Lorem ipsum dolor sit amet, consectetur adipiscing elit lobortis arcu enim urna adipiscing praesent velit viverra sit semper lorem eu cursus vel hendrerit elementum morbi curabitur etiam nibh justo, lorem aliquet donec sed sit mi dignissim at ante massa mattis.
Vitae congue eu consequat ac felis placerat vestibulum lectus mauris ultrices cursus sit amet dictum sit amet justo donec enim diam porttitor lacus luctus accumsan tortor posuere praesent tristique magna sit amet purus gravida quis blandit turpis.
At risus viverra adipiscing at in tellus integer feugiat nisl pretium fusce id velit ut tortor sagittis orci a scelerisque purus semper eget at lectus urna duis convallis. porta nibh venenatis cras sed felis eget neque laoreet suspendisse interdum consectetur libero id faucibus nisl donec pretium vulputate sapien nec sagittis aliquam nunc lobortis mattis aliquam faucibus purus in.
Nisi quis eleifend quam adipiscing vitae aliquet bibendum enim facilisis gravida neque. Velit euismod in pellentesque massa placerat volutpat lacus laoreet non curabitur gravida odio aenean sed adipiscing diam donec adipiscing tristique risus. amet est placerat in egestas erat imperdiet sed euismod nisi.
“Nisi quis eleifend quam adipiscing vitae aliquet bibendum enim facilisis gravida neque velit euismod in pellentesque massa placerat”
Eget lorem dolor sed viverra ipsum nunc aliquet bibendum felis donec et odio pellentesque diam volutpat commodo sed egestas aliquam sem fringilla ut morbi tincidunt augue interdum velit euismod eu tincidunt tortor aliquam nulla facilisi aenean sed adipiscing diam donec adipiscing ut lectus arcu bibendum at varius vel pharetra nibh venenatis cras sed felis eget dolor cosnectur drolo.
I treat international deal compliance as a closing decision - not just a paperwork task. Before spending heavily on diligence, I map where approvals apply, identify deal blockers, and assign each issue an owner.
My approach follows four steps:
My rule: a contract cannot replace a required approval. I keep a jurisdiction matrix, diligence checklist, approval tracker, and integration plan so your team can track <u>what must happen, who owns it, and when it is due</u>.
International Deal Compliance: From Mapping to Integration
Ask the target for a jurisdiction-by-jurisdiction operating map that covers entities, owners, employees, customers, suppliers, facilities, data locations, licenses, government contracts, and financing flows. Include all relevant U.S. states and territories. For each connection, record the entity, business activity, and timing: pre-signing, at closing, or post-close. Incorporation alone doesn't tell you where approvals apply.
Use one row per jurisdiction and approval, rather than one row per transaction. For U.S. HSR screening, use $133.9 million as the transaction threshold and $535.5 million as the point where the size-of-person test usually drops out. Confirm the commerce test, exemptions, and current FTC guidance.
| Country or jurisdiction | Business activity or trigger | Regulator | Potential approval | Responsible adviser | Estimated timing | Status |
|---|---|---|---|---|---|---|
| United States | Acquisition of voting securities, assets, or noncorporate interests meeting applicable HSR tests | FTC and DOJ | HSR premerger notification | U.S. antitrust counsel | 30-day waiting period after a valid filing in ordinary cases | Information gathering |
| United States | Foreign investment in a U.S. business or sensitive real estate | CFIUS | Mandatory-declaration analysis; declaration or notice | CFIUS counsel | Declaration: 30-day assessment; notice: 45-day review, potentially another 45-day investigation | Information gathering |
| Germany | Local business operations and applicable revenue or market-share thresholds | German Federal Cartel Office | Possible merger-control filing | German competition counsel | Confirm current thresholds and review period | Information gathering |
| Each relevant foreign jurisdiction | Foreign ownership or sensitive-sector activity | Investment-screening authority | Foreign-investment approval | Local investment-screening counsel | Confirm filing deadline and review period | Information gathering |
| Each licensing or contract-approval jurisdiction | Ownership limits, license transfer, or public-contract change of control | Sector regulator or contracting authority | Consent, reauthorization, or novation | Local regulatory or government-contract counsel | Confirm whether required before signing or closing | Information gathering |
| Each payment, financing, or exchange-control jurisdiction | Currency conversion, cross-border funding, or investment registration | Central bank or investment authority | Exchange-control approval or registration | Local counsel with treasury lead | Confirm before finalizing funds flow | Information gathering |
For each row, add the filing entity, required documents, approval dependencies, safe filing date, and effect on closing. Check ownership limits separately from licensing consent. A CFIUS declaration may prompt a request for a full notice. Minority investments in certain critical-technology, critical-infrastructure, or sensitive-data businesses can also fall within scope.
