Anti-Corruption Compliance Lawyer | Compliance design and case response, organized by role
Summary
Korea's anti-corruption regime is not a single statute — it is a patchwork built around the Act on the Prevention of Corruption and the Establishment and Management of the Anti-Corruption and Civil Rights Commission (부패방지 및 국민권익위원회의 설치와 운영에 관한 법률), the Improper Solicitation and Graft Act (부정청약금지 및 금품등 수수의 금지에 관한 법률, commonly called 김영란법), and sector-specific rules for public officials, public institutions, and private companies dealing with them. What counts as a violation depends heavily on the actor's status (public official vs. private employee), the value and purpose of the benefit received, and whether a reporting duty was triggered. Frontier Law Firm advises on both sides of this: designing internal compliance controls before a problem arises, and responding once an audit, internal report, or investigation has already started.
Administrative · ComplianceRelated law: Improper Solicitation and Graft ActRelated law: Anti-Corruption and Civil Rights Commission ActPublic officials & institutions
Anti-Corruption Compliance | Which statute applies to your situation
Before building a response, it matters which set of rules actually governs the conduct in question — the answer changes depending on whether the person involved is a public official, works at a public institution, or is a private-sector employee dealing with either.
Public officials and public institution employees
Public officials, employees of public institutions, and staff at schools and press organizations designated as covered entities are subject to reporting and recusal duties under the Improper Solicitation and Graft Act (부정청약금지 및 금품등 수수의 금지에 관한 법률). Receiving money, goods, or entertainment above the thresholds set out in the Act's enforcement decree can trigger administrative penalties or criminal referral even without proof of an improper favor being exchanged.
Private companies interacting with covered entities
A private company does not escape exposure simply because its own employees are not public officials. If a company or its staff offer money or entertainment to a public official or covered-entity employee, both the offering company and the individual who directed or executed the offer can face liability, and the company's internal compliance controls become directly relevant to any mitigation argument.
General anti-corruption duties under the Commission Act
The Anti-Corruption and Civil Rights Commission Act (부패방지 및 국민권익위원회의 설치와 운영에 관한 법률) establishes broader duties for public agencies to prevent corruption, operate reporting channels, and protect whistleblowers, and provides the statutory basis for the Anti-Corruption and Civil Rights Commission's investigative and referral powers.
Anti-Corruption Compliance | Designing an internal compliance system before a problem occurs
Most anti-corruption exposure for companies is not a single dramatic bribery scandal — it accumulates through routine gift-giving, entertainment expenses, and vendor relationships that were never reviewed against the applicable thresholds. A compliance system is meant to catch that before it becomes a case.
Mapping who counts as a covered person
The first step is identifying which counterparties in a company's business relationships qualify as public officials or covered-entity employees under the Improper Solicitation and Graft Act, since gift and entertainment rules apply differently depending on that status. This mapping typically covers regulators, government clients, public institution partners, and any press or education contacts the company deals with regularly.
Setting internal thresholds and approval lines
Internal policy usually sets gift, meal, and entertainment limits below or aligned with the statutory thresholds, along with a pre-approval process for anything close to the line. Documenting this process matters less for preventing every violation than for demonstrating, after the fact, that the company had a functioning control system rather than turning a blind eye.
Training and reporting channels
A compliance system without a working internal reporting channel tends to fail at the moment it is tested, because employees have no clear way to flag a borderline situation before it escalates. Setting up that channel, and training staff on how gift and entertainment rules apply to their specific role, is usually where Frontier Law Firm is engaged before any incident occurs.
Anti-Corruption Compliance | Responding to an audit, internal investigation, or prosecutorial inquiry
Once a company or public official has already received notice of an internal audit, an inspection by the Anti-Corruption and Civil Rights Commission, or a request for materials from investigative authorities, the priorities shift from prevention to containment.
Preserving records and internal communication
Early in an audit or investigation, how internal records and emails are preserved and reviewed can determine whether the company's position is that the conduct was an isolated lapse or a systemic failure. Overbroad internal messaging sent in a panic after the fact often does more damage than the original conduct.
Separating individual and corporate liability
Where an employee's individual conduct is at issue, the company's interest in limiting its own exposure and the employee's interest in their personal defense can diverge quickly, and a single legal representation covering both is not always appropriate. Clarifying this early avoids conflicts that surface later in the process.
Engaging with the Anti-Corruption and Civil Rights Commission or prosecutors
Where a matter is referred for administrative sanction or criminal review, how the company or individual responds to requests for statements and materials affects both the scope of any eventual finding and whether voluntary cooperation is later credited. This is a stage where legal advice on what to disclose, and how, matters more than in the preventive phase.
