US DOJ’s New Corporate Enforcement Policy: What Indian Companies Operating Globally Need to Know
The US DOJ’s new policy rewards voluntary disclosure, cooperation and remediation, making early compliance action crucial for Indian companies with a US connection.
US DOJ’s New Corporate Enforcement Policy: What Indian Companies Operating Globally Need to Know
Indian companies expanding into international markets increasingly face regulatory exposure beyond India's borders. A transaction, employee, customer, intermediary or financial connection involving the United States can potentially bring a company within the scope of US enforcement authorities.
This issue has gained importance following the US Department of Justice's (DOJ) Corporate Enforcement and Voluntary Self-Disclosure Policy (CEP) issued on 10 March 2026.
The policy establishes a department-wide framework under which companies that voluntarily disclose misconduct, cooperate fully and remediate appropriately can receive significant enforcement benefits, including the possibility of a declination.
For Indian companies with global operations, the policy makes one point particularly important: the first few weeks after discovering potential misconduct can significantly influence the company's enforcement position.
What Is the DOJ Corporate Enforcement Policy?
The DOJ's new Corporate Enforcement and Voluntary Self-Disclosure Policy creates incentives for companies to voluntarily disclose misconduct and cooperate with investigations.
A company that satisfies the relevant requirements may potentially receive a declination, meaning the DOJ may decide not to prosecute the company.
Even where aggravating circumstances exist, the policy can provide substantial benefits, including a 50% to 75% reduction in penalties and no requirement for an independent compliance monitor in appropriate circumstances.
The policy therefore creates a strong incentive for companies to respond quickly and systematically when serious misconduct is discovered.
Why Indian Companies Should Pay Attention
It would be a mistake for an Indian company to assume that US enforcement matters only when it is incorporated or listed in the United States.
A US connection can arise through several channels, including:
- US-listed securities
- Dollar-denominated transactions
- US investors
- American Depositary Receipts (ADRs)
- US-based servers or employees
- American customers
- Overseas subsidiaries
- Global tenders
- US-connected intermediaries
The risk can be particularly relevant to businesses operating internationally in sectors such as:
- Pharmaceuticals
- Healthcare
- Defence
- Energy
- Infrastructure
- Logistics
- Mining
- Technology
The First 30 to 90 Days Can Be Critical
One of the most practical lessons from the policy is the importance of the company's initial response.
The source highlights the first 30 to 90 days after discovering potential misconduct as particularly important.
Delays, informal internal clean-ups or inconsistent explanations can undermine a company's ability to demonstrate meaningful cooperation.
For Indian companies, this is especially relevant because internal complaints may initially be treated as ordinary HR, vigilance, audit or business matters.
Where the facts indicate a potential US connection, that approach may create unnecessary risk.
Step 1: Identify US Connections
The first step should be determining whether the DOJ could have a plausible jurisdictional connection.
Companies should examine whether the matter involves:
- US-listed securities
- Dollar transactions
- US-routed data
- American customers
- US-connected intermediaries
- US employees or operations
A single US connection does not automatically mean that a company must make a disclosure to the DOJ.
However, it should trigger a cross-border legal assessment rather than being treated as an ordinary domestic compliance issue.
Step 2: Preserve Evidence Immediately
Evidence preservation is essential when potential misconduct is identified.
Relevant information may exist across multiple systems and devices, including:
- Emails
- WhatsApp conversations
- Personal devices
- ERP systems
- Invoices
- Internal spreadsheets
- Third-party records
Companies should consider issuing appropriate legal holds, securing relevant devices lawfully and taking steps to prevent the deletion or alteration of potentially relevant material.
The ability to demonstrate what was preserved, when it was preserved and why certain information may be unavailable can become important when seeking cooperation credit.
Step 3: Investigate Quickly
The DOJ does not necessarily expect a company to have every answer immediately.
What matters is a prompt, good-faith and focused preliminary investigation.
The initial investigation should attempt to establish:
What happened?
Understand the basic nature of the allegation.
Is the allegation credible?
Determine whether there is sufficient information to justify further investigation.
Who may be involved?
Identify employees, executives, intermediaries or third parties potentially connected to the conduct.
Is there a US connection?
Establish whether the conduct potentially falls within US enforcement jurisdiction.
Is the conduct continuing?
Ongoing misconduct may require immediate intervention.
Are regulators or auditors already aware?
The company should understand whether disclosure obligations have already been triggered elsewhere.
The source also emphasises the importance of involving the board or audit committee at an early stage in serious matters.
Step 4: Remediate the Root Cause
Simply removing one employee or changing a compliance document may not be enough.
Effective remediation should address why the misconduct occurred in the first place.
This can involve:
- Root-cause analysis
- Disciplinary action against responsible individuals
- Strengthening payment controls
- Improving communication controls
- Revising internal compliance systems
- Enhancing third-party oversight
The objective should be to prevent similar misconduct from occurring again rather than merely responding to the individual incident.
