For a compliance team with a footprint in Latin America, treating a terrorist designation as a fire drill gets expensive fast, writes Rafael Antal, an attorney and anti-corruption scholar. What’s worth asking now, while there’s no active fire: Could the program already in place absorb the next designation without anyone pulling an all-nighter?
In June, the US State Department’s designation of Brazil’s Primeiro Comando da Capital (PCC) and Comando Vermelho (CV) as foreign terrorist organizations took effect, the first time a Brazilian criminal organization has received that label. Most compliance officers at US mid-sized contractors with Latin American operations read about it as a legal update, but that framing undersells the reality. Compliance programs’ vendor screenings, trainings, red-flag escalations — all of this was built around a narrower risk than what the designation indicates.
Most US contractors with Brazilian counterparts are already juggling the FCPA on one side and Brazil’s Clean Company Act on the other. Add a UK-linked lender or parent to the ownership chain and the UK Bribery Act joins the mix, and plenty of these programs lean on ISO 37001 as their audit backbone.
What the terrorist designation added is yet another register most of these programs were never built to check. Federal law defines “material support or resources” broadly enough to cover currency, financial services and payments made under duress, and it reaches conduct that happens entirely outside the US — a single transaction through a correspondent account is enough to give federal prosecutors jurisdiction. The Justice Against Sponsors of Terrorism Act adds a civil claim alongside the criminal one. Once the Treasury added PCC and CV to the specially designated nationals list, blocking certain obligations for any entity a designee owns at least 50% of, public issuers picked up a Section 13(r) disclosure duty with no materiality threshold attached. Lafarge paid more than $778 million and Chiquita Brands paid $25 million on material-support findings for payments that were meant to keep operations running, not to bankroll anyone’s cause — the distinction didn’t save either company.
The good news, if there is any, is that fixing this doesn’t mean hiring. Flat budgets against a growing risk register is usually the first objection a compliance officer raises. What it actually takes is a new lane inside the program that already exists, run by the people already doing third-party diligence, working off a longer questionnaire and a screening list that now includes foreign terrorist organizations (FTO) and specially designated global terrorists next to the usual sanctions and politically exposed persons.
Where existing programs fall short
Bribery questionnaires ask about payments to officials. They usually stop there — nothing about whether a subcontractor’s ownership traces to a newly designated group, nothing about telling a protection payment made under duress apart from a garden-variety vendor dispute. A vendor can sail through a standard anti-bribery audit and still hand a company material-support exposure if its books show payments made just to keep operating in territory PCC or CV control, which are mostly in and around Sao Paulo and Rio de Janeiro.
This isn’t the first time a designation has outpaced a compliance program, and it won’t be the last. Earlier rounds hit Mexican cartels like MS-13, Tren de Aragua and organized-crime groups in Haiti and Ecuador, with more expected as the policy keeps expanding through the hemisphere. Each round tends to catch a fresh batch of companies whose programs were sized for a narrower risk.
Training tends to lag the same way. Most anti-bribery modules teach people to spot a payment to a government official, which is a different judgment call than spotting a payment squeezed out by an armed group. Someone who’s spent years learning to flag gifts and hospitality isn’t automatically going to catch a wire transfer that looks routine on paper but is really a protection payment. That’s a training problem as much as a policy one, and it usually only shows up after something’s already gone wrong. That’s an expensive way to find out.
What the EU’s Italian Cases Mean for Sanctions & AML Compliance
Two CJEU rulings on trust structures signal that regulators will look past legal title to who actually benefits, decides and influences assets
Read moreDetailsFixes won’t wait
Six changes address the sharpest gaps for compliance teams with exposure in the region.
- Map beneficial ownership for counterparts and subcontractors operating where PCC or CV hold sway over legitimate commerce. Ownership structures in contested territory are often deliberately opaque, which makes this the slowest and most resource-intensive item on the list and the one most worth prioritizing first.
- Re-scope third-party questionnaires to add a standalone transnational criminal organization (TCO) and FTO screening section. The existing bribery questions won’t catch this risk on their own, and bolting a single new question onto an old form tends to get skipped by whoever is filling it out.
- Fold the Treasury’s Office of Foreign Asset Control (OFAC) specially designated nations list and State Department FTO announcements into periodic re-screening of counterparties already on file, not just new-vendor intake. A counterparty that cleared screening two years ago may not clear it today.
- Pull duress payments out of the ordinary third-party risk bucket. Protection or extortion payments made to keep operating in contested territory need their own escalation path and a bright-line no-payment rule, not field-level discretion left to whoever answers the phone that day.
- Tie the resulting paper trail to ISO 37001’s audit-ready recordkeeping standard, so one record can support a bribery audit and a material-support review instead of maintaining two parallel filing systems.
- Chart the reporting clocks separately. A material-support self-disclosure, an OFAC filing and a Section 13(r) disclosure can share a single fact pattern without sharing a deadline, and missing one because attention was on another is not a defense regulators tend to accept.
None of this needs a parallel compliance program bolted onto what already exists. The existing one can cover more ground. More designations are coming. This is roughly the fourth or fifth round since the underlying policy started, depending on how generously you count, and nothing about the pace says it’s slowing down.


Rafael Antal is a Brazil-licensed attorney (OAB/SP), LL.M. graduate of SMU Dedman School of Law and an ISO 37001 and ISO 19600 lead assessor. He has worked in anti-corruption compliance at a Brazilian engineering and construction company with US contracting relationships and is the author of the “Cross-Border Anti-Corruption and Critical Infrastructure Compliance Framework,” a publicly available 









