Anti-Corruption Compliance: FCPA, UK Bribery Act, and FEPA

Anti-corruption compliance is the set of policies, controls, and practices a company uses to keep itself and its people on the right side of the U.S. Foreign Corrupt Practices Act, the UK Bribery Act, and the parallel anti-bribery laws now on the books in most major economies. A single violation can cost hundreds of millions of dollars, put executives in prison, and end careers. A credible program is the primary defense, and prosecutors judge it by whether it actually works in practice, not by whether a manual exists.

The Laws Your Program Has to Satisfy

Four legal regimes matter most for a company doing business across borders.

The Foreign Corrupt Practices Act

The FCPA, at 15 U.S.C. §§ 78dd-1 through 78dd-3, prohibits offering, paying, or promising anything of value to a foreign government official to influence an official act, secure an improper advantage, or obtain or keep business.1Office of the Law Revision Counsel. 15 USC 78dd-1 – Prohibited Foreign Trade Practices by Issuers “Anything of value” is broad: gifts, travel, charitable donations, and jobs for an official’s relatives all qualify when the purpose is corrupt.

The statute reaches three groups. Issuers are companies whose securities trade on a U.S. exchange, wherever they are incorporated. Domestic concerns include every U.S. citizen, resident, and any business organized or headquartered in the United States.2Office of the Law Revision Counsel. 15 USC 78dd-2 – Prohibited Foreign Trade Practices by Domestic Concerns A third provision captures anyone else, including foreign nationals and foreign companies, who takes any act in furtherance of a bribe while in U.S. territory or using U.S. interstate commerce, such as routing a wire transfer through a U.S. bank.

The FCPA carves out a narrow exception for small payments made to speed up routine government actions the official is already obligated to perform, such as processing a visa or scheduling a required inspection.3U.S. Securities and Exchange Commission. Investor Bulletin – The Foreign Corrupt Practices Act It does not cover any payment that influences whether or on what terms a government awards or continues business. Even where a facilitation payment is technically permitted under U.S. law, most other jurisdictions treat it as an illegal bribe, so a program that relies on the exception is exposing the company somewhere.

The UK Bribery Act 2010

The UK Bribery Act is broader than the FCPA in three important ways. It covers bribery of private-sector individuals, not just public officials. It criminalizes receiving a bribe, not just paying one. And it creates a strict-liability corporate offense: a commercial organization is guilty when any person associated with it pays a bribe to obtain or keep a business advantage, even if no one in management knew. The only defense is proving the organization had “adequate procedures” in place to prevent bribery.4The Crown Prosecution Service. Bribery Act 2010 – Joint Prosecution Guidance That single feature turns compliance program quality into a direct legal defense rather than a sentencing factor.

Individuals convicted on indictment face up to ten years in prison, and there is no statutory cap on fines for organizations.5UK Government. Bribery Act 2010 Section 11 – Penalties Any company that carries on business in the UK is within scope worldwide, so a U.S. company with a London office is covered by the Act globally. There is no exception for facilitation payments.

The OECD Convention and Its Progeny

The OECD Convention on Combating Bribery of Foreign Public Officials, now with 46 signatory parties, requires each member to criminalize bribery of foreign officials in international business under its own domestic law.6OECD. Working Group on Bribery The Convention focuses on the supply side: the payers, not the receivers.7U.S. Department of State. Fact Sheet – OECD Convention on Combating Bribery of Foreign Public Officials The practical result is a global patchwork of statutes, from Brazil’s Clean Company Act to France’s Sapin II law, that companies have to account for alongside the FCPA and Bribery Act.

The Foreign Extortion Prevention Act

Enacted in 2024, FEPA fills a gap the FCPA left open. Codified at 18 U.S.C. § 1352, it makes it a federal crime for a foreign official to demand, seek, or accept a bribe from a U.S. person, a U.S. company, or a company listed on a U.S. stock exchange.8Office of the Law Revision Counsel. 18 USC 1352 – Demands by Foreign Officials for Bribes Officials face up to 15 years in prison and fines up to $250,000 or three times the bribe amount, whichever is greater.9U.S. Department of Justice. Foreign Corrupt Practices Act Unit For companies, FEPA strengthens the case for documenting and reporting extortionate demands rather than quietly paying them.

