International Data Transfers Under GDPR: France Compliance Guide
Data transfer under GDPR in France requires the right legal mechanism, risk assessment, and safeguards. Learn how adequacy decisions, SCCs, Schrems II, TIAs, CNIL guidance,...
ISO 37001 helps organizations strengthen anti-bribery controls through governance, risk assessment, due diligence, training, monitoring, and accountability. This guide explains how ISO 37001 aligns with Sapin II and supports practical anti-corruption compliance in France.
Bribery prevention in France requires organizations to manage both legal obligations and practical anti-corruption controls. ISO 37001 provides an internationally recognized framework for building and improving an anti-bribery management system, while France’s Sapin II regime, particularly Article 17, imposes mandatory measures on organizations that meet the relevant statutory thresholds.
Organizations considering ISO 37001 in France should understand how the international anti-bribery standard interacts with Sapin II, AFA expectations, and their existing anti-corruption controls.
The distinction is important: ISO 37001 certification is voluntary, while SAPIN II obligations are legal requirements for organizations within scope. ISO 37001 can help structure policies, corruption risk assessments, third-party due diligence, reporting mechanisms, training, monitoring, and continuous improvement, but certification does not automatically demonstrate compliance with French anti-corruption law.
This guide explains how ISO 37001 works, how it compares with Sapin II and how organizations can build a practical, evidence-based anti-bribery program.
ISO 37001:2025 is the international standard for anti-bribery management systems. It provides requirements and guidance for establishing, implementing, maintaining, reviewing, and continually improving organizational measures designed to prevent, detect, and respond to bribery.
The standard can be used by private companies, public-sector organizations, non-profits, SMEs, multinational groups, and organizations operating across multiple jurisdictions. Its value lies in the management-system approach. ISO 37001 is not simply an anti-corruption policy template. It brings governance, responsibilities, risk assessment, due diligence, financial and non-financial controls, reporting, training, monitoring, and corrective action together into a single structured framework.
This allows organizations to connect anti-bribery expectations with day-to-day business processes and create evidence that controls are being implemented and reviewed.
ISO 37001:2025 replaced the 2016 edition and is now the current version of the standard. The 2025 update strengthens and modernizes several areas, including the organizational anti-bribery culture, conflict-of-interest management, the role of the anti-bribery function, and alignment with contemporary ISO management system practices.
Organizations using older ISO 37001:2016 documentation should therefore review their policies, risk processes, and management-system controls against the 2025 requirements rather than continuing to treat the 2016 edition as current.
France’s Law No. 2016-1691 of 9 December 2016, commonly known as Sapin II, strengthened the national framework for transparency and the prevention and detection of corruption and influence peddling.
A central provision is Article 17 of the Sapin II law. Under the current framework, specified company leaders must implement anti-corruption measures where a company employs at least 500 employees, or belongs to a French-headed group with at least 500 employees, and has more than €100 million in turnover or consolidated turnover. The legislation also contains additional scope rules for certain public entities, corporate structures, and port operators.
Article 17 was amended by Law No. 2025-532 of 13 June 2025, with the current version in force from 15 June 2025. Organizations should therefore check the current legal text rather than rely on older Sapin II summaries.
Article 17 requires an integrated anti-corruption program covering a code of conduct, an internal reporting mechanism, regularly updated corruption risk mapping, evaluation of customers, first-tier suppliers and intermediaries, accounting controls, training for exposed managers and employees, disciplinary measures, and internal monitoring and evaluation.
These Article 17 duties should not be confused with the broader prohibition of corruption under French law. Falling below the Article 17 thresholds does not remove bribery or corruption risk, nor does it exempt an organization or individuals from other applicable criminal and legal obligations.
