Dun & Bradstreet

RESOURCE

FCPA Compliance Explained: Requirements, Violations, and Best Practices

FCPA compliance requires companies to prevent, detect, and document risks related to bribery of foreign officials, including actions taken by third parties acting on their behalf.

What Is the Foreign Corrupt Practices Act?

The Foreign Corrupt Practices Act (FCPA) is a U.S. anti-bribery and accounting law that prohibits offering, promising, or paying anything of value to foreign officials to obtain or retain business or secure an improper advantage.

The FCPA applies to U.S. public companies, domestic businesses and individuals, and certain foreign companies or individuals that conduct business or take action in furtherance of a corrupt payment in the United States. Because violations can lead to criminal charges, civil penalties, debarment, and reputational harm, FCPA compliance is a core part of anti-corruption risk management for companies and the third parties that act on their behalf.

FCPA Provisions

The FCPA seeks to stamp out corruption by enforcing rules in two categories:

Anti-Bribery Provisions

These provisions prohibit payments or gifts to foreign officials in order to earn favorable treatment or otherwise violate the law.

The term "foreign official" is defined broadly under the FCPA. It covers employees of foreign governments, political parties, and political party officials at any level. It also includes officers and employees of state-owned or state-controlled enterprises, as well as candidates for political office.

Accounting Provisions

The provisions require businesses to adhere to strict bookkeeping standards. Internal controls governing records are intended to make it more difficult to hide illegal actions.

The 5 Elements of an FCPA Violation

The Department of Justice evaluates potential FCPA violations using five key elements. All five must be present for criminal liability to apply.

An FCPA violation typically includes:

  1. A covered person or entity
  2. Corrupt intent
  3. A payment or thing of value
  4. A foreign official recipient
  5. A business purpose

1. Who Made the Payment

The FCPA applies to issuers, domestic concerns, and people or entities acting within U.S. territory. Companies may also be liable for employees, officers, directors, agents, consultants, intermediaries, or joint venture partners if they knew, or should have known, that a corrupt payment would be made.

2. Corrupt Intent

The payment must be made corruptly, meaning the payer intended to influence a foreign official’s actions, misuse of position, or decision-making. Good-faith payments may be relevant to intent, but companies cannot avoid liability simply by ignoring red flags or claiming they did not know how a third party acted.

3. The Payment or Thing of Value

The FCPA covers anything of value, not only cash payments. Gifts, travel, entertainment, charitable donations, job offers, and other non-monetary benefits may qualify. There is no minimum dollar threshold; even a small benefit can create liability if it is given corruptly to a covered recipient for a business purpose.

4. The Recipient

The recipient must be a foreign official, foreign political party, party official, or candidate for foreign political office. The definition also includes employees of state-owned or state-controlled enterprises. Payments to private-sector recipients generally fall outside FCPA anti-bribery provisions, though they may violate other anti-corruption laws.

5. The Business Purpose Test

The payment must be intended to obtain or retain business or secure an improper advantage. This requirement is interpreted broadly and can include efforts to influence licensing, customs clearance, regulatory approvals, contract awards, or other official decisions. The business purpose does not need to be the only motive.

Examples of FCPA Violations

A company hires a local consultant to help secure a government contract in a high-risk market. The consultant passes a portion of their fee to a government official to influence the award decision. Even if the company did not authorize the payment directly, it may still face liability if it ignored red flags about the consultant’s conduct.

In another scenario, a company’s regional sales team offers an all-expenses-paid overseas trip to executives from a state-owned enterprise during an active procurement process. While the trip is presented as a business visit, most of the itinerary consists of leisure activities with minimal business content. Regulators may view the travel as a “thing of value” provided with the intent to influence a contracting decision, particularly if the expenses are disproportionate to any legitimate business purpose.

