In June, the U.S. Department of Justice’s National Security Division (NSD) announced its decision to decline prosecution of the German-headquartered conglomerate Robert Bosch GmbH concerning alleged violations of U.S. export control regulations. This landmark declination is the first issued by the NSD under the department-wide Corporate Enforcement and Voluntary Self-Disclosure Policy (CEP), which was updated in March 2026. The Bosch case offers a crucial early insight into how the NSD will apply the new CEP framework to cases involving national security concerns, particularly export control violations, and signals the potential benefits for companies proactively disclosing potential breaches.
The Assistant Attorney General for National Security underscored the significance of the decision, stating that it "reflects the clear benefits for companies that promptly disclose potential violations and fully assist in our investigations." This statement directly aligns with the stated objectives of the revised CEP, which aims to incentivize voluntary disclosures and robust cooperation by offering a clear path to declination for qualifying companies.
In tandem with the Department of Justice’s decision, the Department of Commerce’s Bureau of Industry and Security (BIS) reached a settlement with Bosch regarding the same alleged conduct. This settlement resulted in a substantial $36 million civil penalty. The Assistant Secretary of Commerce for Export Enforcement remarked that this action "should serve as a warning to embrace compliance and as an example of the benefits of voluntary self-disclosure." The dual actions by the DOJ and BIS highlight a coordinated approach to enforcing export control laws, emphasizing both punitive measures for non-compliance and the significant advantages of transparent engagement.
The Evolving Landscape: The New Corporate Enforcement Policy
The March 2026 release of the DOJ’s first-ever department-wide Corporate Enforcement Policy marked a significant shift in how the department approaches corporate criminal liability. Previously, the CEP was largely confined to the DOJ’s Criminal Division. However, the updated policy now extends its purview to all corporate criminal matters handled by the Justice Department, with the notable exclusion of certain antitrust violations. This broad application signifies the DOJ’s intent to foster a consistent and predictable approach to corporate misconduct across its various divisions.
Under Part I of the updated CEP, the DOJ outlines specific conditions under which it "will decline to prosecute a company for criminal conduct." These conditions are stringent and require a company to:
- Voluntarily self-disclose the misconduct to a criminal component of the department.
- Fully cooperate with the ensuing investigation.
- Timely and appropriately remediate the misconduct, demonstrating a commitment to correcting the issues and preventing recurrence.
- Absence of aggravating circumstances that would warrant prosecution.
Furthermore, under the CEP, companies that meet these criteria will still be obligated to pay any disgorgement, forfeiture, or restitution and victim compensation payments stemming from the misconduct. The National Security Division has explicitly confirmed its adherence to the CEP and has established a dedicated inbox for companies to submit voluntary self-disclosures pertaining to potential criminal violations of U.S. national security laws. This institutional commitment to the CEP by the NSD is a critical development for businesses operating in sensitive sectors.
The new department-wide CEP effectively supersedes the NSD’s prior enforcement policy for business organizations. Under the previous framework, meeting similar compliance requirements generally led to a "presumption" of receiving a non-prosecution agreement, with the division typically refraining from seeking a guilty plea. The new CEP, however, takes a more definitive stance, stating that the DOJ "will decline to prosecute" qualifying companies, indicating a stronger incentive for proactive disclosure and cooperation.
The Bosch Declination: A Case Study in Export Control Compliance
On June 17, the NSD revealed its decision not to prosecute Bosch for violations of the Export Administration Regulations (EAR). The alleged violations were attributed to two of Bosch’s German subsidiaries: Bosch Sensortec GmbH and ETAS GmbH. As detailed in the declination letter, these subsidiaries re-exported foreign-produced micro-electro-mechanical systems (MEMS) sensor products and associated software to Huawei Technologies Co. and its listed affiliates. Crucially, these re-exports were subject to the Entity List Foreign Direct Product Rule (FDR).
The Entity List FDR is a powerful regulatory tool that extends U.S. export controls to certain foreign-produced items if they are manufactured using U.S. software, technology, or production equipment. It specifically prohibits the export, re-export, or in-country transfer of such products to entities on the U.S. Entity List, including Huawei, without prior authorization from BIS.
The NSD’s declination letter highlighted that between September 2020 and September 2024, the two Bosch subsidiaries engaged in transactions involving over $70 million worth of these sensors and software with Huawei. These sales generated pre-tax profits for Bosch exceeding $11.4 million. The division’s findings indicated deficiencies within Bosch’s trade compliance personnel, who were described as "ill-equipped to provide accurate guidance on the (Foreign Direct Product Rule)." Furthermore, the investigation uncovered "several missed opportunities where third-party companies identified potential applications of the Foreign Direct Product Rule to their products or equipment used in the provision of their service," suggesting a systemic breakdown in risk assessment and compliance oversight.
The NSD’s decision to issue a declination was explicitly guided by the principles outlined in the CEP and general principles governing the federal prosecution of business organizations. While the declination letter did not feature a dedicated section detailing the absence of aggravating circumstances, it did acknowledge Bosch’s internal investigation findings. These findings characterized the violations as stemming from "numerous mistakes" rather than willful intent, with Bosch asserting that these errors did not rise to the level of acting willfully. This distinction between unintentional mistakes and deliberate disregard for regulations is often a critical factor in prosecutorial decision-making.