ISO 37001 and SAPIN II overlap significantly in how they approach bribery and corruption risk, but they have different legal status, scope, and purposes. ISO 37001:2025 is a voluntary international management-system standard. Sapin II Article 17 is a French legal requirement for organizations that fall within its statutory scope.
|
Area |
ISO 37001:2025 |
Sapin II Article 17 |
|
Status |
Voluntary international standard |
French legal requirement for organizations within scope |
|
Main purpose |
Anti-bribery management system |
Prevention and detection of corruption and influence peddling |
|
Applicability |
Organizations of any size or sector |
Organizations meeting statutory scope criteria |
|
Risk assessment |
Bribery risk assessment |
Corruption risk mapping |
|
Third-party controls |
Risk-based due diligence |
Evaluation of specified customers, suppliers, and intermediaries |
|
Reporting |
Speak-up and reporting mechanisms |
Internal reporting mechanism |
|
Training |
Risk-based anti-bribery training |
Training for managers and personnel most exposed to corruption risks |
|
Monitoring |
Monitoring, review, audit, and improvement |
Internal control and evaluation of measures |
|
Certification |
Independent certification possible |
No equivalent Sapin II certification |
|
Legal compliance |
Can support compliance |
Direct statutory obligation where applicable |

Yes. The two frameworks align closely around corruption risk assessment, leadership commitment, due diligence, anti-corruption controls, reporting, training, investigations, and continuous monitoring.
For organizations operating in France, ISO 37001 can provide a structured management framework for organizing these controls. However, organizations subject to SAPIN II should map ISO requirements directly against Article 17 and relevant AFA recommendations. Certification should not be treated as a legal safe harbor.
No. ISO 37001 certification demonstrates that an organisation's anti-bribery management system has been assessed against the requirements of the ISO standard. It does not prove that every obligation under French anti-corruption law has been satisfied.
The AFA may still assess whether an organisation has implemented the specific Article 17 measures effectively in practice and can produce appropriate evidence of those controls.
The Agence française anticorruption (AFA) plays a central role in France’s anti-corruption framework through prevention, guidance and control activities. Its recommendations help organisations translate legal obligations into practical anti-corruption measures and provide an important reference point for designing and assessing compliance programmes.
The AFA’s official anti-corruption recommendations organise an effective programme around three fundamental pillars: leadership commitment, understanding corruption risks through risk mapping, and managing those risks through prevention, detection and remediation measures.
This structure aligns naturally with the management-system approach used by ISO 37001. Both frameworks emphasise governance, risk-based controls, accountability, monitoring and continuous improvement. However, they should not be treated as interchangeable. AFA recommendations are not an ISO standard, and they are not a substitute for the legal requirements set out in Sapin II.
Organisations operating in France should therefore use AFA guidance alongside the applicable legal text when designing, implementing, and reviewing their anti-corruption programme.
Proportionality is also important. Controls should reflect the organisation’s actual corruption exposure, business activities, geographic footprint and third-party relationships. A generic policy may appear complete on paper, but an effective programme should demonstrate that resources and controls are focused on the risks that matter most in practice.
An effective anti-bribery programme starts with clear leadership responsibility. Under ISO 37001, leadership is expected to establish anti-bribery objectives, provide appropriate resources, assign responsibilities and promote an organisational culture that rejects bribery.
In a French compliance programme, leadership should be able to demonstrate active involvement rather than simply approve an anti-corruption policy. This includes formally endorsing the programme, defining responsibilities, ensuring the compliance function has sufficient independence and resources, reviewing corruption-risk reporting and responding appropriately to serious allegations.
Management decisions should also be documented. This creates evidence showing how identified risks, investigations, control weaknesses and remediation actions were considered and addressed. Visible communication from senior leaders is equally important, particularly where employees or business partners may face commercial pressure that conflicts with anti-corruption expectations.
The compliance function should have:
Appropriate authority and independence
Direct access to relevant management
Its role should be clear enough to challenge decisions, escalate significant concerns and monitor implementation without unnecessary interference.
Smaller organisations do not need to replicate the structure of a multinational compliance department. Governance can be proportionate to size and risk, but accountability, escalation routes and decision-making responsibilities must remain clearly defined.
An effective anti-corruption policy should translate leadership expectations, legal obligations and risk-management principles into practical rules that employees and relevant business partners can understand and apply.
The policy should address the organisation’s main corruption risks, including bribery, influence peddling, facilitation payments, gifts and hospitality, charitable contributions, sponsorships, political contributions where relevant, conflicts of interest and the use of intermediaries. The level of detail should reflect the organisation’s actual exposure rather than rely on generic wording.
Statements such as “we have zero tolerance for corruption” are not enough on their own. Employees need to know who must approve a transaction, which financial or risk thresholds apply, what conduct is prohibited, what records must be retained and where to seek advice when a situation is unclear.
