skills/legal/fcpa-compliance-policy/SKILL.md
Drafts an implementable Foreign Corrupt Practices Act (FCPA) Compliance Policy for U.S.-jurisdictional corporations with international operations. Covers anti-bribery provisions (15 U.S.C. §§ 78dd-1 through -3), accounting provisions (15 U.S.C. §§ 78m(b)(2)(A)-(B)), gift thresholds, tiered third-party due diligence, internal controls, training, and whistleblower protections. Incorporates DOJ/SEC Resource Guide guidance. Use when drafting or updating an FCPA policy, anti-bribery compliance program, corporate ethics policy, or international corruption risk framework.
npx skillsauth add casemark/skills fcpa-compliance-policyInstall this skill globally with one command. Works with Claude Code, Cursor, and Windsurf.
3 of 9 scanners reported clean
Some scanners were skipped, did not run, or reported a non-clean status. Review each row below.
Drafts a litigation-ready FCPA Compliance Policy anchored in DOJ/SEC enforcement guidance, with specific thresholds, approval workflows, and role-based obligations.
Draft a policy with these nine sections:
| Element | Content | |---|---| | Statutory basis | Anti-bribery: 15 U.S.C. §§ 78dd-1, -2, -3; Accounting: 15 U.S.C. §§ 78m(b)(2)(A)-(B) | | Penalties | Corporate criminal: up to $2M/violation; individual: up to 5 years imprisonment [VERIFY post-inflation adjustments] | | Enforcement | DOJ (criminal), SEC (civil, issuers only) | | Tone | Compliance = legal obligation + business integrity; employees who refuse corrupt practices are supported |
Prohibits offering, promising, giving, or authorizing anything of value to a foreign official, directly or through intermediaries, corruptly to influence official action, induce duty violations, secure improper advantage, or obtain/retain business.
| Term | Scope | |---|---| | Foreign official | Government employees at all levels; state-owned enterprise officials (even minority ownership); political party officials/candidates; public international organization employees | | Anything of value | Cash, gifts, meals, travel, lodging, employment offers, charitable contributions, political donations, business opportunities | | Issuer | Company with U.S.-registered securities or periodic SEC filing obligations | | Domestic concern | U.S. citizens, nationals, residents; U.S.-organized entities |
Facilitation payments: Recommend total prohibition — narrow exception, difficult to document, prohibited by U.K. Bribery Act and many local laws.
Common schemes: Consulting fees to officials' shell companies; luxury travel to influence procurement; hiring officials' relatives as quid pro quo; directed charity donations; cash to expedite customs.
All criteria must be met: reasonable value; lawful under recipient's policies and local law; tied to legitimate business purpose; transparent and documented; not cash; no expectation of official action; infrequent.
Default thresholds:
| Category | Limit | Approval | |---|---|---| | Single gift (foreign official) | ≤ $100 | None | | Aggregate per recipient/year | ≤ $250 | None | | Meals (with business discussion) | Reasonable | Manager | | Exceeding thresholds | Any | Legal/Compliance written | | Travel/lodging | Economy; standard hotel | Legal/Compliance written |
Always prohibited: Cash/equivalents; first-class travel (unless equal to internal policy); family member expenses; personal side trips; unattended event tickets.
Risk-tiered framework:
| Tier | Risk Factors | Diligence | |---|---|---| | Low | No government interaction; low-risk jurisdiction; fixed fee | Registration check; sanctions/media screening; FCPA representation | | Moderate | Occasional government contact; moderate jurisdiction; commission comp | + References; qualifications; comp reasonableness; anti-corruption policy review | | High | Regular government contact; high-risk jurisdiction (TI CPI < 50); success fee; government-recommended; official ownership | + Background investigation; ownership verification; site visit; compliance audit; ongoing monitoring |
Required contract terms: FCPA compliance reps/warranties; accurate books obligation; audit rights; training obligations; termination right for violations.
Compensation rules: Reasonable and documented; prohibit round-sum payments, cash, offshore routing, payments to unqualified parties.
Monitoring: Annual recertification; periodic transaction review; immediate red flag investigation.
All transactions recorded accurately in reasonable detail — not limited to foreign-official interactions.
Prohibited: Off-books accounts; false invoices/expense reports; generic payment descriptions.
Required controls:
| Control | Description | |---|---| | Segregation of duties | No single employee controls all aspects of high-risk transactions | | Approval hierarchy | Management review for foreign-official and high-risk third-party expenditures | | Expense flagging | Automated flags for unusual payments routed to Compliance pre-processing | | Periodic audits | High-risk accounts and third-party transactions | | Payment channels | Payments only to contracting party; only in country of service |
Finance red flags (escalate before payment): Round-sum invoices lacking detail; third-country/offshore payments; cash requests; shell companies; unusual urgency; unapproved vendors.
| Population | Frequency | Content | |---|---|---| | All employees (intl ops, finance) | Hire + annual | FCPA overview, red flags, reporting channels | | High-risk (sales, BD, procurement) | Hire + annual + role change | Scenarios, approval workflows, due diligence | | Senior management | Annual | Compliance culture, resource adequacy, escalation | | Board/Audit Committee | Annual | Oversight, key risks, program effectiveness | | High-risk third parties | Per contract | FCPA fundamentals, policy obligations |
Require written certification of completion; maintain comprehension records (assessments).
Channels: 24/7 multilingual hotline (anonymous where permitted); web portal; direct Legal/Compliance access.
Investigation: Prompt review; independent investigators; document preservation; escalation to Audit Committee for significant matters.
Non-retaliation: Adverse actions prohibited for good-faith reporters or employees refusing to participate in violations. Retaliation = independent terminable offense.
Protections: Dodd-Frank (SEC reporter incentives/anti-retaliation) [VERIFY current bounty %]; SOX (public company fraud reporting).
Include: gift/travel approval form template; tiered due diligence checklist; red flag reference card; Compliance contact info and hotline; country risk tier list (current TI CPI).
tools
Audits the complete in-scope medical-record universe in a litigation matter and produces an attorney-facing, Bates-cited analysis of treatment gaps, missing records or providers, baseline coverage, material billing or production mismatches, and complaint evolution. Use when asked to find missing medical records, analyze treatment gaps or first-care timing, identify absent providers, assess whether a production is complete, or prepare a records-request target list. Use medical-record-chronology instead when the primary request is a chronological clinical narrative.
development
Drafts a legally compliant Private Placement Memorandum for Regulation D offerings (Rule 506(b)/506(c)), covering full disclosure framework including risk factors, capitalization, securities terms, use of proceeds, and investor qualification requirements. Enforces SEC anti-fraud compliance under Section 10(b)/Rule 10b-5, blue sky law considerations, and accredited investor verification under Rule 501. Use this skill when drafting PPMs, offering memorandums, Reg D disclosure documents, or private offering circulars for issuers raising capital from sophisticated investors. Also trigger when the user mentions private placement disclosure, offering memorandum, Reg D fundraising, or accredited investor verification. Even if the user just says "PPM" or "draft our offering memo," use this skill.
data-ai
Generates structured privacy and data protection law briefings across US, EU, UK, and other jurisdictions. Organizes by jurisdiction with compliance deadlines, enforcement actions, and legislative changes. Use when preparing privacy law briefings, compliance updates, regulatory change summaries, or data protection landscape reviews.
testing
Generates structured summaries of prior art references for patent prosecution, validity analysis, and freedom-to-operate assessments. Maps disclosures to claim elements with precise citations. Use when summarizing prior art, analyzing patent landscapes, mapping references to claims, or preparing office action responses.