Most multinational anti-corruption programs were built around a single reference point for a decade: the U.S. Foreign Corrupt Practices Act (FCPA). That reference point shifted twice within the same year. In June 2025, the Department of Justice narrowed FCPA enforcement toward cartels and transnational crime, stepping back from broad foreign bribery cases.
Twelve months later, as an attempt to step up and take the lead, the EU Anti-Corruption Directive (ACD) entered into force and moved in the opposite direction, widening the definition of corruption offenses, extending jurisdiction beyond the bloc’s borders, and raising corporate fines to a share of global turnover.
Neither shift got the attention it deserved on its own. Read together, they change what a defensible compliance program looks like for any company doing business with Europe, whether or not it books a single euro of European revenue.
Directive (EU) 2026/1021 was published in the Official Journal of the European Union on May 11, 2026, and entered into force twenty days later, on May 31, 2026. It creates a harmonized minimum criminal law framework across the EU Member States, except for Denmark, consolidating and substantially replacing earlier instruments and raising the floor on corporate liability, jurisdictional reach and financial exposure.
Member States have until June 1, 2028, to transpose core provisions into national law. Some Member States will legislate well before it, because their existing regime already falls well short of what the Directive requires. Others, going by how long transposition has historically taken on comparable EU criminal law instruments, will probably use most of the runway available to them.
None of this binds a company directly today. As a directive, it only takes legal effect once each Member State enacts its own implementing statute, and because it sets a floor rather than a fixed rule, national laws are free to go further. A company operating across the bloc should expect twenty-six different timelines and, eventually, twenty-six variations on the same minimum standard, not one EU law that arrives on a single date.
In This Article
- How Far the EU Anti-Corruption Directive's Jurisdictional Reach Goes
- How the EU Anti-Corruption Directive Expands Corporate Liability
- What the EU Anti-Corruption Directive Fines Require in Practice
- When FCPA Enforcement Weakens, EU Anti-Corruption Directive Risk Does Not
- The Intermediary Risk That Most Compliance Programs Miss
- What EU Anti-Corruption Directive Compliance Defense Requires in Practice
- Why EU Anti-Corruption Directive Preparation Cannot Wait Until 2028
- Preguntas frecuentes
How Far the EU Anti-Corruption Directive’s Jurisdictional Reach Goes
The EU Anti-Corruption Directive extends jurisdictional reach well beyond physical presence in the EU. Under Article 18, every Member State must establish jurisdiction where the offense is committed, in whole or in part, on its territory, or where the offender is one of its nationals. Recital 33 adds that this territorial jurisdiction also covers offenses committed through information systems used in a Member State, whether or not the underlying technology sits there physically.
The part of Article 18 that gets the most attention, and deserves the most scrutiny, is paragraph 2. It lets a Member State extend jurisdiction to conduct outside its territory where the offense benefits a company established there or is connected to business done there in whole or in part. That ground, it is worth noting, is optional. The text says a Member State “may” extend jurisdiction that far and simply must notify the Commission if it does.
Nothing in the ACD requires all twenty-six participating states to reach for it, and nothing in the Directive tells you which ones will. A company headquartered in Brazil or the United States, with no subsidiary on European soil, can fall within that reach if the relevant Member State chooses to claim it. Whether any particular Member State makes that choice, and how aggressively it acts on it once made, is a separate question this text does not answer.
Here is the clear view of the jurisdictional risk: it is real, it is broader than physical presence, and it is also uneven and, for now, largely unwritten. For companies with European customers, cross-border joint ventures, or supply chains routed through EU financial systems, the sensible response is not a blanket assumption that every EU country now has a claim on your conduct. It is a jurisdiction-by-jurisdiction read of where you have exposure, and where enforcement infrastructure is developed enough that the exposure is more than theoretical.
How the EU Anti-Corruption Directive Expands Corporate Liability
The ACD establishes two distinct grounds for corporate criminal liability under Article 13. The first holds companies liable for corruption committed by persons in leading positions on their behalf. The second lets Member States hold a company liable where a failure to supervise or control by a person in a leading position made a corruption offense possible for the company’s benefit, even when that person did not commit the offense themselves.