Clear operational rules also make it easier to test whether the policy is being followed in practice.
For organisations subject to Sapin II Article 17, the anti-corruption code of conduct has a specific legal role. It should define and illustrate prohibited conduct that may constitute corruption or influence peddling and form part of the organisation’s wider compliance framework.
A generic ISO 37001 policy should therefore not be assumed to satisfy every French requirement automatically. Organisations should map their policy and code of conduct directly against applicable Sapin II obligations and AFA guidance.
Both ISO 37001 and the French anti-corruption framework place risk assessment at the centre of an effective compliance programme. A useful corruption and bribery risk assessment should begin with the organisation’s actual activities, transactions, and business relationships rather than a generic catalogue of possible misconduct.
The assessment should consider exposure linked to countries of operation, business sectors, government interactions, public procurement, licensing, customs, sales intermediaries, agents, distributors, acquisitions, gifts and hospitality, charitable activity and high-value contracting. The objective is to identify where corruption could realistically occur, how serious the consequences could be and which controls are needed.
For organisations subject to Article 17, Sapin II requires regularly updated documentation that identifies, analyses and ranks exposure to external corruption solicitations, taking particular account of business sectors and geographic areas.
The AFA treats corruption risk mapping as a central component of the anti-corruption programme because it should guide the design and prioritisation of other controls.
For each relevant corruption scenario, assess:
Inherent risk before controls
Existing preventive and detective controls
Effectiveness of those controls
Residual risk after controls
Additional action required
The results should influence third-party due diligence, approval procedures, training, monitoring, accounting controls and management oversight.
A risk map should not become an annual compliance document that is reviewed once and then ignored. It should be updated when the organisation enters new markets, changes business models, acquires companies, appoints new intermediaries or identifies new corruption risks. The strongest programmes connect risk assessment directly to operational decisions and documented remediation.
Turn Anti-Bribery Risk Awareness Into Practical Action
Strengthen your understanding of bribery and corruption risks, learn to recognize common warning signs, and apply practical prevention principles in workplace situations. Support stronger anti-corruption controls and more informed compliance decisions across your organization.
Explore the Training →Third parties are one of the most significant bribery exposure points for many organisations. Risk can arise through customers, agents, consultants, distributors, suppliers, joint-venture partners, acquisition targets and other intermediaries acting on the organisation’s behalf or supporting critical business activity.
Effective third-party anti-bribery due diligence should therefore focus on the level of risk presented by each relationship rather than applying the same review to every party.
The depth of due diligence should reflect factors such as country risk, interaction with public officials, ownership structure, reputation, payment arrangements, unusual commissions, use of subcontractors, lack of relevant capability and relationships with decision-makers.
Higher-risk relationships may require deeper ownership checks, adverse-information review, verification of qualifications, explanation of payment structures and additional contractual or approval controls.
Unusually high commissions or requests for payments to unrelated accounts
Reluctance to disclose ownership, qualifications or relationships with public officials
A red flag does not automatically mean corruption has occurred. It indicates that further investigation, documentation or approval is needed before the organisation proceeds.
Due diligence should not end at onboarding. Higher-risk third parties should be reassessed when material circumstances change, including ownership, geography, services, payment arrangements, adverse information or significant compliance incidents.
Monitoring should also connect with the wider corruption risk assessment. If a third party’s risk profile increases, the organisation should reconsider approval conditions, contractual safeguards, training, transaction monitoring or whether the relationship should continue.
Everyday business practices can create bribery risk even when they are presented as routine relationship management. Gifts, meals, travel, entertainment, charitable donations, sponsorships and similar benefits may influence, or appear to influence, a business decision if they are not properly controlled.
Organisations should therefore establish proportionate rules covering gifts and hospitality, charitable contributions, sponsorships, political activity where relevant, conflicts of interest and interactions with public officials. Controls should reflect the level of risk rather than rely on a single approval rule for every situation.
Approval decisions should consider the value and frequency of the benefit, its timing, the identity of the recipient, the legitimate business purpose, local context and whether a tender, contract award, licence or other decision is pending.
Higher-risk situations should require enhanced review, documentation or refusal.
ISO 37001:2025 places stronger emphasis on identifying and managing conflicts of interest. Employees should understand when personal, financial, family or other relationships could affect, or reasonably appear to affect, their professional judgement.
