FCPA Compliance Program: Policies, Third Parties, and DOJ Review

An FCPA compliance program is the set of written policies, internal controls, training, and monitoring a company puts in place to prevent and detect violations of the Foreign Corrupt Practices Act. The Department of Justice and the Securities and Exchange Commission judge these programs against three questions: is the program well designed, is it adequately resourced and applied in good faith, and does it actually work in practice?1U.S. Department of Justice. Evaluation of Corporate Compliance Programs A program that satisfies all three can earn a company a presumption of declination when misconduct surfaces. A program that exists only on paper offers no protection at all.

What the Program Has to Prevent

The FCPA has two sets of prohibitions, and a compliance program has to cover both. The anti-bribery provisions make it illegal to pay, offer, or authorize anything of value to a foreign government official to win or keep business.2U.S. Department of Justice. Foreign Corrupt Practices Act Unit “Anything of value” is read broadly: cash, gifts, travel, charitable donations made at an official’s request, internships for an official’s family member. The payment doesn’t need to succeed. Offering or authorizing it is enough. The prohibition also reaches indirect payments through agents, consultants, or joint venture partners when the company knows the money is going to influence an official.3Office of the Law Revision Counsel. 15 US Code 78dd-1 – Prohibited Foreign Trade Practices by Issuers

The accounting provisions require publicly traded companies to keep books and records that accurately reflect their transactions and to maintain internal accounting controls strong enough to ensure management authorized each transaction.4U.S. Securities and Exchange Commission. 15 USC 78m – Periodical and Other Reports Bribes rarely appear in a ledger labeled “bribe.” They get buried as consulting fees, marketing expenses, or commissions. Because of that, the accounting provisions apply whether or not a bribery violation occurred, and a company can face enforcement action solely for sloppy books.

Who Needs an FCPA Compliance Program

The FCPA’s anti-bribery reach covers three categories. Issuers are any company with securities listed on a U.S. exchange or required to file reports with the SEC, including foreign companies with American Depository Receipts on a U.S. exchange. Domestic concerns are U.S. citizens, residents, or entities organized under U.S. law or headquartered here. Since 1998, the law has also reached any foreign person or entity that takes an act in furtherance of a corrupt payment while in U.S. territory. Officers, directors, employees, agents, and shareholders acting on behalf of any of these are personally covered too.3Office of the Law Revision Counsel. 15 US Code 78dd-1 – Prohibited Foreign Trade Practices by Issuers

The accounting provisions apply only to issuers. A private company still needs anti-bribery controls, but its program can focus there. Any private company that later goes public inherits retroactive accounting exposure for pre-IPO conduct, which is worth factoring in early if an offering is on the horizon.

How the DOJ Evaluates a Compliance Program

Prosecutors deciding whether to charge, reduce a fine, or require a monitor apply the Criminal Division’s three fundamental questions.1U.S. Department of Justice. Evaluation of Corporate Compliance Programs

Is the program well designed? Policies, training, reporting lines, and incentive structures should be integrated into daily operations rather than sitting in a binder.

Is it resourced and empowered? The compliance function needs adequate staff, budget, and genuine authority. Prosecutors look for signs that management is actually enforcing the rules or tacitly encouraging shortcuts.

Does it work in practice? A program that looks good on paper but has never caught anything is a red flag, not a defense. Prosecutors want to see the program tested and updated based on real findings.

There is no rigid formula. Prosecutors make an individualized determination based on the company’s size, industry, geographic footprint, and regulatory landscape. A five-person export firm should not look like a multinational energy company, and the DOJ expects that. What matters is whether resources are directed at the highest-risk areas. Prosecutors have said they will give credit to a risk-based program focused on high-risk transactions even when it fails to prevent a specific violation.

The updated guidance also asks pointed questions about emerging technology. Has the company assessed how artificial intelligence affects its ability to comply with criminal law? Is AI governance integrated into enterprise risk management? Are there controls to keep AI tools trustworthy and consistent with the code of conduct? On the flip side, is the company using data analytics to monitor its own compliance operations? A program that ignores available technology for surfacing risk invites questions about whether it’s functioning at all.

