é É « » à è ù ç ô é

FCPA compliance software: best tools and how to choose

Nikki Young
February 19, 2025
| 14 min read
Audit Analytics Guide
Download Now

FCPA compliance software: how to cover both provisions most programs miss

The Foreign Corrupt Practices Act (FCPA) has two sets of requirements, and most compliance software covers only one.

Anti-bribery platforms handle vendor screening, politically exposed persons (PEP) checks, and third-party onboarding. The accounting provisions (Section 13(b)(2) of the Securities Exchange Act) require something different: internal accounting controls capable of detecting unauthorized payments in financial transactions. No due diligence tool tests whether a suspicious payment actually cleared the books.

That gap explains why enforcement actions regularly name companies with documented compliance programs.

Best FCPA compliance software options in 2026

The two-provision structure maps to two distinct tool categories: anti-bribery platforms that screen who you work with, and accounting provision tools that test what moved through the books.

Key strengths for all six platforms below are drawn from G2 user reviews (ratings and access dates in the note at the end of the article). Primary limitations for accounting provision tools (Oversight, MindBridge) are also G2-sourced. Primary limitations for anti-bribery platforms (NAVEX, Diligent, ProcessUnity) reflect product category scope: these platforms are not designed for transaction analytics, and that observation is editorial, not a G2 user complaint.

Software
FCPA provision covered
Key strength
Primary limitation
Supervizor 
Accounting provisions 
Full-population testing across core processes (P2P, R2R, etc.), travel and expenses (T&E); 350+ pre-built controls; ERP-agnostic 
No PEP screening or third-party due diligence 
Oversight (Casepoint) 
Accounting provisions 
Continuous monitoring for T&E and accounts payable (AP) 
Data flow inconsistencies and slow processing performance (G2 reviewers) 
MindBridge 
Accounting provisions 
AI-powered anomaly detection across general ledger (GL) data 
Clunky data management requiring IT support; time-consuming initial setup (G2 reviewers) 
Navex 
Anti-bribery provisions 
Policy management, incident reporting, third-party screening 
No transaction-level detection 
 Diligent
Anti-bribery provisions 
Third-party due diligence and governance risk 
No financial transaction monitoring 
ProcessUnity 
Anti-bribery provisions 
Vendor onboarding and ongoing risk monitoring 
No transaction analytics 

No single platform covers both provisions. Organizations that rely exclusively on anti-bribery platforms have screened their counterparties but have no visibility into whether payments to those counterparties were authorized, accurately recorded, and consistent with the contract.

Two software categories, one per provision

The platforms above split into two categories built on fundamentally different data. Understanding the split prevents buying a tool that solves the wrong problem.

Family
What it does
What it doesn't do
Target profile
Typical stack
Trigger signal
Anti-bribery and third-party screening 
Screens vendors and agents against sanctions lists and PEP databases; manages disclosure questionnaires; documents onboarding due diligence 
Test whether a payment to a screened counterparty was authorized, accurately recorded, or actually cleared the books 
Compliance and legal teams managing counterparty risk; organizations with significant third-party or agent exposure 
Screening platform (NAVEX, Diligent, ProcessUnity) feeding a vendor master, with periodic re-screening 
"We need to prove due diligence was performed before onboarding" / "An auditor asked how we vet foreign agents" 
Accounting provisions and transaction analytics 
Tests P2P, T&E, and vendor master transactions against control logic; flags round-amount payments, off-cycle disbursements, and shell company indicators; produces a reconstructible audit trail 
Screen counterparties before onboarding or manage PEP/sanctions list checks 
Corporate finance, internal audit, and compliance teams needing operating-effectiveness evidence under Section 13(b)(2)(B) 
ERP (SAP, Oracle, NetSuite, Workday) → analytics platform, often paired with a screening tool upstream 
"We screened the vendor, but can't prove the payment was authorized" / "The DOJ asked whether we test transactions on a population basis" 

What the FCPA's accounting provisions actually require

Books and records

Section 13(b)(2)(A) requires issuers to keep books and records in reasonable detail, defined as the level of detail a prudent person would maintain under similar circumstances. In practice, payments to agents and intermediaries must be traceable to supporting documentation, approval chains, and documented business purpose.

