Less is less: What KKR’s USD 250 million penalty teaches us about information governance in merger control

On 26 August 2026, the U.S. Department of Justice (DOJ) announced that US private equity firm KKR had agreed to pay a record fine of USD 250 million to resolve allegations of repeated violations of the U.S. merger notification regime. Beyond the headline figure, the case points to practical lessons for merger control and M&A compliance.

The KKR case: More than a filing violation

The allegations of the DOJ relate to at least sixteen transactions between 2021 and 2022, a rather small subset of the more than 100 premerger filings under the Hart-Scott-Rodino Antitrust Improvements Act of 1976 (HSR Act) reportedly made by KKR in that period (underscoring the importance of merger control for private equity transactions as recently covered on this blog).

According to the DOJ, the alleged violations fell into three categories:

  • For at least eight transactions, KKR was said to have submitted HSR filings with internal documents that had been modified before filing.
  • In addition, the DOJ claimed that KKR repeatedly left out documents that should have accompanied the filing package, including deal-related materials discussing competitive overlaps, the rationale for transactions and related business considerations.
  • And lastly and more traditionally, in at least two other transactions, the firm allegedly did not make the required HSR filing at all.

Interestingly, KKR, for its part, says that it will be reimbursed the full amount of USD 250 million by external law firms.

Europe has seen this before

While the scale of the proposed U.S. penalty is unprecedented, the underlying principle is familiar. European regulators (as well as this blog) have repeatedly demonstrated that merger control obligations extend beyond notifying a transaction and observing standstill requirements (for practical guidance on avoiding gun-jumping risks, see here).

In 2017, the European Commission imposed its first fine for providing incorrect or misleading information under the 2004 Merger Regulation in connection with its review of Facebook’s acquisition of WhatsApp. Facebook had stated that it could not automatically match Facebook and WhatsApp user accounts reliably; however, the Commission later concluded that this technical capability already existed. While the outcome of the merger was unaffected, the infringement laid in the misleading information itself.

Two years later, the Commission imposed a EUR 52 million fine on General Electric in connection with its acquisition of LM Wind. During the review of GE’s acquisition of LM Wind, GE incorrectly stated that it had no higher-output offshore turbine in development beyond its 6 MW model, despite already offering a 12 MW turbine. GE corrected and re-notified the transaction but was still fined for negligent inaccuracies.

In 2021, the Commission fined Sigma-Aldrich EUR 7.5 million for providing misleading information, primarily concerning an R&D project closely associated with assets to be divested as part of a remedy package.

National regulators have taken a similar approach. In 2024, the UK Competition and Markets Authority (CMA) fined Tereos GBP 25,000 after concluding that the company had failed to provide a full response to a RFI seeking board and governance materials in a merger investigation. The CMA considered Tereos’ interpretation of the request unjustifiably narrow and capable of adversely affecting the inquiry.

In 2025, the Italian regulator AGCM found that PAC 2000A had negligently submitted inaccurate and misleading market-share information in merger proceedings. The error arose from the use of the wrong Google Maps API variable for catchment-area calculations, which added roughly one-third more store observations and produced market shares more favourable to PAC.

The real issue: Process integrity

These cases illustrate a familiar point: Regulators increasingly protect the integrity of the review process itself, not merely its substantive outcome. Merger review depends heavily on the parties’ own documents, submissions and responses to information requests. Unsurprisingly, regulators react strongly when they conclude that relevant material has been withheld, altered or inaccurately described.

AI-assisted review tools will only reinforce this trend. Regulators can increasingly test large document sets for consistency, making it more important than ever that filings, supporting documents and RFI responses tell the same story.

Three lessons for deal teams

The practical takeaway is not simply “do not provide false information”. Deal teams should always bear in mind that internal documents may ultimately be submitted in merger control proceedings and should draft them accordingly. The cases further point to concrete process controls that should sit alongside the substantive merger control analysis:

  • Know your evidence base. Document collection should be run as a governance exercise, not merely as a legal workstream. Deal teams need a clear inventory of potentially responsive materials and a process for escalating uncertainty about the scope of a request. As the Tereos case shows, it can be tricky to resolve genuine ambiguity unilaterally. At times it can be advisable to document assumptions and raise them with the regulator’s case team before production closes.
  • Validate before you submit. The filing narrative, supporting documents and RFI responses need to tell the same story. That may require stakeholder sign-off for factual statements and technical review for computational outputs.
  • Less is less. According to the DOJ, KKR employees allegedly used the phrase “less is more 🙂 ” in the context of incomplete premerger filing submissions. Submissions can be concise where the rules allow it and keeping them lean is in the client’s interest. However, withholding responsive information, narrowing searches too aggressively, sanitising the factual record or using ambiguous wording in internal messages on the collection of information creates a procedural risk that regulators are prepared to pursue.

A final remark

Merger control procedures are not only about thresholds, filing obligations and gun-jumping. Organising the relevant information, understanding what is available and deciding what needs to be submitted is a discipline in its own right, and one that can quickly become a compliance risk with significant consequences. It should therefore be on the agenda of every deal team from the outset.

Photo by Tasha Kostyuk on Unsplash