AFA Compliance Reporting: What Regulators Expect from your Dashboard

Iratxe Gurpegui
Written by
Iratxe Gurpegui
7 min read

When the Agence Française Anticorruption opens a control it assumes you have a compliance program. The question it actually asks, through its questionnaire, its document requests, and its interviews, is whether you can prove your programme works?

This is where many otherwise serious compliance programmes stumble. The code of conduct exists. The training was delivered. The risk map was approved. But when the AFA asks for the indicators that show these measures are steered, reviewed, and corrected over time, the answer is a folder of PDFs and a scramble through old emails.

This article walks through what the AFA actually expects from compliance reporting under Sapin II: where reporting sits in Article 17, what controllers look for, which indicators carry weight and why your compliance dashboard should be designed as audit evidence.

Where reporting sits in Article 17

Article 17 of the Sapin II law lists eight measures that in-scope companies must implement: a code of conduct, an internal whistleblowing channel, a corruption risk map, third-party evaluation procedures, accounting controls, training for exposed staff, a disciplinary regime, andthe one that concerns us here: an internal control and evaluation system for all of the above (Article 17, II, 8°).

Reporting is the eighth measure, and it is also the thread that runs through the other seven. The AFA recommendations organise the entire framework around three pillars: the commitment of top management, the corruption risk map, and the management of the risks identified. Reporting is how the first pillar becomes visible. Top management cannot credibly claim commitment to a programme it never reviews. The only way to review a programme is through indicators, dashboards, and documented decisions.

What the AFA looks for during a control

The AFA questionnaire is your blueprint

Every AFA control begins with a detailed questionnaire, followed by document requests. For example, regarding training, the questionnaire asks which populations were identified as exposed, what proportion of them completed the training, how completion is tracked, and how the programme was adjusted as a result. In other words, it asks for indicators, review cycles, and evidence of follow-up.

The questionnaire becomes the best self-assessment tool available to you, for free, before the AFA ever shows up. If your reporting cannot answer the questionnaire's questions with dated, sourced data, you have found your gap.

Three levels of control and proof that all three run

The AFA expects internal control over the anti-corruption programme to operate at three levels:

  • First level: operational controls performed by the business itself: a sales manager verifying that a new distributor completed due diligence before the contract was signed.
  • Second level: controls performed by the compliance or internal control function: periodically re-testing a sample of third-party files to confirm the first-level control actually operates.
  • Third level: internal audit independently assessing the design and operation of the whole system.
Three levels of controls

Here is the trap: most companies can show that these controls are designed. Far fewer can show that they operate. A control that exists on paper but produces no trace of execution, no sampling results, no exception reports, no follow-up on anomalies, fails the AFA's test of effectiveness. Your reporting must show each level running: who performed the control, when, on what sample, with what findings, and what happened next.

Evidence of steering

Across its published control findings, the AFA has consistently distinguished between programmes that exist and programmes that are steered. Evidence of steering looks like this: compliance committee minutes showing indicators reviewed and decisions taken; dashboard extracts presented to the executive body; remediation plans with named owners, deadlines, and status updates; a documented trail from "anomaly detected" to "corrective action closed."

Three properties make this evidence defensible: it is timestamped, traceable to a source, and versioned. A risk map dated and approved in March, revised in September after an acquisition, with the revision documented that tells a story of a living programme. An undated spreadsheet of unclear provenance tells the opposite story, whatever its content.

This matters beyond the AFA control itself. If your company ever faces a corruption investigation, the same dashboard extracts and committee minutes become the core of your defence file. This is proof that the organisation was diligent.

The indicators that count

The AFA does not prescribe a fixed list of KPIs, and that is deliberate: indicators must be proportionate to your risk profile. But a clear principle emerges from its recommendations and control practice: a small set of robust indicators per pillar, reviewed at a fixed cadence, beats fifty metrics nobody acts on. As a working rule, aim for a handful of indicators per Article 17 measure, reviewed quarterly by the compliance function and at least annually by the executive body.