Organisations should provide a clear disclosure process, define who reviews conflicts and record how identified conflicts are managed. Effective controls help prevent personal interests from undermining procurement, recruitment, contracting or other business decisions.
Bribery prevention requires more than policies, training and employee awareness. Organisations also need operational controls that make it harder for improper payments, approvals or business arrangements to pass through normal processes without challenge.
Relevant financial controls can include segregation of duties, approval limits, expense verification, invoice controls, payment validation, review of unusual transactions and accounting reconciliation.
These controls should be designed around identified bribery risks. For example, payments involving high-risk intermediaries, unusual commissions, round-sum invoices or unexpected changes in bank details may require enhanced review.
For organisations subject to Sapin II Article 17, accounting controls must help ensure that books, records and accounts are not used to conceal corruption or influence peddling. Controls should therefore detect unusual entries, unsupported expenses and transactions that do not reflect a legitimate business purpose.
Non-financial controls are equally important. They can apply to procurement, contracts, recruitment, business partners, tender processes, discounts, sponsorships and other high-risk approvals.
The strongest controls correspond directly to corruption scenarios identified through the organisation’s risk assessment. If public procurement, third-party agents or sponsorships present elevated risk, approval and monitoring procedures should be strengthened in those areas.
This risk-based connection helps ensure that anti-bribery controls operate as practical safeguards rather than isolated compliance procedures.
Organisations need secure and trusted ways for employees and relevant stakeholders to raise concerns about suspected bribery, corruption or other misconduct. A credible reporting mechanism should provide clear reporting channels, controlled access to reports, appropriate confidentiality, documented handling procedures and protection against retaliation.
The system should also define how reports are received, assessed, escalated, investigated and closed. Employees need to know where to report concerns and what will happen after a report is submitted. Poorly designed channels can discourage reporting or create unnecessary confidentiality and procedural risks.
Whistleblower protection in France is governed by legal requirements that extend beyond ISO 37001. Official Service Public guidance on whistleblowers in companies explains protections including confidentiality of identities and safeguards against retaliatory measures. It also sets out internal and external reporting routes, with specific internal-procedure requirements for organisations with 50 or more employees.
France’s framework also reflects protections introduced at EU level through Directive (EU) 2019/1937, which establishes minimum standards for protecting persons who report specified breaches of Union law.
Organisations should therefore integrate anti-corruption reporting channels with applicable French whistleblowing procedures rather than create competing systems with different confidentiality, escalation or protection rules. The objective is a coherent process that supports both effective anti-bribery controls and compliance with applicable whistleblower protections.
When a credible allegation, whistleblower report or bribery red flag is received, the organisation should respond through a defined and documented investigation process. The purpose of an internal investigation is to establish whether the allegation has a factual basis, assess the seriousness of any misconduct and determine what corrective action is required.
The process should begin with initial triage and preservation of relevant evidence. Investigators should have sufficient independence, a clearly defined scope and appropriate access to documents, systems and personnel. Depending on the allegation, the investigation may involve interviews, document review, transaction analysis, email or communications review and examination of third-party relationships.
Confidentiality, data protection, employment-law considerations and legal privilege should be assessed throughout the process. Conclusions should be supported by documented evidence, followed where necessary by remediation, disciplinary action, control improvements or further escalation.
Organisations should determine in advance who can authorise an investigation, who receives the final report, when external counsel or specialist investigators may be required, and when potential notification to authorities or other stakeholders should be considered.
Clear governance reduces the risk of inconsistent or improvised responses.
The AFA and France’s Parquet national financier have issued an official guide on internal anti-corruption investigations. It provides practical guidance on structuring investigations, collecting information, protecting confidentiality and documenting outcomes.
Organisations should use this guidance alongside their legal obligations, internal procedures and wider anti-corruption framework.
Training is one of the clearest areas of alignment between ISO 37001 and Sapin II. Both frameworks recognise that anti-bribery controls are more effective when employees understand the risks they may encounter and know how to respond.
For organisations subject to Article 17, training must be provided to managers and personnel who are most exposed to corruption and influence-peddling risks. Training should therefore reflect role, responsibility and risk rather than use identical content for every employee.
General awareness training should explain core concepts such as bribery, gifts and hospitality, conflicts of interest, reporting obligations, expected conduct and the organisation’s anti-corruption policy.
