Anti-corruption guidelines as a template: What companies really need in 2026
An anti-corruption policy only protects if it is lived, trained and documented. This guide shows the structure, mandatory chapters, chain of custody and the most common errors in templates from the Internet.
According to Section 130 OWiG, company management is liable for breaches of supervisory duties if crimes are committed within the company that could have been prevented through reasonable control. In cases of corruption, according to Section 30 OWiG, there is a risk of an association fine of up to 10 million euros, and in corporate cases significantly higher. An anti-corruption policy as a template is therefore not a decoration for the compliance folder, but rather one of the central pieces of evidence with which you show that your company has actually fulfilled its supervisory obligation. It is the written definition of what is permitted in the company, what is prohibited and how to react in case of doubt.
This article explains which chapters a reliable policy must contain, how you can clearly define thresholds for gifts and invitations and why the best template is worthless if training, acceptance and updating are not documented. We also show how the guideline is embedded in a consistent compliance architecture in which the appointment certificate, reporting line and audit templates work together. In addition, we will look at the most common errors that we see in practice and the few adjustments that can be made to turn a standard template into an audit-proof document. Others run compliance like a filing cabinet. We run it like software.
Key Takeaways
- According to Section 130 OWiG, an anti-corruption guideline is actually mandatory because it is the primary proof of reasonable supervision in the context of corruption.
- Templates from the internet usually only cover the text part and forget the three supporting pillars: training, acceptance and maintenance.
- The guideline only becomes reliable when every gift decision runs through a documented reporting line to the compliance officer.
Why an anti-corruption policy is not an option, but rather a supervisory requirement
The legal basis arises from the interaction of several standards. Section 130 OWiG obliges owners and managers to take appropriate supervisory measures to prevent violations within the company. Section 30 OWiG allows fines to be imposed on the company itself if such obligations have been violated. Sections 331 to 335a of the Criminal Code and Section 299 of the Criminal Code define the relevant corruption offenses, from taking advantage of bribery in business transactions to bribery of public officials. There are also industry-specific standards such as Section 7 HWG for the medical sector or procurement law for business with the public sector. The Money Laundering Act (AMLA) also touches on related topics with its duty of care and the obligation to identify beneficial owners.
In practice, this means: If an employee gives a buyer a weekend trip and your company cannot prove either policy or training, the public prosecutor's office will query precisely this chain of supervision. The defence is no longer 'we didn't know that', but must show what exactly was done to prevent exactly that. A written anti-corruption policy provides the first building block here, but without proof of training and a declaration of acceptance it is only half the battle. The question of whether the guideline actually fits the company's current risk profile also determines its effectiveness.
Whoever clearly fills the role of Compliance Officer and equips it with reporting obligations has the second building block. The third is ongoing maintenance: thresholds, high-risk countries and gift categories change, and a policy from 2021 will rarely be accurate in 2026. This is exactly the point where classic Word templates fail and where a platform-based solution has advantages. CIVAC is a compliance platform and officer-as-a-service. Licence the workspace for your internal representatives or have our representatives order it.
The eight mandatory chapters of a reliable template
An anti-corruption policy should contain at least eight chapters so that it is both legally viable and practical. Firstly, the scope: personal, factual, geographical, including group companies, joint ventures and sales partners. Anyone who draws this area too narrow runs the risk of leaving the most risky relationships outside the rule. Secondly, the definitions: what counts as an advantage, what as a third-party advantage, what counts as a public official according to Section 11 of the Criminal Code, what counts as a foreign official according to Section 335a of the Criminal Code. A clear definition of the term prevents later disputes about whether a specific process even falls under the regulation.
Thirdly, the ban with clear, as concrete as possible examples from your own industry. Fourth, the thresholds and approval procedures for gifts, invitations, donations, sponsorships and political contributions. Fifthly, the documentation and reporting obligations including reporting line to the compliance officer or the reporting office according to HinSchG. Sixth, the training requirement with frequency, target groups and form of proof. Seventh, the sanctions for violations, graded according to severity and repetition. Eighth, the implementation, responsibility, review cycle and version control with a traceable change history. Optionally additional: a glossary, FAQ sections and references to related guidelines such as gift, travel or donation guidelines.
Templates circulating on the internet usually only cover chapters one to four and parts of five. Training, sanctions and version management are often missing or remain non-binding. This is exactly where the question of supervision is decided in an emergency. The CIVAC representative overview shows how these roles can be clearly anchored in the organisational chart. If you want to orchestrate 25 roles without friction, you can't do that with Word documents. CIVAC operates this architecture as a compliance platform and officer-as-a-service, with 490 ready-to-use audit templates that map the transition from template to practice.
