Skip to content

Evidence request lists

US Foreign Corrupt Practices Act (FCPA)

Evidence request list. 34 controls, 34 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 12 September 2026. Published by The Art of Service.

Accounting

USFCPA-2
Accounting Provisions (Books and Records, Internal Controls)

Per FCPA 15 USC 78m: accounting provisions requiring books + records that accurately reflect transactions + reasonable system of internal accounting controls.

Artefacts an auditor will ask for
  • FCPA evidence for USFCPA-2
Where this commonly fails
  • compliance programme + DD partial

Accounting Provisions

15 U.S.C. § 78m(b)(2)(A)
Books and Records Requirements

Issuers must make and keep books, records, and accounts that accurately reflect transactions and assets.

Artefacts an auditor will ask for
  • Internal accounting controls documentation and testing evidence
  • Third-party due diligence files and risk ratings
  • Gifts, hospitality and travel pre-approval logs
  • FCPA training records by role and geography
Where this commonly fails
  • Third-party due diligence not refreshed on risk-based cadence
  • Inadequate transaction monitoring for ABC red flags
  • Books and records adjustments not subject to independent review
  • Facilitating payments policy unclear in high-risk jurisdictions
15 U.S.C. § 78m(b)(2)(B)
Internal Accounting Controls

Issuers must devise and maintain a system of internal accounting controls sufficient to provide reasonable assurances.

Artefacts an auditor will ask for
  • FCPA training records by role and geography
  • Anti-bribery and anti-corruption (ABAC) policy
  • Internal accounting controls documentation and testing evidence
  • Whistleblower hotline intake and investigation records
Where this commonly fails
  • Books and records adjustments not subject to independent review
  • Facilitating payments policy unclear in high-risk jurisdictions
  • Inadequate transaction monitoring for ABC red flags
  • M&A successor liability diligence shallow
15 U.S.C. § 78m(b)(6)
Subsidiary Accountability

Issuers must use good faith efforts to ensure subsidiaries maintain proper books, records, and controls.

Artefacts an auditor will ask for
  • Internal accounting controls documentation and testing evidence
  • FCPA training records by role and geography
  • Anti-bribery and anti-corruption (ABAC) policy
  • Gifts, hospitality and travel pre-approval logs
Where this commonly fails
  • M&A successor liability diligence shallow
  • Inadequate transaction monitoring for ABC red flags
  • Facilitating payments policy unclear in high-risk jurisdictions
  • Books and records adjustments not subject to independent review

Anti-Bribery

USFCPA-1
Anti-Bribery Provisions and Foreign Officials

Per US FCPA 15 USC 78dd-1: anti-bribery prohibition on corruptly making payments to foreign officials + parties + intermediaries to obtain or retain business + understand prohibited conduct.

Artefacts an auditor will ask for
  • FCPA evidence for USFCPA-1
Where this commonly fails
  • compliance programme + DD partial

Anti-Bribery Provisions

15 U.S.C. § 78dd-2(a)
Prohibition on Bribery by Domestic Concerns

US domestic concerns may not offer or pay anything of value to foreign officials to influence official acts.

Artefacts an auditor will ask for
  • Anti-bribery and anti-corruption (ABAC) policy
  • FCPA training records by role and geography
  • Third-party due diligence files and risk ratings
  • Gifts, hospitality and travel pre-approval logs
Where this commonly fails
  • Books and records adjustments not subject to independent review
  • Inadequate transaction monitoring for ABC red flags
  • Third-party due diligence not refreshed on risk-based cadence
  • Facilitating payments policy unclear in high-risk jurisdictions
15 U.S.C. § 78dd-2(h)
Definition of Domestic Concern

Domestic concern includes any US citizen, national, resident, or any business entity organized under US law.

Artefacts an auditor will ask for
  • FCPA training records by role and geography
  • Internal accounting controls documentation and testing evidence
  • Gifts, hospitality and travel pre-approval logs
  • Whistleblower hotline intake and investigation records
Where this commonly fails
  • Books and records adjustments not subject to independent review
  • Third-party due diligence not refreshed on risk-based cadence
  • Inadequate transaction monitoring for ABC red flags
  • Facilitating payments policy unclear in high-risk jurisdictions
15 U.S.C. § 78dd-3(a)
Prohibition on Bribery by Other Persons

Any person who acts within US territory to corruptly further a payment to a foreign official is liable.

