The question at hand
When designing your anti-corruption program, you face a critical choice: focus on demonstrating compliance or on changing behavior. One path emphasizes training completion rates, policy acknowledgments, and audit readiness. The other aims to ensure your team recognizes and stops Kickbacks before they occur.
This isn't just theoretical. A U.S. alcohol distributor recently paid $12.5 million to resolve allegations of Kickbacks to retailers. The company now must make substantial compliance improvements. This settlement raises a practical question for every compliance training manager: Would your program have caught this before the DOJ did?
The answer depends on your approach.
The case for demonstration-focused compliance
Many practitioners build programs around what regulators will examine during an investigation. This approach has its merits.
You need documentation. When the DOJ evaluates your compliance program, they look for evidence: training records, policy distributions, attestations, and audit trails. If you can't show that employees received anti-corruption training before interacting with retailers or government buyers, your defense is weakened.
Standardization protects you. A demonstration-focused program creates consistency across regions and business units. Everyone gets the same training, signs the same policy, and follows the same approval workflow for gifts and hospitality. This uniformity makes it harder for bad actors to claim ignorance and provides your legal team with clearer facts if something goes wrong.
Measurement becomes straightforward. You can report that 94% of sales staff completed anti-bribery training this quarter. You can show the board that 100% of third-party intermediaries signed your Standards of Business Conduct. These metrics communicate program health in language executives understand.
Efficiency matters too. Building training that checks regulatory boxes and scales across thousands of employees takes less time than customizing content for every role and risk scenario. When managing compliance for a distributed workforce, standardized modules and automated tracking let you cover more ground with the same budget.
The case for prevention-focused compliance
Others argue that checking boxes doesn't stop Kickbacks. They build programs around risk scenarios and decision points.
Training needs context to change behavior. A generic anti-corruption module won't help your sales rep recognize that offering a retailer "marketing support" in exchange for shelf space might cross into bribery territory. Prevention-focused programs map training to actual risk moments: the negotiation, the renewal conversation, the request for a favor. They ask: What will this employee face next month, and how do we prepare them for that specific pressure?
Policies don't enforce themselves. You can require pre-approval for all gifts over $50, but if your approval process takes three days and your sales team operates on 24-hour cycles, they'll find workarounds. Prevention-focused compliance means building controls that fit how work actually happens. That might mean delegating approval authority closer to the field or creating decision trees that help employees self-assess before they act.
Culture matters more than documentation. If your team believes compliance exists to protect the company from lawsuits rather than to guide ethical decisions, they'll treat it as a hurdle to clear. Prevention-focused programs invest in explaining why the rules exist: the harm that corruption causes, the reputational damage, the competitive disadvantage of operating in gray areas. This takes longer than pushing out a training module, but it builds the judgment employees need when they face situations your policy manual doesn't address.
The measurement looks different. Instead of tracking completion rates, you're tracking whether employees used your advice channel before making a questionable payment. You're measuring whether reports to your Speak-Up Program increased after you trained managers on recognizing red flags. You're asking whether your due diligence process actually stopped you from engaging a high-risk third party.
Where practitioners actually land
Most compliance training managers don't pick one approach and ignore the other. You need both documentation and behavior change.
The split usually happens by risk level. For low-risk populations, demonstration-focused training works: annual refreshers, policy acknowledgments, basic awareness. For high-risk roles (sales teams dealing with retailers, anyone managing third-party intermediaries, employees in markets with elevated corruption risk), you layer in prevention-focused work: scenario training, role-specific guidance, frequent touchpoints.
The other common split is timing. You demonstrate compliance at the enterprise level (everyone gets the baseline training), then you prevent harm at the operational level (the sales team gets additional coaching before the holiday gifting season, the procurement team gets targeted training before engaging new suppliers).
Resource constraints drive decisions too. If you're a compliance team of two supporting 5,000 employees, you'll lean toward demonstration-focused programs because they scale. If you have embedded compliance partners in each business unit, you can invest more in prevention.
Our take
Build for prevention, but document for demonstration. The $12.5 million settlement shows what happens when compliance becomes performative. The company presumably had policies. They likely had training. But something in the program failed to stop Kickbacks to retailers.
Start with the risk scenario, not the training module. Ask: Where could Kickbacks happen in our business? Who faces pressure to make them? What would stop that person in the moment? Then build training and controls around those answers. Document everything you build, but don't let documentation become the goal.
Your completion rate matters less than whether your sales team knows how to push back when a retailer requests a kickback. Your policy library matters less than whether employees trust they can report concerns without retaliation. Your audit readiness matters less than whether you catch problems before the DOJ does.
The tradeoff is real: prevention-focused programs take more time, more customization, and more ongoing attention. But if your program wouldn't have stopped the conduct that led to a $12.5 million settlement, your documentation won't protect you. It'll just prove you knew better.



