The EU Anti-Corruption Directive 2026/1021 took effect in May. Member states have until June 2028 to implement criminal provisions and June 2029 for preventive measures. This timeline may seem distant, but it's crucial to align it with your compliance roadmap and manage jurisdictional complexities effectively.
What Changed
The directive establishes the EU's first harmonized criminal law framework for corruption offenses across all member states. It addresses bribery in both public and private sectors, trading in influence, conflicts of interest, misappropriation, unlawful exercise of public functions, obstruction of justice, and enrichment from corruption.
Two provisions are particularly significant for compliance teams:
Failure-to-prevent liability. Organizations can be held liable for corruption offenses committed for their benefit if they fail to implement appropriate preventive measures. This shifts the burden to you to prove your program's effectiveness, not just its existence.
Penalties with mitigation pathways. Maximum penalties can reach 5% of worldwide annual turnover or up to €40 million, depending on the offense. Member states may reduce penalties if organizations demonstrate structured preventive measures beyond mere documentation.
Unlike the UK Bribery Act's Section 7, where adequate procedures serve as a complete defense, the ACD considers compliance programs as a mitigating factor. The quality of your program directly influences penalty exposure.
Key Findings
Jurisdictional reach extends beyond EU headquarters. Non-EU parent companies operating through EU subsidiaries or conducting material business activity within the EU face liability for conduct committed for those interests' benefit, regardless of where it occurred. If you have an EU presence, this is a group-level obligation.
27 implementations create divergent standards. The directive sets minimum requirements, but member states can exceed them. Belgium, Germany, Italy, France, Poland, and the Netherlands already show differences in penalty thresholds, corporate liability structures, and sector-specific considerations. You're managing 27 variations, not one standard.
Evidence architecture determines defensibility. The directive assumes five interconnected components: confidential reporting mechanisms, role-tailored training, documented policies with acknowledgment records, third-party due diligence with monitoring trails, and periodic risk assessments. These components matter only if you can demonstrate they functioned effectively. A risk assessment identifying high-risk relationships is meaningless if you can't show the due diligence that followed.
Manual programs create liability gaps. If components are managed manually, inconsistently, or without consolidated audit trails, the evidential record regulators require won't exist. Prosecutors ask, "What did your program do when this concern was raised?" If your answer involves reconstructing events from emails and spreadsheets, your program isn't defensible.
What This Means for Your Team
Your compliance program's operational effectiveness is now a measurable legal factor. The record of how concerns were raised and handled, how third parties who failed due diligence were managed, and what happened when training gaps surfaced is crucial.
This creates a high-stakes documentation challenge. You need to prove your program worked under pressure, recording decisions alongside policies. A policy document sets the standard; the record of how that standard was applied demonstrates whether preventive measures were genuinely operational.
For organizations operating across multiple EU jurisdictions, the challenge is maintaining consistent program standards across entities facing different national legal requirements while evidencing compliance to each market's regulator. Organizations familiar with the EU Whistleblowing Directive or General Data Protection Regulation will recognize this architecture. The ACD adds a layer to a familiar design problem.
Action Items by Priority
Immediate: Map your jurisdictional exposure. Identify every EU market where you operate through subsidiaries, commercial relationships, or material business activity. Rank them by revenue, employee count, and regulatory enforcement history. These are your priority jurisdictions for transposition monitoring.
Q1 2025: Conduct a systematic gap analysis. Map existing capabilities against the directive's five requirement areas: reporting mechanisms, training, policies, third-party due diligence, and risk assessments. Assess not just whether the component exists but whether you can produce an auditable record of its function over the past 12 months. Gaps in your evidential record are your highest regulatory exposure.
Q2 2025: Consolidate your audit trail. If components are managed across separate functions and systems, you face a coherence challenge. The mitigation defense depends on presenting an integrated program. Consolidate evidence into a navigable, auditable record that connects risk assessments to due diligence findings to training design to incident response. This is the foundation for demonstrating genuine preventive measures.
Q3-Q4 2025: Build against the highest likely standard. Don't wait for final national implementing legislation in each jurisdiction. Engage local counsel in your priority markets to identify where anticipated standards exceed the directive's minimums. Design your group standard to meet the highest requirements you'll face, then document jurisdiction-specific supplements where needed.
Ongoing: Record decisions, not just policies. Every time a concern is raised through your reporting mechanism, every time a third party fails due diligence, every time a training gap surfaces, document what your program did in response. These records are what prosecutors will request when examining whether your preventive measures were genuinely in place.
Organizations in early-stage maturity should prioritize documentation and evidence architecture. Mid-stage programs should focus on consolidating the evidential trail. Advanced programs should stress-test cross-jurisdictional consistency against the June 2028 deadline in their highest-profile markets.
The directive builds on frameworks from the UK Bribery Act, the Foreign Corrupt Practices Act, and the OECD. It adds a mandatory legal framework across the EU, statutory penalties for programs that can't demonstrate effectiveness, and a timeline that requires action now, not in 2028.