Written Policies and Codes of Conduct

Every program starts with a written code of conduct that clearly prohibits corrupt payments to foreign officials. Beyond the code, specific anti-corruption policies need to address the scenarios employees actually run into: gifts and entertainment for government contacts, charitable donations, travel sponsorships, political contributions. These should be tailored to the company’s industry risks and the countries where it operates. A template pulled from another company’s website is a compliance program in name only.

Gifts, Travel, and Entertainment

The FCPA sets no dollar threshold for prohibited gifts. A cup of coffee won’t trigger enforcement, but the statute has no safe harbor amount. Companies handle this by setting their own internal limits and requiring pre-approval above a defined value. Expense records for anything provided to a government official should capture who received it, their position, the business purpose, and a receipt. Proper documentation is what separates a legitimate promotional expense from a payment prosecutors will treat with suspicion.

Facilitating Payments

The statute contains a narrow exception for “facilitating payments,” meaning small payments to speed up routine government actions the official is already required to perform, like processing visas, providing utility connections, or scheduling inspections.5U.S. Securities and Exchange Commission. Investor Bulletin: The Foreign Corrupt Practices Act It does not cover any payment that influences whether to award or continue business. In practice the exception is a trap. The line between expediting a routine action and influencing a discretionary decision is blurry, enforcement agencies read it narrowly, and most compliance professionals recommend prohibiting facilitating payments outright. Surveys show the vast majority of U.S. companies have banned them regardless of the statutory exception.

Ephemeral Messaging

The DOJ now examines how companies handle business communications sent through messaging apps with disappearing-message features. Prosecutors look for a written policy governing the use of these platforms, training on that policy, and mechanisms to preserve business communications regardless of the channel used.1U.S. Department of Justice. Evaluation of Corporate Compliance Programs The DOJ will not accept an unexplained failure to produce communications from off-network apps, and using disappearing features to hide evidence can support obstruction charges. Companies should assess employee app usage, define which platforms are approved and for what purposes, require preservation of business communications regardless of origin, and include these platforms in litigation hold notices.

Accounting Controls and Audits

For issuers, the accounting provisions require books and records that accurately reflect the company’s transactions and a system of internal accounting controls strong enough to give reasonable assurance that transactions happen only with management’s authorization and that recorded assets are periodically compared against what actually exists.4U.S. Securities and Exchange Commission. 15 USC 78m – Periodical and Other Reports Every dollar spent needs to be recorded honestly, and someone independent needs to check the records against reality. Off-book accounts, vague ledger entries, and lump-sum consulting payments with no detail are the accounting failures that trigger enforcement.

Periodic auditing is how the compliance program tests itself. A typical schedule includes quarterly reviews of high-risk transactions and a comprehensive annual audit. Auditors examine expense reports, vendor payments, gift logs, and third-party commission structures to confirm they align with authorized limits and policies. Findings should be shared with the relevant department heads, and any identified weaknesses need documented corrective action with follow-up verification.

Leadership, Independence, and Compensation

A compliance program without senior leadership support is paperwork. The DOJ looks at whether management is genuinely enforcing compliance or going through motions. That starts with a chief compliance officer who has real authority and a direct reporting line to the board of directors rather than a chain that runs through the CFO or general counsel. If the compliance officer reports to someone whose bonus depends on closing deals, the independence is compromised before the program even starts.

The board and senior management are responsible for making sure the program has enough staff, budget, and technology to function. Board minutes should reflect regular compliance updates covering risk assessments, investigation outcomes, and program changes. Leaders also communicate through their own behavior. A CEO who jokes about “doing whatever it takes” overseas sends a message no training module can undo.

Compensation Tied to Compliance

The DOJ now requires all companies entering into corporate criminal resolutions to build compliance-related criteria into compensation and bonus systems.6U.S. Department of Justice. Corporate Enforcement Note: Compensation Incentives and Clawback Pilot That means rewarding ethical behavior, structuring deferred compensation to reward long-term good conduct, and clawing back pay from employees who breach compliance rules. Companies that withhold compensation from individuals responsible for misconduct can receive a dollar-for-dollar reduction in their own fines. The DOJ gives companies significant latitude in designing these structures, but linking pay to compliance is no longer optional for any company resolving an enforcement action.

