Skip to content

Evidence request lists

French Sapin II Law (Law No. 2016-1691)

Evidence request list. 14 controls, 14 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 11 September 2026. Published by The Art of Service.

Sapin II: AFA Inspection, Sanctions and Convention Judiciaire d'Interet Public (CJIP)

Sapin2-AFA-Inspection-Sanctions
Agence Francaise Anticorruption (AFA) Inspection Powers and Sanctions

Sapin II Article 1-5 - Agence Francaise Anticorruption (AFA). The AFA is an INDEPENDENT ADMINISTRATIVE AUTHORITY established by Sapin II + reports to the Minister of Justice + Minister of Finance + headed by a Director nominated by Presidential Decree. AFA MISSIONS: (a) ASSISTING public authorities + companies in prevention of corruption + influence peddling + extortion; (b) ELABORATING + PUBLISHING RECOMMENDATIONS on anti-corruption programs + best practices; (c) INSPECTING + ASSESSING the anti-corruption compliance programs of companies + public bodies; (d) ENFORCEMENT through administrative sanctions + judicial referral. INSPECTION POWERS: AFA inspectors may visit company premises + request documents + interview personnel + inspect IT systems + audit programs + observe operations; inspections typically last 6-12 MONTHS + result in an INSPECTION REPORT with findings + recommendations +

Artefacts an auditor will ask for
  • AFA inspection readiness program + mock inspections
  • Sanctions risk assessment
  • Inspection response playbook + counsel engagement
Where this commonly fails
  • AFA inspection unprepared
  • Sanctions risk under-assessed
  • Chief executive personal liability not communicated
Sapin2-CJIP-Settlements
Convention Judiciaire d'Interet Public (CJIP) - Deferred Prosecution Agreement

Convention Judiciaire d'Interet Public (CJIP) - Article 41-1-2 of the Code of Criminal Procedure. CJIP is the French equivalent of US Deferred Prosecution Agreement (DPA) introduced by Sapin II in 2016 + extended by the Loi de Lutte contre la Fraude (Fraud Law) of 23 October 2018. PROCESS: (a) the Prosecutor (Procureur de la Republique) + the National Financial Prosecutor (Procureur National Financier, PNF) may PROPOSE a CJIP to a legal entity facing corruption + tax-fraud + money-laundering + insider-trading + market-manipulation charges; (b) the legal entity may accept or reject; if accepted + the CJIP includes (i) FINE up to 30% of average annual turnover for last 3 fiscal years; (ii) JUDICIAL MONITORSHIP up to 3 years with AFA monitor; (iii) VICTIM COMPENSATION; (iv) ADMISSION of facts (not of guilt - distinct from US plea); (v) IMPLEMENTATION OBLIGATION of a Sapin II-aligned complia

Artefacts an auditor will ask for
  • CJIP negotiation playbook
  • Compliance program AFA-alignment
  • Monitorship engagement procedure
  • Cross-border DPA coordination
Where this commonly fails
  • CJIP eligibility miscalculated
  • Compliance program insufficient for CJIP
  • Monitorship resistance

Sapin II: HATVP Lobbying Register, Coordination with EU Whistleblower Directive + CSDDD + Status

Sapin2-Coordination-FCPA-UKBA-ISO37001
Coordination with FCPA, UK Bribery Act, ISO 37001, OECD Anti-Bribery Convention and UNCAC

Sapin II coordination with international anti-corruption frameworks. US FCPA (Foreign Corrupt Practices Act, 15 USC 78dd-1 + 78dd-2): US extraterritorial anti-bribery law + may apply to French entities listed on US exchanges or doing business with US persons; CJIPs frequently negotiated jointly with US DOJ + SEC. UK BRIBERY ACT 2010: UK anti-bribery regime including OFFENCE OF FAILURE TO PREVENT BRIBERY (S.7) similar to Sapin II Article 17; UK Serious Fraud Office (SFO) DPAs frequently negotiated alongside French CJIPs. ISO 37001:2025 ANTI-BRIBERY MANAGEMENT SYSTEMS - revised version expected 2025 (current is ISO 37001:2016): voluntary international standard providing structured anti-bribery management system; certification available + recognized by AFA. OECD ANTI-BRIBERY CONVENTION (1997): foundational international convention requiring criminalization of foreign-official bribery + extr

