Skip to main content
Build an Anti-Corruption Strategy That Actually WorksAnti-Corruption & AML
5 min readFor Ethics & Hotline Program Leaders

Build an Anti-Corruption Strategy That Actually Works

Your organization just spent six months developing an anti-corruption strategy. You've got dozens of measures, multiple stakeholders, and executive buy-in. Then you realize: nobody knows who's responsible for what, there's no way to measure success, and you've left out the very people who could make it work.

This isn't hypothetical. France's 2025-2029 national anti-corruption plan shows how detailed strategies fail when they lack clear accountability, measurable outcomes, and inclusive design. The plan includes 36 measures across four pillars, but Transparency International France and others have criticized it for being too vague to implement effectively.

For ethics and hotline program leaders, this offers a practical lesson: a strategy document isn't the same as a working program. Here's how to build one that your team can actually execute.

The Problem: Why Generic Strategies Fail

When 77% of French citizens believe corruption is widespread and 81% distrust their government, you'd expect an anti-corruption strategy to address root causes with precision. Instead, France's plan suffers from what many corporate compliance programs face: it describes what should happen without explaining how, when, or by whom.

You're facing similar pressure. Your board wants an anti-corruption program. Regulators expect documented controls. But if your strategy document can't answer "who validates vendor due diligence by when?" or "how do we measure whether reporting channels are working?", you don't have a strategy. You have a wish list.

What You Need Before Starting

Don't draft a single measure until you have:

A current-state assessment. Map where corruption risk actually exists in your organization. France's strategy emphasizes organized crime and drug trafficking connections but gives limited attention to procurement and urban planning corruption, areas where documented problems exist. Your risk assessment should be sector-specific and evidence-based.

Stakeholder identification. List everyone who needs to be involved: compliance, legal, HR, procurement, finance, internal audit, and critically, your frontline employees and any external partners who interact with your controls. France's plan omits civil society organizations despite their contributions to anti-corruption enforcement. Don't make the same mistake by excluding the people who see your risks firsthand.

Measurement criteria. Before you write a single objective, decide what success looks like. Will you track hotline report resolution times? Vendor screening completion rates? Training attestation within 30 days of hire? If you can't measure it, you can't manage it.

Resource allocation. Know your budget and headcount. A strategy without dedicated resources is a policy that sits in a drawer.

Step-by-Step Implementation

Step 1: Write SMART objectives, not general commitments.

Replace "improve whistleblower protections" with "implement psychological support and legal defense fund for whistleblowers who report in good faith, with intake process operational by Q2 2026." France's Measure 13 and 14 reference improving reporting channels and sensitizing staff but don't address documented gaps like lack of financial support or ongoing retaliation despite legal safeguards.

For each objective, specify:

  • What will change (the outcome, not the activity)
  • Who owns delivery (name the role, not the department)
  • When it will be complete (quarter and year)
  • How you'll measure success (the metric and target)
  • What resources you'll allocate (budget, FTE, systems)

Step 2: Assign clear ownership with decision rights.

Create a responsibility matrix. For every measure, identify:

  • Who is accountable (one person who owns the outcome)
  • Who is responsible (the people doing the work)
  • Who must be consulted (subject matter experts)
  • Who must be informed (stakeholders who need updates)

France's strategy created an interministerial committee and appointed anti-corruption coordinators in each ministry, but it's unclear who decides what when measures conflict or require budget reallocation.

Step 3: Build reporting channels that people actually use.

Don't just announce a hotline. Make confidential reporting accessible:

  • Offer multiple channels (phone, web, in-person, third-party)
  • Provide reporting in languages your workforce speaks
  • Train intake coordinators on trauma-informed interview techniques
  • Publish response timeframes and stick to them
  • Track and publish aggregate metrics (volume, category, resolution time, substantiation rate)

Include Anti-Retaliation Safeguards that go beyond policy. Assign a specific person to monitor reporters for signs of retaliation. Create a rapid response process when retaliation is suspected. Consider financial support for reporters facing legal costs, as France's strategy fails to address despite documented need.

Step 4: Engage external voices systematically.

Don't design your program in isolation. Create formal touchpoints with:

  • Industry peers through compliance roundtables
  • Regulators through advisory comment periods
  • External auditors and consultants for independent assessment
  • Community organizations that see your company's impact
  • Journalists who cover your industry

Schedule these engagements quarterly, not annually. France's strategy omits any role for civil society organizations or media despite their contributions to anti-corruption enforcement.

Step 5: Create a public-facing accountability mechanism.

Publish an annual report that includes:

  • Progress against each objective with specific metrics
  • Challenges encountered and how you're addressing them
  • Budget allocated and spent
  • Changes to the strategy based on what you've learned

Make someone senior responsible for presenting this report to your board and posting it publicly.

Validation: How to Verify It Works

After six months, audit your own strategy:

Test ownership clarity. Pick three measures at random. Can you identify in under two minutes who owns delivery? If not, your responsibility assignments aren't clear enough.

Measure activity and outcomes. You should track both. Activity metrics (training completed, vendors screened) show effort. Outcome metrics (substantiated reports, control failures prevented, retaliation incidents) show impact.

Survey your users. Ask employees if they know how to report concerns, whether they trust the process, and if they've seen retaliation. Ask vendors if your due diligence process is reasonable. If awareness is below 70%, your communication plan isn't working.

Check for gaps. Review hotline reports, audit findings, and exit interviews. Are you seeing risks you didn't plan for? France's strategy emphasizes corruption linked to organized crime but may overlook procurement and urban planning issues. Your assessment should evolve as you learn.

Maintenance: Ongoing Tasks

Quarterly: Review metrics and adjust. Track leading indicators (reports filed, training completion, due diligence turnaround time) and lagging indicators (substantiated violations, control failures, regulatory findings). When metrics trend wrong, investigate why and adjust your approach.

Annually: Update your risk assessment. Your corruption risk profile changes as you enter new markets, launch new products, or face new competitive pressures. Refresh your assessment and revise objectives accordingly.

Every two years: Refresh your strategy. Don't wait for the five-year mark. If your objectives aren't driving the right behavior or your measures aren't reducing risk, rewrite them.

The difference between a strategy that works and one that doesn't isn't the number of measures or the polish of the document. It's whether someone can pick it up, understand exactly what they need to do, and see whether they've succeeded. Build that clarity in from the start.

You Might Also Like