Skip to main content
Adapting Your Third-Party Program for FTO DesignationsAnti-Corruption & AML
5 min readFor Ethics & Hotline Program Leaders

Adapting Your Third-Party Program for FTO Designations

The Problem: Why This Matters Now

In June, the US State Department designated Brazil's Primeiro Comando da Capital (PCC) and Comando Vermelho (CV) as foreign terrorist organizations (FTOs). This designation exposed a compliance gap that many programs weren't prepared to handle.

Your vendor screening likely checks for payments to government officials and sanctions lists for politically exposed persons. However, it may not be equipped to identify beneficial ownership linked to a criminal organization now labeled as an FTO or to differentiate a routine invoice from a protection payment made under duress.

The financial consequences are significant. For example, Lafarge paid over $778 million and Chiquita Brands paid $25 million for material-support violations related to payments intended to maintain operations. The intent behind the payments was irrelevant; the liability was triggered regardless.

If your organization operates in Latin America through contractors, subcontractors, or joint ventures, your current screening process might not catch these exposures. More designations are expected, with this being the fourth or fifth round since the policy began, depending on how you count, and the pace isn't slowing.

The question isn't whether to adapt, but when. Will you do it now, thoughtfully, or later, in response to a government inquiry?

What You Need Before Starting

Before making changes, gather your existing resources:

  • Your current third-party due diligence questionnaire: Use the version you actually send to vendors.
  • Your vendor screening workflow: Identify who runs checks, what lists they consult, and when they escalate findings.
  • Your existing sanctions and politically exposed persons screening lists: You'll be adding to these, not replacing them.
  • A current copy of the Treasury's Office of Foreign Assets Control (OFAC) specially designated nationals list: This list is public and frequently updated.
  • The State Department's list of designated foreign terrorist organizations: Also public and subject to change.
  • Your training materials for employees who interact with third parties: Understand what they've been taught to recognize.
  • Access to your ISO 37001 audit documentation: If you're using a different standard, gather your existing anti-bribery compliance records.

You don't need new software or a larger team. You're expanding the scope of your existing process.

Step-by-Step Implementation

1. Add an FTO and TCO Screening Section to Your Questionnaire

Update your third-party due diligence questionnaire with a new section that asks:

  • Does the entity or any beneficial owner appear on the OFAC specially designated nationals list?
  • Does the entity or any beneficial owner appear on the State Department's FTO list?
  • Does the entity operate in territory where a designated transnational criminal organization controls legitimate commerce?
  • Has the entity made payments under duress to non-governmental armed groups in the past 24 months?

These questions need their own header and escalation path.

2. Map Beneficial Ownership for High-Risk Counterparties

For vendors, subcontractors, or partners operating in high-risk areas like Sao Paulo or Rio de Janeiro, trace beneficial ownership back to natural persons. This step is crucial, as ownership structures can be opaque.

If a vendor can't or won't provide beneficial ownership documentation, consider it a red flag. Don't proceed without clarity.

3. Build FTO and TCO Screening into Your Intake Workflow

Incorporate the OFAC specially designated nationals list and the State Department FTO list into your existing sanctions screening. Conduct these checks at the same stage as politically exposed persons screening.

If using third-party screening software, add these lists to your automated checks. For manual searches, create a checklist for vendor intake.

4. Re-Screen Existing Vendors Periodically

A counterparty that cleared screening two years ago may not clear it today. Integrate the new FTO and TCO checks into your periodic re-screening process.

Set a calendar reminder to update OFAC and State Department lists every 90 days and screen your active vendor roster. If you're doing annual reviews, include the FTO and TCO checks.

5. Create a Separate Escalation Path for Duress Payments

If a field employee reports a vendor demanding payment to "keep things moving," or if an invoice seems like a protection payment, escalate it directly to your legal or compliance team. It shouldn't be treated as a regular vendor dispute.

Establish a clear rule: no payment under duress to any non-governmental armed group. Ensure those managing vendor relationships know this rule and where to escalate issues.

6. Tie Your Documentation to Your Existing Audit Framework

If ISO 37001 is your audit backbone, align your FTO and TCO records with your anti-bribery records. One vendor file should support both a bribery audit and a material-support review.

Don't create a separate filing system. Expand the one you have.

7. Update Your Training Materials

Employees need to recognize protection payments, which differ from gifts to government officials.

Add a training module covering:

  • What material support means under federal law
  • How to identify payments made under duress
  • Why payments intended to keep operations running still create liability
  • Where to escalate if pressured by a non-governmental group

Use plain language. Don't assume employees will connect "terrorist designation" with "vendor invoice" on their own.

Validation: How to Verify It Works

Test your updated process with a hypothetical vendor in a contested area:

  • Does your questionnaire reveal the right information?
  • Do your screening checks identify matches against the FTO or specially designated nationals lists?
  • Does your escalation path direct findings to the right person?
  • Can you produce an audit-ready record of your checks?

If any step fails, fix it before full implementation.

Re-screen a sample of existing vendor files against updated lists. Treat any new matches as live issues and escalate them.

Ensure those handling vendor relationships understand the new duress-payment rule and know where to escalate. If there's any uncertainty, your training needs improvement.

Maintenance / Ongoing Tasks

  • Every 90 days: Update OFAC and State Department lists and re-screen your active vendor roster.
  • Every six months: Review your questionnaire. Add new designations to your screening checklist.
  • Every 12 months: Audit a sample of vendor files to confirm compliance with the process. Ensure FTO and TCO screening occurs at intake and re-screening is on schedule.
  • When a new designation is announced: Add it to your screening lists immediately. Run your active vendor roster against the new designation within 30 days.
  • When your team escalates a duress-payment report: Document, investigate, and, if necessary, self-disclose. Track reporting deadlines separately, as they may differ.

This isn't a one-time project. The policy is expanding, and your process needs to keep pace. But you don't need to rebuild your program from scratch. You're adding a lane to the road you're already traveling.

You Might Also Like