Global Advice Network | Borgergade 111 | DK - 1300 Copenhagen K
E-Mail: info@business-anti-corruption.org | Phone: (+45) 60 88 10 44

Responding to an SEC or DOJ Subpoena in an FCPA Investigation

Receiving a subpoena from the U.S. Securities and Exchange Commission (SEC) or Department of Justice (DOJ) signals a formal investigation into possible violations of the Foreign Corrupt Practices Act (FCPA). The request may concern payments to foreign officials, third-party relationships, books and records, internal controls, gifts and hospitality, charitable contributions, or the conduct of a particular employee or business partner.

A subpoena is legally enforceable, but it is not a finding of wrongdoing. The company’s first response can significantly affect the investigation’s cost, duration, and outcome. A rushed production, incomplete preservation effort, or poorly coordinated employee interview may create additional exposure even when the original concern was limited.

Companies should treat the document as both a legal obligation and an operational risk event. The appropriate response combines experienced counsel, disciplined evidence management, careful communication with regulators, and a fact-based assessment of whether voluntary disclosure or other cooperation is warranted.

Confirm the Request and Form a Response Team

Start by authenticating the subpoena and recording the date, issuing authority, response deadline, service method, and named recipient. Review every definition, instruction, schedule, and time period. Terms such as “related to,” “communications,” “agent,” or “foreign official” can expand the scope considerably. Identify whether the demand seeks documents, testimony, electronically stored information, or a combination of these.

The general counsel or designated legal leader should appoint a central response team immediately. It commonly includes outside FCPA counsel, internal legal staff, compliance, information technology, records management, finance, human resources, and senior representatives from affected business units. A single project manager should maintain the response calendar, decision log, custodian list, and record of communications with the SEC or DOJ.

Do not assume that the subpoena’s recipient is the only relevant entity. A parent company, subsidiary, joint venture, distributor, or former affiliate may possess important records. Counsel should also assess whether the company has obligations to disclose the investigation to its audit committee, board, insurers, lenders, stock exchange, or other regulators.

Preserve Documents and Protect Privilege

Issue a written legal hold as soon as counsel identifies a reasonable possibility that relevant information may be lost. The hold should describe the subject matter in accessible language, identify likely custodians and systems, suspend routine deletion, and explain how employees must preserve email, messaging applications, files, paper records, expense reports, and mobile-device data.

Preservation must cover more than corporate email. FCPA investigations often involve personal devices, collaboration platforms, text messages, instant messaging, travel and expense systems, procurement databases, customer relationship management tools, accounting records, and third-party portals. IT should document preservation steps and verify that automated deletion policies have been paused where necessary.

The company should distinguish privileged legal advice from ordinary business records. Marking every investigation document “privileged” does not create privilege, and careless circulation can waive it. Counsel should establish secure channels for legal advice, control interview memoranda, limit distribution of investigative findings, and explain to employees that the company’s attorney-client privilege may belong to the company rather than to individual employees.

A preservation failure can be more damaging than an unfavorable document. Employees must not delete, edit, backdate, conceal, or recreate records. Managers should avoid directing staff to discuss the matter through informal channels or to use personal accounts to evade collection.

Build a Defensible Review and Production Plan

Before collecting millions of files, map the subpoena to the company’s information environment. For each request, identify relevant custodians, systems, date ranges, languages, jurisdictions, file types, and likely search terms. Create a document matrix showing the request, responsive sources, responsible owner, collection status, review status, and production decision.

The response team should agree with the SEC or DOJ on practical issues where appropriate. These may include rolling productions, electronic formats, metadata, search methodology, confidentiality designations, translations, custodial limits, and reasonable extensions. Early dialogue can prevent disputes, but communications with the government should be coordinated through counsel and documented carefully.

Response stage Primary objective Typical controls Common failure
Initial assessment Understand legal scope and deadlines Counsel review, issue log, executive escalation Treating the subpoena as a routine records request
Preservation Prevent loss or alteration of evidence Legal hold, system suspension, custodian notices Ignoring mobile devices or third-party platforms
Collection Gather potentially responsive material Forensic methods, chain-of-custody records Relying on informal employee searches
Review Determine responsiveness, privilege, and sensitivity Review protocols, quality checks, escalation rules Producing privileged or irrelevant material
Production Meet the request accurately and securely Agreed format, rolling schedule, production log Missing categories or inconsistent explanations
Remediation Address control weaknesses and recurrence risk Root-cause analysis, training, monitoring Closing the matter without fixing underlying risks

Review protocols should account for foreign languages, local privacy rules, data localization requirements, employment restrictions, and cross-border transfer laws. A U.S. subpoena does not automatically eliminate obligations under the laws of the country where information or employees are located. Local counsel and qualified forensic providers may be needed before transferring data to the United States.

Quality assurance is essential. A second-level review should test privilege calls, responsiveness decisions, redactions, translations, and production completeness. Keep a defensible record of collection methods, search terms, excluded sources, withheld documents, and the reasons for each material judgment.

Investigate the Underlying FCPA Risk

A subpoena response should not be limited to finding documents named in the request. Counsel should conduct a targeted internal investigation to understand what happened, who knew about it, and whether the conduct reflects an isolated event or a broader control failure. Potential subjects include payments routed through consultants, unusual commissions, charitable donations connected to officials, excessive hospitality, customs facilitation, licensing support, and government tender activity.

