The EU’s Anti-Corruption Directive: a new pillar of global anti-corruption enforcement
Ennio Alagia
Chiomenti, Milan
ennio.alagia@chiomenti.net
Corruption remains one of the most corrosive threats to democratic institutions, economic fairness and the rule of law, undermining public trust, distorting competition, enabling organised crime and jeopardising development. Despite these well-understood harms, the European Union’s legal framework has until now rested on ageing and incomplete instruments, notably Council Framework Decision 2003/568/JHA and the 1997 Convention on corruption involving EU officials, which have failed to keep pace with the transnational nature of modern corruption. Enforcement gaps and divergent national frameworks have long hindered coherent cross-border cooperation.
That landscape has now fundamentally changed. On 21 April 2026, the Council of the European Union gave its final approval to Directive (EU) 2026/1021, otherwise known as the Anti-Corruption Directive, completing the EU’s first comprehensive and binding criminal law framework to address corruption across all of the EU’s Member States.
For the international legal community, this Directive marks a paradigm shift, determining the emergence of a third major anti-corruption pillar, alongside the United States Foreign Corrupt Practices Act (FCPA) and the United Kingdom’s Bribery Act 2010 (UKBA). For businesses operating across the EU, the practical consequences are significant: turnover-based corporate fines, a dual-track liability model and a framework that treats corporate cooperation as a structured incentive, whose value will depend entirely on whether companies choose to engage with the system the Directive creates.
The turnover-based penalty regime: a structural shift
The most immediately striking feature of the Directive is its sanctioning architecture for legal persons.
Article 14 introduces a tiered, turnover-based penalty structure, calibrated according to the severity of the offence. For the most serious offences, namely public and private sector bribery and misappropriation, Member States must ensure maximum fines are imposed of no less than five per cent of a company’s total worldwide annual turnover or, alternatively, a fixed amount corresponding to €40m. For trading in influence, the obstruction of justice and enrichment from corruption, the monetary penalty threshold is set at three per cent of worldwide turnover or €24m.
This brings EU corporate anti-corruption fines closer in scale to those seen under the US FCPA and the UKBA and reflects the sanctioning methodology already employed under the EU’s General Data Protection Regulation (GDPR) and Directive (EU) 1226/2026 on the criminalisation of violations of EU restrictive measures.
The global turnover approach aims to prevent companies from using intermediaries, including related legal persons, to shield themselves from meaningful financial consequences. These amounts are not merely theoretical. The EU has consistently relied on substantial turnover-based financial penalties as an enforcement mechanism under several regulatory frameworks. In areas such as competition law and data protection, fines amounting to hundreds of millions of euros have become commonplace. Against this backdrop, a similarly robust enforcement approach can reasonably be expected in relation to corruption offences following the Directive’s transposition deadline of June 2028.
Beyond fines, the Directive authorises a sweeping range of additional corporate sanctions, including exclusion from public tenders, grants and licences; temporary or permanent disqualification from business activities; withdrawal of permits; contract annulment; placement under judicial supervision; judicial winding-up; and the closure of establishments used to commit the offence. For companies operating in regulated industries or relying on public procurement, the consequences of a conviction may extend well beyond the imposition of a financial penalty, potentially jeopardising their ability to continue conducting business. Moreover, the publication of judicial decisions, subject to applicable privacy safeguards, introduces a significant reputational dimension that reinforces the Directive’s deterrent effect.
Corporate liability: the dual-track model
The Directive’s corporate liability framework, established under Article 13, provides for two distinct routes to liability. The first, primary liability, holds a legal person liable where an offence is committed for the company’s benefit by someone in a ‘leading position’, defined as a person with the power of representation, decision-making authority on behalf of the legal person or control. The second track extends liability where a lack of supervision or control by a person in a leading position has made possible the commission of an offence by a person under the entity’s authority. Corporate and individual liability coexist and may be pursued in parallel.
