Skip to main content
Promotional banner ad for the Penetration Testing Report Kit
AI Can't Build Ethics for YouRegulatory Obligations Management
5 min readFor Compliance Officers

AI Can't Build Ethics for You

The Challenge

When the EU Anticorruption Directive arrived with penalties reaching 5% of global revenue or €40 million for serious offenses, compliance teams faced a familiar problem: integrating new obligations without drowning in manual work. The Directive's scope is broad, establishing corporate criminal liability across all EU member states, demanding robust whistleblower protections, and creating incentives for effective compliance programs that can earn credit during investigations.

The initial response follows a predictable pattern. You run a gap analysis, update policies to cover bribery of both government officials and private businesses, revise training materials, and review third-party payment controls. AI and automation promise to accelerate every step.

However, one compliance officer found that technology solved the easy problems while leaving the hard ones untouched. Their analytics platform flagged high-risk third parties receiving payments without proper due diligence. The AI suggested policy language updates and even translated the new code of conduct into seventeen languages overnight.

What it couldn't do was convince skeptical procurement managers to adopt a redesigned vendor approval process or persuade employees that the new conflict-of-interest disclosure system was trustworthy enough to use honestly.

The Environment and Constraints

The team operated under typical constraints: a limited compliance budget, geographically dispersed operations across twelve EU countries, and a culture viewing compliance as a checkbox exercise rather than a business priority. Senior leadership supported the program in principle but measured success primarily by audit findings, not by whether employees understood why certain behaviors mattered.

The Directive's structure created a specific tension. Member states can grant credit for effective compliance programs, meaning there's a tangible benefit to getting implementation right. But "effective" doesn't mean "well-documented." It means the program actually prevents violations.

The compliance officer had access to a modern GRC platform capable of automated policy gap analysis, bulk contract review, and pattern detection in payment data. The technology could identify risks but couldn't change how people responded to those risks.

The Approach Taken

Rather than treating AI as a solution, the team repositioned it as a triage mechanism. The platform handled the volume work: scanning existing policies against Directive requirements, flagging third-party relationships that needed review, and routing standard conflict disclosures to appropriate managers.

This freed the compliance officer to focus on three areas where human judgment proved irreplaceable.

First, they redesigned the third-party risk management process with input from procurement and finance teams. The AI identified the gap, but only conversations with people who onboard vendors revealed why the old process failed. Documentation requirements were buried in a seventeen-step workflow that duplicated effort across departments. The new process consolidated approvals, reduced steps to nine, and embedded compliance checks at points where buyers were already gathering information. Adoption improved because the process respected how work actually happened.

Second, they rebuilt the conflict-of-interest program around trust rather than surveillance. Instead of positioning the disclosure system as a way to catch violations, they framed it as protection for employees making good-faith decisions in gray areas. The compliance officer held small-group sessions with team leaders to explain why conflicts matter and how disclosure creates a record that protects both the employee and the company. Submission rates doubled within six months.

Third, they changed how they communicated the "why" behind anticorruption requirements. Rather than leading with penalties and legal obligations, the compliance officer worked with regional managers to connect anticorruption standards to business outcomes their teams cared about: fair competition, sustainable partnerships, and reputation protection in markets where corruption creates real competitive disadvantages.

Results and Metrics

The Directive allows member states to give credit for effective compliance programs. While the team can't quantify that credit until an investigation occurs, they can measure whether the program functions in practice.

Third-party due diligence completion rates increased from 64% to 91% after the process redesign. More importantly, the quality of reviews improved. Procurement teams began escalating borderline cases for compliance input rather than approving them to meet deadlines.

Conflict-of-interest disclosures rose from an average of twelve per quarter to forty-seven per quarter. Exit interviews and anonymous feedback indicated the increase reflected greater trust in the system, not an outbreak of conflicts.

Training completion remained above 95%, but post-training assessments showed better retention of core concepts. When asked to identify bribery scenarios, employees scored 23 percentage points higher than before the messaging shift.

What They Would Do Differently

The compliance officer acknowledged waiting too long to involve operational teams in process design. The initial gap analysis and policy updates happened in isolation, which meant the first version of the new third-party approval workflow was technically compliant but operationally impractical. Rebuilding it cost three months.

They also underestimated how much the conflict-of-interest program depended on middle management buy-in. First-line supervisors needed more support explaining to their teams why disclosure mattered and what would happen after someone submitted a conflict. The compliance team assumed managers would intuitively understand this. They didn't.

Finally, they would have pushed back harder on leadership's focus on completion metrics. Training completion rates and policy acknowledgment percentages satisfied auditors but didn't measure whether people understood the underlying principles. Shifting to competency-based assessment earlier would have revealed gaps sooner.

Takeaways for Your Team

AI handles volume, not nuance. Use it to identify which third parties need review, not to decide whether a relationship creates unacceptable risk. Use it to flag policy gaps, not to write policy language that employees will actually follow.

Process design requires understanding how work happens, not just how it should happen according to a control matrix. Involve the people who will use your controls in designing them. Compliance programs fail when they're built in isolation and imposed from above.

Culture change depends on explaining why, not just what. The EU Anticorruption Directive sets penalties of at least 3% of global revenue or €24 million. That's a compelling number for executives. It means nothing to a sales manager deciding whether to approve a distributor's request for an unusual payment structure. That manager needs to understand how corruption undermines fair competition and creates legal exposure for individuals, not just the company.

The Directive will require attention. So will the next regulation, and the one after that. Technology can help you keep pace with the volume of change. It can't create the judgment, trust, and cultural shifts that make compliance programs work in practice. That's still your job.

Application Security Isn’t Optional Anymore.

You Might Also Like