What the First DOJ Export Control Declination Means for Your Enterprise

Article Summary
On June 17, 2026, DOJ issued its first criminal declination for export control violations under its Corporate Enforcement Policy, declining to prosecute Robert Bosch GmbH following an investigation into over $70 million in unauthorized exports to Huawei affiliates on the BIS Entity List between 2020 and 2024. BIS imposed a $36.18 million civil administrative penalty. The declination is significant because it establishes the first public, concrete benchmark for what voluntary self-disclosure, full cooperation, and comprehensive remediation can achieve under the new policy framework.
DOJ identified four pillars that supported the declination: timely voluntary self-disclosure submitted to both DOJ's National Security Division and BIS during active internal inquiry before government detection; full cooperation including direct access to foreign personnel, forensic records, and audit data; comprehensive remediation including immediate termination of non-compliant sales channels, leadership discipline, and structural overhaul; and absence of aggravating factors including no evidence of executive-level willful blindness or systemic corporate concealment.
The Corporate Enforcement Policy is a department-wide framework finalized in March 2026 that standardizes how DOJ evaluates voluntary self-disclosures, cooperation, and remediation across all divisions including the National Security Division that handles export control cases. It replaced earlier division-specific policies and establishes a consistent framework for the treatment of organizations that self-disclose, cooperate fully, and remediate comprehensively.
Bosch is a German company whose subsidiaries made the exports from outside the United States using items manufactured abroad. U.S. jurisdiction applied because the items were produced using U.S.-origin technology, pulling them within scope of the Foreign Direct Product Rule. Any company anywhere in the world that manufactures using U.S. equipment, technology, or software faces the same jurisdictional exposure — and the same VSD strategic calculus — that the Bosch case resolved.
No. The Bosch declination required all four factors simultaneously — timely disclosure, full cooperation, meaningful remediation, and absence of aggravating circumstances. If any factor is missing — particularly evidence of obstruction or leadership involvement — the outcome can be materially different. The declination is not leniency; it is a transaction with defined terms that organizations must satisfy completely to receive the benefit.
On June 17, 2026, the U.S. Department of Justice (DOJ) reached a landmark precedent: issuing its first criminal declination for export control violations under its department-wide Corporate Enforcement Policy (CEP). The subject was Robert Bosch GmbH, following an investigation into over $70 million in unauthorized foreign exports to Huawei affiliates on the BIS Entity List between 2020 and 2024.
The exports involved sensor products and software manufactured outside the United States but subject to U.S. jurisdiction under the Foreign Direct Product Rule (FDPR, 15 C.F.R. § 734.9). Although Bosch had received third-party warnings regarding U.S. jurisdiction prior to disclosure, DOJ declined criminal prosecution while BIS imposed a $36.18 million civil administrative penalty.

Why? Because Bosch did four things right after it got the underlying compliance wrong.
The Four Pillars of the Bosch Declination:
- Timely Voluntary Disclosure: Submitted to DOJ National Security Division and BIS during active internal inquiry before government detection.
- Full Cooperation: Direct access to foreign personnel, internal forensic records, and audit data without reservation.
- Comprehensive Remediation: Immediate termination of non-compliant sales channels, leadership discipline, and structural overhauls.
- Absence of Aggravating Factors: No evidence of executive-level willful blindness or systemic corporate concealment.
What This Means for Your Program
The declination is not leniency. It is a transaction. DOJ is telling the market: disclose voluntarily, cooperate fully, and remediate fast and we will give you a meaningful benefit. Wait for us to find it, or obstruct, and the outcome changes completely.
Three implications for compliance leaders:
Your voluntary self-disclosure posture is now a strategic decision, not a legal technicality. Before the Corporate Enforcement Policy, VSD was a judgment call with uncertain upside. After the Bosch declination, the benefit is concrete and public: criminal prosecution was declined for a $70 million violation pattern. Every general counsel and compliance officer should now have a documented VSD decision framework: when do we disclose, to whom, and on what timeline?
The FDPR makes this relevant to companies that think they're outside U.S. jurisdiction. Bosch is a German company. Its subsidiaries that made the exports were outside the United States. The items were manufactured abroad. But because they were produced using U.S.-origin technology, the FDPR pulled them into U.S. jurisdiction. If your company manufactures using U.S. equipment, technology, or software, anywhere in the world, this case applies to you.
