Summary. The FCPA is enforced against companies that never intended to bribe anyone, through third parties they did not supervise, and proven with accounting provisions requiring no corrupt intent at all. This article covers the anti-bribery provision element by element — foreign official, instrumentality, anything of value, the facilitating payment exception, and the affirmative defenses — then the accounting provisions, which apply only to issuers but account for most enforcement. A long section addresses third-party intermediaries, followed by gifts and hospitality, charitable contributions, hiring, successor liability, the UK Bribery Act, and enforcement policy.
A US medical device manufacturer sells through independent distributors in fourteen countries. It has never made a payment to a government official, and its executives would be genuinely offended by the suggestion.
Its distributor in one country wins a tender to supply a state-owned hospital system. The distributor's commission is 22 percent, roughly triple the company's norm elsewhere, and was negotiated by a country manager who left two years ago. The distributor's owner is the brother-in-law of the hospital system's procurement director. Half the commission is paid to a consulting entity registered in a third country that provides "market access services."
No employee of the manufacturer made a payment. No employee knew about the family relationship. And the company faces exposure under the FCPA on two independent theories: anti-bribery liability if it knew or was aware of a high probability that part of the commission would go to an official, and books and records liability as an issuer, because commissions to an intermediary that were in substance payments to an official were recorded as commissions.
The second theory requires no proof of bribery at all. It requires only that the books not accurately and fairly reflect the transactions.
That asymmetry — a bribery statute enforced through accounting provisions — is the single most important thing to understand about FCPA risk.
The short answer
Two sets of provisions:
- Anti-bribery, 15 U.S.C. §§ 78dd-1, 78dd-2, 78dd-3 — prohibiting corrupt payments to foreign officials to obtain or retain business. Applies to issuers, domestic concerns, and, under § 78dd-3, any person acting within US territory.
- Accounting, 15 U.S.C. § 78m(b)(2) — the books and records and internal controls provisions. Applies only to issuers (companies with securities registered under section 12 or required to file reports under section 15(d)), including foreign private issuers with ADRs.
Enforcement. The DOJ has criminal authority over both, and civil authority over the anti-bribery provisions for domestic concerns. The SEC has civil authority over issuers for both.
The elements of an anti-bribery violation: a covered person, acting corruptly, who offers, pays, promises, or authorizes the giving of anything of value, to a foreign official (or to any person knowing it will be passed to an official), to influence an official act, induce an unlawful act, secure an improper advantage, or induce the official to use influence — in order to obtain or retain business.
Two things the statute does not require: that the payment succeed, and that the payment be made by an employee. An offer is enough, and a third party's payment can be attributed.
Jurisdiction and who is covered
Issuers, § 78dd-1 — any company with a class of securities registered under section 12 of the Exchange Act or required to file reports under section 15(d), including foreign companies with American Depositary Receipts. Liability attaches for acts using the mails or any means of interstate commerce in furtherance of a prohibited payment, and — since 1998 — for acts anywhere in the world by US issuers and their officers, directors, employees, agents, and stockholders acting on their behalf.
Domestic concerns, § 78dd-2 — US citizens, nationals, and residents, and any business entity organized under US law or with its principal place of business in the United States. Same territorial-plus-nationality reach.
Any person in US territory, § 78dd-3 — covering foreign persons and entities that take an act in furtherance of a corrupt payment while in the territory of the United States. Courts have divided on how far this reaches an entirely foreign actor, with the Second Circuit holding in United States v. Hoskins, 902 F.3d 69 (2d Cir. 2018), that a foreign national outside the statute's covered categories cannot be liable under conspiracy or accomplice theories for conduct the statute does not itself reach.
Parents and subsidiaries. A parent is liable for a subsidiary's conduct where the subsidiary acted as its agent, or where the parent participated in or authorized the conduct, or knew of it. For issuers, the accounting provisions reach majority-owned subsidiaries directly because their results are consolidated. For minority holdings, § 78m(b)(6) requires the issuer to proceed in good faith to use its influence to cause the affiliate to devise and maintain a compliant system.
