Sapin II Pillar 3 - Corruption Risk Mapping (Cartographie des risques de corruption). REQUIREMENTS: a documented + risk-based + regularly-updated MAPPING of corruption risks across the organization. METHODOLOGY: (a) IDENTIFICATION of corruption risks per business activity + geography + counterparty + transaction type + product/service line; (b) ASSESSMENT of likelihood + impact (typically 4-tier scale very-low / low / medium / high + 4-tier impact financial / legal / reputational / operational); (c) RISK SCORING + heat map; (d) MITIGATION measures per risk; (e) RESIDUAL risk tracking; (f) ANNUAL REVIEW + after major events. AFA-PREFERRED FEATURES: workshop-based with cross-functional teams (business + legal + audit + finance); per-third-party scoring incorporating Transparency International Corruption Perception Index; integration with risk-based due diligence (Pillar 4); board reporting + audit committee oversight. INTEGRATION: with the company-wide ERM (Enterprise Risk Management) framework + COSO + ISO 31000.
This control maps to 207 controls across 133 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.
The graph holds this control, the 207 it maps to, and the evidence behind each claim, over MCP and REST.