A technology company with 80 employees and rapid growth lost a federal contract worth R$4 million because it had no documented compliance program. The public buyer required proof of an active whistleblowing channel and a signed code of conduct. The company had neither. The contract went to a smaller competitor, with lower revenue, but with its program in order.
This is not an isolated case. It’s the new normal.
TL;DR
- A compliance program is not a drawer full of documents: it’s a set of active, auditable controls.
- The four minimum viable components are: (1) code of conduct, (2) independent whistleblowing channel, (3) third-party due diligence, and (4) documented training.
- Law 12.846/2013 (the Brazilian Anti-Corruption Law) and the FCPA (Foreign Corrupt Practices Act) don’t require a company to be large — they require the company to contract with the government or have a foreign partner.
- The absence of a program is not neutral: in investigations, the lack of compliance is an aggravating factor, not an ordinary circumstance.
- An anonymous, independent whistleblowing channel is a minimum requirement in public tenders and institutional investor due diligence.
Updated on 06/18/2026
Table of Contents
- What a minimum viable compliance program is (and what it isn’t)
- Whistleblowing channel: why it’s indispensable and how to implement it
- Third-party due diligence: compliance’s weakest link
- Frequently Asked Questions
- Speak with a lawyer
What a minimum viable compliance program is (and what it isn’t)
Regulatory compliance is not a cost — it’s risk management.
The most common mistake made by startups and SMEs is confusing compliance with large-company bureaucracy: a 200-page manual nobody reads, a policy that was mentioned in the onboarding email and never appeared again. That’s not a compliance program — it’s the appearance of compliance, and appearance doesn’t protect you.
A minimum viable program has four functional components:
- Code of conduct — clear rules on conflicts of interest, gifts and hospitality, relationships with public officials, use of company resources, and data protection. It should be short enough to be read, specific enough to be followed, and signed by all employees with a dated record.
- Independent whistleblowing channel — a mechanism allowing the reporting of irregularities without the whistleblower having to identify themselves to their direct manager. Independence is the key point: an email channel managed by the company’s own HR department doesn’t count as independent.
- Third-party due diligence — a documented process for vetting business partners, suppliers, and agents before entering into a contract. This is covered in Section 3, given its specific weight.
- Recorded training — at least one annual training cycle on the code of conduct, with an attendance sheet or digital record. Without a record, the training didn’t happen for audit purposes.
What the minimum viable program does not (yet) include
- Formal internal audits with a dedicated team (this is the next stage, for growing companies)
- An ethics committee with quarterly meetings (relevant from a certain size or in regulated sectors)
- ISO 37001 certification (excellent for international contracts, but not a starting point)
Law 12.846/2013 (the Brazilian Anti-Corruption Law) lists the elements of an integrity program in Decree 11.129/2022 and in sector-specific regulations. For contracts with the federal public sector, the program must be demonstrable — not merely declared.
For companies with operations or partners in the United States or the United Kingdom, the FCPA (Foreign Corrupt Practices Act) and the UK Bribery Act come into play, with even more detailed due diligence and documentation requirements.
Editorial case
A software company with 40 employees was undergoing a vendor qualification process for a European multinational. The buyer’s due diligence included a compliance questionnaire with 27 questions on internal controls, anti-bribery policy, and whistleblowing channel. The company had none of these elements documented. The engagement focused on building the program in stages: a simplified code of conduct in the first round, engaging an independent whistleblowing channel provider, and an anti-bribery policy aligned with the UK Bribery Act. The qualification process resumed in the following round with the program documented at an initial stage.
Whistleblowing channel: why it’s indispensable and how to implement it
The whistleblowing channel is the compliance component most frequently missing — and the one most frequently requested first.
Federal public tenders (based on Law 12.846/2013 and Decree 11.129/2022), contracts with companies in the financial sector regulated by the Central Bank of Brazil (Banco Central do Brasil, or BCB), and due diligence processes run by private equity or venture capital funds usually ask for evidence of an active channel before any other document.
Why independence matters
An internal whistleblowing channel — managed by HR, legal, or any other department within the company — creates a psychological barrier to reporting. The employee knows, or suspects, that the report will reach their manager. The result: underreporting. Irregularities that could have been contained internally grow into external problems (fines, investigations, reputational crises).
Operational independence means the channel is managed by a specialized third party, with reports going directly to the board or the partner responsible for compliance, without intermediate filtering.
How to implement it in stages
| Stage | What to do | Estimated time |
|---|---|---|
| 1 | Define who receives reports (minimum committee: CEO + legal, or the board, if there is one) | 1 week |
| 2 | Engage an independent whistleblowing channel platform (affordable options exist for SMEs, with monthly plans) | 2 weeks |
| 3 | Communicate the channel’s existence to all employees, third parties, and partners (email + contract) | Ongoing |
| 4 | Define the investigation protocol: who investigates, response deadline to the whistleblower, recordkeeping | 1 week |
| 5 | Document the first operational cycle (even with no reports received, operation requires a record) | Quarterly |
What the channel does not do
The whistleblowing channel does not replace an investigation policy. Receiving a report without investigating it and documenting the closure of each case creates greater risk than not having a channel at all: it demonstrates awareness of the irregularity without corrective action.
