Ask Kepler.ai
The World's Business Knowledge

Risk & Compliance

Most organizations miss half their corruption exposures

Corruption risk isn't uniform across your business—it concentrates in specific geographies, transaction types, and partner relationships. A structured assessment reveals where you're actually vulnerable, what your controls are really worth, and which investments will reduce risk most.

Ask Kepler Research ·With benchmark data

Most organizations lack a baseline understanding of their corruption exposures and control effectiveness. A structured corruption risk assessment—combining maturity evaluation, process-level risk mapping, and jurisdiction analysis—typically identifies 30–50% more control gaps than routine audits alone. This assessment pinpoints the specific business model vulnerabilities, geographies, and transaction types where corruption is most likely and where control investments will have the greatest impact.

What good looks like

MetricMinimumStrongWorld-class
Audit Finding Remediation TimelinessPercentage of audit findings closed or remediated within the contractually agreed or risk-based timeline.70-80%85-93%94-99%
Audit Issue Severity Distribution RatioRatio of critical or high-risk audit findings to total findings issued, indicating the proportion of the most significant governance and control gaps.15-25%8-14%3-7%
Audit Plan Risk Coverage ScorePercentage of identified enterprise and operational risks subject to audit coverage within a three-year rolling audit plan.60-72%73-85%86-95%

The gap between minimum and world-class tier reveals where organizations underinvest. World-class teams close audit findings in 94–99% of cases and maintain critical finding ratios of 3–7%, compared to minimums of 70–80% remediation timeliness and 15–25% critical issues. This concentration of severity indicates that world-class organizations identify problems earlier and through more targeted risk-based planning (risk coverage of 86–95% vs. 60–72%), preventing critical exposures from accumulating. Organizations stuck in the minimum tier are typically reactive: they audit broadly but not smartly, remediate slowly, and watch minor control gaps compound into critical findings.

Industry-Specific Benchmarks

These ranges are cross-industry. The figures differ materially by sector and company size.

Find benchmarks for your industry →

Why the gap exists

The difference between adequate and excellent anti-corruption programs lies in how they allocate investigative effort. Most organizations audit the same processes on a fixed schedule regardless of actual risk. They complete 75–82% of their planned audits, but those plans are built on generic compliance frameworks, not on where corruption is most likely to occur in their specific business model. This means they find problems late—after schemes have already run—and discover them by accident rather than by design.

World-class organizations invert this logic. They conduct formal corruption risk mapping before the audit plan is written, identifying the specific transaction types, geographies, and partner relationships where schemes are most likely. Their audit plans concentrate on these high-risk areas and achieve 93–98% completion because they've scoped engagements to what matters most. When they do find problems, they're caught earlier in their lifecycle, remediation happens faster (94–99% of findings closed), and critical findings remain rare (3–7% vs. 15–25%). The control maturity assessment isn't a compliance checkbox—it's the mechanism that makes this targeting possible.

This requires three things the typical compliance function lacks: a documented corruption risk profile specific to the organization's business model; clear accountability for remediation tied to executives who can actually unlock resources; and a willingness to rebalance the audit plan mid-year when new risks emerge or old controls fail. Smaller organizations can accomplish this without dedicated specialists; larger ones often have the resources but fragment ownership across multiple committees, guaranteeing slower closure and repeated failures.

What leading organizations do

Map your control maturity against reality, not compliance checklists

Most organizations have anti-corruption controls in some form—policies, training, third-party screening—but have no clear picture of whether those controls are actually working. A maturity assessment changes this by evaluating three dimensions: design (does the control address a real corruption risk?), operating effectiveness (is it being executed consistently?), and sustainability (will it continue to work as the business evolves?). This is different from checking whether a control exists.

The assessment process itself often uncovers incidents that haven't been reported through normal channels, control gaps in acquired units or international subsidiaries, and practices that started as exceptions and became the norm. An outside perspective—either internal audit with genuine independence or a third party—is critical here, because business leaders tend to rate their own controls more favorably than objective review supports. The output isn't a score to brag about; it's a prioritized list of which control gaps pose the highest corruption risk and therefore deserve investment first. For organizations at any scale, this assessment becomes the foundation for board-level reporting on compliance program maturity and for regulatory discussions about control effectiveness.

