Best Compliance and Anti-Bribery Training Programs in Brazil
The best Compliance and Anti-Bribery training programs in Brazil are those that combine updated content, alignment with company risks, practical scenarios, learning evaluations, and auditable proof of completion.
Selecting a program must also account for the changes introduced by ISO 37001:2025, the parameters of the Brazilian Anti-Corruption Act, the criteria of Federal Decree No. 11,129/2022, and, in cases involving federal public procurement, the provisions of Federal Decree No. 12,304/2024 and CGU Normative Ordinance SE/CGU No. 226/2025.
There is no single training program that fits every organization. The most suitable solution depends on the company’s size, industry sector, level of exposure to public officials, use of intermediaries, and the target audiences to be trained—such as employees, leadership, suppliers, commercial representatives, and customs brokers.
This guide outlines the main criteria for evaluating and selecting corporate Compliance and Anti-Bribery training in Brazil.
Overview of the Compliance and Anti-Bribery Training Market in Brazil (2026)
The Brazilian market for Compliance and Anti-Bribery training brings together consulting firms, professional academies, standardized courses, and companies specializing in digital corporate education.
This diversity reflects the maturation of corporate integrity programs. Organizations no longer seek merely to communicate legal concepts; they need to prepare people to recognize risk scenarios, make appropriate decisions, and know who to turn to when facing doubts or suspicions.
Several key trends are gaining traction in 2026:
training tailored to the specific risks of each audience group;
increased focus on third parties and intermediaries;
use of simulators and ethical dilemmas;
scalable digital training modules;
delivery in multiple languages;
learning retention evaluations;
reports and auditable proof of completion;
tracking of attendance and completion metrics;
periodic content updates.
Regulatory advances also drive this transformation.
Law No. 12,846/2013, known as the Brazilian Anti-Corruption Act, established strict administrative and civil liability for legal entities involved in acts against domestic or foreign public administration.
Decree No. 11,129/2022, which regulates the Anti-Corruption Act, includes periodic training and communication initiatives among the key parameters used to evaluate integrity programs.
Decree No. 12,304/2024 regulates the evaluation of integrity programs in specific public procurement scenarios under the Public Bidding Law, such as high-value contracts, tie-breaking criteria in bidding, and the rehabilitation of penalized contractors at the federal level.
On the international front, ISO 37001:2025 updated the requirements and guidance for Anti-Bribery Management Systems (ABMS), reinforcing areas like culture, leadership, conflict-of-interest management, awareness, and risk-based training.
What is the Role of Training in an Integrity Program?
Training translates rules and written policies into actionable guidance for day-to-day business decisions.
A code of conduct may forbid improper advantages, for example. However, professionals must also understand how to react when a public official implies that an approval could be expedited through payment, when a customs broker submits an expense without supporting documentation, or when a business partner offers hospitality exceeding company policy limits.
Therefore, effective training must help participants to:
identify corruption and bribery risks;
understand the rules applicable to their specific job function;
recognize red flags;
evaluate conflicts of interest;
consult internal policies;
stop inappropriate behavior;
reach out to the appropriate internal channels;
report good-faith suspicions;
accurately document decisions and financial operations.
Training, however, is just one component of an integrity program. Delivering a course does not, on its own, guarantee legal compliance, ISO certification, or approval in a Comptroller General of the Union (CGU) audit.
What Does CGU Ordinance No. 226/2025 Evaluate in Training?
Normative Ordinance SE/CGU No. 226/2025 established an evaluation methodology organized into 11 distinct areas. One area is specifically dedicated to training and communication initiatives within integrity programs.
In the training category, the methodology checks whether the company:
maintains a plan with schedules, themes, target audiences, owners, and delivery formats;
conducted integrity training for all employees within the last 12 months;
conducted specific training for high-risk job roles aligned with their specific exposure;
can document and prove the occasions, topics, course load, and audiences reached;
achieved an average completion rate of at least 70% for each target audience group.
The Ordinance does not mandate a universal minimum course load, nor does it require in-person vs. digital delivery. The focus is on planning, periodicity, risk alignment, audience reach, and auditable proof of execution.
These criteria apply specifically to the scenarios regulated by Decree No. 12,304/2024. This does not mean that all Brazilian companies are legally obligated to submit their integrity programs to the CGU or the SAMPI system.
