Foire aux questions (FAQ)

EU Anti-Corruption Directive FAQ: Jurisdiction, Liability, and Penalties Explained

Answers to the questions compliance teams and legal counsel are asking about the ACD, grounded in the directive's operative articles

Directive (EU) 2026/1021 on combating corruption, commonly referred to as the EU Anti-Corruption Directive (ACD), was published in the Official Journal of the European Union on 11 May 2026 and entered into force on 31 May 2026. It applies to 26 EU Member States, with Denmark excluded under Protocol No 22 to the TFEU. Member States have until 1 June 2028 to transpose most provisions into national law, with an extended deadline of 1 June 2029 for national strategy obligations.

This Q&A addresses questions raised by compliance professionals, legal practitioners, and organisations seeking to understand the directive’s scope and obligations. All answers are grounded directly in the text of Directive (EU) 2026/1021 and draw on the operative articles and recitals of the directive.

Jurisdiction and Territorial Scope

Q1. Does the ACD apply to EU Member States only, or does it extend to non-EU European countries such as Switzerland, Vatican City, and Norway?

The ACD binds only EU Member States. Non-EU European countries, including Switzerland, Vatican City, Norway, Iceland, and Liechtenstein, fall outside its scope regardless of their geographic location in Europe.

Extraterritorial reach is the more consequential question. Under Article 18(1)(a), the directive applies where the offense was committed in whole or in part on EU territory. A non-EU company whose employees bribe an official in France, for example, falls within scope of French transposing legislation even if the company has no registered presence in the EU.

Additionally, Article 18(2) sets out further optional jurisdictional extensions, including where the offense is committed for the benefit of a legal person established in a Member State’s territory, or where it is committed for the benefit of a legal person in respect of business done in whole or in part on that territory. Member States that adopt these extensions must notify the European Commission.

Note: Denmark is excluded, despite being an EU Member State, under Protocol No 22 to the Treaty on the Functioning of the European Union. Framework Decision 2003/568/JHA continues to apply to Denmark.

Q2. Does the directive have extraterritorial effect, covering US or Latin American companies?

Yes, in defined circumstances. The ACD is not limited to entities with a physical presence in the EU.

Under Article 18(1)(a), jurisdiction is established where the offense was committed in whole or in part on Member State territory. A US or Latin American company is therefore within scope if the corrupt act itself takes place on EU territory, regardless of where the company is headquartered.

Article 18(2) sets out further optional grounds that Member States may adopt, including where the offense is committed for the benefit of a legal person established in their territory, or in respect of business conducted in whole or in part on their territory. These grounds extend the directive’s reach meaningfully beyond physical presence.

Incidental EU connections (trade association membership, conference attendance, or holding a bank account in a Member State) do not on their own create ACD exposure. The connection must be substantive and tied to the corrupt conduct itself.

Q3. Does the ACD require a physical office in the EU, or can any level of business activity trigger it?

No. A physical office is a reliable trigger for ACD jurisdiction, but not the only one. The directive operates through jurisdictional rules tied to where the offense occurs, where the offender is based, and where affected parties are located, rather than through an incorporation or establishment test alone.

Article 18(1) establishes mandatory jurisdiction where the offense was committed in whole or in part on Member State territory, or where the offender is a national of that Member State. Article 18(2) sets out optional extensions that Member States may adopt, covering habitual residence, offenses against a Member State’s nationals or residents, and offenses committed for the benefit of a legal person conducting business in whole or in part on that territory.

For multinationals, exposure should be mapped at the level of where decisions are made, where payments flow, and where counterparties are located, not by registered entities alone. A company with no EU office can still face exposure if an EU-based public official is the subject of a corrupt arrangement.

Q4. What if the offense is committed outside EU territory by a company headquartered in the US but with subsidiaries in EU Member States?

EU subsidiaries alone do not automatically bring a US parent within scope, but they can, depending on which jurisdictional basis applies.

Under Article 18(1), mandatory jurisdiction applies where the offense was committed in whole or in part on EU territory. If the corrupt act itself occurs entirely outside the EU, for instance, a bribe paid in a third country to a third-country official, the mandatory jurisdictional trigger is not engaged simply because the company has EU subsidiaries.

However, Article 18(2)(c) and (d) set out optional extensions available to Member States, covering offenses committed for the benefit of a legal person established in the Member State’s territory, and offenses committed in respect of business conducted in whole or in part on that territory. Where a Member State adopts these extensions and the EU subsidiary benefits from the corrupt conduct, for example, through a commercial gain that flows to it, there is a credible basis for that Member State to assert jurisdiction.

