Vetting Foreign Vendors Without Creating FCPA Exposure
The FCPA violation that actually gets a company in trouble is rarely a direct bribe paid by an executive. It's a payment made by a foreign vendor, agent, or distributor, on the company's behalf, that the company didn't authorize directly but is still liable for because it didn't do the diligence to know who it was working with.
Vendor vetting is the control that catches this before the relationship starts, not after a payment already looks suspicious. It doesn't need to be complicated to be effective, but it does need to happen consistently, not just for the vendors that feel risky on gut instinct.
Vendors Covered in this Article
Disclosure: We may earn a commission if you buy through some links on this page. It doesn't change what we recommend.
Which foreign vendors need a full FCPA review?
Not every foreign vendor carries the same risk. The review should scale up for vendors who interact with government officials on your behalf, customs brokers, permit facilitators, government sales agents, and scale down for a vendor who simply sells you a commodity product with no government touchpoint. Sorting vendors into a risk tier at intake saves you from either skipping real risk or burning review time on low-risk purchases.
Build the tiering question into your procurement intake form itself: does this vendor interact with any government official or state-owned entity on our behalf. A yes routes to full review automatically.
When should you screen a foreign vendor for FCPA risk?
Screen for sanctions list matches, adverse media, and beneficial ownership before signing, not as a formality after the relationship is already operating. Beneficial ownership matters specifically because a vendor can look clean on paper while being owned or controlled by a government official or their family member, which is exactly the structure enforcement actions target most often.
Document the screening result and the date it was run, since the value of a screen is proving you did it at the time, not just that you would have passed one if asked.
Put Anti-Bribery Language in the Contract, Not Just the Policy
A code of conduct the vendor never reads does less work than a specific anti-bribery clause in the signed contract: representations that the vendor won't make improper payments on your behalf, an audit right, and a termination right if the representation turns out false. This gives you a contractual basis to act, not just a policy violation, if a problem surfaces later.
Have counsel confirm the clause is enforceable under the vendor's local contract law, since some standard anti-bribery language doesn't translate cleanly into every jurisdiction's contract enforcement.
Red Flags That Should Stop the Relationship, Not Just Slow It Down
A few patterns that warrant a hard stop rather than a caveat:
- A request to pay an unusually large commission or fee relative to the service, with no clear justification
- Reluctance to sign an anti-bribery representation or to disclose beneficial ownership
- A request to route payment through a third country or a personal account instead of the vendor's business account
- Specific, unsolicited claims that the vendor can expedite a government approval through a relationship
Any one of these is worth pausing the relationship until it's resolved, not proceeding while you look into it further.
Keep the Review Alive After the Contract Is Signed
Vendor vetting isn't a one-time gate. Re-screen periodically, especially for vendors in the highest risk tier, since ownership changes and sanctions lists update. A compliance platform like Vanta or Drata isn't built specifically for vendor screening, but it's useful for the surrounding structure: documenting that the review policy exists, runs on a schedule, and has an owner.
Name one person accountable for the vendor risk program specifically, distinct from whoever owns general procurement, so the review doesn't quietly stop happening once the person who set it up moves on to something else. Tie the re-screen date to the vendor record itself, not to a separate compliance calendar someone has to remember to cross-reference, so a lapsed review is visible the moment someone opens the vendor file.
Train Whoever Actually Onboards New Vendors
A well-designed screening process still fails if the person adding a new vendor to your system doesn't know it exists or thinks it's optional for a small purchase. Walk procurement and finance staff through a real example of a red flag getting caught, not just the policy document, so they recognize the pattern in their own work rather than treating the checklist as a formality to click through.
MeetMyCOO's Olivia, an AI COO, can flag a new vendor that matches a higher-risk profile as it's entered, prompting the full review before a purchase order goes out rather than after.
What Good Looks Like
Good vendor vetting means every vendor is risk-tiered at intake, screened before signing, and re-screened on a schedule tied to that risk tier, with one person accountable for the program.
Building The Capability (5-Stage Skill Ladder)
How to Get Started
Disclosure: We may earn a commission if you buy through some links on this page. It doesn't change what we recommend.
Frequently Asked Questions
Does FCPA liability only apply to payments a company makes directly?
No, and this is the most common misunderstanding. A company can be liable for a payment a third-party vendor or agent makes on its behalf, especially when the company knew or should have known the payment was likely, which is exactly why vendor due diligence matters as much as internal controls.
How often should high-risk vendors be re-screened?
Annually is a common baseline for vendors in the highest risk tier, with an immediate re-screen triggered by a specific event, an ownership change, a new government contract, or adverse media, rather than waiting for the scheduled date.
Is a signed anti-bribery clause enough protection on its own?
It helps, but it's not sufficient by itself. The clause gives you contractual and evidentiary support, but the underlying diligence, screening, beneficial ownership checks, and red flag review, is what actually reduces the risk of a payment happening. Check with your attorney on how the two should work together.
About the numbers
This guide doesn't quote a sourced benchmark. Figures in it are estimates or general guidance, so check them against your own numbers.
Related Guides
Vendor Onboarding Checklist: Vetting a New Supplier
How to onboard a new vendor: tier the risk, collect the right documents, verify payment details, set up the record, and review the vendor after 90 days.
Granting Equity to International Hires Without a Tax Mess
A step-by-step look at granting stock options to employees outside the US: why the default US plan doesn't travel, and what to check before you extend it.
Structuring Split Payroll for Executives Working Across Borders
How split payroll and dual employment contracts work for executives dividing time between countries, and where the structure commonly breaks down.
What Happens to Employees in a European Acquisition
A step-by-step look at what TUPE-style automatic transfer rules mean for employees when a UK or European business is acquired, and what buyers need to check.
Using Standard Contractual Clauses to Move EU Data to the US
How Standard Contractual Clauses work for transferring EU customer or employee data to the US, and what a transfer impact assessment actually requires.
PEO, EOR, or Your Own Entity: Choosing the Right Structure
A decision framework for choosing between a PEO, an EOR, or opening your own foreign subsidiary, built around headcount, control, and how long you plan to stay.