Corporate Gifting Stack

Gifting Compliance and Anti-Bribery Rules

Context matters more than the gift itself—intention, value, and timing determine legal exposure.

Staff Writer · · 15 min read
Gift Strategy & Planning · August 1, 2026 · 15 min read · 3,465 words

Gift-giving is not illegal under any of the major anti-bribery frameworks. The FCPA does not prohibit gifts. The UK Bribery Act does not prohibit gifts. What these laws prohibit is corrupt purpose, and that distinction, while clean on paper, gets complicated when someone on your sales team is standing in an airport trying to figure out whether sending a bottle of wine tonight is a problem.

Courts and enforcement agencies look at three things: intention, value, and timing.

Intention is the core question. Was the gift given to influence a specific act or decision? A bottle of wine sent to a client after a deal closes reads differently than the same bottle sent the night before a procurement committee votes. The gift is identical. The legal exposure is not. And here is the uncomfortable part: ignorance of context does not reliably reduce the risk. A sender who failed to register the timing is not necessarily protected by that fact. But what if the sender had no knowledge of the timing — does that change anything? Not reliably, no.

Value functions as a signal, not a threshold. A gift whose dollar amount is difficult to explain as mere courtesy invites scrutiny. Prosecutors do not need a signed confession of corrupt intent; circumstantial evidence is sufficient. An extravagant gift, or a pattern of gifts to the same official within a compressed timeframe, can build a circumstantial case without any single transaction crossing an obvious line.

Timing compounds both. A gift exchanged during an active tender, a regulatory review, or an open dispute carries substantially more scrutiny than one sent during a holiday cycle or after a project closes. The same instinct that tells you not to have certain conversations at certain moments applies here, just with a purchase order instead of a phone call.

The FCPA Resource Handbook offers a useful positive framing: an appropriate gift is given openly and transparently, properly recorded in the sender's books, offered only to reflect esteem or gratitude, and permitted under local law. Notice that documentation appears on that list. The gift itself and the record of the gift are both elements of compliance. A gift that checks every substantive box but goes unrecorded is harder to defend than one that is documented thoroughly, even if its value sits at the upper edge of reasonable.

The same physical object can be entirely legal or potentially criminal depending on context. Documentation and intent are what separate them.

The two laws that any company with international exposure must understand: the FCPA and the UK Bribery Act

Table: FCPA vs. UK Bribery Act: Key Differences. Compares Who It Covers, Corporate Liability, Key Defense, Geographic Reach, and 1 more by FCPA and UK Bribery Act.

If your company sells to customers in more than one country, two statutes very likely apply to your gifting program, whether your legal team has told you so explicitly or not.

The Foreign Corrupt Practices Act

The FCPA is a U.S. law with a reach that extends well beyond U.S. borders. It prohibits payments or promises of anything of value, including non-monetary gifts, to foreign government officials for the purpose of obtaining or retaining business. Two components matter for gifting programs: the anti-bribery provisions establish the prohibition, and the accounting provisions require that transactions be recorded accurately in the company's books. A gift that is legal in substance but recorded sloppily, or not recorded at all, can still generate a violation on the accounting side.

The enforcement record makes this concrete. Siemens AG paid $800 million in penalties under the FCPA. Walmart settled for $282 million, largely because of inadequate anti-corruption controls rather than any single egregious act. These are cautionary tales about organizations that never built a compliant program in the first place and then found out what that costs.

The statute applies to U.S. persons and companies, to foreign companies listed on U.S. exchanges, and to anyone acting within U.S. territory. That last category is broader than it sounds. A transaction that originates in California and concludes in Mumbai can be prosecuted under the FCPA.

The UK Bribery Act

The UK Bribery Act is broader than the FCPA in two ways that consistently catch American companies off guard.

First, it covers bribery of private-sector individuals, not only public officials. A government contract does not need to be on the table for the Act to apply. A gift to a commercial counterpart at a private company, if intended to induce improper performance of a business function, can constitute bribery under UK law. That is a meaningful expansion of scope relative to what most U.S. compliance teams are calibrated to think about.

Second, the Act includes a corporate offense of failing to prevent bribery. A company can be liable even when senior management had no knowledge of the offending conduct, so long as the company cannot demonstrate it had adequate procedures in place. That shifts the burden considerably. The absence of a written policy is not merely an administrative gap; it is also a potential element of criminal liability.

