Categories
Trekking Through Compliance

Trekking Through Compliance: Episode 68 – The Dangers of Assumption: How “Elaan of Troyius” Proves Due Diligence Is Essential

Today, let’s set our phasers to “analyze” and travel back to one of Star Trek: The Original Series’ most underrated diplomatic dramas: “Elaan of Troyius.” This episode is not just a space opera of culture clashes, hidden agendas, and diplomatic peril; it is a near-perfect parable for compliance professionals wrestling with the eternal question: Why is due diligence mandatory when considering a new business partner?

Let’s get into the heart of the episode and draw out five compliance lessons that every organization should heed before it signs that next contract.

Lesson 1: First Impressions Are Deceptive: Always Probe Deeper

Illustrated by: Elaan’s arrival is marked by dramatic displays of power, arrogance, and cultural superiority.

Compliance Lesson. How many times have we seen organizations swept off their feet by a potential partner’s surface credentials, market reputation, or charismatic leadership? Due diligence is your organization’s safeguard against falling for the “Elaan effect”: the temptation to trust a partner’s public image without digging into their true character, operational practices, or hidden risks.

Lesson 2: Cultural Blind Spots: Understand the Landscape Before You Leap

Illustrated by: Misunderstandings abound, from differing customs around authority and gender to fundamental misalignments in values.

Compliance Lesson. Entering into any partnership without understanding your partner’s culture, whether corporate, regional, or national, is asking for trouble.

Lesson 3: Hidden Agendas and Sabotage: Trust, But Verify

Illustrated by: The mission is sabotaged by Elaan’s retinue; her bodyguard conspires with the Klingons, hiding a device that compromises the Enterprise’s defenses.

Compliance Lesson. When evaluating new partners, you must assume that unseen risks may be lurking just below the surface.

Lesson 4: Emotional Reactions Cloud Judgment: Stay Objective

Illustrated by: Kirk finds himself emotionally entangled with Elaan after being exposed to her tears, which act as a potent love potion.

Compliance Lesson. In real-world business, emotional bias can cause teams to overlook red flags, downplay risks, or shortcut due diligence.

Lesson 5: The Price of Ignorance: Remediation Is Harder Than Prevention

Illustrated by: Only after chaos erupts do Kirk and the crew scramble to uncover the source of their problems, a hidden device sabotaging the Enterprise’s engines.

Compliance Lesson. If you do not invest in rigorous due diligence up front, you will inevitably spend much more time, money, and resources cleaning up the mess after something goes wrong.

Final ComplianceLog Reflections

Elaan of Troyius” is a warning to any organization tempted to “wing it” when evaluating a new business partner. Diplomacy, optimism, and trust are essential, but they are not substitutes for due diligence. Hidden risks, cultural misunderstandings, and emotional biases can turn opportunity into disaster in a heartbeat. Kirk and the crew of the Enterprise ultimately succeed not because of luck, but because they confront hard truths, adapt, and persevere. In the world of corporate compliance, the same rules apply.

Resources:

⁠⁠Excruciatingly Detailed Plot Summary by Eric W. Weisstein⁠⁠

⁠⁠MissionLogPodcast.com⁠⁠

⁠⁠Memory Alpha

Timothy is an AI-generated voice

Categories
AI in Financial Services in 5 Stories

AI in Financial Services in 5 Stories – Week Ending August 7, 2026

Welcome to AI in Financial Services in 5 Stories. A practical weekly roundup of the five most important AI developments affecting banking, insurance, payments, asset management, and fintech. Each Friday, Tom Fox will break down the top stories that matter most through the lenses of compliance, risk management, governance, and business strategy. Designed for compliance professionals, executives, legal teams, and financial services leaders, it goes beyond headlines to explain why each development matters in a highly regulated industry. The result is a concise weekly briefing that helps listeners stay current on AI innovation while asking sharper questions about oversight, accountability, and trust.