Successor liability applies to acquisitions, discussed below.
Statute of limitations. Five years for the anti-bribery provisions; six years for the accounting provisions under the securities fraud limitations provision, and the government frequently obtains tolling agreements during investigations.
The elements
"Corruptly." The payment must be intended to induce the recipient to misuse an official position. The term connotes an evil motive or purpose, an intent to wrongfully influence. It does not require that the act be unlawful under local law, and it does not require the payment to succeed.
"Knowing." A person acts knowingly with respect to circumstances or a result if they are aware of it, or aware of a high probability of its existence, § 78dd-1(f)(2). This is conscious avoidance — deliberately ignoring warning signs is knowledge. It is how third-party conduct becomes company liability without any direct evidence.
"Anything of value." Not limited to cash. Enforcement actions have covered travel and entertainment, gifts, meals, charitable contributions to officials' preferred causes, medical expenses, scholarships and tuition, internships and jobs for officials' relatives, political contributions, discounts, loans, use of vehicles and property, and cash-equivalent gift cards. There is no de minimis exception in the statute.
"Foreign official." Any officer or employee of a foreign government or any department, agency, or instrumentality thereof, or of a public international organization, or any person acting in an official capacity for or on behalf of any of them, plus foreign political parties, party officials, and candidates.
"Instrumentality" is the contested term, because it determines whether employees of state-owned enterprises are officials. United States v. Esquenazi, 752 F.3d 912 (11th Cir. 2014), defined an instrumentality as an entity controlled by a foreign government that performs a function the government treats as its own, and supplied non-exhaustive factors: the government's formal designation, the government's ownership percentage, the government's power to hire and fire principals, whether profits go to the government and whether the government funds losses, the length of time these indicia have existed, the entity's monopoly, government subsidies, exclusive rights, and the general perception that the entity performs an official function.
The practical consequence is that employees of state-owned hospitals, telecoms, energy companies, airlines, banks, and universities are frequently officials — which is why healthcare, extractive, and infrastructure sectors generate a disproportionate share of enforcement.
"Obtain or retain business." Read broadly. United States v. Kay, 359 F.3d 738 (5th Cir. 2004), held that payments to reduce customs duties and taxes can violate the statute if they were intended to assist in obtaining or retaining business — the connection need not be to a specific contract award.
The facilitating payment exception, § 78dd-1(b). Payments to expedite or secure the performance of a routine governmental action are excepted. Routine governmental action means an ordinarily and commonly performed act such as obtaining permits or licenses to qualify to do business, processing visas and work orders, providing police protection, mail pickup, phone and utility service, loading and unloading cargo, and scheduling inspections — and it expressly excludes any decision to award new business or to continue business with a party.
The exception is far narrower than companies assume. It does not cover payments to obtain a favorable decision, to influence an outcome, or to secure anything the official has discretion over. Most other jurisdictions — including the United Kingdom — permit no such exception, so a global company operating a facilitating-payment policy is compliant with US law and non-compliant elsewhere. The prevailing practice is to prohibit them outright, with a duress carve-out for payments made under threat to health or safety, which are not FCPA violations for lack of corrupt intent but must be accurately recorded and reported internally.
Two affirmative defenses, § 78dd-1(c):
- The payment was lawful under the written laws of the foreign country. This is exceedingly rare; virtually no country's written law authorizes payments to its officials.
- The payment was a reasonable and bona fide expenditure, such as travel and lodging, directly related to the promotion, demonstration, or explanation of products or services, or to the execution or performance of a contract with a foreign government or agency.
The second defense is real and useful — it authorizes bringing officials to a plant for a legitimate product demonstration — but it is narrow. Enforcement actions have involved "inspection trips" featuring shopping, sightseeing, and side excursions for family members.
The accounting provisions
These apply only to issuers, and they account for the majority of FCPA enforcement, because they are far easier to prove.