The Act applies to any company doing business in the UK, including U.S. firms with a subsidiary, an office, or a meaningful commercial presence there. If your company has a London office, the UK Bribery Act belongs to your compliance team's portfolio, not someone else's.

The state-owned enterprise trap that catches most companies off guard

Most gifting-related FCPA violations do not originate where people expect them to.

The common mental model involves someone writing a check to a customs official or bribing a government minister. The reality of enforcement is more mundane: a sales team sends gifts to procurement contacts at what they categorize internally as a healthcare company, an energy company, or a university, without recognizing that the entity is state-owned and its employees are therefore foreign government officials under the FCPA.

The DOJ test is functional, not formal. If a foreign government has majority ownership or significant operational control over an entity, that entity's employees are treated as foreign officials for FCPA purposes, regardless of whether the entity calls itself a corporation or operates in a nominally commercial sector. Engineers at national petroleum companies, doctors at public hospitals, researchers at state-funded universities, procurement officers at sovereign wealth funds: all of these categories have appeared in actual enforcement actions.

Sales and account teams typically organize their workflows around industry vertical, not government affiliation. The healthcare team sends to healthcare contacts. The energy team sends to energy contacts. Nobody stops to ask whether the hospital is government-affiliated or the energy company is majority state-owned, because the question does not fit naturally into a CRM-driven workflow. That raises an important question: at what point in the workflow should that classification check actually happen? The answer is at recipient vetting — before any send is initiated. The classification check that should happen at recipient vetting gets skipped, and the team fails to register the exposure until something else surfaces it.

Your internal policy needs to define "government official" expansively enough to capture employees of state-owned or state-controlled enterprises, political party officials, regulators, customs and immigration agents, and employees of public international organizations. A definition that only covers people with government titles or government email addresses is too narrow for the actual enforcement landscape.

Recipient vetting, not gift value, is the first gate in any compliant gifting workflow. You cannot calibrate an appropriate threshold for a gift if you do not know who you are sending it to.

How sector-specific rules layer on top of the general anti-bribery statutes

The FCPA and UK Bribery Act are the floor. Depending on the industries your customers operate in, additional regulatory frameworks impose their own requirements, often with specific dollar thresholds and recordkeeping obligations that are more stringent than the general statutes.

Financial services

FINRA Rule 3220 historically capped gifts connected to a recipient's employer's business at $100 per person per year, with separate recordkeeping required for all gifts and gratuities. In May 2025, FINRA filed a proposed amendment to raise that cap to $300 per person per year, and the SEC approved the amendments in February 2026. If your company sells to financial services firms, your thresholds need to reflect the updated figure.

The subtler risk in financial services is aggregation. If multiple employees within your organization each send a gift to the same recipient, their individual sends may each fall under the annual cap while the combined total does not. Manual tracking on spreadsheets makes this nearly impossible to catch in any organization with more than a handful of people sending gifts, which is one of the clearest practical arguments for centralized, technology-enabled tracking.

Healthcare and pharmaceutical

Two separate legal frameworks apply here, and they interact in ways that create real operational complexity.

The Sunshine Act requires pharmaceutical and medical device companies to disclose any transfer of value to physicians or hospitals. The reporting threshold is low, roughly $13 per individual payment in recent years with an aggregate annual trigger in the low hundreds of dollars, low enough that almost any gift of consequence to a clinical or procurement contact at a hospital requires disclosure.

Separately, the Anti-Kickback Statute creates felony liability for gifts to decision-makers when the giver's goods or services are reimbursed under a federal healthcare program. The connection between the gift and the reimbursable product does not need to be explicit. A supplier of medical devices who sends gifts to hospital procurement officers operates in this risk zone whether or not anyone in the room draws that connection.

Anyone in a clinical or procurement role at a hospital needs Sunshine Act status verification before a send is initiated. That verification needs to be a built-in workflow step, not something a sender is expected to remember to do on their own.

U.S. federal employees

Federal employees may accept unsolicited gifts not exceeding $20 per occasion, with an aggregate annual limit of $50 from a single source. Cash and checks are prohibited in any amount. Gift cards valued at $20 or less for specific vendors are technically permissible under some interpretations, but a $20 gift card and a $20 box of food are treated differently under federal ethics rules, and the distinction carries practical consequences.

Sector-specific rules do not replace FCPA or UK Bribery Act analysis. They stack on top of it. A healthcare-sector contact who also works at a government-affiliated hospital is subject to both the Sunshine Act and the FCPA simultaneously. Your compliance workflow needs to surface both layers at once, not sequentially.

