No Result
View All Result
SUBSCRIBE | NO FEES, NO PAYWALLS
MANAGE MY SUBSCRIPTION
NEWSLETTER
Corporate Compliance Insights
  • About
    • About CCI
    • Writing for CCI
    • NEW: CCI Press – Book Publishing
    • Advertise With Us
  • Explore Topics
    • See All Articles
    • Compliance
    • Ethics
    • Risk
    • Artificial Intelligence (AI)
    • FCPA
    • Governance
    • Fraud
    • Internal Audit
    • HR Compliance
    • Cybersecurity
    • Data Privacy
    • Financial Services
    • Well-Being at Work
    • Leadership and Career
    • Opinion
  • Vendor News
  • Downloads
    • Download Whitepapers & Reports
    • Download eBooks
  • Research
  • Books
    • CCI Press
    • New: Bribery Beyond Borders: The Story of the Foreign Corrupt Practices Act by Severin Wirz
    • CCI Press & Compliance Bookshelf
    • The Seven Elements Book Club
  • Podcasts
  • Webinars
  • Videos
  • Subscribe
Jump to a Section
  • At the Office
    • Ethics
    • HR Compliance
    • Leadership & Career
    • Well-Being at Work
  • Compliance & Risk
    • Compliance
    • FCPA
    • Fraud
    • Risk
  • Finserv & Audit
    • Financial Services
    • Internal Audit
  • Governance
    • ESG
    • Getting Governance Right
  • Infosec
    • Cybersecurity
    • Data Privacy
  • Opinion
    • Adam Balfour
    • Jim DeLoach
    • Mary Shirley
    • Yan Tougas
No Result
View All Result
Corporate Compliance Insights
Home Featured

The 2019 TRACE Bribery Risk Matrix Rankings for Asia-Pacific

by Wendy Wysong
December 21, 2018
in Featured, Risk
The 2019 TRACE Bribery Risk Matrix Rankings for Asia-Pacific

New Data is Key to Anti-Bribery, Anti-Corruption Efforts

TRACE International published an updated Bribery Risk Matrix earlier this month, and the rankings will be hugely informative in corporations’ business dealings across the globe. Clifford Chance’s Wendy Wysong and Nick Turner discuss.

with co-author Nick Turner

Gut instincts can be good when undertaking an anti-corruption risk assessment on an Asia-Pacific business opportunity. But even better is data obtained from leading public interest and international organizations, including the United Nations, the World Bank and the World Economic Forum, analyzed by experts in the fields of political science, economics and corruption studies and presented in a detailed publicly available matrix.

The 2018 TRACE Bribery Risk Matrix, published online in early December, provides such data in the form of a detailed database that can be used as a basis for a company’s decision to approve a deal in Malaysia, conduct deeper due diligence in, say, Vietnam than Nepal and allocate scarce compliance resources in, say, China rather than India. For compliance and due diligence purposes, this kind of data is indispensable and provides an objective foundation for market-wide expectations and risk-based practices, which is good for business and helps promote the anti-bribery, anti-corruption mission in Asia-Pacific and globally.

The TRACE Matrix scores and ranks each of 200 countries for business bribery risk, based on data from over 50 sources. It categorizes the risk level of each country as: Very Low (i.e., New Zealand, Singapore, Hong Kong and Australia), Low (i.e., Taiwan, South Korea, Japan and Bhutan), Medium (e.g., Malaysia, India, Nepal), High (e.g., Vietnam, China, Myanmar, Cambodia) and Very High (i.e., North Korea).

Published and refined since 2014, the TRACE Matrix provides a valuable analytical tool for measuring bribery risks for commercial decision-making and developing risk-based compliance solutions. The TRACE Matrix also provides its underlying analysis for those figures. It looks at four risk “domains,” including:

  • business interactions with government (opportunity),
  • anti-bribery deterrence and enforcement (deterrence),
  • government and civil service transparency (transparency) and
  • capacity for civil society oversight (oversight).

These domains are further broken down into nine “subdomains.” For example, the oversight domain will look at a subdomain for a free press.

These underlying domain analyses mean that a country such as Vietnam can rank as medium risk for business interaction with the government, enforcement and transparency, but high for oversight, which gives it an overall high-risk score. If medium risk for bribery opportunities (domain 1) is within a company’s risk appetite, it would make sense to move forward (with appropriate compliance measures), even if the overall risk score is high.

As the case of Vietnam makes clear, the five risk-level categories and underlying analyses provide a nuanced approach to risk assessment. Transparency International (TI) also scores and ranks countries, based on the perception of public sector corruption. The TI Corruption Perception Index (CPI) differs from the TRACE Matrix in that the latter focuses on business bribery risk, as opposed to the CPI’s public sector focus. Moreover, the CPI does not provide the data underlying the scores and ranks and uses fewer data sources. Finally, the CPI uses three categories of risk so that Malaysia, while occupying roughly the same rank on both the Matrix and the CPI, is categorized as medium risk by TRACE and high risk by TI. (The 2018 CPI has not yet been published).