Attribution across group structures is a separate question governed by Article 13. Where a person in a leading position within the legal person committed the offense for the benefit of that legal person, the legal person itself can be held liable. Where the offense was made possible by a failure of supervision or control by such a person, liability under Article 13(2) can also arise.

The practical approach: treat any group structure with EU operations as potentially within scope, and ensure compliance programs cover the full group, not only EU-registered entities.

Q5. We are based in the UK. Do we need to ensure conformance for our UK entities as well as any EU entities, or only EU entities?

The ACD is an EU directive and does not bind UK entities as a matter of EU law. The UK is not an EU Member State, and the directive was adopted after the end of the Brexit transition period.

However, UK entities are not insulated from ACD exposure by their location. Where a UK company commits a corrupt act on EU territory, or for the benefit of an EU-established legal person, or in respect of business conducted in whole or in part in an EU Member State, the relevant Member State may have jurisdiction under Article 18 of the directive, particularly where that Member State has adopted the optional extensions under Article 18(2).

UK entities also remain subject to UK domestic anti-corruption law, principally the Bribery Act 2010, which applies to conduct abroad where there is a UK nexus.

The practical advice is to assess EU-facing operations of UK entities against the ACD’s jurisdictional rules, and not assume that UK incorporation provides a safe harbor for conduct that touches EU territory or EU counterparties.

Q6. Why is Denmark excluded from the ACD?

Denmark is excluded from the ACD under Protocol No 22 to the Treaty on the Functioning of the European Union, which gives Denmark a standing opt-out from EU justice and home affairs measures. This opt-out predates the ACD and applies automatically to directives adopted on the legal basis of Articles 82 and 83 TFEU, which is precisely the basis on which the ACD sits, unless Denmark exercises its right to opt in, which it has not done here.

The exclusion is confirmed in Recital 50 of the directive and the EUR-Lex metadata. Framework Decision 2003/568/JHA continues to be binding upon and applicable to Denmark.

The opt-out originated in Denmark’s 1992 Maastricht Treaty negotiations, following a failed initial referendum. It covers police cooperation and judicial cooperation in criminal matters generally, the broader policy area within which the ACD falls.

Denmark has its own domestic anti-corruption legislation and is a signatory to UNCAC and the OECD Anti-Bribery Convention, so the practical compliance gap is narrower than the formal exclusion might suggest. The ACD’s specific requirements, including the penalty tiers under Article 14(3) and the transposition obligations, do not apply.

Personal and Organisational Scope

Q7. Who is in scope? Does the ACD apply only to large for-profit organizations, or does it cover NPOs and public bodies too?

The ACD’s personal scope is deliberately broad and not limited to large commercial entities.

The directive uses the term ‘legal person’, defined in Article 2(8) as ‘any entity having legal personality under applicable national law, except for States or public bodies in the exercise of State authority and for public international organisations.’ This covers commercial companies of all sizes. There is no turnover threshold or headcount minimum equivalent to instruments such as CSRD.

Non-profit organizations with legal personality are not categorically excluded. The directive’s compliance program provisions under Article 16 are calibrated to the circumstances of each legal person, meaning that an NPO with significant financial flows, public funding, or operations in high-risk environments would be expected to have proportionate controls.

Public bodies acting in the exercise of state authority are excluded from the definition of ‘legal person’ for the purpose of organizational liability. However, public officials, including those employed by public bodies, are firmly within scope as potential perpetrators or recipients of corrupt conduct under Articles 3 to 9.

The compliance program obligations in Article 16 are addressed to legal persons facing liability, not to public administrations as such. Member States are separately required under Article 20 to ensure preventive measures are in place across both public and private sectors.

Note: Transposition will matter at the margins. Member States have some discretion in how they implement the directive, and national legislation may adjust scope in areas such as the treatment of NPOs and semi-public entities.

Q8. What is the definition of ‘company’ under the ACD? Does it include non-listed partnerships within a professional network, rather than a traditional headquarters or subsidiary structure?

The ACD does not use the term ‘company’ as a legal concept. It uses ‘legal person’, defined in Article 2(8) as any entity with legal personality under applicable national law, with two exclusions: states or public bodies acting in the exercise of state authority, and public international organizations.

Whether a partnership falls within scope depends on whether it has legal personality under the law of the relevant Member State. Partnership structures vary significantly across EU jurisdictions. Many continental European forms of partnership carry legal personality and would therefore fall within the definition. Traditional English law general partnerships, which lack separate legal personality, sit in more ambiguous territory at the directive level, though Member States may address this in transposition.

