Top management sets up, keeps and reviews an anti-bribery policy. It must: ban bribery; require compliance with the anti-bribery laws that apply; suit the organization's purpose; give a framework for setting, reviewing and meeting anti-bribery objectives; commit to meeting the system's requirements; encourage people to report concerns, in good faith or on reasonable belief, confidentially and without fear of reprisal; commit to continual improvement of the system; explain how much authority the anti-bribery compliance function has and how independent it is; and set out what happens if the policy is breached. The policy is kept as documented information, communicated in suitable languages inside the organization and to business associates whose bribery risk is more than low, and made available to relevant stakeholders where appropriate.
This control maps to 12 controls across 11 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.
The graph holds this control, the 12 it maps to, and the evidence behind each claim, over MCP and REST.