This week’s stories include the following:

  1. Jamie Dimon recruits bankers and IT leaders to tackle AI risks. (Finextra)
  2. When AI overwhelms humans. (Banking Dive)
  3. ROI for banks on AI-redesigned workflows. (American Banker)
  4. AI skills more valuable than an MBA. (CFO Brew)
  5. Mandatory AI training at the top of Deutsche Bank.(Financial News)

For more information on the use of AI in Compliance programs, Tom Fox’s new book, Upping Your Game, is available. You can purchase a copy of the book on Amazon.com.

To learn about the intersection of Sherlock Holmes and the modern compliance professional, check out Tom’s latest book, The Game is Afoot-What Sherlock Holmes Teaches About Risk, Ethics and Investigations on Amazon.com.

Categories
Daily Compliance News

Daily Compliance News: August 7, 2026, The End of Jones Act Edition

Welcome to the Daily Compliance News. Each day, Tom Fox, the Voice of Compliance, brings you compliance-related stories to start your day. Sit back, enjoy a cup of morning coffee, and listen in to the Daily Compliance News. All from the Compliance Podcast Network. Each day, we consider four stories from the business world: compliance, ethics, risk management, leadership, or general interest for the compliance professional.

Top stories include:

  • Mike Bloomberg wants to get rid of the Jones Act.  (Bloomberg)
  • Addition by subtraction. (Forbes)
  • Feds probe JPMorgan’s denial of customer reimbursements. (WSJ)
  • Judge cuts charges against FirstEnergy defendant. (Cleveland.com)

To learn about the intersection of Sherlock Holmes and the modern compliance professional, check out Tom’s latest book, The Game is Afoot-What Sherlock Holmes Teaches About Risk, Ethics and Investigations on Amazon.com.

Categories
Compliance and AI

Compliance and AI: Deterministic Legal Reasoning, Trust, and Auditability in Compliance Automation with Paul Welter

What is the intersection of AI and compliance? What about machine learning? Are you using ChatGPT? These questions are just three of the many we will explore in this cutting-edge podcast series, Compliance and AI, hosted by Tom Fox, the award-winning Voice of Compliance. Today Tom visits with Paul Welter, a German lawyer and former software engineer who co-founded Bayshore AI after research at Stanford Law School’s Codex on automating legal reasoning.

Welter explains Bayshore’s approach: extracting legal decision logic into deterministic, conventional code for predictable, explainable outcomes, while using large language models to gather scenario facts and handle vague legal terms. They discuss regulation as infrastructure for trust and economic activity and how today’s complexity creates bottlenecks that AI can alleviate by providing legal and compliance advice “in abundance.” Welter describes tailoring assessments to each customer’s policies and risk appetite, embedding them into workflows, and building trust through transparency, second-line control, and auditability for regulators. He highlights automation candidates (e.g., gifts/hospitality, third-party reviews) and advises teams to centralize request intake, measure frequency and effort, and automate iteratively.

Key highlights:

  • Predictable Legal AI
  • Regulation Enables Progress
  • Encoding Policies Not Laws
  • Building Trust in AI
  • Explainability and Audits
  • Agentic AI Use Cases

Resources:

Bayshore

Categories
AI in Healthcare

AI in Healthcare: Five Healthcare AI Stories You Need to Know This Week – August 7, 2026

Welcome to AI in Healthcare in 5 Stories. This podcast is a weekly briefing on the five most important AI developments shaping healthcare, medicine, and life sciences. Each week, Tom Fox breaks down the latest stories on clinical innovation, regulation, privacy, compliance, patient safety, and operational transformation through a practical, business-focused lens. Designed for healthcare compliance professionals, executives, legal teams, clinicians, and industry leaders, the podcast moves beyond headlines to explain what each development means in the real world.

The top five stories for the week ending August 7, 2026, include:

  1. Millennials, Gen Z turn to AI for healthcare. (The Business Journal)
  2. Benefits of medical AI assistance vary. (MIT News)
  3. Pharma safety teams still worried. (PharmaLive.com)
  4. AI in hospitals-data trust issues. (HealthcareITNews)
  5. Health systems prefer hybrid AI approach. (HealthcareFinance)

For more information on the use of AI in Compliance programs, Tom Fox’s new book, Upping Your Game, is available. You can purchase a copy of the book on Amazon.com.