How thresholds and local customs differ by country, and why a single global dollar limit doesn't work

Many companies respond to the complexity of international gifting by establishing a single global cap, something like $50 or $75 per recipient, and assuming that conservative uniformity solves the problem. It does not, and the failure mode is worth understanding concretely.

Singapore civil servants cannot retain gifts worth SGD 50 or more without remitting the value to the government. Singapore tax law treats a gift exceeding SGD 200 as taxable income to the recipient. A flat $75 U.S. dollar cap will clear Singapore's gift-receipt threshold in some cases while inadvertently generating a tax event for the recipient, which is a problem your counterpart bears but your program caused.

China's criminal law sets specific monetary thresholds, beginning at RMB 10,000, to define prosecutable bribery. But government bodies and state-owned enterprises commonly set their own internal hospitality limits far below that figure, around RMB 200 in many cases. That is substantially lower than what most Western gifting programs spend per recipient. China also enforces anti-bribery rules against private-sector recipients more assertively than U.S. law does, which is a calibration most American compliance teams have yet to make.

Saudi Arabia, India, and Brazil each maintain their own frameworks that do not map directly onto FCPA or UK Bribery Act thresholds. A policy derived from U.S. legal standards and applied uniformly across all three creates gaps in each one.

Frequency compounds this further. A pattern of regular hospitality in any jurisdiction can suggest corrupt intent even when each individual gift falls below the applicable local threshold. The pattern itself becomes evidence.

A uniform global cap optimizes for administrative simplicity at the expense of accuracy. A $50 limit is conservative enough for some U.S. commercial contacts, too generous for a Singapore civil servant, and potentially meaningless as a compliance signal for a Brazilian procurement official operating under an entirely different legal structure.

What actually works across jurisdictions is a tiered framework built around three variables: recipient type (government official, SOE employee, regulated-sector commercial contact, standard commercial contact), country risk level, and the specific business context of the send. That framework is more complex to administer. There is no simpler version that produces the same result.

U.S. tax rules that affect how gifting programs are structured and what can be deducted

Most finance and procurement teams know there is a tax deduction associated with business gifts. Fewer know how narrow it actually is, or how many common gifting practices fall outside it entirely.

Section 274(b) of the Internal Revenue Code caps the deduction for business gifts at $25 per recipient per tax year. That cap was set in 1962. Adjusted for inflation, $25 in 1962 represents roughly $260 in today's purchasing power. The statute has never been updated, which means the tax code effectively treats a meaningful gift to a client as largely non-deductible. Most companies have quietly accepted this as a cost of doing business, which is probably the right call, but it is worth understanding explicitly rather than discovering during a finance review.

The cap is per recipient, not per gift. Three gifts sent to the same client across a calendar year represent $75 in total spending but generate only a $25 deduction. That distinction matters for budgeting when gifting programs operate at volume.

Branded items worth $4 or less with the company name permanently imprinted do not count toward the $25 limit. Incidental costs, engraving, packing, shipping, are excludable if they do not add substantial value to the gift itself. These are narrow carve-outs, but real ones.

Gift cards are the critical exception most programs get wrong. The IRS treats gift cards, gift certificates, and prepaid cards as cash equivalents. They are not de minimis, even at $5. A $20 gift card is taxable income to the recipient in a way that a $20 box of food is not. If your gifting program defaults to digital gift cards because they are operationally convenient at scale, you are generating taxable income events for recipients without realizing it. Finance teams reviewing past send volumes would do well to examine this exposure specifically.

For employees, the rules are stricter. Gift cards or cash equivalents given to employees are taxable wages regardless of amount and must be processed through payroll and reported on W-2s. Tangible personal property awards are treated differently, with separate exclusion limits that depend on whether the award is part of a qualified plan.

The entertainment deduction is largely gone. The Tax Cuts and Jobs Act eliminated deductibility for most entertainment expenses. Event tickets are not deductible. However, if tickets are given as a gift and the giver does not attend the event, they qualify as a business gift subject to the $25 limit. The giver's attendance is the determining factor.

It is also worth considering how cross-border programs interact with these rules. The UK allows deductions on gifts up to £50 per year per recipient, a meaningfully higher threshold than the U.S. cap. That discrepancy has practical implications for how multinational programs should be structured and budgeted across geographies.