Key Criteria for Evaluating Corporate Anti-Bribery Training
1. Regulatory and Legal Accuracy
The first criterion is ensuring that content is up-to-date and clearly distinguishes between legislation, technical standards, and internal policies.
A training module tailored to the current Brazilian landscape should address:
| Topic | Primary Reference |
| Corporate Legal Liability | Law No. 12,846/2013 |
| Unlawful Acts Against Public Administration | Law No. 12,846/2013, Art. 5 |
| Integrity Program Evaluation | Decree No. 11,129/2022 |
| Public Procurement and Integrity | Decree No. 12,304/2024 |
| CGU Evaluation Methodology | Normative Ordinance SE/CGU No. 226/2025 |
| Anti-Bribery Management Systems | ISO 37001:2025 |
| Third-Party Management | Decree No. 11,129/2022, Decree No. 12,304/2024, and ISO 37001:2025 |
| Interacting with Public Officials | Law No. 12,846/2013 and Internal Policies |
Content should not merely quote legal statutes; it must demonstrate how rules apply to real-world business choices.
2. Risk and Audience Segmentation
The exact same course does not need to be delivered identically to every employee.
Procurement, Sales, Finance, Government Relations, or Public Bidding teams face different risks than employees with little external exposure. C-Level leadership and managers also carry distinct responsibilities for fostering an ethical culture.
A strong corporate training program can combine:
general introductory content for all employees;
specialized leadership training;
tailored tracks for high-risk departments;
training for third parties acting on behalf of the company;
specific guidelines for teams interacting with public officials.
Segmentation must stem from the organization’s formal risk assessment, not just job titles.
3. Practical Scenarios and Simulators
Participants need to know how to act, not just memorize concepts.
Simulators and ethical dilemmas can present scenarios such as:
offers of improper advantages;
requests for facilitation payments;
hiring an intermediary recommended by a public official;
gifts or hospitality exceeding policy limits;
pressure to accelerate licenses, permits, or certificates;
unsubstantiated expenses submitted by a customs broker;
irregularities in public bids or government contracts;
donations or sponsorships with potential conflicts of interest;
inaccurate accounting records;
engaging third parties without due diligence;
fear of retaliation following a report.
Learning becomes actionable when participants must analyze red flags, choose a course of action, and receive immediate feedback on the correct decision.
4. Learning Evaluation
Course completion and actual learning are not the same thing.
A platform can log that a user clicked through all screens, but that alone does not prove that they understood the risks or know how to apply guidelines.
For this reason, it is critical to verify whether the training includes:
knowledge check quizzes;
decision-making simulators;
final assessments;
clear passing grade thresholds;
immediate answer feedback;
individual and aggregated reporting;
analytics on topics with the highest error rates.
It is also important to distinguish between four key metrics:
Attendance: confirms that the person attended;
Completion: demonstrates that they navigated through all steps;
Passing Score: records that they met the grade requirement;
Effectiveness: evaluates whether the training measurably improved knowledge, decision-making, or workplace behavior.
5. Auditability and Traceability
The organization must be able to prove what was trained, to whom, when, and with what outcome.
Essential auditable evidence includes:
annual training schedule;
course syllabus;
script or training materials used;
target audience records;
dates of completion;
course duration (hours);
attendance logs;
completion reports;
test scores;
certificates;
participant communications;
version control and update history.
6. Customization
Off-the-shelf content can provide a basic introduction, but it often misses the specific risks of a particular company or industry.
Customization can incorporate:
industry sector specifics;
identified organizational risks;
internal Code of Conduct;
Anti-Corruption policy;
gift and hospitality thresholds;
whistleblowing channels;
internal approval workflows;
real company business cases;
branding and visual identity;
internal terminology;
required languages.
Customization is especially critical for companies participating in public tenders, relying on government permits, or utilizing third parties to interface with public agencies.
7. Employees, Leadership, and Third Parties: Who Should Be Trained?
Determining target audiences depends on exposure to bribery and corruption risks.
Beyond regular employees, organizations should assess the need to train:
board members and C-Level executives;
managers and supervisors;
commercial representatives;
consultants;
suppliers and service providers;
intermediaries and sales agents;
customs brokers;
business partners;
public bidding teams;
third parties applying for licenses, permits, or certificates;
anyone interacting with public officials.
Decree No. 12,304/2024 requires integrity standards and policies to be extended to third parties where appropriate. It also mandates risk-based due diligence for contracting and monitoring suppliers, service providers, intermediaries, customs brokers, consultants, commercial representatives, and associates.
