
The Sapin 2 law does not explicitly mention gifts and invitations. The text imposes a code of conduct on companies that prohibits behaviors that could characterize acts of corruption or influence peddling, without setting any amount or list of prohibited items. The difficulty lies in this gap between a deliberately broad legal framework and business practices where offering a meal, a concert ticket, or a promotional item remains common.
The French Anti-Corruption Agency (AFA) has attempted to fill this gap by publishing a practical guide dedicated to gift and invitation policies in companies, public industrial and commercial establishments (EPIC), associations, and foundations. This guide now serves as a reference during audits, but it does not create an independent legal obligation. Companies must therefore build their own system, calibrated to their actual risks.
Documentary obligation: what the AFA actually sanctions during an anti-corruption audit
Competitors extensively detail the desirable content of a gift policy. Few focus on what actually triggers a sanction. The decision of the AFA’s sanctions commission No. 25-01 of July 9, 2026, set a clear precedent: the formal existence of a charter is no longer sufficient. The AFA now requires that the company demonstrate the effective application of its system.
In practice, during an audit, auditors request the version of the policy in force at the date of each event examined, hierarchical approvals for gifts exceeding internal thresholds, payment receipts, and records of controls carried out. A company that has a well-drafted policy but is unable to produce these documents exposes itself to a sanction.
This traceability requirement changes the nature of compliance work. Drafting the policy becomes a starting point, not an end in itself. Compliance departments must establish documented, archived, and auditable validation processes, including for modest amounts as soon as they exceed the defined internal threshold. Better understanding the gift and invitation policy under the Sapin 2 law requires going beyond a simple reading of the text to incorporate these operational requirements.

Internal thresholds for corporate gifts: why there is no universal amount
No French legislative text sets a monetary ceiling for professional gifts and invitations. The AFA recommends that companies define their own thresholds, tailored to their industry, size, and exposure to corruption risks. This absence of regulatory amounts creates a gray area that each organization must manage.
The AFA’s practical guide distinguishes two levels of control:
- A threshold below which the gift or invitation is accepted without prior validation, provided that qualitative criteria are met (no expected counterpart, proportionality, transparency).
- A threshold above which prior hierarchical authorization is required, with registration in a dedicated log.
- An absolute ceiling beyond which the gift or invitation is systematically refused, regardless of the situation.
These thresholds must reflect the company’s risk mapping. A company whose main clients are foreign public officials will not apply the same amounts as an SME selling office supplies in France. The pharmaceutical sector, after high-profile cases such as the conviction of Urgo laboratories for 1.125 million euros in fines for offering over 55 million euros in gifts to pharmacists, applies particularly low thresholds.
National Anti-Corruption Plan 2025-2029: SMEs and mid-sized companies now concerned
The National Anti-Corruption Plan 2025-2029 expands the scope of vigilance beyond large companies formally subject to Article 17 of the Sapin 2 law. SMEs, mid-sized enterprises (ETI), and local authorities are now encouraged to structure their anti-corruption systems, including in the area of gifts and invitations.
This extension does not change the strict legal obligations, which remain limited to companies exceeding certain revenue and employee thresholds. However, SMEs exposed to public contracts or international markets have a direct interest in formalizing a policy, if only to comply with the anti-corruption clauses imposed by their clients.
The plan also provides for strengthening the AFA’s resources to support these smaller structures. Field feedback on this point varies: some professional federations believe that the tools offered are still calibrated for large groups, while others welcome the availability of simplified models.
Gift and invitation register: a central tool
The AFA recommends maintaining a register recording each gift or invitation offered or received above the internal threshold. This register must mention the nature of the gift, its estimated value, the identity of the recipient, the date, and the professional justification. The register is the first document requested during an AFA audit.
Its format is not imposed. Shared spreadsheet, module integrated into compliance software, intranet form: the tool matters less than the regularity of its updates and its accessibility for internal audit teams.

AFA’s qualitative criteria for distinguishing acceptable gifts from corruption risks
Beyond amounts, the AFA assesses the compliance of a gift or invitation according to several substantive criteria:
- The gift is offered without expecting a direct or indirect counterpart and does not occur in the context of ongoing commercial negotiations.
- Its value remains proportionate to industry practices and does not place the recipient in a position of dependence or indebtedness.
- It is offered transparently, with the agreement of the recipient’s hierarchy when the internal threshold is exceeded.
- It does not have a marked personal character (jewelry, private travel, family invitation) that would distinguish it from professional courtesy.
A modest gift offered at the wrong time can pose more problems than an expensive gift in a neutral context. A lunch offered the day before a call for tenders raises more questions than an invitation to a trade show without immediate commercial stakes.
The first sanction imposed by the AFA’s sanctions commission in July 2026, targeting both a company and its manager, confirms that these qualitative criteria weigh as much as amounts in assessing risk. Companies that merely set a ceiling without training their teams on these contextual criteria take a non-compliance risk that a written policy alone does not cover.