Third-party due diligence: compliance’s weakest link
Most corporate corruption cases investigated by the Federal Prosecutor’s Office (Ministério Público Federal, or MPF) and the Office of the Comptroller General (Controladoria-Geral da União, or CGU) over the past ten years involve intermediaries: sales agents, consultants, distributors, formal or informal lobbyists.
The pattern is well known: the company doesn’t pay the bribe directly — it hires a third party who “handles the problem” and gets paid for it. Under the law, this isn’t a mitigating factor. Both Law 12.846/2013 and the FCPA establish strict liability for the company for acts committed by third parties acting on its behalf, even without an explicit instruction.
What third-party due diligence needs to verify
The minimum verification for suppliers and partners who interact with government clients or act as intermediaries in contracts should cover:
- Legal existence and tax compliance (CNPJ lookup, tax clearance certificates)
- Sanctions history (CEIS — Register of Barred and Suspended Companies; CNEP — National Register of Sanctioned Companies; OFAC lists for operations with a U.S. component)
- Reputation through open sources (structured search across public databases, not just Google)
- Whether compensation is consistent with the service provided (above-market commissions are a red flag)
- Confirmation that the third party has its own compliance program (or at least a signed anti-bribery policy)
Risk proportionality
Not every supplier needs the same level of scrutiny. A risk-proportional due diligence methodology classifies partners into three tiers:
| Tier | Partner profile | Verification |
|---|---|---|
| High risk | Sales agent for the public sector, intermediary in government contracts, partner in a high-risk country (Transparency International’s Corruption Perceptions Index below 50) | Full due diligence with a documented report |
| Medium risk | Recurring supplier with no contact with the public sector | Simplified checklist + sanctions database check |
| Low risk | One-off supplier, standardized service, no access to sensitive information | Basic tax compliance verification |
Frequency
Due diligence is not a one-time check at the time of contracting. Long-term partnerships require periodic reassessment — at least annually for high-risk partners, and whenever there is a change of corporate control at the third party.
Frequently Asked Questions
My company is small. Does the Anti-Corruption Law apply to me?
Law 12.846/2013 applies to every legal entity, regardless of size, that commits harmful acts against domestic or foreign public administration. Company size is not a criterion for exclusion — it’s a factor in determining the severity of the penalty. What changes with size is the expected depth of the program: a microenterprise doesn’t need a formal ethics committee, but it does need a documented anti-bribery policy if it contracts with the government.
For companies that export or have partners in the United States, the FCPA may also apply even if the company is Brazilian and small. The FCPA’s trigger is not company size — it’s the connection to the U.S. financial system or the presence of any element of U.S. territorial jurisdiction.
This is general information and does not replace an analysis of your specific case with a lawyer.
What’s the difference between a compliance program and an integrity program?
In Brazilian business law practice, the two terms are often used interchangeably. The more precise distinction: “integrity program” (“programa de integridade”) is the term used by Law 12.846/2013 and Decree 11.129/2022 to designate the set of internal mechanisms for preventing, detecting, and remedying deviations, irregularities, and unlawful acts against public administration.
“Compliance” is the broader term, which also covers conformity with sector-specific regulation (the LGPD — Brazil’s data protection law, similar in spirit to the GDPR, but with its own specific requirements —, rules from the Central Bank of Brazil, rules from the Securities and Exchange Commission of Brazil — Comissão de Valores Mobiliários, or CVM —, among others) and with international standards (FCPA, UK Bribery Act). An integrity program is, therefore, one component of a broader compliance program.
For practical purposes: when a public tender asks for a “programa de integridade,” it’s asking for the minimum set required under Law 12.846/2013. When a foreign investor asks for a “compliance program,” the requirement is broader.
This is general information and does not replace an analysis of your specific case with a lawyer.
What happens if a company is investigated without having a compliance program?
Law 12.846/2013 establishes strict liability — a company can be held liable regardless of intent or negligence. Administrative penalties include fines ranging from 0.1% to 20% of gross revenue from the last fiscal year, in addition to mandatory publication of the conviction decision.
The existence of an effective integrity program is expressly provided for as a penalty-reduction factor under Decree 11.129/2022. This means the absence of a program isn’t merely the loss of a potential benefit: in the event of an investigation, the lack of a program can be used to demonstrate that the company failed to adopt preventive measures, which affects both the severity of the penalty and the negotiation of a leniency agreement with the Office of the Comptroller General (CGU) or the Federal Prosecutor’s Office (MPF).
For companies undergoing an IPO (initial public offering) or an investment round with formal due diligence, the absence of a program can also stall or increase the cost of the deal.
This is general information and does not replace an analysis of your specific case with a lawyer.
Speak with a lawyer
If your company is going through a public tender process, investor due diligence, or expansion into regulated markets, and doesn’t yet have a structured compliance program, the starting point is an assessment of where you stand and what needs to be built first.
You don’t need everything at once — you need what your current business stage requires, in an auditable form.
Alessandra De Paula Souza — OAB/PR 31.133
Practice focused on regulatory compliance, integrity programs, and risk management.
This is general information and does not replace consulting a lawyer for an analysis of your specific case. The content of this article is for educational purposes only and does not constitute legal advice.