Brazil's anti-corruption regime is institutionalizing transparency through codified leniency mechanisms. Meanwhile, the US Department of Justice (DOJ) has reduced its foreign-bribery team to around 15 prosecutors from an estimated 32 and now requires senior approval for new FCPA investigations. These diverging enforcement strategies expose a recurring pattern: multinational compliance teams design programs as if regulatory regimes operate in parallel, then scramble when enforcement actions reveal they don't.
Why These Mistakes Keep Happening
Most compliance frameworks treat jurisdictional differences as implementation details rather than strategic design constraints. Teams often build a single global policy, translate it into local languages, and assume consistency. This approach works until enforcement authorities in different jurisdictions make incompatible demands or offer conflicting incentives for cooperation. By then, the company is negotiating under pressure with incomplete data and misaligned internal processes.
The Brazil-US split illustrates the problem. Brazil's draft ordinance introduces a "marker" mechanism that secures priority for companies willing to self-report misconduct, with objective criteria for fine reductions up to two-thirds. The DOJ's updated approach concentrates resources on cases involving national security, large-scale bribery schemes, and individual liability. Your compliance program must serve both jurisdictions without creating gaps or duplication.
Mistake 1: Treating Voluntary Self-Disclosure as a Universal Protocol
Why it happens: Compliance teams read that both Brazil and the US reward voluntary self-disclosure and conclude they can use the same internal escalation process for both jurisdictions.
The consequence: Brazil's draft ordinance codifies a marker that interrupts the statute of limitations once a memorandum of understanding is signed, then suspends it for up to 360 days while negotiations proceed. The US Corporate Enforcement Policy offers automatic declinations when criteria are met but applies strategic selectivity at the intake stage. A company that self-reports to the DOJ may trigger an investigation the department would otherwise have declined to open. A company that delays reporting in Brazil loses timeliness credit that's now quantified in the draft ordinance.
The fix: Build jurisdiction-specific decision trees. Before self-reporting to US authorities, assess whether the conduct falls within DOJ's stated priorities: cartels, transnational criminal organizations, threats to US competitiveness, or national security concerns in defense, critical infrastructure, energy, technology, ports, or critical minerals. If it doesn't, document the analysis but consider whether disclosure creates more risk than it mitigates. In Brazil, trigger the marker early to secure priority and timeliness credit, even before completing the internal investigation. Your legal hold and investigation scoping must account for these different timelines.
Mistake 2: Using Identical Risk Assessments Across Jurisdictions
Why it happens: Compliance teams map corruption risk by transaction type, counterparty category, and geographic market. They assume enforcement authorities weight these factors similarly.
The consequence: The DOJ's June 9 memo directs prosecutors to prioritize cases that safeguard fair opportunities for US companies and address national security threats. A payment to a foreign official in a critical minerals sector carries higher US enforcement risk than an identical payment in retail, even if both violate the FCPA. Brazil's enforcement doesn't tier by sector in the same way; the draft ordinance applies objective fine-reduction criteria based on cooperation and timeliness, not strategic sector weighting.
The fix: Overlay sector-based risk mapping onto your existing controls. Flag transactions in defense, infrastructure, energy, technology, ports, and critical minerals for enhanced US-focused diligence. In Brazil, prioritize speed of detection and internal reporting over sector distinctions, because the draft ordinance rewards first-in, timely self-reporting with up to two-thirds fine reductions. Your quarterly risk reporting to the board should segment exposure by jurisdiction and enforcement priority, not just by business unit or geography.
Mistake 3: Negotiating Penalties in Silos
Why it happens: When enforcement actions arise in multiple jurisdictions, legal teams often negotiate separately with each authority to avoid complicating either discussion.
The consequence: The DOJ's anti-"piling on" policy (Justice Manual § 1-12.100) encourages credit for payments made abroad, and Brazil's draft ordinance clarifies how to compute the advantage obtained while avoiding double jeopardy by crediting amounts paid in other domestic or foreign proceedings. In the Petrobras matter in 2018, the DOJ and SEC explicitly credited amounts paid to Brazilian authorities. In GOL in 2022, the DOJ credited a portion of the Brazilian penalty. Companies that negotiate in silos forfeit this coordination and risk paying duplicative amounts.