Once the approval map is set, collect evidence for the highest-risk jurisdictions first.
Work backward from the proposed closing date. Allow time for document collection, translations, notarization, filing preparation, regulator questions, and possible mitigation. Run independent reviews in parallel where possible, and set the long-stop date based on the slowest approval.
Use one status convention across the matrix and require documented evidence for every status change. “No filing identified” needs a documented basis - it isn't an assumption.
Use Kumo to find targets and geographies for the initial map. Then verify every jurisdiction against corporate records, financials, and contracts. Check ownership, reconcile operating locations and country revenue, and inspect the actual licenses and contracts.
Escalate missing owners or countries that don't appear in the listing. Treat sourcing data as a starting point only; confirm every jurisdiction with counsel. Use the completed matrix to focus diligence on the approvals, counterparties, and activities most likely to block closing.
Use the Step 1 jurisdiction matrix to focus diligence on approvals and conduct risks that could block closing. Build a risk-based request list that tests actual conduct. Request beneficial-owner records, regulator correspondence, investigation files, training records, third-party files, and transaction data. Match sampled commissions, expenses, and customer transactions to invoices and approvals. Label gaps as “not provided,” “not applicable,” or “not tested” - missing evidence does not establish compliance.
Set up a secure data room with multifactor authentication, role-based access, encryption, and audit logs. Have counsel oversee disclosure of personal data, privileged material, government-confidential information, and controlled technology. Where local law restricts sharing, use redactions or in-country review.
Have specialists check filing triggers against market overlaps, vertical relationships, buyer ownership and control rights, sensitive technology, government customers, and personal-data holdings.
Before sharing customer pricing, margins, bids, or strategy, set up a counsel-directed clean team with named recipients, restricted access, and aggregated reports. Track clearance status. Keep pricing, customer allocation, and operational decisions separate until approval.
Trace exposure through agents, distributors, state-owned customers, payment routes, and technology access. Ask counsel to assess successor liability for historical misconduct and required remediation.
| Risk | Requested evidence | Management questions | Red flags | Follow-up action |
|---|---|---|---|---|
| Bribery and improper payments | Third-party files, commissions, gifts and hospitality logs, government-contract records, investigations, training data | Which intermediaries interact with officials? Why were they selected and paid? | Vague services, success fees, offshore accounts, missing invoices | Conduct a deeper third-party review, quantify exposure, suspend risky payments, and obtain counsel’s successor-liability assessment |
| Sanctions and restricted parties | Screening logs, ownership data, customer files, shipping records, bank details | How are indirect owners, resellers, and potential matches screened and escalated? | Incomplete ownership, unusual routing, manual overrides, customers refusing end-use information | Re-screen the population, block or pause transactions, investigate matches, and assess disclosure obligations |
| Export controls and technology transfer | Classification files, licenses, technical-access records, end-use certificates, shipping documents | Who can access controlled technology, and from which countries? | “Unknown” classifications, expired licenses, uncontrolled cloud access, inconsistent end-use data | Reclassify products, restrict access, obtain licenses, and test the export-compliance plan |
| Import and customs compliance | Entry summaries, broker instructions, tariff classifications, country-of-origin records | Who approved classifications and valuations? Are related-party prices documented? | Repeated corrections, undervaluation, inconsistent origin claims | Perform a customs review, quantify duties and penalties, and correct filings |
Review privacy, AML, tax, employment, immigration, consultation, works-council, environmental, waste, and sector-permit obligations separately from general compliance. With local counsel, check data maps, transfer mechanisms, breach response, cybersecurity tests, tax filings, transfer pricing, and permanent-establishment exposure.
Where AML rules apply, test customer identification, beneficial-owner checks, and monitoring alerts. Do not request legally protected suspicious-activity reports. Identify employee consultation or works-council requirements before collecting employee data or closing. Carry the highest-risk findings into the purchase agreement and closing checklist.
Turn the diligence findings into a decision on whether to close and a checklist for signing.