On the network question specifically, the ACD does not require a headquarters or subsidiary relationship to establish scope. Each legally distinct entity within a network is assessed on its own conduct and its own compliance program, not by reference to what a network does centrally.

Attribution is the more complex question for network structures. Under Article 13, where a network shares governance, risk infrastructure, or common leadership, a regulator may look beyond formal legal boundaries when assessing whether a compliance program was genuine rather than merely formal.

For professional services networks, law firm alliances, and similar structures, the practical implication is that each member entity needs a demonstrably independent compliance program, proportionate to its own risk profile, regardless of what exists at network level.

Q9. Can a parent company be prosecuted where an independent subsidiary obtains business through bribery, and the parent benefits when financial results are consolidated?

A parent company can face liability under the ACD where it benefits from a subsidiary’s corrupt conduct or where group-level supervision failures made the offense possible.

Article 13(1) establishes that a legal person can be held liable where a person in a leading position within it, based on a power of representation, authority to take decisions, or authority to exercise control, committed the offense for the benefit of that legal person. The financial consolidation point is directly relevant here: where the parent receives a measurable economic benefit from the subsidiary’s corrupt conduct, there is a credible argument that the offense was committed for the parent’s benefit.

Article 13(2) extends this further. A legal person can also be held liable where a failure of supervision or control by a person in a leading position made possible the commission of the offense by someone under their authority. A parent company that sets risk appetite, approves business plans, or has group-level oversight of the subsidiary’s operations could face exposure on this ground if it is shown that adequate supervision would have detected or prevented the conduct.

Article 13(3) makes clear that liability of the legal person does not preclude parallel criminal proceedings against the natural persons involved.

Recital 27 specifically addresses the use of intermediaries, including related legal persons, to avoid liability, stating that legal persons should not be able to avoid responsibility through such structures.

The compliance implication is significant. Parent companies cannot treat subsidiary conduct as legally ring-fenced where group-level benefit or group-level oversight failure can be demonstrated.

Key Definitions

Q10. What is the definition of ‘turnover’ for the purpose of the ACD’s penalty framework?

The ACD does not contain a standalone definition of turnover, but the term carries a specific meaning within the penalty framework set out in Article 14(3).

Article 14(3) refers to ‘the total worldwide turnover of the legal person, either in the business year preceding that in which the offense was committed, or in the business year preceding that of the decision to impose the fine.’ The reference to worldwide and total turnover means gross revenue across all operations and jurisdictions, the top line of the income statement before deductions for costs or taxes, rather than turnover of a particular division or the entity within which the offense occurred.

This is consistent with how turnover is used across other EU regulatory instruments, including GDPR and the EU AI Act, where it functions as a proxy for overall organizational scale.

For groups, the question of whether the relevant turnover is that of the subsidiary committing the offense or of the consolidated group is not resolved on the face of the directive. Member States have discretion in transposition on this point, and national implementing legislation may address it differently. Where group-level consolidated turnover is used as the reference base, exposure for large multinationals can be substantially higher than a subsidiary-level calculation would suggest.

For financial services entities, turnover is conventionally calculated as net interest income plus fee and commission income. For insurance entities, it is typically gross premiums written. The directive does not specify these adaptations, and Member States may address them in transposition.

The fixed alternative maxima of EUR 40 million (Articles 3 to 5 offenses) and EUR 24 million (Articles 6, 8, and 9 offenses) serve as a floor ensuring meaningful minimum exposure for smaller entities where the percentage calculation produces a lower figure.

Q11. Will Member States be permitted to set their own definitions for terms such as ‘undue advantage’?

The ACD establishes minimum harmonisation, not full harmonisation. Article 1 states explicitly that the directive sets minimum rules. Member States are free, under Article 3 of the directive’s recitals, to adopt or maintain more stringent rules. They are not permitted to set lower standards.

On ‘undue advantage’ specifically: the directive uses the term throughout Articles 3 to 6 without providing a comprehensive definition. Recital 13 offers guidance, noting that an advantage is not considered undue where it is permitted by law or by administrative rules, or in cases of minimum gifts or gifts of very low value. Beyond that, the content of the term is largely left to national implementation.

This creates real scope for definitional divergence across Member States. A gift or hospitality arrangement that falls within a permitted threshold in one jurisdiction may constitute an undue advantage in another. Organizations operating across multiple EU jurisdictions will need to apply the most restrictive applicable standard to their policies, rather than assuming a single EU-wide threshold.

Other terms, including ‘breach of duty’ under Article 4 on private sector bribery, and ‘serious violations of law’ under Article 7 on unlawful exercise of public functions, are similarly left to national elaboration, with Article 7 expressly permitting Member States to limit its application to certain categories of public officials.

