The Securities and Exchange Commission (SEC) is sending letters to technology companies, probing their relationships with distributors, resellers, and other third parties in high-risk corruption areas. These letters aren't accusations; they're reconnaissance. The SEC is evaluating the tech sector for potential Foreign Corrupt Practices Act (FCPA) violations. Your third-party risk management (TPRM) program is about to face scrutiny beyond what your quarterly vendor reviews have prepared you for.
What the SEC Inquiry Reveals
The sweep highlights a critical issue: most TPRM programs can't answer the questions regulators actually ask. You've focused on vendor security questionnaires and annual re-certifications, but the SEC wants details on every intermediary involved in your business in high-corruption risk countries. This requires different information and approaches.
The gap isn't just about identifying your third parties. It's about proving you've managed those relationships with the rigor the FCPA demands. This means documenting due diligence decisions, ensuring contract terms grant you audit rights, maintaining training records for employees and intermediaries on anti-corruption requirements, and conducting ongoing monitoring to catch red flags before they become violations.
Five Findings That Matter for Your Program
Finding 1: Your procurement team knows about third parties you don't. If compliance lacks visibility into every distributor, reseller, and broker relationship, you can't perform due diligence on unknown relationships. The SEC assumes you have a complete inventory, but most companies don't.
Finding 2: Contract language varies wildly across business units. Some contracts include audit rights and anti-corruption clauses, while others don't. This inconsistency creates compliance gaps and hinders uniform monitoring of third-party behavior across high-risk jurisdictions.
Finding 3: Due diligence depth doesn't match risk levels. You're screening for ownership structure and politically exposed persons, but the rigor applied to a low-value domestic vendor often matches what you're doing for a high-value intermediary in a high-risk jurisdiction. The FCPA doesn't consider your vendor spend tiers.
Finding 4: Training happens, but documentation is scattered. You've delivered anti-corruption training to employees and perhaps some third parties. But can you produce records showing which intermediaries completed training, when, and what version of your policy they acknowledged? If these records are scattered across systems or business units, assembling them under regulatory pressure becomes a crisis.
Finding 5: Ongoing monitoring means different things to different teams. Finance might review invoices, procurement might track contract renewals, and compliance might run annual screenings. These activities don't connect into a coherent picture of whether a third party's behavior has changed in ways that increase corruption risk.
What This Means for Your Team
The SEC sweep isn't just about FCPA compliance. It's a stress test of whether your TPRM program integrates with the rest of your business. You might have sophisticated screening technology and detailed policies, but if procurement doesn't inform you about new distributor relationships until contracts are signed, your controls activate too late.
Integration doesn't mean compliance takes over vendor management. It means building workflows that surface the right information at the right time. When procurement evaluates a new reseller in a high-risk jurisdiction, compliance needs to know before the relationship starts, not after. When finance processes payments to intermediaries, they need triggers that flag unusual patterns. When legal negotiates contracts, anti-corruption clauses and audit rights should be standard, not optional.
This requires relationships, not just technology. You need procurement to understand why you're asking about intermediaries in certain countries. You need legal to see contract language as a compliance control, not boilerplate. You need finance to recognize that invoice review is corruption monitoring, not just accounts payable.
Action Items by Priority
Immediate (this quarter):
Map your third-party universe across all business units. Don't limit this to vendors in your GRC platform. Include distributors, resellers, brokers, and any other intermediary acting on your behalf. If procurement, sales, or regional offices maintain separate vendor lists, consolidate them. You can't perform due diligence on relationships you don't know about.
Create a cross-functional response team now, before the SEC letter arrives. Include representatives from compliance, legal, procurement, finance, and internal audit. Define who owns which pieces of a regulatory inquiry response and where the documentation lives.
Short-term (next six months):
Standardize contract language for third parties in high-risk jurisdictions. Every contract should include audit rights, anti-corruption clauses, prohibitions on sub-contracting without approval, and reporting requirements. Work with legal to make these non-negotiable terms.
Implement risk-based due diligence tiers. A domestic software vendor doesn't need the same screening depth as a distributor in a high-corruption jurisdiction. Define what "high-risk" means for your business (geography, transaction types, relationship to government entities), then build due diligence procedures that match those risk levels.
Build a centralized repository for TPRM documentation. This includes due diligence reports, contract versions, training completion records, ongoing monitoring findings, and escalation decisions. When a regulator asks about your relationships, you need to produce evidence quickly and completely.
Long-term (next 12 months):
Redesign your training program to cover both employees and third parties. Focus on scenarios relevant to their roles: how finance spots suspicious payments, how sales teams respond when intermediaries suggest questionable practices, how procurement evaluates corruption risk during vendor selection. Track completion at the individual level and tie refresher training to changes in role or jurisdiction.
Establish ongoing monitoring that connects financial, operational, and reputational signals. This goes beyond annual re-screening. It means monitoring payment patterns, tracking changes in third-party ownership or leadership, and reviewing adverse media in jurisdictions where your intermediaries operate.
The SEC's tech sector sweep is a warning that your TPRM program needs to answer questions it wasn't designed for. Companies that treat this as a compliance project will struggle. Those that treat it as a cross-functional integration challenge will build capabilities that work whether the next inquiry comes from the SEC, the Department of Justice, or a regulator you haven't heard from yet.