Round-amount payments in cash equivalents to consultants with no substantive operations are the highest-risk pattern. They appear in enforcement settlements because they cannot be documented to this standard. A $100,000 quarterly payment to a foreign agent described only as "market development support" fails the books-and-records requirement regardless of whether a bribe was intended.

Internal accounting controls

Section 13(b)(2)(B) requires controls providing reasonable assurance across four dimensions: transaction authorization, accurate recording, asset accountability, and comparison of recorded assets to existing assets.

In practice, this means controls capable of detecting:

  • Unauthorized payments to agents, consultants, or officials outside approved channels
  • Inaccurate payment descriptions: "consulting fees" or "advisory services" used to obscure gifts
  • Off-book structures designed to bypass normal financial system controls

Internal controls at this level require access to transaction data, not vendor databases. The relationship between internal control and compliance is direct: frameworks define the requirement, and transaction-level controls produce the evidence.

FCPA transaction patterns that analytics software detects

Payments to agents and intermediaries

The patterns that appear most consistently in FCPA enforcement run through standard financial systems and are invisible to vendor screening tools:

  • Round-amount disbursements to agents in high-risk jurisdictions where no corresponding revenue was recognized in the same period
  • Off-cycle vendor payments outside normal payment runs to recently created vendors with limited invoice history
  • Shell company indicators: payments to entities without a web presence, employees, or registered addresses that match dozens of other companies
  • Vendor master bank detail changes followed by a payment within 14 days, among the highest-yield fraud signals in AP transaction analytics

Test these patterns against your own transaction data

Supervizor applies 350+ pre-built controls, including the round-amount agent payment, threshold-adjacent T&E, and vendor bank-detail-change patterns named above, to 100% of your transactions. Deployed in days, not months.

See a 30-minute demo with your ERP

T&E and gift controls

Gift and entertainment claims are the transaction category most directly named in FCPA enforcement actions. Key detection patterns:

  • T&E claims submitted in high-corruption-risk countries at amounts just below approval thresholds: $4,999.99 in a $5,000-threshold environment, repeated weekly across a reporting period
  • Expenses coded as "business meals" or "client entertainment" where payee details match government ministry contacts
  • Repeated small gifts to the same recipient that stay under individual-claim limits but aggregate above policy thresholds, visible only through sequence analysis across the full claim population, not through claim-by-claim review

Anti-fraud controls applied to the full payment population surface these patterns before they become enforcement matters. Continuous controls monitoring creates the contemporaneous audit trail that regulators review.

What the DOJ looks for in a compliance program

FCPA enforcement shifted in 2025. A February 2025 executive order paused new FCPA cases for review, and in June 2025 the DOJ issued revised enforcement guidelines that resumed enforcement while refocusing it on misconduct tied to U.S. economic and national security interests, cartels, and individual actors. The statute and its accounting provisions remain in force, the SEC's approach is unchanged, and the DOJ still evaluates whether a compliance program operates in practice, not just on paper.

The DOJ's Evaluation of Corporate Compliance Programs (2023 revision) includes a dedicated data analytics section. Prosecutors assess whether the company:

  • Uses data analytics to identify unusual payment patterns on a continuous basis
  • Tests controls across the full transaction population, not through sampling
  • Maintains an audit trail sufficient to reconstruct suspicious transactions in an enforcement context

The governing standard is whether compliance is "adequately resourced and empowered to function effectively." A program that screens vendors but cannot test whether payments to those vendors were authorized and accurately described does not meet this standard.

Full-population testing answers the question that due diligence cannot: did the payment happen, and was it properly authorized? The ACFE 2024 Report to the Nations found that lack of internal controls is the contributing factor cited most frequently among fraud victim organizations, with a median detection lag of 12 months. An operational monitoring program eliminates that window.