The investigation should test both FCPA provisions. The anti-bribery provisions address corrupt offers, promises, authorization, or payments involving foreign officials, while the accounting provisions require accurate books and records and reasonable internal accounting controls. A payment may create accounting exposure even where evidence of an improper intent is incomplete.

Third parties require close attention. Review due diligence files, beneficial ownership information, contract terms, compensation, invoices, bank details, approval records, and the services allegedly performed. Compare the intermediary’s compensation with market conditions and examine whether the company ignored red flags, bypassed approval procedures, or continued the relationship after concerns arose.

Business teams involved in public procurement should receive particular scrutiny. Records concerning bid consultants, local partners, agents, politically connected individuals, tender access, and success fees may reveal weaknesses in the company’s compliance framework. Practical resources such as this guidance on government tenders can help compliance teams identify corruption risks in procurement processes.

Manage Interviews and Government Cooperation

Employee interviews should be planned rather than improvised. Counsel should determine the purpose of each interview, review available documents in advance, identify conflicts of interest, and decide whether separate counsel is appropriate. At the start of an interview, counsel should provide an accurate explanation of the company’s representation and any applicable privilege principles.

Interview notes should distinguish verified facts, recollections, assumptions, and unanswered questions. Employees should be instructed to preserve records and avoid discussing confidential investigative matters beyond authorized channels. Retaliation against whistleblowers, witnesses, or employees who cooperate with investigators can create separate legal and reputational problems.

Cooperation with the SEC or DOJ is a strategic decision, not an automatic surrender of the company’s rights. Counsel should evaluate the benefits and risks of voluntary disclosure, the reliability of current facts, the possibility of parallel investigations, and the company’s ability to describe the conduct accurately. Overstating cooperation or presenting preliminary theories as established facts can undermine credibility.

The company should designate a small number of spokespersons for government communications. Responses must be truthful, complete within the agreed scope, and consistent across submissions, interviews, financial disclosures, and internal updates. If facts change, counsel should determine promptly whether a correction or supplemental disclosure is necessary.

Coordinate Parallel Legal and Business Risks

An FCPA subpoena may trigger related inquiries by other U.S. agencies, foreign enforcement authorities, tax regulators, competition agencies, or prosecutors in countries where the conduct occurred. It may also lead to shareholder claims, employee disputes, contract termination, debarment concerns, lender notifications, or accounting and audit issues.

Create a privilege-sensitive risk map that records each potential proceeding, applicable deadlines, responsible counsel, information-sharing restrictions, and interactions among investigations. Separate legal analysis from public relations planning, but ensure that both are based on the same verified facts. Public statements should be carefully reviewed so they do not prejudice the investigation or contradict a regulatory submission.

The company should also assess operational continuity. Suspending a questionable distributor, consultant, or payment channel may affect customers and government contracts, but allowing a risky arrangement to continue can increase exposure. Interim controls might include enhanced approval, payment holds, independent verification of services, restricted system access, or temporary reassignment of decision-making authority.

Data protection deserves attention throughout the process. Collect only what is reasonably necessary, secure sensitive personal information, document cross-border transfers, and apply appropriate access controls. FCPA evidence can include passport information, bank details, health data in expense records, and private communications. Regulatory urgency does not justify careless handling.

Turn Findings Into Lasting Controls

When the facts are sufficiently developed, management and the board should decide whether remediation is required. Effective remediation addresses the root cause rather than merely disciplining an individual. It may involve redesigning approval workflows, improving third-party due diligence, strengthening payment controls, separating sales and compliance authority, or adding monitoring in high-risk markets.

Use the investigation to test whether written policies operate in practice. A code of conduct may prohibit bribery, yet employees may still face pressure to use poorly screened agents, pay unexplained “administrative” fees, or meet unrealistic sales targets. Compliance training should be tailored to these situations and delivered in relevant languages to the employees and partners who face them.

The Business Anti-Corruption Portal offers country risk profiles, compliance resources, training materials, and due diligence information that can support a broader review of market-level risks. These tools are most useful when integrated into business decisions, rather than treated as a standalone annual compliance exercise.

After production, preserve the investigation file, production logs, interview records, remediation evidence, and communications with regulators according to a documented retention schedule. Track whether corrective actions were completed and test their effectiveness over time. A regulator is more likely to view the response favorably when the company can demonstrate measurable improvements rather than promises alone.

Practical Rules for a Disciplined Response

  • Put experienced counsel in charge before employees begin collecting or discussing responsive material.
  • Preserve email, messaging, mobile-device, accounting, procurement, and third-party records immediately.
  • Use a written request matrix and production log to monitor scope, deadlines, privilege, and completeness.
  • Investigate the underlying conduct and control environment, not just the documents expressly named.
  • Record remediation steps, ownership, deadlines, and testing results so improvements can be demonstrated.

A subpoena demands urgency, but urgency should produce organization rather than panic. The company’s strongest position comes from preserving evidence early, understanding the facts independently, communicating with regulators carefully, and making decisions that account for privilege, data protection, financial reporting, and business continuity.

Senior management should activate the response team, brief the appropriate board or audit committee members, and establish a documented investigation and remediation program without delay. A disciplined response can meet the government’s demands while giving the company a clearer path to resolve the inquiry and strengthen its anti-corruption controls.

copyright © Global Advice Network