The EU's anti-corruption directive took effect on May 31, and most compliance teams are getting it wrong. Not because they're ignoring it, they're just repeating the same implementation errors that plagued GDPR rollouts and NIS2 preparations. You're likely making at least two of these mistakes right now.
Why These Mistakes Keep Happening
Compliance teams often treat new directives as checkbox exercises. You map requirements to existing controls, update a policy document, and call it done. However, the directive's focus on enforcement gaps and cross-border cooperation means your existing anti-bribery framework probably doesn't cover what regulators actually care about. The gaps aren't in your policies, they're in how you operationalize them across jurisdictions and business units.
Mistake 1: Treating This as an Anti-Bribery Policy Update
Why it happens: You already have FCPA or UK Bribery Act controls in place. Your team assumes the EU directive is just another regional variant requiring minor policy tweaks.
The consequence: You miss the directive's enforcement mechanism changes entirely. Regulators can now coordinate investigations across member states, share evidence more freely, and pursue cases that previously fell through jurisdictional cracks. Your controls might satisfy the letter of previous requirements while completely failing the new enforcement reality.
The fix: Map your current controls against cross-border investigation scenarios. If you operate in multiple EU states, document which entity owns corruption risk in each jurisdiction and how evidence would flow during a coordinated investigation. Your legal team needs a playbook for multi-state regulatory inquiries, not just single-jurisdiction responses. Update your incident response procedures to account for parallel investigations in multiple member states.
Mistake 2: Assuming Your Third-Party Due Diligence Is Sufficient
Why it happens: You run vendor risk assessments that include anti-corruption questions. You think you're covered because you have contracts with anti-bribery clauses.
The consequence: The directive's cross-border cooperation provisions mean regulators can now trace corruption through your vendor relationships across EU borders more effectively. If a vendor in one member state is involved in corrupt practices, investigators can follow that thread to your operations in another state. Your due diligence questionnaire won't protect you if you can't demonstrate ongoing monitoring of cross-border vendor activities.
The fix: Implement ongoing vendor monitoring that specifically tracks cross-border transactions and relationships. For vendors operating in multiple EU states, document their corruption risk profile in each jurisdiction. Don't rely on annual reviews, set up alerts for regulatory actions, sanctions listings, and enforcement actions against your vendors in any EU member state. Your vendor risk profile should include a cross-border risk indicator that triggers enhanced monitoring.
Mistake 3: Siloing Compliance by Business Unit
Why it happens: Your compliance program is organized around your corporate structure. Each regional team handles its own anti-corruption obligations.
The consequence: The directive's enforcement coordination mechanism means regulators don't care about your org chart. They'll connect dots across your business units that you've never connected yourself. When an investigation spans multiple entities, you'll scramble to aggregate information that should have been centralized from the start.
The fix: Create a cross-border corruption risk universe that maps risks across all EU operations, regardless of business unit boundaries. Implement a single policy exception registry for corruption-related exceptions across all entities. If you allow any deviation from standard anti-corruption procedures, different gift limits, different approval thresholds, different due diligence requirements, you need visibility into all of them simultaneously. During your next policy gap analysis, evaluate consistency across jurisdictions, not just compliance within each one.
Mistake 4: Ignoring the Data Flow Implications
Why it happens: You're focused on corruption controls, not data governance. You assume your existing data handling procedures are adequate.
The consequence: Cross-border cooperation means evidence sharing. If regulators in one member state request documentation about activities in another, you need to produce it quickly, and legally. Your data processing register probably doesn't account for regulatory investigations as a lawful basis for cross-border data transfers. You'll face conflicting obligations: cooperate with investigators while respecting data protection requirements.
The fix: Update your data processing register to document how you'll handle cross-border evidence requests under the directive. Work with your DPO to establish procedures for sharing employee and vendor data across borders during investigations. Document your lawful basis for processing personal data in corruption investigations. Create retention schedules that balance investigation needs with data minimization principles. Consider a scenario: if French regulators request employee communications about a vendor relationship managed from your German office, what's your legal pathway for producing those records?
Mistake 5: Underestimating the Whistleblower Hotline Connection
Why it happens: You implemented whistleblower protections to comply with the EU Whistleblowing Directive. You treat corruption reporting as a separate workstream.
The consequence: The anti-corruption directive's enforcement mechanisms rely heavily on insider information. Regulators expect robust whistleblower channels that specifically address corruption. If your whistleblower hotline doesn't explicitly cover corruption scenarios, or if your retaliation protection procedures don't account for cross-border reporting (an employee in one member state reporting conduct in another), you're creating enforcement exposure.
The fix: Review your whistleblower hotline procedures against corruption-specific scenarios. Ensure your retaliation protection extends to cross-border situations. Document how you'll investigate corruption allegations that span multiple jurisdictions. Train your investigation team on the directive's enforcement provisions, they need to understand that their findings might feed directly into multi-state regulatory actions. Update your remediation of deficiencies procedures to account for corruption findings that require coordinated fixes across entities.
Prevention Checklist
Before you close your directive implementation project, verify:
- Cross-border investigation playbook exists and legal team has practiced it
- Vendor risk profiles include jurisdiction-specific corruption indicators
- Ongoing vendor monitoring covers all EU member states where vendors operate
- Single corruption risk universe spans all business units and entities
- Policy exception registry consolidates all anti-corruption deviations
- Data processing register documents cross-border evidence sharing procedures
- DPO has approved procedures for investigation-related data transfers
- Whistleblower hotline explicitly addresses corruption scenarios
- Retaliation protection procedures cover cross-border reporting
- Investigation team understands directive's enforcement coordination mechanisms
- Incident response procedures account for parallel multi-state investigations
The directive's enforcement provisions are already active. If you're treating this as a policy update project, you're building controls for yesterday's enforcement environment. The question isn't whether your policies mention corruption, it's whether your operational procedures can withstand a coordinated cross-border investigation that starts tomorrow.