Use the Step 2 findings to classify each issue as a closing blocker, pre-closing fix, or post-closing task. For each finding, record the jurisdiction, legal basis, exposure, owner, deadline, and supporting evidence.
Have the investment committee document its decision: proceed without changes, proceed with specified conditions, restructure the transaction, defer signing or closing, or terminate. Defer remediation only if counsel confirms that doing so is lawful. If no lawful remedy exists, escalate the issue for restructuring or termination.
Match each contract protection to the risk it addresses. Use representations and warranties for existing facts, covenants for required actions, specific indemnities for known historical exposure, and escrows or holdbacks to support recovery. Make required approvals and agreed fixes objective closing conditions. Define caps, survival periods, and claims procedures.
Assign every filing, response, and fee to a named party. Set a long-stop date and termination rights for approval delays. Specify whether the buyer must accept a divestiture that makes the deal uneconomic.
Contract terms allocate risk; they don't replace required approvals. Budget for continuing CFIUS mitigation duties, including reporting, audits, and access restrictions.
Carry the agreed protections into the closing checklist.
Use one closing checklist to track every clearance, waiting period, license transfer, lawful data transfer, and remediation item. Each entry needs an owner, deadline, evidence location, and sign-off. A filing receipt is not approval.
Before authorizing closing, escalate unresolved conditions to the general counsel and deal committee. For any deferred task, document why deferral is lawful, along with the task's owner, budget, deadline, interim controls, and consequences for nonperformance.
Retain analyses, filings, regulator communications, approvals, and closing authorization. Keep legal advice in a restricted file under counsel’s direction; a “privileged” label alone does not establish protection.
Once the deal closes, move every open issue into an integration tracker and assign owners right away. Keep the compliance plan active after closing: track open obligations, put controls in place, and monitor inherited risk. Closing does not erase inherited exposure or future regulatory duties. Keep investigations into past conduct separate from work to prevent new violations.
Start with access and screening controls. Give each integration task one owner, a deadline, required evidence, and an escalation path.
On Day One, compliance should focus on third-party screening and re-screening. IT and privacy teams should restrict access to personal data, source code, encryption keys, technical drawings, and other controlled technology until permissions are confirmed. Within the first week, legal and finance should confirm entity ownership, regulatory contacts, signing authority, bank access, licenses, permits, data systems, and open compliance matters.
During the first 30, 60, and 90 days, bring the acquired business into the buyer’s policies, risk assessments, training, monitoring, and reporting. Include open investigations, reporting duties, and remediation commitments in the integration plan. DOJ guidance expects a timely, orderly process for bringing acquired entities into existing compliance structures and internal controls, including post-acquisition audits.
After closing, test whether the controls assigned in the integration plan work. Use document reviews, transaction samples, and access testing to check applicable sanctions, export-control, anti-bribery, AML, privacy, and accounting controls.
Review screening alerts, distributor payments, customer-risk ratings, technology access, and unusual journal entries. Monitor high-risk intermediaries and markets more often. Assign one regulatory owner per jurisdiction to track changes, and escalate suspected violations, control failures, and overdue high-risk findings to the board or compliance committee.
Keep post-close monitoring on track with the same trackers. Maintain four live deliverables: a jurisdiction matrix, diligence checklist, approval tracker, and integration plan. Each needs a named owner, version history, last-reviewed date, and links to evidence. Update them when testing identifies new risks.
Conflicting rules can make cross-border acquisitions much more complex. Review each jurisdiction’s requirements early to spot overlapping or contradictory rules on antitrust, data privacy, and foreign investment.
Work with specialized local counsel to anticipate and address these challenges. In some cases, you may need carve-outs to separate problematic jurisdictions from the rest of the global transaction.
Budget for specialized local counsel, regulatory filings, and thorough due diligence. That includes reviews of data privacy, labor law, and licensing requirements. Factor expected compliance costs into the purchase price.
Consider holding 10% to 30% of the purchase price in escrow for 12 to 36 months to cover possible remediation costs or fines. Keep a separate contingency fund for application fees and potential business disruptions.
You may inherit the target company’s liabilities. Check your purchase agreement’s indemnification clauses and any escrow arrangement to see how you might recover losses.
Document the violation immediately, and consult legal counsel about your regulatory reporting obligations. For sanctions issues, act within the 90-day post-closing window to end prohibited relationships, rescreen partners, and take corrective action.