EU Regulatory Domain
Directive (EU) 2026/1021 on combating corruption: harmonised offences, corporate liability and a role for compliance programmes.
Key facts
Member States must transpose the core provisions of Directive (EU) 2026/1021 by 1 June 2028.
Maximum fines for companies must reach at least 5% of worldwide turnover or EUR 40 million for the most serious offences.
Effective internal controls and compliance programmes are relevant mitigating factors when penalties are determined.
In Portugal, public and private entities with 50 or more workers must already adopt a regulatory compliance programme.
Directive (EU) 2026/1021 of 29 April 2026 on combating corruption was published in the Official Journal on 11 May 2026. It replaces Framework Decision 2003/568/JHA and establishes, for the first time, a comprehensive EU criminal-law framework against corruption in the public and private sectors. Member States must transpose its core provisions by 1 June 2028, and the provisions on national strategies and risk assessments by 1 June 2029.
harmonised offences: including bribery in the public and private sectors, misappropriation, trading in influence, abuse of functions and obstruction of justice;
liability of legal persons: companies can be held liable for offences committed for their benefit by persons in leading positions, or made possible by a lack of supervision;
corporate fines: maximum fines of at least 5% of worldwide turnover or EUR 40 million for the most serious offences, and at least 3% or EUR 24 million for the others;
compliance programmes: effective internal controls and compliance programmes are relevant mitigating factors when penalties are determined;
prevention: national anti-corruption strategies, specialised bodies, risk assessments and awareness measures.
An effective, documented and tested compliance programme becomes a relevant factor when penalties are determined, across the whole Union. Programmes should include a corruption risk assessment, a code of conduct, controls on gifts, hospitality and conflicts of interest, due diligence on third parties and intermediaries, a reporting channel, training and periodic review.
Portugal's General Regime for the Prevention of Corruption (RGPC), annexed to Decree-Law 109-E/2021, already requires public and private entities with 50 or more workers to adopt a regulatory compliance programme, consisting of:
a risk prevention plan: covering corruption and related offences, with interim and annual assessment reports;
a code of conduct: with the applicable disciplinary consequences;
a training programme: for managers and staff;
a whistleblowing channel: under Law 93/2021;
a person responsible for regulatory compliance: acting independently, permanently and with decision-making autonomy.
The National Anti-Corruption Mechanism (MENAC) supervises the regime and applies penalties. Law 37/2026, in force since 1 September 2026, reinforced MENAC's powers.
ISO 37001 on anti-bribery management systems provides a recognised structure for designing and certifying the programme.
Compliance Assessment: a corruption risk assessment and review of the compliance programme;
Implementation Kits: the risk prevention plan, code of conduct and reporting templates;
Fractional Compliance Officer: technical support to the person responsible for regulatory compliance;
Training & Capacity: the training programme the law requires.
Related domains: Whistleblower Protection · Anti-Money Laundering · Third-Party & Supply Chain · Corporate Governance
Official text: Directive (EU) 2026/1021 on EUR-Lex
General information as of October 2026; it does not constitute legal advice. Confirm the applicable requirements with the competent authorities.
Related domains
Request a free corruption risk assessment and review of your compliance programme.