Introduction
The Foreign Corrupt Practices Act of 1977 (FCPA) remains at the forefront of corporate compliance and white-collar criminal enforcement. The DOJ and SEC devote substantial resources to identifying and prosecuting violations. Fines routinely reach into the hundreds of millions of dollars, and individuals face significant federal prison sentences. For corporate executives, directors, compliance officers, and legal counsel, understanding how the FCPA is enforced, what penalties attach to violations, and who bears personal criminal exposure is an operational imperative.
The Two Pillars of the FCPA: Anti-Bribery and Accounting Provisions
The anti-bribery provisions (15 U.S.C. §§ 78dd-1, 78dd-2, and 78dd-3) prohibit “issuers,” “domestic concerns,” and certain foreign persons from corruptly offering, paying, promising to pay, or authorizing the payment of anything of value to a foreign government official for the purpose of obtaining or retaining business or securing any improper advantage. The accounting provisions (15 U.S.C. §§ 78m(b)(2) and 78m(b)(5)), applicable exclusively to issuers, require maintaining books and records that accurately and fairly reflect transactions and devising and maintaining a system of internal accounting controls sufficient to provide reasonable assurances. DOJ and SEC frequently charge both sets of violations in the same matter.
The Enforcement Architecture: DOJ and the SEC
The DOJ holds exclusive jurisdiction over criminal enforcement of the anti-bribery provisions for both issuers and domestic concerns, as well as criminal enforcement of the accounting provisions against individuals. The SEC has civil enforcement authority over issuers with respect to both sets of provisions. In practice, DOJ and SEC have developed a closely coordinated enforcement model, often conducting parallel investigations that culminate in simultaneous resolutions on the same day.
DOJ’s FCPA enforcement is concentrated within the Fraud Section of the Criminal Division’s dedicated FCPA Unit, working alongside FBI agents assigned to international corruption matters. The SEC’s FCPA enforcement is led by the FCPA Unit within the Division of Enforcement. Both agencies make extensive use of mutual legal assistance treaties (MLATs) and coordination with foreign counterparts in the UK, Brazil, Switzerland, Germany, and the Netherlands.
Criminal Liability Under the FCPA
Corporate Criminal Liability
A corporation may be held criminally responsible for acts of its employees, agents, and subsidiaries when those acts were performed within the scope of their authority and at least in part intended to benefit the corporation. The scope of corporate liability extends to conduct by third-party agents, consultants, distributors, and joint-venture partners. The FCPA explicitly prohibits authorizing payments by another person or entity, and DOJ and SEC have consistently held companies responsible for bribery carried out through intermediaries.
Individual Criminal Liability
Any individual who is a U.S. citizen or national, a resident of the United States, or a director, officer, employee, or agent of a domestic concern or issuer is subject to criminal prosecution under the anti-bribery provisions. Foreign nationals who take any act in furtherance of an FCPA violation while physically present in the United States are also subject to prosecution. DOJ’s FCPA enforcement policy—reinforced through successive memoranda including the 2015 “Yates Memorandum”—makes prosecution of responsible individuals a priority.
The “corrupt” intent requirement must be proved beyond a reasonable doubt. The government need not show awareness of the specific legal prohibition; the requirement is that the defendant acted knowingly and willfully with the purpose of influencing an official act or decision.
Penalties: Criminal and Civil
Criminal Penalties for Corporations
Corporations face criminal fines of up to $2 million per violation under the statute, but the Alternative Fines Act (18 U.S.C. § 3571(d)) permits fines of up to twice the gross gain or twice the gross loss, whichever is greater. The Federal Sentencing Guidelines provide the primary framework for calculating corporate criminal fines, with adjustments based on a culpability score that accounts for organizational size, senior management involvement, prior criminal history, and the existence of an effective compliance program. Significant reductions are available for self-reporting, cooperation, and acceptance of responsibility.
The largest FCPA corporate penalties illustrate the financial exposure: Goldman Sachs ($2.9 billion, 2020, 1MDB scandal); Airbus (approximately $4 billion, 2020); Ericsson (approximately $1 billion, 2019, plus $206 million in 2022 for breaching its DPA); Walmart ($282 million, 2019).