Finding problems first is now a measurable financial advantage. The gap between "we disclosed" and "they discovered" is no longer abstract. In the Bosch case, it was the difference between a civil penalty with no criminal record and potential criminal prosecution for a $70 million scheme involving Huawei. That delta belongs on a board slide.
Frequently Asked Questions
What is the DOJ Corporate Enforcement Policy? A department-wide framework, finalized in March 2026, that standardizes how DOJ evaluates voluntary self-disclosures, cooperation, and remediation across all divisions including the National Security Division, which handles export-control cases. It replaced earlier division-specific policies.
Does voluntary self-disclosure guarantee a declination? No. The Bosch declination required all four factors: timely VSD, full cooperation, meaningful remediation, and no aggravating circumstances. If any of those are missing, especially if there's evidence of obstruction or leadership involvement, the outcome can be very different.
What's the difference between disclosing to DOJ and disclosing to BIS? They're separate processes. BIS has its own voluntary self-disclosure process under the EAR (Part 764). DOJ's CEP applies to potential criminal violations. Bosch disclosed to both. In practice, companies with significant violations should coordinate disclosures to both agencies, ideally with legal counsel experienced in parallel proceedings.
Does this only matter for companies subject to the FDPR? No. The VSD framework applies to any export-control violation, FDPR or otherwise. The Bosch case is simply the first public declination under the new policy. Companies with potential EAR, ITAR, or sanctions violations all face the same strategic question: disclose or wait.
How CTP Helps
CTP supports compliance programs at the stage where this decision matters most: before a violation becomes an enforcement action. That includes compliance program assessments designed to surface issues early, remediation planning that meets the standard DOJ and BIS have now made explicit, and program design that builds the internal investigation and escalation capacity a VSD framework requires. If your program doesn't have a documented VSD decision framework, this is the reason to build one. [Talk with CTP →]
Key Points
What does the Bosch declination establish about the strategic value of voluntary self-disclosure, and how should compliance leaders translate this precedent into a documented VSD decision framework?
The Bosch declination converts voluntary self-disclosure from a judgment call with uncertain upside into a strategic decision with a publicly established benefit — and the compliance infrastructure required to realize that benefit must be built before a violation occurs rather than assembled under enforcement pressure:
- Concrete public benchmark replacing uncertain VSD upside with a demonstrated outcome that compliance leaders can present to boards and general counsel in financial terms — Before the Bosch declination, voluntary self-disclosure was a judgment call whose benefit was theoretical and whose cost — triggering government scrutiny — was concrete; the declination establishes a public benchmark that makes the VSD benefit specific: criminal prosecution was declined for a $70 million violation pattern when all four CEP factors were present; compliance leaders can now frame the VSD decision in terms that boards and general counsel can evaluate — the delta between a civil penalty with no criminal record and potential criminal prosecution for a $70 million scheme is a financial figure that belongs on a board risk slide, not a compliance department memo.
- Timing requirement making internal investigation capability a VSD prerequisite rather than a post-disclosure remediation step — The Bosch declination's timely disclosure factor — submitted during active internal inquiry before government detection — establishes that VSD benefit requires disclosure before the government finds the violation; organizations that discover potential violations but lack the internal investigation infrastructure to rapidly assess scope, confirm facts, and prepare a disclosure package cannot meet the timing standard that the declination requires; internal investigation capability must be built into the compliance program architecture before a violation occurs rather than assembled after discovery when timeline pressure compresses the decision window.
- Documented VSD decision framework as the compliance program element that converts the Bosch precedent from a case study into an operational capability — Every general counsel and compliance officer should now maintain a documented VSD decision framework that specifies when to disclose, to whom, on what timeline, and through what process; this framework must address the parallel disclosure question — coordinating simultaneous submissions to DOJ's National Security Division and BIS — the legal counsel engagement requirement, the internal investigation scope definition, and the board notification trigger; organizations without a documented framework will face these decisions under enforcement pressure with no pre-established process, producing the decision quality that compressed timelines and organizational stress generate.
- Full cooperation standard requiring that the compliance program can produce direct access to foreign personnel, forensic records, and audit data on the timeline that DOJ cooperation expectations impose — The Bosch declination's full cooperation factor — including direct access to foreign personnel and internal forensic records without reservation — establishes a cooperation standard that requires compliance infrastructure capable of rapid evidence assembly across international operations; organizations that cannot produce the records, personnel access, and forensic data that full cooperation requires — because records are poorly maintained, foreign operations are poorly documented, or internal investigation capability is inadequate — cannot satisfy the cooperation factor regardless of their willingness to cooperate.
