On 9 July 2026, the Sanctions Committee of the French Anti-Corruption Agency (AFA) imposed, for the first time since its establishment, a financial penalty on a company and its legal representative for breach of the obligations set out in the Law of 9 December 2016, on transparency, the fight against corruption, and the modernization of economic life, known as the Sapin 2 law.[1]
Following an audit conducted between June 2024 and July 2025 within SAS V. Investissements and all of its subsidiaries or controlled entities, the AFA identified seven breaches out of the eight obligations set forth in Article 17 of the Sapin 2 law. It thus found the absence, within one subsidiary, of an anti-corruption risk mapping, a code of conduct and a disciplinary regime as well as the absence of procedure for evaluating third parties (customers, suppliers, intermediaries), of anti-corruption accounting controls, of training for personnel most exposed to corruption risks, and of an internal control and evaluation system. [2]
On 26 September 2025, after notifying the company of the final audit report setting out these seven findings, together with twenty-six observations and nine recommendations, the AFA’s director referred the matter directly to the Sanctions Committee for the purpose of imposing sanctions.[3]
This referral differs from the two previous referrals that resulted in a decision, in which the Committee had been seized for the purpose of ordering the companies concerned to comply and, in the event of non-compliance with the decision, of imposing financial penalties, which were ultimately not imposed.[4]
In this case, having found that the alleged breaches were established, the Committee imposed a financial penalty of €350,000 on the company and €60,000 on its executive, thereby making use of the direct penalty provision for the first time, nearly ten years after the adoption of the Sapin 2 law and the creation of the AFA.[5]
Given the nature and particular sensitivity of the industry in which the company concerned operates, the Committee decided to publish its decision in an anonymized form, considering that disclosure of the names would be likely to cause disproportionate harm to the company and its representative.[6]
The decision is, firstly, of procedural interest. By establishing in practice the procedure for direct referral for the purpose of imposing sanctions, and by setting the date of the AFA’s audit, rather than the date on which the sanction is imposed, as the relevant date for assessing the breaches, the Committee clarifies the framework within which it may impose financial sanctions (I).
Furthermore, the Committee ruled on the merits of the case and, having found that the allegations were substantiated, imposed a financial penalty on the company and its executive, holding him personally liable alongside the company (II).
I. The committee, seized for the first time for the purpose of imposing a direct sanction, sets the date for assessing the breaches as the date of the AFA’s audit
A. The committee rules on the first referral by the AFA for the purpose of imposing sanctions
From a procedural standpoint, the Committee first ruled on the admissibility of its referral by the AFA’s director for the purpose of imposing a sanction. This referral raised a novel issue concerning the possibility of referring a matter directly to the Committee with a view to imposing a sanction, a possibility never previously exercised since the entry into force of the Sapin 2 law.[7]
As a reminder, under Article 17 of the Sapin 2 Law, where a breach is found, the matter may be referred to the Committee by the AFA’s director either for the purpose of issuing a compliance order or for the purpose of imposing a sanction.[8]
In the two previous referrals that resulted in a decision of the Sanctions Committee, in 2019 and 2020, the AFA’s director had referred the matter to the Committee for the purpose of ordering compliance and, in the event of non-compliance with the decision, for the purpose of imposing sanctions. The Committee could not therefore impose a financial sanction until it had ordered the companies concerned to act and had then found that the compliance order had not been complied with.[9]
In this decision, the Committee validates the use of direct referral for the purpose of imposing sanctions, citing Article 17, IV of the law of 9 December 2016. It recalls in this new decision that the statute established no mandatory hierarchy between the two referral procedures, so that the AFA’s director is free, in accordance with its own strategy, to refer matters to the Committee for the purpose of issuing an injunction or imposing a sanction, either alternatively or cumulatively.[10]
B. The date for assessing the alleged breaches is the date of the AFA’s audit
The decision’s second procedural contribution concerns the date at which the violation is to be assessed. In its two previous decisions, the Committee had declined to impose any financial sanctions on the grounds that the companies concerned, having achieved compliance by the date of the hearing, were no longer in breach at the time it gave its ruling.[11]
The company concerned relied on this argument, also invoking the principles of legality of criminal offenses and penalties, non-retroactivity of a more severe punitive law, and foreseeability of the law, all of which are guaranteed under Article 7 of the European Convention on Human Rights.[12] It argued that adopting a date other than the date on which the Committee would rule would amount to a reversal of case law and would contravene the aforementioned principles. The company also highlighted the steps it had taken to remedy the breaches identified by the AFA’s audit.
