Where the risk assessment has found more than low bribery risk in particular categories of transactions, projects or activities, of planned or existing relationships with business associates, or of personnel in certain roles, assess what kind of bribery risk arises, and how much, for the specific transactions, projects, activities, associates and staff that fall in those categories, including any due diligence needed to get enough information, and refresh the due diligence at a set frequency so changes and new information are taken into account. The organization may decide that due diligence on some categories of staff or associates would be unnecessary, unreasonable or disproportionate.
This control maps to 23 controls across 20 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.
The graph holds this control, the 23 it maps to, and the evidence behind each claim, over MCP and REST.