77 officer roles, all coveredArt. 33 GDPR, 72 hours to report a breach93 controls under ISO/IEC 27001:2022905 ready-to-run audit templates in the workspace§ 130 OWiG, supervisory duty of the management boardOfficer appointment letter, signed, filed, evidencedOne workspace for tasks, trainings, audits, documentationDIN 14095 fire protection plans, standardisedEU AI Act, the first horizontal AI regulation worldwide77 officer roles, all coveredArt. 33 GDPR, 72 hours to report a breach93 controls under ISO/IEC 27001:2022905 ready-to-run audit templates in the workspace§ 130 OWiG, supervisory duty of the management boardOfficer appointment letter, signed, filed, evidencedOne workspace for tasks, trainings, audits, documentationDIN 14095 fire protection plans, standardisedEU AI Act, the first horizontal AI regulation worldwide
EU Anti-Corruption Directive 2026: Corporate Impact
Governance & Compliance

EU Anti-Corruption Directive 2026: Corporate Impact

21 August 20269 min readBy Dr. Henrik Bauer
CIVAC

The EU Anti-Corruption Directive 2026 raises fines to up to 5 percent of turnover. Learn what the 2028 implementation deadline means for your company.

Key Takeaways

  • The EU Directive must be transposed into German law by 1 June 2028; it does not bind companies immediately.
  • Fines for companies will rise to 3 to 5 percent of global annual turnover, or 24 to 40 million euros.
  • Individuals face prison sentences of 3 to 5 years depending on the specific corruption offence.
  • Managing directors are liable under § 130 OWiG, with national draft laws planning up to 40 million euros in fines.

Directive vs Regulation: The legal framework

With the adoption of the new EU Anti-Corruption Directive, the European Union has enacted a fundamental realignment of European criminal law on corruption. The new legal framework replaces the outdated Council Framework Decision 2003/568/JHA and the 1997 EU Convention on the fight against corruption involving EU officials[1]. For corporate practice, the legal classification is decisive: this is a directive pursuant to Art. 288(3) TFEU, and explicitly not a directly applicable EU regulation.

An EU regulation, such as the GDPR or the EU AI Act, unfolds immediate legal effect for all legal entities across the internal market upon entering into force. By contrast, the Anti-Corruption Directive addresses the legislators of the EU Member States. It does not bind companies in Germany directly from day one of its entry into force at the EU level. Binding obligations and criminal provisions for managing directors and operational businesses only arise through the national transposition act enacted by the German federal legislator.

  • Legal nature: European Union Directive aimed at harmonising criminal offences and sanctions across all Member States
  • No direct effect on businesses: Imposes an obligation on Member States to amend national criminal and administrative offence laws
  • Transposition deadline for companies: Exactly 24 months from entry into force (deadline: 1 June 2028)
  • Special deadline for public authorities: 36 months for national anti-corruption strategies and official risk assessments

Member States have exactly 24 months from the effective date to transform these provisions into national law. The definitive deadline for corporate implementation ends on 1 June 2028. An extended deadline of 36 months applies solely to overarching national anti-corruption strategies and state risk assessments. Interpreting this transition period as a breathing space misunderstands the regulatory momentum: the forthcoming tightening of German law requires an immediate, exhaustive review of all existing internal control mechanisms.

The legislative timeline: From draft to Official Journal

The interinstitutional legislative procedure under file reference 2023/0135 (COD) passed through all formal stages of the European legislative framework[2]. From the initial proposal by the European Commission on 3 May 2023 to its binding publication in the Official Journal of the European Union, the initiative required three full years of intensive negotiations.

DateMilestoneLegal consequence
3 May 2023Commission Proposal (2023/0135 COD)Initiation of the European legislative process to combat corruption
2 December 2025Provisional Trilog AgreementPolitical compromise reached between the European Parliament, Council, and Commission
26 March 2026Formal Adoption by the European ParliamentFirst-reading approval by Parliament
21 April 2026Final Adoption by the CouncilLegally binding decision by the Member States
11 May 2026Publication in the EU Official JournalOfficial promulgation of the Directive in the Official Journal
1 June 2026Entry into Force of the DirectiveCommencement of the 24-month transposition period (20 days post-publication)
1 June 2028End of Transposition Deadline (24 Months)Mandatory enforcement of revised national legislation across all Member States
1 June 2029End of Special Authority Deadline (36 Months)Completion of national anti-corruption strategies and regulatory risk assessments

With its entry into force on 1 June 2026, the clock is ticking for both the German legislature and executive management teams. The Federal Republic of Germany must adapt the German Criminal Code (StGB) and the German Act on Regulatory Offences (OWiG) to meet the minimum standards established in Brussels within this two-year window. By 1 June 2028 at the latest, these revised provisions will be fully applicable and enforceable across daily business operations.