How to build an FCPA compliance program that covers both provisions

Match your profile to the right control type

Profile
Context
Recommended category
Why not the others
Company with significant third-party or agent exposure, limited vendor vetting 
Agents and intermediaries operate in high-risk jurisdictions; onboarding due diligence is inconsistent or undocumented 
Anti-bribery and third-party screening 
Transaction analytics tests payments after the fact; it doesn't replace documented due diligence at onboarding 
Company with mature vendor screening, no transaction-level evidence 
Vendors are screened and PEP-checked, but no one tests whether payments to them were authorized or accurately recorded 
Accounting provisions and transaction analytics 
Screening tools stop at onboarding; they can't test whether a specific payment was round-amount, off-cycle, or misdescribed 
Multinational preparing for a DOJ or SEC compliance program evaluation 
Evaluators will ask whether the program tests controls on a population basis and maintains a reconstructible audit trail 
Both layers: screening upstream, transaction analytics downstream 
Screening alone cannot answer whether payments were authorized; analytics alone cannot document onboarding due diligence 
Company expanding into new high-risk markets 
New agent relationships being established faster than due diligence and monitoring can scale 
Anti-bribery and third-party screening, then add analytics as agent volume grows 
Analytics without a screening layer means testing payments to counterparties that were never properly vetted 
Internal audit or compliance team building a self-disclosure case 
An anomaly has surfaced and the company needs to demonstrate a documented, continuous monitoring program to support voluntary disclosure 
Accounting provisions and transaction analytics 
Screening documents apply to future onboarding decisions, not to an anomaly that already occurred in transaction data 

Map the two-provision gap

Most compliance programs have extensive third-party screening and weak transaction monitoring. The first step is making the gap explicit: map each FCPA enforcement risk to the control type that addresses it.

  • Vendor selection risk → third-party due diligence and PEP screening
  • Payment-level risk → transaction analytics and internal accounting controls testing
  • Books and records risk → continuous monitoring with audit trail output

This mapping also drives tooling decisions. Accounting controls that run against actual transactions, not documentation, provide the evidence base regulators assess.

Build the evidence base the DOJ expects

DOJ evaluators look beyond policy manuals and training completion rates. They assess testing methodology, control coverage rates, exception handling, and remediation workflows: the operational artifacts of a program that runs continuously, not one that exists on paper.

How Supervizor produces the evidence DOJ evaluators look for:

  • Full-population testing: 350+ pre-built controls run against 100% of P2P, T&E, and vendor master transactions, eliminating the sampling gap regulators flag.
  • Continuous monitoring: controls execute on every transaction cycle, not on annual or quarterly audit windows, narrowing the detection lag from the ACFE-documented 12-month median to days.
  • Reconstructible audit trail: every flagged exception traces to a specific control with documented parameters, every investigation is tracked from flag to resolution, every remediation is timestamped, exactly the artifact set DOJ prosecutors assess when evaluating whether a program "worked."

Native integration with SAP, Oracle, NetSuite, and Workday means the evidence base is operational from the first data connection, without months of custom rule development.

FAQ

Frequently Asked Questions

FCPA compliance software is a broad category covering two fundamentally different tool types, and the distinction matters. Anti-bribery platforms document that due diligence was performed before engaging a counterparty. Transaction analytics platforms test whether payments after onboarding were authorized and accurately recorded. Organizations often invest heavily in the first and assume it covers both, a gap that typically surfaces only during enforcement, when regulators ask not whether vendors were screened, but whether the payments that followed were properly controlled.

The anti-bribery provisions prohibit corrupt payments to foreign government officials to obtain or retain business. The accounting provisions (Section 13(b)(2)) require books and records in reasonable detail and sufficient internal accounting controls. A critical distinction: the accounting provisions contain no intent element. A company can be cited under Section 13(b)(2) purely for control weaknesses, with no evidence of an actual bribe required. This is why enforcement settlements often include accounting provision charges even in cases where the underlying bribery allegation is resolved separately.

