Know your third parties before the DOJ asks.
FCPA and U.K. Bribery Act compliance for U.S. companies and investors doing business in Africa. We build the third-party approval framework, gifts and hospitality controls and diligence files that show who acts for you, what you pay them and what you checked, and we support investigations and M&A diligence when a question needs facts.
The Risk Travels Through the People Who Act for You
Doing business in African markets often means working through others: sales agents and distributors, customs brokers and freight forwarders, consultants who handle licenses and permits, joint venture partners, and local firms that deal with ministries, regulators and state-owned enterprises on your behalf. Each of them can create exposure that you answer for.
The FCPA's anti-bribery provisions generally prohibit corruptly offering, promising or paying anything of value to a foreign official, directly or indirectly, to obtain or retain business. A payment made through an agent can still be treated as your payment if you knew, or were aware of a high probability, that it would be passed on. Employees of state-owned or state-controlled companies can count as foreign officials.
For issuers, the FCPA's books and records and internal accounting controls provisions also generally reach how third-party payments are approved and recorded. For organizations that carry on business in the U.K., the U.K. Bribery Act adds a corporate offense of failing to prevent bribery by persons acting on their behalf, with adequate procedures as a defense.
Enforcement priorities in Washington can shift from one administration to the next. The FCPA remains law, and the U.K. Bribery Act and the anti-corruption laws of the countries you operate in still apply. Acquirers, lenders, bank partners and boards still ask what your program does and how you know it works. Anti-bribery and corruption is one of the four pillars of our financial crimes advisory practice, alongside AML, sanctions and fraud risk.
Regulator-facing experience: direct engagement with FinCEN, state banking departments, FDIC and OCC exam teams and the DOJ, plus Big Four and national-firm validation work.
Where Clients Start
Anti-corruption work usually starts with a decision that cannot wait: a partner to approve, a deal to sign or a concern to run down. Start where you are.
A new agent, distributor or partner
Your team wants to appoint a third party who will deal with customs, permits, licensing or public buyers in a new market. You need a risk rating, a diligence file and an approval decision you can defend.
Third-party approval frameworksA deal in diligence
You are investing in or acquiring a company with operations in African markets. You need to know how it wins business, who it pays and what its controls look like before the term sheet becomes a signed agreement.
Compliance due diligence for investorsA red flag or whistleblower report
Diligence has turned up a concern, or someone inside has reported one: a request for cash, an unexplained commission, a payment to an account in another country. The facts need to be established before decisions are made.
Anti-corruption investigations supportA program that exists mainly on paper
You have an anti-corruption policy, but no one can show how third parties are approved, how gifts to officials are logged or when the controls were last tested. A board, acquirer or bank partner is starting to ask.
How we build and test anti-corruption programsAnti-Corruption Compliance from Approval to Exit
Our anti-bribery and corruption work covers FCPA, U.K. Bribery Act, and global anti-corruption program design, risk assessments, and third-party due diligence frameworks. Each workstream can be scoped on its own. Most engagements combine two or three, tied to the decision in front of you.
Anti-Corruption Risk Assessment
Where your business touches government: the markets, the officials and state-owned enterprises you deal with, the third parties who deal with them for you, and the payments, gifts and hospitality involved. The result is a risk rating by market, business line and third-party type that the rest of the program is built on.
Third-Party Approval Frameworks
Risk tiers, diligence scaled to each tier, a written business justification, approval authority, contract protections and payment controls, with refresh dates tied to risk. Built so every approval can be explained to a reviewer who was not in the room.
Third-party approval frameworksGifts, Hospitality and Travel
Policy design, value thresholds, pre-approval for anything given to a government official, a register that captures what was given, to whom and why, and testing that the register matches the expense data.
Gifts and hospitality controlsInvestigations Support
Fact-finding when a red flag or report points to an improper payment: scoping, payment and invoice testing, review of the third party's file and contract, and the control gaps that allowed it, run at the direction of your counsel where privilege matters.
Anti-corruption investigations supportReporting Built for DOJ Review
Program reporting that shows the program works in practice: testing results, third-party metrics, investigation outcomes and remediation tracked to closure, organized around the questions the DOJ's guidance on evaluating corporate compliance programs asks.
Reporting built for DOJ reviewM&A Diligence and Integration
Pre-close anti-corruption diligence on a target's third parties, government touchpoints, payments and program, and post-close integration that brings the acquired business under your controls.
M&A anti-corruption diligenceAn Approval Decision You Can Defend
A third-party program has to answer three questions for every intermediary: why the business needs this party, what you checked before approving it, and how you know what it did with your money afterward. The DOJ's guidance on evaluating corporate compliance programs asks similar questions: the business rationale for using the third party, how its compensation is set and tied to the services, whether diligence is scaled to risk, and whether the company monitors the relationship and uses its audit rights.
