INTERNATIONAL TRADE LAW
FCPA Compliance Checklist for U.S. Businesses

The Foreign Corrupt Practices Act (FCPA) makes it illegal for U.S. companies and individuals — and many foreign companies — to bribe foreign government officials to win or keep business, and it requires publicly traded companies to keep accurate books and maintain real internal controls. If your company sells abroad, uses overseas agents, or touches U.S. markets, the FCPA applies to you. This checklist covers what the law prohibits, who it reaches, what it costs to get wrong, and the controls a working compliance program needs.
What the FCPA prohibits
The FCPA has two distinct parts, and most companies have to satisfy both.
The anti-bribery provisions make it unlawful to offer, promise, authorize, or give anything of value to a foreign official to obtain or retain business or secure an improper advantage. “Anything of value” is broad — cash, gifts, lavish travel, entertainment, charitable donations steered at an official, even a job for an official’s relative. “Foreign official” includes employees of state-owned enterprises, not just elected politicians. Payments made indirectly through a consultant, distributor, or agent count: you cannot do through a third party what you cannot do yourself.
The accounting provisions apply to “issuers” — companies with securities registered with the U.S. Securities and Exchange Commission (SEC). They require two things: accurate books and records that fairly reflect transactions, and a system of internal accounting controls. These provisions are how many cases are actually charged, because the government does not have to prove a bribe to prove that books were falsified or controls were missing.
Who must comply
The FCPA reaches further than many businesses expect:
- Issuers — any company (U.S. or foreign) with securities listed or registered in the U.S., plus their officers, directors, employees, and agents.
- Domestic concerns — U.S. citizens, nationals, residents, and any business with its principal place of business in the U.S. or organized under U.S. law.
- Other persons — foreign companies and individuals that take any act in furtherance of a corrupt payment while in U.S. territory.
The two enforcement agencies are the Department of Justice (DOJ), which handles criminal cases, and the SEC, which brings civil cases against issuers.
2025 enforcement changes — what’s current
FCPA enforcement shifted in 2025, but the statute itself did not change and compliance is still mandatory. A February 10, 2025 executive order directed the DOJ to pause new FCPA investigations and enforcement actions while it reviewed its approach. On June 9, 2025, the DOJ issued revised enforcement guidelines that ended that pause. As of mid-2026, the DOJ’s stated priorities emphasize conduct that harms U.S. economic or national-security interests, individual criminal misconduct, and bribery tied to cartels and transnational criminal organizations. The SEC’s posture toward issuers continued to evolve over the same period.
The practical takeaway: enforcement priorities can move, but the law remains in force, the statute of limitations is long, and prior conduct stays exposed. Treat the FCPA as fully live and confirm the current enforcement posture before relying on any “lighter touch” assumption.
FCPA penalties
Penalties are severe and are adjusted for inflation, so always confirm the current figures. The amounts below reflect the 2025 adjustments.
| Violation | Civil penalty | Criminal penalty |
|---|---|---|
| Anti-bribery (company) | Up to about $26,262 per violation | Up to $2,000,000 per violation |
| Anti-bribery (individual) | Up to about $26,262 per violation | Up to $250,000 and/or up to 5 years in prison |
| Accounting (company) | About $118,225–$1,182,251 per violation | Up to $25,000,000 per violation |
| Accounting (individual) | About $118,225–$1,182,251 per violation | Up to $5,000,000 and/or up to 20 years in prison |
Under the Alternative Fines Act, criminal fines can be raised to twice the benefit the defendant sought to obtain — which in large cases dwarfs the statutory caps. Companies also face disgorgement of profits, monitorships, and reputational damage that outlasts the case.
The FCPA compliance checklist
A defensible program is risk-based and documented. Work through these elements:
- Tone at the top. Visible, repeated commitment from senior leadership and the board that bribery is never acceptable, even if it costs a deal.
- Risk assessment. Map where you operate, which government touchpoints you have, and which third parties act for you. Update it as the business changes.
- Written policies. A clear anti-corruption policy plus specific rules for gifts, travel, entertainment, charitable and political contributions, and facilitating payments.
- Third-party due diligence. Vet agents, distributors, consultants, and joint-venture partners before engaging them; use written contracts with anti-corruption representations and audit rights.
- Internal accounting controls. Approval thresholds, segregation of duties, and documentation so that no payment leaves the company without a legitimate, recorded purpose.
- Books and records discipline. No off-the-books accounts, no vague “consulting fee” or “miscellaneous” entries that hide what really happened.
- Training. Role-specific training for sales, finance, and anyone interacting with officials or third parties — repeated, not one-and-done.
- Reporting channels. A confidential hotline with a strict no-retaliation policy, plus a process to investigate reports.
- Monitoring and auditing. Periodic testing of high-risk areas and third-party payments, with findings escalated and fixed.
- M&A due diligence. Screen acquisition targets for corruption exposure before closing, and integrate them into your controls afterward.
Third-party red flags to watch
Most FCPA cases involve intermediaries. Slow down when you see: a third party recommended by the foreign official; unusual or oversized commissions; requests for payment in cash, to an offshore account, or to a different entity than the one performing the work; refusal to sign anti-corruption terms; a partner with no real staff or track record; or vague invoices that don’t describe the services.
Voluntary self-disclosure
The DOJ’s Corporate Enforcement Policy rewards companies that catch problems and come forward. A company that voluntarily self-discloses, fully cooperates, and remediates may earn a declination (no prosecution) or, where aggravating factors exist, a substantial reduction in penalty — up to 50%. The calculus is fact-specific and time-sensitive, so involve counsel before disclosing.
Frequently asked questions
Does the FCPA apply to small or private companies? Yes. The anti-bribery provisions reach any U.S. business and U.S. person regardless of size or whether the company is public. Only the accounting provisions are limited to SEC issuers.
Are “facilitating payments” allowed? The FCPA has a narrow exception for small payments to expedite routine, non-discretionary government actions. It is risky, easily abused, and illegal under many other countries’ laws — most mature programs prohibit facilitating payments outright.
Can we be liable for what an agent or distributor does? Yes. Paying a bribe through a third party, or ignoring red flags that one is occurring, can create liability. Due diligence and contractual controls over intermediaries are essential.
Did FCPA enforcement stop in 2025? No. New enforcement was briefly paused in early 2025, but the DOJ resumed under revised guidelines in June 2025. The statute never changed, and compliance remains required.
Importing or exporting? Reidel Law Firm delivers a flat-fee Import/Export Compliance Memo — a plain-English review of your classification, licensing, screening, and anti-corruption obligations from a trade attorney. Get an import/export compliance memo →