Books and records, § 78m(b)(2)(A). Issuers must make and keep books, records, and accounts that in reasonable detail accurately and fairly reflect the transactions and dispositions of the issuer's assets. "Reasonable detail" means the level of detail that would satisfy prudent officials in the conduct of their own affairs.
Note what this provision does not require: no bribery, no materiality in the securities-law sense, and no corrupt intent. Recording a bribe as a "commission," a "consulting fee," or "marketing expenses" violates it. So does recording a legitimate expense inaccurately. Enforcement actions have been brought for mischaracterized entertainment, unsupported petty cash, off-book accounts, and inflated invoices — sometimes with no allegation of bribery at all.
Internal controls, § 78m(b)(2)(B). Issuers must devise and maintain a system of internal accounting controls sufficient to provide reasonable assurances that transactions are executed in accordance with management's authorization; that transactions are recorded as necessary to permit preparation of financial statements in conformity with GAAP and to maintain accountability for assets; that access to assets is permitted only in accordance with management's authorization; and that recorded accountability for assets is compared with existing assets at reasonable intervals.
This is where the compliance program becomes a legal requirement in substance. Controls the SEC has cited as inadequate include: no diligence on third-party intermediaries, no approval process for gifts and entertainment, no verification that services invoiced were performed, unmonitored petty cash, discount and rebate authority without oversight, and no testing of the controls that existed on paper.
Knowing falsification of books and records, or knowing circumvention of internal controls, is a criminal violation under § 78m(b)(5), carrying individual exposure.
No private right of action exists under the FCPA. Private plaintiffs proceed through securities fraud claims, derivative suits, and RICO or state-law theories, and shareholder derivative litigation reliably follows a significant enforcement action.
Third parties: where the exposure lives
The overwhelming majority of FCPA enforcement actions involve payments made by agents, distributors, consultants, joint venture partners, customs brokers, freight forwarders, and local sponsors rather than by employees.
The statute reaches this through the knowledge standard: a company is liable if it knew, or was aware of a high probability, that a payment would be passed to an official. Conscious avoidance is knowledge. A company that structures its relationships to avoid learning what its agents do has not solved the problem; it has documented the state of mind the statute condemns.
Third-party red flags, drawn from enforcement actions and from the DOJ and SEC Resource Guide:
- The intermediary was recommended by the government official or customer.
- Family, personal, or business ties between the intermediary and officials.
- The intermediary lacks staff, facilities, or expertise to perform the services.
- Compensation is disproportionate to the services, or is a large percentage success fee.
- Requests for payment to a third country, to a numbered account, in cash, or to a party other than the contracting entity.
- Requests for payment in advance of any services, or for an unusual bonus.
- Refusal to sign anti-corruption representations or to allow audit rights.
- Vague or generic descriptions of services rendered; invoices without detail.
- Operating in a country with a high perceived corruption risk.
- Reluctance to disclose beneficial ownership.
- The intermediary was recently formed or has no track record.
- Unusual contract terms, off-book arrangements, or a request to disguise the relationship.
Risk-based due diligence — proportionate to the risk, documented, and refreshed:
- Screen against sanctions, debarment, enforcement, and adverse media databases.
- Obtain a completed questionnaire: ownership and beneficial ownership, government affiliations of owners and employees and their family members, other clients, licenses held, and prior investigations.
- Verify the information independently — corporate registries, references, site visits for higher-risk relationships, and in-country investigative diligence where the risk warrants.
- Assess business rationale: what does this intermediary do that the company cannot do itself, and is the compensation consistent with market?
- Resolve red flags in writing before engaging. An unresolved red flag is the evidence of conscious avoidance.
- Approve at a level commensurate with risk, with legal and compliance sign-off.
- Refresh periodically and on any change in ownership, personnel, or role.
Contract provisions that matter:
- Anti-corruption representations and warranties, and covenants of ongoing compliance.
- A prohibition on subcontracting or delegating without consent.