Clearly define thresholds for gifts and invitations
The most common vulnerability in templates is the handling of thresholds. Many models quote a flat rate of 35 or 50 euros per person per year. This may be sufficient for promotional gifts to private customers, but is far too rough in a B2B context with public clients, pharmaceutical sales or the medical profession. The professional association of the medical professions, for example, has its own recommended values, the Medicines Advertising Act (Section 7 HWG) largely prohibits donations, and in the public sector the rate is often 25 euros or less per person per year. Tax law also plays a role: according to Section 4 Paragraph 5 EStG, gifts to business partners can only be deducted as business expenses up to 50 euros net per recipient per year.
A reliable guideline therefore defines thresholds based on categories: one value for private customers, a second for commercial business partners, a third for public officials according to Section 11 StGB, a fourth for the medical professions and one for high-risk countries according to the Corruption Perceptions Index. Every acceptance or award above the minor threshold must be documented; everything above the approval threshold requires advance approval from the superior and the compliance officer. Approvals are not made by shout, but rather via a ticket system with a time stamp, justification and a four-eyes principle. Invitations to sporting and cultural events, trips, training and further education must also be clearly mapped out because their amount is often higher than traditional gifts.
In the CIVAC workspace, exactly this process is mapped out as a workflow, with an appointment certificate for the representative, reporting line and automatic file management. The appointment certificate, signed, filed, verifiable. The auditor calls, the evidence is ready. Licence the workspace for your internal representatives or have our representatives order it. In this way, an abstract threshold becomes a comprehensible decision-making path that can still be reconstructed two years later.
Training, declaration of acceptance and repetition cycle
A policy without proof of training is a piece of paper in an emergency. Supervisory authorities and public prosecutors regularly ask not for the text, but for the training register. Who was trained on what content, when, who understood and confirmed it in writing, who is overdue. Anyone who cannot provide anything here has a significant problem with proof in the Section 130 OWiG procedure, regardless of how elegantly the text of the guidelines is formulated. ISO 37001 (Anti-Bribery Management Systems) also explicitly requires verifiable training and awareness as a core requirement.
In practice, a three-part model is recommended. Firstly, mandatory onboarding training for all new employees in the first 30 days, with a test and written declaration of acceptance. Secondly, an annual repetition for all employees in risk-exposed functions such as purchasing, sales, public contracts, research and management. Thirdly, event-related training following incidents, changes in the law or mergers. Each training course is archived with date, content, participants and test results. External service providers, sales agents and distribution partners are included in the training regime through contractual clauses. A specific briefing with a focus on personal liability risks is also recommended for management.
The declaration of acceptance should not be lost in the personnel file, but should be part of a searchable compliance register that can be evaluated in the audit within seconds. Templates from the internet do not provide any infrastructure for this. It provides a compliance platform as standard. Audit-proof, documented, Section 130-proof. Anyone who sets things up seriously not only reduces the risk of fines, but also significantly shortens the response time to inquiries from auditors and supplier audits. Several weeks become a few days because the data does not have to be collected first. Collective bargaining agreements and co-determination aspects in accordance with Section 87 of the BetrVG must also be taken into account when setting up a training regime, especially if electronic learning systems are used. Employees with functions that require particular protection, such as internal auditing, internal investigations or sales in risk countries, should complete additional compulsory modules.
Reporting line, reporting point and interaction with HinSchG
Since the Whistleblower Protection Act (HinSchG) came into force in July 2023, companies with 50 or more employees have had to set up an internal reporting office. Suspicion of corruption is one of the central use cases. The anti-corruption directive must therefore clearly regulate to whom suspicious activity reports are sent, how whistleblower protection is ensured and which investigative obligations are triggered. The clock starts on awareness. Anyone who receives a report and does not respond not only risks fines against the company, but also personal liability for those responsible.
A reliable model connects three channels. Firstly, the direct line to the supervisor or management. Secondly, the anonymous report to the internal reporting office in accordance with Section 12 HinSchG. Thirdly, the external channel to the Federal Financial Supervisory Authority or the Federal Office of Justice, where required by law. The guideline explicitly names these channels, describes the response periods (seven days confirmation of receipt, three months feedback) and guarantees protection against reprisals in accordance with Section 36 HinSchG. The handling of anonymous reports must also be regulated because anonymous reports may neither be ignored nor passed on without a plausibility check. A technical solution with encryption and the option to choose between open and anonymous reporting is almost standard.
Selectivity is crucial in the investigation process: who investigates, who documents, who decides, who informs. A template from the internet rarely describes this. An integrated internal reporting point according to HinSchG with a compliance officer in person or a clear escalation matrix solves the problem structurally. CIVAC links both roles via a consistent reporting line and an EU data residency, so that data protection in accordance with Art. 33 GDPR is maintained in a whistleblower case with personal references. The retention period for reports and investigation documents must also be regulated: the HinSchG requires a reasonable period of time; in practice, three years after completion of the procedure are common, with a longer period for legally relevant processes.