Earlier anti-corruption frameworks, including the U.S. Foreign Corrupt Practices Act and Brazil’s Clean Company Act (Federal Law No. 12,846/2013), have generally held companies liable for the acts of individuals who committed corruption on their behalf. The ACD keeps that logic in place, then adds the supervisory ground on top of it.
The impact of this second ground for liability varies by jurisdiction. Some Member States already have regimes similar to failure-to-prevent standards, while others, such as Germany, do not and will require legislative changes. The key point is that new exposure arises in some jurisdictions, while in others it is already addressed. Treating the entire EU as having the same level of change misrepresents the actual risk.
A “leading position” under Article 13 includes anyone authorized to represent the company, make decisions, or exercise control, extending beyond the C-suite to all with significant authority. For companies that have allowed compliance programs to atrophy, or that have built programs primarily for appearance rather than operation, the supervisory failure standard creates exposure of a kind prior frameworks did not impose.
What the EU Anti-Corruption Directive Fines Require in Practice
For core offenses, the Directive requires Member States to set maximum fines for legal persons at no less than 5% of total worldwide turnover or €40 million, whichever is higher. For secondary offenses, including trading in influence and obstruction of justice, the floor is 3% of worldwide turnover or €24 million. Both figures are calculated on global revenue, not on EU operations alone.
Whether that ceiling is ever applied to a given company is a different question, and the ACD itself is candid about why it might not be. Article 23 requires Member States to ensure that the bodies handling corruption prevention and enforcement have an adequate number of qualified staff and the financial, technical and technological resources their job requires, an obligation that would not be worth writing into the text if that capacity already existed everywhere. It does not. Enforcement of corporate corruption offenses across the EU has historically concentrated in a handful of jurisdictions with active, well-resourced financial crime prosecutors, while other Member States have gone years without bringing a comparable case. A higher statutory ceiling does not, on its own, change who is staffed to bring it.
In addition to fines, the Directive permits Member States to impose sanctions such as exclusion from public procurement, withdrawal of permits and licenses, judicial supervision, and closure of EU establishments. These consequences are significant because they require less prosecutorial effort than imposing a full corporate fine. For many companies, procurement exclusion is a more immediate risk than the maximum fine.
The Directive provides a path to mitigation, but its requirements are specific. Article 16 allows Member States to consider effective internal controls, ethics awareness, and compliance programs as mitigating factors. Recital 29 clarifies that the program must be genuine, effective, and duly assessed. Programs that exist only for appearance do not qualify for mitigation.
Recital 29 and Article 15 make clear that window dressing does not qualify as mitigation and, importantly, it is not formally treated as an aggravating factor at sentencing, which corrects an overstatement in some earlier summaries of this Directive. Judges have discretion to determine whether a program meets the standard, so thorough documentation is more important than simply having policies in place.
What changes under the Directive is not the size of the fine on paper; it is the cost of failing to prove, with real documentation and in advance, that the compliance program worked.
Is Your Compliance Program Built for the Standard That Counts?
Discover More NowWhen FCPA Enforcement Weakens, EU Anti-Corruption Directive Risk Does Not
When the DOJ narrowed its FCPA enforcement focus in June 2025, many compliance teams read the move as a broader retreat from cross-border anti-corruption enforcement, and some read the EU Anti-Corruption Directive as the automatic answer to that retreat. Neither reading survives close inspection.
As A&O Shearman has analyzed, the ACD reduces cross-border enforcement friction on paper: harmonized definitions make it easier for authorities in different Member States to cooperate on the same conduct. Whether that translates into more enforcement, sooner, against companies that assumed a US pullback meant less scrutiny across the board, is a separate question this Directive cannot settle by itself.
