Last Updated on 15 July, 2026

Understanding Sapin II: A Manager’s Guide to Anti-Corruption Compliance

A practical Sapin II manager's guide to anti-corruption compliance in France: your obligations, the 8 pillars, and how to avoid personal liability.

Sapin II Manager's Guide with compliance checklist and governance documents

If you manage a team, a budget, or a business relationship in France, Sapin II is not just legal department paperwork. It is a law that can attach personal liability to you specifically, separate from any penalty your company faces. This Sapin II manager's guide breaks down what the law actually requires of you day to day, without the legal jargon that makes most compliance content unreadable.

Key takeaways

  • Sapin II is France's anti-corruption law, in force since June 2017, enforced by the AFA (Agence Française Anticorruption).

  • Full compliance programme obligations apply to companies with 500+ employees and over €100 million turnover. A lower threshold, 50+ employees, triggers a mandatory whistleblowing channel regardless of turnover.

  • Executives and managers can be personally fined up to €200,000. Company fines can reach €1 million, and negotiated settlements (CJIPs) can cost up to 30% of average annual turnover.

  • The law is extraterritorial: French parent companies must extend compliance to foreign subsidiaries, and managers remain liable wherever a breach happens.

  • Sapin III has not been enacted as of 2026. Build your compliance approach around current Sapin II requirements, not proposed reforms.

What Sapin II Actually Is

Sapin II, formally Law No. 2016-1691 on Transparency, Fighting Corruption and Modernising Economic Life, is France's landmark anti-corruption legislation. It was passed on 9 December 2016 and took effect on 1 June 2017. Named after Michel Sapin, the finance minister who championed it, the law represents the most significant overhaul of France's anti-corruption framework to date.

Before Sapin II, France lagged behind comparable economies on anti-corruption enforcement. The law changed that in three ways: it created a binding obligation for large companies to actively prevent corruption rather than simply avoid committing it, it established the AFA to supervise and enforce that obligation, and it introduced France's first general legal framework for protecting whistleblowers. It draws heavily on the US Foreign Corrupt Practices Act and the UK Bribery Act, emphasising corporate transparency, internal monitoring, and robust whistleblower safeguards.

For a full breakdown of every requirement, risk area, and enforcement mechanism, see The Complete Guide to Sapin II Compliance in 2026: Requirements, Risk Management, and Anti-Corruption Best Practices. This guide focuses specifically on what lands on a manager's desk.

Who Sapin II Applies To

This is where managers most often get the scope wrong, particularly at mid-sized subsidiaries of larger groups. There are actually two separate thresholds under the law, and they trigger different obligations.

Requirement

Who it applies to

What's required

Full anti-corruption programme (Article 17)

Companies with 500+ employees and turnover over €100 million (cumulative, includes subsidiaries and consolidated groups)

All 8 compliance pillars

Whistleblowing channel only (Article 8)

Any organisation, public or private, with 50+ employees in France

Confidential internal reporting mechanism, regardless of turnover

The Article 17 thresholds are cumulative, and they apply to subsidiaries and state-owned commercial establishments, not only standalone French companies. The law's reach is also extraterritorial: a company headquartered in France must extend its anti-corruption programme to foreign subsidiaries, and the AFA can examine how those overseas operations apply it. Executives remain personally liable regardless of where the breach actually occurred.

The lower, 50-employee threshold catches many managers off guard. Even if your company doesn't meet the Article 17 revenue and headcount bar, you likely still owe employees a working internal reporting channel, a requirement reinforced by the 2022 Loi Waserman. Our guide on Anti-Corruption Policies Under Sapin II: What Every Manager Should Know covers how to build that channel properly.

The Eight Pillars, Explained for Managers

Article 17 requires the effective application of eight measures, and the AFA has published its own detailed recommendations on how to implement each one. Here is what each pillar actually means for someone managing people, budgets, or supplier relationships, not just for the compliance team.

1. Code of conduct. Sets expectations for employee and stakeholder behaviour and requires up-to-date compliance training. If you haven't reviewed it with your team in the last year, that's a gap worth flagging.

2. Internal reporting system. Employees need a working channel to report potential misconduct. Your job as a manager is making sure your team knows this channel exists and actually trusts it enough to use it.

3. Risk mapping. The company's exposure to corruption risk must be identified, analysed, prioritised, and updated regularly. Your input matters here. You know which suppliers, markets, and relationships in your area carry real risk better than a central compliance function does.

4. Third-party due diligence. Vendors, customers, and suppliers should be screened and monitored in line with the risk map. If you're the one approving a new supplier or intermediary, this is your control point, not a formality to skip because a deal is time-sensitive.

5. Accounting controls. Internal and external controls must ensure transparent recordkeeping. Unusual invoicing, vague consulting fees, or success payments tied to nothing measurable are the classic red flags auditors look for.

6. Training. Regular, practical, and documented training must reach the executives and employees most exposed to corruption risk. Generic annual e-learning sent to the whole company does not, on its own, satisfy this requirement for high-risk roles. If your job touches procurement, sales in high-risk markets, or public contracts, expect and push for role-specific training.

7. Disciplinary regime. Clear consequences for code violations must be defined in advance and communicated to employees. Enforceable consequences are one of the signals the AFA uses to judge whether a programme is genuinely effective rather than paper compliance.

8. Monitoring and assessment. The whole programme needs ongoing evaluation, including internal audits and reporting to senior management, with adjustments made when gaps or new risks emerge.

For implementation checklists on each pillar, see The 8 Mandatory Sapin II Requirements Every Organisation Must Understand.

★ Free PDF Certificate Included

Master Sapin II Anti-Corruption Compliance.

