Finance Accounting Marketing Human Resources Sales Corporate Governance Technology Startup Procurement Law
Select Page
⚡ TL;DR
An effective competition compliance program has six components: a documented risk assessment, board-level commitment and clear ownership, policies written for the actual risk points, role-targeted training, monitoring and audit that tests reality rather than paperwork, and a rehearsed response capability (leniency, dawn raid, internal investigation). Programs that exist only as a policy PDF fail at every one of those points — and fail at the moment they are needed.

A competition compliance program is the only antitrust investment that pays before anything goes wrong: it prevents infringements, detects the ones that start anyway while leniency is still available, mitigates fines in the regimes that credit it, and — increasingly — determines whether a regulator chooses conduct remedies or structural ones. This guide sets out how to build one that survives contact with reality, opening the compliance pillar of our Global Competition & Antitrust hub.

Disclaimer: This article is general information, not legal advice. Competition rules and notification thresholds vary by jurisdiction and change frequently. Consult qualified competition counsel for your specific transaction or conduct.
Key Takeaways

Where does compliance risk actually concentrate?
Competitor contact points (trade associations, benchmarking, JV boards, ex-rival hires), pricing and discount design in businesses approaching dominance, tender and bidding processes, distribution contracts, and M&A conduct between signing and closing.

Does a compliance program reduce fines?
In the US (Sentencing Guidelines credit), UK, France and increasingly Türkiye, yes; the European Commission traditionally refuses credit for a program that failed. But every regime rewards what a real program produces: earlier detection, faster leniency, and a cooperation posture that shapes the outcome.

What separates real programs from paper ones?
Testing. Real programs audit inboxes and chat channels, run tabletop exercises, screen pricing structures against legal tests, and can produce evidence of all three on demand — paper programs produce a signed acknowledgment form.

Why do companies with policies still commit infringements?

Because policies address the wrong layer. Most infringements are not committed by executives who read the antitrust policy and decided to violate it; they are committed by commercial staff who never mapped their situation onto the rules — the sales manager who joined the industry WhatsApp group, the category manager relaying “what the market is doing”, the tender team who called a competitor to check capacity, the HR director benchmarking salaries with talent rivals.

The failure pattern is consistent across published decisions: rules stated abstractly, training delivered once at onboarding, no owner for the risky channels, no monitoring of the media where the conduct actually lives, and incentive structures pulling the other way. That last point deserves emphasis — bonus plans rewarding “market discipline”, exclusivity wins or price stability are compliance risks written into compensation. A program that never touches incentive design is arguing with the organisation’s own machinery.

How do you run a competition risk assessment?

Start from the business, not the statute. Map each business unit’s market position (share bands, dominance triggers), its competitor-contact channels, its pricing and discount mechanics, its tender exposure, its distribution structure and its M&A activity. Score each intersection for likelihood and impact, and let the top ten cells drive everything else — policy content, training targets, monitoring scope.

Standard high-risk findings: trade-association memberships with no attendance rules; benchmarking or market-intelligence subscriptions of unverified provenance; JV boards where competitors sit; sales incentives tied to share-of-wallet; recurring public tenders in concentrated bidder pools; distribution agreements templated years ago and never re-reviewed as the business grew into dominance; and HR practices exchanging compensation data with talent competitors. Re-run the assessment annually and after any structural change — an acquisition, a market exit, a share jump. The dominance trigger matters most: the same commercial practice can move from unremarkable to actionable purely because the business grew, as our abuse overview explains.

💡 Pro Tip: Build the risk map with commercial leaders in the room, not for them. The single most valuable output of a compliance risk workshop is usually a disclosure — ‘we’ve always called them before bidding’ — surfaced because someone finally described the practice out loud to a lawyer. Those conversations are also privileged if structured properly; structure them properly.

What do the six components look like in practice?

1. Commitment and ownership: a board-approved policy, a named senior owner with budget and access, and — critically — visible reinforcement when compliance costs money (a walked-away deal, a rejected exclusivity offer). 2. Risk-based policies: short, situational documents (“what to do at a trade association meeting”, “how to respond to a competitor’s email”, “tender independence rules”) rather than one long statute summary.

3. Targeted training: sales, procurement, HR, pricing and legal each get scenarios from their own work; refreshed at least annually; delivered by someone who can answer real questions. 4. Monitoring and audit: sampling communications channels, screening pricing and rebate structures against the AEC tests, reviewing tender behaviour, checking association attendance records. 5. Reporting channels: a route to raise concerns without career risk, with documented non-retaliation. 6. Response capability: rehearsed dawn-raid and leniency protocols, pre-mandated external counsel, document-preservation switches — covered in our dawn raid guide and leniency guide.

⚖️ Case Study — Compliance credit becomes real (US DOJ Antitrust Division, 2019–present)

The Antitrust Division reversed its long-standing refusal to credit compliance programs at the charging stage, publishing evaluation guidance and, in cases since, granting deferred prosecution and reduced culpability scores where programs proved genuine. The evaluation questions are the field’s best checklist: Is the program well designed for this company’s actual risks? Applied earnestly and in good faith — resourced, empowered, incentive-aligned? Does it work in practice — did it detect this conduct, and what happened next? Companies that can answer all three with documents, not assertions, now negotiate from materially better positions on both sides of the Atlantic.

THE SIX COMPONENTS OF A WORKING PROGRAM1. COMMITMENTboard policy • named ownerbudget • visible trade-offs2. RISK ASSESSMENTcontacts • pricing • tendersdominance triggers • M&A3. POLICIESshort • situationalwritten for the risk point4. TRAININGrole-specific scenariosannual • tested5. MONITORINGchannel sampling • AEC screenstender + association audits6. RESPONSEraid + leniency protocolsrehearsed, not writtenTest of a real program: can you produce evidence of each component from the last 12 months?
Six components, one test: evidence from the last twelve months, not a binder from three years ago.