Drastic sanctions: Liability risks for companies

The core of the new EU mandate lies in a massive escalation of the sanctioning framework, far exceeding historical liability caps. Member States are required to establish effective, proportionate, and dissuasive sanctions against natural and legal persons alike. Under Art. 13 of Directive (EU) 2026/1021, legal persons are explicitly held liable whenever a lack of supervision or control by a person in a leading position made it possible for a subordinate person to commit an offence for the benefit of the company[3].

For commercial entities, the new standard establishes a fine framework ranging from 3 to 5 percent of total worldwide annual turnover, or alternatively fixed minimum maximums of 24 to 40 million euros, depending on the gravity of the underlying offence[1]. For severe offences such as bribery in the public and private sectors as well as misappropriation, the maximum threshold reaches 5 percent of global turnover or 40 million euros. For offences such as trading in influence, obstruction of justice, and illicit enrichment, the minimum statutory ceiling is set at 3 percent or 24 million euros[4].

  • Corporate financial penalties: 3 to 5 percent of global annual turnover or 24 to 40 million euros depending on the offence severity
  • Custodial sentences for executives: Imprisonment ranges of 3 to 5 years for convicted individuals
  • Expanded catalogue of offences: Harmonised definitions for bribery, misappropriation, granting undue advantages, and trading in influence
  • Exclusion from public procurement: Ancillary sanctions including disqualification from public tenders, commercial debarment, and withdrawal of subsidies

For acting individuals and members of governing bodies, the Directive mandates prison terms of 3 to 5 years. This marks a new level of severity across the European Union: corruption is no longer treated as an administrative irregularity or secondary economic offence, but as a primary corporate crime that directly threatens company solvency and personal liberty.

The German status quo: § 130 OWiG in practice

Under the German legal system, managing directors and board members are already subject to stringent liability for supervisory failures. Pursuant to § 130 OWiG, the owner or managing director of an enterprise commits an administrative offence if they intentionally or negligently fail to take the supervisory measures necessary to prevent operational crimes or administrative violations committed by employees. In conjunction with § 30 OWiG, this triggers substantial corporate association fines against the legal entity itself.

Currently, the statutory maximum fine for supervisory breaches in connection with corruption offences in Germany stands at up to 10 million euros (§ 30(2) sentence 1 no. 1 OWiG). However, a national draft bill has already been drafted to raise this threshold up to 40 million euros while introducing stricter assessment criteria for public prosecutors and courts. This legislative initiative is pending completion: neither the German Bundestag nor the Bundesrat has granted final approval.

  • Current legal framework: § 130 OWiG in conjunction with § 30 OWiG caps corporate fines at 10 million euros
  • Planned reform: National draft legislation to raise penalties to 40 million euros with stricter supervisory scrutiny
  • Legislative status: National legislation in preparation and not yet formally enacted
  • Liability mechanism: Failure to install adequate controls creates direct personal exposure and corporate fines

The pending EU transposition by June 2028 obliges the German legislature to align § 30 OWiG with the required percentage-of-turnover sanction models. Managing directors cannot rely on ignorance regarding subordinate employee misconduct. An absence of verification mechanisms, ambiguous approval workflows, or fragmented audit records fully establishes an actionable breach of supervisory duty under § 130 OWiG.

The Compliance Officer as the operational center

To satisfy the requirements of the EU Directive and the statutory supervisory duties under § 130 OWiG, appointing a formal officer is indispensable. A qualified Compliance Officer serves as the operational interface between statutory mandates and daily business processes. Without a clearly designated individual equipped with genuine authority, any corporate anti-corruption policy remains ineffective paper compliance.

Operational responsibilities extend far beyond maintaining static codes of conduct. The officer must actively identify operational risk clusters, implement verification routines for financial disbursements and corporate gifts, and oversee engagements with external commercial agents. This requires an exhaustive risk analysis that quantifies exposure across operational divisions, regional markets, and transaction thresholds while defining documented mitigation measures.

