Introduction
The Foreign Corrupt Practices Act (FCPA) is one of the most consequential and rigorously enforced statutes in United States law. For companies with any international dimension to their operations, a working understanding of what triggers enforcement scrutiny is not optional — it is a core component of responsible governance.
Enacted in 1977 in the wake of the Watergate-era revelations that hundreds of American corporations had been making secret payments to foreign officials, the FCPA has two principal pillars. The anti-bribery provisions prohibit any covered person or entity from offering, paying, promising, or authorizing the payment of money or anything of value to a foreign official for the purpose of obtaining or retaining business. The accounting provisions — which are often underappreciated — require issuers of securities registered under the Securities Exchange Act to maintain accurate books and records and to implement a system of internal accounting controls sufficient to ensure that transactions are properly authorized and recorded. Violations of either set of provisions can carry severe consequences: criminal fines running into the hundreds of millions of dollars, civil penalties, disgorgement of profits, debarment from government contracting, monitorship requirements, and, for individuals, potential prison sentences.
The Department of Justice (DOJ) and the Securities and Exchange Commission (SEC), which share enforcement authority over the FCPA, have in recent years signaled an intensified focus on individual accountability and on the adequacy of corporate compliance programs. Understanding the circumstances — the red flags — that attract regulator attention is therefore essential for any company doing business across borders. This article sets out the most significant categories of red flags that should prompt heightened scrutiny and, where necessary, a pause in the relevant transaction or relationship.
Red Flags in Third-Party Relationships
The single most common vehicle through which FCPA violations occur is the use of third parties: agents, distributors, consultants, joint-venture partners, and other intermediaries who interact with foreign officials on a company’s behalf. The FCPA’s reach is intentionally broad enough to cover payments made through such intermediaries — a company cannot insulate itself from liability merely by placing a layer of representation between itself and an improper payment. The DOJ and SEC have made clear that willful blindness to red flags in third-party relationships will not be treated as an exculpatory defence.
Unusual Commission Structures and Requests for Cash
Perhaps the clearest red flag in any agent or distributor relationship is a commission, fee, or payment structure that is disproportionate to the legitimate services being rendered, or that is structured in a way that obscures its ultimate destination. A request from an intermediary to be paid in cash, through an offshore account, in a currency that is not standard for the market, or to a bank account in a jurisdiction that has no obvious connection to the place of business, demands immediate and serious attention. Legitimate service providers operating in good faith rarely have a commercial rationale for structuring their compensation in ways that resist transparency.
Companies should also be alert to requests by intermediaries for payments that are described vaguely — as “government relations support,” “facilitation services,” or similar formulations that lack specific, verifiable content. Where a third party is unwilling or unable to provide a clear breakdown of how their fee is being used to deliver legitimate commercial services, this is a significant warning signal.
Lack of Qualifications or Apparent Expertise
When an intermediary is recommended by a foreign government official, or when their apparent qualifications bear no rational relationship to the services they are being engaged to provide, companies should proceed with caution. A consulting firm with no discernible staff, no track record of relevant work, and no credible explanation of how it will add value — yet which commands a substantial fee in connection with a government contract or regulatory approval — raises obvious concerns. Similarly, a distributor who is represented to be essential for market access but who has no apparent operational infrastructure or industry expertise warrants scrutiny.
Connections to Foreign Officials
Any close personal or financial connection between a proposed agent, consultant, or joint-venture partner and a foreign government official is a red flag that requires genuine investigation, not merely documented acknowledgement. This includes situations where the intermediary is a relative, friend, or former colleague of the relevant official, or where the intermediary has recently departed from a position in the relevant government ministry or procurement office. The so-called “revolving door” issue has attracted significant enforcement attention, including in the context of hiring programs that employed the family members of foreign officials in circumstances where those officials had direct authority over business decisions affecting the employing company.
Geographic and Industry Risk Factors
While no jurisdiction is inherently corrupt, and while the FCPA does not operate on any principle of geographic profiling, the practical reality is that the risk of encountering solicitations for improper payments varies significantly across markets. Corruption Perceptions Index scores published annually by Transparency International, together with the State Department’s Country Reports on Human Rights Practices, provide a useful baseline for identifying markets where the risk environment is heightened. Operating in a market consistently rated as having high levels of public-sector corruption does not, of course, imply that a company is violating the FCPA — but it does mean that robust due diligence, enhanced monitoring, and a carefully calibrated compliance program are not merely good practice but are a practical necessity.
