Why Multinational Companies Still Struggle With FCPA Compliance

FCPA Compliance
Share Post :

The policy is approved. Training is complete. Third parties signed the required certifications.

Then a local consultant requests payment through another country. The invoice says “business development,” while supporting documents offer little detail.

Sales wants the payment released. Finance sees an approved contract. Compliance discovers the issue only after an internal report.

This is the modern FCPA Compliance problem.

Multinational companies often have extensive policies. However, bribery risks develop inside ordinary business activity, where information remains divided across teams.

The weakness is rarely one missing control. More often, several acceptable decisions combine into one unacceptable transaction.

The 60-Second FCPA Stress Test

Could senior leaders answer these questions without requesting a month-long review?

  • Which intermediaries currently interact with government officials or employees of state-owned enterprises?
  • Which distributors receive the largest discounts, commissions, reimbursements, or marketing funds?
  • Which countries generate the most compliance overrides, incomplete records, or late approvals?
  • Which acquired businesses still operate outside central third-party and payment controls?
  • Which employees can approve both a commercial relationship and its related payments?

Unclear answers signal limited visibility. A multinational business cannot manage corruption risks it cannot locate quickly.

One Global Standard, Many Local Interpretations

Headquarters may prohibit improper payments clearly. Yet daily decisions occur through subsidiaries, joint ventures, distributors, and agents.

Each market brings different customs, languages, government structures, and commercial pressures. Consequently, one policy can produce many interpretations.

Local teams may view certain payments as routine. Meanwhile, headquarters may not understand the recipient’s government position.

Regional employees may also recognise political relationships that screening tools miss. However, those employees need safe and direct escalation routes.

Effective FCPA Compliance combines global standards with local intelligence. Removing either element creates a dangerous blind spot.

Where Multinational FCPA Compliance Breaks

Business activityWhat appears acceptableWhat may signal corruption risk
Third-party appointmentA consultant has useful local connectionsOwnership, qualifications, or government relationships remain unclear
Distributor discountA larger discount supports an important saleExcess margin may fund an undisclosed payment
Advisory invoiceA contract supports consulting servicesEvidence does not confirm that meaningful work occurred
Business hospitalityThe expense follows local customsTiming connects the benefit with a government decision
Charitable donationThe recipient supports a worthy community projectAn official connected with pending business selected the charity
AcquisitionThe target signed anti-bribery certificationsHistoric transactions and intermediaries received limited testing

These warning signs require context. However, they should never disappear inside fragmented review processes.

The Third-Party Trap

Agents and distributors help multinational companies enter markets, find customers, and manage local requirements.

However, they also create distance between the company and government-facing activity.

Initial due diligence may confirm ownership, experience, reputation, and qualifications. Yet risk can change immediately after approval.

A partner may appoint an undisclosed subcontractor. Bank details may change, while invoices become less specific.

Therefore, oversight must continue throughout the relationship.

A credible third-party file should explain:

  • Why the relationship is commercially necessary and why internal employees cannot perform the required services.
  • How compensation reflects market conditions, documented responsibilities, and verifiable evidence of completed work.
  • Whether owners, subcontractors, bank accounts, political exposure, or government interactions changed after initial approval.
  • How monitoring results, compliance concerns, and unusual transaction patterns affected the decision to continue the relationship.

Certification alone provides limited assurance. Evidence should support both the relationship and every material payment.

The Discount Nobody Followed

Discounts are common commercial tools. Nevertheless, unusually large discounts can create funds outside the company’s direct visibility.

A distributor may retain the additional margin. The company may then lose sight of how that money supports the final sale.

This risk becomes greater when government customers are involved.

Approvers should understand the final customer, expected resale price, distributor role, and business reason for the discount.

Furthermore, monitoring should compare approved terms with actual outcomes. Repeated exceptions may reveal a wider control problem.

When Sales Pressure Rewrites the Rules

A policy says high-risk intermediaries require enhanced review. Yet an important tender closes tomorrow.

Another rule requires detailed invoices. However, a regional team needs the payment processed before quarter-end.

Commercial pressure does not automatically create bribery. Still, it can make weak decisions appear reasonable.

Incentives matter because employees notice what leadership rewards.

If promotions depend only on revenue, compliance messages lose credibility. Similarly, exceptional performers may expect exceptions from established controls.

Senior leaders should review how results were achieved. Revenue quality deserves the same attention as revenue value.

Case Studies: When the Gaps Connected

Major enforcement matters often involve familiar warning signs. Their importance lies in how those signs survived several control stages.

Case Study 1: SAP’s Third-Party and Discount Risks

During January 2024, SAP agreed to pay more than $220 million to resolve DOJ and SEC investigations.

The conduct involved South Africa, Malawi, Kenya, Tanzania, Ghana, Indonesia, and Azerbaijan.

Authorities described schemes involving intermediaries, consultants, expenses, and improper payments connected with government business.

The case also included concerns involving discounts, inaccurate records, and internal accounting controls.

SAP received credit for cooperation and remediation. Its actions included control restructuring, stronger monitoring, and ending relevant third-party relationships.

The practical lesson is simple. Commercial approvals and compliance approvals cannot remain separate.