Example

Steering indicators

Training coverage of exposed populations, by entity and role

Alert-to-resolution time, and share of alerts investigated within target

Share of active third parties screened — and re-evaluated on schedule

Residual risk trend per scenario since last review

Second-level testing results: pass rate, anomalies, remediation status

Training coverage of exposed populations, by entity and role

Alert-to-resolution time, and share of alerts investigated within target

Share of active third parties screened — and re-evaluated on schedule

Residual risk trend per scenario since last review

Second-level testing results: pass rate, anomalies, remediation status

Example Loi Sapin II Dashboard

From risk map to dashboard: closing the loop

The single most persuasive artefact you can show a controller is not a list of measures. It is a chart showing gross risk, the controls applied, and the resulting net (residual) risk — moving over time.

This is the loop the AFA wants to see closed: the risk map identifies and rates scenarios; action plans are derived from the highest residual risks; the action plans are tracked to completion; and the next review of the risk map shows residual risk actually moving. Each pass around the loop is dated and documented. That trajectory, gross risk stable, controls strengthened, residual risk declining, is the definition of a programme that works.

This is how platforms like Naltilia function: documents and operational data are analysedby AI, outcome is validated by humans, risk scoring is algorithmic and refreshed as the underlying data and action plan completion changes, and the dashboard is fed by evidence of action plan completion. The reporting layer becomes a live view, which is precisely what "pilotage" means.

The CSRD overlap: one dashboard, two obligations

If your company is in scope of the CSRD, your anti-corruption reporting now has a second audience. In October 2024, the AFA published a guide helping companies map their anti-corruption programme to the CSRD's ESRS G1 "business conduct" disclosures, covering, among others, corruption incidents, convictions and fines, training coverage of at-risk functions, and the governance of the anti-corruption system.

Look closely at that list: it is largely the same data your Sapin II dashboard should already contain. Training coverage of exposed populations, incident counts and outcomes, programme governance, collected once, used twice. Companies that structured their compliance data for internal steering are finding CSRD business-conduct disclosure easier to comply with.

Conclusion: build the dashboard before the AFA asks for it

The AFA's expectation is coherent once you see reporting for what it is: the eighth measure of Article 17, the visible proof of the first pillar, and the audit trail for everything in between. A compliance programme that is genuinely steered produces its own evidence as a by-product: dated indicators, documented reviews, tracked remediations. A programme that is not steered can produce that evidence only through reconstruction, and controllers can tell the difference.

The practical takeaway: define a handful of decision-triggering indicators per measure, fix a review cadence, and make sure every data point on your dashboard is timestamped and traceable to its source. Your dashboard is not a reporting chore. It is your programme's testimony.

Frequently Asked Questions

What indicators does the AFA expect for an anti-corruption programme?

The AFA prescribes no fixed list. Indicators must fit your risk profile. In practice, controllers expect a small set of robust indicators per Article 17 measure: coverage of exposed populations for training, screening and re-evaluation rates for third parties, alert handling times for the whistleblowing channel, second-level testing results for internal controls, and residual risk trends from the risk map.

Is a compliance dashboard mandatory under Sapin II?

The word "dashboard" appears nowhere in the law. But Article 17 requires an internal control and evaluation system for the whole programme, and the AFA's recommendations expect top management to steer the programme on the basis of reporting. A dashboard is the practical form that obligation takes.

How often should compliance indicators be reviewed?

A common, defensible cadence: quarterly review by the compliance function, with escalation of anomalies as they arise, and at least annual review by the executive body alongside the risk map update. What matters to the AFA is that the cadence is defined, respected, and documented.

What documents does the AFA request during a control?

Typically: the completed questionnaire, the risk map and its methodology, policies and procedures for each Article 17 measure, training records, third-party evaluation files, alert logs, control plans and testing results, compliance committee and board minutes, and remediation plans with their status. The common thread is evidence of execution and follow-up, not just design.

About the Author

Iratxe Gurpegui

Iratxe Gurpegui

I've spent 20 years as a compliance and competition lawyer across Europe and Latin America, and throughout my career, I've seen firsthand how complex and costly regulations can hold companies back. But I've also learned that compliance doesn't have to be a burden, it can be a strategic advantage. My mission is to help companies harness the power of AI, transforming compliance into something faster, simpler, and most importantly, a real driver of growth for businesses.