A service of

Adapting Compliance Programs to Manage Criminal and Civil FTO Risk

One of the first acts of the second Donald Trump presidential administration (Trump 2.0) was to issue Executive Order 14157 calling for the designation of several transnational criminal organizations (TCOs) as foreign terrorist organizations (FTOs). Since then, the U.S. Department of State has designated multiple TCOs in Latin America (and Haiti) as FTOs.

While any dealings with a TCO were always risky for a multinational company (doing business with criminal organizations is usually bad for business in the long run), interacting with an FTO triggers additional laws that can have serious consequences. The Anti-Terrorism Act of 1987 (together with future amendments, ATA), targeted at preventing the Palestine Liberation Organization from operating in the U.S., was the first piece of legislation to address terrorism as such. It was reenacted in 1992, followed by the Antiterrorism and Effective Death Penalty Act of 1996, which allowed for the designation of additional terrorist organizations as well as a host of other changes. After the terrorist attacks of September 11, 2001, Congress passed the Uniting and Strengthening America by Providing Appropriate Tools Required to Intercept and Obstruct Terrorism Act of 2001 (USA PATRIOT Act), which expanded the U.S. government’s abilities to seize assets and increased its investigative powers.

Then, in 2016, Congress further amended the ATA in the Justice Against Sponsors of Terrorism Act (JASTA). The JASTA broadened the rights of victims of terrorist attacks carried out by designated FTOs to sue individuals or entities that aided or abetted those acts. With the new FTO designations of TCOs, this right to sue under JASTA could be an area of significant risk for companies that do business in Latin America.

As a result, companies need to take a holistic approach to mitigating FTO risk that addresses the heightened risks of enforcement, the possibility of civil suits and the potential for reputational harm. The Anti-Corruption Report spoke with Rebecca (Becky) Rohr, the former CCO and head of investigations at Telefonaktiebolaget LM Ericsson (Ericsson), a multinational telecommunications company headquartered in Stockholm, Sweden, that resolved bribery allegations with the DOJ in 2019 and again in 2023. Ericsson also was sued in a civil litigation partially based on the ATA due to allegations that the company made protection payments to the Islamic State in Iraq and al-Sham (ISIS). That suit was eventually dismissed. This article highlights Rohr’s insights on how companies can adjust their compliance programs to address these emerging areas of risk, based on her in-house experience as well as her time as a leader and prosecutor in the DOJ’s Criminal Fraud Section.

See “The Importance of Human Intelligence in Mexico to Combat FTO Risk” (Jul. 15, 2026).

A Historical Perspective on FTO Risk

ACR: Five years ago, how common was FTO risk and where were companies encountering it?

Rohr: Five years ago, FTO risk was pretty limited for most companies. At that time, the organizations designated as FTOs were well-known terrorist organizations such as ISIS and Hezbollah. As such, there were few touch points between organizations designated as FTOs and most companies.

That is reflected in the fact that there were really only two major criminal cases against companies for support of terrorism. In March 2007, Chiquita Brands International pled guilty to one count of engaging in transactions with a “specially-designated global terrorist,” and, in 2022, global building materials manufacturer Lafarge SA pled guilty to conspiring to provide material support and resources to designated FTOs in Syria, including ISIS.

ACR: How do the designations made since January 2025 differ from those made previously?

Rohr: The designations in 2025 and 2026 are different in that they are targeting criminal organizations rather than ideologically driven terrorist groups. The administration has made clear that eliminating cartels and TCOs is a priority, and these designations are a tool it is using toward that elimination. Many TCOs were already covered by sanctions, but the new designations allow the government to bring charges under the anti-terrorism laws, which increases the potential of a criminal prosecution instead of a regulatory action and brings more significant consequences. Additionally, the designations allow private plaintiffs to bring civil suits under the ATA. That ratchets up the potential consequences for companies.

[See “How the U.S. Focus on Cartels and Transnational Criminal Organizations Impacts Multinationals in Mexico” (Jul. 2, 2025).]

New Areas of Risk

ACR: Prior to Trump 2.0, how common was it for TCOs to be sanctioned, and how did that impact companies?

Rohr: There were some sanctions against narcotics criminals, for example, those designated under the Foreign Narcotics Kingpin Sanctions Regulations. Most companies have some sort of sanctions screening as part of their third-party due diligence. This screening would likely identify any sort of direct payments to a criminal cartel or a contractual relationship with them, but that was unlikely to happen in the first place because companies generally do not engage in direct transactions with criminal cartels.

ACR: What is the difference in risk between a TCO that is on a sanctions list versus one that has been designated as an FTO?

