PolicyTrak
›
How to Write an FCPA Compliance Program Beyond Just the Gift Policy
FCPA Compliance Guide
How to Write an FCPA Compliance Program Beyond Just the Gift Policy
A Foreign Corrupt Practices Act (FCPA) compliance program goes substantially beyond the gift and entertainment policy that some organizations consider their complete FCPA response. The FCPA prohibits bribery of foreign officials to obtain or retain business and requires accurate books and records and adequate internal controls for issuers. The combined requirements affect most organizations with any international exposure. The program that works addresses risk assessment, third-party diligence and management (most FCPA enforcement involves third-party intermediaries), training calibrated to risk profile, internal controls, monitoring, and integration with broader compliance. This guide covers practical FCPA program design.
⚡ Key Takeaway
A Foreign Corrupt Practices Act (FCPA) compliance program goes substantially beyond the gift and entertainment policy that some organizations consider their complete FCPA response. The FCPA prohibits bribery of foreign officials to obtain or retain business and requires accurate books and records and adequate internal controls for issuers. The combined requirements affect most organizations with any international exposure — sales to government customers anywhere in the world, operations in foreign jurisdictions, third-party intermediaries acting on the organization’s behalf, M&A activity involving foreign businesses. The program that works addresses risk assessment specific to organizational operations, third-party diligence and management (most FCPA enforcement involves third-party intermediaries), training calibrated to risk profile, internal controls that prevent and detect issues, monitoring and audit, and integration with broader compliance functions. This guide covers practical FCPA program design beyond the basic gift policy.
Why FCPA Compliance Requires Substantive Program
FCPA enforcement has remained substantial despite changes in enforcement priorities across different administrations. DOJ and SEC have continued to bring cases with substantial penalties — multi-hundred-million-dollar settlements remain common, individual prosecutions continue, deferred prosecution agreements impose multi-year compliance commitments. The international framework has also expanded with UK Bribery Act enforcement, Brazilian Clean Companies Act, French Sapin II, German anti-corruption developments, and similar frameworks in many other jurisdictions. The combined regulatory and enforcement environment makes anti-corruption compliance one of the higher-stakes compliance areas for organizations with international exposure. The FCPA has two main provisions affecting organizations differently. The anti-bribery provisions prohibit offering or providing anything of value to foreign officials to obtain or retain business; these apply broadly to organizations with U.S. nexus. The books and records and internal controls provisions require accurate financial records and adequate internal controls; these apply specifically to issuers (companies with securities registered with SEC or that file SEC reports). Both provisions can produce substantial enforcement; the books and records provisions have produced significant cases even where actual bribery wasn’t established. Beyond direct organizational liability, FCPA enforcement has expanded to address third-party conduct. Most FCPA cases involve third-party intermediaries — agents, consultants, distributors, joint venture partners, customs brokers, and others — who engaged in conduct producing organizational liability. The third-party dimension matters because organizations often have substantial third-party relationships in higher-risk jurisdictions, often with limited operational visibility into the third parties’ conduct. The compliance program needs to address third-party risk specifically rather than focusing only on direct employee conduct. The successor liability dimension also affects FCPA exposure. Acquirers of companies with prior FCPA conduct can face liability for that conduct under successor liability principles. M&A diligence on FCPA matters has become routine for transactions involving international operations. Post-acquisition integration of FCPA programs has become standard for acquirers building or maintaining international operations. The investment in substantive FCPA programs reflects this enforcement environment and exposure structure. Bare-minimum programs (basic gift policy, annual training video) typically don’t satisfy regulatory expectations or actually prevent issues; substantive programs (risk-based design, third-party management infrastructure, ongoing monitoring, specific industry and jurisdiction tailoring) produce both compliance and risk management value.Program Elements Beyond the Gift Policy
Risk Assessment
Specific risk assessment identifying countries, products, customer types, third-party relationships, and operational patterns that elevate FCPA risk. The risk assessment drives where program attention concentrates.Third-Party Due Diligence
Diligence on agents, consultants, distributors, JV partners, customs brokers, and other third parties acting on the organization’s behalf. Risk-based diligence depth with stronger diligence for higher-risk relationships.Third-Party Contractual Provisions
Specific anti-corruption provisions in third-party agreements — representations and warranties, audit rights, training requirements, termination rights for violations, indemnification, certification obligations.Government Customer Procedures
Specific procedures for interactions with government customers globally — tender processes, hospitality during procurement processes, post-award gifts and entertainment, hiring of former government officials.Books and Records Controls