Artefacts an auditor will ask for
  • Cross-border coordination playbook
  • ISO 37001 implementation if applicable
  • International cooperation engagement
  • EU Directive tracking
Where this commonly fails
  • FCPA + UKBA exposure not addressed
  • ISO 37001 mentioned but not implemented
  • International cooperation absent
  • EU Directive not tracked
Sapin2-HATVP-Lobbying
HATVP Lobbying Register, Public Officials Transparency and EU Coordination

Haute Autorite pour la Transparence de la Vie Publique (HATVP) - High Authority for Transparency in Public Life. ESTABLISHED by Sapin I (Loi 2013-907 of 11 October 2013) + EXTENDED by Sapin II to include the LOBBYING REGISTER (Repertoire numerique des representants d'interets). LOBBYING REGISTER: all NATURAL + LEGAL persons engaging in INFLUENCE ACTIVITY on national + local public decision-makers must register + declare lobbying activity + budget + clients + topics + frequency. SCOPE: covers Parliamentary lobbying + government lobbying + senior civil servant lobbying + judicial lobbying + military lobbying + EU Permanent Representation lobbying. REPORTING: annual declarations + per-lobbying-meeting records + sanctions for non-compliance up to EUR 75,000 + criminal sanctions for false declarations. EU COORDINATION: HATVP shares data with the EU Transparency Register (joint Parliament + Co

Artefacts an auditor will ask for
  • Lobbying registration + declarations
  • Per-meeting records
  • Conflict-of-interest declarations
  • EU coordination evidence
Where this commonly fails
  • Lobbying registration missing
  • Declarations incomplete
  • Conflict-of-interest assessment skipped
  • EU coordination ad-hoc
Sapin2-Status-Waserman-CSDDD-AI
Sapin II Status, Waserman Whistleblower Reform 2022, CSDDD Coordination and 2024-2025 Pipeline

Sapin II status + Waserman + CSDDD coordination. STATUS: Sapin II Loi 2016-1691 of 9 December 2016 in force since 2016 + extensively amended including by the Waserman Law 2022-401 (21 March 2022 - whistleblower regime overhaul transposing EU Whistleblower Directive 2019/1937); the Fraud Law of 23 October 2018 (CJIP extension); the PACTE Law 2019-486 (22 May 2019 - simplified compliance for SMEs); the Climate-Resilience Law 2021-1104 (climate-corruption nexus). 2024-2025 PIPELINE: (a) PROPOSED SAPIN III (early-stage parliamentary discussion) - potential expansion of AFA powers + extraterritorial reach + new sectoral provisions; (b) EU CORPORATE SUSTAINABILITY DUE DILIGENCE DIRECTIVE (CSDDD, Directive (EU) 2024/1760) - in force July 2024 with phased transposition deadlines 2027 + 2028 + 2029 - extends due-diligence obligations to human-rights + environmental impacts in addition to anti-cor

Artefacts an auditor will ask for
  • Sapin II amendment tracking
  • CSDDD readiness plan
  • Sapin III legislative monitoring
  • AFA Recommendations adoption
Where this commonly fails
  • Amendments not tracked
  • CSDDD readiness gap
  • Sapin III not anticipated
  • AFA Recommendations outdated

Sapin II: Pillars 1+2 - Code of Conduct and Internal Whistleblowing System (Waserman Reform 2022)

Sapin2-Pillar1-Code-of-Conduct
Pillar 1 - Anti-Corruption Code of Conduct

Sapin II Pillar 1 - Anti-Corruption Code of Conduct (Code de conduite). REQUIREMENTS: a documented + formally-adopted Code of Conduct articulating: (a) prohibited behaviour (active + passive corruption + influence peddling + facilitation payments + foreign-official bribery + gifts + hospitality + sponsorship + political contributions thresholds); (b) the company's commitment to anti-corruption + ethical conduct; (c) the consequences of breach (disciplinary regime); (d) the whistleblowing channels + protections; (e) decision-making authority + escalation; (f) integration into employment contracts + Internal Regulations (Reglement interieur per French Labour Code Art. L. 1321-1) via Article 17 II.1 explicit reference. ADOPTION + COMMUNICATION: must be communicated to ALL EMPLOYEES + acknowledged + posted prominently; must be translated into local languages for foreign subsidiaries; must be