Artefacts an auditor will ask for
  • Anti-bribery and anti-corruption (ABAC) policy
  • Internal accounting controls documentation and testing evidence
  • Third-party due diligence files and risk ratings
  • FCPA training records by role and geography
Where this commonly fails
  • Third-party due diligence not refreshed on risk-based cadence
  • Facilitating payments policy unclear in high-risk jurisdictions
  • Books and records adjustments not subject to independent review
  • M&A successor liability diligence shallow
FCPA-01
Anti-Bribery Prohibition on Payments to Foreign Officials

Issuers, domestic concerns, and persons acting on their behalf must not corruptly offer, promise, or pay anything of value to a foreign official, foreign political party, party official, or candidate, for the purpose of influencing an official act, securing an improper advantage, or obtaining or retaining business. Liability attaches to direct payments and to payments made through intermediaries when the payer knows or has reason to know.

Artefacts an auditor will ask for
  • Global anti-bribery policy signed by CEO and updated annually
  • Training records by role and country
  • Risk assessment identifying high-risk jurisdictions and counterparties
  • Disciplinary action records for policy violations
Where this commonly fails
  • Policy not translated for local offices
  • Training not refreshed annually
  • No risk-based training intensity
  • Disciplinary action inconsistent across regions
FCPA-05
Anti-Bribery Contractual Protections

Contracts with third parties operating outside the United States or in higher-risk environments must include FCPA representations, warranties, audit rights, termination rights for non-compliance, training obligations, and periodic certifications, with these clauses tracked in a contract management system.

Artefacts an auditor will ask for
  • Approved FCPA contract clauses library
  • Contract management system reports showing clause coverage
  • Annual third-party certifications
  • Audit rights exercised on selected counterparties
Where this commonly fails
  • Local contracts omit FCPA clauses
  • Audit rights never exercised
  • Certifications collected but not reviewed
  • Termination right not enforced after red flag
FCPA-06
Facilitating Payments Position

FCPA includes a narrow exception for routine governmental action facilitating payments, but enforcement risk and parallel laws such as the UK Bribery Act make zero-tolerance preferable. Companies should adopt and document an explicit position on facilitating payments and apply it consistently across the enterprise.

Artefacts an auditor will ask for
  • Documented facilitating payments policy (typically zero tolerance)
  • Country-specific guidance
  • Pre-clearance process for any exception
  • Annual policy refresh evidence
Where this commonly fails
  • No explicit policy
  • Local practices vary by country
  • Pre-clearance process informal
  • Annual review not performed
FCPA-07
Gifts, Travel, and Entertainment Controls

Gifts, travel, and entertainment provided to foreign officials must be reasonable, bona fide, directly related to promotion or contract performance, and permitted under local law. Pre-approval, monetary thresholds, and accurate expense coding are required to demonstrate compliance.

Artefacts an auditor will ask for
  • GTE policy with country-specific monetary thresholds
  • Pre-approval workflow records
  • Expense reports with detailed descriptions
  • Periodic GTE audit reports
Where this commonly fails
  • No country-specific thresholds
  • Pre-approval bypassed for senior travellers
  • Expense descriptions vague
  • GTE audits not performed
FCPA-08
Charitable Contributions and Sponsorships Due Diligence

Charitable contributions and sponsorships in foreign jurisdictions must be reviewed to confirm they are not a conduit for improper payments to officials. Diligence on recipient organisations, their leadership, beneficial owners, and any connection to officials is required, along with documented business rationale.

Artefacts an auditor will ask for
  • Donation request forms with business rationale
  • Recipient organisation diligence files
  • Approval committee minutes
  • Post-payment monitoring including fund use confirmation
Where this commonly fails
  • Donations approved by single executive
  • No recipient diligence
  • Fund use never confirmed
  • Donations clustered before bid awards
FCPA-16
Political Contributions Controls

Corporate political contributions in foreign jurisdictions must comply with local law and must not be used to influence foreign officials. Pre-approval, recipient diligence, and disclosure consistent with local rules are required.