Discounts, third-party compensation, final customers, and payment evidence should tell one consistent story.

The DOJ’s SAP resolution confirms the conduct, financial resolution, cooperation, and remediation.

Case Study 2: Ericsson’s Post-Resolution Failure

Ericsson entered a deferred prosecution agreement during 2019 after resolving a significant FCPA case.

The underlying conduct involved third-party agents, consultants, improper payments, and off-the-books funds across several countries.

However, problems continued after the agreement.

Authorities later determined that Ericsson breached its disclosure and cooperation obligations. During 2023, the company pleaded guilty and accepted another penalty exceeding $206 million.

This case changed the central question.

FCPA Compliance is not only about preventing the original conduct. It also requires reliable investigations, records, disclosures, remediation, and continuing cooperation.

The DOJ’s Ericsson case record explains the original resolution and later breach.

The Acquisition Blind Spot

Acquisitions can introduce hidden intermediaries, informal approvals, government contracts, and poorly documented payments.

Pre-acquisition reviews may uncover visible problems. However, access limitations and deal deadlines can restrict detailed testing.

After closing, integration teams often focus on systems, customers, and financial targets. Compliance improvements may receive longer deadlines.

That delay creates exposure.

Post-acquisition priorities should include:

  1. Reviewing government contracts, permits, licences, customs activity, donations, sponsorships, commissions, and unusual expenses.
  2. Identifying third parties with government contact, unclear ownership, high compensation, offshore payments, or limited service evidence.
  3. Connecting the acquired business with reporting channels, approval controls, training, monitoring, and investigation procedures.
  4. Assigning deadlines and responsible owners for every identified weakness, particularly those affecting ongoing transactions.

Temporary controls should have clear expiry dates. Otherwise, “temporary” can become the permanent operating model.

Why Technology Still Misses the Story

Screening platforms can identify sanctions, political exposure, adverse information, and ownership concerns.

Analytics can also detect unusual payments, duplicate invoices, rounded amounts, split transactions, and unexpected bank locations.

However, technology only sees recorded information.

A system cannot identify an undisclosed owner. It also cannot confirm services described through intentionally vague documentation.

Poorly calibrated systems may produce excessive alerts. Reviewers can then spend more time clearing noise than investigating meaningful risks.

Therefore, technology should connect information rather than simply generate warnings.

Compliance, sales, finance, procurement, legal, and internal audit need access to relevant pieces of the same transaction.

Changing Enforcement Priorities Do Not Cancel Risk

The DOJ issued revised FCPA investigation and enforcement guidelines during June 2025.

Those guidelines describe factors prosecutors should consider when deciding whether to pursue a matter.

However, the FCPA remains law. Additionally, SEC authority and anti-corruption laws in other jurisdictions remain relevant.

Companies may also face contractual disputes, debarment, investor concerns, reputational damage, and expensive internal investigations.

The DOJ and SEC FCPA Resource Guide explains the anti-bribery, books and records, and internal control provisions.

A reactive program follows enforcement headlines. A stronger program follows the organization’s actual exposure.

Six Modern Moves for Stronger FCPA Compliance

1. Follow the Money, Not the Department

Review the entire transaction from third-party selection through final payment. Separate departmental approvals may conceal the combined risk.

Connect contracts, discounts, invoices, expenses, bank details, government interactions, and final customer information.

2. Replace Document Collection With Evidence Testing

A complete file does not prove a legitimate relationship.

Test whether the third party performed the stated work. Compare invoices with deliverables, communications, meetings, and measurable outcomes.

3. Monitor Business Pressure as a Risk Indicator

Identify deals involving major targets, government decisions, urgent deadlines, or repeated exceptions.

These transactions deserve closer review because urgency can weaken judgment and bypass normal challenge.

4. Give Local Knowledge a Direct Route Upward

Regional employees often know which partners have political connections or questionable reputations.

Provide confidential reporting and escalation routes. Then respond without allowing commercial leaders to suppress uncomfortable information.

5. Treat Acquisitions as New Risk Assessments

Do not assume acquired controls work because policies exist.

Test transactions, intermediaries, payment routes, government exposure, and unresolved allegations. Track integration through measurable deadlines.

6. Make Investigations Improve the Business

After substantiating misconduct, identify the control, incentive, supervision, or data failure that allowed it.

Then search for similar conditions elsewhere. One problematic relationship may reveal a wider multinational weakness.

Key Takeaways and Next Steps

Multinational companies still struggle with FCPA Compliance because risks travel across departments, countries, and third parties.

Policies may remain central, while decisions remain local. Technology may process data, while important relationships remain undisclosed.

Start with the highest-risk government touchpoints. Then connect every related third party, discount, invoice, approval, and payment.

Next, examine transactions completed under unusual pressure. Review quarter-end deals, public tenders, licence renewals, acquisitions, and urgent market-entry activity.

Finally, assign control improvements to named owners. Set deadlines and verify completion through evidence and transaction testing.

The strongest FCPA Compliance program does not create more paperwork. It makes questionable business easier to identify, challenge, and stop.

Recent Posts

Our goal is to help people in the best way possible. this is a basic principle in every case and cause for success. contact us today for a free consultation.