On June 5th, 2026, the U.S. Department of State formally designated Brazil’s two largest criminal organizations, Primeiro Comando da Capital (“PCC”) and Comando Vermelho (“CV”), as Foreign Terrorist Organizations (FTOs). Although these measures come from U.S. authorities, their reach does not stop at the border. Any Brazilian company with international operations, foreign investors, access to the global financial system, or transnational supply chains now faces heightened exposure to sanctions, trade restrictions, regulatory scrutiny, and reputational implications.
In this context, ICC Brazil and the Office of the Comptroller General (CGU)) have released a Guide on Managing the Risks that Criminal Organizations Pose to Business (the “Guide” – in Portuguese, Guia para Empresas sobre Gestão de Riscos Associados a Organizações Criminosas). It marks an important step in Brazil’s corporate integrity agenda, recognizing that organized crime is no longer only a public-security threat but a concrete business risk that can affect operations, supply chains, investments, M&A, and the long-term sustainability of a company.
From a security threat to a governance issue
The Guide’s central contribution is to reframe organized crime as a corporate governance matter rather than a concern for law enforcement alone. The paradigm has shifted: illicit capital no longer seeks only to stay hidden, but to gain integration, scale, and influence. within the formal economy. As criminal organizations become increasingly sophisticated, detecting criminal infiltration becomes substantially more challenging, exposing the limitations of traditional compliance and control mechanisms. Criminal groups enter through legitimate structures such as investment funds, private equity, M&A transactions, fintechs, and holding companies, which makes their presence far harder to detect and places functions like M&A and investor relations on the front line of a company’s defenses.
Just as important is a reality many companies underestimate: infiltration rarely arrives through obviously suspicious relationships. More often it comes through seemingly legitimate suppliers, investors with complex ownership, commercial intermediaries, strategic partners, or even co-opted employees. The question is no longer whether a company could be exposed, but whether its governance framework is robust enough to identify and manage that exposure.
The Guide stresses that infiltration often begins with people and habits rather than transactions, through the co-optation of employees in sensitive roles, informal pressure, and small exceptions that gradually become routine. It therefore extends the familiar “know your client” discipline to business partners and employees alike, and gives real weight to organizational culture, safe reporting channels, and the ability to read weak signals early, which is often the difference between catching a problem and discovering it too late.
The scale of the problem
The U.S. enforcement dimension
The U.S. response goes beyond designation. Under guidance issued in 2025, the DOJ has made cartels and transnational criminal organizations, many of them now treated as foreign terrorist organizations, a priority for enforcement of the Foreign Corrupt Practices Act, with particular focus on the financing structures and front companies these networks rely on. In practice, an apparently ordinary commercial link to a group such as the PCC or the Comando Vermelho can expose a company not only to sanctions, but to U.S. criminal enforcement, including theories of material support to terrorism. The arrangements the Guide warns about, opaque funds, nominees, and front companies, are precisely those now drawing scrutiny on both sides of the border.
What the Guide expects of companies
Developed by ICC Brazil together with the CGU and published in April 2026, the Guide is deliberately practical rather than theoretical. It takes the risk-based approach already familiar from anti-corruption and anti-money-laundering compliance and adapts it to the specific threat of criminal infiltration, with recommendations organized around governance and compliance structures, third-party due diligence, ongoing monitoring, training and culture, and the management of incidents once a red flag appears.
It offers non-mandatory guidance to be adapted to each company’s size, sector, geography, and governance maturity, which is precisely why applying it well calls for judgment rather than a checklist. Its core message is that compliance must widen its scope: beyond corruption, fraud, and conflicts of interest, companies should address the specific risk of criminal infiltration, which typically hides behind ordinary-looking arrangements, gradual equity acquisitions, the use of nominees, fund investments, and offshore vehicles that obscure the ultimate beneficial owner and the true source of capital.
On the response side, the Guide favors continuous risk management over one-off reviews, treats third-party due diligence calibrated to each relationship as the main preventive tool, and, for companies with cross-border activity, advises controls aligned with international standards such as OFAC guidance. It also carries a warning that should reach the boardroom: directors and compliance officers may be held personally responsible where they had enough information to identify red flags and failed to act.
Practical next steps
Putting this into practice starts with understanding where the company is actually exposed: mapping critical operations, higher-risk third parties, supply chains, and contracting and investment processes. From there, continuous monitoring, through corporate linkage analysis, screening against restricted lists, and adverse-media checks, helps detect changes in risk well after onboarding. Finally, companies should prepare incident-response protocols so that a suspected link to a criminal organization triggers prompt legal assessment, evidence preservation, coordinated communication, and, where appropriate, engagement with the authorities.
With the U.S. designations now in force, managing these risks has shifted from good practice to a necessary part of protecting a company’s reputation, operational continuity, and value. Exposure varies from one business to the next, and an effective response has to be tailored to each company’s sector, geography, and governance maturity. For more information, please contact our team at Saud Advogados.
