FCPA Compliance for Turkish Companies with U.S. Operations
The Foreign Corrupt Practices Act (FCPA) is one of the most aggressively enforced U.S. laws affecting international business. Turkish companies with U.S. operations, U.S. subsidiaries, or U.S.-listed securities face FCPA jurisdiction — and the consequences of non-compliance can be severe. This guide explains FCPA's reach, its key prohibitions, and the compliance program elements every Turkish company with U.S. exposure needs.
FCPA Compliance for Turkish Companies with U.S. Operations
Introduction
The Foreign Corrupt Practices Act (FCPA) is a U.S. federal law that prohibits bribery of foreign government officials and requires companies to maintain accurate books and records. Enacted in 1977 and significantly strengthened since, the FCPA is enforced jointly by the U.S. Department of Justice (DOJ) and the Securities and Exchange Commission (SEC).
For Turkish companies, the FCPA is not a distant American concern. Any Turkish company that has a U.S. subsidiary, conducts business in the United States, lists securities on a U.S. exchange, or uses U.S. banks or the U.S. financial system in connection with a corrupt payment can face FCPA liability. Penalties — including criminal fines, disgorgement of profits, and deferred prosecution agreements — can be existential for mid-size companies.
This guide explains who is covered, what is prohibited, how enforcement works, and what a FCPA compliance program looks like for a Turkish company with U.S. exposure.
Who Does the FCPA Cover?
Issuers
Companies that have securities registered under the U.S. Securities Exchange Act of 1934 or that are required to file reports with the SEC are issuers under the FCPA. This includes:
- Companies listed on U.S. stock exchanges (NYSE, NASDAQ)
- Companies with American Depositary Receipts (ADRs) traded in the U.S.
- Companies that have issued securities in U.S. public offerings
Turkish companies with U.S.-listed securities or ADR programs are issuers subject to both the anti-bribery provisions and the accounting provisions of the FCPA.
Domestic Concerns
U.S. citizens, nationals, residents, and companies organized under U.S. law are domestic concerns. This includes:
- U.S. subsidiaries of Turkish companies
- U.S. employees of Turkish companies
- U.S. agents acting on behalf of Turkish companies
A Turkish company's U.S. subsidiary is a domestic concern and is directly subject to the FCPA's anti-bribery provisions.
The Territorial Jurisdiction Hook
Even Turkish companies that are neither issuers nor domestic concerns can face FCPA liability if they take any act in furtherance of a corrupt payment while in the territory of the United States. This includes:
- Sending an email through a U.S. server
- Wiring funds through a U.S. correspondent bank
- Attending a meeting in the United States in connection with a corrupt scheme
- Using U.S. cloud services or communications infrastructure
The territorial hook is broad and frequently used by DOJ to assert jurisdiction over foreign companies.
The Two Core Prohibitions
1. The Anti-Bribery Provisions
The FCPA prohibits offering, paying, promising to pay, or authorizing the payment of anything of value to a foreign government official for the purpose of:
- Obtaining or retaining business
- Directing business to any person
- Securing any improper advantage
"Anything of value" is interpreted broadly and includes:
- Cash payments
- Gifts (including luxury goods, entertainment, travel)
- Meals and hospitality
- Charitable donations made at an official's request
- Employment offers for officials' family members
- Discounts, rebates, or favorable contract terms
"Foreign government official" includes:
- Employees of foreign governments at any level (national, regional, local)
- Employees of state-owned enterprises (SOEs) — this is critical for Turkish companies operating in countries with significant state ownership
- Officials of international organizations (UN, World Bank, IMF)
- Political party officials and candidates for office
The SOE issue for Turkish companies: Many Turkish companies operate in markets — including Turkey itself, Central Asia, the Middle East, and Africa — where significant industries are state-owned. Payments to employees of state-owned banks, energy companies, telecommunications providers, or construction authorities can constitute FCPA violations if made to obtain or retain business.