- Audit rights over books and records relating to the engagement, exercisable on notice.
- Termination rights for breach or for a credible suspicion of a violation, without penalty.
- Compensation terms that are documented, market-based, and paid to the contracting entity in the country of performance, into an account in its name.
- Invoicing requirements: itemized descriptions of services actually performed.
- Certification of compliance, annually.
- Training obligations.
- Indemnity — of limited practical value against an insolvent agent, but useful as a signal.
Monitoring is what distinguishes a program that works: exercising audit rights at least occasionally, reviewing invoices for substance, testing whether services were performed, and following up on the certifications rather than filing them.
Gifts, hospitality, charitable contributions, and hiring
Gifts, travel, and entertainment are lawful in principle and are the subject of many enforcement actions in practice. A defensible framework:
- Prohibit cash and cash equivalents, including gift cards.
- Set modest per-item and annual limits, adjusted for local norms, with pre-approval above a threshold.
- Require a legitimate business purpose and, for travel, a genuine agenda directly related to promotion or contract performance.
- Pay directly to the vendor, not by reimbursing the official.
- Prohibit payments for family members and for side trips.
- Confirm the official's own rules permit acceptance — many governments prohibit gifts outright.
- Record accurately and specifically in the books: not "entertainment," but who, what, when, and why.
- Prohibit gifts and hospitality entirely during a live tender or pending decision.
Charitable contributions have been the vehicle in several enforcement actions where the charity was connected to an official or where the donation was requested in connection with a pending decision. Controls: due diligence on the recipient organization and its principals, confirmation that no official controls or benefits from it, a written agreement with use restrictions and audit rights, no donations requested by an official in connection with a pending matter, and accurate recording.
Hiring of officials' relatives — the "princelings" pattern — has produced significant enforcement, including cases in which internships and jobs were provided in exchange for business. Controls: apply the same standards as for any other candidate, document the qualifications and the ordinary-course process, prohibit hiring at the request of an official with a pending matter, and require compliance approval for any candidate referred by a government-affiliated source.
Political contributions to foreign parties, officials, and candidates are within the anti-bribery provision's scope and should be prohibited outright.
Successor liability
A company generally acquires the FCPA exposure of the entity it buys, in a stock deal without qualification and in an asset deal depending on structure and on successor liability doctrine.
Pre-acquisition diligence should include: identification of government customers and touchpoints; the third-party intermediary population and the diligence performed on it; commission and discount structures; gifts and entertainment records; petty cash and cash-intensive operations; the compliance program, training records, and hotline history; prior investigations, audits, and enforcement contacts; and country risk mapping.
Where diligence is impracticable — a hostile transaction, a carve-out with poor records, or a jurisdiction where access is limited — DOJ policy contemplates post-acquisition remediation. The M&A safe harbor in the Department's corporate enforcement policy provides that where an acquirer promptly and appropriately discloses misconduct discovered through bona fide, timely, and reasonable pre- or post-acquisition diligence, and remediates fully, there is a presumption of a declination for the acquirer, absent aggravating circumstances — with a defined period after closing for the disclosure and remediation.
Post-closing integration should include: extending the acquirer's code and policies, training, integrating the acquired entity into the financial reporting and internal control environment, re-screening and re-papering third parties, auditing high-risk transactions, and terminating relationships that cannot be remediated.
Deal protection: anti-corruption representations, a specific indemnity with its own survival and cap, an escrow sized to the risk, and a closing condition where diligence is incomplete.
The UK Bribery Act and other regimes
A US company with international operations is subject to more than the FCPA, and the other regimes are in some respects broader.
The UK Bribery Act 2010 differs in four significant ways:
- It prohibits commercial bribery — bribery of private parties — not only bribery of officials.
- It contains no facilitating payment exception.
- It creates a corporate offense of failing to prevent bribery by an associated person, section 7, which is a strict liability offense subject to one defense: that the organization had adequate procedures in place designed to prevent bribery.
