Skip to main content
Category: Anti-Bribery and Corruption

Books and Records Provisions

Also known as: Accounting Provisions, FCPA Books and Records Provision
Simply put

Books and records provisions are legal requirements that certain companies keep accurate financial, operational, and legal records reflecting their transactions. In the context of the U.S. Foreign Corrupt Practices Act (FCPA), these rules are intended to help ensure corporate records are truthful and to make it harder to hide improper payments, such as bribes disguised as ordinary fees or expenses. They are generally understood as part of a broader set of accounting requirements rather than a standalone anti-bribery rule.

Formal definition

Under the FCPA's accounting provisions, covered issuers, their subsidiaries, and associated individuals are required to make and keep books, records, and accounts that, in reasonable detail, accurately and fairly reflect transactions and dispositions of assets. According to available evidence, these provisions are designed to strengthen the accuracy of corporate books and records and the reliability of the audit process, and they operate alongside related internal accounting controls requirements. Enforcement typically addresses failures such as the mischaracterization of bribes as legitimate fees or expenses. The precise scope, covered entities, and applicable standards depend on the governing statute and jurisdiction; broader references to 'books and records' may also describe general obligations to maintain financial, operational, and legal documents outside the FCPA context. This entry is educational and not legal, audit, or compliance advice; the specific requirements applicable to any entity turn on the relevant law, sector, and facts.

Why it matters

The FCPA's books and records provisions matter because inaccurate corporate records are frequently the mechanism through which improper payments are concealed. When a bribe is disguised as a legitimate consulting fee, commission, or business expense, the misconduct often first surfaces as a records problem rather than as an obvious act of corruption. According to available evidence, these provisions are designed to strengthen the accuracy of corporate books and records and the reliability of the audit process, which makes accurate record-keeping a first line of defense against the concealment of illicit conduct.

For covered companies, the significance lies partly in scope. The accounting provisions apply to how transactions are recorded generally, not only to those involving bribery, so a records failure can give rise to exposure even where the underlying transaction may be harder to prove as a corrupt act. Enforcement in this area typically addresses failures such as the mischaracterization of bribes as legitimate fees or expenses, which underscores why disciplined transaction documentation is central to a compliance program rather than a back-office formality.

Because the precise scope, covered entities, and applicable standards depend on the governing statute and jurisdiction, organizations should treat these provisions as one part of a broader accounting and controls environment rather than a standalone anti-bribery rule. This entry is educational and not legal, audit, or compliance advice; the requirements applicable to any specific entity turn on the relevant law, sector, and facts.

Who it's relevant to

Chief Compliance and Ethics Officers
Compliance leaders generally treat books and records requirements as a core element of an anti-bribery and corruption program, since inaccurate records are a common way that improper payments are concealed. They typically focus on how transactions with third parties, agents, and intermediaries are described and documented, given that enforcement often addresses the mischaracterization of bribes as fees or expenses. Ownership of specific controls, however, sits with the relevant business and finance functions, not compliance alone.
Chief Financial Officers and Controllers
Finance leaders are typically responsible for the systems and processes that produce books, records, and accounts reflecting transactions in reasonable detail. Because the accounting provisions operate alongside internal accounting controls requirements, controllers generally consider both the accuracy of individual entries and the design of the controls intended to keep records reliable. The applicable standards depend on the governing law and the entity's status.
Internal Auditors and Assurance Functions
Internal audit and other assurance functions generally test whether records fairly reflect transactions and whether related controls are operating as intended, providing independent evaluation rather than owning the underlying processes. The evidence notes that the accounting provisions are designed in part to support the reliability of the audit process, making record accuracy directly relevant to assurance work. Auditors distinguish between control design and operating effectiveness in forming their conclusions.
General Counsel and Legal Teams
Legal teams typically advise on how the FCPA's accounting provisions apply to the organization, keeping in mind that covered entities, scope, and standards depend on the governing statute and jurisdiction. They generally help distinguish the books and records provisions from the FCPA's separate anti-bribery provisions and from broader record-retention obligations that exist outside the FCPA context. Any application to specific facts requires case-specific legal judgment.
Audit Committees and Boards
Boards and audit committees generally exercise oversight of financial reporting integrity and the compliance program, rather than performing the operational record-keeping themselves. Because records accuracy underpins the reliability of financial reporting and the audit process, this area is typically within the audit committee's oversight remit, with management and assurance functions carrying out the underlying activities.

Inside Books and Records Provisions

Accurate Books and Records Requirement
The obligation, found in certain statutes and regulations, that a company keep books, records, and accounts that in reasonable detail accurately and fairly reflect its transactions and the disposition of assets. The precise standard and the entities covered vary by jurisdiction and by statute, and this requirement is generally distinct from the separate substantive anti-corruption prohibitions with which it is often paired.
Internal Accounting Controls Component
A related but separate requirement, under some regimes, to devise and maintain a system of internal accounting controls sufficient to provide reasonable assurances about the authorization, recording, and access to assets and transactions. This is a controls concept owned by management, and 'reasonable assurance' typically reflects a cost-benefit standard rather than a guarantee of perfection.
Scope of Covered Entities and Records
Which organizations and which records fall within a given books-and-records provision depends on the specific statute, listing rule, or regulation and on the entity type (for example, issuers versus privately held companies). Application to subsidiaries, joint ventures, and foreign operations is often a fact-specific and jurisdiction-specific question.
Relationship to Broader Governance and Assurance
Books-and-records obligations intersect with financial reporting, the three lines model, and external audit, but each function's role differs: management designs and operates controls, internal audit or compliance may test them, and the board and its audit committee provide oversight rather than day-to-day execution.