What Violations Actually Cost

FCPA anti-bribery violations carry criminal fines up to $2 million per violation for corporations and up to $100,000 and five years’ imprisonment for individual officers, directors, employees, or agents, though the general federal sentencing statute allows courts to impose fines up to $250,000 for felony convictions.10Office of the Law Revision Counsel. 15 USC 78ff – Penalties Courts can also impose fines equal to twice the gain or twice the loss, whichever is greater, if that exceeds the statutory cap.

The books-and-records and internal-controls provisions carry even steeper penalties: up to $25 million for corporations that willfully falsify records or fail to maintain adequate controls, and up to $5 million and 20 years in prison for individuals.10Office of the Law Revision Counsel. 15 USC 78ff – Penalties SEC civil actions add disgorgement of profits and additional monetary penalties on top, and in large cases those figures dwarf the criminal fines.

The Core Elements of a Working Program

The DOJ evaluates whether a compliance program is “truly effective” by examining whether it is actually followed in practice, not just whether a policy manual sits on a shelf.11U.S. Department of Justice. Evaluation of Corporate Compliance Programs A program that exists only on paper is worse than useless: it proves the company knew the rules and chose not to follow them.

Code of Conduct and Gift Rules

A written code of conduct sets the baseline. It has to state the company’s zero-tolerance position on bribery and translate that position into the practical situations employees actually encounter: gifts, meals, entertainment, travel reimbursements, charitable donations, and political contributions. Most companies set dollar thresholds, commonly in the $50 to $100 range, above which any gift or hospitality requires pre-approval and documentation. The specific limit matters less than having one people actually follow and one that accounts for local customs in higher-risk markets.

The code has to be available in the native languages of all employees. An anti-bribery policy a plant manager cannot read is no policy at all.

Risk-Based Training

Annual training satisfies a checkbox. Effective training does more. Prosecutors look at whether a company tailors training to employees’ actual risk exposure, whether supervisors get supplemental training, and whether the company measures whether employees understood what they learned.11U.S. Department of Justice. Evaluation of Corporate Compliance Programs A salesperson working with government procurement officers in a high-corruption market needs different training than an accountant at headquarters.

Training that uses real scenarios and lessons from past compliance failures, including competitors’ failures, outperforms generic modules. Shorter, targeted sessions tend to outperform marathon webinars. A clear path for employees to ask case-by-case ethics questions signals depth.

Whistleblower Channels

Anonymous reporting hotlines, available around the clock in multiple languages, give employees a way to flag suspicious activity without exposing themselves. They need to be genuinely anonymous and visibly independent of local management. A hotline that routes to the country manager whose conduct is being reported does nothing.

Retaliation against whistleblowers is illegal and strategically ruinous. Under the Dodd-Frank Act, employees who report potential securities violations, including FCPA violations, to the SEC are protected from discharge, demotion, or other discriminatory treatment. An employee who suffers retaliation can sue for reinstatement, double back pay, and attorney’s fees. Beyond the legal exposure, punishing a whistleblower tells every other employee the program is for show.

Discipline and Remediation

When misconduct surfaces, the response matters as much as the underlying act. Discipline should be consistent and proportionate at every level, including senior management. If a junior employee is fired for a small bribe while an executive who approved a larger scheme is reassigned, prosecutors will notice.

Just as important: employees who refuse to pay a bribe cannot face adverse consequences, even if the refusal costs a deal. Companies that punish ethical behavior have no credible program regardless of what the code says. After any incident, the program itself should be reviewed and updated to close whatever gap the misconduct exploited.

Third-Party Due Diligence

Third-party agents, consultants, and distributors are where most FCPA enforcement actions originate. A company that hires a local agent and looks the other way does not escape liability by claiming ignorance. Before any third-party relationship, investigate the partner’s ownership structure and look specifically for government officials or their family members who hold a financial interest.

Practical due diligence uses detailed questionnaires covering past legal problems, government service, and business references, then verifies the answers against public records and legal databases. Certain facts should immediately escalate the review:

  • Payment requested in a country where the third party does no business, or into a personal rather than corporate account.
  • The entity has no physical office, no employees with relevant expertise, or no industry track record.
  • Beneficial owners include current or former officials, or the entity was formed just before the contract opportunity arose.
  • Public records show prior litigation, regulatory sanctions, or media reports linking the entity to questionable dealings.