- Its jurisdictional reach extends to any organization that carries on a business or part of a business in the United Kingdom, regardless of where the conduct occurred.
The adequate procedures defense is defined by six principles in the Ministry of Justice guidance: proportionate procedures, top-level commitment, risk assessment, due diligence, communication including training, and monitoring and review. Those six principles are a serviceable specification for a global program.
Other frameworks to account for: the OECD Anti-Bribery Convention and the implementing legislation of its parties; France's Sapin II, which requires a defined compliance program and is enforced by the Agence Française Anticorruption; Brazil's Clean Company Act, which imposes strict corporate liability with mitigation for compliance programs; and the growing number of jurisdictions with failure-to-prevent offenses. The Foreign Extortion Prevention Act added US criminal liability for foreign officials who demand bribes, complementing the FCPA's supply-side focus.
Local law matters independently. Payments lawful under the FCPA's affirmative defense are vanishingly rare, but many countries impose their own gift limits, public procurement rules, and registration requirements for agents, and a global policy should defer to the stricter rule.
Enforcement policy, disclosure, and resolutions
The DOJ's corporate enforcement policy creates a structured set of incentives. Where a company voluntarily self-discloses misconduct, fully cooperates, and timely and appropriately remediates, there is a presumption of declination absent aggravating circumstances — such as involvement by executive management, significant profit from the misconduct, pervasiveness, or recidivism. Where aggravating circumstances warrant a criminal resolution, self-disclosure earns a substantial reduction off the low end of the Sentencing Guidelines fine range and, generally, no monitor where the compliance program has been implemented and tested.
Cooperation in this context means timely disclosure of relevant facts about individuals, preservation and production of documents including those located abroad, deconfliction with the government's investigation, and making witnesses available.
Remediation means root cause analysis, discipline of responsible individuals, compensation clawbacks where available, and demonstrable improvement to the compliance program, tested.
Resolution vehicles: a declination with disgorgement; a non-prosecution agreement; a deferred prosecution agreement with a term, an admitted statement of facts, a penalty, and often reporting obligations; a guilty plea; and, on the SEC side, administrative proceedings or civil actions with disgorgement and prejudgment interest. Independent compliance monitors are imposed selectively, and Department policy has emphasized that monitors should not be the default where the company has implemented and tested an effective program.
Individual accountability is the stated priority. Executives face criminal charges, and the SEC pursues officers and directors, including for internal controls violations.
Evaluating a program. The Criminal Division's Evaluation of Corporate Compliance Programs guidance asks three questions: Is the program well designed? Is it applied earnestly and in good faith — adequately resourced and empowered? and Does it work in practice? The guidance addresses risk assessment, policies and procedures, training and communications, confidential reporting and investigation, third-party management, mergers and acquisitions, autonomy and resources, incentives and discipline, continuous improvement and testing, and the use of data analytics. It is the closest thing to a specification the government publishes, and it should be read by anyone building a program.
A worked example
Return to the medical device manufacturer.
Detection. An internal audit of distributor margins flags the 22 percent commission as an outlier. A hotline report from a departing regional employee references "the brother-in-law arrangement."
Immediate steps. Counsel is engaged. A litigation hold issues. The investigation is scoped in writing and conducted under privilege, with a forensic accounting firm retained through counsel. Payments to the distributor are suspended pending review — carefully, to avoid tipping off custodians before preservation is complete.
Findings. Over four years, roughly $2.4 million in commissions were paid. About $1.1 million was paid onward to a consulting entity beneficially owned by the procurement director's spouse. The company's country manager knew and did not report it. Diligence on the distributor consisted of a credit check performed in year one. The commission rate was approved by a regional vice president who did not question it. The payments were recorded as "sales commissions."
Exposure. Anti-bribery liability turns on knowledge or conscious avoidance — the country manager's knowledge is attributable, and the unresolved red flags support conscious avoidance at the regional level. Books and records liability is straightforward: commissions that were in substance payments to an official were not accurately recorded. Internal controls liability is straightforward as well: no third-party diligence, no commission benchmarking, no verification that services were performed.
