Framework Trade, Ethics & Franchise
FCPA
The Foreign Corrupt Practices Act of 1977 is the US anti-bribery statute. Its anti-bribery provisions make it a crime to offer or pay anything of value to a foreign official to win or keep business, and its accounting provisions require companies with securities registered in the US (issuers) to keep accurate books and records and to maintain a system of internal accounting controls.
The Department of Justice handles criminal enforcement and the Securities and Exchange Commission handles civil enforcement against issuers. The two agencies' joint Resource Guide, second edition published July 2020, sets out how they read the statute and lists the hallmarks of an effective compliance program that they credit when deciding charges and penalties.
The FCPA does not prescribe a compliance program, but the enforcement record and the DOJ's Evaluation of Corporate Compliance Programs make one a practical necessity for any company with overseas sales, agents, or government touchpoints.
In writing, that means a board-approved anti-corruption policy, a risk assessment that maps where bribery could happen, procedures for gifts, travel, hospitality, and political and charitable contributions, third-party due diligence and contract clauses, accounting controls over payments, training records, a reporting channel, investigation and discipline procedures, and periodic testing of the program.
Who has to comply
Anti-bribery provisions reach issuers (companies with US-registered securities, including foreign companies with ADRs), domestic concerns (US citizens, residents, and companies), and anyone who acts in furtherance of a bribe while in US territory. The accounting provisions apply to issuers and, through them, to their controlled subsidiaries.
Small private US companies are covered by the anti-bribery provisions regardless of size.
What the assessor asks to see
When DOJ or SEC evaluates a program, or a counterparty performs anti-corruption due diligence: anti-corruption policy and code of conduct; risk assessment methodology and results; gifts, hospitality, and expense procedures with approval records; third-party due diligence files, contracts with anti-corruption clauses, and monitoring; books and records and payment controls; training content and completion records; hotline reports and investigation files; disciplinary records; internal audit or independent review reports; board and committee minutes showing oversight; remediation of prior findings.
Where the requirement sits: DOJ Evaluation of Corporate Compliance Programs (updated Sept 2024)
Hallmarks of an effective compliance program
The 2020 Resource Guide lists eleven hallmarks: commitment from senior management and a clear anti-corruption policy; a code of conduct and compliance policies and procedures; oversight, autonomy, and resources; risk assessment; training and continuing advice; incentives and disciplinary measures; third-party due diligence and payments; confidential reporting and internal investigation; continuous improvement through periodic testing and review; mergers and acquisitions diligence and integration; and investigation, analysis, and remediation of misconduct.
What AllyMatter does here
Policy and training-acknowledgment layer.
AllyMatter publishes this site.
Assessors
Who assesses FCPA
None required by law. Companies self-assess, use internal audit, or commission independent program reviews by law firms or forensic accountants. After an enforcement resolution DOJ may impose an independent compliance monitor chosen from candidates the company proposes.
No firm has claimed a FCPA assessor listing yet. Claim yours →
Consultants
Who helps with FCPA
A mature ecosystem of law firms, forensic accounting practices, and compliance consultancies. Typical work is a bribery risk assessment, program design or refresh against the Resource Guide hallmarks and DOJ evaluation guidance, third-party due diligence programs, training, and periodic independent program reviews.
Engagements range from a few weeks for a policy refresh to multi-year monitorships after an enforcement action.
Firms that name this framework in their own material. Listings we have not verified yet come from public filings and partner lists. Each firm can confirm its own.
No firm has claimed a FCPA consultant listing yet. Claim yours →
Software
Tools for FCPA
Tools that name this framework in their own material.
Related reading
- DOJ issues new FCPA guidelines and enforcement prioritiesExplains the 2025 enforcement guidelines and which conduct the Department now says it will and will not pursue.Cleary Gottlieb
- DOJ's new FCPA investigations and enforcement guidelines: how organizations need to respondTranslates the guidelines into concrete changes to policy, third-party due diligence and internal reporting.Bracewell
- DOJ and SEC increase compliance expectations with updated requirementsSets out the hallmarks of an effective programme and the questions prosecutors ask to test whether it works in practice.Global Investigations Review
Independent third-party explainers, chosen by hand. Not affiliated with this site and not paid placements. All links are nofollow.
Need a hand implementing it?
Find a Consultant for FCPA
Tell us what you need done and we will point you to firms that do this work. Your details go to a firm only when you choose it.
From the publisher
Run the Policy Side of FCPA in AllyMatter
Approve the policies FCPA asks for, keep every version, and record a named acknowledgment from each person who has to read them.