Skip to main content
DOJ Resources Are Down? Five Myths About What That Means for Your Anti-Corruption ProgramEnforcement & Penalties
5 min readFor AML Compliance Officers

DOJ Resources Are Down? Five Myths About What That Means for Your Anti-Corruption Program

You've heard it: DOJ anti-corruption resources are scaling back. Presidential pardons in bribery cases are making headlines. Compliance teams are questioning what this means for their Foreign Corrupt Practices Act (FCPA) programs.

The answer isn't what most assume.

When enforcement signals shift, myths fill the vacuum. Some compliance officers think reduced resources mean reduced risk. Others believe political interference makes anti-corruption work optional. Both assumptions are wrong, and acting on them puts your institution in jeopardy.

These myths persist because they're comforting. They suggest you can do less. But the reality is more complex and demands smarter, not lighter, compliance strategies.

Myth 1: Fewer DOJ Resources Mean Fewer Enforcement Actions

Reality: Resource constraints change enforcement patterns, not enforcement appetite.

When the DOJ scales back anti-corruption resources, prosecutors don't stop pursuing cases. They become more selective, focusing on egregious violations, repeat offenders, and cases with clear evidence trails.

Here's what changes: The DOJ will prioritize cases where your institution ignored red flags, failed to remediate known issues, or demonstrated a pattern of misconduct. They'll target low-hanging fruit with high impact. If your controls are weak and your documentation is sloppy, you're exactly the target a resource-constrained prosecutor wants.

What doesn't change: The FCPA remains on the books. The statute of limitations still runs five years. And foreign regulators, particularly the UK's Serious Fraud Office and authorities in France, Germany, and Brazil, are expanding their own anti-corruption enforcement.

Myth 2: Presidential Pardons Make Anti-Corruption Compliance Less Important

Reality: Pardons affect individual defendants, not institutional liability or civil exposure.

Presidential pardons in bribery cases create headlines, but they don't erase your institution's compliance obligations. A pardon may release an individual from criminal penalties, but it doesn't protect your bank from:

  • Civil enforcement actions by the Securities and Exchange Commission
  • Parallel proceedings by financial regulators (FinCEN, OCC, Federal Reserve)
  • Reputational damage that triggers customer attrition and investor scrutiny
  • Correspondent banking relationship terminations
  • Enforcement by foreign jurisdictions where you operate

Consider what happens when a pardoned executive's conduct becomes public. Your board still answers to shareholders. Your compliance program still gets examined during your next regulatory exam. And your counterparties still reassess whether they want to do business with you.

Pardons create political noise. They don't create a compliance safe harbor.

Myth 3: "Deregulation" Means You Can Relax Your Anti-Corruption Controls

Reality: Deregulation pressures and compliance obligations operate on different timelines and authorities.

Calls to ease "de-banking" practices and reduce compliance burdens are not permission to loosen anti-corruption due diligence.

Deregulation discussions typically focus on Customer Due Diligence requirements under the Bank Secrecy Act, access to banking services, and the scope of enhanced due diligence triggers. These are separate from your FCPA obligations, which are criminal statutes enforced by the DOJ and civil provisions enforced by the SEC.

Even if BSA regulations change, your duty to prevent bribery of foreign officials doesn't. Your requirement to maintain accurate books and records under the FCPA's accounting provisions doesn't. And your exposure under the UK Bribery Act (if you operate there) definitely doesn't.

Deregulation might change how you onboard customers. It won't change your liability when a customer uses your platform to pay bribes.

Myth 4: Global Banks Face More Risk Than Regional Institutions

Reality: Your risk profile depends on your customer base and transaction patterns, not your asset size.

Small and mid-sized institutions often assume anti-corruption enforcement targets only global banks with international operations. That assumption is dangerous.

You're exposed if you:

  • Process wire transfers for customers doing business in high-risk jurisdictions
  • Bank trade finance companies, particularly those importing from or exporting to countries with elevated corruption risk
  • Serve as a correspondent bank for foreign financial institutions
  • Provide services to government contractors or companies in extractive industries

A regional bank processing payments for a construction company bidding on foreign infrastructure projects carries meaningful FCPA risk. So does a fintech facilitating cross-border payments for e-commerce merchants selling to government procurement portals.

The question isn't whether you operate internationally. It's whether your customers do, and whether you've designed controls to detect when their transactions involve potential bribery.

Myth 5: You Can Outsource Anti-Corruption Risk to Your Vendors

Reality: Third-party due diligence is your obligation, not your vendor's.

Some institutions believe that hiring a due diligence vendor or a screening service transfers their anti-corruption compliance responsibility. It doesn't.

When a third party you engage pays bribes on your behalf, you own the FCPA violation. The DOJ will examine:

  • Whether you conducted risk-based due diligence before engaging the third party
  • Whether your contract included anti-corruption representations and audit rights
  • Whether you monitored the relationship for red flags
  • Whether you investigated and remediated when issues surfaced

Vendors provide tools and information. You provide judgment. A screening report that flags a politically exposed person means nothing if you don't assess the nature of the relationship and the transaction purpose. A clean background check means nothing if you ignore subsequent red flags.

The compliance decision remains yours, and so does the liability.

What to Do Instead

Stop treating reduced enforcement resources as a signal to pull back. Treat them as a reason to get sharper.

Focus your program on these priorities:

Document your risk assessment. When enforcement does come, prosecutors will ask why you allocated resources the way you did. A written, board-approved risk assessment that ties controls to specific risks is your first line of defense.

Investigate red flags promptly. Resource-constrained regulators love cases where the institution saw the problem and did nothing. Timely investigation and remediation demonstrate good faith.

Train on real scenarios. Generic anti-corruption training doesn't work. Train your relationship managers and trade finance teams on the specific red flags they'll encounter in their roles: unusual payment routing, requests to pay third parties, vague invoices from consulting firms.

Test your controls. Run transaction samples through your monitoring rules. Review third-party due diligence files. Audit your gift and hospitality logs. Find your gaps before a regulator does.

Coordinate with sanctions and AML teams. Anti-corruption risk rarely appears in isolation. The customer evading sanctions might also be paying bribes. The shell company layering funds might be hiding procurement fraud. Your controls should connect these dots.

The enforcement landscape is shifting. Your obligation to prevent bribery isn't. Build a program that holds up regardless of who's running the DOJ.

You Might Also Like