Learn how to build and manage an effective Sapin II compliance programme, conduct corruption risk assessments, implement third-party due diligence, strengthen financial controls, and prepare for AFA reviews. Earn a recognized PDF certificate at no additional cost. Gain the practical knowledge to protect your organisation, reduce compliance risks, and lead with integrity.

Enrol Now →

Why This Is Personal, Not Just Corporate

The single most important thing for a manager to internalise: Sapin II makes executives and managers primary parties responsible for anti-corruption compliance. In the event of a breach, they are personally exposed to financial sanctions, independently of whatever penalty the company faces.

That means "the company will handle it" is not a defence. If you sign off on a supplier payment, approve a hospitality budget, or manage a team in a high-risk market, you are a compliance control point, not just a business decision-maker.

The flip side is protection for people who do the right thing. Employees are treated as full participants in risk detection and are protected as whistleblowers whenever they report a breach in good faith, particularly through the internal reporting channel. If someone on your team raises a concern, retaliation of any kind is itself a legal exposure for the company and potentially for you.

Enforcement and Fines: What's Actually at Stake

The AFA sits under the joint authority of the Minister of Justice and the Minister of the Budget. It has the power to conduct proactive audits on its own initiative as well as compliance audits following referral from judicial authorities. In 2024 it carried out 39 audits across private companies, public entities, and organisations connected to the Olympic Games.

Sanctions are applied by an independent sanctions committee, not the AFA itself. They include a public reprimand, which may be published, and fines of up to €200,000 for individuals, including company directors. Company-level fines can reach up to €1 million. These administrative sanctions are separate from criminal penalties for proven corruption, which can include exclusion from public procurement.

Separately, under negotiated settlements known as CJIPs, the Public Prosecutor can require a company to pay a public interest fine of up to thirty percent of its average annual turnover over the past ten years, implement an AFA-supervised compliance programme for up to three years, and compensate identifiable victims.

For a full breakdown of how fines are calculated and what they mean for budgeting and risk decisions, see How Sapin II Fines Can Impact Your Business Decisions.

What's Changing: Sapin III and CSRD

Two developments are worth watching if you're managing a compliance-adjacent role in 2026.

A bill known as Sapin III was tabled in October 2021 to strengthen the framework. It proposed extending Article 17 obligations to French subsidiaries of foreign groups and reinforcing the CJIP mechanism. As of 2026, Sapin III has not been enacted, and the binding framework remains Sapin II as supplemented by the 2022 Waserman law.

Separately, in October 2024 the AFA published guidance for companies subject to the Corporate Sustainability Reporting Directive, which requires reporting on anti-bribery and corruption programmes under the ESRS G1 standard. The AFA's position is that CSRD's reporting obligations effectively push companies that don't meet the Sapin II thresholds to progressively adopt Sapin II-aligned compliance measures anyway. If your company reports under CSRD, expect Sapin II-style expectations even below the €100 million turnover threshold.

A Quick Self-Check for Managers

Before your next AFA audit cycle or internal review, ask yourself:

  • Do I know where my team's whistleblowing channel is, and would I use it myself?

  • Have I approved any third party (supplier, agent, consultant) in the last year without documented due diligence?

  • Has my team had role-specific anti-corruption training, or just the general company-wide module?

  • Would I recognise a red flag in an invoice or expense claim from someone I manage?

  • Do I know what disciplinary consequences apply if someone on my team breaches the code of conduct?

If you answered no or not sure to more than one of these, that's your starting point, not a reason to panic.

Where to Go Next

This guide covers the manager's-eye view of Sapin II: your exposure, your obligations, and where the law is heading. For the complete regulatory picture, including AFA audit procedures and a full 2026 compliance checklist, start with The Complete Guide to Sapin II Compliance in 2026. For hands-on implementation of each pillar, read The 8 Mandatory Sapin II Requirements Every Organisation Must Understand. If you're specifically responsible for policy language, Anti-Corruption Policies Under Sapin II is the next step, and How Sapin II Fines Can Impact Your Business Decisions walks through the financial exposure in more detail.

For ongoing monitoring of France's anti-corruption performance against international peers, the OECD's Working Group on Bribery publishes regular reports worth bookmarking.

Frequently Asked Questions

What is Sapin II in simple terms?
Sapin II is a French anti-corruption law that requires large companies to proactively prevent corruption through a documented compliance programme rather than relying solely on sanctions after misconduct occurs. The law also established the French Anti-Corruption Agency (AFA) and strengthened legal protections for whistleblowers.
Who does Sapin II apply to?
Sapin II's anti-corruption compliance programme requirements apply to companies with more than 500 employees and annual turnover exceeding €100 million, including French subsidiaries of larger corporate groups. In addition, organisations with at least 50 employees must maintain an internal whistleblowing channel, regardless of their annual revenue.
Can a manager be personally fined under Sapin II?
Yes. Company executives and directors may be personally fined up to €200,000 for failing to comply with Sapin II obligations, independently of any penalties imposed on the company. Personal liability may also arise when compliance failures occur within foreign subsidiaries of a French parent company.
What are the penalties for non-compliance?
Administrative sanctions may include public reprimands and fines of up to €1 million for companies and €200,000 for individuals. Criminal penalties for proven corruption offences may also include exclusion from public procurement. In addition, companies may enter into a Judicial Public Interest Agreement (CJIP), which can result in financial settlements of up to 30% of the company's average annual turnover.
Is Sapin III now in force?
No. As of 2026, Sapin III has not been enacted. The current legal framework remains Sapin II, supplemented by the 2022 Waserman Law, which strengthened whistleblower protection and updated reporting procedures in France.