Corporate FCPA enforcement is down, but enforcement involving international business, especially under export controls and economic sanctions, remains active, Thad McBride of Bass Berry & Sims explains. Third parties remain a primary source of risk, but when violations do arise, the DOJ has made voluntary disclosure a compelling option.
For decades, the US government aggressively enforced the FCPA, the primary US law prohibiting bribery of foreign government officials. But since early 2025, the enforcement record has been thin. The corporate FCPA enforcement page maintained by the DOJ identifies a single corporate enforcement action dated 2026 — a deferred prosecution agreement (DPA) with Scoular in July, the month the page was last updated. Additionally, in March 2026, the DOJ announced that it was declining to prosecute French medical device company Balt SAS after the company voluntarily self-disclosed misconduct.
To be clear, FCPA enforcement has not disappeared. The statute has not been removed from the books, and the government is continuing to prosecute individuals. But it does appear the regulated community can expect a narrower, more selective enforcement approach.
At the same time, businesses operating across borders should not equate fewer corporate FCPA cases with lower overall compliance risk. The departments of Commerce and Treasury have each brought significant export control and sanctions cases, often involving foreign subsidiaries, distributors, brokers and other intermediaries — the same types of parties that create anti-corruption risk.
A narrower FCPA enforcement agenda
In February 2025, President Donald Trump directed the DOJ to pause new FCPA investigations and review existing matters. Then, in June 2025, the DOJ issued new FCPA enforcement guidelines. The guidelines instructed prosecutors to prioritize cases involving cartels and transnational criminal organizations; harm to identifiable US companies; national security concerns; and serious misconduct involving substantial bribes, concealment, fraud or obstruction.
The July Scoular matter illustrates what the policy looks like in practice. According to the DOJ’s announcement of the resolution, Scoular used third-party customs brokers between 2013 and 2019 to pay more than $400,000 in bribes to Mexican officials to overlook inspection issues in shipments crossing the US-Mexico border. The brokers allegedly invoiced those payments back to Scoular as “reinspection” charges, helping the company avoid more than $6.5 million in fees and costs.
The DOJ emphasized that some of the bribe money ultimately benefited people associated with cartel operations, even though Scoular personnel were unaware of that connection. Scoular agreed to pay more than $10 million in criminal penalties and entered into a three-year DPA. Under the agreement, Scoular must continue cooperating with the DOJ, maintain an enhanced compliance and ethics program and periodically report to the DOJ on its remediation and compliance efforts. The department also gave Scoular a 25% reduction from the bottom of the applicable sentencing guidelines range based on its cooperation and remediation, although the company did not receive voluntary disclosure credit because it failed to self-report the misconduct.
The Scoular facts align with the DOJ’s stated priority of targeting cartel activity. The matter also involved other points of emphasis — regular payments concealed through third-party invoices and shipments across the US-Mexico border, a clear hot-button issue for this administration.
Fewer FCPA corporate cases but no lack of cross-border enforcement
For the remainder of 2026 and the foreseeable future, observers should expect limited prosecution of corporate FCPA matters except when the facts fit the DOJ’s priorities.
At the same time, the Justice Department’s prosecution of individuals shows that reduced corporate case volume does not mean individual exposure has diminished. Moreover, broader cross-border enforcement is robust. The Commerce Department’s Bureau of Industry and Security (BIS), which administers US commercial export controls, continues to announce export control settlements. Its public export enforcement page lists 11 administrative orders issued so far this year, and the penalties can be substantial.
For example, in February, Applied Materials and Applied Materials Korea agreed to pay approximately $252 million to the BIS to resolve allegations related to semiconductor manufacturing equipment ultimately shipped to an entity list company in China. (An export license is required to export or even transfer in-country almost any US-origin item to a party on the entity list.) The BIS said the penalty equaled twice the value of the transactions, and as part of the resolution the company must conduct multiple compliance audits buttressed with annual compliance certifications.
The Treasury Department’s Office of Foreign Assets Control, which administers and enforces US economic and trade sanctions programs, has also remained active. In February, IMG Academy agreed to pay $1.72 million to resolve apparent counternarcotics sanctions violations arising from tuition agreements and related payments involving two sanctioned individuals tied to a Mexican drug cartel. The case illustrates how sanctions risk can arise even in industries that may not traditionally view themselves as high-risk, particularly when businesses have international customers, payment flows or other cross-border relationships. The matter is also evidence of the larger US government effort to target activity related to cartels.
These cases matter because compliance risk does not usually arrive in a neat box. A customs broker, freight forwarder, distributor or sales agent can create anti-corruption, sanctions, export control and customs exposure in the same transaction. A matter that may at first appear to raise mainly sanctions questions can be revealed to primarily create bribery issues, or vice versa. Scoular illustrates the point: The bribery scheme operated through customs brokers whose legitimate role placed them in regular contact with government officials at the border, and payments made to those officials ultimately benefited cartels.