Artefacts an auditor will ask for
  • Code document + Board minutes
  • Acknowledgement registry
  • Translation evidence
  • Annual review records
Where this commonly fails
  • Code generic or stale
  • Communication gaps
  • Translation missing for foreign subsidiaries
  • Annual review skipped
Sapin2-Pillar2-Whistleblowing-Waserman
Pillar 2 - Internal Whistleblowing System (Waserman Reform 2022)

Sapin II Pillar 2 - Internal Whistleblowing System AS REVISED BY THE WASERMAN LAW (Loi 2022-401 du 21 mars 2022) transposing EU Whistleblower Directive 2019/1937. REQUIREMENTS: (a) DEDICATED CHANNEL for employee + temporary + contractor + alumni + suppliers + applicants to report concerns about prohibited conduct + violations of law + fundamental ethical principles; (b) CONFIDENTIAL HANDLING with anonymous option; (c) DEDICATED HANDLER (referent or compliance officer) with adequate independence + authority + resources; (d) ACKNOWLEDGEMENT within 7 DAYS of receipt + INVESTIGATION within reasonable time + RESPONSE within 3 MONTHS (extendable for complex cases); (e) PROTECTIONS for whistleblowers - no retaliation + reverse burden of proof in retaliation cases (employer must prove decision not motivated by report) + provisional measures + interim suspension reversal + statutory civil + crimi

Artefacts an auditor will ask for
  • Whistleblowing channel + handler designation
  • Acknowledgement + response SLA tracking
  • Anti-retaliation training
  • External channel coordination
Where this commonly fails
  • Channel limited to employees (Waserman extends to alumni + applicants)
  • Handler conflicted or under-resourced
  • SLA missed
  • Anti-retaliation training absent

Sapin II: Pillars 3+4 - Corruption Risk Mapping and Third-Party Due Diligence

Sapin2-Pillar3-Risk-Mapping
Pillar 3 - Corruption Risk Mapping (Cartographie des Risques)

Sapin II Pillar 3 - Corruption Risk Mapping (Cartographie des risques de corruption). REQUIREMENTS: a documented + risk-based + regularly-updated MAPPING of corruption risks across the organization. METHODOLOGY: (a) IDENTIFICATION of corruption risks per business activity + geography + counterparty + transaction type + product/service line; (b) ASSESSMENT of likelihood + impact (typically 4-tier scale very-low / low / medium / high + 4-tier impact financial / legal / reputational / operational); (c) RISK SCORING + heat map; (d) MITIGATION measures per risk; (e) RESIDUAL risk tracking; (f) ANNUAL REVIEW + after major events. AFA-PREFERRED FEATURES: workshop-based with cross-functional teams (business + legal + audit + finance); per-third-party scoring incorporating Transparency International Corruption Perception Index; integration with risk-based due diligence (Pillar 4); board reporting

Artefacts an auditor will ask for
  • Risk-mapping document + methodology
  • Cross-functional workshop minutes
  • Mitigation tracker
  • Board reporting evidence
Where this commonly fails
  • Risk mapping shallow or generic
  • Mitigation absent
  • Annual review skipped
  • Board awareness gap
Sapin2-Pillar4-ThirdParty-DueDiligence
Pillar 4 - Third-Party Due Diligence (Clients, Suppliers, Intermediaries, M&A)

Sapin II Pillar 4 - Third-Party Due Diligence (Evaluations integrite des tiers). REQUIREMENTS: a risk-based due-diligence procedure for THIRD PARTIES including: (a) CLIENTS (especially government clients + politically-exposed persons + high-risk jurisdictions); (b) SUPPLIERS + VENDORS; (c) INTERMEDIARIES + agents + consultants + distributors; (d) JOINT VENTURE partners; (e) M&A targets (acquired entities); (f) AGENTS + CONSULTANTS providing introductions or advocacy services. METHODOLOGY: per-third-party RISK SCORING (geography + sector + transaction nature + counterparty type + government-touchpoints); SANCTIONS + WATCHLIST screening (OFAC + EU + UN + UK HMT + France DGT + sectoral lists); ADVERSE MEDIA screening; ULTIMATE BENEFICIAL OWNER (UBO) verification; INTERVIEWS + questionnaires; SIGNED ANTI-CORRUPTION CERTIFICATIONS in contracts; PERIODIC REFRESH (annual for high-risk + 3-year

