US Foreign Corrupt Practices Act (FCPA)
Evidence request list. 34 controls, 34 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 12 September 2026. Published by The Art of Service.
Accounting
Per FCPA 15 USC 78m: accounting provisions requiring books + records that accurately reflect transactions + reasonable system of internal accounting controls.
- FCPA evidence for USFCPA-2
- compliance programme + DD partial
Accounting Provisions
Issuers must make and keep books, records, and accounts that accurately reflect transactions and assets.
- Internal accounting controls documentation and testing evidence
- Third-party due diligence files and risk ratings
- Gifts, hospitality and travel pre-approval logs
- FCPA training records by role and geography
- Third-party due diligence not refreshed on risk-based cadence
- Inadequate transaction monitoring for ABC red flags
- Books and records adjustments not subject to independent review
- Facilitating payments policy unclear in high-risk jurisdictions
Issuers must devise and maintain a system of internal accounting controls sufficient to provide reasonable assurances.
- FCPA training records by role and geography
- Anti-bribery and anti-corruption (ABAC) policy
- Internal accounting controls documentation and testing evidence
- Whistleblower hotline intake and investigation records
- Books and records adjustments not subject to independent review
- Facilitating payments policy unclear in high-risk jurisdictions
- Inadequate transaction monitoring for ABC red flags
- M&A successor liability diligence shallow
Issuers must use good faith efforts to ensure subsidiaries maintain proper books, records, and controls.
- Internal accounting controls documentation and testing evidence
- FCPA training records by role and geography
- Anti-bribery and anti-corruption (ABAC) policy
- Gifts, hospitality and travel pre-approval logs
- M&A successor liability diligence shallow
- Inadequate transaction monitoring for ABC red flags
- Facilitating payments policy unclear in high-risk jurisdictions
- Books and records adjustments not subject to independent review
Anti-Bribery
Per US FCPA 15 USC 78dd-1: anti-bribery prohibition on corruptly making payments to foreign officials + parties + intermediaries to obtain or retain business + understand prohibited conduct.
- FCPA evidence for USFCPA-1
- compliance programme + DD partial
Anti-Bribery Provisions
US domestic concerns may not offer or pay anything of value to foreign officials to influence official acts.
- Anti-bribery and anti-corruption (ABAC) policy
- FCPA training records by role and geography
- Third-party due diligence files and risk ratings
- Gifts, hospitality and travel pre-approval logs
- Books and records adjustments not subject to independent review
- Inadequate transaction monitoring for ABC red flags
- Third-party due diligence not refreshed on risk-based cadence
- Facilitating payments policy unclear in high-risk jurisdictions
Domestic concern includes any US citizen, national, resident, or any business entity organized under US law.
- FCPA training records by role and geography
- Internal accounting controls documentation and testing evidence
- Gifts, hospitality and travel pre-approval logs
- Whistleblower hotline intake and investigation records
- Books and records adjustments not subject to independent review
- Third-party due diligence not refreshed on risk-based cadence
- Inadequate transaction monitoring for ABC red flags
- Facilitating payments policy unclear in high-risk jurisdictions
Any person who acts within US territory to corruptly further a payment to a foreign official is liable.
- Anti-bribery and anti-corruption (ABAC) policy
- Internal accounting controls documentation and testing evidence
- Third-party due diligence files and risk ratings
- FCPA training records by role and geography
- Third-party due diligence not refreshed on risk-based cadence
- Facilitating payments policy unclear in high-risk jurisdictions
- Books and records adjustments not subject to independent review
- M&A successor liability diligence shallow
Issuers, domestic concerns, and persons acting on their behalf must not corruptly offer, promise, or pay anything of value to a foreign official, foreign political party, party official, or candidate, for the purpose of influencing an official act, securing an improper advantage, or obtaining or retaining business. Liability attaches to direct payments and to payments made through intermediaries when the payer knows or has reason to know.