High-risk countries, third parties and supply chain risk
Corruption is not a binary risk. It scales with geography, industry and partner structure. Transparency International's Corruption Perceptions Index provides a reliable basis for categorizing countries. Businesses in countries with an index below 40 should be marked as high risk in the policy, with stricter clearance, documentation and audit requirements. Industries such as construction, raw materials, defence and pharmaceuticals carry additional risk profiles that must be reflected in the policy and approval processes. Sectors with a high density of approvals, such as medical devices, energy supply or critical infrastructure, also belong to the increased risk category.
Third parties are the most common Achilles heel. Sales agents, distributors, customs agents, lobbying firms and joint venture partners are at the centre of 80 percent of international corruption proceedings. The policy must therefore describe a third-party due diligence process, graded according to risk, with background checks, contractual clauses on anti-corruption, audit rights and termination options in the event of a breach. Success-based commission models, cash payments and consultant fees without a comprehensible service description must be examined particularly critically. Politically exposed persons (PEPs) also require a more in-depth examination, comparable to the requirements of the Money Laundering Act.
With the Supply Chain Due Diligence Act (LkSG), the picture is getting worse. Corruption is not an original LkSG obligation, but the LkSG risk analysis, the complaint mechanisms and the reporting obligation to BAFA overlap significantly with anti-corruption structures. If you build both separately, you are duplicating work. If you think about it together, you save effort and gain transparency. The role of the LkSG officer and that of the compliance officer should meet in one workspace, not in two Excel files. The country of the contractual partner's branch, not just the headquarters of the parent company, is also relevant for the risk assessment. Anyone who only looks at the letterhead often overlooks the actual risks in operational business processing.
Sanctions, disciplinary measures and the question of proportionality
An anti-corruption directive without sanctions is toothless. This is exactly where supervisory authorities read whether the company takes its own rules seriously. Sanctions must be graduated and proportionate, from verbal warnings to written warnings to extraordinary termination in accordance with Section 626 of the German Civil Code (BGB). For executives and managing directors, additional recourse options apply in accordance with Sections 43 GmbHG, 93 AktG and withdrawal of appointment. Claims for damages under labour law and the loss of variable remuneration are also part of the catalogue of possible consequences. Filing a criminal complaint and reporting to the Federal Financial Supervisory Authority may also be mandatory in relevant cases.
Consistency is important. If a clerk is warned for 200 euros, but a sales manager only receives a note for 5,000 euros, the credibility of the guideline collapses. Sanction decisions should therefore be documented, kept in a sanctions register and countersigned by the compliance officer. The register also serves as a learning basis to recognise recurring patterns and improve prevention. An anonymized excerpt is suitable for training and makes the consequences tangible for all employees.
The most difficult part is dealing with managers. Here the directive needs a clear escalation chain to the supervisory board or advisory board so that the presumably biased superior does not decide on his own case. This also belongs in the template, but is left out in 90 percent of the freely available patterns. Anyone who works cleanly here not only protects the company, but also the compliance officer personally from accusations of tolerating violations. Audit-proof, documented, Section 130-proof. The question of voluntary disclosure is also important: in which cases, to which office and with what consequences for the reporting employee. A clearly formulated self-reporting rule can reduce fines and is part of a mature compliance culture.
Version management, review cycle and audit readiness
An anti-corruption policy is not a one-off document, but a living set of rules. It should be checked at least once a year to ensure it is up to date, adjusted if necessary and re-enacted. Occasions outside the regular cycle include changes in the law, incidents, M&A transactions, new markets and audit findings. Findings from industry cases, such as legally binding fines against competitors, are also reason for a review. The review obligation should be expressly anchored in the guideline itself, with the person responsible, frequency and escalation path.
The version management must be traceable: who changed what and when, who approved it, from when the new version is binding, which training was followed up. This rarely works reliably in Word documents with a file name suffix because versions exist in parallel and it remains unclear which version was valid during the period in question. A compliance platform with version history, audit trail and automatic re-training request solves this structurally. Old versions must also remain archived so that in the event of a dispute, the version valid at the time of the incident can be proven.
Audit readiness means that you can respond to an ISO 19600 question or an ISO 37001 certification in 24 hours with documents and training registers, not in 24 days. Auditors, BAFA auditors and supplier auditors expect exactly this speed of reaction. CIVAC provides the infrastructure for this with 490 ready-to-use audit templates, 93 controls according to ISO/IEC 27001:2022 for IT support and a reporting line that logs every step. A template alone does not provide this. A platform does. The auditor calls, the evidence is ready. An additional recommendation: an annual compliance report to the management and, if necessary, the supervisory board, which summarizes the effectiveness of the guideline, abnormalities, sanctions and training status. This report is a high-quality piece of evidence in the audit.