Artefacts an auditor will ask for
  • Due diligence procedure + records per third party
  • Sanctions screening tool + UBO records
  • Anti-corruption clauses in contracts
  • M&A diligence checklist + post-close assessments
Where this commonly fails
  • Third-party DD ad-hoc or risk-blind
  • Sanctions screening not refreshed
  • Contract clauses missing
  • M&A integrity DD skipped

Sapin II: Pillars 5+6 - Accounting Control Procedures and Anti-Corruption Training

Sapin2-Pillar5-Accounting-Controls
Pillar 5 - Accounting Control Procedures (Specific Anti-Corruption Controls)

Sapin II Pillar 5 - Accounting Control Procedures (Controles comptables specifiques). REQUIREMENTS: ENHANCED + ANTI-CORRUPTION-SPECIFIC accounting controls IN ADDITION TO routine financial controls: (a) GIFTS + HOSPITALITY + SPONSORSHIP + DONATIONS RECORDS + threshold-driven approval + tracking (typical thresholds EUR 100-500 for gifts + EUR 500-2000 for hospitality); (b) AGENT + INTERMEDIARY PAYMENTS tracking + justification + invoice matching + approval workflow; (c) PETTY CASH controls + thresholds + documentation; (d) HIGH-RISK PAYMENT JURISDICTIONS (countries of concern) + watchlist controls; (e) UNUSUAL or off-pattern payment detection (e.g. round-number + back-dated + last-minute approvals); (f) CONSULTANT + ADVISER FEES proportionality assessment; (g) CONFERENCE + EVENT SPONSORSHIP transparency; (h) POLITICAL CONTRIBUTIONS tracking (prohibited in many contexts under Sapin II). AU

Artefacts an auditor will ask for
  • G+H+S+D register + approvals
  • Agent/intermediary payment register
  • Anomaly detection rules + alerts
  • Audit trail evidence
Where this commonly fails
  • G+H+S+D thresholds unenforced or missing
  • Agent payments without justification
  • Anomaly detection absent
  • Audit trail incomplete
Sapin2-Pillar6-Training
Pillar 6 - Anti-Corruption Training Program

Sapin II Pillar 6 - Anti-Corruption Training (Programmes de formation). REQUIREMENTS: (a) GENERAL AWARENESS training for ALL employees (typically online + 30-60 minutes + annual refresh); (b) ROLE-SPECIFIC training for high-risk positions (Sales + Procurement + Finance + Government Affairs + HR + Senior Management) with case studies + decision exercises; (c) BOARD-LEVEL briefing on legal regime + AFA expectations + corruption-incident response; (d) ENHANCED training for high-risk geographies + business lines; (e) NEW-HIRE training within reasonable onboarding window; (f) POST-INCIDENT + post-AFA-inspection refreshers; (g) METRICS - completion rates + knowledge-check pass rates + manager attestations + correlation with risk-event frequency. CONTENT FRAMEWORK: integrate Code of Conduct + risk mapping outputs + whistleblowing channel + third-party DD + accounting controls + sanctions regime

Artefacts an auditor will ask for
  • Training program + curriculum
  • Completion + pass rate metrics
  • Mandatory completion enforcement evidence
  • Content review + sector adaptation records
Where this commonly fails
  • Training only at onboarding or one-off
  • Role-specific gaps
  • Metrics not tracked
  • Content outdated

Sapin II: Pillars 7+8 - Disciplinary Regime and Internal Monitoring and Continuous Improvement

Sapin2-Pillar7-Disciplinary-Regime
Pillar 7 - Disciplinary Regime for Anti-Corruption Violations