It depends on which Member State ends up with jurisdiction over a given piece of conduct, whether that Member State’s prosecutors and courts are already active in financial crime work, and whether the political appetite to pursue a foreign company over conduct committed abroad exists once the statute is on the books. Some Member States have functioning financial crime prosecution infrastructure and a track record with complex cross-border cases. Several others do not, and building that capacity from where it stands today, which is exactly what Article 23 obliges them to do, will take longer than transposing the text of the Directive itself.
The Blanche Memo, issued in June 2025, reflected a deliberate narrowing of U.S. foreign bribery enforcement and framed prior FCPA activity as having put American companies at a disadvantage abroad. In practice, the memo created a perception, widely repeated in compliance circles, that international anti-corruption enforcement was retreating across the board. The reading goes too far in both directions. The U.S. narrowed FCPA enforcement specifically. It did not lose the ability to act through other statutes, and Europe’s capacity to fill the gap left behind is, right now, more a matter of law in the books than of cases in court.
None of that makes the comparison to other frameworks less useful; it just changes what the comparison is for. A strong Clean Company Act program, on its own, does not satisfy the EU’s approach to compliance mitigation, regardless of how quickly EU enforcement ramps up. The two frameworks share important principles, including corporate liability, compliance as a mitigating factor, and risk-based program design. They diverge on points that require deliberate mapping.
The Directive’s supervisory failure standard reaches further than what Brazilian law requires, and the evidentiary bar for program effectiveness, at least as Reed Smith reads it, is higher too: internal reviews, third-party audits and board-level oversight need to be documented, not just in place. On self-disclosure the frameworks part ways as well. Under the Directive, voluntary disclosure is a mitigating circumstance, but it does not produce the declination pathway that current U.S. DOJ policy offers. And the range of offenses the Directive covers, trading in influence in particular, is wider than the FCPA’s.
Treating the two frameworks as equivalent is a mistake regardless of how quickly EU enforcement materializes. Mapping where they diverge is the part of this exercise with a fixed answer today. Guessing at enforcement timing is not, and a compliance program built on that guess is building on the wrong foundation.
The Intermediary Risk That Most Compliance Programs Miss
Companies that have invested most heavily in FCPA-aligned due diligence may, somewhat counterintuitively, face the sharpest gaps under the Directive, precisely because the EU framework reaches conduct the FCPA does not. Article 6 criminalizes trading in influence, the exchange of an undue advantage to improperly influence a public official’s decisions, and the ACD is explicit that it is irrelevant whether the influence was exerted or whether it produced the intended result. The exchange itself is the offense.
In the cross-border advisory work I do regularly, the most exposed relationships tend to be the ones that feel most familiar: the consultant who has always opened the right doors, the advisor who understands how decisions get made in a given market. These relationships are not automatically illegal. But under the Directive’s trading-in-influence standard, they carry a category of legal risk that most current frameworks were not built to identify.
The third-party risk management frameworks most companies operate today were built around the FCPA’s narrower transactional bribery standard. Under the Directive’s trading-in-influence offense, the analysis has to go broader and the documentation requirements get more demanding, not because a regulator is about to knock, but because the legal theory that would apply if one did is different from the one most due diligence checklists were designed against.
Companies should approach this as a substantive review, not a minor update to due diligence procedures. Assess which intermediary relationships now present new risks under the ACD and whether existing controls are adequate for those risks. Most of these intermediary relationships have never been reviewed under a trading-in-influence standard.
What EU Anti-Corruption Directive Compliance Defense Requires in Practice
Recital 29 says a compliance program that is genuine, effective and duly assessed can reduce penalties at sentencing, filling out the mitigating circumstance Article 16 already provides for. It does not say what those three words mean in any operational sense, and neither the Directive nor its recitals define them with precision. The ambiguity cuts both ways. It gives a court room to credit a program that does not match a checklist, and it gives a court just as much room to decide whether a program falls short even when the company thought it had done enough.
