Understanding the SEC's Inquiry
Recently, compliance teams at technology companies have been receiving letters from the SEC. These letters focus on business relationships with distributors, resellers, and other intermediaries in high-corruption-risk areas. This is part of an apparent Foreign Corrupt Practices Act (FCPA) enforcement sweep targeting the tech sector.
These letters aren't accusations of wrongdoing. They're investigative inquiries to assess potential FCPA violations. However, they've sparked urgent discussions in compliance departments, revealing confusion about the sweep's implications and necessary actions.
Does Receiving an SEC Letter Indicate Trouble?
No, receiving an SEC inquiry letter doesn't imply evidence of corruption or impending enforcement action. It's part of a sector sweep where the SEC is casting a wide net to identify potential violations.
Consider it a preliminary assessment. The SEC wants to understand your third-party relationships in high-risk countries. Your response will help them decide whether further investigation is needed.
However, your response is crucial. Inaccurate or incomplete information about your intermediaries raises red flags. If your response shows gaps in due diligence or oversight, it invites further scrutiny. The letter itself isn't an accusation, but your response could influence whether it becomes one.
Identifying Relevant Distributors
You must be aware of all your distributors, as the SEC is interested in relationships in high-corruption-risk countries. Transparency International's Corruption Perceptions Index lists numerous jurisdictions where bribery risks are significant.
Without a complete inventory of your third-party intermediaries, you can't accurately answer the SEC's questions. This is where the relationship between compliance and procurement is vital. Procurement manages vendor relationships, while compliance needs visibility into them.
Begin by mapping every distributor, reseller, broker, and sales agent your company works with. Overlay this map with corruption risk data for each jurisdiction. You should be able to produce this analysis quickly. If not, that's your first third-party risk management (TPRM) capability gap.
Is Basic Due Diligence Sufficient?
Basic background checks won't meet the SEC's expectations for FCPA compliance in high-risk markets.
Your due diligence should include ownership structure, beneficial owners, connections to politically exposed persons, past misconduct allegations, sanctions screening, and adverse media. You need to know if your intermediary has government officials on its board, if it's been investigated for bribery, or if its owners have ties to state-owned enterprises.
This information requires access to corporate registries, sanctions databases, PEP screening tools, and local news sources. Most compliance teams use specialized screening technology for this reason.
Ongoing monitoring is essential, not just initial checks. A distributor who was clean two years ago might have new owners today. Continuous monitoring is the standard.
What Should Contracts with Intermediaries Include?
Your contracts must grant you compliance oversight and enforcement rights. At a minimum, include:
- Right-to-audit provisions for examining the intermediary's books and records
- Anti-corruption representations and warranties
- Prohibition on sub-contracting without your written consent
- Requirement for regular activity reports
- Immediate termination rights if misconduct is discovered
- Compliance with your anti-corruption policies
The sub-contracting prohibition is crucial. If your distributor hires a local agent who pays bribes, you're still liable under the FCPA. Your contract should prevent that scenario or require advance approval.
Include clauses requiring the intermediary to maintain records of all payments and transactions for a specified period. When the SEC asks for documentation, you need to be able to produce it.
How Much Documentation is Necessary?
You need enough documentation to prove you're managing these relationships prudently. This includes due diligence reports, approval records, contracts, activity reports from the intermediary, payment records, training completion records, and periodic reviews.
Your policies should specify required documentation and retention periods. Conduct periodic internal audits to verify compliance with these requirements.
The practical test: if the SEC asks you to demonstrate how you vetted and monitored a specific distributor in a specific country over the past three years, can you produce a complete file within 48 hours? If not, your record-keeping isn't adequate.
Initiating Anti-Corruption Training for Third Parties
Start by requiring anti-corruption training as a condition of doing business. Your contract should specify that the intermediary's relevant personnel must complete your training program annually.
The training must be relevant to their role. Sales agents need to understand what constitutes an improper payment and how to decline bribe requests. Finance staff need to recognize red flags in expense reports and invoices.
Document everything: who completed training, when, what topics were covered, and assessment results if you're testing comprehension. This documentation becomes evidence of your good-faith compliance efforts.
Don't forget your own employees. Your sales teams, procurement staff, and finance personnel all need training tailored to their exposure to third-party risk.
Justifying the Investment to Leadership
Frame it as risk mitigation with measurable ROI. FCPA settlements often reach tens or hundreds of millions of dollars, plus the cost of monitorship, legal fees, and reputational damage.
The SEC's enforcement sweep signals its priorities. You're not asking leadership to invest in theoretical risk; you're responding to demonstrated regulatory focus.
Present the business case in terms leadership understands: "We have X distributors in high-risk jurisdictions representing Y revenue. We currently lack adequate due diligence, monitoring, and documentation capabilities. The cost to build those capabilities is Z, which is a fraction of potential FCPA penalties and far less disruptive than responding to an SEC investigation without adequate records."
Next Steps
If you've received an SEC inquiry letter, engage outside counsel immediately. Your response must be accurate, complete, and carefully crafted.
Whether or not you've received a letter, treat this sweep as a warning. The SEC is scrutinizing third-party relationships in high-risk jurisdictions, and technology companies are just the current focus. Other sectors will follow.
Assess your TPRM capabilities against the outlined requirements. Identify gaps. Build a remediation plan. Recognize that strong third-party risk management isn't just about regulatory compliance; it's about knowing who you're doing business with and protecting your organization from the risks they might create.