What Detractors Keep Getting Wrong About the FCPA
FCPA rewards companies; it doesn’t hamstring them
Read moreDetailsDue diligence on third parties, robust contractual protections
To be honest, this is old news, but it bears repeating given how frequently third parties trigger liability: Due diligence needs to be an ongoing activity and regularly refreshed based on risk rather than treated as a one-time onboarding exercise.
A better way to think of diligence is as vigilance, with continual monitoring of business relationships, including through auditing and payment testing that focuses on vague or unusual charges, such as “reinspection,” “facilitation,” “handling,” “expediting,” “administrative” or “special” fees that do not match supporting documentation. Round numbers, e.g., unexplained charges in the amount of $100 or $250 or the like, also warrant review. And companies should compare invoices against customs records, government fee schedules and proof of payment where possible.
Contracts should give companies clear termination rights and require third parties to follow applicable anti-corruption, sanctions and export control laws. Companies may also want to provide compliance training to higher-risk third parties based on where they operate and the services they perform. Foreign third parties may not always understand when US law applies to their conduct. They may also operate in markets where informal payments are more common or assume that fewer FCPA enforcement actions mean the risk of enforcement has declined. Other contractual protections, such as maintaining an audit right or requiring the intermediary to provide a detailed activity report each time it requests payment, should also be considered.
Voluntary disclosure is the clearest path to best resolution
The DOJ’s March 2026 department-wide corporate enforcement and voluntary self-disclosure policy (CEP) offers companies substantial benefits for voluntarily disclosing potential misconduct. Under Part I, the DOJ says it will decline prosecution when a company voluntarily self-discloses misconduct to the appropriate DOJ criminal component, fully cooperates, timely and appropriately remediates and has no disqualifying aggravating circumstances. Even when aggravating circumstances exist, prosecutors retain discretion to recommend a declination. Companies may still be required to pay disgorgement, forfeiture, restitution or victim compensation.
The CEP also creates benefits for companies that narrowly miss a declination. When a company self-reports in good faith but the report does not satisfy all of DOJ’s voluntary self-disclosure requirements, or aggravating factors support a criminal resolution, the DOJ generally calls for a non-prosecution agreement, a term of fewer than three years, no independent monitor and a 50% to 75% reduction from the low end of the applicable US sentencing guidelines fine range.
The benefits of the CEP were evident almost as soon as it was published: Only a few days later, the DOJ declined to prosecute Balt under the CEP. The medical device company self-disclosed a long-running bribery scheme in which a consultant funneled payments to a senior doctor at a state-owned hospital in France in exchange for the hospital purchasing Balt products. According to the DOJ, the payments were disguised as consulting fees and bonuses and concealed through sham consulting agreements, fake invoices and personal email accounts.
As a result of Balt’s voluntary disclosure, cooperation and remediation, the DOJ declined prosecution, though it did require approximately $1.2 million in disgorgement. Separately, the DOJ charged a former Balt USA executive and the company’s Belgium-based consultant with FCPA and money-laundering offenses arising from the alleged scheme. The individual cases remain pending.
The contrast between Balt and Scoular is instructive, even though the underlying facts differ. Scoular did not receive voluntary disclosure credit. Although the DOJ credited its cooperation and remediation, Scoular entered a three-year DPA and received only a 25% reduction from the bottom of the applicable guidelines range. Balt, of course, received a declination.
The CEP also puts a premium on speed. A disclosure generally must occur before there is an “imminent threat” that the government will learn of the misconduct and within a reasonably prompt time after the company becomes aware of it. Notably, the CEP provides a limited exception in the case of internal whistleblower reports. If a whistleblower reports misconduct both internally and to the DOJ, the company may still qualify for a declination even if the whistleblower reaches the DOJ first, provided the company investigates the allegations and self-reports the conduct as soon as reasonably practicable but no later than 120 days after receiving the whistleblower’s internal report. Companies therefore have some time to assess a whistleblower’s allegations before approaching the DOJ, though the CEP does not require or contemplate waiting until an internal investigation is complete.
It is important to recognize that every potential violation need not automatically be disclosed. Companies still need to investigate enough to understand what happened, evaluate jurisdiction and assess parallel regulatory exposure. But it is essential to move promptly. Legal and compliance teams should have an escalation process that allows them to identify potentially criminal conduct quickly, preserve evidence and make disclosure decisions before the most valuable incentives disappear.


Thad McBride is a partner at Bass, Berry & Sims PLC in the firm’s Washington, D.C. office. He counsels clients on compliance with and investigations involving the FCPA, economic sanctions and embargoes, export and import controls and other US trade laws. 