- Global anti-bribery policy signed by CEO and updated annually
- Training records by role and country
- Risk assessment identifying high-risk jurisdictions and counterparties
- Disciplinary action records for policy violations
- Policy not translated for local offices
- Training not refreshed annually
- No risk-based training intensity
- Disciplinary action inconsistent across regions
Contracts with third parties operating outside the United States or in higher-risk environments must include FCPA representations, warranties, audit rights, termination rights for non-compliance, training obligations, and periodic certifications, with these clauses tracked in a contract management system.
- Approved FCPA contract clauses library
- Contract management system reports showing clause coverage
- Annual third-party certifications
- Audit rights exercised on selected counterparties
- Local contracts omit FCPA clauses
- Audit rights never exercised
- Certifications collected but not reviewed
- Termination right not enforced after red flag
FCPA includes a narrow exception for routine governmental action facilitating payments, but enforcement risk and parallel laws such as the UK Bribery Act make zero-tolerance preferable. Companies should adopt and document an explicit position on facilitating payments and apply it consistently across the enterprise.
- Documented facilitating payments policy (typically zero tolerance)
- Country-specific guidance
- Pre-clearance process for any exception
- Annual policy refresh evidence
- No explicit policy
- Local practices vary by country
- Pre-clearance process informal
- Annual review not performed
Gifts, travel, and entertainment provided to foreign officials must be reasonable, bona fide, directly related to promotion or contract performance, and permitted under local law. Pre-approval, monetary thresholds, and accurate expense coding are required to demonstrate compliance.
- GTE policy with country-specific monetary thresholds
- Pre-approval workflow records
- Expense reports with detailed descriptions
- Periodic GTE audit reports
- No country-specific thresholds
- Pre-approval bypassed for senior travellers
- Expense descriptions vague
- GTE audits not performed
Charitable contributions and sponsorships in foreign jurisdictions must be reviewed to confirm they are not a conduit for improper payments to officials. Diligence on recipient organisations, their leadership, beneficial owners, and any connection to officials is required, along with documented business rationale.
- Donation request forms with business rationale
- Recipient organisation diligence files
- Approval committee minutes
- Post-payment monitoring including fund use confirmation
- Donations approved by single executive
- No recipient diligence
- Fund use never confirmed
- Donations clustered before bid awards
Corporate political contributions in foreign jurisdictions must comply with local law and must not be used to influence foreign officials. Pre-approval, recipient diligence, and disclosure consistent with local rules are required.
- Political contributions policy
- Pre-approval records
- Recipient diligence files
- Disclosure submissions where required
- Policy silent on foreign contributions
- Contributions made without pre-approval
- Recipient diligence absent
- Disclosure not made where required
Books, Records and Internal Accounting Controls
Issuers must make and keep books, records, and accounts that, in reasonable detail, accurately and fairly reflect the transactions and dispositions of the assets of the issuer. Records must not be falsified to disguise improper payments, regardless of materiality.
- Chart of accounts with descriptive line items
- Journal entry review and approval workflows
- Quarterly self-certifications by finance leadership
- Records retention schedules
- Vague accounts such as miscellaneous or sundry used to record large amounts
- Manual journal entries without secondary review
- Self-certifications signed without supporting work
- Records retention shorter than statute of limitations
Issuers must devise and maintain a system of internal accounting controls sufficient to provide reasonable assurances that transactions are executed and recorded properly, access to assets is permitted only with management authorisation, and recorded accountability for assets is compared with existing assets at reasonable intervals.
- ICFR control matrix per process
- Authorisation matrices
- Periodic asset reconciliations
- Internal audit reports testing FCPA-relevant controls
- Authorisation matrices outdated
- Reconciliations performed but not reviewed
- Internal audit does not test FCPA controls
- Control failures not remediated
While the books and records and internal controls provisions apply primarily to issuers, domestic concerns and persons within the United States remain subject to anti-bribery provisions and should maintain records sufficient to defend against allegations and to support voluntary cooperation.