Artefacts an auditor will ask for
  • Political contributions policy
  • Pre-approval records
  • Recipient diligence files
  • Disclosure submissions where required
Where this commonly fails
  • Policy silent on foreign contributions
  • Contributions made without pre-approval
  • Recipient diligence absent
  • Disclosure not made where required

Books, Records and Internal Accounting Controls

FCPA-02
Books and Records Accuracy

Issuers must make and keep books, records, and accounts that, in reasonable detail, accurately and fairly reflect the transactions and dispositions of the assets of the issuer. Records must not be falsified to disguise improper payments, regardless of materiality.

Artefacts an auditor will ask for
  • Chart of accounts with descriptive line items
  • Journal entry review and approval workflows
  • Quarterly self-certifications by finance leadership
  • Records retention schedules
Where this commonly fails
  • Vague accounts such as miscellaneous or sundry used to record large amounts
  • Manual journal entries without secondary review
  • Self-certifications signed without supporting work
  • Records retention shorter than statute of limitations
FCPA-03
Internal Accounting Controls

Issuers must devise and maintain a system of internal accounting controls sufficient to provide reasonable assurances that transactions are executed and recorded properly, access to assets is permitted only with management authorisation, and recorded accountability for assets is compared with existing assets at reasonable intervals.

Artefacts an auditor will ask for
  • ICFR control matrix per process
  • Authorisation matrices
  • Periodic asset reconciliations
  • Internal audit reports testing FCPA-relevant controls
Where this commonly fails
  • Authorisation matrices outdated
  • Reconciliations performed but not reviewed
  • Internal audit does not test FCPA controls
  • Control failures not remediated
FCPA-17
Books and Records for Non-Issuer Domestic Concerns

While the books and records and internal controls provisions apply primarily to issuers, domestic concerns and persons within the United States remain subject to anti-bribery provisions and should maintain records sufficient to defend against allegations and to support voluntary cooperation.

Artefacts an auditor will ask for
  • Voluntary record retention policy covering FCPA-relevant transactions
  • Vendor master data quality controls
  • Payment justification files
  • Audit trail evidence
Where this commonly fails
  • No FCPA-specific retention rules for non-issuers
  • Vendor master data unverified
  • Payment justifications absent
  • Audit trails incomplete

Compliance Programme

USFCPA-4
Compliance Programme and Due Diligence

Per FCPA Resource Guide + DOJ Evaluation of Corporate Compliance Programs: compliance programme + risk-based DD on third parties + agents + JV partners + M&A + training.

Artefacts an auditor will ask for
  • FCPA evidence for USFCPA-4
Where this commonly fails
  • compliance programme + DD partial

Compliance Programme Design and Testing

FCPA-10
Compliance Programme Resourcing and Authority

The chief compliance officer must have sufficient seniority, authority, autonomy, and resources to operate the FCPA compliance programme effectively, with direct reporting to the board or audit committee in addition to executive management.

Artefacts an auditor will ask for
  • Compliance organisation chart with reporting lines
  • Compliance budget over multi-year period
  • Headcount data including geographic coverage
  • Board and audit committee meeting minutes including compliance reports
Where this commonly fails
  • CCO reports through general counsel without dotted line to board
  • Compliance budget cuts year over year
  • Headcount concentrated in headquarters only
  • Board reports infrequent
FCPA-11
Whistleblower and Reporting Channels

Multiple confidential reporting channels including hotline, email, and web intake must be available globally, in local languages, with anti-retaliation protections, anonymous reporting where legally permitted, and a tracked investigation workflow.

Artefacts an auditor will ask for
  • Hotline provider contract
  • Multi-language reporting portal
  • Anti-retaliation policy with disciplinary teeth
  • Investigation case management records with disposition
Where this commonly fails
  • Hotline only in English
  • Anonymous reporting blocked in jurisdictions where allowed
  • Anti-retaliation cases never investigated
  • Investigation case management ad hoc
FCPA-12
Investigations Quality and Documentation

Allegations of bribery or accounting violations must be investigated by appropriately resourced and independent investigators, with documented scope, evidence handling, interview memoranda, conclusions, and remediation. Counsel involvement may preserve attorney-client privilege.

