The expanded use of Foreign Terrorist Organization (FTO) designations is blurring the line between what is a security risk and unwarranted legal exposure, prompting companies operating in Latin America to reassess third-party risk, legacy practices and operational decisions.
Business practices previously regarded as operational necessities, such as ensuring the safe movement of goods and personnel through high-risk areas, are now being evaluated from a terrorism-related legal perspective. This change is tangible and is influencing how prosecutors, regulators and civil litigators assess corporate conduct throughout the region.
Earlier this year, senior legal, compliance, investigations, government affairs and risk professionals met in Washington, D.C., for a closed-door briefing hosted by Kroll and Freshfields. The discussion addressed the use of FTO designations to target criminal organizations in Latin America and examined the implications for companies operating where organized crime, legitimate business and local governance frequently overlap.
The conclusion is clear: FTO designations are no longer limited to diplomatic signaling or national security policy execution. Since 2025, the designation of criminal organizations across Mexico, Central America and South America, including the recent designation of Brazil's Primeiro Comando da Capital (PCC) and Comando Vermelho (CV), as well as Ecuador’s Chone Killers, has reinforced the expanding scope of FTO-related risk and its implications for companies operating throughout Latin America.
Their expanded use signifies a structural shift in corporate risk, impacting compliance programs, operational decisions and post-incident legal exposure.
Intersection of Geopolitics and Compliance
Participants emphasized that geopolitical risk, compliance exposure, security concerns and operational realities must be managed together, not as separate categories. National security priorities are increasingly shaping regulatory expectations and enforcement tools, often with minimal advance notice for businesses. As a result, risk assessments that historically focused on corruption, sanctions or regulatory exposure may also need to consider broader national security implications.
This convergence creates legal, reputational and financial risks that often become apparent only after an incident occurs. Entirely eliminating these risks, while continuing to operate in high-risk jurisdictions, is not realistic. Instead, businesses should focus on governance frameworks that can withstand intense post-event scrutiny.
Legal Exposure and the Increasing Significance of Civil Liability
Criminal enforcement traditionally commands executive attention; however, participants noted that civil liability under the U.S. Anti-Terrorism Act is a more persistent and destabilizing risk that also needs attention.
Civil claims require a lower burden of proof than criminal cases. Conduct that does not result in government enforcement may still lead to prolonged and costly litigation. Organized plaintiffs’ firms often drive these cases, which may proceed independent of or before any official action by authorities. Even in the absence of criminal enforcement, civil litigation can create significant costs, management distraction, reputational scrutiny and prolonged uncertainty for organizations operating in high-risk environments.
The lack of visible enforcement activity in a specific country or sector does not indicate reduced risk. Organizations that wait for a clear test case often respond too late.
For companies involved in logistics, infrastructure, natural resources, energy, agriculture or local intermediaries, this risk is cumulative rather than episodic.
Operational Reality and Geographic Variability
The discussion emphasized that risk exposure in Latin America is highly localized. National-level assessments often obscure significant differences among regions, cities and supply chain corridors. Areas affected by criminal influence, strategic transportation routes or critical infrastructure may present significantly different risk profiles than broader national assessments suggest.
In several jurisdictions, criminal organizations are integrated into legitimate businesses, logistics networks and vendor ecosystems. This integration complicates due diligence efforts and renders uniform risk assumptions unreliable. Practices considered benign in one location may bring significantly higher exposure elsewhere.
As a result, many organizations are reevaluating long-standing third-party relationships, transportation routes and security arrangements, especially where territorial control or informal governance structures affect access and operations.
Limitations of Traditional Due Diligence Models
Technology-driven screening is necessary but insufficient. Screening tools identify known and established risks using historical data, sanctions lists and formal designations. Screening is unlikely to proactively identify risky third parties, including those subject to extortion demands, under criminal control or with tacit accommodation arrangements with designated organizations.
FTO-related risk stems not from direct engagement with designated organizations, but from proximity, intermediaries and operational dependencies within contested environments.
Bridging this intelligence gap requires supplementing structured data with human-led intelligence, local insight and investigative judgment. Understanding how risk manifests on the ground is essential for making defensible decisions when legal exposure is evaluated retrospectively.
Compliance Decision Management amid Uncertainty
Compliance leaders must prioritize multiple risk vectors despite limited resources and uncertain enforcement outcomes. The discussion emphasized that panic-driven or unfocused program changes can unintentionally create new risks or weaken existing controls.
Effective risk management in this environment relies on strong fundamentals, prioritization, proportionality and thorough documentation. Regulators and courts assess whether decisions were reasonable based on the information available, whether risks were escalated appropriately and whether leadership acted in good faith.
Practical Road Map for Risk Mitigation
Participants identified targeted actions, rather than complete program redesigns, that can materially improve organizational defensibility:
- Reassess High-Risk Logistics: Evaluate security providers, transportation routes and local logistics partners in regions where criminal organizations hold territorial influence or control access.
- Audit Legacy Practices: Assess facilitation, access or security practices that were previously tolerated but are now susceptible to reinterpretation under terrorism-related statutes.
- Document Decision-Making: Clearly record risk assessments, approvals and escalation decisions, as well as the rationale and constraints underlying them.
- Engage in Scenario Planning: Conduct tabletop exercises and operational drills addressing supplier coercion, criminal infiltration and abrupt regulatory changes.
- Strengthen Escalation Protocols: Maintain clear communication across compliance, legal, security, investigations and government affairs teams to ensure early identification of emerging risks.
These steps cannot eliminate exposure entirely, but they demonstrate disciplined governance, informed decision-making and preparedness as risks evolve.
Conclusion
Defensibility was the central theme of the discussion. As FTO designations continue to reshape legal and enforcement frameworks across Latin America, organizations must ensure that their compliance programs are risk-based, robust and adaptable to changing geopolitical conditions.
The most resilient companies advance beyond checklist compliance to proactive intelligence-led governance. In an environment where scrutiny is inevitable and often retrospective, organizations should be prepared to demonstrate that their decisions were informed, risk-based and appropriately documented. Preparedness, prioritization, documentation and defensibility underpin sustainable operations.






