments, third-party due diligence checks, training sessions for employees, internal investigations, and compliance monitoring activities. A well-maintained documentation trail allows organisations to demonstrate that anti-corruption policies are actively implemented and enforced across departments.

Additionally, companies should keep records of their code of conduct, disciplinary procedures, accounting control measures, and compliance programme evaluations. These documents form the evidence regulators often review during investigations.
The French Anti-Corruption Agency (AFA) is responsible for monitoring the implementation of anti-corruption measures within organisations covered by Sapin II. The agency can review internal procedures, interview employees, and assess the effectiveness of compliance programmes.
To prepare for an audit, companies should ensure their compliance programme reflects the eight core measures recommended by regulators, including a code of conduct, risk mapping, whistleblower systems, training programmes, and internal monitoring mechanisms. A structured compliance framework demonstrates that the organisation has taken reasonable steps to prevent corruption.
Managers can reduce the risk of regulatory sanctions by strengthening internal compliance practices. Key actions include conducting regular corruption risk assessments, implementing thorough due diligence procedures for business partners, and ensuring that employees receive training on anti-corruption policies.
Leadership commitment is also essential. When senior management actively supports compliance programmes and integrates ethical standards into decision-making processes, organisations are better positioned to detect misconduct early and avoid regulatory penalties. Over time, these measures not only reduce legal exposure but also strengthen trust with regulators, investors, and business partners.
Anti-corruption compliance is no longer just a legal requirement for large companies in France. It has become a strategic issue that directly influences how organisations operate, make investments, and expand internationally. The Sapin II law, introduced in 2016, strengthened France’s anti-corruption framework and created strict obligations for companies to prevent bribery and influence peddling. These obligations include implementing compliance programmes, risk mapping, whistleblowing mechanisms, and internal monitoring systems.
Companies that fail to implement effective anti-corruption programmes can face significant penalties and regulatory scrutiny. The French Anti-Corruption Agency (AFA) is responsible for supervising compliance programmes and auditing organisations to verify whether anti-corruption controls are properly implemented.
As enforcement becomes more active, executives must now treat corruption risk as a key business factor. Decisions about suppliers, market expansion, and partnerships increasingly involve compliance assessments. In practice, this means anti-corruption policies are now integrated into corporate governance frameworks, risk management strategies, and long-term business planning.
Sapin II does not operate in isolation. It is increasingly linked to broader European regulatory frameworks that focus on transparency, accountability, and ethical governance.
Environmental, Social, and Governance (ESG) standards now emphasise ethical conduct, transparency, and anti-corruption controls. Investors and regulators expect companies to demonstrate strong governance practices, including effective anti-bribery systems. Sapin II reinforces this expectation by requiring companies to establish structured compliance programmes and internal monitoring systems.
As a result, anti-corruption compliance is now closely tied to ESG performance. Companies with strong compliance programmes are more likely to attract investors and maintain credibility in international markets.
Whistleblower protection is another area where Sapin II aligns with broader European policy. The law introduced mechanisms allowing employees to report corruption or misconduct while ensuring their confidentiality and protection from retaliation.
These protections complement the EU Whistleblower Directive, which aims to strengthen reporting systems across European organisations. Together, these frameworks encourage employees to report misconduct early, allowing companies to address risks before they escalate into major legal violations.
Global businesses operating in France must ensure that their compliance frameworks meet Sapin II standards. The law can apply not only to French companies but also to subsidiaries and international groups headquartered in France that exceed certain size thresholds.
This extraterritorial reach means companies expanding internationally must maintain consistent anti-corruption controls across all operations.
Sapin II increasingly affects everyday business decisions across organisations.
Companies must now perform due diligence on intermediaries, suppliers, and business partners. Regulators consider third-party relationships a major source of corruption risk, so organisations are expected to assess the integrity and reputation of partners before entering agreements.
Anti-corruption compliance has become a key factor in mergers and acquisitions. Acquiring a company with weak compliance systems may expose the buyer to regulatory investigations or financial penalties. Therefore, legal and compliance teams often conduct corruption risk assessments before completing transactions.
When entering new markets, organisations must evaluate corruption risks associated with local regulations, government interactions, and intermediaries. Failure to assess these risks can lead to significant legal consequences under Sapin II and other international anti-corruption laws.
While many organisations initially view anti-corruption compliance as a regulatory burden, strong compliance systems can actually create competitive advantages. Companies with robust compliance frameworks are more likely to win government contracts, attract international partners, and build trust with investors.
In global markets, reputation plays a major role in business relationships. Demonstrating strong ethical governance and anti-corruption controls signals reliability and transparency to stakeholders.
Senior leadership plays a decisive role in anti-corruption compliance. Sapin II places responsibility on executives and directors to ensure that compliance programmes are effectively implemented within their organisations.
Without proper training, executives may fail to recognise corruption risks in procurement decisions, partnership negotiations, or international expansion strategies. For this reason, many organisations now provide specialised compliance training to senior managers and board members.
Executive awareness strengthens internal oversight and ensures that anti-corruption policies are applied consistently across the organisation. In the long term, this approach helps companies reduce legal exposure while building sustainable and responsible business practices.