Section 13(b)(2)(B) requires controls "sufficient to provide reasonable assurance," a lower bar than SOX Section 404's "effective" controls standard. The practical difference: the SEC assesses whether controls were designed to prevent or detect suspicious payments, not solely whether they caught every instance. A company that designed reasonable controls over agent disbursements but still had payments slip through may have a defensible position; a company with no controls over agent payments has none. Authorization controls, payment description accuracy, and systematic monitoring of intermediary disbursements are the areas regulators examine most closely.

Transaction monitoring flags suspicious payment patterns: round-amount agent disbursements, threshold-adjacent T&E claims, off-cycle vendor payments in high-risk jurisdictions. The less obvious benefit is the voluntary disclosure angle: when a monitoring program with documented exception-handling uncovers a potential issue, the company has both the evidence and the institutional choice to self-report. The DOJ's declination policies explicitly credit self-disclosure and remediation. Discovering an anomaly through continuous monitoring before enforcement creates the conditions for a cooperative resolution; discovering the same anomaly during an investigation does not.

The DOJ's Evaluation of Corporate Compliance Programs is the framework prosecutors use to assess whether a compliance program was genuinely operational at the time of an offense. It asks three questions: Was the program well-designed? Was it applied earnestly? Did it work? The 2023 revision added explicit emphasis on data analytics: prosecutors now assess whether the company tested controls on a population basis, used continuous monitoring, and maintained an audit trail sufficient to reconstruct transactions. A program that satisfies the first question on paper but not the second two will not support a mitigation argument.

The FCPA covers direct payments to foreign officials and indirect payments through intermediaries when the company "knew or should have known" the payment would be passed on. One nuance worth noting: historically, small payments to low-level officials to expedite routine governmental actions (customs clearance, permits) were excluded as "facilitating payments." That exception offers limited protection today. The UK Bribery Act, which applies to UK-listed subsidiaries of US multinationals, contains no equivalent exception. DOJ guidance also makes clear that excessive or repeated facilitating payments attract scrutiny regardless of the technical exclusion.

The DOJ's Evaluation states explicitly that a one-size-fits-all approach is not considered well-designed. The foundation is a documented risk assessment that maps high-risk markets, business lines, and counterparty types, and translates them into proportional controls. High-risk agent relationships require transaction-level monitoring and periodic reconciliation against recognized revenue; lower-risk domestic procurement does not. The program also needs a documented exception-handling and escalation process. Regulators do not expect zero anomalies; they expect to see how anomalies were handled, which is exactly what a continuous monitoring audit trail provides.

A note on the competitor comparisons in this article

Key strengths for all six platforms in the comparative table above are drawn from G2's aggregated "pros and cons" review themes:

Primary limitations for the two accounting provision tools (Oversight and MindBridge) are also sourced from G2 reviewer themes. Primary limitations for the three anti-bribery platforms (NAVEX, Diligent, ProcessUnity) reflect product category scope: these tools are designed for third-party due diligence and policy management, not financial transaction analytics. That observation is editorial and specific to the FCPA accounting-provisions context described in this article; it does not reflect a criticism raised by G2 reviewers of those products.

This comparison reflects a snapshot of third-party user reviews at a single point in time. Vendor products, features, and user sentiment change. If you believe any of the information above is inaccurate or out of date, please contact contact@supervizor.com.

Nikki Young
Nikki is a freelance writer, editor, proofreader, and general word-nerd. Nikki has a 20+ year career background in internal audit, risk, and fraud, and now applies that knowledge in her writing and editorial work, rather than in daily practice. She holds her Certified Internal Auditor (CIA), Certification in Risk Management Assurance (CRMA), and Certified Fraud Examiner (CFE) designations. She is also an active member of both the Institute of Internal Auditors (IIA) and the Associated of Certified Fraud Examiners (ACFE).
See more