Skip to main content
Category: Anti-Corruption and AML

Good Practice Guidance on Internal Controls

Also known as: OECD Good Practice Guidance on Internal Controls, Ethics and Compliance
Simply put

The Good Practice Guidance on Internal Controls is a set of non-binding recommendations describing the elements companies can use to build an effective approach to preventing bribery. It outlines practical measures for internal controls, ethics, and compliance rather than imposing legally enforceable rules. It is intended to help organizations design and strengthen their anti-bribery programs, though its effectiveness depends on how it is implemented.

Formal definition

The Good Practice Guidance on Internal Controls, Ethics and Compliance is guidance issued in the anti-bribery context (associated with the OECD framework per the evidence) that sets out in detail the elements of a sound anti-bribery compliance approach, including internal controls, ethics, and compliance components. It is principles-based and non-binding, offering recommended practices rather than mandatory, jurisdiction-specific legal obligations, and it addresses only the anti-bribery dimension of a broader compliance program rather than constituting a complete program itself. Practitioners should note that this guidance is distinct from prescriptive standards or certifiable frameworks; its provisions are advisory, and adoption is generally regarded as supporting, not guaranteeing, an effective compliance posture. Specific issuing details and scope should be confirmed against the primary source, and application to particular legal obligations requires qualified legal counsel.

Why it matters

Bribery risk is one of the most consequential exposures a company faces, spanning legal liability, financial penalties, and reputational damage across the jurisdictions in which it operates. The Good Practice Guidance on Internal Controls, Ethics and Compliance matters because it distills, in practical detail, the elements that make up a sound anti-bribery approach, giving compliance officers and program designers a recognized reference point for what a credible program should contain. Because it is principles-based rather than prescriptive, it can be adapted to organizations of different sizes, structures, and risk profiles.

For practitioners, the value lies in its function as a design and benchmarking aid. When a company is building or strengthening its anti-bribery controls, the Guidance offers a structured set of recommended practices to work against, helping teams identify gaps in internal controls, ethics elements, and compliance components. This is particularly useful for demonstrating that a program reflects widely recognized good practice, though the Guidance itself is non-binding and does not carry the force of law.

It is equally important to understand the limits of what this Guidance provides. Adopting it is generally regarded as supporting an effective compliance posture, but it does not guarantee prevention of misconduct or protection from enforcement. Its effectiveness depends entirely on how it is implemented, monitored, and sustained over time, and it addresses only the anti-bribery dimension of what is typically a much broader compliance program. Companies should confirm specific obligations against primary sources and qualified legal counsel, since actual legal requirements vary by jurisdiction.

Who it's relevant to

Compliance Officers and Anti-Bribery Program Managers
For those responsible for designing and maintaining anti-bribery programs, the Guidance serves as a structured reference for the elements a sound approach should include. It can help identify gaps across internal controls, ethics, and compliance components, though managers should remember it addresses only the anti-bribery dimension and does not, on its own, constitute a full program.
Legal and Audit Teams
Legal and audit functions can use the Guidance as a benchmark when evaluating whether existing controls reflect recognized good practice. Because it is non-binding and jurisdiction-neutral, however, teams must map its recommendations against actual legal obligations that vary by jurisdiction, and application to specific requirements calls for qualified legal counsel.
Internal Controls and Risk Management Staff
Staff focused on internal controls can draw on the Guidance to strengthen the control environment against bribery risk. It offers recommended practices rather than mandatory rules, so its usefulness depends on how thoroughly and consistently the recommendations are implemented and sustained.
Learning and Development and Ethics Training Staff
Those who build ethics and compliance training can use the ethics and compliance elements described in the Guidance to inform content and reinforce expected conduct. Training is only one component of the broader approach the Guidance describes, and adopting it supports rather than guarantees an effective compliance posture.

Inside Good Practice Guidance on Internal Controls

Scope and Nature of the Guidance
Good Practice Guidance on Internal Controls refers to non-binding, principles-based recommendations addressing internal controls, ethics, and compliance programs, typically issued to help organizations design measures that deter and detect misconduct. It offers guidance rather than imposing legally binding obligations, and its specific authority and content should be confirmed against the primary source document from the issuing body.
Internal Controls Component
The internal controls element concerns the systems, processes, and checks an organization establishes to promote adherence to applicable laws, regulations, and internal policies. This is a program element distinct from a standalone training module; training may support awareness of controls but does not by itself constitute the control environment.
Ethics and Compliance Distinction
Such guidance generally spans both compliance (adherence to external laws, regulations, and internal policies with defined consequences) and ethics (values-based conduct that may exceed legal minimums). The guidance sits across this spectrum rather than treating the two as interchangeable.
Risk-Based Orientation
Good practice guidance is commonly framed around assessing and responding to an organization's specific risks, meaning controls are intended to be proportionate to identified exposures rather than applied uniformly. A risk assessment is a separate program element that informs, but is not the same as, the controls themselves.
Supporting Program Elements
Effective internal controls typically operate alongside other distinct components such as a code of conduct, a whistleblower or reporting channel, and a monitoring and auditing function. The guidance addresses how these elements interrelate, but each remains a separate part of a larger compliance and ethics system.