Documenting every step of this process before signing creates a record prosecutors and regulators recognize as evidence of good faith. Skipping due diligence because a deal is moving fast is the most common failure in enforcement actions, and it never persuades anyone after the fact.

Books, Records, and Internal Controls

The FCPA’s accounting provisions apply to every issuer with securities registered on a U.S. exchange, regardless of whether any bribery occurred. Companies have to maintain books and records that accurately reflect all transactions and asset dispositions in reasonable detail.12U.S. Securities and Exchange Commission. Recordkeeping and Internal Controls Provisions Section 13(b) of the Securities Exchange Act of 1934 You cannot hide a bribe if every payment must be recorded with enough specificity that an auditor can tell what it was for. Vague line items like “consulting fees” or “miscellaneous expenses” are exactly the entries that trigger investigations.

Companies also have to maintain internal controls that provide reasonable assurance transactions are authorized and recorded properly. In practice that means segregating duties so the person authorizing a payment is not the one recording it. Regular internal audits should verify that payments correspond to services actually rendered at fair market value. Criminal penalties for willful circumvention reach $25 million for corporations and $5 million for individuals.10Office of the Law Revision Counsel. 15 USC 78ff – Penalties

The statute of limitations for FCPA criminal prosecutions is five years, and civil enforcement follows the same timeline, but investigations frequently begin years after the conduct. A company that destroys records prematurely may lose the ability to demonstrate its own innocence.

When Something Surfaces: Self-Disclosure and Cooperation

The DOJ’s Corporate Enforcement and Voluntary Self-Disclosure Policy offers substantial incentives to companies that come forward. A company that voluntarily discloses misconduct, fully cooperates, and remediates the problem can receive a complete declination of prosecution.13U.S. Department of Justice. Corporate Enforcement and Voluntary Self-Disclosure Policy When aggravating factors rule out a declination, the company can still receive a fine reduction of 50% to 75% off the low end of the federal sentencing guidelines range.

Companies that cooperate only after the government comes knocking receive less: prosecutors retain discretion but will not recommend more than a 50% reduction.13U.S. Department of Justice. Corporate Enforcement and Voluntary Self-Disclosure Policy The math favors self-reporting. A $100 million potential fine could drop to $12.5 million, or to zero, for a company that self-discloses and cooperates; a company that waits for a subpoena pays $50 million at best.

Some resolutions require an independent compliance monitor, typically for one to three years. The DOJ considers monitorship appropriate when a compliance program is untested, ineffective, or was not fully implemented at the time of resolution.14U.S. Department of Justice. Justice Manual 9-28.000 – Principles of Federal Prosecution of Business Organizations In practice it remains uncommon: out of the last 25 corporate FCPA resolutions over a recent five-year period, the DOJ imposed a monitor in only three.

Successor Liability in Mergers and Acquisitions

Acquiring a company means acquiring its compliance problems. If the target paid bribes before closing, the acquirer can inherit liability once the target becomes subject to U.S. jurisdiction. The DOJ has said a mere acquisition does not retroactively create liability where none previously existed, but that principle has limits. If the acquired company continues to benefit from contracts or relationships obtained through bribery after the acquisition, the new parent is exposed.

The DOJ’s M&A Safe Harbor Policy gives acquirers a clear path when misconduct surfaces during or shortly after closing. The acquiring company has to disclose within 180 days of closing and remediate within one year. Meeting those deadlines, with full cooperation, makes the company eligible for a declination on the acquired entity’s past conduct. Both deadlines can be extended based on the specific facts.

Pre-acquisition FCPA due diligence separates experienced buyers from naive ones. The standard playbook covers the target’s anti-corruption policies, an audit of high-risk payments and third-party relationships, interviews with key personnel, and financial red-flag checks. After closing, the acquirer implements its own compliance program at the target as quickly as practicable and runs FCPA-specific training for the target’s directors, employees, and third-party partners. Discovering a problem early and disclosing it voluntarily converts a potential enforcement disaster into a manageable compliance project.