A comparison with the UKBA is instructive. Section 7 of the UKBA creates a strict liability offence of ‘failure to prevent bribery’ by any ‘associated person’, a category potentially broad enough to capture employees, agents, subsidiaries, joint-venture partners and third-party intermediaries. The trade-off for this breadth is a statutory defence: a company escapes liability if it can prove it had ‘adequate procedures’ in place to prevent bribery, making the quality of the compliance programme the determinative question. The EU Directive takes a different path on both fronts. It does not create a failure-to-prevent offence and it does not offer compliance as a defence to liability. Its corporate liability trigger also differs in terms of personal scope: Article 13 operates through the conduct of persons in a leading position, or of a subordinate, where a leading person’s lack of supervision or control made the offence possible, provided in each case that the offence was committed for the entity’s benefit, rather than through the diffuse network of ‘associated persons’ that the UKBA captures.
It may be argued that a model of corporate liability predicated on the offender’s leading position within the organisation reflects a more traditional approach, particularly in light of the growing prominence of alternative frameworks that focus on the organisation’s own conduct. According to these models, liability is grounded on organisational deficiencies, such as failures in governance, supervision or the implementation of adequate compliance mechanisms, rather than solely on the status of the individual perpetrator. Jurisdictions including Italy, Spain, the Czech Republic, Austria and Poland have adopted variations of this organisational liability model.
Where the UKBA allows compliance to operate as a complete defence to liability, the EU Directive locates it at a different stage. Article 16 introduces a structured set of mitigating circumstances that, while they cannot exclude liability, play a central role in shaping the incentive framework governing corporate conduct. Three elements are particularly significant. First, where a legal person has implemented effective internal controls, ethics awareness and compliance programmes to prevent corruption, whether adopted before or after the offence, this may be regarded as a mitigating circumstance. ‘Post-offence’ recognition is particularly significant, as it implies that a company’s subsequent response, including the conduct of internal investigations and its level of cooperation with the competent authorities, will be taken into account as a mitigating factor during the determination of fines. Second, swift voluntary disclosure of an offence by a legal person upon discovery, accompanied by remedial measures, is similarly mitigating. Third, where offenders provide the competent authorities with information they would not otherwise have been able to obtain, helping to identify other offenders or uncover evidence, this too constitutes a mitigating factor.
The Directive’s recitals make clear, however, that these provisions are not invitations for cosmetic gestures. Compliance programmes maintained only for formal purposes, ‘window dressing’ as per the Directive’s own terminology, will not qualify for mitigation. Sentencing courts retain discretion to evaluate whether a compliance programme is genuinely effective in practice, as opposed to being merely formally established. Accordingly, companies will be required to show not only that such a programme exists in documentary form, but also that it is meaningfully implemented, subject to ongoing review and effective in operational terms.
Importantly, the Directive preserves Member States’ discretion to adopt more far-reaching approaches. The compliance programmes' mitigating circumstances apply ‘unless it constitutes a ground for exclusion of liability’ under national law. This formulation accommodates jurisdictions such as Italy, where an effectively implemented compliance model under Legislative Decree No 231/2001 may operate to exclude corporate liability altogether. Thus, the resulting structure is layered: the Directive establishes a minimum standard, recognition of effective compliance as a mitigating factor, while permitting Member States to develop more extensive incentive mechanisms, including full defences, beyond that baseline.
The absence of harmonised rules on negotiated resolutions, including deferred prosecution agreements, introduces an additional layer of complexity. Unlike the US and the UK where deferred prosecution agreements have become a central feature of anti-corruption enforcement, the Directive does not establish a uniform framework for non-trial resolutions, instead leaving Member States free to develop their own mechanisms or refrain from doing so altogether. This omission is significant, as the practical effectiveness of cooperation incentives depends in large part on the existence of procedural avenues through which such cooperation can yield concrete benefits that fall short of a full trial and conviction.
Transposition as a catalyst: aligning with the OECD Anti-Bribery Convention
Recital 4 of the Directive expressly acknowledges that Union action ‘should take into account the work of’ the OECD, among other international bodies. This is more than a formal reference; it reflects an alignment with established international monitoring processes. Over successive rounds of evaluation, the OECD Working Group on Bribery has produced a detailed account of structural weaknesses in Member States’ anti-corruption frameworks. Against this background, the transposition deadline of June 2028 functions less as an isolated legislative milestone and more as a catalyst for implementation, as measures long recommended at the international level will, for the first time in many instances, acquire binding force under EU law.
