Skip to main content
Dark green background, "Weak Application Security Can Cost You Millions," 3 slanted images of fingers pointing to digital locks, and a "Learn the Basics" button
Should We Still Report FCPA Violations?Ethics & Conduct
5 min readFor Compliance Officers

Should We Still Report FCPA Violations?

Context: Questions from the compliance team channel

Since the DOJ's June 9 policy memo redefining FCPA enforcement priorities, many compliance officers have asked whether the old playbook still applies when a potential violation is discovered. These questions aren't academic; they arise in Slack channels, team meetings, and hallway conversations.

The memo from Deputy Attorney General Todd Blanche introduced four assessment criteria for foreign bribery cases. FCPA enforcement now ranks ninth on the DOJ's top 10 corporate misconduct priorities. The statute and your obligations remain. Here's what you need to know.

Do we still have to self-disclose FCPA violations?

There's no legal requirement to self-disclose most FCPA violations. You're weighing risk versus consequence.

Under the new policies, self-disclosure nearly guarantees a declination, but you'll need to disgorge ill-gotten proceeds and remediate your compliance program. If you don't disclose and a whistleblower reports you later, you lose the declination benefit and retain the tainted revenue on your books.

The calculation has shifted, not disappeared. Your legal team and outside counsel will drive this decision. As the compliance officer, you can advocate for disclosure, but you won't make the final call. Ensure you have a clear record of what you found, when you found it, and what you recommended.

Does anticorruption compliance still matter if enforcement is deprioritized?

Yes, for three reasons unrelated to DOJ priorities.

First, the statute of limitations for FCPA violations is unchanged. A violation today could be prosecuted five years from now under different enforcement leadership. You're managing for future priorities.

Second, anticorruption controls don't exist in isolation. The same control environment that prevents bribery also prevents money laundering, sanctions violations, and contracting fraud. Those issues rank higher on the DOJ's priority list. Dismantling your anticorruption program weakens defenses against enforcement risks that remain significant.

Third, corruption creates operational dysfunction. When customers expect bribes, employees normalize shortcuts, and capital allocation decisions get distorted by under-the-table payments, you've built a business model that can't scale. The compliance question and the business sustainability question converge here.

How do we explain this shift to our board?

Frame it as a change in enforcement likelihood, not exposure.

The four assessment factors Blanche outlined focus on misconduct involving drug cartels, misconduct that blocks specific U.S. organizations from competing overseas, national security threats, and serious misconduct versus routine business practices at lower dollar amounts. Your board should understand that these criteria introduce ambiguity. Does "specific, identifiable U.S. organizations" mean the DOJ will prioritize foreign companies whose corruption harms U.S. competitors? Or will they also pursue U.S. businesses whose bribery thwarts other U.S. companies?

The memo states prosecutors will work "not by focusing on particular individuals or companies on the basis of their nationality, but by identifying and prioritizing the investigation and prosecution of conduct that most undermines these principles." You won't know what that means until you see it applied.

Tell your board: enforcement risk is lower, but exposure hasn't changed. A robust compliance program still protects against whistleblower complaints, civil litigation, reputational damage, and future regulatory shifts.

What should we change about our FCPA compliance program right now?

Probably nothing structural.

If your program was risk-based before June 9, it should remain risk-based now. Don't pull back on third-party due diligence in high-risk markets. Don't reduce training frequency for employees in roles with bribery exposure. Don't eliminate approval workflows for gifts, hospitality, or facilitation payments.

What you might recalibrate is resource allocation. If you were planning to expand your anticorruption team or implement new monitoring technology specifically for FCPA compliance, you might defer those investments and redirect resources toward higher-priority risks like tariff compliance or sanctions screening.

But the core program, the one that ensures you can detect and respond to potential violations, should stay intact. You're managing for the next investigation, whenever it comes.

If we find a violation now, how do we assess whether it meets the DOJ's new criteria?

You probably can't, at least not with confidence.

The four factors Blanche outlined are subjective. Does your violation involve "serious misconduct" or "routine business practices"? That's a judgment call prosecutors will make, not you. Does it "threaten U.S. national security interests"? Unless you're in defense, critical infrastructure, or intelligence, you'll struggle to argue it does.

Document how the violation maps to each factor. If you're considering self-disclosure, your outside counsel will need that analysis. If you're not disclosing, you'll need it to defend your decision if the issue surfaces later.

Most violations won't clearly fit the new priority criteria, which means most companies will make disclosure decisions based on the same factors they always have: the severity of the misconduct, the strength of your compliance program, and your tolerance for future enforcement risk.

Where should we focus our compliance resources if FCPA enforcement is lower priority?

Look at what the DOJ listed above FCPA on its priority ranking: healthcare fraud, tariff evasion, collaboration with drug cartels or terrorist groups, and money laundering.

If your company has tariff exposure, that's where your next control gap analysis should focus. If you process payments through jurisdictions with money laundering risk, review your transaction monitoring capabilities. If you operate in regions with cartel activity, assess your supply chain due diligence.

The enforcement landscape shifted, but your obligation to maintain a risk-based compliance program didn't. Adjust your risk assessment to reflect the new priorities, then allocate resources accordingly.

Where to go for more

The DOJ's June 9 policy memo outlines the four assessment factors. Read it directly rather than relying on summaries. The February 2025 executive order that initiated the 180-day enforcement pause has now been fulfilled, so the pause is over. The FCPA itself remains valid law, unchanged by executive action.

If you're evaluating whether to self-disclose a violation, involve outside counsel early. The declination calculus has changed, but the decision process hasn't.

DOJ FCPA Resource Guide

Promotional banner for the Penetration Report Template Kit

You Might Also Like