In a recent LinkedIn post, Francisco Gaffney discusses the pervasive challenges companies face with third-party bribery and fraud risks, arguing that traditional paper-based policies often fall short of regulatory expectations, particularly concerning the Bribery Act.
Gaffney emphasizes that regulatory bodies are increasingly looking for tangible, embedded controls rather than mere documented procedures. He points out that the standard of “adequate procedures” implies that a company’s internal controls are actively working to prevent bribery, not just theoretically addressing the possibility.
“Prosecutors seek embedded controls, not just documented procedures.”
The Shortcomings of Traditional Policies
Francisco Gaffney highlights a common pitfall for many organizations: relying on policies that exist primarily on paper. While documentation is a starting point, Gaffney argues that it’s insufficient to satisfy the demands of modern compliance and regulatory scrutiny. The key differentiator, according to Gaffney, lies in the active, embedded nature of these controls.
He elaborates on the practical implications:
“Adequate procedures mean that a company’s internal controls are actively preventing bribery, not just theoretically addressing it.”
This distinction is crucial for businesses operating in environments where third-party interactions can introduce significant compliance risks. Gaffney suggests that companies should consider proportionate measures, especially in critical areas like supplier due diligence and sanction screening, to bolster their defenses against bribery and fraud.
Ensuring Effective and Audit-Ready Controls
The core of Gaffney’s message revolves around the question of how companies can ensure their controls are both effective in practice and robust enough to withstand an audit. He posits that a more streamlined and integrated approach is necessary.
Gaffney proposes a solution focused on centralization and continuous analysis:
“All in one place. Continuous gap analysis. Clear view of what’s done, what’s missing, and who owns the fix before assurance or audit.”
This approach, as outlined by Gaffney, aims to provide clarity and accountability, moving beyond the reactive nature of audits to a proactive stance on compliance. The emphasis is on doing it right the first time, thereby reducing the ongoing burden of managing compliance risks.
A Call for Proactive Compliance
Francisco Gaffney’s insights underscore a shift in the compliance landscape, moving from a check-the-box mentality to a demand for demonstrable, embedded preventative measures. By advocating for a centralized, continuous analysis of controls, Gaffney provides a framework for businesses seeking to strengthen their defenses against third-party bribery and fraud effectively.
He concludes with a concise call to action:
“Do it once. Do it properly. Move on.”
This sentiment encapsulates the efficiency and effectiveness Gaffney believes can be achieved through the right compliance strategies.
📝 About This Content
This article is based on insights shared by Francisco Gaffney on LinkedIn.
📅 Originally posted on November 13, 2025 | View original post on LinkedIn →