US Anti-Bribery and FCPA Compliance for Turkish Companies 2026: Risks, Requirements, and Best Practices
The US Foreign Corrupt Practices Act (FCPA) has broad extraterritorial reach and applies to Turkish companies with US operations, US-listed securities, or US business partners. FCPA violations carry severe criminal and civil penalties. This guide explains FCPA exposure for Turkish companies and how to build an effective compliance program.
US Anti-Bribery and FCPA Compliance for Turkish Companies 2026: Risks, Requirements, and Best Practices
The Foreign Corrupt Practices Act (FCPA) is one of the most aggressively enforced US laws with extraterritorial reach. Turkish companies that have US operations, US-listed securities, or conduct business through US persons or US territory can face FCPA liability for corrupt payments made anywhere in the world. Understanding FCPA exposure and implementing an effective compliance program is essential for Turkish companies with any US nexus.
What is the FCPA?
The FCPA, enacted in 1977 and significantly amended in 1988 and 1998, has two main components:
Anti-Bribery Provisions
Prohibit US persons, US companies, and certain foreign companies from paying, offering, or authorizing corrupt payments to foreign government officials to obtain or retain business.
Accounting Provisions
Require companies with US-listed securities to:
- Maintain books and records that accurately reflect transactions
- Maintain a system of internal accounting controls
The accounting provisions apply to all transactions — not just those involving bribery — and can be violated even without a corrupt payment.
Who is Subject to the FCPA?
Issuers
Companies with securities listed on US exchanges (NYSE, Nasdaq) or required to file reports with the SEC. This includes Turkish companies that are US-listed or have US-registered securities.
Domestic Concerns
US citizens, nationals, residents, and companies organized under US law — including US subsidiaries of Turkish companies.
Foreign Nationals and Companies (Territorial Jurisdiction)
Foreign companies and individuals who take any act in furtherance of a corrupt payment while in US territory — including using US banks, email servers, or other US infrastructure.
Key FCPA Concepts
"Foreign Government Official"
The FCPA broadly defines foreign government officials to include:
- Employees of foreign governments at any level
- Employees of state-owned or state-controlled enterprises (SOEs)
- Employees of public international organizations
- Foreign political party officials and candidates
Significance for Turkish companies: Many Turkish companies do business with Turkish government entities, municipalities, and state-owned enterprises. Payments to employees of these entities — even if characterized as "commissions" or "consulting fees" — can constitute FCPA violations.
"Corrupt Intent"
The payment must be made with corrupt intent — to influence the official's actions or decisions in their official capacity. The FCPA does not require proof that the payment actually influenced the official.
"To Obtain or Retain Business"
The corrupt payment must be made to obtain or retain business, or to direct business to any person. This is broadly interpreted.
Facilitating Payments Exception
The FCPA has a narrow exception for "facilitating payments" — small payments to low-level government officials to expedite routine government actions (issuing permits, processing visas, providing utilities). This exception is narrow and frequently misunderstood; it does not cover payments to obtain favorable decisions.
Affirmative Defenses
- Local law defense: The payment was lawful under the written laws of the foreign country
- Reasonable and bona fide expenditure: The payment was a reasonable and bona fide expenditure (travel, lodging, meals) directly related to the promotion of products or services, or the execution of a contract
Third-Party Risk: The Most Common FCPA Exposure
The most common source of FCPA liability for Turkish companies is not direct payments to government officials — it is payments made through third parties (agents, distributors, consultants, joint venture partners) who then make corrupt payments on the company's behalf.
Third-Party Due Diligence
Turkish companies must conduct meaningful due diligence on third parties who interact with foreign government officials on their behalf:
- Identify red flags: Unusual payment requests, requests for cash payments, lack of legitimate business purpose, connections to government officials
- Background checks: Verify the third party's identity, reputation, and business legitimacy
- Contractual protections: Include FCPA compliance representations, audit rights, and termination rights in third-party agreements
- Ongoing monitoring: Monitor third-party relationships for changes in circumstances
Building an Effective FCPA Compliance Program
The DOJ and SEC evaluate the effectiveness of a company's compliance program when determining whether to prosecute and what penalties to impose. Key elements of an effective program:
Tone at the Top
Senior management must demonstrate genuine commitment to compliance. A compliance program that exists only on paper — without genuine support from leadership — will not satisfy regulators.
Risk Assessment
Conduct a periodic FCPA risk assessment to identify:
- High-risk markets and business activities
- High-risk third-party relationships
- Gaps in existing controls
Policies and Procedures
Written policies covering:
- Prohibition on corrupt payments
- Gifts, hospitality, and entertainment limits
- Political contributions
- Third-party due diligence requirements
- Books and records requirements
Training
Regular FCPA training for employees who interact with government officials or manage third-party relationships. Training should be tailored to the specific risks of each employee's role.
Internal Reporting
Anonymous reporting mechanisms (hotlines) for employees to report suspected violations without fear of retaliation.
Monitoring and Auditing
Periodic audits of high-risk transactions and third-party payments to detect potential violations.
Remediation
Prompt investigation and remediation of potential violations. Self-disclosure to the DOJ/SEC can significantly reduce penalties.
FCPA Penalties
FCPA violations carry severe penalties:
- Criminal fines: Up to $2 million per violation for companies; up to $250,000 per violation for individuals
- Civil penalties: Up to $21,410 per violation
- Disgorgement: Forfeiture of profits derived from the violation
- Deferred prosecution agreements (DPAs): Companies often resolve FCPA investigations through DPAs, which require compliance improvements and monitoring
- Individual prosecution: Senior executives can face personal criminal liability
How ULF New York Can Help
Our compliance attorneys advise Turkish companies on FCPA risk assessment, compliance program design, third-party due diligence, internal investigations, and DOJ/SEC engagement. We help Turkish companies build compliance programs that are proportionate to their risk profile and satisfy regulatory expectations.
This article is for informational purposes only and does not constitute legal advice. FCPA compliance is complex and fact-specific; please consult qualified compliance counsel for advice specific to your situation.
Explore Topics
Written by
ULF New York Editorial Team
ULF New York legal team — New York-based attorneys advising Turkish companies and investors on U.S. market entry, corporate law, real estate, and international trade.