No Result
View All Result
SUBSCRIBE | NO FEES, NO PAYWALLS
MANAGE MY SUBSCRIPTION
NEWSLETTER
Corporate Compliance Insights
  • About
    • About CCI
    • Writing for CCI
    • NEW: CCI Press – Book Publishing
    • Advertise With Us
  • Explore Topics
    • See All Articles
    • Compliance
    • Ethics
    • Risk
    • Artificial Intelligence (AI)
    • FCPA
    • Governance
    • Fraud
    • Internal Audit
    • HR Compliance
    • Cybersecurity
    • Data Privacy
    • Financial Services
    • Well-Being at Work
    • Leadership and Career
    • Opinion
  • Vendor News
  • Downloads
    • Download Whitepapers & Reports
    • Download eBooks
  • Research
  • Books
    • CCI Press
    • New: Bribery Beyond Borders: The Story of the Foreign Corrupt Practices Act by Severin Wirz
    • CCI Press & Compliance Bookshelf
    • The Seven Elements Book Club
  • Podcasts
  • Webinars
  • Videos
  • Subscribe
Jump to a Section
  • At the Office
    • Ethics
    • HR Compliance
    • Leadership & Career
    • Well-Being at Work
  • Compliance & Risk
    • Compliance
    • FCPA
    • Fraud
    • Risk
  • Finserv & Audit
    • Financial Services
    • Internal Audit
  • Governance
    • ESG
    • Getting Governance Right
  • Infosec
    • Cybersecurity
    • Data Privacy
  • Opinion
    • Adam Balfour
    • Jim DeLoach
    • Mary Shirley
    • Yan Tougas
No Result
View All Result
Corporate Compliance Insights
Home Opinion

You Settled With the FTC; Now Comes a 20-Year Consent Decree

Third-party assessments generally considered costliest part of FTC decrees

by Tyler Bridegan and Audrey Karman
August 17, 2026
in Opinion, Risk
federal trade commission building front

Calls are growing for reforms to FTC consent decrees issued as part of commission enforcement action. Tyler Bridegan and Audrey Karman of Womble Bond Dickinson explore the often costly injunctive terms and outline cost-saving measures while the FTC’s leader weighs changes.

While FTC monetary penalties usually grab the headlines, the agency’s enforcement playbook has increasingly come under scrutiny for a different practice: its use of onerous and costly injunctive terms. Companies targeted by the FTC are oftentimes surprised to learn that the real costs are incurred after settling with the commission. 

FTC enforcement reform has been a topic of discussion for decades. There are a variety of enforcement tactics with which critics take issue. Following high-profile calls for FTC consent decree reform, the current FTC chairman, Andrew N. Ferguson, has signaled that some (albeit limited) relief may be on the horizon.

Recently, Ferguson publicly directed staff to re-examine whether consent decrees should, by default, continue to automatically include an effective period of 20 years. This direction is notable, in part, because the FTC’s default 20-year term has been in effect since 1995. But the chair’s comments were also notable because he previewed what moving away from a default effective period might look like. Specifically, he noted that a consent decree’s duration should be calibrated to the severity of the alleged unlawful conduct as well as the underlying risk of recurrence, rather than applied as a default.

While the FTC has yet to officially reform its consent decree terms, Ferguson’s apparent willingness to reform FTC practices has already resulted in at least one company formally petitioning the FTC to set aside its consent decree. Depending on the FTC’s response to the company’s petition, there may be opportunities for other companies to follow suit.

Costly injunctive terms

For companies targeted by an FTC investigation or already subject to an FTC consent decree, it is essential that they understand the costs and implications of the more onerous provisions regularly included in FTC consent decrees. These include:

  • Recurring independent third-party assessments: Widely regarded as the single largest cost driver, these biennial assessments require engagement of an independent, often highly specialized assessor approved by the FTC. Critically, assessors must conduct independent testing, sampling and fact-gathering rather than relying on management representations. Each cycle demands extensive internal preparation, production of documentation, remediation of findings, and follow-up, repeated every two years for the life of a decades-long order. This is not an audit that can be handled with a checklist; it is a substantive, resource-intensive evaluation.
  • Verified compliance reports and certifications: Interim, annual and sometimes quarterly reports detailing compliance with the order must be signed under penalty of perjury by a senior officer. The legal review, internal audit coordination and personal liability exposure associated with these certifications add significant cost layers beyond the assessment itself. This is a somewhat open-ended requirement where the FTC retains discretion to mandate additional reports at any time, creating an ongoing compliance obligation.
  • Recordkeeping and data retention obligation: Some orders impose retention requirements lasting five or more years, and legacy orders have required perpetual retention of broad categories of business records. These obligations can become misaligned with evolving data-minimization best practices and impose ongoing storage, governance and retrieval costs.
made in usa label
Featured

Born in the USA? The FTC Wants Your Substantiation File

by Julia Solomon Ensor and John Feldman
August 12, 2026

Read moreDetails

Practical cost-mitigation strategies

Given the FTC’s own recent signals that order terms should be proportionate, compliance teams have both the opportunity and the obligation to approach consent decree negotiations and ongoing compliance strategically.

