Insights

A New Era in the EU’s Fight Against Corruption: The Message for Companies Is Clear 

Cerebra
Article

The new EU Anti-Corruption Directive reinforces the importance of corporate responsibility, effective anti-fraud controls, and ethics and compliance mechanisms in preventing corruption. What does the Directive mean for companies and internal investigations in Türkiye?

When we think about the fight against corruption, the first things that often come to mind are bribes paid to public officials or major corruption scandals. 

Yet the risks companies face today are far more diverse and complex. 

An improper payment to a distributor, opaque funds created under the guise of “marketing support,” third parties that are not subject to adequate due diligence, conflicts of interest, or control weaknesses overlooked by management… These are no longer merely ethical concerns. They can also expose companies to significant legal and corporate risks. 

The EU’s new Anti-Corruption Directive (EU 2026/1021), which entered into force on 31 May 2026, responds to this evolving risk environment.  

What Does The Directive Change?

At first glance, the Directive may appear to be a technical piece of criminal law legislation. But its implications for companies are much broader.

It is no longer enough for companies simply to refrain from corrupt conduct. Establishing effective corporate structures and mechanisms designed to prevent corruption is becoming increasingly important.

Against this backdrop, the Directive:

  • Brings corruption offences in the public and private sectors under a more harmonised framework;
  • Strengthens the rules on corporate liability;
  • Introduces a more deterrent approach to sanctions; and
  • Seeks to enhance cooperation among EU Member States.

For companies, however, one particularly important aspect is the emphasis placed on effective internal controls and ethics and compliance mechanisms in the fight against corruption.

The Real Issue: The Control Environment

The issues identified in internal investigations are not always limited to proving bribery, false invoicing, embezzlement or personal gain.

Often, more fundamental governance and control weaknesses emerge:

  • An inability to establish why certain decisions were made;
  • Inadequate documentation of transactions and decisions;
  • A lack of transparency in approval processes;
  • Decision-making and control responsibilities concentrated in the same individuals; and
  • Third parties being engaged without sufficient due diligence.

When these weaknesses come together, they can create an environment highly vulnerable to misconduct, even where no specific act of fraud or corruption has been proven.

What Internal Investigations Often Reveal

Cerebra’s experience in conducting internal investigations has repeatedly highlighted similar governance and control issues.

In some cases, there may not be sufficient evidence to establish that an employee obtained a personal benefit or that a specific act of corruption occurred.

What may emerge instead are significant risk indicators, such as:

  • Weak governance;
  • Inadequate or ineffective internal controls;
  • Insufficient record-keeping and documentation;
  • Opaque management of funds; and
  • Complex payment arrangements involving third parties.

In other words, it may not always be possible to prove misconduct, but it may be very clear that the conditions enabling misconduct to occur were present.

This is where one of the Directive’s key messages for companies becomes particularly relevant: fighting corruption is not only about responding to incidents after they occur. It is also about building a control and compliance environment that makes such incidents more difficult to occur in the first place.

Why Should Turkish Companies Pay Attention?  

Although this is an EU Directive, its impact is unlikely to remain confined to Europe. Anti-corruption standards are also becoming increasingly relevant for Turkish companies that operate in the EU or have business relationships with EU-based companies.

Areas that Turkish companies may need to reassess regarding corruption in Türkiye include third-party risk management, Anti-Bribery & Corruption (ABAC) programmes, whistleblowing mechanisms, conflicts of interest, internal investigations and effective internal controls.

Final Thoughts

One of the most important messages the new Directive sends to companies is clear:

A company’s strongest defence is not the explanation it prepares after an incident, but the governance, ethics, compliance and control systems it has put in place before the incident occurs.

When an allegation of corruption or fraud arises, the question is no longer simply:

What happened?

An equally important question is:

Why did the controls designed to prevent or detect it fail?

The answer to that second question can be one of the clearest indicators of how well prepared an organisation truly is to manage corruption risk.

Related Insights