The Scoular Company Deferred Prosecution Agreement (DPA) ends where every effective compliance program should begin: accountability. The agreement does not leave anti-corruption compliance solely with the Chief Compliance Officer, legal department, or internal audit. It assigns responsibilities throughout the enterprise, then requires senior executives to certify that the company has met its disclosure and compliance obligations.
The CEO signs twice. The Chief Financial Officer signs the disclosure certification. The Chief Legal Officer signs the compliance certification. Each certification is expressly treated as a material statement and representation for purposes of 18 U.S.C. Sections 1001 and 1519. A compliance program is not effective because someone owns it. It is effective when executives can reasonably rely on tested evidence and personally stand behind the result.
Attachment C Creates an Accountability System
Attachment C contains the minimum elements Scoular must maintain in its anti-corruption compliance program. Read separately, they look familiar: risk assessment, policies, training, reporting, investigations, incentives, discipline, third-party management, testing, data access, and remediation. Read together, they create an accountability system.
Directors and senior management must provide strong, explicit, and visible support through actions and words. Middle management must reinforce that commitment in day-to-day operations. One or more senior corporate executives must oversee the anti-corruption program and have authority to report directly to internal audit, the board, or an appropriate board committee.
Those officials must also have adequate autonomy from management and sufficient resources, authority, and senior leadership support. This is more demanding than tone at the top. It asks whether compliance can challenge the business, reach the board, obtain data, investigate allegations, and require remediation when commercial pressure is greatest.
In the DPA, the admitted conduct involved customs brokers, failed inspections, disguised invoices, communications, and recurring business benefits. An empowered compliance function must connect those facts across organizational boundaries. Formal reporting access means little if the function lacks the people, technology, information, or standing to do that work.
Compensation and Discipline Make Culture Measurable
Attachment C requires compliance criteria in compensation and bonus systems. It also requires disciplinary procedures to be applied consistently and fairly, regardless of an individual’s position or perceived importance. Those provisions address the incentives that can turn a workaround into an operating model.
If a logistics team is rewarded only for delivery speed, it may treat a delayed train as failure. If a senior manager receives credit for avoiding demurrage but no consequence for bypassing controls, the company has placed its real values inside the compensation plan. Training cannot overcome incentives that point in the opposite direction.
Scoular must therefore do more than add a generic compliance factor to an annual review. It should define the behaviors that affect compensation, document how compliance input changes an award, and test whether consequences are applied upward as well as downward. The board should examine outcomes. Who lost compensation? Who received recognition for escalating a concern? Were supervisors assessed for misconduct they tolerated or failed to detect? Did seniority affect the consequence? Culture becomes credible when employees can see that ethical conduct affects careers, compensation, and promotion.
Third-Party Accountability Requires Proof of Work
The bribery scheme operated through customs brokers. Attachment C responds directly to that risk. Scoular Company must document the business rationale for using a third party, assess reputation and foreign-official relationships, describe services specifically in the contract, confirm that the work was actually performed, and determine whether compensation is reasonable for the industry and geography. Ongoing monitoring may include updated due diligence, training, audits, and annual certifications. This is an operating control, not a procurement checklist.
An approved broker, executed contract, and completed screening report do not establish that a reinspection occurred or that a payment was legitimate. The business owner must be accountable for the service, finance must validate the invoice, compliance must assess red flags, and internal audit must test whether the control works. The central question is not whether the broker passed onboarding. It is whether the company knows what the broker did with its money.
Data Access Connects Oversight to Evidence
Attachment C requires compliance and control personnel to have sufficient direct or indirect access to relevant data for timely and effective transaction monitoring and testing. It also requires root-cause analysis of misconduct and the sharing of systemic issues, control failures, and remediation with management as appropriate. That obligation connects the program to the certifications.
Executives cannot make a defensible representation about program effectiveness if compliance cannot obtain accounts-payable data, broker records, shipment information, inspection results, communications, investigation files, and audit findings. The company cannot certify complete disclosure if allegations remain fragmented across the hotline, internal audit, legal, due diligence, and business systems. Data access is therefore an accountability issue. It determines whether management can see the whole risk picture before signing.
Two Certifications, Two Different Questions
The DPA requires two certifications at the end of its term.
The CEO and CFO Certify Disclosure
Attachment E requires the CEO and CFO to certify that Scoular has disclosed any and all evidence or allegations required by the DPA, including qualifying FCPA or Foreign Extortion Prevention Act matters involving employees or agents.
The form expressly reaches information identified through the compliance and controls program, whistleblower channel, internal audit reports, due diligence, investigations, or other processes.
The CFO’s inclusion is significant. Disclosure is not treated as a legal department judgment alone. The certification requires an enterprise process capable of gathering information from finance, controls, audit, compliance, investigations, and the business.