  • Negotiate duration and scope at settlement: Rather than accepting default terms, push for risk-calibrated order duration, sunset or step-down provisions and early-termination mechanisms tied to demonstrated compliance milestones. The FTC’s public statements create leverage for these arguments.
  • Build on existing infrastructure: Mandate-specific compliance programs should be layered on top of not parallel to existing enterprise risk management, internal audit and information security frameworks. Duplicative cost centers are avoidable with thoughtful program design from the outset.
  • Treat assessments as continuous compliance: Transform the biennial third-party assessment from a fire drill into a continuous-readiness function. Maintain assessment-ready documentation, control testing evidence and sampling logs year-round so that each assessment cycle requires incremental effort rather than ground-up mobilization.
  • Insist on precise definitions: During settlement negotiations, seek technology-neutral, precisely defined terms for covered data categories, reportable incidents and compliance triggers. Overbroad or outdated language, particularly around consent mechanisms or retention, becomes costly to comply with and difficult to modify after entry.
  • Centralize recordkeeping and reporting: Consolidate the audit trail needed for both the FTC order and overlapping state or federal obligations into a single reporting function to reduce duplication and coordination costs.
  • Assign clear accountability: Designate a single executive function with unambiguous authority over certification, training and reporting obligations. Fragmentation across departments multiplies coordination costs without improving compliance quality.
  • Seek modification of outdated terms: Where business practices or technology evolve, petition to reopen or modify legacy order terms that have become disproportionate. The FTC has signaled openness to reconsidering order scope where a party demonstrates the terms are no longer calibrated to the underlying risk.

Looking ahead

The growing consensus that FTC consent decree terms warrant reform reflects a broader recognition that effective enforcement need not require indefinite or disproportionate compliance burdens. For companies facing or currently subject to FTC orders, the message is clear: the injunctive terms deserve at least as much strategic attention as the penalty amount. Proactive negotiation, thoughtful program design, and continuous compliance readiness are the most effective tools for managing the true cost of settlement.

Tags: Federal Trade Commission (FTC)
Previous Post

Illinois Genetic Information Protection Act Comes of Age

Next Post

As Midterms Approach, Specter of Transcribed Interviews Rises for Non-Governmental Actors

Tyler Bridegan and Audrey Karman

Tyler Bridegan and Audrey Karman

Tyler R. Bridegan, CIPP, CIPM, is a partner in the Houston office of Womble Bond Dickinson. He counsels clients on proactive compliance with federal and state consumer protection laws. He formerly was director of privacy and technology enforcement for the Texas Attorney General’s Office and acting legal advisor at the Federal Communications Commission.
Audrey Karman is a senior counsel in the Washington, D.C., office of Womble Bond Dickinson. She is a member of the firm's white collar defense, investigations and regulatory enforcement practice.

Related Posts

made in usa label

Born in the USA? The FTC Wants Your Substantiation File

by Julia Solomon Ensor and John Feldman
August 12, 2026

The FTC is cracking down on “Made in USA” claims, but risk is not equal across all claims and all...

scotus building

SCOTUS Broadens White House Influence Over ‘Independent’ Agencies

by Jennifer L. Gaskin
July 8, 2026

In part of a flurry of end-of-term activity, the Supreme Court in late June overturned a 90-year-old precedent and held...

federal trade commission building

[Q&A] Big Tech & Free Speech Under the Microscope: FTC’s New Direction

by FTI Consulting
April 28, 2025

What compliance teams need to know about the changing approach to consumer protection and data privacy

data governance concept

The US Still Lacks Its Own GDPR, But That Doesn’t Mean Data Privacy Enforcement Isn’t Happening

by Brian McGinnis and Maddie San Jose
April 16, 2025

Despite the absence of comprehensive federal privacy legislation, American businesses face mounting regulatory pressure from multiple directions. Brian McGinnis and...

Next Post
ways and means meeting room

As Midterms Approach, Specter of Transcribed Interviews Rises for Non-Governmental Actors

GGR sq
No Result
View All Result

Privacy Policy | AI Policy

Founded in 2010, CCI is the web’s premier global independent news source for compliance, ethics, risk and information security. 

Got a news tip? Get in touch. Want a weekly round-up in your inbox? Sign up for free. No subscription fees, no paywalls. 

Follow Us

Browse Topics:

  • CCI Press
  • Compliance
  • Compliance Podcasts
  • Cybersecurity
  • Data Privacy
  • eBooks Published by CCI
  • Ethics
  • FCPA
  • Featured
  • Financial Services
  • Fraud
  • Governance
  • GRC Vendor News
  • HR Compliance
  • Internal Audit
  • Leadership and Career
  • On Demand Webinars
  • Opinion
  • Research
  • Resource Library
  • Risk
  • Uncategorized
  • Videos
  • Webinars
  • Well-Being
  • Whitepapers

© 2026 Corporate Compliance Insights

No Result
View All Result
  • About
    • About CCI
    • Writing for CCI
    • NEW: CCI Press – Book Publishing
    • Advertise With Us
  • Explore Topics
    • See All Articles
    • Compliance
    • Ethics
    • Risk
    • Artificial Intelligence (AI)
    • FCPA
    • Governance
    • Fraud
    • Internal Audit
    • HR Compliance
    • Cybersecurity
    • Data Privacy
    • Financial Services
    • Well-Being at Work
    • Leadership and Career
    • Opinion
  • Vendor News
  • Downloads
    • Download Whitepapers & Reports
    • Download eBooks
  • Research
  • Books
    • CCI Press
    • New: Bribery Beyond Borders: The Story of the Foreign Corrupt Practices Act by Severin Wirz
    • CCI Press & Compliance Bookshelf
    • The Seven Elements Book Club
  • Podcasts
  • Webinars
  • Videos
  • Subscribe

© 2026 Corporate Compliance Insights