Bribes are disguised, assets are transferred, front men are used – corporate crime does not conform to regulatory categories. This is precisely where the new EU Anti-Corruption Directive (Directive (EU) 2026/1021) comes in. This article explains what this means in practical terms for banks and financial service providers.
Corruption prevention is being harmonised across Europe: criminal law and sanctions provisions must be implemented by 1 June 2028, whilst regulations on risk analyses and prevention strategies must be in place by 2029. Together with the EU Anti-Money Laundering Regulation (Regulation (EU) 2024/1624) and the AMLA, this strengthens the integrated EU framework against financial crime. The common thread: risk-based prevention and significantly greater corporate responsibility.
There are three key points compliance officers should be aware of:
Hardly any other sector is as exposed as the financial sector: close ties to supervisory authorities and central banks, a multitude of distribution partners, intermediaries and other third parties, and a business that is, by its very nature, cross-border. Each of these interfaces is a potential point of entry.
The real problem often lies in the organisation. In many places, corruption prevention still operates as a separate silo alongside money laundering, fraud and sanctions. This separation does not reflect reality. White-collar crime does not think in terms of areas of responsibility: one and the same set of facts – a concealed payment, a front man, a convoluted corporate structure – can simultaneously point to corruption, money laundering, fraud and breaches of sanctions.
The good news is that new processes are not necessarily required. Banks usually already have the key tools in place – from risk analyses and governance to whistleblowing schemes, internal investigations, transaction monitoring and due diligence. However, these are often not yet specifically geared towards corruption risks.
This is precisely where the practical challenge lies: corruption risks are often assessed only qualitatively; third parties such as intermediaries or advisers are scrutinised less rigorously; and warning signs such as conflicts of interest or conspicuous remuneration models are too often kept separate from existing anti-financial crime data.
Closing these gaps strengthens prevention whilst simultaneously reducing complexity and duplication of effort. The implementation deadline therefore represents a strategic window of opportunity – for all those who seize it now.
Would you like to align your anti-financial crime framework with the new requirements? Please feel free to contact us – we can support you in analysing existing structures and the integrated further development of your compliance systems.