Common questions

Answers to the questions practitioners most commonly ask about Good Practice Guidance on Internal Controls.

Is the Good Practice Guidance on Internal Controls a legally binding regulation that companies must follow?
No. It is non-binding guidance rather than a statute or enforceable regulation, so it does not itself carry the force of law. It is intended to inform how organizations design and strengthen internal controls, ethics, and compliance measures, but the specific legal obligations that apply to an organization arise from the applicable laws and regulations in its jurisdictions. Whether and how the guidance is relevant to any particular legal requirement should be confirmed with qualified legal counsel, as this entry is educational and not a substitute for professional advice.
Does adopting this guidance guarantee that an organization will prevent misconduct or be protected from enforcement?
No. No guidance, control framework, or set of measures can guarantee prevention of misconduct or provide legal protection. The guidance is generally regarded as describing practices that may support effective internal controls and compliance efforts, but outcomes depend on how measures are implemented, resourced, and sustained in a given organizational context. Any assessment of how such practices are viewed in an enforcement or legal setting depends on jurisdiction and specific facts and should be evaluated with qualified counsel.
How does this guidance relate to the other components of a compliance program, such as training or a code of conduct?
The guidance addresses internal controls as one element within a broader compliance and ethics system. Internal controls are distinct from, but connected to, components such as training modules, a code of conduct, risk assessment, whistleblower channels, and monitoring and auditing functions. The guidance is intended to inform the controls dimension and should be read alongside those other components rather than as a substitute for any of them or for the program as a whole.
Who within an organization is typically responsible for applying this guidance?
Application generally involves collaboration among the functions that design, deliver, and maintain compliance and ethics measures, including compliance officers, ethics program managers, legal and audit teams, and learning and development staff. Because internal controls span financial, operational, and compliance domains, responsibilities are commonly shared and should be assigned according to the organization's structure, risk profile, and governance arrangements.
How can an organization assess whether its internal controls align with this guidance?
Alignment is generally assessed through the organization's own review, monitoring, and auditing functions, which examine whether controls are designed appropriately for identified risks and whether they operate as intended in practice. Because the guidance is principles-based rather than a prescriptive checklist, assessment involves judgment about fit to the organization's context, and results should be interpreted alongside the specific legal and regulatory requirements that apply.
How does this guidance fit with certifiable standards or other compliance frameworks an organization may use?
This guidance provides non-binding recommendations and does not itself establish a certifiable framework. Organizations may use it alongside other frameworks or standards they have adopted, recognizing that some standards are certifiable and others are advisory, and that voluntary frameworks do not carry the force of law. How the guidance and any adopted frameworks are reconciled depends on the organization's objectives and applicable requirements, which should be confirmed against primary sources and with qualified advisors.

Common misconceptions

Good practice guidance on internal controls carries the force of law and must be followed exactly as written.
This guidance is generally non-binding and principles-based. It offers recommendations rather than mandatory legal obligations, and organizations must still identify the binding laws and regulations that apply in their jurisdictions. Whether and how it should be applied may require qualified legal counsel, as requirements vary by local law.
Implementing the recommended internal controls guarantees the prevention of misconduct or provides legal protection.
No set of internal controls guarantees prevention of misconduct or legal protection. Such measures are intended to support deterrence and detection, but outcomes depend heavily on implementation, organizational context, and ongoing monitoring. Any protective effect should not be assumed.
Following this guidance means delivering training satisfies the organization's internal controls obligations.
Training is only one component and does not by itself constitute an internal controls framework or a complete compliance program. Internal controls encompass processes, checks, monitoring, and auditing that operate independently of, and alongside, any training module.

Best practices

Confirm the exact content, issuing body, and authority of the specific guidance against the primary source document before relying on it, rather than assuming universal applicability.
Treat the guidance as principles-based input and map its recommendations to the binding laws and regulations that actually apply in each relevant jurisdiction, engaging qualified legal counsel where obligations are unclear.
Base internal controls on a documented risk assessment so that controls are proportionate to the organization's identified exposures rather than applied uniformly.
Integrate internal controls with other distinct program elements such as the code of conduct, reporting channels, and the monitoring and auditing function, treating each as a separate but connected component.
Use qualified language when communicating expected outcomes, describing controls as intended to support deterrence and detection rather than as guarantees of prevention or legal protection.
Periodically review and test the controls, and document implementation, since effectiveness depends on ongoing execution and context rather than one-time adoption.