How suspected violations come to light
The Foreign Corrupt Practices Act prohibits bribing foreign officials to obtain or keep business, and it imposes record-keeping and internal control requirements on companies with US-listed securities. Problems usually surface through third parties such as agents, distributors, or consultants, whose fees or invoices do not match the work. Whistleblower reports, auditor questions, and acquisition diligence are other common sources. Criminal enforcement belongs to the Justice Department, while the SEC brings civil actions involving issuers. Foreign authorities may also investigate the same conduct under their own laws.
Shifting enforcement, unchanged law
In 2025 the Justice Department paused new FCPA enforcement and then issued revised guidelines with narrower priorities. The statute itself did not change, and the limitations period can outlast any policy shift, so conduct that is not a priority today may be reviewed later. Policies on voluntary self-disclosure, cooperation, and remediation also continue to matter in how companies are treated. Companies should also be aware that a separate federal law now reaches foreign officials who demand bribes, which can affect how extortion situations are handled. Because enforcement priorities move, current policy needs to be checked before any decision about disclosure.
First decisions after a red flag
When we first meet, we map what has been found, who was involved, and which countries and business lines are affected. We discuss whether an internal investigation should be run under the board or a committee, and how to protect privilege in that work. Payments under suspicion should usually be suspended, and documents preserved across the relevant offices and personal devices used for business. We consider whether the company should self-report, and when, along with the foreign law implications of moving data across borders. Individual employees may need their own counsel, and we discuss when that point arrives.