Anti-Corruption Compliance | Internal and external whistleblower reports
Reports can come from inside a company (an employee flagging a colleague or superior) or be filed externally with the Anti-Corruption and Civil Rights Commission or investigative authorities, and each track carries different protections and different response obligations for the organization.
Protection against retaliation for the reporting person
A person who reports corruption in good faith is generally protected from disadvantageous personnel action taken because of the report, and organizations that retaliate against a whistleblower face their own separate exposure. Advising an organization on how to handle a reported employee's status during an ongoing investigation is a routine but sensitive part of this work.
Evaluating the substance of a report before reacting
Not every internal report describes conduct that actually meets the statutory thresholds for a violation, and organizations sometimes over-react (or under-react) because the underlying legal analysis was skipped. A prompt but careful review of what was actually reported, against the specific conduct thresholds in the applicable statute, usually shapes everything that follows.
Anti-Corruption Compliance | From initial consultation to resolution
1
Initial fact review and status classification We first identify whether the people involved are public officials, covered-entity employees, or purely private-sector actors, since this classification determines which statute and thresholds apply.
2
Risk diagnosis or incident scoping For preventive engagements, this means reviewing existing gift/entertainment practices and vendor relationships against statutory thresholds. For incident response, it means scoping what records exist and what has already been disclosed to any authority.
3
System design or response strategy We draft or revise internal compliance policies, approval workflows, and reporting channels, or, in a live case, set a strategy for engaging with internal audit, the Anti-Corruption and Civil Rights Commission, or prosecutors.
4
Implementation support This can include training sessions for staff, drafting written responses to audit requests, or preparing a client for an investigative interview.
5
Follow-up and monitoring After a compliance system is adopted or a case concludes, we typically remain available for periodic review, since thresholds and enforcement practice under these statutes are updated from time to time.
Anti-Corruption Compliance | How fees are generally structured
Advisory retainer For ongoing compliance advisory work (policy drafting, periodic training, ad hoc questions from a compliance officer), fees are usually structured as a monthly or project-based retainer scaled to the scope of work and frequency of consultation requested.
Investigation/audit response fee For responding to an active internal audit, Commission inquiry, or prosecutorial request, fees are typically set based on the complexity of the fact pattern, the volume of records to be reviewed, and the number of individuals whose interests need to be separately represented.
Compliance system build-out A one-time engagement to design or overhaul an internal anti-corruption compliance system (policy documents, approval workflows, training materials) is generally quoted as a fixed project fee after an initial scoping review.
Disbursements Costs such as document translation, expert review, or travel for on-site training are billed separately as actual expenses incurred.
※ Costs vary depending on case complexity and specific circumstances; exact fees will be provided during consultation. No specific outcome is guaranteed.
Anti-Corruption Compliance | Self-Check by Role
1️⃣ For Compliance Officers Building a System
Have you mapped which of your counterparties qualify as public officials or covered-entity employees?
Do you have written thresholds for gifts, meals, and entertainment that align with the Improper Solicitation and Graft Act?
Is there a functioning internal channel for employees to ask about a borderline situation before it happens?
Have your sales and government-relations staff received role-specific training in the past year?
2️⃣ For a Public Official or Covered-Entity Employee
Did the benefit you received exceed the per-instance or annual threshold under the applicable enforcement decree?
Was the benefit connected to your official duties or a matter you could influence?
Have you already reported the receipt to your institution's ethics officer, and if not, how much time has passed?
Is there a written record (invitation, receipt, correspondence) that documents the context of the benefit?
3️⃣ For a Company Facing an Audit or Investigation
Has a formal request for materials or a statement already been received, or is this still an internal rumor?
Have you issued a litigation hold to prevent relevant records from being altered or deleted?
Does the employee at the center of the inquiry need separate representation from the company?
Has anyone in the company communicated with the reporting person or investigators without legal advice?
4️⃣ For Someone Considering an Internal Report
Does the conduct you observed involve a benefit or favor connected to an official duty, rather than a purely personal dispute?
Do you have any documentation (messages, receipts, calendar entries) that supports your account?
Are you aware of the retaliation protections that apply once a good-faith report is filed?
Have you decided whether to report internally first, or directly to the Anti-Corruption and Civil Rights Commission?
Frequently Asked Questions
Q. Does the Improper Solicitation and Graft Act apply to my company if none of our employees are public officials?
A. Yes, if your employees offer money, gifts, or entertainment to a public official or a covered-entity employee (such as staff at a public institution, school, or press organization), the offering company and individual can face liability even though your own staff are private-sector employees (부정청약금지 및 금품등 수수의 금지에 관한 법률).