Third-Party Due Diligence

Third-party intermediaries are where most FCPA violations happen. A company hires a local agent, consultant, or distributor, and that intermediary pays bribes to win contracts. The company can be held liable even if no one at headquarters knew about the payments, as long as there were reasons to suspect them. This is the single most important operational component of any compliance program.

Every third-party relationship should begin with a due diligence file that includes beneficial ownership information identifying who actually profits from the entity, verification that no government officials or their family members hold financial interests, and a check of the entity’s business reputation through databases, media searches, and local references. Depth should match risk. A vendor supplying office furniture in a low-corruption country does not need the same scrutiny as a government-relations consultant in a country with a high corruption perception index.

Red Flags

Certain patterns signal elevated bribery risk and should trigger deeper investigation before a relationship proceeds:

  • Commissions significantly above market rate for the services actually provided.
  • Requests to be paid in cash rather than by wire transfer.
  • Payments to unrelated third parties or offshore accounts with no obvious connection to the work.
  • Resistance to providing financial records, ownership information, or references.
  • A beneficial owner who is a current or former government official, or a close family member of one.

A high-risk score on the due diligence assessment should trigger enhanced review, which may involve in-person interviews, deeper financial investigations, and verification that the third party’s compensation reflects fair market value for the services actually being performed.

Contract Protections

Every third-party contract should include anti-corruption representations and warranties, a right-to-audit clause allowing inspection of the third party’s books and records, and a termination provision that activates if the third party violates anti-corruption laws or refuses to cooperate with compliance reviews. In an enforcement action, prosecutors examine whether the company had contractual tools to detect and stop misconduct by its partners.

Training and Communication

Training has to reach the people who face actual bribery risk. Online modules work for general awareness across the company, but employees in sales, business development, government affairs, and international management need interactive sessions built around realistic scenarios. Localized-language training is essential for employees in foreign offices who may not be fluent in the parent company’s primary language.

Companies must keep records proving that training happened: completion dates and scores for online modules, attendance for live sessions, and signed certifications from each participant confirming they understand the anti-corruption policies. Those records are evidence of good-faith compliance efforts during a government investigation. Beyond formal training, internal newsletters, portal updates, and targeted communications reinforce policy changes and remind employees of reporting channels. A program that speaks up once a year during annual training is not the continuous engagement prosecutors expect.

Internal Reporting and Investigations

Employees need a way to report suspected misconduct without fear of retaliation. An anonymous hotline available around the clock and in multiple languages is the baseline. The DOJ now looks at whether employees actually trust the system. Companies that measure only the volume of reports are missing the point. Leading programs survey employees on willingness to speak up, track the gap between perceived willingness and actual reporting, and share anonymized outcomes so the workforce sees that reports lead to real consequences.

When a report comes in, the compliance team needs a documented intake process to categorize the allegation and decide whether a formal investigation is warranted. Investigations follow consistent steps: preserve relevant emails and financial documents immediately, engage internal or external counsel to conduct interviews and review evidence, and document findings in a formal report to the chief compliance officer and the board. The report should include recommended remedial actions, whether disciplinary measures, process changes, or referral for potential self-disclosure to the government.

Timing of Voluntary Self-Disclosure

When an investigation confirms potential FCPA violations, the company has a decision to make. Under the DOJ’s Corporate Enforcement and Voluntary Self-Disclosure Policy, a company that voluntarily self-discloses, fully cooperates, and timely remediates receives a presumption that prosecutors will decline to bring charges, provided there are no aggravating circumstances such as particularly egregious conduct or recent recidivism.7U.S. Department of Justice. Justice Manual 9-47.120 – Criminal Division Corporate Enforcement and Voluntary Self-Disclosure Policy

To qualify, the company must disclose reasonably promptly after discovering the misconduct and before it becomes aware of an impending government investigation. It must also turn over all relevant facts, including information about the individuals involved. If a declination isn’t warranted because of aggravating factors, full self-disclosure credit typically means a fine reduced by up to 50% below the low end of the sentencing guidelines range and often avoids the appointment of an independent compliance monitor.7U.S. Department of Justice. Justice Manual 9-47.120 – Criminal Division Corporate Enforcement and Voluntary Self-Disclosure Policy

For reports that arrive through internal whistleblower channels, the DOJ expects disclosure within 120 days of receiving the report. The definition of recidivism has also expanded: the DOJ looks at resolutions from the prior five years and any earlier resolution involving similar conduct regardless of when it occurred. Those timelines create urgency to investigate internal reports quickly and make disclosure decisions without unnecessary delay.

