Scope of This Guide
This guide focuses on maintaining compliance programs during the current pause in U.S. Foreign Corrupt Practices Act (FCPA) enforcement, initiated by an executive order on February 10. It provides specific guidance on managing anti-corruption risk when federal enforcement is paused, yet legal obligations and international regulatory scrutiny persist.
This guide is relevant for:
- U.S. companies with international operations or third-party relationships
- Compliance officers managing anti-corruption programs
- Risk managers assessing exposure to UK, French, and other non-U.S. enforcement regimes
- Audit committees evaluating the adequacy of compliance controls
Key Concepts and Definitions
FCPA Enforcement Pause: The executive order directed Attorney General Pam Bondi to issue new guidelines on future FCPA enforcement while pausing current actions for at least six months. The statute remains law with a five-year statute of limitations.
Extraterritorial Enforcement: The UK Bribery Act and France's Sapin II law allow prosecution of companies operating in their markets or using their financial systems, regardless of where the bribery occurred.
Adequate Procedures Defense: Under the UK Bribery Act, companies can defend against corporate liability by demonstrating they had adequate procedures to prevent bribery, requiring documented, functioning controls.
Convention Judiciaire d'Intérêt Public (CJIP): France's deferred prosecution agreement mechanism. The Parquet National Financier has secured more than 20 CJIPs related to bribery, indicating active enforcement.
Requirements Breakdown
U.S. Legal Obligations
The FCPA remains federal law. Your company's legal obligation to comply hasn't changed, only the current enforcement posture. The statute of limitations extends five years, reaching beyond 2029.
Anti-Bribery Provisions: 15 U.S.C. § 78dd-1 (issuers), § 78dd-2 (domestic concerns), § 78dd-3 (persons other than issuers or domestic concerns) prohibit corrupt payments to foreign officials.
Accounting Provisions: 15 U.S.C. § 78m requires accurate books and records plus adequate internal accounting controls.
UK Bribery Act Requirements
Section 7 - Failure to Prevent Bribery: Creates corporate liability when an associated person commits bribery intending to benefit the company. Your defense requires proving adequate procedures were in place.
Section 6 - Bribery of Foreign Public Officials: Directly criminalizes payments to foreign officials, with no facilitation payment exception.
Six Principles (Ministry of Justice Guidance 2011):
- Proportionate procedures
- Top-level commitment
- Risk assessment
- Due diligence
- Communication and training
- Monitoring and review
France's Sapin II Framework
Article 17 Requirements: Companies with 500+ employees and €100 million+ revenue must implement:
- Code of conduct
- Internal alert system (whistleblower mechanism)
- Risk mapping
- Third-party evaluation procedures
- Accounting controls
- Training program
- Disciplinary regime
- Control and evaluation system
The Agence Française Anticorruption (AFA) conducts compliance audits and can impose penalties for inadequate programs.
Implementation Guidance
Adjust Your Risk Assessment Geography
Recalibrate your risk assessment to reflect where enforcement is most active. SFO Director Nick Ephgrave has indicated a desire to take a "bolder, more proactive" approach to enforcement.
Immediate actions:
- Map your operations against UK and French jurisdictional triggers (UK nexus: operations, contracts, use of UK financial system; French nexus: French parent/subsidiary, operations in France, French persons involved)
- Identify third parties that could create UK or French exposure
- Review whether your procedures meet the UK's "adequate procedures" standard and Sapin II's Article 17 requirements
Maintain Core Capabilities
Your compliance program infrastructure serves multiple regulatory and operational purposes. Don't dismantle capabilities because one enforcement agency has paused.
Essential capabilities to preserve:
Hotline and Investigation Function: Employees report more than FCPA violations. You'll still receive reports about harassment, discrimination, conflicts of interest, and other misconduct. A functioning investigation process remains essential.
Third-Party Due Diligence: Beyond corruption risk, third parties bring sanctions exposure, data privacy obligations, modern slavery risks, and operational dependencies. Your due diligence program addresses all of these.
Control Testing and Monitoring: Your accounting controls serve both FCPA compliance and financial statement accuracy. Section 404 of the Sarbanes-Oxley Act still requires management assessment of internal control over financial reporting.
Training and Communication: Don't signal to your workforce that anti-corruption standards have changed. Maintain training cadence and reinforce that your company's ethical standards remain unchanged.
Prepare for International Cooperation Standards
UK and French regulators have different expectations for cooperation and self-disclosure than U.S. authorities.
UK SFO cooperation:
- Early engagement is valued but not always rewarded with declination
- Disclosure must be truly voluntary (before investigation begins)
- Remediation must be swift and thorough
- The SFO may still prosecute individuals even if the company cooperates
French PNF approach:
- CJIP negotiations require admission of facts
- Public interest assessment affects settlement availability
- Compliance monitor appointments are common
- Penalties can reach 30% of average annual revenue
Common Pitfalls
Pitfall 1: Assuming Low Enforcement Equals Low Risk
Contracts secured through bribery can be voided in court. Corrupt officials become emboldened to demand more payments. Competitors may report your conduct to international regulators. The underlying business risks haven't changed.
Pitfall 2: Focusing Only on Government Enforcement
Shareholder derivative suits, whistleblower complaints, and reputational damage all create risk independent of regulatory action. Your compliance program mitigates these exposures.
Pitfall 3: Treating International Standards as Optional
If you operate in the UK or France, those jurisdictions' laws apply to you directly. This isn't extraterritorial overreach; it's a local compliance obligation.
Pitfall 4: Reducing Compliance Budget Without Risk Analysis
Present your board and management team with a risk-based analysis: what specific risks increase if you reduce specific capabilities? Make them choose consciously rather than cutting by default.
Pitfall 5: Ignoring the Statute of Limitations
Five years extends well beyond the current administration. Document your risk assessment and the board's decisions about compliance investment. You'll need that record if enforcement resumes.
Quick Reference Table
| Requirement | Source | Key Standard | Enforcement Body | Current Activity Level |
|---|---|---|---|---|
| Anti-bribery provisions | FCPA, 15 U.S.C. § 78dd | No corrupt payments to foreign officials | DOJ, SEC | Paused (executive order) |
| Books and records | FCPA, 15 U.S.C. § 78m | Accurate records, adequate controls | SEC | Active (accounting rules) |
| Failure to prevent bribery | UK Bribery Act, Section 7 | Adequate procedures defense | SFO | Increasing |
| Foreign official bribery | UK Bribery Act, Section 6 | No facilitation payment exception | SFO | Increasing |
| Anti-corruption program | Sapin II, Article 17 | Eight mandatory elements | AFA, PNF | Active (20+ CJIPs) |
| Internal controls (public companies) | Sarbanes-Oxley, Section 404 | Management assessment required | SEC | Active |
| State consumer protection | Consumer Financial Protection Act | Varies by state | State AGs, banking regulators | Active |
Your compliance obligations haven't paused. Adjust your program to address where enforcement is most active, maintain the capabilities that serve multiple risk areas, and document your decisions. The whirlwind will pass, but your risk register won't.