Q. What is the difference between the Improper Solicitation and Graft Act and general bribery under the Criminal Act?
A. The Improper Solicitation and Graft Act sets specific monetary thresholds and administrative penalties that can apply even without proving an improper favor was exchanged, while bribery under the Criminal Act generally requires showing a connection between the benefit and an official's duties. In practice, a single set of facts can trigger exposure under both frameworks depending on the amount and context involved.
Q. Can our company be penalized even if a single employee acted without management's knowledge?
A. It depends on the specific facts, including whether the company had a functioning compliance system and supervisory controls in place at the time. A documented internal policy and approval process is often the main evidence a company can point to in arguing that an individual employee's conduct was not attributable to a corporate failure.
Q. What should I do if I receive a notice of inspection from the Anti-Corruption and Civil Rights Commission?
A. The notice will typically specify what materials or statements are being requested and a deadline; reviewing the scope of the request carefully before responding, rather than immediately submitting everything on hand, is usually the more prudent first step. Getting legal advice at this stage, before any written response is submitted, tends to matter more than at almost any later point in the process.
Q. Is there a deadline for reporting a suspected violation internally?
A. There is generally no statutory deadline for filing an internal or external report, but delays can affect how a report is later evaluated, particularly if evidence has degraded or the underlying conduct has continued. If you are uncertain whether to report, an initial legal consultation to assess the facts before filing can clarify your options.
Q. Are whistleblowers protected if their report turns out to be only partially accurate?
A. Protection generally attaches to a report made in good faith, based on a reasonable belief that a violation occurred, rather than requiring that every detail later be confirmed as accurate. Reports made with knowledge that they are false, however, are treated differently and can expose the reporting person to liability.
Q. Can a company and an employee under investigation share the same lawyer?
A. It depends on whether their interests are aligned; if the company's position may ultimately blame the individual employee (or vice versa), joint representation creates a conflict that should be addressed before the investigation proceeds further. In many cases it is safer for the individual to retain separate counsel.
Q. What triggers a criminal referral instead of just an administrative penalty under the Graft Act?
A. Referral for criminal review generally depends on the value of the benefit received and whether it was connected to a specific official duty or decision, with higher-value or duty-connected benefits more likely to be treated as a criminal matter rather than an administrative violation. The specific thresholds are set out in the Act and its enforcement decree, so the facts of each case need to be checked against them directly.
Q. How often should a company update its anti-corruption compliance policy?
A. There is no fixed statutory interval, but because enforcement thresholds and administrative guidance under the Improper Solicitation and Graft Act are periodically revised, an annual review alongside any relevant regulatory changes is a common practice among companies with active compliance programs.
Q. Does entertaining a government client at a normal business dinner automatically violate the law?
A. Not automatically — the Improper Solicitation and Graft Act sets specific per-instance and annual value thresholds, and ordinary hospitality below those thresholds is generally permitted. The risk arises when the value exceeds the threshold, when the dinner is connected to a pending decision affecting the company, or when it is part of a repeated pattern that suggests an attempt to influence official action.
법무법인 프런티어(이하 “사무소”)는 개인정보보호법에 따라 정보주체의 개인정보 및 권익을 보호하고 개인정보와 관련된 정보주체의 고충을 신속하고 원활하게 처리하기 위하여 본 개인정보 처리방침을 수립·공개합니다.
제 1 조 수집하는 개인정보의 항목, 목적, 방법
제 2 조 개인정보의 처리 및 보유기간
제 3 조 개인정보의 제3자 제공
제 4 조 개인정보 처리업무의 위탁
제 5 조 정보주체의 권리·의무 및 그 행사방법
제 6 조 개인정보의 파기
제 7 조 의견수렴 및 불만처리
제 8 조 개인정보 처리방침의 변경
제 9 조 개인정보의 안전성 확보 조치
제 1 조 (수집하는 개인정보의 항목, 목적, 방법)
① 게시판 글 작성 시 필수 항목에 대한 수집목적은 ‘별도의 구체적 상담을 위하여’이며 수집항목은 ‘이름, 이메일, 연락처’입니다.
② 전항 외에 고객의 서비스 이용 과정이나 요청 사항 처리 과정에서 ‘IP주소, 접속로그, 단말기 및 환경정보, 서비스 이용기록, 쿠키’와 같은 정보들이 자동으로 수집 및 저장될 수 있으며, 이 때의 수집목적은 ‘사용자 홈페이지 이용, 사이트 이용에 대한 문의 민원 등 고객 고충 처리’입니다.
