Global Workforce, EOR & Cross-Border OperationsPlaybook3 min readUpdated September 2026

Vetting Foreign Vendors Without Creating FCPA Exposure

The FCPA violation that actually gets a company in trouble is rarely a direct bribe paid by an executive. It's a payment made by a foreign vendor, agent, or distributor, on the company's behalf, that the company didn't authorize directly but is still liable for because it didn't do the diligence to know who it was working with.

Vendor vetting is the control that catches this before the relationship starts, not after a payment already looks suspicious. It doesn't need to be complicated to be effective, but it does need to happen consistently, not just for the vendors that feel risky on gut instinct.

Vendors Covered in this Article

Disclosure: We may earn a commission if you buy through some links on this page. It doesn't change what we recommend.

Which foreign vendors need a full FCPA review?

Not every foreign vendor carries the same risk. The review should scale up for vendors who interact with government officials on your behalf, customs brokers, permit facilitators, government sales agents, and scale down for a vendor who simply sells you a commodity product with no government touchpoint. Sorting vendors into a risk tier at intake saves you from either skipping real risk or burning review time on low-risk purchases.

Build the tiering question into your procurement intake form itself: does this vendor interact with any government official or state-owned entity on our behalf. A yes routes to full review automatically.

When should you screen a foreign vendor for FCPA risk?

Screen for sanctions list matches, adverse media, and beneficial ownership before signing, not as a formality after the relationship is already operating. Beneficial ownership matters specifically because a vendor can look clean on paper while being owned or controlled by a government official or their family member, which is exactly the structure enforcement actions target most often.

Document the screening result and the date it was run, since the value of a screen is proving you did it at the time, not just that you would have passed one if asked.

Put Anti-Bribery Language in the Contract, Not Just the Policy

A code of conduct the vendor never reads does less work than a specific anti-bribery clause in the signed contract: representations that the vendor won't make improper payments on your behalf, an audit right, and a termination right if the representation turns out false. This gives you a contractual basis to act, not just a policy violation, if a problem surfaces later.

Have counsel confirm the clause is enforceable under the vendor's local contract law, since some standard anti-bribery language doesn't translate cleanly into every jurisdiction's contract enforcement.

Red Flags That Should Stop the Relationship, Not Just Slow It Down

A few patterns that warrant a hard stop rather than a caveat:

  • A request to pay an unusually large commission or fee relative to the service, with no clear justification
  • Reluctance to sign an anti-bribery representation or to disclose beneficial ownership
  • A request to route payment through a third country or a personal account instead of the vendor's business account
  • Specific, unsolicited claims that the vendor can expedite a government approval through a relationship

Any one of these is worth pausing the relationship until it's resolved, not proceeding while you look into it further.

Keep the Review Alive After the Contract Is Signed

Vendor vetting isn't a one-time gate. Re-screen periodically, especially for vendors in the highest risk tier, since ownership changes and sanctions lists update. A compliance platform like Vanta or Drata isn't built specifically for vendor screening, but it's useful for the surrounding structure: documenting that the review policy exists, runs on a schedule, and has an owner.

Name one person accountable for the vendor risk program specifically, distinct from whoever owns general procurement, so the review doesn't quietly stop happening once the person who set it up moves on to something else. Tie the re-screen date to the vendor record itself, not to a separate compliance calendar someone has to remember to cross-reference, so a lapsed review is visible the moment someone opens the vendor file.

Train Whoever Actually Onboards New Vendors

A well-designed screening process still fails if the person adding a new vendor to your system doesn't know it exists or thinks it's optional for a small purchase. Walk procurement and finance staff through a real example of a red flag getting caught, not just the policy document, so they recognize the pattern in their own work rather than treating the checklist as a formality to click through.

MeetMyCOO's Olivia, an AI COO, can flag a new vendor that matches a higher-risk profile as it's entered, prompting the full review before a purchase order goes out rather than after.

Executive Capability Standard

What Good Looks Like

Good vendor vetting means every vendor is risk-tiered at intake, screened before signing, and re-screened on a schedule tied to that risk tier, with one person accountable for the program.

Building The Capability (5-Stage Skill Ladder)

1. Learn:Map your current foreign vendors by risk tier based on whether they touch a government official or state-owned entity on your behalf.
2. Do Manually:Run the screening and beneficial ownership checks by hand for your highest-risk vendors first, before building a formal process.
3. Delegate:Assign one owner for the vendor risk program, separate from whoever runs general procurement.
4. Automate:Use a compliance platform to keep the screening schedule and documentation current rather than tracking it in email.
5. Buy:Bring in FCPA counsel to review your contract language and your highest-risk vendor relationships before you scale into a new country.

How to Get Started

Disclosure: We may earn a commission if you buy through some links on this page. It doesn't change what we recommend.

Frequently Asked Questions

Does FCPA liability only apply to payments a company makes directly?

No, and this is the most common misunderstanding. A company can be liable for a payment a third-party vendor or agent makes on its behalf, especially when the company knew or should have known the payment was likely, which is exactly why vendor due diligence matters as much as internal controls.

How often should high-risk vendors be re-screened?

Annually is a common baseline for vendors in the highest risk tier, with an immediate re-screen triggered by a specific event, an ownership change, a new government contract, or adverse media, rather than waiting for the scheduled date.

Is a signed anti-bribery clause enough protection on its own?

It helps, but it's not sufficient by itself. The clause gives you contractual and evidentiary support, but the underlying diligence, screening, beneficial ownership checks, and red flag review, is what actually reduces the risk of a payment happening. Check with your attorney on how the two should work together.

About the numbers

This guide doesn't quote a sourced benchmark. Figures in it are estimates or general guidance, so check them against your own numbers.

Related Guides