As illustrated in the attached chart comparing the 2018 TRACE Matrix results with the 2017 CPI results for a selection of Asia-Pacific countries, despite the different focus, methodology and details, the two databases make roughly the same assessments at the bottom and top of the list. But there are more Asia-Pacific countries categorized as low and medium risk by TRACE – about 20 of 34 on the complete list – as opposed to about nine of 30 on the complete CPI. There are other interesting differences, such as China: While both rank China as high-risk, TI gives it a better rank and score, just below medium-risk, while TRACE ranks and scores it as a higher-risk jurisdiction. TRACE categorizes Nepal as medium-risk, while TI ranks it as high-risk. TI ranks and scores China and India more closely, with China leading, while TRACE has a wider gap between the two, with India leading.

How should companies treat discrepancies between the TRACE Matrix and CPI? The simple approach is to take the lower of the two scores. Companies may also opt to select the risk score that is most relevant to their investment or opportunity, based on the underlying methodology. More sophisticated compliance programs will factor the TRACE Matrix and CPI outcomes into a blended risk rating based on a bespoke model. In whatever case, the availability of objective and credible data provides a helpful starting point that companies should not overlook.

Tags: Anti-CorruptionAsia PacificDue DiligenceRisk AssessmentTransparency International
Previous Post

Should THAT Be in a Personal Online Profile?

Next Post

New Year’s Resolutions: Cybersecurity Should Be at the Top of Your List for 2019

Wendy Wysong

Wendy Wysong

Wendy L. Wysong is a partner at Steptoe & Johnson. She served previously as a litigation partner with Clifford Chance, offering clients advice and representation on compliance and enforcement under the Foreign Corrupt Practices Act, the Arms Export Control Act, International Traffic in Arms Regulations, Export Administration Regulations, and OFAC Economic Sanctions. She was appointed by the State Department as the ITAR Special Compliance Official for Xe Services (formerly Blackwater) in 2010. Wendy combines her experience as a former federal prosecutor with the United States Attorney for the District of Columbia for 16 years with her regulatory background as the former Deputy Assistant Secretary for Export Enforcement at the Bureau of Industry and Security, U.S. Department of Commerce. She managed its enforcement program and was involved in the development and implementation of foreign policy through export controls across the administration, including the Departments of Justice, State, Treasury and Homeland Security, as well as the intelligence community. Wendy received her law degree in 1984 from the University of Virginia School of Law, where she was a member of the University of Virginia Law Review.

Related Posts

cisa website

Deferred, Not Ignored: Explaining Unpatched Vulnerabilities to Your Auditor

by Apu Pavithran
September 7, 2026

Teams should follow CISA’s lead and create the documentation and decision-making that gets the art of safe deferrals right

Rethink TPRM_f

Benchmarking Study: Third-Party Risk Management

by Corporate Compliance Insights
September 4, 2026

Third-party relationships are essential to modern business, but they can also introduce significant ethics and compliance risks. A new benchmarking...

tree roots overlapping

Root Cause Analysis: Right-Sized Guidance Before the Crisis Hits

by Jonny Frank, Kaitlyn Cecala and Annie Budra
August 25, 2026

RCA guidance helps a company avoid improvisation, apply consistent criteria and distinguish fixing an incident from fixing its cause

blindfolded statue

Audit‑Dominated Risk Oversight Leaves Boards Blind to Modern Risks

by Adley John Fisher
August 10, 2026

The solution won’t be found in incremental tweaks to existing compliance templates but in a spirit to change how the...

Next Post
red open padlock beside blue closed padlocks, concept of security threat

New Year’s Resolutions: Cybersecurity Should Be at the Top of Your List for 2019

GGR sq
No Result
View All Result

Privacy Policy | AI Policy

Founded in 2010, CCI is the web’s premier global independent news source for compliance, ethics, risk and information security. 

Got a news tip? Get in touch. Want a weekly round-up in your inbox? Sign up for free. No subscription fees, no paywalls. 

Follow Us

Browse Topics:

  • CCI Press
  • Compliance
  • Compliance Podcasts
  • Cybersecurity
  • Data Privacy
  • eBooks Published by CCI
  • Ethics
  • FCPA
  • Featured
  • Financial Services
  • Fraud
  • Governance
  • GRC Vendor News
  • HR Compliance
  • Internal Audit
  • Leadership and Career
  • On Demand Webinars
  • Opinion
  • Research
  • Resource Library
  • Risk
  • Uncategorized
  • Videos
  • Webinars
  • Well-Being
  • Whitepapers

© 2026 Corporate Compliance Insights

No Result
View All Result
  • About
    • About CCI
    • Writing for CCI
    • NEW: CCI Press – Book Publishing
    • Advertise With Us
  • Explore Topics
    • See All Articles
    • Compliance
    • Ethics
    • Risk
    • Artificial Intelligence (AI)
    • FCPA
    • Governance
    • Fraud
    • Internal Audit
    • HR Compliance
    • Cybersecurity
    • Data Privacy
    • Financial Services
    • Well-Being at Work
    • Leadership and Career
    • Opinion
  • Vendor News
  • Downloads
    • Download Whitepapers & Reports
    • Download eBooks
  • Research
  • Books
    • CCI Press
    • New: Bribery Beyond Borders: The Story of the Foreign Corrupt Practices Act by Severin Wirz
    • CCI Press & Compliance Bookshelf
    • The Seven Elements Book Club
  • Podcasts
  • Webinars
  • Videos
  • Subscribe

© 2026 Corporate Compliance Insights