- Voluntary record retention policy covering FCPA-relevant transactions
- Vendor master data quality controls
- Payment justification files
- Audit trail evidence
- No FCPA-specific retention rules for non-issuers
- Vendor master data unverified
- Payment justifications absent
- Audit trails incomplete
Compliance Programme
Per FCPA Resource Guide + DOJ Evaluation of Corporate Compliance Programs: compliance programme + risk-based DD on third parties + agents + JV partners + M&A + training.
- FCPA evidence for USFCPA-4
- compliance programme + DD partial
Compliance Programme Design and Testing
The chief compliance officer must have sufficient seniority, authority, autonomy, and resources to operate the FCPA compliance programme effectively, with direct reporting to the board or audit committee in addition to executive management.
- Compliance organisation chart with reporting lines
- Compliance budget over multi-year period
- Headcount data including geographic coverage
- Board and audit committee meeting minutes including compliance reports
- CCO reports through general counsel without dotted line to board
- Compliance budget cuts year over year
- Headcount concentrated in headquarters only
- Board reports infrequent
Multiple confidential reporting channels including hotline, email, and web intake must be available globally, in local languages, with anti-retaliation protections, anonymous reporting where legally permitted, and a tracked investigation workflow.
- Hotline provider contract
- Multi-language reporting portal
- Anti-retaliation policy with disciplinary teeth
- Investigation case management records with disposition
- Hotline only in English
- Anonymous reporting blocked in jurisdictions where allowed
- Anti-retaliation cases never investigated
- Investigation case management ad hoc
Allegations of bribery or accounting violations must be investigated by appropriately resourced and independent investigators, with documented scope, evidence handling, interview memoranda, conclusions, and remediation. Counsel involvement may preserve attorney-client privilege.
- Investigation protocol
- Sample investigation files with scope memos, evidence registers, and conclusions
- Privilege management procedures
- Outcomes tracker linking findings to remediation
- Investigations performed by managers of accused employees
- Evidence not preserved
- No privilege strategy
- Remediation not tracked
The compliance programme must be tested, measured, and improved over time, using metrics such as training completion, hotline activity, investigation outcomes, third-party risk coverage, and internal audit findings. Lessons learned from internal and external enforcement events must drive enhancements.
- Compliance programme metrics dashboard
- Annual programme effectiveness review
- External benchmark comparisons
- Remediation plans with executive sponsors
- Metrics report on activity not outcomes
- No annual effectiveness review
- Benchmarks against peers absent
- Remediation plans without executive sponsorship
Defenses
Per FCPA: Facilitating Payments Exception + Affirmative Defenses including Local Law + Reasonable Expenditure including travel and lodging.
- FCPA evidence for USFCPA-3
- compliance programme + DD partial
Enforcement
Per FCPA Corporate Enforcement Policy: self-reporting + cooperation + remediation including DPA + NPA + declination.
- FCPA evidence for USFCPA-5
- compliance programme + DD partial
Penalties and Enforcement
Domestic concerns face criminal fines up to 50,000 per violation and individuals up to 5 years imprisonment.
- Anti-bribery and anti-corruption (ABAC) policy
- Internal accounting controls documentation and testing evidence
- Third-party due diligence files and risk ratings
- FCPA training records by role and geography
- Facilitating payments policy unclear in high-risk jurisdictions
- Third-party due diligence not refreshed on risk-based cadence
- Books and records adjustments not subject to independent review
- Inadequate transaction monitoring for ABC red flags
Foreign nationals and entities face fines up to 50,000 and individuals up to 5 years imprisonment.
- Anti-bribery and anti-corruption (ABAC) policy
- Internal accounting controls documentation and testing evidence
- Gifts, hospitality and travel pre-approval logs
- Third-party due diligence files and risk ratings
- Inadequate transaction monitoring for ABC red flags
- M&A successor liability diligence shallow
- Books and records adjustments not subject to independent review
- Facilitating payments policy unclear in high-risk jurisdictions
Willful violations of accounting provisions carry fines up to 5 million for entities and 20 years imprisonment for individuals.
