Navigating the FCPA Minefield: How Multinationals Can Build Defensible Compliance Programs Without Sacrificing Global Growth
For the general counsel of a multinational corporation with operations in Southeast Asia, West Africa, or Latin America, the Foreign Corrupt Practices Act is not an abstract legal concern. It is an ever-present operational reality — one that shapes vendor selection, shapes how sales teams are compensated, and determines whether a government contract opportunity is pursued or declined. In recent years, the tension between rigorous FCPA enforcement and the commercial imperatives of international business has grown considerably more acute, leaving many companies caught in what experienced practitioners have begun calling the compliance trap.
The core dilemma is straightforward, even if its resolution is not. The DOJ and the Securities and Exchange Commission have made clear that FCPA enforcement remains a top institutional priority. At the same time, businesses operating in jurisdictions where facilitation payments, opaque procurement processes, and intermediary relationships are deeply embedded in commercial culture face genuine difficulty drawing a clean line between legitimate business development and conduct that triggers federal liability.
The Enforcement Landscape Has Shifted — and Not Quietly
The DOJ's posture on FCPA enforcement has evolved meaningfully over the past decade. The department has moved away from a model centered primarily on corporate resolutions and toward one that places substantially greater emphasis on individual accountability. The 2015 Yates Memorandum formalized this shift, directing prosecutors to identify culpable individuals early in any corporate investigation. Subsequent policy guidance has reinforced that message: corporations seeking cooperation credit must now affirmatively identify and produce evidence against the natural persons responsible for misconduct.
Recent enforcement actions illustrate the breadth of the DOJ's reach. The 2023 resolution involving a major commodities trading firm — resulting in a combined penalty exceeding $1.7 billion across multiple jurisdictions — signaled that even sophisticated, compliance-aware organizations are not insulated from liability when systemic failures exist at the business unit level. Equally significant was the department's growing willingness to pursue cases in industries not historically associated with FCPA risk, including technology, healthcare, and financial services.
The SEC, for its part, has maintained an active parallel enforcement program, particularly against issuers whose books-and-records and internal controls failures enable or conceal corrupt payments. Together, the two agencies have created an enforcement environment that rewards early disclosure and punishes willful blindness — but that also demands a level of compliance infrastructure that many mid-market multinationals struggle to sustain.
Where Legitimate Business Practice Ends and FCPA Exposure Begins
One of the most persistent challenges facing compliance counsel is the ambiguity that attaches to common international business practices. Consider the use of third-party intermediaries — local agents, distributors, joint venture partners, and consultants — whose relationships with foreign government officials may be entirely legitimate or deeply problematic, often without any outward indication of which. The FCPA does not prohibit the use of intermediaries. It does, however, impose liability on companies that pay or authorize payments to third parties while knowing — or consciously disregarding — that some portion of those funds will be passed to foreign officials.
The DOJ's guidance on this point is instructive but not entirely satisfying. Prosecutors evaluate whether a company conducted adequate due diligence on its intermediaries, whether the compensation structure was commercially reasonable, and whether red flags were identified and addressed. What constitutes adequate due diligence in a frontier market with limited public records infrastructure is a question that rarely has a clean answer.
Similar tensions arise around travel and entertainment expenditures, charitable contributions to organizations connected to government officials, and the hiring of relatives of foreign officials — practices that may reflect ordinary relationship-building in some jurisdictions but that carry substantial FCPA risk under the right set of facts.
Building a Compliance Program That Can Withstand Scrutiny
The DOJ's guidance documents, including the 2020 update to the FCPA Resource Guide and the 2023 revisions to the Evaluation of Corporate Compliance Programs, provide a detailed — if not always precise — framework for what a defensible compliance program looks like. Several elements consistently appear as critical indicators of program adequacy.
Tone from the Top and Middle. Prosecutors are increasingly skeptical of compliance programs that exist primarily on paper. Genuine commitment from senior leadership, reflected in resource allocation, personnel decisions, and the willingness to walk away from business opportunities that cannot be pursued cleanly, is treated as a meaningful indicator of program effectiveness.
Risk-Tiered Due Diligence. Not all third-party relationships carry equivalent risk. A defensible program allocates compliance resources proportionally, applying enhanced due diligence protocols to intermediaries operating in high-risk jurisdictions, those with government-facing roles, and those whose compensation structures include success fees tied to government contract awards.
Transaction Monitoring and Financial Controls. Books-and-records violations frequently accompany substantive FCPA charges. Robust internal controls over disbursements, expense reimbursements, and off-balance-sheet arrangements are essential both for detecting misconduct and for demonstrating that the company did not turn a blind eye to suspicious transactions.
Speak-Up Culture and Non-Retaliation. The effectiveness of any compliance program ultimately depends on whether employees feel safe reporting concerns. Companies that can demonstrate a genuine non-retaliation culture — supported by documented investigations and consistent disciplinary outcomes — are better positioned to argue that misconduct was an isolated failure rather than a systemic one.
The Business Cost of Over-Compliance
A dimension of the FCPA debate that receives less attention than it deserves is the competitive cost of aggressive compliance postures in markets where local and foreign competitors operate under fewer constraints. American companies bidding on government contracts in jurisdictions with endemic corruption face a structural disadvantage when their compliance programs effectively prohibit practices that competitors — including state-owned enterprises from countries without equivalent anti-bribery regimes — engage in routinely.
This is not an argument for relaxing compliance standards. It is, however, a reason for compliance counsel to engage constructively with business leadership rather than defaulting to prohibition as the answer to every risk question. A compliance program that consistently says no without offering a path to yes will eventually be marginalized — or circumvented.
The more productive approach involves helping business teams structure transactions in ways that achieve legitimate commercial objectives while minimizing FCPA exposure. That might mean restructuring the role of a local intermediary, redesigning a compensation arrangement, or building additional approval layers into a government-facing transaction. It requires compliance counsel to understand the business well enough to offer workable alternatives.
Voluntary Disclosure: A Decision That Demands Careful Analysis
When internal investigations surface potential FCPA violations, companies face one of the most consequential decisions in the compliance lifecycle: whether to make a voluntary self-disclosure to the DOJ. The department's current policies offer meaningful cooperation credit for timely disclosure, full cooperation, and remediation — but the calculus is not straightforward.
Voluntary disclosure initiates a process that the company does not control. It requires producing individuals and documents, and it creates reputational and collateral consequences that may extend well beyond the DOJ resolution itself. Companies operating in regulated industries, or those with significant government contracting relationships, must weigh those downstream effects carefully before concluding that disclosure is the optimal path.
Experienced FCPA counsel will conduct a sober assessment of the strength of the underlying evidence, the likelihood of independent detection, the jurisdiction's enforcement posture, and the company's remediation capacity before advising on disclosure. That analysis, undertaken with appropriate rigor and documented carefully, is itself a component of a defensible compliance posture.
Conclusion
The FCPA compliance environment is unlikely to become simpler. The DOJ has signaled continued prioritization of international corruption cases, and the increasing coordination between US prosecutors and foreign enforcement authorities means that companies cannot assume that conduct outside the United States will remain outside the government's view.
What companies can do is build compliance programs that are genuinely operational rather than merely aspirational — programs that are calibrated to actual risk, supported by real resources, and capable of adapting as business activities evolve. That is a demanding standard. It is also, increasingly, the minimum that regulators and prosecutors expect.