1. Home
  2. |Insights
  3. |DOJ and SEC Issue Long-Awaited FCPA Guidance

DOJ and SEC Issue Long-Awaited FCPA Guidance

Client Alert | 1 min read | 11.14.12

The Department of Justice (DOJ) and the Securities and Exchange Commission (SEC) today issued long-awaited written guidance on the U.S. Foreign Corrupt Practices Act (FCPA), in a 120-page publication entitled A Resource Guide to the U.S. Foreign Corrupt Practices Act. According to the government, the Guide aims to "provide helpful information to enterprises of all shapes and sizes – from small businesses doing their first transactions abroad to multi-national corporations with subsidiaries around the world."

The Guide covers numerous topics, including several that are at the forefront of compliance officers' minds and central to current litigation, enforcement actions, and negotiations. Topics the Guide addresses include:

  • Who and what are covered by the FCPA's bribery and accounting provisions
  • What are proper and improper gifts, travel, and entertainment expenses
  • The definition of "foreign official"
  • The scope of the facilitating payments exception
  • The affirmative defenses, such as reimbursement of reasonable travel expenses
  • How successor liability applies in the M&A context
  • The hallmarks of effective corporate compliance programs
  • Penalties, sanctions, and remedies
  • Available types of criminal and civil resolution


The Guide reflects not only the government's interpretation of the law, but also its enforcement practices, providing hypotheticals and examples of enforcement actions and declinations. The Guide also includes discussion of the impact of self-reporting, cooperation, corporate compliance programs and remedial efforts.

Understanding the Guide, which may be found here, will be essential to any company that could fall within the broad reach of the FCPA. To that end, we will issue a full analysis within the next few days.

Insights

Client Alert | 7 min read | 08.17.26

Delayed Notification of Cyberattacks May Trigger HIPAA Breach Notification Rule

After identifying a ransomware attack in 2021, OSF Healthcare System waited until its forensic investigation had concluded before notifying the U.S. Department of Health and Human Services (HHS) — and the affected individuals — of the breach. The 110-day delay (nearly double the 60-calendar-day notification deadline mandated by the HIPAA Breach Notification Rule) triggered an investigation from HHS’s Office for Civil Rights (OCR). The health system’s investigation determined that protected health information (PHI) had been stolen....