Have procedures that: encourage people, and make it possible for them, to raise, in good faith or on reasonable belief, attempted, suspected or actual bribery and any breach of or weakness in the system to the compliance function or suitable personnel, directly or via a suitable third party; keep reports confidential so the identity of the reporter and others named is protected, except as needed to progress an investigation; allow reports to be made anonymously; forbid retaliation and protect people who raise such concerns in good faith or on reasonable belief; and let staff get advice from a suitable person when facing a situation that might involve bribery. Make sure all personnel know the procedures, can use them and understand their rights and protections. Where local law forbids the confidentiality or anonymity items, the organization records that it cannot comply; the channel may be shared with other kinds of concern and may be run by a business associate.
This control maps to 7 controls across 4 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.
The graph holds this control, the 7 it maps to, and the evidence behind each claim, over MCP and REST.