Privacy & Security

Anti-Bribery and FCPA Awareness Training

August 23, 2026·9 min read·Certified Training USA

What the FCPA and UK Bribery Act Actually Require

The Foreign Corrupt Practices Act, codified at 15 U.S.C. §§ 78dd-1, 78dd-2, and 78dd-3, prohibits U.S. persons and companies, along with certain foreign issuers, from paying or offering anything of value to a foreign official to obtain or retain business. A companion provision, 15 U.S.C. § 78m(b), imposes accounting and internal-controls requirements on public companies, which is why FCPA enforcement often runs through a company's books-and-records and internal-controls failures rather than the bribery itself. Nowhere in this statute does Congress require employee training. The FCPA tells companies what conduct is illegal and, for issuers, what kind of internal controls they need; it is silent on how a company gets its workforce to understand and follow that rule.

The UK Bribery Act 2010 is structured differently and is, in several respects, a broader statute. It criminalizes bribery of any person, not just foreign government officials, meaning purely commercial, private-sector bribery between two companies is covered in a way the FCPA does not reach. It also creates a corporate offense, under Section 7, of failing to prevent bribery by an associated person, which is a strict-liability offense unless the company can show it had adequate procedures in place.

That adequate-procedures defense under Section 7 is the closest thing to a training requirement that either statute contains, and even then it is a defense, not an affirmative duty. The UK Ministry of Justice's guidance on adequate procedures explicitly lists training and communication as one of six principles a company should be able to point to. A company with no anti-bribery training program has no such defense available to it if an employee or agent bribes someone on its behalf.

So the honest summary is this: no federal statute orders a company to train employees on anti-bribery law. What exists instead is a set of real, concrete incentives that make training the sensible business decision anyway, which is what the rest of this article is about.

Why Companies Train on Anti-Bribery Anyway

The first and most direct incentive is U.S. Sentencing Guidelines § 8B2.1(b)(4). If a company is ever convicted of a federal crime, including an FCPA violation, its sentence is calculated using an organizational culpability score, and that score can be reduced if the company had an effective compliance and ethics program in place before the offense occurred. Training employees, including on topics like anti-bribery, is one of the concrete elements the Guidelines look for when deciding whether a program counts as effective. This is not a training mandate. It is a sentencing credit, but for a company facing a criminal conviction the difference between a reduced sentence and a full one is enormous.

The second incentive sits inside DOJ's own charging process. The Department of Justice publishes and periodically updates its Evaluation of Corporate Compliance Programs guidance, which prosecutors use when deciding whether to charge a company at all, what kind of resolution to offer, and what monitor or reporting conditions to impose. That guidance asks specific questions about training: was it risk-based, was it tailored to the roles most exposed to bribery risk, was completion tracked, and did the company test whether people actually understood it. A company that can answer those questions with real records is in a materially different negotiating position than one that cannot.

The third incentive is the UK Bribery Act's Section 7 adequate-procedures defense described above. For any company with UK operations, UK counterparties, or UK-linked transactions, that defense is the only way to avoid strict liability for bribery committed by an employee, agent, or business partner acting on the company's behalf. Training is one of the six principles UK guidance points to when assessing whether procedures were adequate, so a company with no training program is choosing to go into that defense empty-handed.

Put together, none of these three reasons is a legal requirement in the way that, say, a workplace safety training mandate is a requirement. They are risk-management incentives: reduce sentencing exposure if convicted, improve your position in DOJ's charging decision, and preserve a statutory defense under UK law. That is a real and substantial set of reasons to train. It is just not the same thing as a legal mandate, and this article will not claim otherwise.

Is FCPA training legally required?
No. There is no statute that requires it. Companies train because of the sentencing credit under U.S. Sentencing Guidelines § 8B2.1(b)(4), because DOJ's charging guidance looks for it, and because the UK Bribery Act's Section 7 defense depends on having adequate procedures, including training, in place.

Who Needs This Training

Anti-bribery training is most valuable for employees who interact with government officials, foreign business partners, agents, distributors, or intermediaries, because those are the relationships where bribery risk concentrates. Sales and business development staff working in markets with higher perceived corruption risk, procurement and logistics staff who deal with customs and permitting officials, and anyone who manages third-party agents or consultants on the company's behalf are the core audience.

Finance and accounting staff also belong in this training population, even though they rarely interact with foreign officials directly, because the FCPA's books-and-records and internal-controls provisions under § 78m(b) mean that a bribe disguised as a consulting fee or a marketing expense is as much a compliance failure as the bribe itself. People who approve invoices, process expense reports, or reconcile vendor payments are often the last line of defense against a bribe that has been mislabeled to get past them.