Artefacts an auditor will ask for
  • Investigation protocol
  • Sample investigation files with scope memos, evidence registers, and conclusions
  • Privilege management procedures
  • Outcomes tracker linking findings to remediation
Where this commonly fails
  • Investigations performed by managers of accused employees
  • Evidence not preserved
  • No privilege strategy
  • Remediation not tracked
FCPA-18
Continuous Programme Improvement and Testing

The compliance programme must be tested, measured, and improved over time, using metrics such as training completion, hotline activity, investigation outcomes, third-party risk coverage, and internal audit findings. Lessons learned from internal and external enforcement events must drive enhancements.

Artefacts an auditor will ask for
  • Compliance programme metrics dashboard
  • Annual programme effectiveness review
  • External benchmark comparisons
  • Remediation plans with executive sponsors
Where this commonly fails
  • Metrics report on activity not outcomes
  • No annual effectiveness review
  • Benchmarks against peers absent
  • Remediation plans without executive sponsorship

Defenses

USFCPA-3
Affirmative Defenses (Facilitating Payments, Local Law, Reasonable Expenditure)

Per FCPA: Facilitating Payments Exception + Affirmative Defenses including Local Law + Reasonable Expenditure including travel and lodging.

Artefacts an auditor will ask for
  • FCPA evidence for USFCPA-3
Where this commonly fails
  • compliance programme + DD partial

Enforcement

USFCPA-5
Enforcement, Self-Reporting, Cooperation, Remediation

Per FCPA Corporate Enforcement Policy: self-reporting + cooperation + remediation including DPA + NPA + declination.

Artefacts an auditor will ask for
  • FCPA evidence for USFCPA-5
Where this commonly fails
  • compliance programme + DD partial

Penalties and Enforcement

15 U.S.C. § 78dd-2(g)
Penalties for Domestic Concerns

Domestic concerns face criminal fines up to 50,000 per violation and individuals up to 5 years imprisonment.

Artefacts an auditor will ask for
  • Anti-bribery and anti-corruption (ABAC) policy
  • Internal accounting controls documentation and testing evidence
  • Third-party due diligence files and risk ratings
  • FCPA training records by role and geography
Where this commonly fails
  • Facilitating payments policy unclear in high-risk jurisdictions
  • Third-party due diligence not refreshed on risk-based cadence
  • Books and records adjustments not subject to independent review
  • Inadequate transaction monitoring for ABC red flags
15 U.S.C. § 78dd-3(e)
Penalties for Other Persons

Foreign nationals and entities face fines up to 50,000 and individuals up to 5 years imprisonment.

Artefacts an auditor will ask for
  • Anti-bribery and anti-corruption (ABAC) policy
  • Internal accounting controls documentation and testing evidence
  • Gifts, hospitality and travel pre-approval logs
  • Third-party due diligence files and risk ratings
Where this commonly fails
  • Inadequate transaction monitoring for ABC red flags
  • M&A successor liability diligence shallow
  • Books and records adjustments not subject to independent review
  • Facilitating payments policy unclear in high-risk jurisdictions
15 U.S.C. § 78ff(a)
Criminal Penalties for Accounting Violations

Willful violations of accounting provisions carry fines up to 5 million for entities and 20 years imprisonment for individuals.

Artefacts an auditor will ask for
  • Third-party due diligence files and risk ratings
  • Gifts, hospitality and travel pre-approval logs
  • Whistleblower hotline intake and investigation records
  • FCPA training records by role and geography
Where this commonly fails
  • M&A successor liability diligence shallow
  • Facilitating payments policy unclear in high-risk jurisdictions
  • Third-party due diligence not refreshed on risk-based cadence
  • Books and records adjustments not subject to independent review
15 U.S.C. § 78ff(c)
Criminal Penalties for Anti-Bribery Violations

Anti-bribery violations carry fines up to million for entities and 50,000 plus 5 years for individuals.

Artefacts an auditor will ask for
  • Third-party due diligence files and risk ratings
  • FCPA training records by role and geography
  • Whistleblower hotline intake and investigation records
  • Gifts, hospitality and travel pre-approval logs
Where this commonly fails
  • Inadequate transaction monitoring for ABC red flags
  • M&A successor liability diligence shallow
  • Facilitating payments policy unclear in high-risk jurisdictions
  • Books and records adjustments not subject to independent review
15 U.S.C. § 78u(d)
Civil Enforcement Actions

SEC may bring civil enforcement actions seeking injunctions, disgorgement, and civil monetary penalties.

