The exposure is rarely the bribe. It is the third party who paid it.
Investigations and prosecutions under the Foreign Corrupt Practices Act have continued to rise, and the organizations caught by them are seldom the ones that set out to pay anybody. They are the ones that could not say, when asked, exactly who was acting on their behalf in a difficult market and what that person was being paid for.
What the Act actually reaches
The FCPA prohibits offering or giving anything of value to a foreign government official to influence a decision, secure business, or obtain an improper advantage. Two features make it wider than most people expect. It reaches conduct by agents and intermediaries acting for you, whether or not anyone at head office authorized it. And its accounting provisions — requiring books that accurately reflect transactions, and adequate internal controls — are enforced independently, which in practice makes them the easier case to bring.
Our work is the investigative half of managing that: establishing who your intermediaries are, what stands behind them, and whether your program does anything when it is tested.

Questions clients bring us
What the work covers
Almost no organization sets out to bribe a foreign official. The exposure that produces enforcement action is nearly always indirect: an agent who secures a permit unusually fast, a distributor whose margin is unexplained, a consultant retained shortly before an award, a joint-venture partner whose ownership includes someone’s relative. The Act reaches conduct by third parties acting on your behalf, whether or not anyone at head office knew.
We work on the parts of that problem that are established by investigation rather than by policy: who your intermediaries actually are, what they were paid and for what, whether the ownership behind them includes a government official or their family, and whether the books reflect the transaction accurately. The accounting provisions of the FCPA are enforced independently of the anti-bribery provisions, and in practice they are the easier charge to prove.
We also test whether an existing program works in the field. A compliance program is not evidenced by its manual. It is evidenced by what a regional sales manager under quota pressure actually does when a local partner asks for an unusual payment, and whether anyone would hear about it if they agreed.
What we are not. We are not your counsel and we do not give legal opinions on the Act. Where a matter looks like it may require disclosure, the right next call is to your lawyers, and we work alongside them — often through litigation support — rather than in place of them.
How the engagement runs
Four stages, scoped to the markets and relationships that actually carry risk.
Enforcement outcomes turn heavily on what an organization did before it was contacted. A documented, risk-ranked review of intermediaries is worth more at that moment than a longer policy manual.
1. Mapping the third parties
We build the actual list of agents, distributors, consultants, customs brokers, freight forwarders and joint-venture partners acting for you in higher-risk markets. This list is almost always longer than the one procurement holds, because relationships get added locally and never travel back to head office.
2. Testing the ones that matter
Risk is not evenly spread, so neither is the work. We take the relationships where the combination of jurisdiction, government touchpoint and payment pattern is most exposed, and establish beneficial ownership, political connections, and whether the commercial rationale holds. This is due diligence applied to a specific statutory risk.
3. Assessing the program as it operates
We test the program against practice: whether training reaches the people who face the decision, whether the reporting channel is trusted enough to be used, whether gifts and hospitality approvals are real controls or a formality, and whether anyone has ever been told no.
4. Remediation, documented
Findings become a prioritized list with owners and dates, and the work of closing them is recorded. That record is the asset. It is what turns “we take compliance seriously” into something you can hand to a regulator.
When to commission one
Investigations and prosecutions under the Act have continued to rise, and the pattern of when organizations wish they had looked earlier is consistent:
- Before entering a market where government contact is unavoidable — licensing, customs, utilities, public procurement.
- Before an acquisition. Successor liability is real: you can inherit the conduct of a target that predates your ownership, which is why this sits close to mergers and acquisitions support.
- When an intermediary relationship has grown materially without anyone re-examining it.
- On a whistleblower report, an internal audit finding, or an unexplained payment — where the priority is establishing scope quickly and preserving evidence properly.
- When a counterparty, lender or insurer asks for evidence of your program and you do not have a current answer.
What you get
A written report your counsel and your board can both use:
- The full third-party population, risk-ranked, with the basis for each ranking.
- Findings on the relationships examined — ownership, political exposure, payment rationale.
- An assessment of the compliance program as it operates, not as written.
- A remediation plan with owners and dates.
- A clear separation of what is established, what is indicative, and what could not be resolved.
Straight answers
What is our FCPA exposure?
It is largely a function of three things: how many intermediaries act for you, how often your business requires a government decision, and how well you can evidence what those intermediaries were paid for. Most organizations can answer the first two and not the third.
Does the Act apply to us if we are not a US company?
Frequently, yes. Its reach extends beyond US issuers, and other regimes — notably the UK Bribery Act — impose comparable or broader obligations. The practical answer is that if you are asking, the mapping exercise is worth doing regardless of which statute ultimately bites. Which one applies is a question for your lawyers.
Do our programs prove effective in the field?
That is testable and rarely tested. The gap between a program that exists and one that operates is where enforcement risk lives.
How do we document and report non-compliance?
Carefully, early, and with counsel involved from the start — because how a finding is recorded affects privilege and what disclosure obligations attach. Get the lawyers in before the internal email chain has been written.
Will an investigation make things worse if we find something?
This is the real question behind most hesitation. Finding a problem yourself, scoping it properly and remediating it is a materially better position than having it found for you. What is unhelpful is a half-scoped internal look that surfaces enough to establish knowledge and not enough to define the extent.
Falcone International
Get in touch about Foreign Corrupt Practices Act consulting
Tell us which markets you operate in and who acts for you there. We will tell you where the exposure concentrates and what can be established — without obligation, and in confidence.
Further reading
Selected from our Book of the Month series for their bearing on this service.
Lying, Cheating, and StealingGreen works through what bribery and related offenses actually consist of, morally and legally, and where the criminal line falls. For FCPA work that precision matters, because the hard cases are the ones where the conduct is locally ordinary and the line is still crossed.
International Handbook of White-Collar and Corporate CrimePontell and Geis assembled the research on how these offenses are defined, detected and punished across different jurisdictions. It is the reference to reach for when a compliance program has to work in more than one legal system at once.
Billion Dollar Whale1MDB is cross-border corruption at full scale, followed through to the enforcement outcome and the institutions that paid for it. It is a useful reminder that FCPA exposure usually arrives through intermediaries rather than through your own staff.