Executives and board members are frequently the highest-risk group in practice, not because they are more likely to offer a bribe personally, but because DOJ and UK enforcement authorities look closely at what senior leadership knew, approved, or turned a blind eye to. A training program that only reaches junior sales staff and skips the people who approve high-value contracts or sign off on third-party agent relationships has a visible gap that a prosecutor or auditor will notice.

Smaller or domestically-focused companies sometimes assume this training does not apply to them because they have no foreign operations. That assumption is worth checking rather than assuming: even a single foreign sales trip, a single overseas distributor, or a single joint venture partner can create FCPA and UK Bribery Act exposure, and by the time a company is trying to sort that out after an incident, it is too late for training to help.

The Facilitating Payments Trap: US vs UK

One of the more consequential and less well-known gaps between U.S. and UK anti-bribery law is the treatment of facilitating payments, sometimes called grease payments. The FCPA carves out a narrow exception for payments made to a foreign official to expedite or secure the performance of a routine, non-discretionary government action, things like processing a visa, obtaining a permit the company is already entitled to, or getting a phone line connected. This exception is narrow and has been interpreted narrowly by DOJ, but it exists.

The UK Bribery Act contains no equivalent exception. A payment made to speed up a routine government process that might be defensible under the FCPA's facilitating-payments carve-out can still constitute a criminal bribe under UK law, full stop. This is not a minor technical difference; it means a company that trains its staff only on U.S. rules, and lets them assume facilitating payments are broadly acceptable, is setting up employees operating in UK-linked transactions for a real legal exposure.

This gap matters most for companies with operations, subsidiaries, or transactions touching both jurisdictions, which today includes most companies of any meaningful size doing cross-border business. A U.S. parent company with a UK subsidiary, a UK-incorporated joint venture, or even UK-based intermediaries handling a transaction can find UK law reaching conduct that a U.S.-only playbook would have called acceptable.

Effective training addresses this directly rather than glossing over it: employees need to understand that facilitating payments are a U.S.-specific, narrow exception, not a general principle, and that when UK law or UK-linked counterparties are involved, the safer default is to treat any payment to a government official as prohibited regardless of how small or routine it seems.

How this standard compares, by OSHA citation count
Fall Protection
30,929
Hazard Communication
28,898
Respiratory Protection
17,672
Lockout/Tagout
17,359
Powered Industrial Trucks
12,902
Scaffolding
11,522
Walking-Working Surfaces
11,110
Machine Guarding
9,782
The course
Anti-Bribery and FCPA Awareness
Documents this training with an instant, verifiable certificate. $49.
View the course

What Counts as a Defensible Anti-Bribery Program

Based on DOJ's Evaluation of Corporate Compliance Programs guidance and the UK Ministry of Justice's adequate-procedures principles, a defensible program has a few recognizable features. It is risk-based, meaning higher-risk roles and higher-risk geographies get more frequent or more detailed training than low-risk roles. It is tracked, meaning the company can produce records of who completed training and when. And it is periodically reassessed, meaning the company revisits its risk assessment and training content rather than running the same module indefinitely.

A program built entirely around a single generic training module, with no tailoring to role or geography and no record of who actually completed it, will struggle to satisfy either DOJ's expectations or the UK's adequate-procedures standard. Prosecutors and regulators evaluating a program after the fact are specifically looking for evidence that training was more than a checkbox exercise.

Third-party due diligence is closely tied to training in both frameworks. A company can train its own employees thoroughly and still face significant exposure through an agent, distributor, or consultant who was never vetted or trained on the company's expectations. A defensible program extends its anti-bribery expectations, and ideally some form of training or certification, to the third parties who act on the company's behalf.

Finally, both frameworks look for a real reporting channel and a genuine no-retaliation policy, because a training program that tells employees what bribery looks like but gives them no safe way to report a concern is incomplete. Employees who complete anti-bribery training should leave knowing exactly who to contact if they are asked for or offered a bribe, and should have confidence that raising the issue will not cost them their job.

Does Online Training Satisfy Regulators and Prosecutors

Neither DOJ nor UK guidance requires any particular training format, so online or on-demand training is not disqualified simply for being delivered that way. What both frameworks care about is whether the training was actually completed, understood, and tailored to real risk, not whether it happened in a classroom or on a screen. A well-built online course with completion tracking, a knowledge check, and role-based content can satisfy the substance of what DOJ and UK guidance are looking for.

Where online training falls short is when it is treated as a one-size-fits-all exercise assigned identically to every employee regardless of their actual exposure to bribery risk. A generic module that a sales director in a high-risk market completes identically to an accounts-payable clerk in a domestic back office is not the risk-based approach that DOJ's evaluation guidance describes, even if the completion records look clean.