This does not mean every third party requires the exact same training. Content, frequency, and depth must be proportional to the risk level and operational scope of each partner.
How TothBe’s Solution Aligns with CGU Evaluation Criteria
According to institutional data, TothBe has trained over 260,000 employees and develops multi-language content in Portuguese, English, and Spanish.
Its training solutions can be deployed to employees, executive leadership, and third parties—including representatives, consultants, intermediaries, and customs brokers who act on behalf of the company or interface with public officials.
TothBe’s reports, learning assessments, and certificates help generate audit-ready evidence. However, training alone does not guarantee approval of an integrity program by the CGU, as evaluations consider the full suite of measures implemented by the company.
Common Mistakes When Hiring a Corporate Training Provider
Choosing solely based on lowest price: Cost must be evaluated alongside legal accuracy, customization, learning assessments, platform support, and available auditable records.
Applying identical content to everyone: While general introductory content is necessary, roles exposed to specific risks require supplementary targeted training.
Confusing training with full program implementation: Training strengthens an integrity program, but it cannot replace risk assessments, policies, controls, due diligence, whistleblowing channels, investigations, and ongoing monitoring.
Confusing a course completion certificate with ISO certification: A certificate proves individual participant completion or passing grade. ISO 37001 certification involves a comprehensive audit of the organization’s overall management system by an accredited certifying body.
Conducting a one-off event and considering the topic closed: Regulations explicitly call for “periodic training and communication initiatives.” A single lecture may raise awareness, but it fails to demonstrate continuity, risk alignment, or planned coverage.
Frequently Asked Questions (FAQ)
What are the minimum training requirements under CGU Ordinance No. 226/2025?
The methodology evaluates documented planning (schedules, topics, target audiences, owners, and execution formats). It also evaluates integrity training conducted over the prior 12 months for all employees and specific high-risk roles, checking logged topics, hours, execution dates, and audience reach—verifying whether an average completion rate of at least 70% was achieved per group.
Does CGU Ordinance No. 226/2025 mandate a minimum course duration?
No. Companies must report the duration of delivered training, but the Ordinance does not set a universal minimum time limit. Course load should be defined based on risks, responsibilities, and audience profiles.
Are all companies required to submit their integrity programs via SAMPI?
No. SAMPI is the system used to collect data and documents for evaluations under Decree No. 12,304/2024 and CGU Ordinance No. 226/2025, which primarily apply to major federal public procurements and contractor rehabilitation proceedings.
Does aligned training make a company ISO 37001 certified?
No. Training supports the competence and awareness requirements of an Anti-Bribery Management System, but it does not confer ISO certification. Certification requires an independent system audit by an accredited certifying body.
Should third parties and customs brokers receive anti-bribery training?
This should be determined by risk assessment. Third parties acting on behalf of the company, interacting with public officials, or securing licenses and permits face higher exposure and justify targeted training.
Can Compliance training be delivered via EAD / e-learning?
Yes. Regulations do not mandate a single delivery method. E-learning is suitable when it provides relevant content, user authentication, learning evaluations, completion logs, and features adapted to the audience profile.
How do you prove that training took place?
Companies can compile annual schedules, syllabi, training materials, dates, course loads, target audience lists, attendance logs, evaluation test scores, completion reports, and certificates.
What is the best Compliance and Anti-Bribery training program?
The best program is legally up-to-date, reflects company-specific risks, reaches target audiences, uses practical scenarios, evaluates learning retention, and generates auditable evidence. Selection should not be based solely on course length, price, or vendor brand recognition.
Conclusion
The best Compliance and Anti-Bribery training programs in Brazil are not necessarily the longest or most well-known. They are the ones that transform laws and internal policies into actionable decisions in the workplace.
To achieve this, content must reflect business risks, cover employees and key third parties, incorporate practical scenarios, evaluate learning retention, and generate traceable data for audit defense.
Combining updated regulatory content, decision simulators, customization, assessments, and traceability transforms training from a box-checking exercise into an active driver of corporate integrity.
Want to discover a training solution that can be tailored to your organization’s risks, sector, and target audiences?
Request a demo of TothBe’s Anti-Corruption and Anti-Bribery Training.
Related Content:
ISO 37001:2025: What changed and how to adapt training programs
LGPD awareness and data privacy training