Certain industries carry structurally elevated FCPA risk because of the frequency and materiality of their interactions with foreign government officials. The energy, mining, and extractive industries are obvious examples: licenses, concessions, and environmental approvals are typically granted by state actors, often in markets with weak governance institutions. Defense contracting, pharmaceutical and medical device sales in markets with state-owned health systems, telecommunications companies seeking spectrum allocations, and infrastructure companies bidding on government-funded projects all share a similar structural feature — the commercial opportunity is effectively gatekept by a public official whose discretion is, or may be perceived to be, susceptible to improper influence.
When a company is entering a new, high-risk market for the first time, or when it is pursuing a particularly large or competitively sensitive government contract, the risk that one of its agents or employees may resort to improper payments — whether on their own initiative or in response to solicitation — is at its highest. This is precisely when compliance procedures must be most rigorous, and when senior leadership must make unmistakably clear that no contract is worth an FCPA violation.
Financial Transaction Red Flags
The FCPA’s accounting provisions impose independent obligations that go beyond the prohibition on bribery itself. A company can face significant liability if its books and records do not accurately and fairly reflect its transactions, or if its internal controls are insufficiently robust to detect and prevent improper payments. The following financial warning signs are therefore important both as indicators of potential bribery and as potential standalone accounting violations.
Payments Without Adequate Documentation
Any payment — whether to a third party, a government entity, or a charitable organization — that lacks a clear contractual basis, a proper invoice, a documented approval chain, and evidence of legitimate services rendered, is a red flag. This is particularly true where the payment is described at a high level of generality in the accounting records, or where it is classified in a way that does not correspond to its actual nature. Regulators examining corporate records look carefully at categories such as “miscellaneous expenses,” “consulting fees,” “government relations,” and “facilitating payments” — especially where those categories show unusual spikes in markets where the company is simultaneously pursuing significant government business.
Gifts, Hospitality, and Travel Expenses
While the FCPA does not prohibit reasonable and bona fide expenditures on hospitality and travel — including the payment of a foreign official’s reasonable travel costs in connection with the promotion of products or services — the gift, hospitality, and travel expense category has been the source of numerous enforcement actions. The key questions are whether the expenditure is proportionate and consistent with local business custom, whether it is accurately recorded in the company’s books, and whether the timing of the expenditure relative to a pending regulatory or procurement decision creates any inference of improper intent.
Companies should be alert to patterns of expenditure that, while individually modest, aggregate into a material benefit conferred on foreign officials or their family members. All-expenses-paid trips that combine a nominal business component with substantial leisure, luxury gifts that bear no relationship to legitimate business promotion, and entertainment expenditures incurred in circumstances where the relevant official has a pending discretionary decision affecting the company, all warrant careful scrutiny against the company’s policies and against the FCPA standard.
Side Agreements and Undisclosed Payments
The existence of a side agreement — that is, an arrangement that is not reflected in the formal contract or recorded in the company’s books — is one of the most serious FCPA red flags. Side agreements are commonly used to establish unofficial compensation for intermediaries that exceeds the rate disclosed in the formal engagement letter, or to create an obligation to make payments that neither party wishes to have documented. Discovery of a side agreement, or of persistent discrepancies between contractual terms and actual payment patterns, should trigger an immediate compliance review.
Internal and Organisational Red Flags
Red flags do not only arise from a company’s external relationships. The internal culture of an organisation, and the conduct of its own employees, can be equally important indicators of FCPA risk.
A Culture of Results Over Compliance
Perhaps the most dangerous internal red flag is an organisational culture in which commercial results are valued to the exclusion of compliance considerations, and in which employees perceive that they will be rewarded for securing business by any means necessary and penalised for raising compliance concerns that threaten to derail a deal. Regulators have repeatedly emphasised that an effective compliance program requires genuine commitment from the most senior levels of leadership — not merely the formal existence of a written policy. Where senior management communicates, even implicitly, that the compliance function is an obstacle rather than a partner, employees operating in high-risk markets will draw their own conclusions.
Pressure Around Specific Transactions
Unusual urgency around the execution or payment stages of a transaction involving a foreign government counterparty is a red flag, particularly where that urgency has the effect of circumventing normal approval or documentation processes. Requests from local management or from an external agent to accelerate a payment, to approve an invoice without customary review, or to obtain a sign-off from a senior executive who would not normally be involved in such matters, should prompt rather than suppress inquiry. Similarly, where a business opportunity is presented as time-sensitive in a way that discourages due diligence on the third parties involved, this should be treated with suspicion.