Prohibited Conduct: What the FCPA Actually Covers

Many FCPA violations do not involve obvious bribery. Companies frequently face enforcement actions for conduct that seemed, at the time, like ordinary business practice. Understanding the categories of prohibited conduct reduces the risk of accidental violations.

Facilitation Payments

Small payments to expedite routine, non-discretionary government actions may fall under the FCPA’s narrow facilitation payments exception, but only when they do not influence an official’s discretionary decision. Many other anti-corruption laws, including the UK Bribery Act, do not recognize this exception, so companies should not rely on it as a general defense.

Example: Paying a customs official to process paperwork faster may qualify; paying the official to overlook missing documentation would not.

Travel, Entertainment, and Gifts

Travel, meals, entertainment, and gifts for foreign officials are not automatically prohibited, but they must be reasonable, bona fide, and directly tied to a legitimate business purpose. Lavish hospitality, personal side trips, or gifts with no clear business justification increase FCPA risk.

Example: Covering reasonable travel for an official to inspect a facility may be permissible; paying for a family vacation attached to the trip would not.

Charitable Contributions and Sponsorships

Charitable contributions, sponsorships, grants, and in-kind donations can create FCPA risk when they are made at a foreign official’s request, with corrupt intent, and for a business purpose. Legitimate giving should follow a standard approval process and be documented independently from any pending government decision.

Example: Donating to a vetted local charity through normal approval channels may be appropriate; donating to an official’s preferred charity while awaiting a license approval may raise red flags.

Hiring Relatives of Foreign Officials

Hiring a relative of a foreign official is not prohibited by itself, but it can become an FCPA violation when the decision is made with corrupt intent to obtain or retain business. A documented, merit-based hiring process is the clearest protection against this type of claim.

Example: Hiring a qualified candidate through the standard recruiting process may be defensible; creating a role for an official’s relative to influence a contract award would not.

How to Create an Effective FCPA Compliance Program

The DOJ and SEC consider an effective, actively enforced compliance program a key factor in FCPA enforcement decisions. Most programs are built around five core components.

An effective FCPA compliance program typically includes:

  • Risk assessment
  • Written policies and internal controls
  • Training
  • Confidential reporting and investigation
  • Monitoring and continuous improvement

Risk Assessment

Start with a risk assessment that maps FCPA exposure by geography, business line, transaction type, and third-party activity. Higher-risk factors include high-corruption markets, government contracts, local intermediaries, and joint ventures. The assessment should be refreshed regularly as the company enters new markets, changes its operating model, or expands partner relationships.

Written Policies and Internal Controls

Policies should define prohibited conduct, approval thresholds, and documentation requirements for gifts, travel, entertainment, political contributions, and charitable donations involving foreign officials. Internal controls should make improper payments harder to make or conceal through segregation of duties, approval hierarchies, expense substantiation, and accurate books and records.

Training

Training should be role-specific and practical. Employees who interact with foreign officials, manage third parties, approve expenses, or pursue government contracts need more detailed guidance than employees with lower exposure. Scenario-based training helps employees recognize red flags, and attendance records or completion certificates can support the company’s compliance posture during an investigation.

Confidential Reporting and Investigation

Employees need safe ways to report potential violations without fear of retaliation. Anonymous hotlines, non-retaliation policies, and clear escalation paths support a defensible program. Reports should trigger prompt, documented investigations and appropriate remediation. Ignoring a known red flag can itself signal that the compliance program is not operating effectively.

Monitoring and Continuous Improvement

FCPA compliance programs should be tested, updated, and adjusted as risk changes. Regular audits of high-risk transactions, reviews of third-party relationships, and post-transaction monitoring help identify gaps. Compliance leaders should report meaningful program metrics, issues, and remediation efforts to senior management and the board on a regular basis.