Higher-risk employees may need more detailed training, particularly in sales, procurement, government relations, international markets, tendering, finance and third-party management.
Scenarios should reflect real operational risks. For example, a distributor may request an unexplained success fee shortly before a public tender decision, or a supplier may ask an employee to route payment through a third-country intermediary.
Organisations should retain evidence of training completion, course content, delivery dates, target audiences and assessment results.
Training should also be reviewed when risk assessments, policies, business activities or legal requirements change. This helps ensure that training remains connected to current corruption risks rather than becoming a routine annual exercise.
ISO 37001 is a management-system standard, so continuous review is a fundamental part of an effective anti-bribery programme. Organisations should monitor whether controls are operating as intended, not simply whether policies and procedures exist.
Useful evidence can include third-party due-diligence completion, approval exceptions, whistleblowing reports, investigation findings, audit results, accounting-control failures, training completion data and emerging corruption risks. These indicators help identify where controls are effective, where weaknesses remain and where additional action is required.
Internal audit should test the effectiveness of anti-bribery controls in practice. Relevant questions include whether a high-risk agent was properly evaluated, whether gifts above approval thresholds were identified, whether an investigation followed the approved procedure and whether remediation actions were completed.
Testing should focus on real transactions, decisions and evidence rather than document existence alone.
Leadership should periodically assess whether the anti-bribery management system remains appropriate, adequately resourced and effective.
Management review should consider changes in corruption risk, audit findings, investigations, control failures, training results and outstanding corrective actions. The outcome should lead to documented decisions, updated controls and clear ownership for improvement.
This continuous-improvement cycle helps organisations demonstrate that their anti-corruption programme adapts to changing risks and operates effectively in practice.
ISO 37001 certification can provide independent assurance that an organisation has established a structured anti-bribery management system. However, certification should be understood as an assessment against the ISO standard, not as proof that every French anti-corruption obligation has been satisfied.
No. ISO 37001 certification is voluntary.
Sapin II does not require an organisation subject to Article 17 to obtain ISO 37001 certification. French legal obligations apply independently of whether an organisation chooses to pursue certification.
An independent certification body assesses whether the organisation’s anti-bribery management system conforms to the requirements of ISO 37001.
The process typically includes an initial assessment of the management system, followed by ongoing surveillance and later recertification in accordance with the applicable certification framework. The exact process can vary depending on the certification body, organisational scope and accreditation arrangements.
Organisations may pursue certification to demonstrate a structured anti-bribery programme to customers, business partners or procurement teams. It can also support stronger governance, international business requirements, internal accountability and a more disciplined approach to monitoring and continuous improvement.
ISO 37001 certification does not guarantee that bribery will never occur, that employees cannot commit misconduct or that all French legal obligations have been met.
It also does not prevent the AFA or another competent authority from identifying weaknesses in the organisation’s anti-corruption controls. Certification should therefore be viewed as one form of assurance within a broader compliance framework, not as a legal safe harbour.
Many SMEs and smaller ETIs in France do not meet the employee and turnover thresholds that trigger the mandatory Article 17 anti-corruption program. That does not mean bribery risk is irrelevant.
Smaller organizations can still face exposure through international markets, public procurement, agents, distributors, government interactions, and complex supply chains. Larger customers and business partners may also expect suppliers to demonstrate credible anti-corruption controls as part of procurement or third-party due diligence.
The AFA has published a dedicated practical anti-corruption guide for SMEs and smaller ETIs, recognising that proportionate anti-corruption measures can be valuable even where Article 17 does not impose the full mandatory framework.
For an SME, the objective should not be to recreate the compliance structure of a multinational group. The priority is to identify genuine bribery risks and implement controls that match them.
ISO 37001 can provide a useful structure for this approach, particularly where the organization wants stronger governance, clearer responsibilities, more consistent due diligence, or greater assurance for customers and partners.
Implementing ISO 37001 in France is most effective when organizations treat it as a structured management-system project rather than a documentation exercise.
Define which entities, locations, activities, and business relationships fall within the anti-bribery management system. Assign senior-level responsibility and establish a clearly defined anti-bribery compliance function with appropriate authority.