Completion records matter more than most companies initially expect. If a company is ever investigated, one of the first things DOJ or a UK regulator will ask for is documentation: who was trained, when, on what content, and whether they demonstrated understanding. A training platform that logs completion dates, quiz scores, and content versions gives a company something concrete to hand over; a training program run informally with no records gives a company nothing to show.

The practical takeaway is that online training is a legitimate and often efficient way to deliver this content, provided the company layers risk-based assignment and recordkeeping on top of it rather than treating the course itself as the entire program.

How Often to Retrain

Neither the FCPA nor the UK Bribery Act specifies a mandated retraining interval, so any claim of a fixed legal requirement here would be inaccurate. What exists instead is a practical norm, shaped by DOJ's expectation that a compliance program evolve and by the reality that bribery risk changes as a company enters new markets, adds new third-party relationships, or changes its business model.

Most companies with meaningful cross-border exposure retrain annually, and there are good practical reasons for that cadence even without a legal mandate. Personnel turn over, new employees join without any prior exposure to the company's policy, and a year is long enough for specific scenarios and red flags to fade from memory if they are not periodically reinforced.

Certain events should trigger retraining outside the normal annual cycle regardless of when the last cycle ran: entering a new higher-risk market, onboarding a new class of third-party intermediaries, a merger or acquisition that brings in employees who were never trained under the acquiring company's program, or an internal investigation that surfaces a gap in understanding.

The company's own risk assessment, not a fixed external rule, should ultimately drive the retraining schedule. A company that can explain why it chose its cadence, and can show that it revisited that decision as its risk profile changed, is in a stronger position than one simply repeating an arbitrary annual cycle without ever asking whether it still fits the business.

If a payment is legal under the FCPA's facilitating-payments exception, is it safe everywhere?
No. The UK Bribery Act has no facilitating-payments exception at all. A payment that might be defensible under the FCPA's narrow carve-out can still be a criminal bribe under UK law, which is a real trap for companies operating in both jurisdictions.

Rolling This Out: Guidance for Compliance Officers and Employees

For a compliance officer standing up or refreshing this program, the first step is a genuine risk assessment rather than a training purchase: identify which business units, roles, and geographies carry the highest bribery exposure, and let that assessment drive who gets trained, how often, and with what level of detail. Document that assessment in writing, because it is the piece of evidence that shows DOJ or a UK regulator the program was built deliberately rather than assembled after the fact.

Pair the training itself with visible executive sponsorship. A program that senior leadership completes alongside everyone else, and that a senior executive introduces or endorses, signals to the rest of the company that this is a real expectation rather than an HR formality, which is exactly the kind of tone-at-the-top evidence DOJ's guidance looks for.

For an individual employee taking this training, the practical goal is simple: know what to do the moment something feels off. If you are ever asked for a payment, gift, or favor by a government official, or asked by a manager or business partner to make a payment that seems unusual, routine business activity does not require secrecy, urgency, or off-the-books handling. Those are the classic signals worth pausing on.

The single most useful habit an employee can take away from this training is knowing exactly who to call before a payment is made, not after. Compliance teams would overwhelmingly rather field a five-minute question about a payment that turns out to be fine than discover, months later, that a payment nobody flagged has become a federal investigation.

Frequently asked questions

Does completing this course make my company FCPA compliant?

No single training course makes a company compliant. This course covers the (e)(1)-style training element of an anti-bribery program; a full program also needs risk assessment, third-party due diligence, internal controls, and a reporting channel.

Who should take this course within a company?

Anyone who interacts with foreign government officials, manages third-party agents or distributors, approves payments or invoices, or holds a senior leadership role where tone-at-the-top matters to DOJ or UK enforcement authorities.

Does the FCPA only apply to bribery of foreign officials?

The anti-bribery provisions target payments to foreign officials, but the accounting and internal-controls provisions under 15 U.S.C. § 78m(b) apply more broadly to how public companies record and control payments, which is often where enforcement actually starts.

Is the UK Bribery Act only relevant to UK companies?

No. It can reach any company with a UK nexus, including a UK subsidiary, UK-based agents, or business conducted in the UK, even if the parent company is based elsewhere.

How is this different from a general ethics or code-of-conduct course?

A general ethics course covers broad workplace conduct. This course focuses specifically on the legal definitions, jurisdictional gaps, and real-world red flags tied to the FCPA and UK Bribery Act, which a generic ethics module typically does not address in enough detail to support a compliance defense.

Get your team certified

Every course maps to the regulation it satisfies and issues a verifiable certificate. Browse the catalog and certify your workforce today.

See all courses