First, as previously mentioned, in terms of pecuniary sanctions against legal persons, which the OECD has persistently found inadequate across the board. In Italy, fines against legal persons for corruption offences range between around €25,000 and €1.2m, which the Working Group has repeatedly found to be unfit for purpose since 2011. Belgium’s new Penal Code, which entered into force in April 2026, paradoxically reduces fines for legal persons to a maximum of approximately €1.4m in the most serious cases, a level the OECD considers fall ‘well short’ of its requirements. Fines against legal persons in Poland have also been deemed not to be sufficiently effective, proportionate and dissuasive, as is the case in Estonia, where the maximum applicable sanctions for larger bribery cases are considered by the OECD to be inadequate.
Second, the OECD Working Group has found that the standard for triggering corporate liability due to failures of supervision remains unclear or excessively restrictive across multiple jurisdictions. While Belgian law still does not clearly specify the authority level of the natural person whose conduct may trigger the liability of a legal person, the parliamentary work conducted in 1999 suggests that the involvement of management bodies is required. However, a lack of supervision by management leading to the commission of the offence by a lower-level employee does not trigger the liability of a legal person. In Spain, prosecutors interpret the ‘serious breach’ standard required to trigger corporate liability as requiring intent or gross negligence of a natural person, excluding organisational defects, such as the absence of a compliance programme. Article 13 of the Directive clearly establishes that a legal person is liable where the lack of supervision or control by a person in a leading position has made possible the commission of the offence by a person under its authority. This standard directly mirrors the OECD’s expectation that corporate liability is triggered when a higher-level person fails to prevent a lower-level person from bribing a foreign public official, including through a failure to supervise them or through a failure to implement adequate internal controls, ethics and compliance programmes or measures.
Moreover, a recurring concern voiced by the OECD is that whistleblowing protection frameworks do not clearly cover the reporting of foreign bribery. In several Member States, the material scope of whistleblower protection legislation either omits any explicit reference to the offence or relies on vague, undefined concepts to delimit the range of reportable conduct, creating ambiguity that risks discouraging potential whistleblowers from coming forward. Article 25 of the Directive addresses the most fundamental of these gaps by mandating that Directive (EU) 2019/1937 on the protection of whistleblowers is applicable to the reporting of all corruption offences defined in the Directive, including bribery within both the public and private sector. Transposition of the Directive will, therefore, require Member States to remove the ambiguities in relation to the scope of whistleblower protection that the OECD has consistently flagged, ensuring that persons reporting foreign bribery are unequivocally entitled to adequate protection.
Jurisdictional reach
The Directive’s jurisdictional provisions deserve close attention. Article 18 establishes two mandatory bases: territorial jurisdiction (including offences committed wholly or partly on a Member State’s territory) and active nationality jurisdiction. However, the Directive also offers four optional extensions that Member States may adopt, including jurisdiction over offences committed for the benefit of a legal person established in the Member State’s territory, or for the benefit of a legal person in respect of any business carried out in whole or in part on its territory. The latter functions similarly to the UKBA’s ‘carrying on a business’ jurisdictional hook, under which any entity, wherever it is incorporated, that carries on a business or part of a business in the UK is a ‘relevant commercial organisation’ and, thus, can be prosecuted for failing to prevent bribery, regardless of where the corrupt conduct took place.
Conclusions
The Anti-Corruption Directive marks a significant milestone in the EU’s criminal law framework, establishing for the first time a comprehensive and harmonised approach to the prevention, investigation and sanctioning of corruption across the Union. By modernising outdated instruments, broadening the scope of criminalised conduct, strengthening enforcement mechanisms and promoting greater consistency among Member States, the Directive addresses the increasingly transnational and sophisticated nature of corruption.
The Directive’s ultimate impact will depend largely on its implementation. The transposition process offers Member States an opportunity to address longstanding deficiencies identified by international monitoring bodies.
For businesses, the implications are equally significant: effective compliance programmes, robust internal investigations and meaningful cooperation with the relevant authorities are no longer peripheral governance considerations but increasingly central elements of risk management. Even foreign companies with EU exposure, whether through subsidiaries, supply chains, public procurement or financial infrastructure, should begin their gap analyses now, before national implementing legislation takes shape and narrows the room for adjustments. In particular, companies should review their existing compliance frameworks against the Directive’s prevention standards and monitor how each relevant Member State transposes the optional jurisdictional extensions. Early engagement will reduce enforcement risk and position organisations to adapt smoothly as the June 2028 transposition deadline approaches.