Caroline Black at Gherson Solicitors LLP explains how the EU’s new Anti-corruption Directive will affect business across the world

Europe is entering a new harmonised era in its fight against corruption – and businesses, both inside and outside the EU, are firmly in the spotlight.
On 24 March 2026, the European Parliament approved the Anti-Corruption Directive, marking the most significant overhaul of the region’s anti-bribery and corruption framework in decades. Although corruption has long been criminalised across Member States, definitions of relevant conduct and penalties have varied widely. That inconsistency is at the heart of what Brussels is now trying to remedy, whilst attempting to retain a respect for individual States’ autonomy on issues of implementation.
Harmonised Standards of Conduct
At its core, the Directive introduces a harmonised legal approach to corruption across the EU, by defining what conduct must be prohibited by Member States and setting minimum standards for consequential penalties for individuals and companies. The concepts go far beyond traditional notions of bribery and include public and private sector corruption, trading in influence, abuse of power, embezzlement and obstruction of justice linked to corruption cases.
Corporate Liability for Corruption Across EU
Perhaps the most significant change is the requirement to introduce corporate liability across all Member States. In practical terms, once implemented, companies will be held responsible not only for corrupt acts committed by senior executives but also for failures in oversight. If an employee or intermediary engages in corruption and the company is found to have inadequate controls, liability can follow – with an ineffective control or monitoring program even being seen as an aggravating factor to the offence itself.
This brings the EU closer to regimes like the UK Bribery Act 2020, which has long imposed a “failure to prevent” standard. For businesses operating internationally, the direction of travel is clear: regulators are no longer satisfied with punishing wrongdoing ‘after the fact’ – they expect companies to actively prevent, detect, report and remediate it. This increases regulatory risk across EU operations.
New Penalty Floor
The financial stakes are high. The Directive requires Member States to impose substantial penalties on companies, including fines linked to 3%-5% of global turnover depending on the offence or a minimum/maximum of EUR 24m or EUR 40m. The level of these potential fines places the issue firmly in the category of a board-level risk. Additional sanctions may also include exclusion from public procurement contracts, withdrawal of licences and even judicial supervision. For companies reliant on government contracts or regulated markets, the implications of a conviction could be existential.
Jurisdictional Reach
While the Directive is an EU instrument, its impact will not stop at the border. Non-EU companies will find themselves subject to its provisions if they operate within the EU, have subsidiaries there or engage in business that touches EU markets. In effect, the Directive means that the EU-wide rules are poised to become another global compliance benchmark, alongside long-arm US and UK anti-corruption laws.
For multinational organisations, this creates a complex but familiar challenge: aligning compliance programmes across multiple jurisdictions with overlapping expectations. However, even once implemented, it remains to be seen if enforcement is similarly consistent across the EU, with recent OECD reports suggesting the existence, currently, of significant variations.
What Should Businesses Be Doing Now?
Companies need not wait for Member States to implement relevant provisions domestically. The direction of travel is clear, and legislation such as the UK Bribery Act (together with its “adequate procedures” defence and associated guidance) provides an established route to prevention.
The first step for companies is to undertake a specific and focused risk assessment on corruption risks, which often hide in third-party relationships such as with agents, distributors and consultants – particularly in higher-risk markets. The new framework places significant emphasis on accountability for these relationships, meaning due diligence processes will need to be both deeper and more dynamic.
Equally important is corporate governance. Compliance should be embedded at the highest levels of the organisation, meaning active board oversight, clear reporting lines and demonstrable accountability. A policy sitting on a shelf (or in an inbox) is far from enough: companies must be able to show that they ‘live and breathe’ compliance with effective controls working in practice.
Sophisticated organisations are increasingly moving towards data-driven compliance, using analytics to identify (almost in real time) unusual patterns in payments, procurement or third-party activity. As enforcement agencies become more sophisticated, static, checklist-based approaches are likely to fall short.
Robust whistleblowing mechanisms, aligned with existing EU rules, will be essential. Employees and partners must have safe, accessible channels to report concerns – and companies must be prepared to act on them quickly and effectively.
Ultimately, what is emerging is a shift in regulatory philosophy across the EU. The question is no longer simply whether corruption occurred, but whether a company did enough to prevent it. For compliance teams, this places a premium on evidence: documented risk assessments, training records, audit trails and clear enforcement of policies.
Compliance moving up the agenda
It is clear that the Directive ensures that anti-corruption compliance is moving further up the corporate agenda across the region. No longer confined to legal departments, it is a strategic issue with direct implications for growth, reputation and market access. As the EU tightens its grip, businesses operating within its borders face a simple reality: prevention is no longer optional. It is a legal expectation and, increasingly, a condition for doing business at all.
Caroline Black is White Collar Crime Consultant at Gherson Solicitors LLP
Main image courtesy of iStockPhoto.com and PeopleImages


© 2025, Lyonsdown Limited. Business Reporter® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543