Buying a Sanctions Violation, Part 1: The FCPA Lesson Every Acquirer Already Knows, With a Twist That Makes Sanctions Worse

Anyone who has spent time in the FCPA world knows the basic cautionary tale of M&A: you can buy a company and, with it, you can buy its bribery problem. Compliance professionals have spent two decades building pre-acquisition due diligence protocols around that idea. The same lesson applies to economic sanctions, but with a twist that makes the sanctions version in many ways more dangerous. This is the first of a three-part series on what it means to acquire a sanctions violation. Part 1 lays out the FCPA analogy, explains the twist, and walks through what OFAC’s 2019 Framework for Compliance Commitments says about mergers and acquisitions. Part 2 examines enforcement actions where the acquirer’s diligence missed the problem or failed to prevent it. Part 3 covers the cases where the acquisition itself created U.S. jurisdiction over conduct that continued after closing, and ends with a practical deal playbook.
The FCPA Analogy
In the FCPA context, the acquirer’s exposure comes in two flavors. First, there is inherited liability: if the target was already subject to the FCPA and had paid bribes before the deal, the buyer can end up responsible for that history as a successor. Second, there is the risk of continuing misconduct: if corrupt practices keep going after closing, the buyer is now the owner of a business that is actively violating the law under the buyer’s own roof. Enforcement agencies have long said that the way to manage both risks is the same: do real diligence before the deal, integrate compliance quickly after it, and self-report what you find. A buyer that does those things can expect meaningful credit. A buyer that doesn’t can expect to be treated as having bought the problem on purpose.
Sanctions follow the same two-flavor structure. An acquirer can inherit a target’s past violations. And an acquirer can find that violations continue after closing. But sanctions add a third dynamic that the FCPA world mostly doesn’t have, and it deserves its own section.
The Twist: Sometimes the Acquisition Itself Creates the Jurisdiction
The FCPA generally doesn’t reach a foreign company that has no connection to the United States, which means that when a U.S. company acquires a foreign target, the target’s pre-closing foreign bribery usually isn’t a violation of U.S. law to begin with. The buyer’s problem is primarily about what happens after closing.
Sanctions work differently, and the difference is enormous. Under several of the most important U.S. sanctions programs, notably Cuba and Iran, a foreign company that is owned or controlled by a U.S. person is itself subject to the sanctions prohibitions. That means the moment a U.S. company or a U.S.-controlled fund takes ownership of a foreign business, that business can go overnight from lawfully doing business with a sanctioned country, in the eyes of local law, to violating U.S. law every time it does the same thing the next day. Nothing about the foreign target’s business has changed. The only thing that changed is who owns it. The acquisition created the jurisdiction.

That is the central lesson in a series of OFAC enforcement actions, and it is why I think of acquiring a sanctions violation as a distinct category of risk. In many cases, the acquirer isn’t buying a historical problem at all. It’s buying a business model that is lawful until the closing date and unlawful on the day after, unless the acquirer takes affirmative steps to shut the problem down and verify that it has been shut down.
What the 2019 OFAC Framework Says About M&A
OFAC’s Framework for Compliance Commitments, which I discussed in a recent series, lists mergers and acquisitions explicitly as an area where organizations face recurring sanctions challenges. The Framework observes that, in recent years, M&A transactions appear to have presented numerous challenges with respect to OFAC sanctions, and it tells organizations to treat M&A as a core element of their sanctions risk assessment. Its specific expectations are worth restating plainly, because they function as OFAC’s own checklist for what an acquirer should have done:
First, compliance functions should be integrated into the merger, acquisition, and integration process itself, whether as an adviser or as a participant. Compliance shouldn’t be learning about the deal after signing.
Second, the organization should conduct appropriate due diligence so that sanctions-related issues are identified, escalated to the relevant senior levels, and addressed before the transaction concludes. Notice the sequence: identify, escalate, and address, all before closing.
Third, those issues should be folded back into the organization’s ongoing risk assessment process.
Fourth, and this is the sentence that many acquirers miss, the Framework says that after the transaction is completed, the organization’s audit and testing function will be critical to identifying any additional sanctions-related issues. In other words, OFAC expects verification after closing, not just paperwork before it. The Framework also singles out transactions involving non-U.S. companies as warranting special attention in risk assessments and due diligence.
If you read the enforcement cases I discuss in this series with that language in mind, you will see that nearly every one of them is a story about one of those four expectations failing.
DOJ Adds a Safe Harbor Incentive

The Justice Department’s National Security Division has reinforced the same message with an incentive structure. Under its March 2024 enforcement policy, an acquirer that completes a bona fide acquisition, voluntarily and promptly self-discloses misconduct by the acquired company, generally within 180 days after closing, cooperates fully, and remediates appropriately, generally within one year of closing, can expect a presumption that the Justice Department will decline to prosecute the acquirer. That is a meaningful carrot. As I’ll discuss in Part 2, the first public declination under that policy, involving a private equity firm that acquired a Texas catalyst company, came in 2025. It also illustrates the limit of the carrot: the acquirer escaped prosecution, but the acquired company still paid millions in penalties and forfeiture.
Strict Liability Changes the Calculus
One more feature of sanctions enforcement matters here: civil liability under OFAC’s programs is strict liability. A company can violate the regulations without knowing, and without intending to, and still face a penalty. OFAC does consider knowledge, willfulness, concealment, voluntary self-disclosure, and the quality of the compliance program when it decides how to treat a case, and those factors can move a penalty dramatically. But the basic liability doesn’t depend on whether the acquirer’s executives had any idea what the target’s employees were doing overseas. As we will see, some acquirers were deceived by the target’s managers, did everything the playbook said, and still ended up paying penalties.
What Comes Next
With the framework in place, the next installment turns to the cases. Part 2 covers acquisitions where the buyer’s diligence failed to uncover the sanctions problem, including a private equity firm’s purchase of a Texas catalyst manufacturer and a consumer-products giant’s acquisition of a cosmetics company, and a case where the buyer found the Iran exposure during diligence and still could not stop it. Part 3 covers the jurisdiction-trigger cases, where the closing itself switched on U.S. sanctions for the target’s foreign business, and then closes with a practical checklist for dealmakers.