FCPA Enforcement

The Securities and Exchange Commission (SEC) is tasked with enforcing FCPA compliance and can file civil charges against businesses or individuals. The Department of Justice can bring both civil and criminal charges to court. Who needs to be concerned with FCPA compliance? The SEC identifies three parties subject to enforcement:

  1. Issuers: Generally speaking, these are publicly traded companies that are required to file SEC reports.
  2. Domestic Concerns: Any individual or company doing business within the United States.
  3. Foreign Nationals and Entities: Regardless of nationality, people or businesses engaging in bribery within the borders of the United States. (That foreigners can be charged with FCPA violations effectively gives this US law international relevance.)

To summarize: Any individual working for or on behalf of a company doing business in the United States must comply with FCPA regulations.

It’s important to note that employees or contractors can face charges based upon actions they’ve undertaken for the benefit of the company. A corporate structure doesn’t shield people from liability.

Penalties for FCPA Violations

The government can inflict substantial civil and criminal penalties on businesses and individuals found guilty of violating the Foreign Corrupt Practices Act, including:

Criminal Penalties for Bribery

Businesses are subject to fines of up to $2 million for each violation. Individuals can be fined up to $250,000 and jailed for no more than five years.

Civil Penalties for Bribery

Businesses and individuals can be fined up to $16,000 per violation.

Criminal Penalties for Accounting Violations

Businesses are subject to fines of up to $25 million per violation. Individuals can be fined up to $5 million and face up to 20 years in jail.

Civil Penalties for Accounting Violations

Businesses and individuals convicted of accounting violations can be fined the amount of their perceived financial gain from the scheme or in accordance with specific dollar limitations prescribed by law.

There are a variety of other penalties that can be applied to businesses and individuals found guilty of FCPA violations. Among the most onerous is suspension or debarment, which prevents businesses from working on federal contracts. This prohibition also applies to subcontracting on deals valued at $30,000 or more.

Managing FCPA Risk Exposure

Even businesses that follow FCPA rules can face exposure through non-compliant suppliers and subcontractors. A vendor facing civil or criminal penalties may miss deadlines, disrupt orders, or become ineligible for federally funded work. Before engagement, companies should confirm that key partners are not subject to suspension or debarment.

Procurement teams often use compliance software to screen vendors, agents, and other business partners. These tools can flag sanctions, debarments, adverse media, ownership concerns, and prior compliance issues. Early screening helps companies avoid risky relationships before they create operational, legal, or reputational harm.

Identifying High-Risk Third Parties

FCPA enforcement often involves payments routed through third parties, including sales agents, distributors, consultants, customs brokers, and joint venture partners. Risk increases when a party interacts with foreign officials, works in a high-corruption market, receives commissions tied to government contracts, or was recommended by an official. These factors require deeper due diligence before engagement.

What Due Diligence Should Cover

High-risk third-party due diligence should verify identity, ownership, beneficial owners, government ties, sanctions status, watchlist results, and adverse media involving corruption or bribery. It should also assess whether fees match the services provided. Unusually high commissions, vague scopes of work, or unexplained intermediaries should trigger further review.

Contractual Protections

Third-party contracts should require compliance with the FCPA and other anti-corruption laws, give the company audit rights for engagement-related books and records, and allow termination if a violation occurs. These clauses do not excuse ignored red flags, but they support a defensible third-party risk management program.

The Foreign Corrupt Practices Act has far-reaching implications for businesses of all sizes. A better understanding of its provisions and penalties is essential to staying on the right side of the law.

FAQs about FCPA Compliance

Paying a customs official to expedite clearance, making charitable donations at the direction of an official with decision-making authority over a pending contract, and channeling payments through a local agent known to have government connections are all common enforcement scenarios. The violation in each case stems from the combination of something of value, a foreign official, and a business purpose.

Explore Our Solutions

Compliance Risk Solutions

Verify new partners, improve relationship transparency, identify beneficial owners, and monitor for changes in the organizations you do business with.

Learn More

There are multiple Contact Forms popups in the page. Only one Contact Form popup could be present on single page. Please reconfigure Contact Forms and refresh the page.