The fix: Establish a cross-border resolution protocol before you need it. Designate a single coordinating counsel with authority to share information across enforcement discussions (subject to privilege and confidentiality rules). Document penalty calculations, cooperation credit, and monitorship obligations in a format that can be presented to multiple authorities. When negotiating with Brazilian authorities under the draft ordinance's memorandum of understanding stage, preserve the record of cooperation and disclosure for potential US discussions. When negotiating with the DOJ, quantify amounts already paid or committed in Brazil and present them as part of the resolution calculus.
Mistake 4: Ignoring Statute-of-Limitations Mechanics
Why it happens: Compliance teams treat limitations periods as background legal facts, not as variables they can influence through procedural choices.
The consequence: Brazil's draft ordinance provides that once a memorandum of understanding is signed, the statute of limitations is interrupted and then suspended for up to 360 days while negotiations proceed. This gives companies breathing room but also locks them into a negotiation timeline. In the US, the statute of limitations continues to run unless tolled by agreement or other action. A company that sequences its Brazilian and US disclosures without accounting for these mechanics may find itself time-barred in one jurisdiction while still negotiating in the other.
The fix: Map limitations periods for each jurisdiction before you begin internal investigations. In Brazil, understand that signing the MoU triggers the suspension, so time your investigation completion and disclosure to maximize the value of the marker while preserving your ability to negotiate. In the US, if you're approaching the limitations deadline, negotiate a tolling agreement early in the cooperation process. Your investigation timeline should be driven by these procedural deadlines, not by the pace of document review.
Mistake 5: Drafting M&A Provisions That Assume Regulatory Symmetry
Why it happens: Transaction agreements use standard anti-corruption representations and warranties, often borrowed from prior deals or form books.
The consequence: A target company with operations in Brazil and the US may have exposure under both regimes, but the reps, warranties, and indemnities often don't distinguish between them. If the DOJ has closed an FCPA matter as part of its strategic selectivity but Brazilian authorities later open an investigation under the Clean Company Act, the buyer may lack contractual protection. If the target has initiated a marker in Brazil but not disclosed to the DOJ, the buyer inherits a ticking clock without adequate data.
The fix: Draft jurisdiction-specific disclosure schedules. Require the target to disclose any markers filed, memoranda of understanding signed, or cooperation discussions initiated in Brazil, with copies of all submissions. Require separate disclosure of any FCPA matters, including those the DOJ declined to pursue. Include indemnities that account for parallel Brazil-US exposure, with clear allocation of liability if one jurisdiction's penalty isn't credited in the other. Preserve all data needed to satisfy the DOJ's Corporate Enforcement Policy criteria, because voluntary self-disclosure post-acquisition can still earn credit if the buyer acts promptly.
Prevention Checklist
- Maintain jurisdiction-specific self-disclosure decision trees that account for DOJ strategic priorities and Brazil's marker mechanism
- Segment corruption risk assessments by enforcement priority (US: national security, competitiveness, TCO links; Brazil: timeliness and cooperation credit)
- Designate coordinating counsel with authority to negotiate across jurisdictions and present unified penalty calculations
- Map statute-of-limitations deadlines for each jurisdiction before beginning internal investigations
- Draft M&A provisions with separate disclosure schedules for Brazil (markers, MoUs) and US (FCPA matters, including declined cases)
- Document cooperation and disclosure in formats that can be presented to multiple authorities
- Review commercial anti-corruption clauses to capture US priority sectors and Brazil's transparency expectations
- Train investigation teams on procedural differences: Brazil's MoU suspension period vs US tolling agreements
- Update quarterly board risk reporting to segment exposure by jurisdiction and enforcement priority, not just geography
The contrasting anti-corruption enforcement strategies of Brazil and the US highlight the need for multinational companies to adopt adaptive, dual-track compliance strategies.