Sapin II Pillar 7 - Disciplinary Regime (Regime disciplinaire). REQUIREMENTS: a documented disciplinary regime in the Internal Regulations (Reglement interieur per French Labour Code Art. L. 1321-1) covering: (a) PROHIBITED CONDUCT - active + passive corruption + facilitation payments + influence peddling + gifts above thresholds + retaliation against whistleblowers + obstruction of investigations + failure to cooperate with AFA inspection; (b) SANCTIONS LADDER from verbal warning to dismissal for serious misconduct (faute grave) + dismissal for very serious misconduct (faute lourde); (c) INVESTIGATION PROTOCOL with HR + legal + compliance involvement + due process + employee defense rights per French Labour Code; (d) DOCUMENTATION + chain-of-command + decision rationale + sanction proportionality; (e) APPEALS to employer representatives + Conseil des Prud'hommes (labour court); (f) APPL

Artefacts an auditor will ask for
  • Reglement interieur with anti-corruption provisions
  • Investigation playbook + records
  • Sanction decisions documented
  • Consistent application across levels
Where this commonly fails
  • Reglement interieur silent on anti-corruption
  • Investigation ad-hoc
  • Sanctions inconsistent or absent for senior management
Sapin2-Pillar8-Internal-Monitoring
Pillar 8 - Internal Monitoring and Continuous Improvement

Sapin II Pillar 8 - Internal Monitoring + Continuous Improvement (Dispositif de controle et evaluation interne). REQUIREMENTS: (a) ONGOING MONITORING through KPIs + KRIs + dashboards + management reviews + audit committee briefings; (b) PERIODIC INTERNAL AUDITS of the 8-pillar program + sample testing of controls; (c) THIRD-PARTY ASSESSMENT - at least annual + after major incidents + by external consultants where appropriate; (d) MANAGEMENT REVIEW - the chief executive + Board of Directors must review program performance annually with documented findings + corrective actions; (e) CONTINUOUS IMPROVEMENT - lessons-learned from incidents + audits + AFA feedback + regulatory developments + industry benchmarks (e.g. OECD Anti-Bribery Convention + UNCAC + ISO 37001) drive program updates; (f) MATURITY ASSESSMENT against AFA Recommendations + benchmarks (e.g. ISO 37001 + COSO + SCCE); (g) BENCH

Artefacts an auditor will ask for
  • Monitoring dashboard + reports
  • Internal audit + 3rd-party assessment reports
  • Management review minutes + action tracker
  • Maturity assessment results
Where this commonly fails
  • Monitoring lagging or unaudited
  • No external assessment
  • Management review pro-forma without action
  • Maturity assessment absent

Sapin II: Scope, Applicability Thresholds (500 employees / EUR 100M) and Article 17 8-Pillar Program

Sapin2-Art17-Scope-Program
Article 17 - 8-Pillar Anti-Corruption Compliance Program Scope and Applicability

Sapin II Article 17. SCOPE + APPLICABILITY: applies to (a) French companies + groups (including French subsidiaries of foreign groups) with AT LEAST 500 EMPLOYEES + AT LEAST EUR 100 MILLION ANNUAL TURNOVER (consolidated for groups); (b) public officials + appointees of state-owned enterprises; (c) elected officials per HATVP. 8-PILLAR MANDATORY PROGRAM: (1) Code of Conduct; (2) Internal Whistleblowing System; (3) Corruption Risk Mapping (cartographie); (4) Third-Party Due Diligence; (5) Accounting Control Procedures; (6) Anti-Corruption Training; (7) Disciplinary Regime; (8) Internal Monitoring + Assessment. PROGRAM OWNERSHIP: must be approved by + reported to the Board of Directors + the chief executive; the chief executive bears personal responsibility for the program implementation + the AFA may impose individual sanctions. AFA RECOMMENDATIONS: detailed guidance on each pillar (most r

Artefacts an auditor will ask for
  • Threshold assessment + corporate structure
  • 8-pillar program charter + Board approval
  • Chief executive sign-off
  • AFA Recommendations gap analysis
Where this commonly fails
  • Threshold assessment outdated or wrong scope
  • Pillars implemented superficially without Board oversight
  • Chief executive uninvolved
  • AFA Recommendations not adopted or applied
Assembled from the framework's own control set. Every line traces to a control in the graph, so this pack is regenerated rather than written, and stays current as the graph does.

Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the French Sapin II Law (Law No. 2016-1691) framework page.