Map business processes and identify realistic bribery scenarios. Focus on higher-risk markets, transactions, public-sector interactions, intermediaries, suppliers, and other third parties.
Review the current anti-corruption policy, code of conduct, reporting mechanism, due diligence processes, accounting controls, training, investigation procedures, and monitoring arrangements.
For organizations subject to Article 17, this review should also map existing controls directly against Sapin II requirements and relevant AFA expectations.
Prioritise weaknesses according to risk and potential impact. Avoid measuring progress by the number of policies created. The objective is to strengthen controls where actual bribery exposure is highest.
Embed procedures into procurement, sales, finance, HR, contracting and third-party management. Employees should understand what approvals, records and escalation steps are required in real situations.
Use monitoring, internal audit, investigations, risk indicators and management review to determine whether controls operate effectively.
If certification is a business objective, complete an internal readiness assessment, address significant gaps and confirm that the management system is operating before external assessment begins.

A strong anti-bribery programme should be demonstrable through current controls, records and decisions, not policies alone. Organisations reviewing ISO 37001 in France should be able to answer the following questions clearly.
Governance and risk: Is senior management visibly accountable for anti-bribery compliance? Is corruption risk mapping current and based on actual business activities? Does the organisation understand which locations, transactions, functions and third parties create its highest exposure?
Controls and evidence: Are anti-corruption policies translated into practical procedures? Are higher-risk third parties assessed before and during the relationship? Are accounting and business-process controls designed to detect or prevent improper payments and approvals? Are employees trained according to their level of corruption risk?
The organisation should also be able to show that concerns can be reported safely, credible allegations are investigated appropriately, disciplinary and remediation processes are defined, and weaknesses are tracked through to completion.
Monitoring matters as much as implementation. Controls should be tested periodically through review, audit, investigation findings, management reporting and corrective action.
For organisations subject to Sapin II Article 17, one final question is critical:
Can each of the eight statutory measures be demonstrated through current, operational evidence rather than policies alone?
If the answer is no, the priority should be to close the evidence and control gap before treating the programme as mature.
ISO 37001 certification does not automatically demonstrate Sapin II compliance. Better approach: map ISO 37001 requirements separately against Article 17 obligations and relevant AFA expectations.
A standard risk template may overlook the organisation’s real exposure. Better approach: build corruption scenarios from actual operations, countries, transactions, third parties and interactions with public officials.
Third-party risk can change after onboarding. Better approach: reassess higher-risk parties when ownership, geography, services, payment arrangements or adverse information changes.
Generic training often fails to address role-specific risks. Better approach: give exposed personnel practical scenarios linked to their responsibilities and corruption risk.
A well-written policy does not prove that procedures work. Better approach: audit real transactions, approvals, gifts, payments and third-party decisions to confirm controls are followed.
Waiting until an allegation arises can lead to inconsistent decisions and weak evidence handling. Better approach: define escalation routes, investigation authority, evidence-preservation procedures and reporting responsibilities before a serious concern is received.
Effective anti-bribery compliance depends on employees recognising risk before a questionable payment, gift, third-party request or conflict of interest becomes a serious compliance issue.
The French Compliance Institute’s Anti-Bribery and Corruption Training helps professionals understand bribery and corruption risks, recognise common warning signs and apply practical prevention principles in workplace situations.
Training can support a broader ISO 37001 or Sapin II programme by strengthening employee awareness, reinforcing organisational controls and helping staff respond more consistently to potential red flags.
It should, however, form part of a wider risk-based compliance framework rather than be treated as a substitute for ISO 37001 certification or full Sapin II implementation.
ISO 37001:2025 provides a structured international framework for preventing, detecting and responding to bribery through governance, risk assessment, due diligence, controls, reporting, training and continuous improvement.
Sapin II creates specific legal anti-corruption obligations for organisations that fall within Article 17. Although the two frameworks overlap substantially, they are not interchangeable. French organisations should use ISO 37001 as a management framework while separately mapping applicable Sapin II requirements and AFA recommendations.
ISO 37001 certification can provide evidence that an organisation has implemented a structured anti-bribery management system, but it does not guarantee that bribery will never occur or that every French regulatory obligation has been satisfied.
Organisations that connect corruption risk assessment, practical controls, employee training and continuous monitoring will be better positioned to demonstrate that their anti-corruption programme operates effectively in practice.