We design the framework around risk tiers. A logistics provider with no government contact and a consultant paid a success fee to secure a permit should not receive the same review. Tiering looks at the country, whether the party will deal with officials or state-owned enterprises on your behalf, the service, how it is paid, and who introduced it. Higher tiers get deeper diligence, senior approval and closer monitoring.
The framework covers the full relationship: intake and business justification, diligence by tier, red flag resolution, approval, contract terms, payment controls, periodic refresh and exit. We write the procedures and templates your team will use.
Every file also includes sanctions screening of the party and its owners; see sanctions screening and OFAC compliance. Where local law shapes the answer, such as what can be collected about a third party's owners, we coordinate with your in-country counsel.
Courtesy With a Record Behind It
Gifts, meals, hospitality and travel are a normal part of business relationships in most markets, including relationships with officials. The FCPA provides an affirmative defense for reasonable and bona fide expenditures, such as travel and lodging, directly related to the promotion, demonstration or explanation of products or services, or to the execution or performance of a contract with a foreign government or agency.
The risk sits in what falls outside that line: lavish entertainment, side trips, per diems paid in cash, travel for family members, or hospitality timed around a pending license or tender.
We design policies with thresholds that fit your markets, pre-approval for anything given to a government official or an employee of a state-owned enterprise, and a register that records what was given, to whom and why. Then we test it, sampling expense and payment data against the register to find what was never logged. The same controls cover charitable donations and sponsorships that an official has asked for or will benefit from.
When a Red Flag Becomes a Question of Fact
When diligence, an audit or a whistleblower report points to a possible improper payment, the first job is to establish what happened. We help scope the review, test payments, invoices and supporting records, examine the third party's diligence file and contract, interview the people who own the relationship where appropriate, and identify the control gaps that allowed it.
Where privilege matters, or a voluntary self-disclosure to the DOJ or SEC is under consideration, the investigation runs at the direction of your counsel, and we work inside that structure. DOJ and SEC enforcement response support works the same way: we establish facts, test controls and document remediation, and your counsel leads.
Afterward, the program has to show it learned. For companies under a DOJ resolution, facing an inquiry, or preparing for their program to be evaluated, reporting has to demonstrate that controls work in practice, not only that policies exist: testing results, third-party metrics, hotline and investigation outcomes, and remediation tracked to closure. Our principal, Victor B. George, JD, has worked anti-corruption programs under DOJ oversight, and we build reporting to the standard that kind of review applies.
Before You Sign, and After You Close
An acquirer can, in some circumstances, inherit liability for a target's past bribery, and an investor can find that the growth it paid for depended on payments it cannot defend. Pre-close anti-corruption diligence shows how the target wins business in its markets: its government touchpoints, its third parties and what it pays them, its gifts and hospitality practice, its program as written and as run, and any history of allegations or investigations.
We rate each finding by severity and deliver it in time to shape the deal: price, representations, indemnities, conditions to closing or a remediation plan. Your counsel on the transaction handles the legal conclusions and the deal documents.
The first months after closing matter. DOJ policy generally encourages acquirers to disclose misconduct discovered at an acquired company and to remediate it promptly after closing, so integration should start on day one: re-diligence of high-risk third parties, rollout of your policies and approval framework, training, and early testing.
If the target is a remittance business, AML diligence runs alongside; see U.S.-Africa remittance corridor compliance. For the investor view across the deal, see compliance due diligence for investors.
Map, Build, Prepare, Stay Accountable
The lifecycle we use across our cross-border work, applied to the third parties and government touchpoints in your markets.
- 01
Map
Map where your business touches government in each market: the licenses, permits, customs steps, tenders and state-owned customers, and the third parties who handle each one for you.
- 02
Build
Build the program the map calls for: risk assessment, third-party approval framework, gifts and hospitality controls, contract terms and payment controls, fitted to how your business actually operates in its markets.
- 03
Prepare
Prepare for the moment someone checks: an acquirer's diligence, a bank partner's questionnaire, a board review or a regulator's inquiry, with files and evidence organized the way the reviewer will read them.
- 04
Stay accountable
Stay accountable through periodic testing of third-party files, payments and the gifts register, refresh of high-risk parties, and reporting that management and the board can act on.
The Experience Behind This Practice
Anti-corruption work is judged by whether it holds up when someone independent looks: an auditor, an acquirer, a bank partner or the DOJ.
Victor B. George, JD, Ethixera's founder and principal, spent over 15 years inside Big 4 advisory firms, Fortune 500 financial institutions, and regulated healthcare companies, where he worked consent order remediation programs, enterprise risk assessments, AML/BSA validations, and anti-corruption programs under DOJ oversight.
