Provide personnel with anti-bribery awareness and training that is adequate and fitting and that, as relevant in light of the risk assessment, covers: the policy, procedures and system and the obligation to follow them; bribery risk and the harm bribery can do to them and to the organization; where bribery can arise in their work and how to spot it; how to spot and deal with requests for or offers of bribes; how to help prevent and avoid bribery and notice key warning signs; how they contribute to the system's effectiveness, including why better anti-bribery performance and reporting suspected bribery help; what follows from not conforming; how and to whom to raise concerns (8.9); and what training and resources are available. Provide it regularly at intervals the organization plans, matched to roles, risk exposure and changing circumstances, and refresh the programmes when new information calls for it. Also put procedures in place for awareness and training of business associates acting for the organization, or in its name, who could present a bribery risk above low, naming which associates, what content and how it is delivered. Keep documented information on the procedures, the content and who was trained when.
This control maps to 41 controls across 34 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.
The graph holds this control, the 41 it maps to, and the evidence behind each claim, over MCP and REST.