For everyone on the staff (7.2.2.1), procedures must ensure that: employment terms oblige compliance with the policy and system and let the organization discipline people who fail to comply; new staff get the policy, or access to it, and training on it within a reasonable time of starting; disciplinary action can be taken against those who breach the policy or system; and nobody faces retaliation, discrimination or discipline (threats, isolation, demotion, blocked promotion, transfer, dismissal, bullying, victimization or other harassment) for refusing an activity they reasonably judge to carry a bribery risk above low that has not been mitigated, or for raising in good faith or on reasonable belief attempted, actual or suspected bribery or breaches, unless they took part. For roles whose bribery risk exposure is above low, and for the compliance function (7.2.2.2), procedures must provide for: due diligence on candidates before hiring and on staff before transfer or promotion, to judge whether they are suitable and likely to comply; periodic review of bonuses, targets and other incentive pay for safeguards against encouraging bribery; and declarations of compliance with the policy, filed by those staff, by top management and by the governing body at intervals proportionate to the risk.
This control maps to 4 controls across 4 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.
The graph holds this control, the 4 it maps to, and the evidence behind each claim, over MCP and REST.