Internal controls supporting accurate financial recording — expense documentation, transaction approvals, supporting documentation requirements. The books and records provisions require both accurate records and adequate controls.Cash and Disbursement Controls
Specific controls on cash payments and disbursements, particularly in jurisdictions where cash is common. Cash transactions are higher-risk for FCPA purposes and warrant specific attention.Training Calibrated to Risk
Training programs calibrated to specific risk profiles — broader training for general workforce, deeper training for higher-risk roles (international sales, government relations, third-party management), specialized training for compliance staff.Reporting and Investigation
Channels for reporting concerns, investigation procedures for reported matters, escalation paths for serious matters, integration with broader compliance investigation infrastructure.Monitoring and Auditing
Ongoing monitoring of FCPA risk indicators, periodic auditing of specific risk areas (third-party relationships, expense patterns, sensitive transactions), responsive audit when issues emerge.M&A Diligence and Integration
FCPA diligence on acquisition targets, integration of acquired entities into FCPA program, addressing identified pre-acquisition issues appropriately.Third-Party Risk Management
-
1
Inventory of Third-Party Relationships
Comprehensive inventory of third parties acting on the organization’s behalf or in ways that produce FCPA exposure. Without inventory, third-party risk management has gaps. -
2
Risk Tiering
Tiering of third parties by FCPA risk — geography, nature of services, government interaction, payment patterns, prior issues. Higher-risk third parties warrant more intensive diligence and ongoing attention. -
3
Diligence Calibrated to Tier
Diligence depth proportionate to risk tier. Higher-risk relationships face comprehensive diligence — background investigations, reference checks, financial review, ownership verification, ongoing screening. Lower-risk relationships face proportionate but lighter diligence. -
4
Red Flag Recognition
Training in recognition of red flags — unusual payment patterns, requests for cash payments, payments to unexpected jurisdictions, third parties recommended by government officials, requests for excessive compensation. Red flags warrant additional investigation. -
5
Periodic Re-diligence
Periodic refresh of third-party diligence — circumstances change, relationships evolve, new information emerges. Initial diligence isn’t sufficient for ongoing relationships. -
6
Termination of High-Risk Relationships
Willingness to terminate relationships when red flags can’t be resolved or risk profile elevates beyond acceptable. The willingness reinforces program credibility and limits exposure.
Industry and Jurisdiction Considerations
Higher-Risk Industries
Some industries face elevated FCPA risk — extractive industries (oil, gas, mining), defense and aerospace, life sciences interacting with government healthcare systems, telecommunications, certain financial services. Industry-specific programs address industry-specific patterns.Higher-Risk Jurisdictions
Specific jurisdictions consistently produce more FCPA enforcement — China, Russia, Brazil, India, Mexico, Indonesia, Nigeria, and others have produced substantial enforcement. Risk profiles vary substantially across regions and within them.Government Customer Considerations
Operations selling to government customers (any government, anywhere) face elevated FCPA scrutiny. Sales processes, hospitality during procurement, post-award relationships all warrant specific attention.Border and Customs Risk
Cross-border operations face customs and border interactions that have produced FCPA cases — facilitating payments to customs officials, expediters working through inappropriate channels, hospitality affecting border processes.Healthcare Industry Specifics
Healthcare operations interacting with government healthcare systems globally face specific anti-corruption considerations including HHS-OIG considerations alongside FCPA, foreign healthcare official interactions, hospitality during medical conferences.International Compliance Coordination
International operations face multiple anti-corruption frameworks beyond FCPA — UK Bribery Act, French Sapin II, German anti-corruption, Brazilian Clean Companies Act, Chinese anti-corruption, and many others. Multi-framework coordination matters for global operations.Build FCPA Programs Beyond Just the Gift Policy
PolicyTrak supports the FCPA policy framework — anti-corruption policies with version control, training tracking for required FCPA training, third-party policy framework, acknowledgment workflows.Frequently Asked Questions
Through risk-based analysis of organizational exposure. Organizations with limited international exposure, no government customers, no third-party intermediaries, and no acquisitions of international businesses may warrant proportionately modest investment — basic anti-corruption policy, periodic awareness training, standard internal controls. Organizations with substantial international operations, government customers, extensive third-party relationships, or acquisition activity warrant substantial investment — risk-based program, dedicated FCPA expertise, third-party management infrastructure, specialized training, ongoing monitoring. The Resource Guide to the FCPA published by DOJ and SEC provides framework for proportionate program design. Specific calibration benefits from FCPA counsel review of organizational exposure. The investment should match exposure; bare minimums in high-exposure situations and elaborate programs in low-exposure situations both miss appropriate proportion.
