← Blog & Resources
FCPA · DOJ2026-05-15·8 min

FCPA enforcement in LATAM: the linguistic signals that raise alarms at the DOJ

Legal notice: This content is educational information about compliance regulation and does not constitute legal advice. Specific requirements vary by jurisdiction, sector and company history. Consult your certified legal advisor before implementing changes. Author: vario editorial team.

The extraterritorial reach of the FCPA

The Foreign Corrupt Practices Act (FCPA) was enacted in 1977, and its extraterritorial enforcement intensified dramatically from the late 2000s onward, through more than a decade of record enforcement.

The statute reaches companies listed on US exchanges (issuers), US persons and entities (domestic concerns), and anyone taking acts in furtherance of a corrupt scheme within US territory. On that basis, the DOJ and the SEC have advanced broad jurisdictional theories: dollar payments cleared through US correspondent banks, or emails routed via US servers, have sufficed as a nexus in several cases, though courts have set limits on the most expansive readings, particularly for foreign nationals acting entirely outside the country.

For Latin American companies with international operations, FCPA risk is not theoretical. Odebrecht pleaded guilty before the DOJ and agreed to a global penalty of USD 2.6 billion split between Brazil, the United States and Switzerland, the largest foreign bribery resolution in history alongside Braskem (roughly USD 93 million went to US authorities, and about 80% of the total to Brazil). SBM Offshore, a Dutch company sanctioned in part for bribes to Petrobras officials, paid USD 238 million to the DOJ. LATAM Airlines paid roughly USD 22 million between the DOJ and the SEC over payments channeled in Argentina through a sham consulting contract. All of these cases grew out of conduct that began as private conversations between executives.

What changed in 2025, and what didn't

In February 2025, an executive order paused FCPA investigations and enforcement actions for 180 days. In June 2025, the Department of Justice issued new guidelines resuming enforcement with more selective priorities: drug cartels and transnational criminal organizations, conduct that harms the competitiveness of US companies, national security and strategic sectors, and serious cases with clear indicia of corrupt intent by individuals. In parallel, low-value courtesies and prolonged corporate investigations without evidence of systemic misconduct were deprioritized.

The result by mid-2026: the DOJ closed roughly half of the FCPA investigations inherited from the prior administration, and the pace of corporate actions dropped noticeably.

The tempting read for a board is that the FCPA has stopped being a problem. That read is dangerous, for four concrete reasons:

  1. Enforcement did not stop, it was redirected. The DOJ itself describes the change as a pivot rather than a retreat, and 2025 saw new corporate actions, including the first corporate FCPA indictment in fifteen years.
  2. Bribery that distorts competition is an explicit priority. A Latin American tender won through improper payments against a US competitor fits precisely the scenario the 2025 guidelines flag as a priority.
  3. Limitation periods outlast a political cycle. The FCPA allows prosecution of conduct up to five years back, extendable to eight in certain accounting-provision scenarios. What is not investigated today can be investigated under the next administration.
  4. The FCPA is not the only exposure. The SEC retains jurisdiction over issuers, and local anti-corruption laws remain fully in force: Lei 12.846 in Brazil, Ley 20.393 and the new economic crimes regime in Chile, Law 27,401 in Argentina.

Betting that the pause is permanent means betting the company on a political cycle.

The linguistic patterns documented in FCPA cases

The statements of facts in resolved cases show something consistent: corrupt conversations rarely use the word "bribe."

Odebrecht is the clearest example. The company ran a Division of Structured Operations, a formal department dedicated to managing improper payments, with a parallel communications system and code names identifying recipients. In the LAN Airlines case, the vehicle was a sham consulting contract that channeled money to third parties.

Drawing on those cases and on the experience of compliance teams across the region, the usual disguises in Spanish-language communications include:

  • "Comisión" or "comisión especial" (commission / special commission): used where no legitimate registered sales agent exists
  • "Gastos de relaciones" or "gastos de protocolo" (relations / protocol expenses): payments to officials presented as entertainment
  • "Honorarios de consultoría" (consulting fees): payments to shell companies controlled by public officials or their relatives
  • "Arreglar el tema" or "destrabar" (sort the issue out / unblock it): referring to regulatory processes or tenders
  • "Facilitación" or "gestión" (facilitation / handling): referring to influencing officials' decisions

High-risk communication patterns

Beyond specific vocabulary, investigations reveal structural patterns that work as red flags:

  1. Sudden channel switch: the conversation moves from corporate email to WhatsApp or Signal. Since 2023, the DOJ's compliance guidance has included a specific section on ephemeral messaging apps: prosecutors assess whether the company preserves those communications, and failing to produce them during an investigation counts against the company when its cooperation is measured.

  2. Instructions to leave no trace: phrases like "let's discuss this in person" or "don't put this in an email" appear repeatedly in the exchanges preceding documented acts of corruption.

  3. Atypical approval circuits: payments that bypass normal expense-approval processes, or contracts that don't follow standard procurement protocols.

  4. Unclear references to third parties: mentions of "the contact," "the minister's friend," or "the person who helps us" without identifying the recipient.

The compliance officer's role in the face of the FCPA

From the DOJ's perspective, having an effective compliance program is one of the factors that most influences the decision to criminally prosecute a company or negotiate a resolution.

The Criminal Division's Evaluation of Corporate Compliance Programs, updated in September 2024, explicitly states that prosecutors will assess whether the program has detection mechanisms that work in practice, not just on paper. That version reinforced three points that matter directly to a CCO:

  • That compliance has access to the same data as the business, and analytics capability over it
  • That the company manages risks arising from artificial intelligence and emerging technologies
  • That real communication-preservation policies exist, including for ephemeral messaging

For the CCO of a company with FCPA exposure, the implication is direct: documented detection capability isn't just an internal tool, it's potentially the most powerful evidence of due diligence in the face of an investigation.

What you should do today

If your company has any nexus with the US (subsidiaries, partners, investors, USD payment processing), exposure remains real, even though the pace of enforcement has changed. The minimum steps:

  1. Map the nexus points: identify every point of contact with FCPA jurisdiction
  2. Review third-party payment processes: especially consultants, agents and intermediaries
  3. Implement targeted training for teams that interact with public officials
  4. Activate communications monitoring in the highest-risk areas: sales, procurement, government relations
  5. Check your preservation policy for corporate messaging, including what happens with ephemeral apps

Want to assess your company's FCPA exposure? Tell us about your case.

Does your company carry this risk?

vario keeps you ahead of signs of collusion and corruption in your corporate communications.

Request a demo