As Ethixbase360 previously covered, when the European Union’s Directive 2026/1021 “On combatting corruption” (the “Directive”) entered into force on May 31, 2026, it became the first EU-wide criminal law framework on corruption.
The Directive establishes, first, common definitions for a range of corruption offenses and second, common minimum penalties across the EU. Companies may face fines of three to five percent of worldwide turnover, or €24 to €40 million, depending on the offense, and can be held liable where a failure of supervision or control by leadership enabled the conduct. Notably, an effective compliance program is treated as a mitigating factor at sentencing, though not a complete defense. The jurisdictional reach is broad, even companies headquartered outside the EU could fall within scope.
While member states have until June 2028 to transpose most of its provisions into national law, there is already a broader shift underway in both the EU and the United Kingdom, as the bar for corporate accountability is rising. Corporate compliance leaders need to recognize that increasingly, regulators will scrutinize the adequacy of the compliance program itself, not merely the absence of misconduct.
Intensifying National Enforcement
France
In July of this year, the Sanctions Committee of the French Anti-Corruption Agency (AFA) issued its first-ever financial penalty under Article 17 of the Sapin II law, in the amount of €350,000 against an unnamed company and €60,000 personally against its legal representative. The penalty followed an audit that found deficiencies in risk mapping, third-party due diligence, training, and controls.
Firms operating in or with France should note several critical points. First, Sapin II requires no underlying act of bribery, or even a suspicion of one; a company can be sanctioned for an inadequate prevention program regardless of its actual risk profile. Second, the Sanctions Committee held that prior violations should not be linked to subsequent remediation, and that remediation would be taken into account only when deciding on the sanction amount. Next, the Committee held that the relevant date for assessing compliance was that of the final control report, not the later date of its ruling. Companies currently under or anticipating an AFA audit should treat the control period itself as the critical window to take action.
United Kingdom
The UK has been strengthening its corporate crime framework on a separate track, as Ethixbase360 has also highlighted in a recent webinar. On September 1, 2025, the failure to prevent fraud offence under the Economic Crime and Corporate Transparency Act came into force, exposing large organizations to criminal liability where an associated person commits fraud for the company’s benefit, unless the organization can demonstrate it had “reasonable procedures” in place. As our webinar made clear, the Act also broadened the test for corporate attribution from the “directing mind and will” standard to a wider “senior manager” test, and the Serious Fraud Office has signaled its intention to make active use of the new offence. As with the UK Bribery Act’s “adequate procedures,” the reasonable-procedures defense again puts the compliance program at the center of the analysis.
Germany
A draft bill (in German) published in April 2026 by the German Federal Ministry of Justice and Consumer Protection is principally focused on transposing the EU’s Environmental Crime Directive into national law. However, if the bill is approved by German legislators, it will have important ramifications for expanded corporate liability. The government has proposed quadrupling the maximum corporate fine under the Regulatory Offenses Act, from €10 million to €40 million for intentional offenses and from €5 million to €20 million for negligent offenses. The draft bill also codifies, for the first time, criteria for whether and how fines are assessed, including, among others, the size of the company, the significance of the offense, a company’s efforts to uncover an offense and compliance measures taken by the company.
Implications for compliance programs
Taken together, these developments point in a similar direction: regulators are paying more attention to the quality of a company’s prevention program and its ability to document that program. Companies should continue to track national implementing legislation closely, since EU member states retain discretion to go beyond the floor the Directive sets.
As Ethixbase360 seeks to help compliance leaders navigate this evolving landscape, we will host a webinar this fall examining the EU Anti-Corruption Directive, these recent UK and European developments, how they compare with existing frameworks such as the UK Bribery Act and the US FCPA. We will highlight the practical steps that companies can take now to prepare, before the Directive’s 2028 transposition deadline, to benchmark their compliance programs, due diligence approaches, and third-party risk management across jurisdictions.