Response.
- Voluntary self-disclosure to DOJ and SEC, within the policy's timing expectations, after enough investigation to describe the conduct accurately.
- Full cooperation, including identification of the individuals involved.
- Remediation: terminate the distributor and the country manager; discipline the regional vice president; implement third-party diligence, approval, and monitoring across all fourteen countries; benchmark and cap commissions with exception approval; require itemized invoices and verification of services; add anti-corruption terms and audit rights to all intermediary contracts; train the sales organization; enhance the hotline; and test the new controls.
- Disgorge the profits attributable to the affected tenders.
Outcome. The combination of prompt self-disclosure, full cooperation, and thorough remediation places the company within the presumption of declination, subject to disgorgement, absent aggravating circumstances — the outcome the policy is designed to produce, and one unavailable to a company that discovered the same facts and decided to fix it quietly.
A compliance program checklist
Foundation
- A written anti-corruption policy in local languages, distributed and acknowledged.
- Tone from the top, evidenced by communications and by decisions that cost money.
- A risk assessment by country, sector, customer type, and channel, refreshed periodically and documented.
- A compliance function with autonomy, resources, and access to the board.
Third parties
- A complete inventory of intermediaries, refreshed continuously.
- Risk-tiered diligence with documented red flag resolution and approval.
- Contract terms: representations, audit rights, no subcontracting, termination, itemized invoicing, annual certification.
- Monitoring: sample invoice review, verification of services, periodic audits actually exercised.
Transactions and controls
- Gifts, travel, and entertainment policy with limits, pre-approval, and accurate coding.
- Charitable contribution and sponsorship approval process.
- Hiring controls for candidates referred by government-affiliated sources.
- Petty cash, discount, and rebate controls with segregation of duties.
- Vendor master controls preventing payment to unapproved parties or third-country accounts.
- Accurate account coding with specific descriptions, and periodic testing.
People
- Training by role and risk, in local languages, refreshed.
- A confidential reporting channel available in every country, with anti-retaliation protection.
- Discipline applied consistently, including to high performers, and incentives that do not reward results without regard to means.
Deals
- Anti-corruption diligence in every acquisition and joint venture.
- Post-closing integration plan with a defined timeline.
- Deal terms: representations, specific indemnity, escrow, and closing conditions.
Assurance
- Testing and auditing of controls, with data analytics on payments, vendors, and expense patterns.
- Continuous improvement documented, including changes made in response to findings.
- A written investigation and disclosure protocol decided before it is needed.
Frequently asked questions
We do not sell to governments. Are we exposed? Possibly. Customs, licensing, permitting, tax, inspection, and immigration touchpoints all involve officials, and state-owned enterprises are frequently instrumentalities, which makes their employees officials.
Are small gifts allowed? There is no de minimis exception in the statute. A modest, transparent, accurately recorded gift with a legitimate business purpose, permitted by the official's own rules, is a very different matter from a pattern of gifts around a pending tender — but the analysis is about purpose and record, not amount.
Can we make facilitating payments? Under the FCPA, narrowly, for routine governmental actions. Under the UK Bribery Act and most other regimes, no. Most global companies prohibit them, with a duress exception that must be reported and recorded.
Our agent made the payment, not us. Are we liable? If you knew, or were aware of a high probability, or consciously avoided finding out. Unresolved red flags are how that is proven.
What if the payment is customary in that country? Custom is not the affirmative defense. The defense requires that the payment be lawful under the written laws of the country, which it almost never is.
Do the accounting provisions apply to us? Only if you are an issuer. Private companies face the anti-bribery provisions only — which is a meaningful difference, because the accounting provisions are what make most cases easy to prove.
Should we self-disclose? Investigate first, then decide with counsel. The DOJ's policy creates a presumption of declination for prompt disclosure, full cooperation, and remediation, and the incentives are deliberately strong.