2. The Accounting Provisions
The accounting provisions apply only to issuers (companies with U.S.-listed securities). They require issuers to:
Books and records: Make and keep books, records, and accounts that accurately and fairly reflect transactions and dispositions of assets. This means:
- No off-the-books accounts
- No falsely recorded transactions
- No mischaracterized payments (e.g., recording a bribe as a "consulting fee")
Internal controls: Devise and maintain a system of internal accounting controls sufficient to provide reasonable assurances that:
- Transactions are executed in accordance with management's authorization
- Transactions are recorded as necessary to permit preparation of financial statements
- Access to assets is permitted only in accordance with management's authorization
The accounting provisions are significant because they can be violated even without a corrupt payment. Inaccurate books or weak internal controls — even if no bribe was paid — can constitute an FCPA violation for issuers.
Key Exceptions and Affirmative Defenses
Facilitating Payments Exception
The FCPA contains a narrow exception for facilitating payments — small payments to low-level government officials to expedite or secure the performance of a routine governmental action (e.g., processing a visa, clearing customs, providing utility connections). This exception:
- Applies only to routine, non-discretionary actions
- Does not apply to payments to obtain or retain business
- Is narrow and frequently misunderstood — many companies have faced enforcement actions for payments they believed were facilitating payments
Important: The UK Bribery Act (which applies to companies with UK operations) has no facilitating payments exception. Turkish companies with both U.S. and UK exposure must comply with the stricter UK standard.
Affirmative Defenses
The FCPA provides two affirmative defenses:
Local law defense: The payment was lawful under the written laws of the foreign country. This defense is rarely available in practice because most countries have anti-bribery laws on the books.
Reasonable and bona fide business expenditure: The payment was a reasonable and bona fide expenditure (such as travel and lodging) directly related to the promotion, demonstration, or explanation of products or services, or the execution or performance of a contract. This defense covers legitimate business hospitality but requires documentation.
FCPA Enforcement: How It Works
Joint DOJ/SEC Enforcement
The DOJ has criminal enforcement authority over the FCPA's anti-bribery provisions. The SEC has civil enforcement authority over issuers for both the anti-bribery and accounting provisions.
Enforcement Trends
FCPA enforcement has been consistently active:
- Corporate resolutions: DOJ and SEC regularly resolve FCPA cases through deferred prosecution agreements (DPAs), non-prosecution agreements (NPAs), and guilty pleas
- Individual prosecutions: DOJ increasingly prosecutes individual executives, not just companies
- International cooperation: DOJ and SEC cooperate with foreign law enforcement agencies, including Turkish authorities, in cross-border investigations
- Self-disclosure: Companies that voluntarily disclose FCPA violations, cooperate with investigations, and remediate receive significantly reduced penalties
Penalties
FCPA penalties can be severe:
- Criminal fines: Up to $2 million per violation for companies; up to $250,000 per violation for individuals
- Alternative fines: Courts can impose fines up to twice the gross gain or gross loss from the violation
- Disgorgement: Companies must disgorge profits obtained through corrupt conduct
- Debarment: Companies can be debarred from U.S. government contracting
- Reputational damage: FCPA resolutions are public and can damage business relationships, financing access, and customer trust
Building an FCPA Compliance Program
The DOJ and SEC have published guidance (the "FCPA Resource Guide") identifying the hallmarks of an effective compliance program. For Turkish companies with U.S. exposure, the following elements are essential:
1. Tone at the Top
Senior management — including the CEO, CFO, and board — must visibly and consistently communicate commitment to FCPA compliance. A compliance program that exists on paper but is not supported by leadership will not withstand DOJ/SEC scrutiny.