- Absence of aggravating factors as a compliance culture outcome that must be built over time rather than demonstrated in response to a specific enforcement situation — The Bosch declination's fourth factor — no evidence of executive-level willful blindness or systemic corporate concealment — is not a disclosure strategy choice; it is a compliance culture outcome that reflects how the organization has managed its compliance obligations over time; organizations where executives are isolated from compliance risk information, where escalation of compliance concerns is discouraged, or where compliance failures are managed through concealment rather than correction cannot demonstrate the absence of aggravating factors that the declination framework requires regardless of how well they execute the other three factors.
How does the Foreign Direct Product Rule extend U.S. export jurisdiction to non-U.S. companies, and what does the Bosch case reveal about the scope of FDPR exposure for global manufacturers?
The Bosch case's FDPR dimension is its most significant implication for the majority of global manufacturers who believe their operations outside the United States place them outside U.S. export control jurisdiction — and that belief is precisely what the FDPR is designed to correct:
- FDPR jurisdictional reach extending U.S. export control authority to foreign-manufactured items produced using U.S.-origin technology, equipment, or software regardless of where manufacturing occurs or where the exporting company is headquartered — The Foreign Direct Product Rule establishes U.S. jurisdiction over items manufactured outside the United States when those items are the direct product of U.S.-origin technology or software, or are produced by a plant or major component of a plant that is itself the direct product of U.S.-origin technology or software; Bosch's situation — a German company with subsidiaries manufacturing outside the United States — fell within FDPR jurisdiction because the manufactured items were produced using U.S.-origin technology, making the exports subject to U.S. export control requirements that Bosch did not initially recognize as applicable to its operations.
- Third-party warning receipt before disclosure creating an aggravating circumstance that Bosch navigated through timely voluntary disclosure despite having received jurisdictional alerts prior to self-reporting — The Bosch case notes that Bosch had received third-party warnings regarding U.S. jurisdiction prior to disclosure — a fact that could have been an aggravating circumstance if Bosch had continued exports after receiving those warnings without investigation and self-disclosure; the case demonstrates that receiving jurisdictional warnings creates an immediate obligation to investigate and disclose rather than a period of deliberation, and that timely disclosure following warning receipt can support a declination outcome while continued violation after warning creates the willful blindness exposure that aggravating factor analysis targets.
- Entity List restriction applicability to FDPR-jurisdictional items creating export control obligations for foreign manufacturers who supply Entity List-designated customers without recognizing U.S. jurisdiction over their products — Bosch's exports involved sensor products and software supplied to Huawei affiliates on the BIS Entity List; the Entity List restriction applied to these exports not because Bosch was a U.S. company but because the FDPR established U.S. jurisdiction over the exported items; foreign manufacturers who supply Entity List-designated customers — particularly in the semiconductor, telecommunications, and advanced technology sectors where Huawei affiliate relationships are most common — face the same jurisdictional exposure that Bosch encountered, often without recognizing that U.S. export controls apply to their products.
- Global supply chain FDPR audit as an immediate compliance priority for any manufacturer that incorporates U.S.-origin technology, software, or equipment in its production processes regardless of where manufacturing occurs — The Bosch case makes clear that FDPR compliance cannot be assumed based on the manufacturer's non-U.S. location or the non-U.S. origin of the exported items; any manufacturer that uses U.S.-origin technology in its production process must conduct a FDPR audit that identifies which of its products are subject to U.S. jurisdiction, which of its customers are on applicable restricted party lists, and whether current sales and distribution practices comply with the U.S. export control obligations that FDPR jurisdiction creates.
- Ongoing FDPR monitoring obligation requiring that foreign manufacturers maintain current awareness of Entity List additions and sanctions designations affecting their customer base — FDPR jurisdiction is not a static determination — it applies to every export of a covered item to every customer, and the restricted party status of customers can change through new Entity List designations, sanctions additions, and ownership changes that bring previously unrestricted customers within export control restrictions; foreign manufacturers subject to FDPR jurisdiction must implement the same ongoing customer screening and list monitoring obligations that U.S. exporters apply to their direct export transactions, rather than treating the initial FDPR applicability determination as a complete compliance response.
What remediation standard does the Bosch declination establish, and what does comprehensive remediation require organizationally to satisfy the CEP's third pillar?