Mergers and Acquisitions

Acquiring a company means inheriting its FCPA exposure. If the target has been paying bribes through foreign subsidiaries, the buyer can face successor liability for conduct that closed long before the deal. Pre-acquisition due diligence should review the target’s compliance program, third-party relationships in high-risk countries, books and records, and any history of government investigations.

The DOJ has a safe harbor for misconduct discovered during or after acquisitions. An acquiring company that discloses criminal conduct at the acquired entity within six months of closing and fully remediates within one year receives a presumption of declination. Both deadlines are subject to a reasonableness analysis based on deal complexity. If the misconduct involves ongoing harm or threats to national security, the company can’t wait for the deadline and must disclose immediately. The safe harbor applies only to bona fide, arm’s-length transactions and does not cover misconduct that was already public or known to the DOJ.

Post-acquisition, the DOJ expects the acquirer to integrate the target into its compliance program within a reasonable period. Failing to extend compliance controls, training, and monitoring to the acquired entity signals that the buyer is not serious about preventing future violations.

What a Strong Program Earns You

The direct payoff for a well-designed, resourced, and functioning program is measurable at resolution. Full self-disclosure credit generally means declination or a fine reduced by up to 50% below the guidelines range. It also usually means no independent compliance monitor. Monitorships run two to three years, cost significant money, and put an outside party inside the company reporting to the government. The DOJ decides whether to require one based on whether the company has already made significant investments in compliance and whether remedial improvements have been tested to show they would prevent similar misconduct.1U.S. Department of Justice. Evaluation of Corporate Compliance Programs A company that overhauled its program, added controls, and demonstrated their effectiveness by the time of resolution has a strong argument against a monitor. A company that waited to get caught before starting will almost certainly get one. Companies that qualify for full self-disclosure credit generally won’t be required to accept a monitor if they have an effective program in place at resolution.7U.S. Department of Justice. Justice Manual 9-47.120 – Criminal Division Corporate Enforcement and Voluntary Self-Disclosure Policy

Corporate criminal fines for anti-bribery violations run up to $2 million per violation on the face of the statute, but the Alternative Fines Act lets courts impose fines up to twice the gross gain from the corrupt payment.8GovInfo. 15 USC 78dd-2 – Prohibited Foreign Trade Practices by Domestic Concerns9Office of the Law Revision Counsel. 18 US Code 3571 – Sentence of Fine Corporate penalties in major enforcement actions routinely run into the hundreds of millions. Individuals face up to $100,000 in fines and five years in prison for willful anti-bribery violations. FCPA fines and disgorgement are not tax-deductible, and a company cannot pay fines imposed on individual officers or employees directly or indirectly.10Office of the Law Revision Counsel. 15 USC 78ff – Penalties Everything the compliance program is designed to earn, in credit and avoided cost, has to be measured against those numbers.

Where Affirmative Defenses Fit In

The FCPA provides two affirmative defenses: a payment is not illegal if lawful under the written laws of the foreign official’s country, or if it was a reasonable and bona fide expenditure directly related to promoting a product or performing a contract with the foreign government.3Office of the Law Revision Counsel. 15 US Code 78dd-1 – Prohibited Foreign Trade Practices by Issuers The burden falls on the defendant. In practice these defenses rarely succeed, and relying on them as a compliance strategy is a mistake. The local-law defense requires proof that the foreign country’s written law authorizes the payment, which is almost never true since most countries have their own anti-bribery statutes. The bona fide expenditure defense requires thorough documentation showing the payment was reasonable, tied to a legitimate business purpose, and not a disguised bribe. A compliance program’s job is to make sure the company never has to argue either one.