French Law no. 2016-1691 of 9 December 2016 on transparency, the fight against corruption and the modernisation of economic life, known as the “Sapin II Act”, requires public and private legal entities to put in place measures and procedures designed to prevent and detect acts of corruption and influence peddling. One of the unavoidable steps in this process is mapping the integrity risks to which the entity is exposed.
What do we mean by “risk mapping”?
Mapping integrity risks proves to be an essential tool for guaranteeing an entity’s regulatory compliance in the fight against corruption. According to the French Anti-Corruption Agency (AFA), it is the cornerstone of the anti-corruption framework, since it is from this mapping that the main measures for preventing and detecting integrity breaches are defined. This analysis of all the processes through which the entity interacts with third parties makes it possible to identify, assess and manage the risks linked to the organisation’s activities and environment, and to take the appropriate measures to control them effectively.
Its objective is therefore to limit the legal, human, financial and reputational consequences of the breaches described above. The risk map is approved by the governing body, which must also assess its relevance and effectiveness at least once a year.
What are the different stages of a risk mapping exercise?
To produce an efficient risk map, one that will then allow relevant and workable arrangements to be put in place within the organisation, we recommend following the steps below.
Step 1: Defining the roles and responsibilities of the stakeholders in the risk mapping exercise
Clarifying roles and responsibilities (governing body, compliance officer, staff, and so on) ensures that the mapping exercise is promoted and its preparation coordinated under the right conditions and by the right people, while taking care to capture the risks inherent in the activities carried out by everyone working in the organisation, whatever their status.
Step 2: Identifying the risks inherent in the organisation’s activities
This step aims to list and categorise the risks to which the entity is exposed in the course of its business. Once the processes have been inventoried and discussions with staff have taken place, the point is to draw up a precise picture that identifies, in a detailed and documented way, the risks specific to the organisation.
As a result, a comprehensive inventory of the risks inherent in the activities requires not only knowledge of the organisation involved and of the roles assigned, but also a fine-grained command of the processes in place.
Step 3: Assessing the risks
The purpose of this phase is to assess the organisation’s level of vulnerability for each risk scenario identified in the previous step. First, we can identify the “gross” risks to which the organisation is exposed, that is, the risks considered before the controls in place are taken into account. The level of vulnerability is assessed using the following three indicators: impact, frequency and aggravating factors. Then come the “net” risks, namely the re-assessment of the “gross” risk scenarios taking into consideration the risk controls already in existence and implemented, in other words, assessing the effectiveness of existing measures against those risks.
Step 4: Assessing net risks
Once step 3 has been validated, a ranking of risk scenarios by level emerges. Prioritising net risks is an indispensable step towards implementing an action plan. It determines which risks are the most urgent to address and where the governing body wishes to improve control.
Step 5: Formalising, monitoring and updating the risk map
All the previous steps together make up the risk map. Their output is then written up in a summary document which will serve as a management tool for corruption risks. The presentation of this map, which is particularly important for internal buy-in, may be structured by business line, by process, by entity or by geography, as the organisation prefers.
Its update is reviewed each year and may also be triggered by specific events affecting the entity.
Conclusion
Risk mapping is a complex exercise. It brings into play many players and many sets of data, both inside and outside the organisation. In an uncertain environment, however, it is an indispensable tool for helping your organisation limit various types of risk, such as:
• financial, criminal and administrative penalties
• loss of reputation
• loss of trust among partners, investors or clients
• loss of appeal, competitiveness and productivity.
Prime Conseil, drawing on its expertise, can support you in building your risk map and help inform your strategic and operational decisions in this area. Do get in touch if you would like to know more about our approach.