Limited exception under FCPA but with substantial complications. FCPA includes a narrow exception for facilitation payments — small payments to expedite or secure routine, non-discretionary governmental actions like processing visas, providing utility services, scheduling inspections. The exception is narrow and limited in practice — many payments organizations might consider facilitation don’t actually qualify under the legal definition. Beyond the narrow legal exception, other anti-corruption frameworks (UK Bribery Act, others) don’t include facilitation payment exceptions. Many organizations adopt zero-tolerance policies on facilitation payments because the legal complexity exceeds the operational benefit. Specific situations involving potential facilitation payments warrant FCPA counsel review rather than relying on the technical legal exception. The conservative approach for most organizations is to prohibit facilitation payments entirely.
Through clear policy, escalation paths, and organizational backing of employees who refuse inappropriate payments. Employees in high-risk jurisdictions sometimes face pressure for payments — from customers, agents, government officials, or local partners. The pressure can be substantial: business loss, operational delays, professional consequences for the specific employee. The program needs to support employees facing these situations through clear policy that prohibits the payments, escalation paths that bring senior involvement to specific situations, organizational backing that protects employees who refuse inappropriate payments even when business is lost, and training that prepares employees to handle pressure situations. Without organizational backing, employees often capitulate to pressure regardless of policy; with backing, employees can resist pressure knowing the organization stands behind them. Specific pressure situations may warrant immediate FCPA counsel engagement.
Through integrated trade compliance programs that address multiple frameworks. FCPA is one element of broader trade compliance affecting international operations — economic sanctions (OFAC), export controls (EAR, ITAR), anti-money laundering, anti-boycott provisions, customs compliance, and various country-specific frameworks. Mature international compliance programs typically integrate these frameworks rather than handling them in isolation. The integration produces operational efficiency (shared infrastructure, shared training, shared diligence processes), better risk identification (issues often cross frameworks), and consistent compliance posture. Specific framework requirements remain distinct — FCPA isn’t sanctions law isn’t export controls — but program infrastructure can be shared substantially. PolicyTrak supports integrated trade compliance frameworks alongside specific framework details.
Through FCPA-specific diligence and post-acquisition integration. M&A diligence on international targets includes FCPA dimensions — review of target’s third-party relationships, government customer interactions, expense patterns, prior compliance issues, ongoing investigations. Identified issues affect transaction structure (price adjustments, indemnification, specific representations) or in serious cases transaction decisions (walking away from targets with substantial uncovered issues). Post-acquisition integration addresses identified issues, brings target into acquirer’s FCPA program, and continues investigation of issues identified during diligence. DOJ has provided specific guidance on M&A FCPA handling that affects transaction structuring and integration approaches. Specific M&A FCPA situations benefit from FCPA counsel engaged in transaction work, not just generalist M&A counsel.
Through the policy framework that FCPA programs rest on. Anti-corruption policy, gift and entertainment policy, third-party management policy, government customer interactions policy — all live in PolicyTrak with version control as the regulatory environment and organizational practices evolve. Acknowledgment workflows capture employee acknowledgment of these policies. Training tracking supports the substantial training that FCPA programs typically require, often differentiated by risk profile. The operational FCPA work — third-party diligence platforms, transaction monitoring, sanctions screening, expense monitoring — typically lives in specialized FCPA platforms or integrated compliance management systems. The combination produces appropriate separation: PolicyTrak owns the policy framework; specialized tools handle the operational compliance work.
⚠️
Legal & Compliance Disclaimer
The information on this page is provided for general informational purposes only and does not constitute legal, HR, or compliance advice. Regulations and standards referenced are complex and require interpretation specific to your organization’s facts, jurisdiction, and circumstances. Always consult qualified legal counsel and your industry-specific compliance professionals before making decisions. PolicyTrak is a software platform — not a law firm. FCPA and related anti-corruption frameworks involve complex federal law including DOJ and SEC enforcement, international frameworks including UK Bribery Act, French Sapin II, and many others. Specific anti-corruption program decisions should be reviewed with qualified FCPA counsel. PolicyTrak is a software platform — not a law firm. All examples and interpretations are illustrative only.









