Skip to main content
A gavel sitting on a desk in front of scales of justice.

Beyond Compliance: Rethinking Fraud & Corruption Risk

See why enforcement trends demand a shift from program design to real-world effectiveness.

Compliance programs have come a long way. Most organizations now have policies, training, and third-party due diligence in place. On paper, frameworks are stronger than they were a decade ago. Yet enforcement outcomes tell a different story.

Insights from our analysis of 99 Foreign Corrupt Practices Act (FCPA) enforcement actions, shared during our webinar, “A Decade of FCPA Enforcement: Lessons for Corporate Counsel,” point to a persistent gap between how programs are designed and how they operate under pressure. Regulators are asking a simpler question. Not whether the program exists, but whether it works when it matters.

From Design to Reality

For years, organizations invested in building comprehensive compliance structures. That work is still important, but it’s no longer enough.

Enforcement decisions are shaped by what happens after an issue surfaces. Investigations must move quickly. Evidence needs to be preserved. Regulators expect cooperation backed by facts, not assumptions.

The shift is subtle but meaningful. Compliance is no longer judged on intent or structure alone, but on how it holds up in practice. That view is consistent with the report findings from Forvis Mazars in the Netherlands.1

Fraud & Corruption Are Not Outliers

One of the more practical takeaways from enforcement activity is that misconduct is not rare. Most organizations will encounter some form of fraud or corruption signal over time.

Prevention is only part of the challenge. Recognizing issues and responding to them matters just as much. Signals often appear indirectly, such as:

  • A whistleblower report
  • An unusual transaction
  • A conversation that raises questions

Early indicators rarely arrive fully formed, so they can be easy to dismiss. However, when escalation is delayed, options may narrow and data may become harder to retrieve. If the context fades, decisions may be reactive instead of deliberate. That pattern appears repeatedly in enforcement cases.

A Broader Enforcement Environment

The FCPA still anchors global anti-corruption enforcement, but the waters around it have expanded.

Regulators outside the U.S. are becoming more active, and cooperation across jurisdictions is more common. New legal frameworks introduce broader accountability, including obligations tied to prevention and organizational benefit, such as the UK ‘failure to prevent fraud offence’ that went live in September 2025. The effect is cumulative, with exposure no longer limited to one regulator or statute.

Organizations that operate globally may be evaluated across multiple systems at once. A shared standard is emerging across jurisdictions.2 Companies should understand their risks, act responsibly when issues arise, and demonstrate control over their operations.

Third Parties Remain a Focus

Third-party risk remains one of the most consistent themes in enforcement. Our research found that in 73 out of 99 cases reviewed, payments flowed through third-party intermediaries such as distributors or agents. That’s not new. What is changing is how closely that activity is monitored.

Proof of due diligence isn’t as persuasive as it once was. Regulators look for evidence that companies understand who they are working with and how those relationships operate over time. A well-documented process carries limited weight if warning signs are visible and not acted on.

Third-party oversight should be active and evolve with the relationship. When risk changes so should the level or amount of oversight.

Why Do Controls Break Down?

In many investigations, unchallenged controls are an issue. If processes become routine, approvals may move forward without scrutiny. This can lead to risk assessments being completed, but then left unchanged. Over time, familiarity may be mistaken for confidence, even when confidence isn’t warranted.

One example captures this. A third-party due diligence report contained multiple red flags:

  • An offshore agent
  • High-risk jurisdiction of operations
  • Unusual payment flows

All of it was documented and approved without challenge. The process worked as designed, but not as intended. A gap like this may become a central issue when regulators evaluate responsibility and decide on enforcement outcomes.

Culture as a Practical Control

As enforcement frameworks evolve, culture becomes more visible. Our research and practitioner interviews consistently highlight the importance of speak-up culture, psychological safety, and visible leadership commitment in identifying and escalating concerns before they develop into larger issues.

Historically, fraud and bribery prevention have focused on protecting the company from bad actors. Newer frameworks reverse that lens and ask what the organization is doing about misconduct that “benefits” the business.

When a scheme appears to help the company hit a target or avoid a penalty, employees may convince themselves that the conduct “helps” the business rather than harms it. That rationalization is one of the three sides of the fraud triangle, and it’s often the hardest to detect because the people involved don’t see themselves as bad actors.

Therefore, building a culture of ethical conduct becomes paramount. The tone set by leadership often influences how employees interpret risk. It may affect which concerns are raised and how thoroughly issues are pursued once identified. Strong culture emphasizes compliance; a fragile or lax culture can undermine it.

A Different Set of Questions for Leadership

For corporate attorneys and executives, the shift in enforcement expectations changes the questions worth asking. The focus moves from whether policies are in place to how the organization would respond in practice. Key questions include:

  • How quickly could an investigation begin?
  • Could relevant data be accessed without delay?
  • Who would be responsible for key decisions?

These are operational questions that require planning before an issue arises. The answers to these questions should be embedded in daily operations.

What Are Actions to Consider Now?

Research findings show that cases involving high-level personnel resulted in penalties that were, on average, sixteen times higher than cases without such involvement. For leadership teams looking to help improve response readiness, consider the following:

  • Test investigation readiness through real scenarios rather than tabletop assumptions
  • Revisit risk assessments to confirm they reflect current operations
  • Review third-party relationships with a focus on how they function in practice, and whether current monitoring activities are sufficient
  • Clarify escalation paths and decision ownership before issues surface
  • Decipher whether controls are being followed consistently or exist only “on paper”

How Forvis Mazars Can Help

Organizations are operating in an environment in which enforcement outcomes are increasingly shaped by response quality rather than program design alone. The question is no longer whether a compliance program exists, but whether it performs effectively when tested. When issues arise, speed, clarity, and independence matter. The Forensics professionals at Forvis Mazars support clients through investigations, assess how controls perform in practice, and help organizations respond in ways that align with regulatory expectations. Connect with us today to ask your questions.

Related Reading

  • 1“A decade of accountability: What 10 years of FCPA enforcement reveal about risk, integrity, and the value of compliance,” forvismazars.com, September 9, 2025.
  • 2Such as the International Foreign Bribery Taskforce (IFBT) guidance on Indicators of Foreign Bribery that can be found here: https://www.afp.gov.au/crimes/fraud-and-corruption/foreign-bribery-and-grand-corruption

Related FORsights

Like what you see?
Subscribe to receive tailored insights directly to your inbox.