Reed Smith’s read of the framework, that internal reviews, third-party audits and board-level oversight need to be documented rather than merely operative, is a reasonable inference from the text. It is not a guarantee the text itself provides. There is no case law yet interpreting these three words, because the Directive has been in force for a matter of weeks and no Member State has transposed it. Anyone describing precisely what a court will accept in 2029 is speculating, including client alerts that state it with more confidence than the current record supports, and that includes commentary I have written myself.
What is not speculative is the floor. A program that exists only on paper will not qualify under any plausible reading, and Recital 29 says so directly: window dressing does not count. Beyond that floor, a plain reading of the three words still points somewhere useful.
Genuine suggests the program must function day to day, not exist as a set of policies filed away and rarely revisited. Effective suggests its controls, training and oversight have to produce some observable change in behavior, not just a complete checklist. Duly assessed suggests someone must have reviewed the program on a schedule and recorded what they found, through internal reviews, third-party audits, or board minutes, rather than assuming it works because no one has complained.
None of this is invented from scratch. The three-word test in Recital 29 sits inside a longer lineage, the OECD’s Good Practice Guidance on Internal Controls, Ethics and Compliance, first annexed to its 2009 Recommendation and updated in 2021, which already described the criteria that have since become the global default, among them senior management commitment, a documented risk assessment, third-party due diligence, financial controls, a working speak-up channel, and periodic review.
Brazil’s Decree No. 11,129/2022 and the UK Bribery Act’s adequate procedures defense draw on the same source. The OECD Working Group on Bribery’s peer review reports, publicly available and country-specific, are also the most defensible evidence for the enforcement variation described earlier in this piece: they document, country by country, which Member States have prosecuted foreign bribery and which have gone years without a case.
There is no guarantee a court will find a program genuine. However, maintaining thorough documentation is the most defensible position if questioned by regulators or judges. Most current programs were designed for FCPA-style risks and may not meet the Directive’s broader requirements. Importantly, documentation built after an incident only shows the company’s response, not that the program was effective beforehand, which is what Article 16 requires.
The documentation trail matters as much as the program itself. In any enforcement proceeding, the question will not be whether a compliance program exists. It will be whether there is evidence it worked and whether that evidence was built before the problem arose.
Why EU Anti-Corruption Directive Preparation Cannot Wait Until 2028
Member States have until June 1, 2028, to transpose the Directive into national law, but some may act earlier, especially where current regimes fall short. The Directive’s preventive obligations, including national strategies and corruption risk assessments under Article 20(5) and Article 21, have a 36-month implementation period, reflecting the time needed to build institutional capacity beyond passing legislation.
A wave of enforcement is unlikely in 2026 or 2027, as no Member State has implemented national laws yet. Building the necessary documentation, such as training logs, risk registers, and audited third-party files, takes years. The practical reason to start now is to ensure the record is built prospectively, as two years is a realistic timeframe to establish credible documentation, not a period to wait for case law.
GRC expert Jan Stappers recommends compliance leaders begin with a gap analysis of new corporate liability grounds, a review of intermediary relationships under the trading-in-influence standard, and an assessment of existing documentation versus likely court expectations. This work is time-consuming, especially for multi-jurisdictional organizations, and should not be left until just before the transposition deadline, which may not be the most relevant date for your company.
The Directive has set the standard. The question is not whether your program will be tested against it. The question is whether your record was built before that test began. Building it now, before an incident, before enforcement, and before a court has to decide whether what you have qualifies, is the only way to put that answer out of doubt.
Don’t Let a Good Program Become a Paper Defense
Discover More Now
Meeting the EU Anti-Corruption Directive’s compliance mitigation standard requires more than intent; it demands a documented, forward-looking record that the program is genuine, effective, and regularly evaluated, something most current programs lack. The Mitratech Global GRC platform provides the infrastructure to build and maintain this record, offering centralized policy management, third-party risk workflows with audit trails, training and certification tracking, investigation case management, and board-level reporting in one platform. For companies evaluating their programs against the ACD or building the necessary documentation, Mitratech delivers scalable, cross-jurisdictional solutions. Learn more about the Mitratech Global GRC Platform.
