Skip to main content
Category: Anti-Bribery and Corruption

Foreign Corrupt Practices Act

Also known as:
Simply put

The Foreign Corrupt Practices Act is a United States federal law, originally enacted in 1977, that prohibits U.S. citizens and entities from bribing foreign government officials to gain or keep business. It bars offering, promising, authorizing, or giving money or anything of value to obtain an improper business advantage. This entry is educational and not legal or compliance advice; the statute's application depends on specific facts and requires professional judgment.

Formal definition

The FCPA is a U.S. federal law, originally enacted in 1977, containing anti-bribery provisions of broad applicability that prohibit persons and entities subject to U.S. law from offering, authorizing, promising, or giving money or 'anything of value' to foreign government officials to obtain or retain business or secure an improper business advantage. The statute is designed to prevent illicit payments or bribes as a condition of doing business, and its reach extends to U.S. citizens and entities as well as others within U.S. jurisdiction. Enforcement in the United States is handled in part by the Department of Justice's Criminal Division, including its Foreign Corrupt Practices Act Unit. Precise scope, jurisdictional coverage, and the interaction with related statutes (such as the Foreign Extortion Prevention Act) depend on the facts and applicable authority; practitioners should consult the governing statutory text and counsel for specific matters.

Why it matters

The FCPA is one of the most consequential anti-corruption statutes affecting how U.S. citizens and entities, and others within U.S. jurisdiction, conduct international business. Because its anti-bribery provisions are broadly applicable, they reach a wide range of dealings with foreign government officials, and a single improper payment (or even the offer, promise, or authorization of one) can expose an organization and its personnel to significant legal jeopardy. For boards, general counsel, and chief compliance officers, this makes the FCPA a central reference point when assessing the risks embedded in cross-border operations, third-party intermediaries, and market-entry strategies.

The statute also shapes how organizations design and resource their compliance programs. Because liability can attach to conduct undertaken to obtain or retain business or to secure an improper business advantage, entities operating internationally generally treat anti-bribery controls, due diligence on agents and partners, gifts and hospitality policies, and books-and-records discipline, as core elements of their compliance frameworks. The consequences of getting this wrong are not limited to the FCPA itself; related statutes address adjacent conduct, and the U.S. Department of Justice's Criminal Division, including its FCPA Unit, plays a role in enforcement. Note that the FEPA penalty figures cited in some enforcement materials (such as up to 15 years' imprisonment and a maximum fine of $250,000 or three times the value involved) relate to the Foreign Extortion Prevention Act, a distinct statute, rather than to the FCPA's own penalty provisions.

Crucially, whether particular conduct violates the FCPA depends heavily on the specific facts, the nature of the counterparty, and the applicable authority. This entry is educational and not legal or compliance advice; organizations facing real matters should consult the governing statutory text and qualified counsel.

Who it's relevant to

Boards and audit committees
Directors exercising oversight of an organization with international operations generally need assurance that anti-bribery risk is identified and managed. While the board does not run the compliance program itself, it typically oversees whether management has established adequate policies, controls, and monitoring to address FCPA exposure, particularly around third-party relationships and market entry.
Chief compliance officers and compliance teams
Compliance functions typically own the design and operation of anti-bribery controls, due diligence on agents and intermediaries, gifts and hospitality policies, training, and monitoring, intended to prevent illicit payments or bribes as a condition of obtaining or retaining business. They also help translate the statute's broad applicability into practical, fact-sensitive guidance for the business.
General counsel and legal teams
Because the FCPA's application depends on specific facts, jurisdictional coverage, and its interaction with related statutes such as the Foreign Extortion Prevention Act, legal counsel is generally central to assessing potential exposure, advising on transactions and counterparties, and managing any interaction with enforcement authorities.
Internal audit and assurance functions
Assurance functions typically evaluate whether anti-bribery controls are both well designed and operating effectively, providing independent testing of areas such as payments to foreign officials, third-party spend, and books-and-records accuracy, without owning the underlying operational controls.
Personnel in international-facing roles
Employees and agents involved in international sales, procurement, government interactions, or partnerships can encounter situations implicating the statute, since offering, promising, or authorizing anything of value to a foreign official may fall within its scope. Such individuals generally rely on organizational policies and should escalate uncertain situations rather than exercising judgment alone.

Inside FCPA

Anti-Bribery Provisions
Provisions that generally prohibit offering, paying, promising, or authorizing the payment of anything of value to foreign officials to obtain or retain business or secure an improper advantage. Coverage typically extends to issuers, domestic concerns, and certain persons acting within the relevant jurisdiction, though the precise scope depends on the facts and the statutory definitions.
Accounting and Internal Controls Provisions
Requirements generally directed at issuers to keep books and records that accurately and fairly reflect transactions and to devise and maintain a system of internal accounting controls. These provisions can apply independently of whether bribery occurred and are typically enforced alongside broader securities-law obligations.
Definition of Foreign Official
The concept of who qualifies as a foreign official can be broad and may include officers or employees of government-owned or government-controlled entities, as well as officials of public international organizations. Whether a particular person falls within scope is often fact-dependent and a frequent area of interpretive dispute.
Facilitating Payments and Affirmative Defenses
Certain narrow exceptions and affirmative defenses are commonly discussed in connection with the statute, such as limited allowances for routine governmental action or defenses tied to payments lawful under local written law or reasonable, bona fide expenditures. The availability and boundaries of these are narrow, fact-specific, and should be assessed with qualified advice.
Enforcement and Accountability
Enforcement is typically shared among the relevant civil and criminal authorities, with both anti-bribery and accounting provisions capable of forming the basis for action. Consequences can attach to entities and individuals; specific outcomes depend on the facts and the enforcing authorities' discretion.
Extraterritorial Reach
The statute is often described as having significant reach beyond domestic conduct, potentially capturing acts connected to covered persons or occurring in part within the relevant jurisdiction. The precise jurisdictional hooks are technical and depend on the actor's status and the nature of the conduct.