Common questions

Answers to the questions practitioners most commonly ask about Books and Records Provisions.

Are the books and records provisions only about preventing bribery?
No. While books and records requirements are often discussed alongside anti-bribery regimes, for example, the accounting provisions associated with certain anti-corruption statutes, their reach is generally broader. In many jurisdictions the recordkeeping and internal accounting controls obligations apply to how transactions are recorded and controlled regardless of whether any bribery occurs. A recordkeeping failure can arise from inaccurate or incomplete records even where no improper payment is involved. The precise scope, and whether specific provisions attach only to certain regulated entities, depends on the applicable statute, regulator, and jurisdiction, so this description is educational rather than a statement of any particular law's requirements.
Do books and records provisions require that a company detect and prevent every error or misstatement?
Generally not. Recordkeeping and internal accounting controls obligations are typically framed around maintaining records in reasonable detail and designing systems that provide reasonable assurance, rather than guaranteeing a perfect, error-free result. "Reasonable" is usually understood by reference to what a prudent organization would do in similar circumstances, and no control system eliminates all risk. Whether a particular standard applies, and how "reasonable" is interpreted, varies by framework and jurisdiction and can turn on the specific facts. This is a conceptual overview and not legal, audit, or compliance advice.
Which functions own responsibility for compliance with books and records provisions?
Accountability is typically distributed across the lines of defense rather than resting with a single function. Management and the business units that originate transactions generally own the first-line responsibility for recording them accurately and operating the relevant controls. Compliance and finance functions often provide second-line oversight, policy, and monitoring, while internal audit typically offers independent assurance over control design and operating effectiveness. The board or its audit committee generally holds an oversight role rather than an operational one. The exact allocation depends on the entity's structure, sector, and governance model, and roles should be defined in the organization's own policies.
How can an organization demonstrate that its recordkeeping controls are operating effectively, not just well designed?
Control design and operating effectiveness are distinct concepts, and demonstrating both usually requires different evidence. Design generally addresses whether a control, if operating as intended, would achieve its objective; operating effectiveness addresses whether the control actually functioned throughout the relevant period. Organizations commonly evidence operating effectiveness through testing of samples over time, reperformance, review of exception logs and reconciliations, and retained documentation showing controls ran as designed. The appropriate testing approach depends on the control, the associated risk, and any applicable assurance framework, and professional judgment is generally required to determine sufficiency.
What role does the audit committee typically play in relation to books and records obligations?
An audit committee generally exercises oversight rather than performing the underlying recordkeeping or control activities. This oversight commonly includes reviewing the adequacy of internal accounting controls, considering reports from management, internal audit, and external auditors, and challenging significant judgments and identified deficiencies. The committee typically does not design or operate controls itself; that operational responsibility usually sits with management. The specific mandate of an audit committee varies with listing rules, statutory requirements, and the entity's governance arrangements, so the committee's charter should be the reference point for its actual duties.
How should record retention be approached given that requirements can differ across the organization?
Retention is generally handled through a documented retention schedule that maps categories of records to applicable legal, regulatory, tax, and operational requirements, and that reflects any legal hold obligations arising from litigation or investigations. Because requirements can vary by jurisdiction, sector, and record type, organizations often adopt the longest applicable period for a given category or maintain jurisdiction-specific schedules. Coordination among legal, compliance, finance, and records or IT functions is typically needed to keep the schedule current and to ensure controls exist for both retention and defensible disposal. Specific retention periods depend on the applicable rules and should be confirmed against current sources rather than assumed.

Common misconceptions

Books-and-records provisions only matter where fraud, bribery, or an underlying substantive offense has occurred.
Under several regimes the accurate-records and internal-controls requirements are generally framed as standalone obligations that can be at issue independently of whether a separate substantive violation is proven. Whether and how they apply depends on the specific statute and jurisdiction; this is educational information, not legal advice.
The internal accounting controls requirement obliges a company to guarantee that no error or improper transaction ever occurs.
Where such requirements exist, they typically call for 'reasonable assurance' reflecting a cost-benefit judgment, not absolute certainty. Control design and operating effectiveness are distinct considerations, and a well-designed control can still fail to operate as intended.
Books-and-records compliance is solely the board's responsibility because it is a governance matter.
Management generally owns the design and operation of record-keeping and accounting controls, while the board and its audit committee typically provide oversight. Attributing operational execution to the board, or oversight duties to management, mischaracterizes where accountability sits.

Best practices

Confirm which specific statutes, regulations, or listing rules apply to your entity type and jurisdictions, and treat books-and-records obligations as potentially separate from any related anti-corruption or substantive requirements.
Clarify roles across the three lines: assign management ownership of record-keeping and accounting controls, define assurance and testing responsibilities for internal audit or compliance, and reserve oversight for the board and audit committee.
Assess controls on both dimensions, evaluate whether they are designed appropriately and separately test whether they operate effectively over the relevant period.
Extend consideration of books-and-records and controls requirements to subsidiaries, joint ventures, and higher-risk foreign operations, recognizing that coverage is fact- and jurisdiction-specific.
Maintain documentation that supports the 'reasonable detail' and 'reasonable assurance' standards, including rationale for cost-benefit judgments in control design.
Obtain qualified legal, audit, or compliance advice for specific application, since the scope and standard of these provisions vary by jurisdiction, sector, and facts.