③ 사무소는 ‘홈페이지 고객 문의/고충 처리 시 전화 또는 인터넷을 통한 상담’과 같은 방법으로 개인정보를 수집합니다
제 2 조 (개인정보의 처리 및 보유기간)
관계법령의 규정에 따라 개인정보를 보존하여야 하는 의무가 있는 경우가 아닌 한, 정보주체의 개인정보는 원칙적으로 해당 개인정보의 처리목적이 달성될 때까지 보유 및 이용되며, 그 목적이 달성되면 지체 없이 파기됩니다.
제 3 조 (개인정보의 제3자 제공)
사무소는 정보주체의 개인정보를 본 처리방침에서 명시한 목적에 한해서만 처리하며 정보주체의 사전동의가 있는 경우 또는 개인정보보호법 등 관계법령의 규정에 의거한 경우에만 개인정보를 제3자에게 제공합니다. 사무소는 현재 개인정보를 제3자에게 제공하지 않고 있습니다.
제 4 조 (개인정보 처리업무의 위탁)
사무소는 현재 귀하의 개인정보 보호를 위해 귀하의 개인정보를 직접 취급 관리하고 있습니다. 단, 향후 보다 전문적인 서비스를 제공하기 위하여 제3의 전문기관에 귀하의 정보를 위탁할 필요가 있다고 판단되는 경우, 귀하의 사전 동의 하에 개인정보에 대한 취급을 위탁할 수 있습니다.
제 5 조 (정보주체의 권리·의무 및 그 행사방법)
① 정보주체는 개인정보보호법 등 관계법령이 정하는 바에 따라 사무소에 대해 개인정보의 열람, 정정 및 삭제, 처리정지 요구 등 개인정보 보호 관련 권리를 행사할 수 있습니다.
② 제1항에 따른 권리행사는 정보주체의 법정대리인이나 위임을 받은 사람을 통해서도 할 수 있습니다. 다만, 이 경우에는 개인정보보호법 시행규칙에 따른 위임장을 사무소에 제출하여야 합니다.
③ 사무소는 정보주체의 권리행사에 대하여 개인정보보호법 등 관계법령이 정하는 바에 따라 지체 없이 조치하겠습니다.
제 6 조 (개인정보의 파기)
① 사무소는 원칙적으로 개인정보의 처리목적이 달성된 경우 등 그 개인정보가 불필요하게 되었을 때에는 지체 없이 해당 개인정보를 파기합니다.
② 사무소가 관계법령의 규정에 따라 개인정보를 파기하지 아니하고 보존하여야 하는 경우에는 해당 개인정보 또는 개인정보파일을 다른 개인정보와 분리해서 저장·관리 합니다.
③ 사무소는 파기사유가 발생한 개인정보를 선정하여 개인정보 보호책임자의 승인을 받아 해당 개인정보를 파기합니다.
④ 사무소는 파기하여야 할 개인정보가 전자적 파일 형태인 경우 복원이 불가능한 방법으로 영구 삭제하며, 이외의 기록물, 인쇄물, 서면, 그 밖의 기록매체인 경우 파쇄 또는 소각합니다.
제 7 조 (의견수렴 및 불만처리)
정보주체는 개인정보 보호 관련 문의, 불만처리, 피해구제 등에 관한 사항을 아래 개인정보 보호책임자 또는 담당부서에 문의하실 수 있습니다. 사무소는 정보주체의 문의에 대하여 신속하고 충분한 답변을 드릴 것입니다.
개인정보 보호 책임자 : 변호사
연락처 : 02.
제 8 조 (개인정보 처리방침의 변경)
사무소의 개인정보 처리방침은 관련 법령, 지침 및 사무소 내부규정에 따라 변경될 수 있으며, 개인정보 처리방침이 변경되는 경우 관련 법령이 정하는 방법에 따라 공개합니다.
제 9 조 (개인정보의 안전성 확보 조치)
사무소는 개인정보의 안전성 확보를 위해 다음과 같은 조치를 취하고 있습니다.
관리적 조치 : 내부관리계획의 수립 및 시행, 구성원에 대한 정기적인 개인정보 보호교육 등
기술적 조치 : 개인정보처리시스템 등의 접근권한 관리, 접근통제시스템 설치, 고유식별정보 등의 암호화, 보안프로그램의 설치 등
물리적 조치 : 전산실, 자료보관실 등 개인정보 보관장소에 대한 접근통제