We are buying a company in a high-risk market. What if diligence is limited? Do what is reasonable pre-closing, and plan the post-closing remediation. The M&A safe harbor is designed for exactly that situation, but it requires prompt disclosure and genuine remediation within the defined period.
Conclusion
The FCPA punishes two very different failures. The first is bribery, which is rare and which most companies have no intention of committing. The second is not knowing — not knowing who the intermediaries are, not knowing why a commission is three times the norm, not knowing whether the services invoiced were performed, and not recording transactions in a way that reflects what actually happened.
The second failure is what enforcement actions are made of, and it is entirely a systems problem. A third-party inventory, risk-tiered diligence with documented resolution of red flags, contract terms with audit rights that are occasionally exercised, and accurate account coding would prevent the great majority of FCPA cases that have ever been brought.
None of that requires anyone to be honest, which is the point. It requires only that the company build controls that make dishonesty visible before the government finds it.
Practical guidance for smaller companies
Most FCPA guidance is written for multinationals with compliance departments. A company with sixty employees and distributors in eight countries faces the same statute and none of the infrastructure. Five steps carry most of the value.
1. Build the intermediary list. Not the vendor master — the list of every party that touches a customer on the company's behalf: distributors, agents, resellers, customs brokers, freight forwarders, local sponsors, and consultants. Most small companies cannot produce this list on request, and producing it is the first thing an investigation requires.
2. Ask four questions about each one. Who owns it? Is any owner, officer, or close family member a government official or connected to one? What does it actually do for us? Is its compensation consistent with what we pay elsewhere for similar work? Four questions, answered in writing, resolve most of the exposure — and an unanswerable question is itself the finding.
3. Fix the paperwork once. A two-page anti-corruption addendum to every intermediary agreement, containing representations, a no-subcontracting clause, audit rights, itemized invoicing, an annual certification, and a termination right. It costs one afternoon of drafting and is reused indefinitely.
4. Code expenses accurately. The books and records provisions do not apply to a private company, but the same records will be examined under the anti-bribery provisions and by any acquirer. "Consulting" and "marketing expense" as catch-all codes are the single most damaging accounting habit a small company can have. Require a description of who, what, and why.
5. Decide the hard cases in advance. Write down, before anyone is standing at a customs counter, what the company will do when asked for a payment to release a shipment; when a customer's procurement officer suggests a particular distributor; when an official requests a donation; and when a candidate is referred by a government contact. A one-page decision guide distributed to the people who face these situations prevents more violations than a thirty-page policy nobody reads.
What to skip. A small company does not need a monitor, a data analytics program, or a global hotline vendor. It needs to know who its intermediaries are, why they are paid what they are paid, and what its records say about it. Everything else scales later.
Related articles
- Export Controls and Economic Sanctions — the parallel cross-border compliance regime.
- Internal Investigation and Upjohn Warning Checklist — running the investigation before disclosure.
- Responding to a Government Subpoena or Civil Investigative Demand — handling the government's process.
- Whistleblower and Retaliation Claims — the SEC program that surfaces many FCPA cases.
- Distribution, Reseller, and Channel Partner Agreements — contracting with the intermediaries at issue.
- Buying and Selling a Business Toolkit — diligence and successor liability.
- Corporate Governance for Closely Held Companies — board oversight of compliance risk.
- Securities Fraud Litigation Under Rule 10b-5 — the follow-on shareholder litigation.
- Litigation Hold and Evidence Preservation Checklist — preservation at the outset of an investigation.
- Attorney-Client Privilege and Work Product for Businesses — structuring the investigation for privilege.
This article is provided for general informational purposes and does not constitute legal advice. Enforcement policy, declination criteria, and the scope of related statutes change, and non-US anti-corruption regimes impose additional and sometimes stricter obligations. Consult qualified counsel before engaging a foreign intermediary, responding to a demand for payment, or deciding whether to disclose.