Skip to main content
Promotional banner for the pentest readiness checklist
FCPA Enforcement Dropped. Your Risk Didn't.Regulatory Obligations Management
5 min readFor GRC Leaders

FCPA Enforcement Dropped. Your Risk Didn't.

When the DOJ's corporate FCPA enforcement page shows just one action in 2026, you might be tempted to relax your anti-corruption controls. That's a mistake. Misreading enforcement trends as risk trends can lead compliance teams to mistake quiet periods for safe harbors.

Here's what you and your team need to know.

Myth 1: Fewer FCPA Cases Mean Lower Corruption Risk

Reality: Your third-party exposure hasn't changed just because DOJ priorities have shifted.

The same intermediaries that create anti-corruption risk, customs brokers, freight forwarders, distributors, sales agents, also trigger export control and sanctions violations. In February 2026, Applied Materials and Applied Materials Korea paid approximately $252 million to the Bureau of Industry and Security for semiconductor equipment that reached an entity list company in China. That same month, IMG Academy settled apparent counternarcotics sanctions violations for $1.72 million arising from tuition payments involving individuals tied to a Mexican drug cartel.

A single transaction can violate multiple regimes simultaneously. Your customs broker who facilitates border crossings has regular contact with government officials (FCPA risk), handles controlled goods (export control risk), and processes payments that could reach sanctioned parties (OFAC risk). The Scoular case demonstrated this overlap: customs brokers paid more than $400,000 in bribes to Mexican officials between 2013 and 2019, and some of that money allegedly benefited people associated with cartel operations.

You can't compartmentalize these risks. Your vendor risk profile needs to account for all three exposure areas, not just the compliance regime you think is most active.

Myth 2: One-Time Due Diligence Is Sufficient

Reality: Due diligence is vigilance, not a checkbox.

Scoular's brokers invoiced bribes back to the company as "reinspection" charges. That scheme ran for six years. If you're only screening third parties at onboarding, you're missing the ongoing activity that creates liability.

Continual monitoring means regular payment testing focused on vague charges: "facilitation," "handling," "expediting," "administrative," or "special" fees that don't match supporting documentation. Round-number charges, unexplained $100 or $250 line items, warrant review. Compare invoices against customs records, government fee schedules, and proof of payment where possible.

Your contracts should include clear termination rights and require third parties to follow applicable anti-corruption, sanctions, and export control laws. Consider adding an audit right and requiring detailed activity reports before processing payments. For higher-risk intermediaries, provide compliance training. Foreign third parties may not understand when US law applies to their conduct, or they may assume that fewer enforcement actions mean enforcement risk has declined.

Myth 3: You Should Wait to Fully Investigate Before Disclosing

Reality: Speed matters more than completeness under the DOJ's voluntary disclosure policy.

The March 2026 corporate enforcement and voluntary self-disclosure policy (CEP) offers substantial benefits for self-reporting: declination when you voluntarily disclose, fully cooperate, timely remediate, and have no disqualifying aggravating circumstances. But disclosure must occur before there's an "imminent threat" the government will learn of the misconduct and within a reasonably prompt time after you become aware of it.

Balt SAS received a declination in March 2026 after self-disclosing a scheme where a consultant funneled payments to a senior doctor at a state-owned hospital in France. The DOJ required approximately $1.2 million in disgorgement but declined prosecution. Scoular, which didn't self-report, entered a three-year DPA and paid more than $10 million in criminal penalties, receiving only a 25% reduction from the bottom of the sentencing guidelines range despite cooperation and remediation.

The CEP does provide a limited whistleblower exception: if someone reports misconduct both internally and to the DOJ, you can still qualify for a declination if you investigate and self-report within 120 days of receiving the internal report. That's a window, not an invitation to wait.

Your escalation process should allow legal and compliance teams to identify potentially criminal conduct quickly, preserve evidence, and make disclosure decisions before the most valuable incentives disappear. You don't need to disclose every potential violation automatically, but you do need to investigate enough to understand jurisdiction and assess parallel regulatory exposure, and you need to do it fast.

Myth 4: The Current Enforcement Posture Is Permanent

Reality: Enforcement priorities shift with administrations and geopolitical events.

In February 2025, the DOJ paused new FCPA investigations and reviewed existing matters. In June 2025, new guidelines instructed prosecutors to prioritize cases involving cartels, harm to identifiable US companies, national security concerns, and serious misconduct involving substantial bribes or obstruction.

That's a policy choice, not a statutory change. The FCPA remains on the books. Individual prosecutions continue. And the DOJ's current priorities, cartel activity, border security, payments concealed through third-party invoices, reflect this administration's focus areas, not a permanent redefinition of corruption risk.

If you scale back your compliance program now because corporate enforcement is down, you'll be rebuilding from scratch when priorities shift again. Maintain your controls, refresh your risk assessments, and keep your training current. The regulatory infrastructure you dismantle today will cost more to reconstruct tomorrow than it costs to maintain now.

Myth 5: Export Controls and Sanctions Are Separate Compliance Functions

Reality: These risks converge in the same transactions and require integrated management.

Your sales agent in Southeast Asia who helps you navigate local procurement rules might also be facilitating shipments to entity list companies or processing payments through jurisdictions under sanctions. The Commerce Department's BIS has issued 11 administrative orders so far this year. Treasury's OFAC remains active across industries that don't traditionally view themselves as high-risk.

You need control objective mapping that connects anti-corruption, export control, and sanctions obligations to the same business processes: vendor onboarding, payment approval, shipment documentation, contract review. Your policy exception registry should track waivers across all three areas so you can see accumulating risk. Your ongoing vendor monitoring should pull from entity lists, sanctions designations, and corruption indices simultaneously.

Siloed compliance functions miss the convergence points where a single relationship creates multiple violations.

What to Do Instead

Build an escalation protocol that routes third-party red flags, unusual invoices, vague charges, round-number fees, payment routing through unexpected jurisdictions, to a cross-functional review team that includes legal, compliance, finance, and operations. That team should have authority to pause payments and terminate relationships without waiting for complete investigations.

Refresh your vendor risk profiles quarterly for high-risk intermediaries. Annual reviews aren't sufficient when enforcement priorities and sanctions designations change monthly.

Train your procurement and finance teams to recognize the language of concealment: "facilitation," "reinspection," "special handling." Those aren't just compliance buzzwords, they're the invoice descriptions that appeared in actual enforcement actions.

And maintain your disclosure decision framework now, while you're not under pressure. Define the threshold for escalation to outside counsel, the timeline for internal investigation, and the criteria for approaching the DOJ. You can't build that process during a crisis.

Quiet enforcement doesn't mean quiet risk. It means the consequences for getting it wrong just got steeper.

DOJ Corporate Enforcement Policy

a promotional banner asking how ready are you for PCI DSS 4.0? With a call-to-action to get the checklist now.

You Might Also Like