🇵🇹 Daily Portugal news for expats & investors — FREE Subscribe

Twenty of Thirty-Eight Audited State Bodies Run No Staff Rotation at All, and Thirteen Never Reported the Whistleblower Complaints They Took In

The finance inspectorate audited how Portugal's anti-corruption regime is applied across 38 public entities in 2024. Nearly all had the required documents; a large share were not doing what the documents say.

Twenty of Thirty-Eight Audited State Bodies Run No Staff Rotation at All, and Thirteen Never Reported the Whistleblower Complaints They Took In

The Inspeção-Geral de Finanças, the finance ministry's audit body, has published the results of an audit into how Portugal's anti-corruption rulebook is actually being applied inside the state. It examined 38 public entities in the finance, economy and Presidency of the Council of Ministers areas, looked at the year 2024, and found that almost all of them own the documents the law demands while a substantial number are not doing what the documents say.

The rulebook in question is the Regime Geral de Prevenção da Corrupção, in force since 2022. It obliges public and larger private bodies to keep a risk-prevention plan, a code of conduct, internal and external whistleblowing channels, a named compliance officer and a training programme. The IGF's finding is that adoption is close to universal and application is not.

Thirty-Seven Plans, Thirteen of Them Silent on the Boardroom

Thirty-seven of the 38 entities had a Plano de Prevenção de Riscos de Corrupção e Infrações Conexas. Thirteen of those plans did not identify any risk attached to the exercise of senior management or board functions, which is to say they mapped the risk of corruption everywhere except at the top. In two entities the measures covering high risks were not detailed or prioritised sufficiently, and seven were in the middle of revising their plans when the auditors arrived.

Codes of conduct were near universal too, with one entity still drafting. Two of the codes did not set out any sanction for breaching them.

The Reporting Channels Nobody Reported On

The weakest area was whistleblowing. One audited entity had no internal reporting channel at all. Five had no external channel despite being required to run one. Of the 33 that did have an external channel, 13 never produced the annual report on the complaints they received in 2024. Three entities had not designated a compliance officer, and one had no training programme on the regime whatsoever.

The evaluation reports fared little better. Among the 29 entities that had identified high or maximum risk situations, nine failed to produce the interim assessment of their prevention plan for 2024, and a further seven produced no annual assessment and offered the IGF no explanation it considered plausible. Readers who want to know what protection the law gives a person who does come forward can consult our guide to the denunciante regime.

What the Websites Do Not Show

Every entity published its prevention plan. After that the list of omissions is long. Twelve did not publish who their compliance officer is. Seven gave no information about the training programme or the sessions held under it. Nine had not published their 2023 or 2024 activity and accounts reports, four were missing activity plans for 2024 and 2025, eight had not published the orders appointing their senior staff and four published incomplete information about those appointments. Six were missing notices of relevant pre-contractual procedures, and five gave no information about multi-year commitments or overdue payments and receipts.

Rotation, and Why It Is Not Happening

The single most widespread gap concerns staff rotation, a standard control against corruption in roles that handle money or award contracts. Twenty of the 38 entities had not implemented any rotation mechanism, and a further one rotated staff only partially. The justifications offered were the small size of the organisation and a shortage of staff.

Three entities admitted they had no adequate internal control mechanisms, and seven were revising theirs. Fourteen did not regularly promote or monitor the implementation of the internal control system, and five had no software able to cross-check information reliably. On impartiality, three entities had adopted no measures to guarantee the independence of managers and staff, in nine the measures were judged insufficient, and six could not demonstrate any rules or procedures for handling requests to hold a second job.

The IGF recommended that the boards of all 38 revise or complete their plans, publish what the law says they must publish and strengthen internal control. According to the inspectorate, every audited entity accepted the recommendations and the deadlines attached to them.