The committee rejects these arguments, recalling first that the previous decisions cited concerned referrals for the purpose of issuing an injunction, a scenario in which it could impose a financial penalty only after finding that a prior injunction had not been complied with.[13]
It emphasizes that the provisions of Article 17 of the Sapin 2 law are drafted in clear terms that have remained unchanged for ten years, such that companies cannot be mistaken as to their obligations and thus no unforeseeable reversal of case law can be invoked.[14]
Moreover, since the purpose of the Sapin 2 law is to prevent and detect corruption risks, its provisions, by their very nature, require prompt implementation, all the more so in a sector particularly exposed to corruption risks.[15]
This is why, in the event of a direct referral for the purpose of imposing sanctions, the assessment of the alleged breaches must be carried out as of the date of the audit conducted by the AFA. Adopting the opposite approach would render the mechanism entirely ineffective: breaches could then continue indefinitely, at the cost of unfair competition between companies that comply with their obligations without delay and those that defer compliance pending an audit.[16]
The Committee reiterates that it is applying clear provisions that have remained unchanged for nearly ten years, through a direct sanction procedure that is also provided for: consequently, no unforeseeable reversal of position can be held against it.[17]
Compliance achieved after the audit report was issued cannot therefore erase the breaches identified as of that date.[18] Adopting the position defended by the AFA[19] , the Sanctions Committee finds that the corrective measures undertaken by the company can only be taken into account at the stage of assessing the sanctions and their severity.[20]
By establishing the possibility of a direct referral for the purpose of imposing sanctions and by setting the date for assessing the breaches as the date of the AFA’s audit, the Committee makes clear that subject companies cannot expect to neutralize the risk of enforcement action by waiting for an audit or by using the time taken by the procedure to achieve compliance. These companies must be able to demonstrate, from the very opening of the audit, the measures already in place and the steps taken to address any breaches.
II. The committee finds seven breaches of the obligations set forth in the Sapin 2 law and imposed sanctions on the company and its legal representative
A. The analysis of the alleged violations does not take corrective measures into account
On the merits, the Committee examines the notified allegations without conducting an individualized or in-depth analysis of each of them. With regard to the five breaches relating to risk mapping, third-party assessment procedures, anti-corruption accounting controls, the training program, and the internal control and evaluation system, it finds that, as at the date of the audit, the company did not have tools appropriate to its risk profile and considers the allegations to be well-founded.[21]
Regarding the lack of a code of conduct and disciplinary procedures within a subsidiary of the group, which could have been incorporated into the subsidiary’s work rules, the company argued that it had not been in a position to establish them.[22] It contended that the implementation of work rules was contingent on an industry-wide collective agreement, which was ultimately reached in 2026.[23]
The Committee notes, however, that the steps taken to reach this agreement and thereby regularize the situation were excessively delayed. Consequently, while this factor could be taken into account in assessing the sanction and its severity, the allegations remained well-founded.[24]
B. The Committee holds the informed executive personally liable given his involvement in the company’s operations
The Committee then holds the company’s executive personally liable. It notes that, as a knowledgeable professional operating in a sector particularly exposed to the risk of corruption, he could not have been unaware, seven years after the entry into force of the law, of the obligations incumbent upon the company he headed.[25]
The Committee also placed significant emphasis on the nature of his duties, his involvement in the company’s operations, and his strategic role as the group’s founder, chairman of the company serving as the group’s holding company, principal shareholder, and chairman of the supervisory board of the company.[26]
Since the company had sufficient resources to undertake compliance efforts, it was therefore incumbent on its legal representative, who held the requisite authority, to act without waiting for an AFA audit.[27] Accordingly, the Committee finds him personally liable for the breaches found to exist.
In its previous decisions, the Committee had not sanctioned the companies or their executives and therefore did not developed any reasoning regarding their personal liability.[28] Through this new decision, it makes clear that failure to comply can directly expose executives, when they had the necessary means and requisite authority to act, thereby encouraging them to become more closely involved in the implementation and monitoring of anti-corruption programs. The Sanctions Committee appears to assess an executive’s liability based on the functions actually performed, their involvement in the company’s operations, and their knowledge of the relevant sector as well as its corruption risks.[29]
C. The sanctions imposed take into account both the severity of the breaches and the corrective measures undertaken
The Committee notes that the breaches found upon completion of the AFA’s audit were established and had persisted. Even though the company operated in a sector particularly exposed to the risk of corruption, corrective measures had only been implemented in response to the audit conducted by the AFA.[30] Based on these factors, the Committee decided that imposing a sanction was justified.
The Committee, however, examines the specific circumstances surrounding the breaches. It thus finds that the liability of both the company and the executive must be mitigated on account of the wait for the industry-wide agreement, which had delayed the establishment of a code of conduct and a disciplinary regime within one subsidiary of the group.[31] The corrective measures implemented, such as the commitment of resources and the rectification of the situation, were also taken into account in this regard.[32]
As regards the quantum of the fines, the Committee first recalls that it is not bound by the requests made by the AFA,[33] which had sought penalties of at least €400,000 against the company and €80,000 against the company’s chairman.[34] As a reminder, the statutory caps are €200,000 for individuals and one million euros for legal entities.[35]
In light of the breaches identified, the factors taken into account in assessing the sanction, and the company’s turnover and the chairman’s income, the Committee ultimately imposed financial penalties in the respective amounts of €350,000 and €60,000.[36]