Criminal Penalties for Individuals
Individual defendants convicted of criminal violations of the anti-bribery provisions face imprisonment of up to five years per violation. Those convicted of criminal violations of the accounting provisions face imprisonment of up to twenty years per violation under Section 32(a) of the Securities Exchange Act. Additional charges under wire fraud, money-laundering, and other federal statutes often produce cumulative exposure of decades in federal prison. Criminal fines for individuals reach up to $100,000 per violation under the FCPA, with higher fines available under the Alternative Fines Act.
Civil Penalties
The SEC may impose civil penalties on issuers and their officers, directors, employees, and agents for violations of the anti-bribery and accounting provisions. Civil penalties for anti-bribery violations may reach $16,000 per violation (subject to inflation adjustments). For accounting provisions violations, civil penalties reach up to $100,000 per violation for natural persons and up to $500,000 per violation for entities. The SEC may also seek disgorgement of profits derived from violations plus prejudgment interest, subject to the limitations established by Liu v. SEC (2020).
Resolution Mechanisms: DPAs, NPAs, and Plea Agreements
The vast majority of corporate FCPA resolutions are negotiated settlements through deferred prosecution agreements (DPAs), non-prosecution agreements (NPAs), or guilty pleas. A DPA requires the company to pay a monetary penalty, cooperate with ongoing investigations, implement or enhance its compliance program, and submit to an independent compliance monitor; if the company satisfies its obligations during the deferral period, charges are dismissed. An NPA, typically reserved for companies that self-reported promptly and cooperated extensively, requires similar commitments without any charges being filed. A guilty plea is reserved for the most serious cases and carries collateral consequences including mandatory debarment from certain federal programs and potential loss of banking licenses.
Self-Disclosure, Cooperation, and the FCPA Corporate Enforcement Policy
DOJ’s FCPA Corporate Enforcement Policy creates a formal framework of incentives to encourage self-disclosure, cooperation, and remediation. It establishes a presumption that DOJ will decline to prosecute a company that (1) voluntarily self-discloses the violation, (2) fully cooperates with DOJ’s investigation, (3) timely remediates the violation, and (4) disgorges all ill-gotten gains. Where a declination is precluded by aggravating circumstances, the policy provides for penalty reductions of up to 50 percent below the low end of the Sentencing Guidelines range for companies that self-disclose, cooperate, and remediate; up to 25 percent for companies that cooperate and remediate but did not self-disclose.
The decision whether to self-disclose a potential violation is one of the most consequential judgments a company and its counsel will face. Self-disclosure necessarily triggers an official investigation and may stimulate parallel investigations by foreign authorities. The policy’s benefits are conditioned on disclosure that precedes imminent public disclosure or media reporting. Experienced counsel should be engaged immediately upon discovery of potential violations.
The Role of Compliance Programs and the Prospect of Declinations
A robust and genuinely effective compliance program is the foundation of a company’s defense against prosecution. DOJ’s Evaluation of Corporate Compliance Programs guidance (most recently updated in 2023) sets out a detailed framework assessing whether a program is “well-designed,” “adequately resourced and empowered to function effectively,” and “works in practice.” Evaluation dimensions include leadership commitment to ethics; risk-based resource allocation; rigor of third-party due diligence; effectiveness of training and communication; robustness of reporting mechanisms and internal investigation procedures; and the company’s track record of disciplining misconduct. A program that exists primarily on paper will receive little credit in enforcement proceedings.
Conclusion
The FCPA enforcement landscape is demanding and will remain so. Nine-figure corporate fines, debarment, monitorship, and individual prison sentences are sufficient to threaten even large enterprises. At the same time, the government’s framework of incentives creates a meaningful path for companies that discover violations to manage their exposure through proactive disclosure, full cooperation, and genuine remediation. Investment in effective compliance programs—adequately resourced, genuinely risk-based, and backed by real management commitment—is the most reliable insurance against prosecution.
This article is intended for general informational and educational purposes only. It does not constitute legal advice and does not create an attorney-client relationship. Businesses with concerns about potential FCPA exposure or compliance program adequacy are encouraged to consult with experienced counsel.