Before signing, the CEO and CFO should know what allegations were received, how they were triaged, which matters were investigated, what remains open, and how the company determined whether each matter was reportable.
The CEO and CLO Certify the Program
Attachment F requires the CEO and Chief Legal Officer to certify that Scoular’s DOJ reports are “true, accurate, and complete.” They must also certify, based on their review and understanding, that the company has implemented a program meeting Attachment C and that the program is reasonably designed to detect and prevent anti-corruption violations throughout Scoular’s operations. That is not a promise that misconduct will never occur. No compliance program can guarantee that result.
It is a representation about design, implementation, coverage, and the quality of the reports submitted to the government. The signatories therefore need evidence that the program operates across the enterprise, including in high-risk markets and functions. The CCO may build and test much of that evidence, but the CCO does not sign Attachment F. The DPA places the final representation with the CEO and CLO.
Sections 1001 and 1519 Change the Sign-Off Process
Both certification forms state that they constitute material statements and representations for purposes of Section 1001 and records or documents for purposes of Section 1519. That language should create rigor, not panic. It does not mean an executive should refuse to sign because testing found exceptions. A credible program should find weaknesses. The question is whether the certification and supporting reports accurately describe the program, testing, findings, remediation, and remaining limitations.
The greater risk is a ceremonial sign-off supported by filtered information, unresolved contradictions, narrow testing, or undocumented assumptions. Scoular Company should treat certification as a process rather than an event. That process should include:
- A written certification standard tied to each representation in Attachments E and F;
- Sub-certifications from the leaders who own finance, compliance, legal, internal audit, investigations, human resources, procurement, and high-risk operations;
- A complete inventory of allegations, investigations, audit issues, control exceptions, remediation items, and DOJ commitments;
- Independent challenge of management’s evidence and closure decisions;
- Documented treatment of qualifications, unresolved matters, and contrary evidence; and
- Audit committee review before the executives sign.
Sub-certifications should support executive diligence without diluting executive responsibility. The purpose is to create a reliable chain of evidence from the operational control to the final signature.
The Board Must Oversee the Evidence
The board does not sign Attachments E or F. Its oversight role is nevertheless central. The board authorized the DPA, and Attachment C gives the anti-corruption function access to the board or an appropriate committee. The board should use that access to test whether management’s certification process is credible.
Directors should not ask only whether the company is on schedule. They should ask what evidence could prevent a certification, which findings remain open, whether management has limited the scope of testing, and whether compliance, legal, finance, and internal audit agree on the facts. This is also a Caremark-style oversight lesson. Board-level information systems must bring significant compliance risks and red flags to directors, particularly during a formal government resolution. A dashboard should not replace discussion of disputed findings, repeat issues, overdue remediation, or business resistance.
Is It Real or Is It Memorex
I acknowledge there a contra view of this which comes to us from my Compliance into the Weeds, co-host, Matt Kelly. In a blog post entitled Scoular DPA Unveiled, Doesn’t Help, he questions why the company CCO is not required to certify the DPA. It could be as Kelly writes that “an agriculture supply business with 1,250 employees and $7.3 billion in revenue — even has a chief compliance officer; maybe it doesn’t, and the chief legal office also holds the CCO role.” He goes on to write “Then again, if a company’s chief legal officer pulls double duty as the chief compliance officer too, and that’s why he or she is signing the certification — doesn’t that whole arrangement run contrary to the spirit of what the Justice Department wants to see for an empowered and autonomous compliance function?” He concludes by asking “But if we’re now letting companies sign prosecution agreements where they commit to a strong, independent, empowered compliance function, except for the part that you don’t even have an actual chief compliance officer — then what are we even doing here, people?” [Emphasis supplied]
The Scoular Company website lists the Chief Legal Officer as Tim Manning, whose duties include leading “ Scoular’s legal team and serves as principal advisor on legal, risk, compliance, governance, and other matters to Scoular’s Senior Leadership Team and Board of Directors. He also has oversight of Scoular’s real estate function.” It appears the CCO and GC functions are wrapped into one person’s job description.
The Bottom Line on Accountability
We began this week’s blog post series with the admitted facts from the DPA: a payment process designed to prevent adverse customs decisions. It then examined the missed voluntary-disclosure window and a deep dive into how the use of data analytics and internal controls could have caught the FCPA violation. Today we end with the signatures. Scoular Company’s DPA demonstrates that executive accountability is not an abstract statement about culture. It is built through access, resources, incentives, discipline, third-party controls, data, testing, root-cause analysis, and complete reporting. The signature is not the beginning of accountability. It is the final confirmation that accountability has operated throughout the company, at least during the term of the DPA.