He has completed the TRACE anti-bribery accreditation (TASA), is a member of the Association of Certified Fraud Examiners (ACFE), and co-chairs the Financial Crimes Committee of NABCRMP, the National Association of Black Compliance & Risk Management Professionals.
Engagements are principal-led, with direct access to senior expertise. Meet the Ethixera team.
The anonymized engagements below are compliance testing and validation work, the same discipline we apply when we test third-party files, payments and the gifts register.
Mid-Size Community Bank · Southeast
Led independent 3rd-line validation testing under FDIC consent order. Developed risk-based test scripts and executed validation across 20+ remediation initiatives spanning AML, GRC, and enterprise governance workstreams.
Top 25 U.S. Banking Institution
Conducted comprehensive 2LOD compliance testing and transactional reviews across the Banking division. Identified deficiencies and recommended actionable remediation strategies.
“Ethixera understood both the regulatory landscape and the market dynamics. They did not try to impose a Western compliance template. They built something that works for how business actually moves in our market.”
Reading for Cross-Border Teams
Why African VASPs need Western-grade compliance architecture now, not later.
The institutions that build compliance credibility first will be the ones that capture institutional capital flows.
Compliance architecture for African VASPsKnow ethics, know accountability: the conviction behind Ethixera.
Our founder Victor George on the thesis that shaped the firm, and why “ethics training” as practiced across most of the industry is solving the wrong problem.
Know ethics, know accountabilityQuestions we hear
What makes a third party high risk under the FCPA?
The FCPA does not sort third parties into risk tiers. That is a judgment your program has to make and document, and the factors that drive it are well known.
The party will deal with foreign officials or state-owned enterprises on your behalf, for example on customs, permits, licenses, taxes or public tenders. It operates in a market with high corruption risk. It is paid by commission or success fee, or its fee is high for the work described. An official recommended it, or its owners have ties to officials. It asks for cash, advance payments, or payment to an account in another country or another name. It lacks the qualifications or staff to perform the service, or it resists compliance terms and audit rights.
A party with several of these factors belongs in your highest tier, with enhanced diligence, senior approval and closer monitoring. See third-party approval frameworks.
What should a third-party due diligence file contain?
Enough for a reviewer, whether your board, an acquirer or a regulator, to see why you engaged the party, what you checked and how you keep watching it.
That means the business justification and how compensation was set; the legal entity, ownership and beneficial owners; any links to government officials or state-owned enterprises; sanctions, adverse media and litigation screening of the party and its owners; evidence it can perform the service; each red flag and how it was resolved; anti-corruption contract terms, including audit and termination rights; payment terms checked against the party's location; and the risk tier, approver, training status and next refresh date.
The depth scales with the tier. A file that holds a completed questionnaire and nothing else rarely answers the questions a reviewer will ask.
How do you handle a red flag found during diligence?
Document it, and do not approve the party until the red flag is resolved or mitigated and the approver's reasoning is recorded in writing. Resolution usually means asking the party direct questions, obtaining documents such as ownership records, references or a breakdown of fees, and running enhanced diligence where needed.
Some red flags can be mitigated with tighter contract terms, audit rights, payment controls, training and certifications. Some cannot, and then the answer is to decline the party or exit the relationship. Every step goes in the file.
If a red flag suggests an improper payment has already been made, it stops being a diligence question and becomes an investigation, which typically runs at the direction of your counsel. See anti-corruption investigations support.
Can you review a target before we invest?
Yes. Pre-close anti-corruption diligence looks at how the target wins business: its government touchpoints, its third parties and what it pays them, gifts and hospitality involving officials, its program as written and as run, and any past allegations or investigations.
We test a sample of payments against contracts and invoices, rate each finding by severity, and deliver in time to shape price, representations, indemnities or conditions to closing. Your counsel on the transaction handles the legal conclusions and the deal documents.
After closing, we can support integration: re-diligence of high-risk third parties, rollout of your policies and approval framework, and early testing. See compliance due diligence for investors.
Is Ethixera a law firm?
No. Ethixera Advisory is a compliance advisory firm, not a law firm, and does not provide legal advice. We assess, design, test and help run anti-corruption compliance programs, and we establish facts in investigations.
We work alongside your counsel on legal interpretation, privilege, voluntary self-disclosure decisions, deal documents and any dealings with the DOJ or SEC, and alongside your in-country counsel on local law.
A Third Party, a Deal or a Red Flag on Your Desk?
Tell us where you are: a partner to approve, a target in diligence or a concern that needs facts. We will scope the work with you and tell you what it takes.