Rohr: Once a TCO is designated as an FTO, the “material support” of terrorism provisions of the ATA, as codified in 18 U.S.C. §§ 2339A and 2339B, applies. These provisions have been interpreted broadly by the DOJ to include payments made through intermediaries and third parties. The statute applies to “whoever knowingly provides material support,” to an FTO and does not require an intent to promote the terrorist activities. Additionally, the statute of limitations under the anti-terrorism laws is longer – 10 years. The statute has extraterritorial applications beyond most other criminal statutes, as well.

On a more practical level for companies, a criminal case by the DOJ against a company for terrorism violations has a different reputational hit than a sanctions violation.

ACR: How might plaintiffs use the ATA to bring claims against companies?

Rohr: Under 18 U.S.C. § 2333, any U.S. national who has been injured in connection with terrorism can bring a lawsuit. Usually, these suits are brought by military service members or their families directly against terrorist organizations. However, if a plaintiff can draw a connection between corporate conduct and the act of terrorism, a company could be sued, as well. It may be a more difficult argument to make, because the causality is less direct, but there are many creative plaintiffs’ attorneys who could come up with a case.

Identifying FTO Exposure

ACR: How important is it for companies to assess their risk for interacting with cartels, TCOs and designated FTOs?

Rohr: Assessing the risk of interacting with these groups is very important for companies to figure out right now. In many countries in Latin America, particularly Mexico, the cartels are so influential in most areas of day-to-day life that companies can be impacted in many ways that would not be accounted for by compliance programs built to prevent FCPA violations. Anti-corruption programs typically focus on government touchpoints, but there are many more potential interactions with cartels than with government officials, and the types of interactions are different. That is why local intelligence is so important for identifying these risks.

ACR: What does local intelligence look like, and how can companies use it?

Rohr: Local intelligence usually involves speaking with people who live and work in the area of concern to understand how local cartels and TCOs operate and how they might be interacting with companies.

One concern with local intelligence is that it is often based on personal relationships and word of mouth, which might not be fully accurate, and in any event does not allow for a robust paper trail explaining how a decision was made. But companies still should try to get local intelligence and then document their efforts at due diligence and risk assessment as much as possible, including the discussions with locals.

ACR: Can a company’s own employees help with local intelligence?

Rohr: Yes. A company can work with outside consultants who specialize in this type of intelligence gathering, but a company’s own employees can be excellent sources of local information, as well.

For example, the company businessperson who wants to work with a third party to accomplish the company’s project goals can be made accountable for understanding the third party’s ownership and any potential ties to cartels, TCOs or FTOs. Local company business leaders and procurement teams are also great sources of information.

If there is a local company team that handles physical security, it is important to bring them into risk assessments, as well, as they may have some of the most relevant information. After the initial assessment, it is totally feasible for a compliance team to set up an ongoing quarterly meeting with these employees to get a pulse check on what cartel activity there is in the region and any changes.

[See “Due Diligence in Africa: The Human Intelligence Factor” (Apr. 12, 2017).]

ACR: What are some unexpected places where you have seen companies make contact with TCOs?

Rohr: One of the most likely ways a company will encounter TCOs is through requests for safety payments or access payments. In Spanish, a safety payment may be called a derecho de piso, and it is essentially protection money where a cartel threatens violence if a fee is not paid. An access payment may be called a derecho de paso in Spanish, which is a small payment to access a work site or a road.

The question now is whether the DOJ might consider paying a derecho de piso or a derecho de paso as material support of an FTO, and what the DOJ would expect a company to know about who the recipients of the funds are.

ACR: Are there other places where companies may not realize they are encountering FTO risk?

Rohr: Cartels can also sometimes sneak into a company’s logistics and transportation. For example, the cartel may get a company’s truck driver to put its illicit goods onto a company truck or store things in a company warehouse.

Additionally, cartels can also play a hand in hiring local workers and might insert themselves into a company’s hiring of workers to collect fees. Cartels may also attempt to have their own people infiltrate the company, which can be a security risk.

A Complete Compliance Rethink

ACR: How can companies manage the risks associated with safety and access payments?

Rohr: All elements of compliance programs need to be redesigned to address and tackle FTO risk for any company doing business in regions where FTOs are present. The changed nature of the risk for companies is significant, and compliance programs operating in these countries must adapt to address it. Each of the hallmarks of an effective compliance program, for example, as outlined in the DOJ’s Evaluation of Corporate Compliance Programs, needs to be reevaluated and rethought through the lens of FTO risk, especially for companies that are doing business in Mexico or elsewhere in Latin America.

ACR: Where should a company begin in updating its compliance program to incorporate this new risk area?

Rohr: To start, policies need to make clear that the company does not tolerate payments to cartels, TCOs or FTOs, either by the company or third parties the company uses. That seems obvious, but it might not be a sentiment that companies have clearly articulated before.