How do you make training actually change behaviour?

By replacing law with situations. Nobody remembers Article 101; everybody remembers “a competitor sends you their price list — what do you do in the next ten minutes?” Build the curriculum from your own risk map and, where possible, your own near-misses (anonymised): the association meeting that drifted, the tender call, the benchmarking invitation.

Three design rules improve retention measurably. Role-specific: sales, procurement, HR, pricing, corp-dev and legal each need different scenarios — generic all-staff modules train nobody well. Decision-oriented: end each scenario with the exact action (leave the room, say this sentence, send this email, call this number), because compliance failures are usually failures of knowing what to do, not what is prohibited. Reinforced: short quarterly nudges tied to real events beat annual marathons. And test comprehension, not attendance — the metric regulators ask about is whether people knew what to do, and the answer should be measured.

⚠️ Risk: Training records are discoverable and cut both ways: they evidence a real program, but they also prove the company told employees exactly what was prohibited. That is the correct trade — it converts organisational liability arguments into individual-deviation ones — but it means training content must be accurate. Overbroad prohibitions (‘never talk to competitors’) that staff routinely ignore in practice are worse than useless.

What does monitoring look like beyond the checkbox?

Sampling with teeth. Periodic, privileged review of communications in the highest-risk populations (sales in concentrated markets, tender teams, association delegates) using keyword and pattern screens across email and the messaging apps people actually use — a program that ignores WhatsApp is monitoring the wrong medium. Pricing and rebate structures screened against the cost and AEC tests before launch, with a documented gate for below-cost or loyalty-conditioned designs.

Add bid-pattern analytics where you sell into tenders (your own win/loss patterns tell you what a screener would see), association-attendance logs with agenda review, and an annual contract sweep for exclusivity, parity and information-sharing clauses. The output that matters is a short, honest register of findings and fixes — because the question after any incident is not “did you have monitoring?” but “what did it find, and what did you do?” A monitoring function that has never found anything has never looked.

How do you handle an internal report of possible infringement?

With a pre-designed sequence, because improvisation here destroys options. Route the report immediately to legal under privilege; open a scoped internal investigation with external counsel where the allegation touches cartel conduct; suspend document destruction across relevant custodians the same day; and interview with Upjohn-style warnings so employees understand who counsel represents.

Then take the two decisions that matter: whether the conduct must stop immediately (almost always yes, choreographed so co-participants are not tipped off) and whether to seek leniency in each affected jurisdiction — a board-level call to be made in days. Discipline decisions come later and carefully: acting too fast creates hostile witnesses and independent leniency applicants; acting too slowly reads as ratification. Companies that have written and rehearsed this sequence reach the marker queue while others are still scheduling meetings.

How do you measure whether the program works?

With leading indicators, not incident counts. Useful metrics: training comprehension scores by role (not completion rates); number of drift incidents reported from associations and competitor contacts (rising is good — it means the channel works); percentage of rebate and exclusivity structures screened before launch; time-to-legal for competitor contact reports; results of communications-channel sampling; and drill performance on dawn-raid and leniency scenarios.

Report these to the board annually alongside the risk map’s changes. The narrative that matters is trajectory: risks identified, controls added, incidents surfaced early and closed. That report is also the document you will hand a regulator to evidence good faith — which is a strong argument for writing it as if that day has already arrived.

How do you build compliance into incentives and systems?

By making the compliant path the easy one. Pricing-approval workflows that require a legal gate for below-cost, exclusivity-conditioned or retroactive-rebate designs catch abuse risk before launch. Contract-management systems with dominance-mode clause libraries stop old templates propagating into new market positions. Tender systems that require an independent-bid certification and log competitor contacts create both deterrence and evidence. CRM and expense systems that flag competitor meetings feed the monitoring function automatically.

On incentives, review the compensation plans in the highest-risk populations: bonuses for share-of-wallet exclusivity, “price discipline” targets in concentrated markets, and tender win-rate metrics without independence controls all pay people to take the risks the policy prohibits. Aligning incentives is unglamorous and slow, and it does more to change conduct than any training module — which is precisely why the DOJ’s evaluation questions ask about it directly.

Frequently Asked Questions

How much should a program cost?

Proportionate to risk, not revenue: a mid-size industrial group with tender exposure and trade-association activity needs materially more than a low-share consumer business. Benchmark against the exposure our fine arithmetic guide computes — programs cost a small fraction of a single infringement’s total cost.

Who should own competition compliance?

Legal, with a named senior business sponsor. Pure legal ownership without business sponsorship produces paper; business ownership without legal produces confident errors. Both need direct board access for escalation.

Does certification (ISO 37301 etc.) help?

Marginally with regulators, more with counterparties and boards. No authority accepts certification as a defence, but the discipline of an external audit cycle does improve programs — provided the audit tests substance, not documentation completeness.

How do we handle a group with many jurisdictions?

Build one global framework at the strictest common standard (usually EU/Türkiye-level), with local overlays for criminal exposure (US, UK), local reporting duties and language. Divergent per-country programs create the gaps infringements grow in.

Last Updated: August 2026 · Reviewed by the Kurums Law editorial team.

Discover more from Kurums | Business Intelligence

Subscribe to get the latest posts sent to your email.

Discover more from Kurums | Business Intelligence

Subscribe now to keep reading and get access to the full archive.

Continue reading

Discover more from Kurums | Business Intelligence

Subscribe now to keep reading and get access to the full archive.

Continue reading