The Bosch declination's comprehensive remediation factor — immediate termination of non-compliant sales channels, leadership discipline, and structural overhaul — establishes a remediation standard whose organizational depth distinguishes genuine remediation from surface-level compliance response:
- Immediate sales channel termination as the threshold remediation action demonstrating that the organization prioritized compliance over revenue preservation when the violation was identified — Bosch's immediate termination of non-compliant sales channels demonstrates a remediation action whose commercial cost — lost revenue from established customer relationships — demonstrates to DOJ that the organization's remediation commitment was genuine rather than performative; organizations that identify violations but delay sales channel termination to preserve revenue relationships while remediation is planned are signaling that commercial considerations outweigh compliance in the organizational priority structure — precisely the organizational culture indicator that aggravating factor analysis examines.
- Leadership discipline as a remediation component demonstrating accountability at the organizational level where compliance decisions were made or should have been escalated — Leadership accountability in remediation is not optional; DOJ's evaluation of remediation comprehensiveness specifically examines whether the organization held accountable the individuals whose decisions, oversight failures, or inaction contributed to the violation; remediation programs that implement process improvements without addressing leadership accountability for the conditions that produced the violation present an incomplete remediation picture that DOJ's comprehensive remediation standard does not satisfy.
- Structural overhaul distinguishing genuine compliance program redesign from cosmetic policy updates that address surface symptoms without correcting the organizational conditions that produced the violation — Comprehensive remediation requires structural changes — to compliance program governance, to internal controls, to escalation procedures, to screening systems — that address the root causes of the violation rather than the surface manifestation; DOJ's remediation assessment distinguishes structural overhaul from policy documentation updates by evaluating whether the changes made would have prevented the violation if they had been in place when the underlying conduct occurred.
- Remediation documentation demonstrating the scope, timeline, and organizational depth of implemented changes in a format that DOJ can evaluate against the comprehensive remediation standard — Remediation that is implemented but not documented provides no evidentiary basis for DOJ's assessment of whether the comprehensive remediation standard has been met; organizations must maintain contemporaneous documentation of remediation steps — including what was changed, when changes were implemented, who was held accountable, and how structural changes address the root causes identified in the internal investigation — that enables DOJ to assess remediation completeness from the documented record rather than from organizational representations.
- Remediation timeline compression as a CEP factor requiring that structural changes are implemented rapidly rather than phased over extended planning and implementation periods — The Bosch declination's remediation factor reflects action taken during and immediately following disclosure rather than remediation planned for future implementation; organizations that disclose violations while committing to future remediation without implementing immediate structural changes are not satisfying the comprehensive remediation standard that the CEP requires; remediation planning that begins before disclosure — anticipating the structural changes that will be required and sequencing their implementation to begin at the moment of disclosure — enables the remediation timeline that the CEP's comprehensive remediation standard demands.
How should compliance programs be designed to build the internal investigation and escalation capacity that a functional VSD framework requires?
A VSD framework is only as valuable as the internal investigation capability that can detect violations early enough to meet the timely disclosure standard — and building that capability requires compliance program design choices that most organizations have not made in advance of needing them:
- Internal investigation protocol specifying the trigger conditions, investigation scope, timeline, and decision authority that govern the organization's response when potential violations are identified — A documented internal investigation protocol that specifies when an identified compliance concern triggers formal investigation, what investigation scope is required, who conducts the investigation, what timeline applies, and who has authority to make the VSD decision provides the organizational infrastructure for rapid, disciplined response to potential violations; organizations without a documented protocol will face these decisions ad hoc under the time pressure and organizational stress that potential enforcement exposure creates — producing the decision quality that those conditions generate.
- Compliance monitoring capability that identifies potential violations through internal review before external detection rather than discovering violations through customer inquiries, government investigation, or third-party notification — The timely disclosure standard requires that organizations identify their own violations before the government finds them; compliance programs without transaction monitoring, audit sampling, and internal investigation triggers that can surface potential violations cannot meet the timing requirement that the Bosch declination establishes as a CEP prerequisite; monitoring capability must be designed to find violations that have already occurred rather than only to prevent future violations.
- \Escalation architecture that routes identified compliance concerns to the organizational level with VSD decision authority without requiring multiple escalation steps that consume the timeline that timely disclosure demands — VSD decisions require input from general counsel, compliance leadership, and in some cases board notification — a decision-making process that must be completed rapidly when timely disclosure requires acting before government detection; escalation architecture must route identified potential violations directly to the decision-making level with VSD authority rather than through sequential escalation steps that consume timeline; organizations whose escalation processes require multiple approval layers before reaching VSD decision authority cannot consistently meet the timing standard that the Bosch declination requires.