Third-Party Risk Is Particularly Important
For Indian companies operating internationally, third parties can represent a significant compliance risk.
These may include:
- Agents
- Distributors
- Customs brokers
- Joint-venture partners
- Intermediaries
Basic KYC checks may not always be sufficient.
Companies may also need to consider:
- Beneficial ownership
- Political exposure
- Sanctions connections
- Unusual commission structures
- Success-fee arrangements
- Relationships with public officials
Third-party relationships should therefore form an important part of any internal compliance review.
Step 5: Coordinate Indian and US Legal Obligations
A US disclosure strategy cannot be considered independently of Indian law.
The same facts may potentially trigger obligations under:
- SEBI regulations
- Companies Act, 2013
- Prevention of Money Laundering Act (PMLA)
- Foreign Exchange Management Act (FEMA)
- Sector-specific regulations
- Lender covenants
- Commercial contracts
- Arbitration agreements
This makes coordination particularly important.
Different regulators or stakeholders receiving inconsistent explanations can create additional legal problems.
Companies therefore need to carefully sequence communications and understand the consequences of disclosure in every relevant jurisdiction.
Should Every Company Immediately Self-Report?
No.
The new DOJ policy should not be interpreted as requiring every company to immediately approach US authorities whenever a potential compliance issue arises.
Self-disclosure can itself create consequences.
Depending on the facts, disclosure could potentially lead to:
- Criminal exposure under Indian law
- SEBI disclosure obligations
- PMLA implications
- FEMA concerns
- Contractual disputes
- Arbitration claims
- Additional regulatory scrutiny
The decision should therefore be made after considering the company's complete legal position.
The Role of the Board and Audit Committee
Serious misconduct allegations should reach the appropriate level of corporate oversight.
The board or audit committee should ideally receive a structured assessment covering:
- Known facts
- Potential US nexus
- Indian legal implications
- Available disclosure options
- Remediation measures
- Litigation risks
- Regulatory consequences
This helps ensure that the company's decision is documented, informed and capable of being revisited as new facts emerge.
Why Documentation Matters
A company may ultimately decide not to make an immediate voluntary disclosure.
That decision should not necessarily be viewed as evidence of non-cooperation.
What matters is whether the company can demonstrate that it reached the decision through a reasoned and good-faith process.
A properly documented assessment can show:
- What information was available
- What legal advice was considered
- Which risks were identified
- What alternatives were evaluated
- Why a particular course of action was selected
This can become valuable if the company's decision is later examined by regulators or investigators.
What Indian Companies Should Do Now
Companies with significant international operations should consider strengthening their compliance systems around potential US exposure.
1. Map US Touchpoints
Identify transactions, customers, investors, employees, data systems and intermediaries connected with the US.
2. Create an Escalation Protocol
Potential misconduct with a US connection should be escalated quickly to the appropriate legal and compliance teams.
3. Strengthen Evidence Preservation
Establish clear procedures for legal holds and preservation of electronic and third-party evidence.
4. Review Third-Party Relationships
Go beyond basic KYC and assess ownership, political exposure, sanctions risks and unusual payment structures.
5. Coordinate Cross-Border Counsel
Indian and US legal advisers should work together where jurisdictional and privilege issues overlap.
6. Prepare Board-Level Reporting
Serious matters should be presented to the board or audit committee in a structured format.
Key Takeaways
- The US DOJ issued its first department-wide Corporate Enforcement and Voluntary Self-Disclosure Policy on March 10, 2026.
- Voluntary disclosure, cooperation and timely remediation can provide significant enforcement benefits.
- Indian companies can face US exposure even without being US-listed or having an American subsidiary.
- US connections can arise through dollar transactions, American customers, investors, employees, servers and intermediaries.
- The first 30 to 90 days after discovering potential misconduct can be especially important.
- Companies should preserve evidence before conducting informal internal clean-ups.
- Third-party relationships require careful compliance monitoring.
- US disclosure decisions must be coordinated with Indian legal and regulatory obligations.
- Self-disclosure should be based on a structured legal assessment rather than an automatic response.
- Board and audit committee involvement can help ensure that major decisions are informed and properly documented.
Conclusion
The DOJ's new Corporate Enforcement and Voluntary Self-Disclosure Policy creates a significant compliance consideration for Indian companies operating across borders.
The most important lesson is not that every company should immediately self-report potential misconduct. Instead, companies need to identify US connections early, preserve evidence, investigate promptly, assess cross-border legal obligations and make carefully documented decisions.
For businesses with international operations, the handling of a compliance incident can sometimes be as important as the underlying misconduct itself.
A structured response involving legal, compliance, investigation and board-level oversight can help companies understand their options and determine whether voluntary disclosure, remediation or another response is appropriate.
The policy therefore makes speed, documentation and coordinated cross-border decision-making central elements of modern corporate compliance