Policies and procedures should also be updated to provide specific instructions for what to do if a safety or access payment is demanded. One possibility for companies is to say that protecting employee safety is the priority, but, other than for urgent safety reasons, the company does not allow those payments, and any such requests need to be documented and escalated quickly.

Additionally, it is important for companies to have ways of identifying requests for these payments and expediting them in the moment so that informed decisions can be reached about whether to make the payments. Companies should explore ways to avoid making protection payments. For instance, a company might be able to hire extra security to help prevent demands for these types of payments. Even if the company determines that employees’ safety is truly at risk and a payment needs to be made, it is critical for the situation to be properly assessed and documented.

ACR: Do trainings need to be updated, as well?

Rohr: Yes. Compliance training and other communications must be revised to discuss these new risks the company faces. Employees that are most likely to encounter requests for safety or access payments may need special training so that they know how to properly escalate.

Companies can start by using all the best practices they have learned from anti-bribery compliance, such as making information accessible to all levels of employees and in local languages, securing business leader buy-in for compliance even at the risk of losing business, and having a strong tone-from-the-top promoting ethical conduct and integrity. Companies need to clearly state that they do not condone making payments or providing services to criminal or terrorist organizations.

Then companies can provide specific training on what red flags to look for, how to respond to demands for payments from cartels, what approvals are necessary before payments are made, how to get answers to questions and the escalation procedures.

[See this three-part series “Rethinking Click-Through Training”: The Pluses and Minuses (Feb. 26, 2025), Maximize Effectiveness With Customization (Apr. 9, 2025), and Integration Into a Comprehensive Training Program (May 7, 2025).]

ACR: How might investigations need to change as a result?

Rohr: Investigation protocols need to be updated so that any possible nexus to a TCO or FTO is flagged as a high priority and escalated quickly. The company should apply best practices in conducting an investigation and consider involving outside counsel, placing the investigation under attorney-client privilege, particularly if a matter could result in a government investigation or private lawsuit.

ACR: What about third-party risk management?

Rohr: Updating third-party diligence is particularly important. Companies need to have an accurate understanding of their third parties and take a fresh look to try to identify touchpoints where newly designated FTOs might be involved. Multinational companies that use a risk matrix for each country (like Transparency International’s Corruption Perceptions Index) should include FTO risks, not only anti-bribery risks. Third-party questionnaires should now include screening questions that get at terrorism risk, and existing third parties should be rescreened using these new questions. Transaction monitoring should be adapted beyond anti-corruption and fraud risks and include cartel risks, and companies should consider increasing monitoring in regions subject to cartel risk.

Third-party contracts should also be updated to explicitly prohibit payments to cartels and FTOs just as they now prohibit bribes, and business partners should be required to report any interactions with cartels and TCOs that they have. This likely will require training of the third parties and the company business teams to ensure they understand what the company expects from them.

Outside of third parties that are business partners, companies also need to think about other payments that could be sources of FTO risks, such as charitable contributions and marketing sponsorships. The prepayment reviews should look at cartel risks.

ACR: You mentioned that cartels have tried to infiltrate companies by getting their members hired within a company. How can companies prevent that?

Rohr: This is one area where many companies may already have controls in place because it is a known security concern. Companies should have good vetting questions for prospective employees and identify high-risk positions that might be targeted by cartels. Companies might want to think about how to prevent existing employees from being compromised by cartels, as well, and make sure that employees in high-risk positions are rescreened periodically.

ACR: Is there one overarching thing companies should be thinking about to adjust their compliance programs to this new risk?

Rohr: The cleanest way to think about it is knowing who the company is doing business with. Many compliance programs were built around the FCPA and then broadened to prevent bribery more generally, and also address targeted risks such as sanctions, money laundering, fraud and trade compliance. But now, I think compliance needs to be expanded toward understanding all the ways in which money and services flow out of the company and all of the risks involved, including risks related to TCOs and FTOs, as a priority.

ACR: In situations where employee health and safety might be at risk, how can a company reassure employees that their well-being remains paramount while trying to avoid interacting with cartels?

Rohr: That is where tone at the top and local business leader involvement really become critical. If employees personally know the people delivering the message that the company does not support criminal organizations, they are more likely to believe it and follow the policy. The business leaders need to make clear that the principle applies even if it means losing business, delaying a project or having some other negative effect. Repetition, in multiple formats, is also important – this is not a message that employees will internalize after hearing it just once. Ultimately, the proof is in the pudding – employees will need to see examples of how the company has responded to requests for safety and access payments, including how the company analyzed the issue and any consequences for employees or third parties who did not comply with the company’s approach to these payments.

[See this four-part series on compliance representations and warranties: “Definitions and Goals” (Mar. 25, 2026), “Negotiations” (Apr. 8, 2026), “Verification and Enforcement” (May 6, 2026), and “Adapting to Emerging Risks” (Jul. 1, 2026).]