- Foreign operation compliance visibility ensuring that potential violations originating in non-U.S. subsidiaries and operations are identified and escalated to the VSD decision level with the same speed as domestic violations — The Bosch violation originated in foreign subsidiary operations — a compliance visibility challenge that many organizations have not resolved; compliance programs must maintain monitoring and escalation infrastructure that reaches foreign operations with sufficient visibility to identify potential violations and sufficient escalation authority to reach the VSD decision level without the organizational delays that cross-border escalation often involves.
- Legal counsel pre-engagement for VSD decision support ensuring that the attorneys with export control enforcement experience needed to evaluate VSD decisions are identified and engaged before a violation is discovered — VSD decisions require legal counsel with specific experience in export control enforcement, parallel DOJ and BIS disclosure proceedings, and CEP framework application; organizations that have not pre-identified legal counsel with this specific expertise will spend critical early investigation time identifying and engaging counsel rather than conducting the investigation and disclosure preparation that the timely disclosure standard requires; pre-engagement of experienced export control enforcement counsel — through existing retainer relationships or identified standby arrangements — enables the rapid legal support that VSD decision-making requires.
What does the Bosch declination mean for how compliance leaders should frame export compliance risk at the board and executive level, and what does a board-ready risk presentation on this topic require?
The Bosch declination provides compliance leaders with the specific, quantified precedent needed to frame export compliance as enterprise financial risk in terms that boards can evaluate alongside other material business risks:
- Quantified delta between disclosure and discovery outcomes providing the financial risk framing that board-level resource allocation decisions require — The Bosch case provides a specific financial delta: the difference between a $36.18 million civil penalty with no criminal record and potential criminal prosecution for a $70 million violation scheme is a quantifiable risk reduction that voluntary self-disclosure produced; compliance leaders can frame this delta as the financial value of a proactive compliance program — the compliance investment that would have detected and disclosed the violation early versus the enforcement outcome that non-detection would have produced — in terms that boards can evaluate against other risk reduction investments.
- FDPR exposure quantification for boards of non-U.S. companies or U.S. companies with international manufacturing operations who have not previously understood their U.S. export jurisdiction exposure — The Bosch case provides compliance leaders at non-U.S. companies with a board-level teaching moment — a $70 million violation by a German company for exports from non-U.S. operations using U.S.-origin technology demonstrates that U.S. export jurisdiction extends to their operations in ways that boards may not have understood; presenting FDPR exposure as a quantified financial risk — based on the volume of exports that may be subject to U.S. jurisdiction and the enforcement consequences the Bosch case demonstrates — provides the board visibility that FDPR compliance investment requires.
- VSD framework investment as a risk reduction expenditure with a demonstrated return that boards can evaluate against the financial exposure the Bosch precedent quantifies — Compliance leaders seeking board authorization for VSD framework investment can now present a specific risk reduction return: the Bosch case demonstrates that a functioning VSD framework — including internal investigation capability, disclosure decision infrastructure, and remediation planning — produced a declination outcome for a $70 million violation; the cost of building and maintaining that framework against the financial exposure of the violations it would address and the enforcement outcomes it would influence is a risk reduction calculation that boards can evaluate with the financial specificity that the Bosch precedent provides.
- Board notification trigger as a VSD framework component requiring governance decisions about when the board must be informed of identified potential violations and what information must be provided — The VSD decision involves board-level governance obligations whose parameters must be defined in the VSD framework before a violation is discovered; boards that are not informed of material potential violations before VSD decisions are made cannot fulfill their governance oversight obligations, and the absence of board notification in the VSD process creates the leadership isolation that aggravating factor analysis examines; the VSD framework must specify when board notification is required, what information must be provided, and how board input is incorporated into the VSD decision without creating the delay that timely disclosure requires.
- CTP compliance assessment as the proactive compliance investment that builds the program infrastructure the Bosch declination demonstrates is necessary before violations occur rather than after enforcement pressure forces its construction — The Bosch declination's message — that proactive disclosure, cooperation, and remediation produce materially better outcomes than waiting for government detection — applies equally to the proactive compliance assessment that identifies potential violations and program gaps before they become enforcement actions; CTP's compliance program assessments build the internal investigation capability, escalation architecture, and VSD decision framework that the CEP now makes a measurable financial advantage — enabling organizations to find problems first rather than waiting for enforcement to find them.