  1. 1Formal appointment: Written, designated appointment with an explicit scope of duties and an unmediated reporting line to executive management
  2. 2Risk evaluation: Systematic analysis of corruption risks across sales channels, procurement, corporate sponsorships, and external intermediaries
  3. 3Policy administration: Establishment of mandatory value thresholds for hospitality, gifts, and donations via an anti-corruption policy
  4. 4Third-party due diligence: Risk-based screening and background checks prior to signing consulting, advisory, or brokerage contracts
  5. 5Whistleblower oversight: Active supervision of internal reporting channels under the German Whistleblower Protection Act (HinSchG) and execution of remedial actions

For corporate management, the formal appointment of a dedicated compliance officer is the primary evidence of fulfilling statutory supervisory obligations. In the event of a regulatory investigation, enforcement agencies first assess who was assigned operational oversight and whether that individual was granted adequate investigative and intervention powers.

Building a Resilient Compliance Management System

An effective Compliance Management System (CMS) cannot be a static PDF sitting on the company drive. Article 16 of the new EU Anti-Corruption Directive explicitly establishes that the existence of functioning internal control and compliance programmes can be treated as a mitigating factor in a company's favour. Recital 29, however, makes one thing unambiguous: paper-tiger programmes with no practical implementation carry no weight in court.

A resilient CMS rests on standardised processes and recurring control routines. Staff in high-risk functions such as sales, procurement and public affairs must be demonstrably trained. Training without a digitally signed record of attendance and comprehension has no evidentiary value before supervisory authorities. The same applies to approval workflows for invitations, sponsorships and consultancy agreements: every transaction must follow a defined audit trail.

  • Mandatory recurring training: repeat sessions with automated attendance and comprehension checks
  • Two-person rule and thresholds: documented approval workflows for gifts, hospitality and fees
  • Internal audits: regular spot checks of high-risk accounts and payment flows
  • Audit-proof archiving: gapless storage of every approval, audit report and training certificate
  • Immediate remediation: demonstrable investigation and sanctioning of any irregularity found

Only when controls, audits and training are documented end to end and time-stamped does the CMS deliver its liability-mitigating effect. Supervisory authorities do not assess intent - they assess the actual density of controls in place.

Audit-Proof Processes for the Expanded Supervisory Duty

The transition period running to 1 June 2028 gives companies a clear window to put their compliance architecture on a professional footing. Anyone who waits until the German transposition law takes effect risks incomplete processes and personal liability exposure under § 130 OWiG. In practice, proving that obligations have been met only works when all tasks, training and audits come together centrally and in an audit-proof way.

In practice, companies have two models available: they can license a central workspace for €49 per officer role per month to equip internal officers with audit-proof templates and structured workflows, or they can have named, certified external officers appointed to run the mandate on a liability-safe basis. Either way, the result is a gapless chain of evidence that holds up under regulatory review.

  • Central workspace: manage all 77 statutory and industry-specific officer roles on one platform
  • Audit-proof evidence chain: tasks, training records, site visits and audits with timestamp and digital signature
  • Legally sound appointment deeds: formally valid appointment documents for management and supervisory authorities
  • Automated reporting: audit-proof compliance reports for boards, auditors and supervisory bodies

We handle compliance. You run your company. Prepare your organisation now, in a structured way, for the 2028 transposition deadline, so your evidence is ready the moment a regulator calls.

FAQ

Is the EU Anti-Corruption Directive 2026 immediately binding on German companies?

No. Because it is a directive rather than a regulation, it has no direct effect. The German legislature has 24 months from entry into force to transpose the requirements into national law. The final transposition deadline ends on 1 June 2028.

What sanctions does the EU Council require for companies?

According to the Council's official press release, Member States must enshrine fines of 3 to 5 percent of total worldwide annual turnover, or 24 to 40 million euros, in national law, depending on the offence.

What penalties do individuals face under the new EU directive?

For individuals found guilty of corruption, the directive provides for tough criminal consequences. Depending on the severity of the offence, Member States must set prison sentences of 3 to 5 years in their national criminal law.

How high is the current fine framework in Germany under § 130 OWiG?

Currently, the maximum fine for supervisory breaches linked to corruption offences in Germany is 10 million euros. A draft bill is in preparation that would raise this to up to 40 million euros, but the legislative process has not yet been completed.

Which older rules does the new directive replace?

The new directive replaces the Council Framework Decision 2003/568/JHA on combating private-sector bribery and the 1997 EU Convention on combating bribery involving EU officials.

No obligation

Sounds like a lot of work?

Officer duties, deadlines, paperwork — that's exactly what we take off your hands. Say hello and we'll show you how.

Turn this into a mandate.

Let us carry the operational weight. External officer, templates and documentation in one workspace. No obligation.

Related articles