Leading Practice Report

Full detail: Anti-Corruption Controls Maturity Assessment and Benchmarking

The full report covers:

  • Expected benefits
  • Core principles
  • Key success factors
  • Key metrics
  • Risks and mitigations
  • Implementation roadmap
Get the full report →

Identify the specific corruption scenarios embedded in your business model

Generic anti-corruption controls miss the point because generic corruption doesn't exist. A bribery scheme in customs clearance looks nothing like one in a sales commission structure, and the controls that catch one won't catch the other. Corruption risk mapping identifies the high-risk scenarios specific to your organization: which transaction types, geographies, and relationships create the opportunity and incentive for schemes to work.

This exercise is scenario-driven, not checklist-driven. It asks: How could someone bribe a government official using our processes? What does our sales incentive structure incentivize? Which supply chain partners operate in jurisdictions where corruption is endemic, and how would that show up in our transactions? The output is a heat map showing which business units, geographies, and transaction types concentrate the highest corruption risk. This becomes the basis for everything else—where to concentrate third-party due diligence, which audit areas warrant data analytics, which control improvements will reduce risk most. Organizations that skip this step tend to apply the same controls everywhere, which means high-risk areas are undertreated and low-risk areas are over-controlled.

Leading Practice Report

Full detail: Corruption Risk Mapping and Scenario Analysis

Benefits, core principles, success factors, metrics, risks and the implementation roadmap.

Get the full report →

Evaluate corruption risk before you enter a market or sign a major contract

Corruption risk varies by orders of magnitude across jurisdictions. An organization expanding into a market without systematic risk evaluation enters blind, almost guaranteeing higher incident rates and regulatory exposure. A country and jurisdiction assessment is straightforward in structure: it combines public corruption indices (available from UNODC, Transparency International, and others) with internal factors specific to your business—sector-specific corruption prevalence, regulatory sophistication, your company's track record in similar markets, and the types of government relationships the business will require.

The assessment produces a risk score that informs investment decisions. A high-corruption jurisdiction doesn't mean you can't enter it; it means you need stronger controls, more careful partner selection, and likely higher compliance costs. It also means your board needs to understand the risk explicitly before committing capital. Organizations that conduct this assessment before market entry or major government contracts report 30–50% fewer corruption incidents in the first three years of operation compared to those that assess risk retrospectively. The assessment also prevents surprises: when compliance issues do emerge, they've been flagged, scoped, and budgeted for rather than arriving as sudden emergencies.

Leading Practice Report

Full detail: Country and Jurisdiction Risk Assessment for Business Operations and Expansion

Benefits, core principles, success factors, metrics, risks and the implementation roadmap.

Get the full report →

Industry context

The corruption risk profile varies sharply by sector. Organizations in extractives, infrastructure, defense, and government contracting face endemic corruption risk because their primary customers are governments and large state-owned enterprises. These organizations typically operate in jurisdictions where corruption perception is high and regulatory oversight is inconsistent. For them, a corruption risk assessment isn't optional—it's a license to operate. By contrast, organizations in consumer goods, financial services, or technology often perceive corruption as a low-probability risk and defer assessment until after an incident or regulatory inquiry.

Geography and scale matter. A 200-person firm operating in two countries can conduct corruption risk mapping with a single workshop involving sales, operations, and finance leaders; a 40,000-person multinational with operations across 50 countries needs a more structured process, likely involving regional compliance teams and external expertise. For smaller organizations, the assessment becomes a board discussion informed by an outsider's perspective; for larger ones, it's a systematic engagement across business units. The maturity assessment also surfaces faster in smaller organizations—they can identify control gaps in weeks rather than months—but the remediation depends equally on executive sponsorship, which some small organizations lack and large ones sometimes fragment across competing priorities.

Where to start

  1. Commission an objective evaluation of your current anti-corruption controls—what exists, what actually works, and which gaps pose the highest risk. This becomes your baseline.
  2. Map the corruption scenarios specific to your business: which transaction types, geographies, and partner relationships carry the highest risk of bribery or sanctions violations?
  3. For any new market entry or major government contract, conduct a jurisdiction risk assessment before the investment is approved, not after problems emerge.

Ask Kepler how to design a corruption risk assessment that fits your organization's actual risk profile and the controls you actually have in place.

Start free with Ask Kepler →

Advanced and emerging approaches

Corruption Susceptibility Maturity Assessment & Control Benchmarking

Benchmark your anti-corruption control effectiveness against peer organizations and identify which gaps pose the highest relative risk to your specific business model and scale.

Corruption Risk Heat-Mapping & Geopolitical Intelligence Integration

Overlay your transaction data and supplier networks with real-time geopolitical risk and sanctions designations to detect corruption exposure as conditions change, not months later.

Advanced & Emerging Practices

Emerging practices are included with Ask Kepler Pro and Max.

Unlock these practices →