The Foreign Corrupt Practices Act (FCPA) doesn't disadvantage US companies in global markets. Poor implementation of FCPA compliance programs does. Companies that treat anti-bribery controls as mere regulatory checkboxes rather than strategic frameworks consistently make operational mistakes, creating the disadvantages critics wrongly attribute to the statute itself.
Why These Mistakes Keep Happening
Many organizations approach FCPA compliance reactively, building programs in response to enforcement actions or audit findings instead of integrating anti-corruption controls into their business strategy from the start. This reactive stance leads to superficial programs that meet documentation requirements without changing deal structures or third-party management. Consequently, compliance teams become gatekeepers rather than advisors, and business units view controls as obstacles. This results in lost opportunities and unnecessary risks.
Mistake 1: Treating Due Diligence as a Pass/Fail Exercise
Why it happens: Compliance teams often inherit a vendor or partner after terms have been negotiated. Under time pressure, they run a risk-scoring matrix and either approve or reject based on threshold scores.
The consequence: This binary approach misses the point of third-party due diligence. A distributor in a high-corruption area may present risks but also be the only viable market route. Rejecting or approving without tailored controls either loses business or accepts unmanaged exposure.
The fix: Redesign due diligence as a risk calibration process. When a third party presents corruption risk but also strategic value, determine what contractual provisions, payment structures, audit rights, and oversight mechanisms would make the relationship manageable. This could involve joint-signature approvals, quarterly transaction reviews, or restructuring commission rates. The goal is informed decisions about controllable risks.
Mistake 2: Building Controls That Ignore How Corruption Actually Happens
Why it happens: Compliance programs often focus on direct bribes to government officials, as that's clearly prohibited by the statute. Training modules depict obvious scenarios like cash payments to customs officers.
The consequence: Real FCPA violations are rarely straightforward. Corruption often involves intermediaries, disguised expenses, or reciprocal arrangements. Programs focused on direct bribes miss the consultant who's a procurement official's relative or the distributor funding political campaigns.
The fix: Map your actual transaction flows and relationship structures in high-risk markets. Identify where value transfers to third parties, where discretion concentrates, and where oversight gaps exist. Build controls addressing these vulnerabilities. If agents interact with government offices, controls should cover selection, monitoring, and compensation. For joint ventures in state-dominated jurisdictions, controls should address hiring, expense approvals, and government relationship management.
Mistake 3: Separating Accounting Controls from Anti-Corruption Strategy
Why it happens: Organizations often treat the FCPA's books-and-records provisions as an accounting responsibility, separate from anti-bribery work handled by compliance.
The consequence: This separation ignores the FCPA's dual requirements: anti-bribery and accurate books with sufficient internal controls. Many enforcement actions focus on accounting violations because inaccurate records and weak controls enable undetected corruption. When finance and compliance operate in silos, neither sees the full picture.
The fix: Integrate accounting and anti-corruption controls into a single framework. Finance teams need to understand which expense categories and payment patterns present corruption risk. Compliance teams need to know how payments are recorded and reconciled. Build approval hierarchies requiring compliance sign-off on payments to high-risk third parties, establish expense coding for additional review, and create reconciliation procedures comparing contract terms to payment patterns.
Mistake 4: Assuming Enforcement Risk Falls Only on US Companies
Why it happens: The FCPA is a US statute, enforced by the Department of Justice and the Securities and Exchange Commission. Companies assume it primarily constrains American businesses.
The consequence: This assumption is incorrect and costly. Nine out of 10 of the largest FCPA enforcement actions have been against foreign companies. The statute applies to any company with US securities listings, using US financial systems, or acting through US persons. Foreign competitors face the same legal exposure, often with less-developed compliance programs.
The fix: Reframe FCPA compliance as a competitive advantage. In high-corruption markets, your compliance program, documented due diligence, and clean enforcement record become differentiators. Sophisticated counterparties prefer partners with robust controls. Highlight your compliance capabilities in proposals, due diligence responses, and discussions. Emphasize your ability to structure deals that withstand scrutiny and manage third-party risk.
Mistake 5: Treating Country Risk as Static
Why it happens: Compliance teams assess corruption risk by jurisdiction, using third-party risk indices, and apply uniform controls across each risk tier.
The consequence: Corruption risk isn't static or uniform within jurisdictions. Political transitions, enforcement priorities, and economic conditions change the risk environment. Uniform controls based on static classifications miss these variations, over-constraining low-risk activities or under-protecting high-risk ones.
The fix: Build dynamic risk assessment into your compliance program. Monitor political developments, enforcement actions, and regulatory changes, adjusting controls accordingly. Reassess third-party relationships and transaction structures when new governments take power or enforcement priorities shift. Recognize that country-level risk ratings are a starting point, not a conclusion.
Mistake 6: Measuring Compliance by Activity Rather Than Outcomes
Why it happens: Organizations track easy-to-measure compliance metrics like training completion rates and due diligence reports generated.
The consequence: Activity metrics don't indicate whether your program prevents corruption or enables competitive advantage. High training completion rates mean nothing if behavior doesn't change. Extensive due diligence reports mean nothing if they don't inform better decisions.
The fix: Supplement activity metrics with outcome indicators reflecting program effectiveness. Track the percentage of third-party relationships requiring enhanced controls and their performance. Monitor how often business units consult compliance early in deal development. Measure how often red flags are identified and addressed before escalating. Assess whether your compliance program enables business growth in high-value markets.
Prevention Checklist
Use this checklist to audit your FCPA compliance program against the mistakes outlined above:
Risk Assessment
- Have you mapped actual transaction flows and relationship structures in high-risk markets within the past 12 months?
- Do your risk assessments account for how corruption typically occurs in your industry and business model, not just direct bribery scenarios?
- Do you have a process for updating risk assessments when political or regulatory conditions change in key markets?
Third-Party Management
- Does your due diligence process produce risk calibration and control recommendations, not just approve/reject decisions?
- Can you articulate what specific controls would make a high-risk third-party relationship manageable?
- Do your third-party contracts include audit rights, transaction review provisions, and termination clauses tied to compliance failures?
Internal Controls
- Do your payment approval workflows require compliance review of transactions involving high-risk third parties or government-related expenses?
- Have you integrated your accounting controls and anti-corruption controls into a single framework with defined handoffs between finance and compliance?
- Do your expense coding and reconciliation procedures flag government-related costs and third-party payments for additional scrutiny?
Strategic Positioning
- Do your proposals and relationship discussions emphasize your compliance capabilities as a competitive advantage?
- Have you assessed whether your foreign competitors in key markets face similar or greater FCPA exposure?
- Do you track whether your compliance program enables business development in high-value markets or only constrains it?
Program Effectiveness
- Do you measure program outcomes (risks identified and managed, business enabled in high-risk markets) in addition to activities (training completed, reports generated)?
- Do business units consult compliance early in deal development, or only at the approval stage?
- Can you demonstrate that your compliance program has prevented potential violations or enabled competitive wins in the past 24 months?
Organizations that succeed in high-corruption markets aren't those that ignore the FCPA or treat it as a burden. They're the ones that build compliance programs sophisticated enough to manage real risk while preserving real opportunity. Avoiding these mistakes turns a strategic advantage into a competitive edge.