- Third-party due diligence files and risk ratings
- Gifts, hospitality and travel pre-approval logs
- Whistleblower hotline intake and investigation records
- FCPA training records by role and geography
- M&A successor liability diligence shallow
- Facilitating payments policy unclear in high-risk jurisdictions
- Third-party due diligence not refreshed on risk-based cadence
- Books and records adjustments not subject to independent review
Anti-bribery violations carry fines up to million for entities and 50,000 plus 5 years for individuals.
- Third-party due diligence files and risk ratings
- FCPA training records by role and geography
- Whistleblower hotline intake and investigation records
- Gifts, hospitality and travel pre-approval logs
- Inadequate transaction monitoring for ABC red flags
- M&A successor liability diligence shallow
- Facilitating payments policy unclear in high-risk jurisdictions
- Books and records adjustments not subject to independent review
SEC may bring civil enforcement actions seeking injunctions, disgorgement, and civil monetary penalties.
- Anti-bribery and anti-corruption (ABAC) policy
- Whistleblower hotline intake and investigation records
- Third-party due diligence files and risk ratings
- FCPA training records by role and geography
- Books and records adjustments not subject to independent review
- Facilitating payments policy unclear in high-risk jurisdictions
- Inadequate transaction monitoring for ABC red flags
- M&A successor liability diligence shallow
Self-Disclosure and Cooperation
The DOJ Criminal Division FCPA Corporate Enforcement Policy provides a presumption of declination, with disgorgement, for companies that voluntarily self-disclose, fully cooperate, and timely and appropriately remediate, absent aggravating circumstances. Decisions to disclose require counsel involvement and documented analysis.
- Voluntary disclosure decision framework
- Counsel memoranda on disclosure considerations
- Past disclosure records with declination or resolution
- Cooperation evidence (interview availability, document production)
- No documented framework
- Decisions to disclose made under pressure without analysis
- Cooperation patchy across subsidiaries
- Remediation not started before disclosure
Third Party and Transaction Due Diligence
Because liability extends to payments made through intermediaries, organisations must conduct risk-based due diligence on third parties including agents, distributors, consultants, joint venture partners, and merger and acquisition targets, with the depth of review proportionate to the risk presented.
- Tiered due diligence procedure
- Questionnaires and responses with red flag analysis
- Background check reports from reputable vendors
- Approval committees with documented minutes
- Same diligence applied regardless of risk
- Red flags identified but not resolved
- Approval committees rubber-stamp
- M&A diligence rushed and superficial
Acquirers may inherit FCPA liability from target companies. Pre-acquisition diligence, post-acquisition integration, and remediation of identified issues are expected, with rapid escalation to counsel and possible voluntary disclosure where serious violations are found.
- FCPA M&A diligence playbook
- Diligence findings reports with risk rating
- Post-closing integration plan covering compliance
- Voluntary disclosure files where applicable
- No FCPA module in M&A diligence
- Findings not integrated into purchase price or representations
- Integration plan silent on compliance
- Disclosure decisions made without counsel
Parent issuers are responsible for ensuring foreign subsidiaries comply with FCPA, including consolidation of accounts, oversight of local management, and integration into the global compliance programme. Subsidiaries with autonomous decision-making in higher-risk jurisdictions require closer attention.
- Subsidiary risk rating matrix
- Local compliance officer designations
- Quarterly subsidiary compliance reports
- Internal audit rotation covering subsidiaries
- No subsidiary risk ratings
- Local compliance officers in name only
- Quarterly reports superficial
- Audit rotation skips highest risk subsidiaries
Discounts, rebates, and commissions to distributors and resellers in higher-risk markets must be analysed to identify margins that exceed market norms, which can be used to fund corrupt payments. Periodic margin reviews and reasonable benchmark documentation are expected.
- Margin analytics by country and channel partner
- Benchmark documentation for normal market margins
- Exception reports with explanations
- Channel partner certifications
- No margin analytics
- Benchmarks not documented
- Exceptions accepted without analysis
- Certifications collected but not reviewed
Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the US Foreign Corrupt Practices Act (FCPA) framework page.