CFIUS Formalizes Its Enforcement and Penalty Process
Client Alert | 2 min read | 10.27.22
On October 20, 2022, the Committee on Foreign Investment in the U.S. (CFIUS) adopted long-awaited CFIUS Enforcement and Penalty Guidelines (the “Guidelines”) identifying how it will review and consider three categories of non-compliances that may be subject to penalties:
- Failure to file a mandatory declaration or notice, when applicable;
- Non-compliance with a CFIUS mitigation agreement, condition, or order; or
- Material misstatements, omissions, or false certifications in connection with CFIUS filings.
Depending on the category of the violation and the circumstances, the underlying statute affords CFIUS a range of remedies such as imposing civil penalties of up to $250,000 or the value of the transaction (whichever is greater), directing the parties to file a declaration or notice, negotiating additional mitigation, or ordering the divestment of some or all of the U.S. business involved. In addition, CFIUS may refer conduct to other government enforcement authorities where appropriate.
The Guidelines identify the sources of information from which CFIUS may learn and investigate potential violations, including, significantly, a “tips line” on its website for anyone to report apparent violations. The Guidelines also set forth a process under which CFIUS will provide the person subject to penalties (“Subject Person”) 15 business days to respond to a notice detailing the reason for the proposed penalty and penalty amount, before the final penalty is assessed. Of particular importance in such a response will be the list of aggravating and mitigating factors that CFIUS will consider in determining whether to impose a penalty and the appropriate amount, such as the extent of the harm to national security, the willfulness of the non-compliance, and whether the Subject Person submitted a timely self-disclosure and cooperated with CFIUS’s review.
To date, CFIUS has only publicly disclosed two penalties it has imposed: (1) a $1,000,000 penalty in 2018 for breach of a 2016 mitigation agreement and (2) a $750,000 penalty in 2019 for violating a 2018 interim order. Although it remains to be seen whether publication of the Guidelines foretells an increased willingness by CFIUS to impose penalties, it certainly underscores the mitigating value of voluntary self-disclosures and working closely with the CFIUS Monitoring & Enforcement office if compliance issues do arise.
The publication of the Guidelines follows a September 15, 2022 executive order issued by the Biden Administration that specifically identified certain additional national security factors for CFIUS to consider when evaluating transactions involving foreign investors.
Contacts
Insights
Client Alert | 7 min read | 08.17.26
Delayed Notification of Cyberattacks May Trigger HIPAA Breach Notification Rule
After identifying a ransomware attack in 2021, OSF Healthcare System waited until its forensic investigation had concluded before notifying the U.S. Department of Health and Human Services (HHS) — and the affected individuals — of the breach. The 110-day delay (nearly double the 60-calendar-day notification deadline mandated by the HIPAA Breach Notification Rule) triggered an investigation from HHS’s Office for Civil Rights (OCR). The health system’s investigation determined that protected health information (PHI) had been stolen.
Client Alert | 4 min read | 08.14.26
License to Hack? The White House Greenlights Private-Sector Offensive Cyber Operations
Client Alert | 4 min read | 08.13.26
Supreme Court Confirms Contractual Loss of Bargain Without Repudiatory Breach
Client Alert | 7 min read | 08.12.26
Developments in Canadian Investment Treaty Practice: New FIPA Between Canada and UAE in Force



