Skip to main content
Dark green background, "Weak Application Security Can Cost You Millions," 3 slanted images of fingers pointing to digital locks, and a "Learn the Basics" button
Compliance Programs Don't Fail Because of Missing PoliciesAnti-Corruption & AML
4 min readFor Compliance Training Managers

Compliance Programs Don't Fail Because of Missing Policies

The Conventional Wisdom

Ask most compliance professionals about effective anti-bribery programs, and you'll hear a familiar list: a Standards of Business Conduct, clear policies, regular training, and a whistleblowing channel. These elements are foundational.

While this thinking isn't entirely wrong, having these components in place doesn't guarantee compliance success. Federal Sentencing Guidelines for Organizations and ISO 37001 Anti-Bribery Management Systems include them, but they're just the basics. Southern Glazer's Wine & Spirits had all these elements when employees allegedly routed Kickbacks through approved vendors, hidden under legitimate-looking invoices.

The Real Issue

The conventional approach views compliance as a checklist, but it's actually a systems issue. Perfect policies won't stop misconduct if there are gaps between them.

Southern Glazer's didn't fail due to a lack of policy against Kickbacks. They failed because their financial controls couldn't detect when approved vendors generated millions in prepaid gift cards with invoices that didn't accurately describe the expenses. The policy was there; the payments happened anyway.

This highlights a crucial point: the gap between what your policies prohibit and what your systems can detect. If someone wants to route a bribe through your organization, they won't label it "bribe." They'll use approved infrastructure like marketing budgets or vendor invoices.

The real question isn't whether you have anti-bribery policies. It's whether your accounts payable system would flag suspicious patterns, whether your procurement team knows what disguised payments look like, and whether finance and compliance are communicating effectively.

Evidence of Change

Southern Glazer's settlement with the US Department of Justice offers insight into effective compliance changes. After agreeing to pay $12.5 million under a two-year non-prosecution agreement, they didn't just rewrite their Standards of Business Conduct.

The company increased compliance staff by 85% between 2022 and 2024, and funding rose by over 65%. These aren't superficial changes; they show a commitment to building capacity, not just assigning responsibility to an overstretched legal team.

However, resources alone aren't enough. Southern Glazer's restructured how compliance connected to business processes. They introduced mandatory vendor approval before payments, implemented independent audits of bill-backs and accounts payable, and created an "iShop" platform for marketing expenditure.

These changes focus on the intersection of compliance policy and financial transactions, addressing how money moves, not just the rules about it.

The company also tackled third-party vendor issues. In 2019, they stopped marketing companies from handling incentives and gift cards. Yet, employees found other routes, receiving funds directly from suppliers or using other approved vendors.

This pattern should concern you: a control that closes one channel but leaves the underlying risk unaddressed.

Taking Action

Start by mapping where money moves in your organization, especially in areas with bribery risk. Don't just document approved processes. Identify workarounds: discretionary budgets, loosely defined vendor categories, and expense types that don't require detailed receipts.

Then, assess whether your financial controls can catch misconduct in those channels. Can your accounts payable system identify:

  • Invoices that don't match the stated service?
  • Repeat payments to vendors providing vague "marketing support"?
  • Expenses split to stay under approval thresholds?
  • Patterns suggesting personal benefits routed through business expenditure?

If not, your anti-bribery program has a blind spot that policies alone won't fix.

Connect compliance to transaction processors. Your compliance team should work directly with finance, procurement, and internal audit, not just at annual training sessions but in designing controls, reviewing vendor relationships, and investigating anomalies. Southern Glazer's introduced compliance champions in each state to provide local support and identify risks in specific business units, recognizing that headquarters policies need ground-level implementation.

For third-party relationships, extend controls beyond onboarding. Due diligence before appointment matters, but so does monitoring vendors once they're in your payment system. You need periodic reviews, transaction monitoring, audit rights, and a credible process for suspending relationships when concerns arise. Southern Glazer's made vendor approval a prerequisite to payment, linking due diligence to accounts payable rather than a separate compliance database.

Finally, test your remediation. When you identify a compliance issue and implement a fix, verify that people haven't found another way around the control. Block gift cards through one vendor? Check if they're now coming through a different category or directly from suppliers. Require pre-approval for entertainment expenses? Ensure they're not being reclassified.

When Conventional Wisdom Holds

This doesn't mean you should abandon policies, training, or reporting channels. They're essential. You can't build financial controls without defining acceptable expenditure. Employees need training to recognize red flags, and you need reporting channels for concerns.

Conventional elements matter for another reason: prosecutors and regulators expect them. The DOJ Criminal Division Guidance asks if an organization has clear policies, regular training, and accessible reporting mechanisms. Their absence signals a lack of effort.

But here's the distinction: these elements are necessary, not sufficient. They show your intent to prevent misconduct. What actually prevents it is the work of connecting policies to transaction systems, empowering compliance teams, and continuously testing controls against real risks.

Southern Glazer's had the conventional program. What they built afterward was a more effective compliance function with the capacity, authority, and financial integration to detect problems before prosecutors do.

Promotional banner for the Pentest Readiness checklist download

You Might Also Like