Featured







Loi Sapin II dix ans après : pourquoi la cartographie des risques reste le pilier le moins déployé
En bref : dix ans après la loi Sapin II, l'AFA publie une enquête menée par IPSOS-bva auprès de 502 entreprises. Parmi celles qui se déclarent assujetties à l'article 17, seules 56 % ont élaboré une cartographie des risques de corruption. Dans le même temps, 68 % d'entre elles expliquent l'absence de certaines mesures par un risque jugé faible ou suffisamment maîtrisé. Le problème est là : on ne peut pas savoir qu'un risque est faible sans l'avoir mesuré, et l'outil qui le mesure est précisément celui qui manque. Nous comprenons pourquoi la cartographie est le pilier le moins déployé. C'est l'exercice le plus exigeant du dispositif. C'est aussi celui qui conditionne tous les autres.

Competition Risk Mapping and Dawn Raids: Why a Risk Map Is Not a Smoking Gun
In short: A competition risk map records where a company is exposed, not what it has done. It describes market conditions, contacts with competitors, pricing processes and the scenarios those create. It does not record infringements. Facts that surface during the mapping exercise belong in the internal alert and investigation procedure, not in the map. Built this way, the map is evidence of diligence. The weakness behind the fear of seizure is not confidentiality. It is a misconception of the exercise itself: what a risk map should show, and what it is for. Confidentiality comes second, and that gap is narrowing anyway, including in France with the law of 23 February 2026.

Segregation of duties: a practical matrix for mid-size firms
Segregation of duties (SoD) means splitting the critical steps of a process: initiation, approval, execution, recording, and review, so that no single person can both create and validate a risky transaction. A mid-size firm does not need five people per process. It needs three things: incompatible steps never held by the same person, a documented compensating control wherever headcount makes separation impossible, and an exceptions register that proves the gaps are governed rather than ignored.

When to hire compliance consultants
Hire a compliance consultant when independence, specialist expertise, or credibility with a regulator is decisive: a first Sapin II or ISO 37001 program, an investigation or dawn raid, a certification or customer audit within 120 days, or expansion into a new jurisdiction. Keep accountability, risk decisions, and evidence ownership in house. Use technology for the recurring work, data collection, monitoring, evidence trails, so consultant hours go to judgment, not administration.

Ce que l'AFA attend réellement de votre reporting de conformité
Lors d'un contrôle de l'AFA, votre tableau de bord fait preuve. Ce que l'AFA attend du reporting de conformité Sapin II, et quels indicateurs construire.