The first wave of national transposing legislation, due by 1 June 2028 for most provisions, will be the key moment for organizations to audit definitional variations across their operating jurisdictions.

Compliance Programs and Penalties

Q12. Does having a compliance program provide a complete defense under the ACD?

No. Article 16 positions compliance programs as a mitigating circumstance, not a defense to liability.

Under Article 16(c), where a legal person has implemented effective internal controls, ethics awareness, and compliance programs to prevent corruption, either prior to or after the commission of the offense, this can be considered as a mitigating circumstance when sentencing. Article 16(d) separately provides for mitigation where a legal person, once the offense is discovered, rapidly and voluntarily discloses it and takes remedial measures.

The word ‘effective’ carries significant weight. Recital 29 explicitly flags the risk of compliance programs that exist ‘only for cosmetic purposes, also called window dressing’, stating that this factor may be taken into account when determining the penalty. A compliance program that is not operationally embedded, not subject to genuine assessment, and not capable of detecting or deterring actual conduct will not attract meaningful mitigation.

The distinction from some other jurisdictions, notably the UK Bribery Act’s ‘adequate procedures’ defense, is material. Under the ACD, there is no provision by which demonstrating a compliance program eliminates liability. It affects the sentence, not the underlying finding.

Article 16 also makes clear that the mitigating circumstances in points (c) and (d) are applicable only to legal persons, not to natural persons.

Q13. What are the penalty levels for legal persons under the ACD?

For the most serious offenses, fines can reach 5% of total worldwide annual turnover or €40 million — whichever is higher. Article 14(3) establishes two tiers:

For offenses under Articles 3 to 5 (bribery in the public sector, bribery in the private sector, and misappropriation): the maximum fine must be at least 5% of the legal person’s total worldwide turnover in the relevant year, or alternatively, EUR 40 million, whichever is higher.

For offenses under Articles 6, 8, and 9 (trading in influence, obstruction of justice, and enrichment from corruption offenses): the maximum fine must be at least 3% of total worldwide turnover in the relevant year, or alternatively, EUR 24 million.

These are minimum maxima. Member States may set higher ceilings in their national transposing legislation.

Beyond fines, Article 14(2) sets out a range of additional criminal and non-criminal penalties and measures available to Member States, including exclusion from public procurement, temporary or permanent disqualification from business activities, judicial winding-up, and closure of establishments. These measures are available in addition to, or instead of, financial penalties, depending on national implementing choices.

Note: The fine thresholds apply specifically to liability under Article 13(1). Article 14(1) and (2) also address liability under Article 13(2) — failure of supervision — which is subject to effective, proportionate, and dissuasive penalties but without the specified percentage floors.

Comparative and US Context

Q14. Does the US have updated regulations comparable to the ACD and GDPR?

The US has no direct federal equivalent to the ACD. The primary US instrument remains the Foreign Corrupt Practices Act (FCPA) of 1977, which prohibits bribery of foreign government officials by US companies and persons, and by foreign companies listed on US exchanges. The FCPA is enforced jointly by the Department of Justice and the Securities and Exchange Commission.

The FCPA and the ACD share the objective of combating bribery but differ in several important respects. The FCPA focuses on bribery of foreign public officials; the ACD covers a broader range of offenses, including private sector bribery, trading in influence, misappropriation, obstruction of justice, and enrichment from corruption offenses. The ACD also introduces harmonized compliance program provisions and specific penalty structures across 26 Member States. The FCPA is enforced through prosecutorial discretion and deferred prosecution agreements rather than a harmonized regulatory framework.

At the state level, various US jurisdictions have their own anti-corruption statutes, though these vary significantly and do not constitute a coherent federal framework.

On the GDPR comparison: the US does not have a federal equivalent to GDPR. Several states, including California (CCPA/CPRA), Virginia, Colorado, and Connecticut, have enacted comprehensive consumer privacy legislation, but there is no single federal data protection law of comparable scope or enforcement architecture.

Organizations operating across the US and EU, therefore, face genuinely different regulatory frameworks on both counts, requiring jurisdiction-specific compliance programs rather than a single unified approach.

En savoir plus

This document was prepared by Mitratech’s GRC Solutions Strategy team. It reflects the text of Directive (EU) 2026/1021 as published in the Official Journal of the European Union on 11 May 2026. It is intended for informational purposes only and does not constitute legal advice. Organisations should seek qualified legal counsel in the relevant Member State jurisdictions when assessing their specific obligations under the directive and its national implementing legislation.