Complaints, Whistleblower Reports, and Prior Incidents
The receipt of a whistleblower complaint, an anonymous tip, or a formal complaint from a competitor or business partner alleging improper payments in connection with a specific market or transaction is a red flag that carries a legal dimension beyond internal compliance concerns. The Dodd-Frank Act provides significant financial protections for individuals who report potential FCPA violations to the SEC, and the Commission maintains an active whistleblower program that has resulted in substantial awards. When a company receives any credible report of potential improper payments, a prompt and thorough investigation is not simply good practice — in many cases it is a legal and governance obligation.
A company’s own history of FCPA-related issues is also highly relevant. Prior enforcement actions, declinations conditioned on remedial measures, or internal investigations that uncovered problematic payment practices should elevate the level of scrutiny applied across the business, not merely in the specific market or transaction type that was previously implicated.
Due Diligence Failures as Red Flags in Transactions
Mergers, acquisitions, and joint-venture formations present a distinctive FCPA risk: a company may, through the acquisition of a target, inherit not only that target’s assets and operations but also its pre-existing FCPA liabilities. The DOJ and SEC have addressed this risk in their enforcement guidance, making clear that acquiring companies can inherit successor liability for pre-acquisition conduct — and that robust pre-closing due diligence, combined with prompt post-closing remediation where issues are discovered, can be important mitigating factors in any subsequent enforcement action.
Red flags that should be pursued vigorously in the due diligence phase of any international transaction include a target company’s use of agents or intermediaries who are not party to written agreements or whose compensation is not reflected in the formal accounts; entries in the target’s books that suggest payments to government officials or their associates; unusual concentrations of business with state-owned enterprises; significant operations in markets rated as high-risk for corruption; and a compliance program that is either non-existent or exists only on paper.
Where pre-closing due diligence identifies potential FCPA issues, the options include renegotiating the transaction price to reflect the risk, requiring the seller to make specific representations and indemnities, conditioning closing on remediation of identified issues, or, in the most serious cases, walking away from the transaction altogether. What is not a responsible option is proceeding to closing with knowledge of significant red flags and without a clear plan for addressing them.
Responding to Red Flags: Practical Guidance
Identifying a red flag is only the first step. What a company does in response — and what it can demonstrate it did — is at least as important as the initial identification. The DOJ and SEC’s Joint Resource Guide to the FCPA makes clear that a company’s good-faith response to red flags, including voluntary self-disclosure of potential violations, full cooperation with investigators, and the implementation of meaningful remedial measures, can substantially affect both the decision to prosecute and the ultimate penalties imposed.
At the operational level, a company that encounters a red flag should in most cases pause the relevant transaction or relationship pending investigation, document the steps taken to identify and evaluate the concern, involve legal counsel at an early stage, and escalate appropriately within the organisation’s governance structure. The compliance function should be empowered to make genuine recommendations — including the recommendation to decline a business opportunity — and those recommendations should receive serious consideration from senior management and the board.
Companies should also ensure that their compliance programs are designed with red-flag detection in mind: this means robust third-party due diligence procedures, periodic audits of high-risk markets and relationships, meaningful training for employees who interact with foreign officials or manage relationships with government-facing agents, and clear and confidential mechanisms for reporting concerns. The existence of these procedures, and evidence that they are followed in practice rather than merely in theory, is central to the “adequate procedures” analysis that regulators apply when assessing corporate culpability.
Conclusion
The FCPA red flags described in this article are not an exhaustive catalogue — the circumstances in which improper payments may be solicited or made are as varied as the commercial relationships companies enter into across the globe. What is consistent is the framework of analysis: the question is always whether a reasonable person in possession of the relevant facts would conclude that something requires investigation, and whether the company’s response to that conclusion was adequate.
For business clients, the practical takeaway is this: the cost of getting FCPA compliance right is a fraction of the cost of getting it wrong. A major FCPA enforcement action carries not only substantial direct financial penalties but also the reputational, operational, and governance disruptions associated with a monitorship, a deferred prosecution agreement, or a criminal conviction. The companies that navigate international business most successfully are those that treat anti-corruption compliance not as a box-ticking exercise but as a genuine element of their commercial strategy — one that protects long-term enterprise value and ensures that the business relationships they build are founded on legitimate competitive merit.
If your company is expanding into new international markets, conducting due diligence on a cross-border acquisition, reviewing an existing third-party compliance framework, or responding to a potential FCPA issue, we would welcome the opportunity to discuss how we can assist. The time to address FCPA compliance concerns is before they become enforcement matters.
This article is intended for general informational purposes only and does not constitute legal advice. Readers should consult qualified legal counsel regarding their specific circumstances.