The core elements a corporate gifting policy needs to cover

A written gifting policy is not optional if your company operates under the UK Bribery Act's "adequate procedures" defense or under FINRA's recordkeeping requirements. It is the evidentiary artifact that demonstrates a functioning compliance program exists. When something goes wrong and you are in front of a regulator, the policy document is what you produce first.

Tiered approval thresholds by recipient type and gift value

The policy needs to establish different rules for different recipient categories. Government officials and SOE employees warrant the lowest caps and should require senior pre-approval before any purchase is initiated. Regulated-sector commercial recipients in financial services, healthcare, and similar industries sit in a middle tier aligned to the sector-specific rules described above. Commercial recipients in low-risk jurisdictions can operate under higher caps with manager-level approval sufficient.

Recipient classification as a required first step

Classification needs to happen before a send is initiated, not after. Teams need to determine whether a recipient is a government official, an SOE employee, a regulated-sector contact, or a standard commercial contact as part of the workflow itself. Retroactive classification is not compliance; it is documentation of something you did not actually control at the time.

Recordkeeping requirements

Every gift above a defined minimum threshold requires documentation: type and description of gift, fair market value, recipient name and employer, business purpose, name of the approver, and date sent. These records satisfy the FCPA's accounting provisions and provide the audit trail your compliance team will need if a question arises later.

Explicit prohibitions

The policy needs to name what is categorically off the table: cash and cash equivalents sent to government officials or regulated recipients; gifts timed to coincide with active tenders, procurement decisions, or regulatory reviews; gifts prohibited under local law in the recipient's jurisdiction. Naming these explicitly removes interpretive ambiguity for team members making judgment calls under time pressure, which is when most mistakes happen.

Pre-clearance for high-risk sends

Define who approves high-value or high-risk sends, what documentation is required before approval is granted, and how long the approval window runs. Without a defined process, high-risk sends either stall indefinitely or proceed without proper review. Neither outcome is defensible.

Safe harbors and country-specific schedules

A clearly defined list of low-dollar gifts that require no additional approval reduces friction without increasing risk. If your team knows that a branded item under a certain value, sent to a commercial contact in a defined set of jurisdictions, requires no escalation, they can move quickly in routine situations without having to guess. Country-specific annexes or schedules attached to the main policy document handle threshold variation across jurisdictions without requiring teams to consult outside counsel for every international send.

How to build the operational systems that make a gifting policy enforceable at scale

A policy document sitting in a shared drive is a starting point. Calling it a compliance program would be an overstatement.

The gap between a written policy and an enforceable one is entirely operational, and it tends to be larger than teams appreciate until they try to close it. Here is what I mean by that. Manual tracking breaks not on the individual send but on aggregation. You can log a single transaction on a spreadsheet reasonably well. What you cannot reliably catch is three different members of an account team each sending a $200 gift to the same recipient across a quarter, none of which individually triggers a review but which collectively breach the applicable annual cap. That kind of violation is essentially invisible to manual systems in any organization of meaningful size.

One might argue that a well-maintained spreadsheet and a diligent administrator are sufficient — but that argument fails when you stress-test it: accurate aggregation across every sender, every recipient, and every jurisdiction, updated in real time, with no gaps during staff turnover or high-volume send periods. That is a fragile system, and fragility is precisely what regulators probe for when they are evaluating whether "adequate procedures" is a real claim or a phrase in a document.

What a technology-enabled gifting program needs to do

The system needs to enforce per-recipient annual caps automatically, aggregating across all senders within the organization. It needs to flag recipient types that require elevated scrutiny, government officials, SOE employees, healthcare and financial services contacts, before a send is approved, not as a post-hoc report generated after the fact. And it needs to generate an auditable record for every send: value, recipient identity, employer, business purpose, and approver.

That audit trail is not bureaucracy for its own sake. It is what you produce when a regulator asks whether your company had adequate procedures in place. A system that enforces the rules and documents the enforcement simultaneously is what makes "adequate procedures" defensible, rather than aspirational.

The global gifting market is heading toward nearly two trillion dollars within the decade. The number of individual transactions touching regulatory jurisdictions will grow proportionally. The regulatory frameworks themselves are largely established; what becomes more consequential with every increase in send volume is the operational infrastructure for managing compliance within them. Companies that build that infrastructure into their gifting programs from the beginning are in a fundamentally different position than those that retrofit it later, usually after something has already gone wrong.

Sources

  1. antibriberyguidance.org
  2. ankura.com
  3. sendoso.com
  4. blog.clientgiant.com

More in Gift Strategy & Planning