From template to resilient compliance structure
If you are looking for an anti-corruption policy as a template today, you are faced with two paths. One is the quick one: download a sample from the Internet, replace the company name, upload it to the intranet, and you're done. This approach does not help in the audit and does not protect the management from Section 130 OWiG in an emergency. It creates evidence, but no chain of custody. This is noticeable in the audit at the latest when the question about training register, version history and sanctioning practice.
The other way is the reliable one: a guideline that is embedded in a compliance architecture, with an appointment certificate for the Compliance Officer, a documented reporting line, annual training with a declaration of acceptance, sanctions register, version history and audit readiness. This is exactly what CIVAC delivers as a compliance platform and officer-as-a-service. Licence the workspace for your internal representatives or have our representatives order it. The appointment certificate, signed, filed, verifiable.
Turn reading into a mandate. If you would like to know how your existing policy can be converted into a platform-supported structure, write to info@civac.de or use the contact form on civac.de. CIVAC-SLA: two working days instead of the classic two to six weeks. You will receive an initial assessment of your current template, a gap analysis against Section 130 OWiG, Section 30 OWiG and HinSchG as well as a concrete path to audit readiness. Others run compliance like a filing cabinet. We run it like software. If you are looking for a discussion, you can also book a 30-minute exploratory meeting in which we will outline your initial situation, identify gaps and suggest a realistic schedule for implementation. An overview of the typical stumbling blocks that we see in comparable mandates is also part of the initial consultation so that you develop realistic expectations of time and effort. The appointment certificate, signed, filed, verifiable.
FAQ
Is an anti-corruption guideline as a template from the Internet sufficient to comply with Section 130 OWiG?
No, a template alone only provides the text part. Section 130 OWiG requires reasonable supervisory measures that include training, declaration of acceptance, reporting line, sanctioning and ongoing maintenance. Without these building blocks, the guideline remains a single document without a supporting structure in the audit. Only when it is linked to a designated compliance officer, a training register and a documented approval process does the template become reliable evidence in terms of the supervisory obligation.
What are the usual thresholds for gifts and invitations?
In the B2B sector, de minimis limits are usually 35 to 50 euros per person per year; when dealing with public officials, they are often 25 euros or less. For medical professions, stricter rules apply according to Section 7 HWG, which largely prohibit benefits. A serious guideline differentiates by recipient category, industry and country and defines clear approval and documentation requirements above the respective threshold. Lump sums without context are rarely tenable in an audit.
Who is responsible for the anti-corruption policy in the company?
The ultimate responsibility lies with the management in accordance with Section 130 OWiG; it cannot be delegated. The compliance officer is operationally responsible for the policy, its training, its maintenance and the sanctions register. If there is a staff union with the internal reporting office in accordance with the HinSchG, reporting lines and selectivity must be documented particularly clearly. Orders, reporting requirements and resources must be recorded in writing so that the role in the audit is demonstrably filled.
How often should the anti-corruption policy be reviewed?
At least once a year as part of a regular review, and additionally when there are changes to the law, incidents, M&A transactions or new markets. Legally binding fines against competitors or relevant judgments are also reasons for an update. Every change must be versioned, released and linked to retraining of the affected employees. A version history without comprehensible training documentation is only worth half as much in an audit.
How are the Anti-Corruption Directive and the Whistleblower Protection Act connected?
Suspicion of corruption is a core case of the HinSchG. The guideline must name the internal reporting office, specify response deadlines (seven days confirmation of receipt, three months feedback) and guarantee protection against reprisals in accordance with Section 36 of the HinSchG. Both sets of rules should converge in a compliance architecture so that a reference to corruption becomes a documented investigation with a reporting requirement, preservation of evidence and sanction decision without media disruption.
What role does the Supply Chain Due Diligence Act play in the Anti-Corruption Directive?
The LkSG requires risk analysis and complaint mechanisms along the supply chain. Corruption is not an original LkSG obligation, but third-party due diligence, audit rights and reporting overlap significantly. An integrated compliance platform avoids duplicate structures and reduces effort because the same third-party data can be used for LkSG risk analysis and anti-corruption due diligence. This saves time and increases data quality.
Sounds like a lot of work?
Officer duties, deadlines, paperwork — that's exactly what we take off your hands. Say hello and we'll show you how.
Turn this into a mandate.
Let us carry the operational weight. External officer, templates and documentation in one workspace. No obligation.