As a condition of the DOJ’s declination, Bosch was required to disgorge the full $11.4 million in pre-tax profits. The DOJ subsequently credited Bosch with more than $7.8 million already paid as part of the BIS settlement, thereby reducing the net disgorgement amount to approximately $3.6 million. This arrangement demonstrates a coordinated effort to ensure that financial penalties are applied holistically across agencies.
BIS Consent Order: A Parallel Enforcement Action
As previously mentioned, the BIS concurrently entered into a settlement agreement with Bosch, imposing a penalty of over $36 million for the same alleged export control violations. The BIS consent order explicitly stated that "Bosch’s U.S. export compliance team did not have sufficient expertise or resources at the time to adequately address" the complexities of the Foreign Direct Product Rule. It further noted that "Bosch’s failure to have an effective U.S. export controls compliance program in place . . . contributed directly to the violations at issue."
The BIS report indicated that Bosch had received multiple "warnings" from third-party companies about the inability to supply products processed by those companies to Huawei under the FDR. The fact that Bosch did not heed these warnings underscores a significant lapse in due diligence and risk management.
The BIS settlement amount of $36.1 million represented half of the total value of goods and software, approximately $72.2 million, that were re-exported to Huawei in violation of the FDR. While the order did not provide an exhaustive justification for the specific settlement figure, it is noteworthy that this amount falls well below the maximum penalty of twice the value of the transactions that BIS can impose. The BIS order referenced several mitigating factors that were also considered by the DOJ. These included Bosch’s timely voluntary self-disclosure to BIS, its remediation efforts which involved committing "significant resources" to enhance its compliance program, and its "full cooperation" with the BIS investigation.
Under BIS regulations, a voluntary self-disclosure is considered a significant "mitigating factor." Conversely, a company’s deliberate decision not to disclose apparent significant violations is treated as an "aggravating factor," emphasizing the importance of proactive reporting.
The BIS settlement also incorporated a credit for the $3.6 million disgorgement amount paid under the DOJ declination, bringing the net amount due to the BIS to approximately $32.5 million. This coordinated credit mechanism ensures that companies are not penalized twice for the same conduct by different government agencies.
Key Takeaways and Broader Implications
The NSD’s declination in the Bosch case offers a critical early indicator of the division’s intent to implement the Corporate Enforcement Policy in a manner that genuinely rewards companies that exhibit proactive compliance behaviors. This includes voluntary disclosure, thorough cooperation, and effective remediation of misconduct, even when the alleged violations involve substantial financial values or span extended periods. The significance of this declination is amplified by its context: sales to a high-profile Chinese company, Huawei, which has been a persistent focus of U.S. national security enforcement priorities under both the current and previous administrations.
While the National Security Division had previously issued a declination in 2024 to a company where export control violations were attributed to the actions of a single employee engaged in fraudulent activities that contravened established compliance requirements, the Bosch declination is particularly noteworthy. Unlike the rogue employee scenario, the conduct in the Bosch case was not isolated but rather appeared to be integrated into the company’s standard operating practices over an extended duration. This suggests that the NSD’s application of the CEP may extend beyond individual misconduct to encompass systemic compliance failures, provided that the company demonstrates sufficient commitment to correction.
In the Bosch case, the company proactively filed a voluntary self-disclosure while its internal investigation was still underway. It subsequently cooperated extensively with the division’s investigation and undertook significant remediation by enhancing its trade compliance functions. This declination can be interpreted as a positive signal for businesses contemplating whether to voluntarily disclose potential violations of U.S. national security laws. However, it remains to be seen how the NSD will apply the CEP to a wider array of factual scenarios. The declination letter’s emphasis on Bosch’s characterization of the violations as "numerous mistakes" and the company’s belief that these did not rise to the level of willful action is a crucial detail. The NSD may adopt a more stringent approach in cases involving conduct that exhibits clearer hallmarks of intent or falls under the definition of aggravating circumstances within the CEP.
The parallel actions by the DOJ and BIS underscore the profound importance of accurately interpreting and applying complex export control laws, particularly those with extraterritorial reach, such as the Foreign Direct Product Rule. These regulations have been a significant area of focus for BIS in recent years, reflecting a broader trend of increased scrutiny on global supply chains and the flow of sensitive technologies. Both agencies have consistently emphasized that U.S. export control laws can extend to items subject to the Export Administration Regulations regardless of their geographical location and can apply to foreign persons who engage with them, embodying the principle that "the law follows the goods." The coordinated enforcement actions by the DOJ and BIS serve as a clear demonstration of their ongoing commitment to enforcing U.S. export controls, including against non-U.S. companies, reinforcing the global reach and impact of these regulations.
The Bosch case, therefore, serves as a crucial precedent, offering valuable insights into the practical application of the DOJ’s new Corporate Enforcement Policy within the critical domain of national security. It highlights the evolving expectations for corporate compliance and the tangible benefits of transparency and proactive engagement when confronting potential regulatory breaches.
