ZenGRC

FCPA Compliance Checklist

An FCPA compliance checklist guides American companies in conducting foreign business by ensuring adherence to the U.S. Foreign Corrupt Practices Act of 1977, which prohibits corrupt payments to foreign officials and requires accurate accounting and internal controls, with enforcement by the SEC and DOJ, and emphasizes risk assessments, training, and corporate policies to prevent violations and avoid severe penalties.

An FCPA compliance program checklist outlines the steps an American company should take when conducting business in a foreign country to ensure adherence to the U.S. Foreign Corrupt Practices Act (FCPA) of 1977.

The FCPA is a federal law designed to prevent U.S. companies and their officers, directors, employees, and agents from making corrupt payments to foreign government officials to retain or obtain business. Agents—including consultants, third-party business partners, distributors, and joint ventures—are also subject to the FCPA’s anti-bribery provisions. The FCPA applies to foreign companies with subsidiaries in the United States, those doing business in the U.S., or whose transactions pass through the U.S. banking system.

FCPA violations can also occur if companies make payments to non-government third parties acting for or on behalf of foreign government officials.

In addition to the anti-bribery provision, the FCPA includes accounting transparency requirements. Every company reporting to the SEC must maintain accurate books and records and have a system of internal controls.

Corporations that fail to comply with the FCPA may face significant government fines, and individuals can be fined and imprisoned. The SEC and the DOJ (U.S. Department of Justice) are jointly responsible for FCPA enforcement actions. The FCPA is the most enforced U.S. anti-corruption law.

Follow an FCPA Compliance Checklist

Organizations can avoid FCPA violations by following a compliance checklist. The DOJ and SEC evaluate the adequacy of a company’s compliance program, focusing on training, risk assessment, and corporate policies.

Before drafting compliance programs, companies should conduct comprehensive risk assessments. The risk assessment should identify key risk areas, such as:

  • Significant dealings with foreign officials and workers of state-owned companies
  • Business units operating in countries with high levels of perceived corruption
  • Locations where anti-corruption concerns have been identified in the past
  • Business operations that depend heavily on third parties, such as agents, business partners, and distributors

The DOJ and SEC do not prescribe specific requirements for compliance programs, as each company must tailor its program to its size and risk exposure.

What to Include in an FCPA Compliance Checklist

To help organizations design effective compliance programs, the FCPA recommends including the following elements:

  • A clear policy prohibiting FCPA violations and violations of other applicable anti-corruption laws
  • Commitment from senior management that permeates the organization
  • Compliance program policies and procedures detailing proper internal controls, auditing practices, and documentation policies
  • Communication of compliance program policies and procedures throughout the organization
  • Clear disciplinary measures for violating compliance policies and procedures; encouragement and incentives for employees to adhere to compliance policies
  • Oversight personnel separate from management, with sufficient resources to implement the compliance program effectively
  • Regular assessment of third parties, including business partners, and informing them of the company’s compliance program and code of conduct
  • A confidential whistleblowing mechanism allowing employees to report possible FCPA violations without fear of retaliation; after internal investigations, update the compliance program and internal controls as needed
  • Regular review and updating of the compliance program and internal controls to adapt to changing business environments

Additional Questions to Ask

As companies assess and improve their compliance programs, they should consider the following questions:

  • Do you periodically analyze the results of investigations to identify patterns of wrongdoing or red flags indicating weaknesses in FCPA compliance?
  • How often and by what methods do you measure your culture of compliance?
  • How do you determine which FCPA complaints or red flags warrant further investigation?
  • How do you decide who should conduct investigations of potential FCPA violations, and who makes that determination?
  • Do you have a process to monitor the outcome of FCPA investigations and ensure accountability for responses to recommendations or findings?
  • Have supervisors received role-specific or supplemental training?
  • Have you conducted a gap analysis to determine whether your policies, internal controls, and training sufficiently address particular risk areas?
  • If you have foreign subsidiaries, are there language or other barriers that hinder foreign employees’ access to your FCPA compliance program policies and procedures?
  • Have you updated your FCPA compliance program policies and procedures in light of lessons learned?
  • Do you periodically analyze investigation results for patterns of wrongdoing or red flags?
  • How often and how do you measure your culture of compliance?