Common questions

Answers to the questions practitioners most commonly ask about FCPA.

Does the FCPA only apply to U.S. companies operating inside the United States?
No. The FCPA's reach is generally broader than domestic activity. Under the anti-bribery provisions, it typically applies to certain U.S. persons and entities (often described as issuers and domestic concerns) and, in many circumstances, to foreign persons and companies that act in furtherance of a corrupt payment while in U.S. territory. Its focus is on improper payments to foreign officials to obtain or retain business, so conduct occurring wholly or partly outside the United States can fall within scope depending on the actors and jurisdictional connections involved. Because the precise jurisdictional tests turn on facts and evolving enforcement interpretations, specific situations warrant qualified legal analysis. This entry is educational and not legal advice.
Is the FCPA purely an anti-bribery law, or does it impose other obligations?
It is a common misconception that the FCPA addresses only bribery. The statute generally has two distinct components: the anti-bribery provisions, which prohibit corrupt payments to foreign officials, and the accounting provisions, which typically require certain issuers to keep accurate books and records and to maintain a system of internal accounting controls. The accounting provisions can apply to conduct beyond bribery and do not always require proof of an improper payment. These are separate obligations with different elements and enforcement pathways, so treating the FCPA as a single bribery prohibition understates its scope. Application depends on entity type and facts; consult qualified counsel.
Which internal functions typically own FCPA-related activities, and where does accountability sit?
Responsibilities are generally distributed rather than concentrated in one place. Management typically owns the design and operation of day-to-day controls, such as third-party due diligence, payment approvals, and gifts and hospitality procedures. The compliance function generally sets policy, delivers training, and monitors adherence, while internal audit or another assurance function typically provides independent evaluation of control design and operating effectiveness. The board or a designated committee generally holds oversight accountability, including for the tone at the top and the adequacy of the program, without taking on operational execution. The specific allocation varies by entity size, structure, and risk profile.
How can an organization approach third-party and intermediary risk under an FCPA-oriented program?
Third parties such as agents, distributors, and consultants are frequently a significant source of corruption risk because payments can be made on a company's behalf. Programs generally address this through risk-based due diligence proportionate to the intermediary's role and geography, contractual provisions such as anti-corruption representations and audit rights, and ongoing monitoring rather than one-time screening. Distinguishing inherent risk from residual risk after controls is useful when calibrating the depth of review. The appropriate intensity depends on facts and the organization's own risk appetite and tolerance, and this overview is educational rather than a substitute for tailored compliance advice.
What role do books-and-records and internal accounting controls play in FCPA compliance?
For entities subject to the accounting provisions, accurate recording of transactions and a functioning system of internal accounting controls are typically central to compliance. These controls help ensure that payments are properly authorized and documented, which can both deter improper conduct and support detection. It is important to distinguish control design, meaning whether a control is capable of addressing the risk, from operating effectiveness, meaning whether it works as intended over time; assurance work generally tests both. Whether these provisions apply, and how, depends on entity type and jurisdiction, so organizations should confirm scope with qualified professionals.
How might a board or its committee exercise oversight of FCPA-related risk without stepping into management's role?
Oversight generally involves setting expectations and testing whether management's program is adequate, rather than executing controls directly. In practice, a board or committee may review the organization's corruption risk assessment, monitor how risk appetite and tolerance are reflected in policies, receive periodic reporting on incidents and remediation, and consider independent assurance findings on control effectiveness. The distinction matters: the board typically holds an oversight duty, while management retains the operational duty to build and run controls. Reporting cadence, committee assignment, and depth of review vary by organization and are matters of judgment; this is not legal or audit advice.

Common misconceptions

The FCPA only prohibits actual cash bribes.
The prohibition generally extends to anything of value, not only cash, and the accounting and internal controls provisions can be triggered by recordkeeping and control failures even absent a proven bribe. The two sets of provisions serve distinct purposes and can apply separately.
The FCPA is a compliance program requirement that the compliance function alone owns.
The statute is binding law, not a voluntary framework, and accountability is not confined to the compliance function. The board and its committees typically exercise oversight, management owns operational implementation of controls, and assurance functions provide independent evaluation. Conflating these roles obscures where accountability actually sits.
Facilitating payment exceptions and affirmative defenses provide broad, reliable protection.
Any such exceptions or defenses are generally narrow and highly fact-specific, and their availability varies with the circumstances. Relying on them without qualified legal analysis is risky, and this entry is educational rather than legal advice.

Best practices

Treat anti-bribery risk as a shared responsibility: clarify in governance documents that the board or a designated committee oversees the program, management owns day-to-day controls, and internal audit or another assurance function independently evaluates both control design and operating effectiveness.
Maintain accurate books and records and a system of internal accounting controls that can withstand scrutiny under the accounting provisions, recognizing these obligations can apply independently of whether any bribery is alleged.
Conduct risk-based due diligence on third parties, intermediaries, and business partners, giving particular attention to interactions with government-owned or controlled entities where the definition of foreign official may apply.
Do not rely on facilitating-payment exceptions or affirmative defenses without obtaining qualified legal advice, since their scope is narrow and fact-dependent.
Calibrate the program to the entity's jurisdictional footprint, given the statute's potential extraterritorial reach and the way requirements can vary by jurisdiction, sector, and entity type.
Provide targeted training and clear escalation and reporting channels so that potential issues reach the appropriate oversight and assurance functions promptly, and document decisions to support later review.