2. Written Policies and Procedures
The company should have written anti-corruption policies that:
- Prohibit bribery of foreign government officials
- Define "foreign government official" broadly (including SOE employees)
- Address gifts, entertainment, travel, and hospitality with clear approval thresholds
- Cover charitable donations and political contributions
- Address third-party relationships (agents, distributors, joint venture partners)
3. Risk Assessment
FCPA risk varies significantly by geography, industry, and business model. Turkish companies should conduct a formal risk assessment that identifies:
- Countries where the company operates and their corruption risk levels
- Interactions with foreign government officials (including SOE employees)
- Third parties who interact with government officials on the company's behalf
- High-risk transactions (government contracts, licenses, permits, customs)
4. Third-Party Due Diligence
The majority of FCPA enforcement actions involve payments made through third parties — agents, distributors, consultants, and joint venture partners. Turkish companies must:
- Conduct due diligence on third parties before engagement
- Include FCPA representations and warranties in third-party contracts
- Monitor third-party relationships on an ongoing basis
- Terminate relationships with third parties who present unacceptable corruption risk
5. Training
All employees who interact with government officials or third parties — and all senior management — should receive regular FCPA training. Training should be:
- Tailored to the employee's role and risk level
- Conducted in the employee's language (Turkish and English for Turkish companies)
- Documented with attendance records
6. Reporting Mechanisms
The company should have a confidential reporting mechanism (hotline, email, or web portal) that allows employees to report suspected FCPA violations without fear of retaliation. Reports should be investigated promptly and thoroughly.
7. Internal Controls and Accounting
For issuers, the accounting provisions require robust internal controls. For all companies, strong financial controls reduce the risk of off-books payments:
- Segregation of duties in payment approval
- Documentation requirements for all payments to government officials or third parties
- Regular internal audits of high-risk transactions
8. Mergers and Acquisitions Due Diligence
FCPA liability can be inherited through acquisitions. Turkish companies acquiring U.S. businesses — or businesses that operate in high-risk markets — should conduct FCPA due diligence as part of the M&A process and implement remediation plans for identified issues before or promptly after closing.
Practical Guidance for Turkish Companies
Common Risk Scenarios
Government contracts: Turkish companies pursuing U.S. government contracts or contracts in foreign markets through U.S.-connected entities face heightened FCPA risk. All interactions with procurement officials should be documented.
Customs and import/export: Payments to customs officials to expedite clearance are a common FCPA risk area. Turkish companies should have clear policies prohibiting such payments and alternative procedures for addressing customs delays.
Licensing and permits: Obtaining business licenses, construction permits, or regulatory approvals in high-risk markets often involves interactions with government officials. These interactions should be documented and conducted through proper channels.
State-owned enterprise customers: Turkish companies that sell to SOEs — including state-owned banks, energy companies, or infrastructure operators — must treat SOE employees as "foreign government officials" for FCPA purposes.
When to Seek Legal Counsel
Turkish companies should consult U.S. FCPA counsel when:
- Entering a new market with significant corruption risk
- Engaging a new agent, distributor, or consultant who will interact with government officials
- Receiving a government subpoena, civil investigative demand, or informal inquiry from DOJ or SEC
- Discovering a potential FCPA violation through internal audit or employee report
- Conducting M&A due diligence on a target with government-facing operations
Conclusion
The FCPA is a significant compliance obligation for Turkish companies with U.S. operations, U.S.-listed securities, or business activities that touch the U.S. financial system. The jurisdictional reach is broad, enforcement is active, and penalties can be severe.
An effective FCPA compliance program — built on clear policies, risk-based due diligence, training, and strong internal controls — is the best protection against enforcement risk and the foundation of sustainable international business.
ULF New York advises Turkish companies on FCPA compliance program design, third-party due diligence, M&A anti-corruption due diligence, and government investigations. Contact us to assess your company's FCPA exposure and compliance posture.
This article is for informational purposes only and does not constitute legal advice. FCPA enforcement priorities and guidance are subject to change; consult qualified U.S. counsel for advice specific to your situation.
Explore Topics
Written by
ULF New York Editorial Team
ULF New York legal team — New York-based attorneys advising Turkish companies and investors on U.S. market entry, corporate law, real estate, and international trade.