Artefacts an auditor will ask for
  • Anti-bribery and anti-corruption (ABAC) policy
  • Whistleblower hotline intake and investigation records
  • Third-party due diligence files and risk ratings
  • FCPA training records by role and geography
Where this commonly fails
  • Books and records adjustments not subject to independent review
  • Facilitating payments policy unclear in high-risk jurisdictions
  • Inadequate transaction monitoring for ABC red flags
  • M&A successor liability diligence shallow

Self-Disclosure and Cooperation

FCPA-13
Voluntary Self-Disclosure and Cooperation

The DOJ Criminal Division FCPA Corporate Enforcement Policy provides a presumption of declination, with disgorgement, for companies that voluntarily self-disclose, fully cooperate, and timely and appropriately remediate, absent aggravating circumstances. Decisions to disclose require counsel involvement and documented analysis.

Artefacts an auditor will ask for
  • Voluntary disclosure decision framework
  • Counsel memoranda on disclosure considerations
  • Past disclosure records with declination or resolution
  • Cooperation evidence (interview availability, document production)
Where this commonly fails
  • No documented framework
  • Decisions to disclose made under pressure without analysis
  • Cooperation patchy across subsidiaries
  • Remediation not started before disclosure

Third Party and Transaction Due Diligence

FCPA-04
Third-Party Due Diligence

Because liability extends to payments made through intermediaries, organisations must conduct risk-based due diligence on third parties including agents, distributors, consultants, joint venture partners, and merger and acquisition targets, with the depth of review proportionate to the risk presented.

Artefacts an auditor will ask for
  • Tiered due diligence procedure
  • Questionnaires and responses with red flag analysis
  • Background check reports from reputable vendors
  • Approval committees with documented minutes
Where this commonly fails
  • Same diligence applied regardless of risk
  • Red flags identified but not resolved
  • Approval committees rubber-stamp
  • M&A diligence rushed and superficial
FCPA-09
Mergers and Acquisitions Successor Liability

Acquirers may inherit FCPA liability from target companies. Pre-acquisition diligence, post-acquisition integration, and remediation of identified issues are expected, with rapid escalation to counsel and possible voluntary disclosure where serious violations are found.

Artefacts an auditor will ask for
  • FCPA M&A diligence playbook
  • Diligence findings reports with risk rating
  • Post-closing integration plan covering compliance
  • Voluntary disclosure files where applicable
Where this commonly fails
  • No FCPA module in M&A diligence
  • Findings not integrated into purchase price or representations
  • Integration plan silent on compliance
  • Disclosure decisions made without counsel
FCPA-14
Foreign Subsidiary Oversight

Parent issuers are responsible for ensuring foreign subsidiaries comply with FCPA, including consolidation of accounts, oversight of local management, and integration into the global compliance programme. Subsidiaries with autonomous decision-making in higher-risk jurisdictions require closer attention.

Artefacts an auditor will ask for
  • Subsidiary risk rating matrix
  • Local compliance officer designations
  • Quarterly subsidiary compliance reports
  • Internal audit rotation covering subsidiaries
Where this commonly fails
  • No subsidiary risk ratings
  • Local compliance officers in name only
  • Quarterly reports superficial
  • Audit rotation skips highest risk subsidiaries
FCPA-15
Distributor and Reseller Margin Analysis

Discounts, rebates, and commissions to distributors and resellers in higher-risk markets must be analysed to identify margins that exceed market norms, which can be used to fund corrupt payments. Periodic margin reviews and reasonable benchmark documentation are expected.

Artefacts an auditor will ask for
  • Margin analytics by country and channel partner
  • Benchmark documentation for normal market margins
  • Exception reports with explanations
  • Channel partner certifications
Where this commonly fails
  • No margin analytics
  • Benchmarks not documented
  • Exceptions accepted without analysis
  • Certifications collected but not reviewed
Assembled from the framework's own control set. Every line traces to a control in the graph, so this pack is regenerated rather than written, and stays current as the graph does.

Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the US Foreign Corrupt Practices Act (FCPA) framework page.