To learn about the intersection of Sherlock Holmes and the modern compliance professional, check out Tom’s latest book, The Game is Afoot-What Sherlock Holmes Teaches About Risk, Ethics and Investigations on Amazon.com.

Categories
Hill Country Treasures

Hill Country Treasures: Understanding Gold, Silver, Bullion, and Collectible Coins

This podcast from MR Mint Coins & Collectibles in Kerrville, Texas, explores the value, history, and stories behind coins, currency, gold, silver, jewelry, bullion, sports cards, memorabilia, and family collections. Whether you are a lifelong collector, a curious beginner, or someone who just inherited a box of old coins, this show helps you understand what you have, what makes it valuable, and how to make smart, confident decisions. Join host Tom Fox and MR Coin owner Mike Russ for a show that celebrates local expertise, honest conversations, and the treasures hiding in plain sight across the Hill Country.

In this episode, Mike and Tom discuss how he explains gold and silver to everyday customers, emphasizing this is not investment advice. Russ describes how pricing differs for jewelry, scrap, bullion, and numismatic (collectible) coins: jewelry values depend on karat purity, typically paid as a percentage of spot because it must be refined, while bullion and coin pricing reflects spot plus spreads/premiums, and collectible coins depend on key dates, mint marks, condition, and grading. He notes using XRF testing for purity and a projector to show coin details. Russ outlines store offerings (bullion, collectibles, currency, gems/minerals) and highlights the importance of listening to customer stories, including estate and end-of-life situations.

Key highlights:

  • Gold & Silver Basics
  • Pricing Jewelry Scrap
  • Collectible Coin Factors
  • Bullion Forms Explained
  • Testing Broken Jewelry
  • Inside the Shop
  • Listening to Stories

Resources:

MR Mint and Coin Collectibles

Categories
AI Today in 5

AI Today in 5: August 7, 2026, The Perfect Pringle Edition

Welcome to AI Today in 5, the newest addition to the Compliance Podcast Network. Each day, Tom Fox will bring you 5 stories about AI to start your day. Sit back, enjoy a cup of morning coffee, and listen in to AI Today in 5. All from the Compliance Podcast Network. Each day, we consider five stories from the business world, compliance, ethics, risk management, leadership, or general interest about AI.

Top AI stories include:

  1. Talk, don’t type to prompt. (FT)
  2. China AI surging in Africa. (NYT)
  3. The quest to make the perfect Pringle. (WSJ)
  4. Compliance for government contractors using AI. (The National Law Review)
  5. The voice compliance challenge. (FinTech Global)

For more information on the use of AI in compliance programs, Tom Fox’s new book, Upping Your Game, is available. You can purchase a copy of the book on ⁠Amazon.com⁠.

To learn about the intersection of Sherlock Holmes and the modern compliance professional, check out Tom’s latest book, The Game is Afoot-What Sherlock Holmes Teaches About Risk, Ethics and Investigations on ⁠Amazon.com⁠.

Categories
Blog

The Price of Ignorance: Five Due Diligence Lessons from Star Trek’s “Elaan of Troyius”

Today, let’s set our phasers to “analyze” and travel back to one of Star Trek: The Original Series’ most underrated diplomatic dramas: “Elaan of Troyius.” This episode is not just a space opera of culture clashes, hidden agendas, and diplomatic peril; it is a near-perfect parable for compliance professionals wrestling with the eternal question: Why is due diligence mandatory when considering a new business partner?

For those who have not revisited this classic, the USS Enterprise is assigned a high-stakes diplomatic mission: transport Elaan, the tempestuous Dohlman of Elas, to the planet Troyius, where her arranged marriage will seal a peace treaty between two warring worlds. As tensions flare between Elaan’s culture and that of the Federation, Captain Kirk, Spock, and the crew quickly realize that more than just a wedding is at stake; hidden motivations, subterfuge, and cross-cultural misunderstandings threaten to unravel the entire peace process. What seems a straightforward escort mission rapidly reveals layers of complexity and risk.

Let’s get into the heart of the episode and draw out five compliance lessons that every organization should heed before it signs that next contract.

Lesson 1: First Impressions Are Deceptive: Always Probe Deeper

Illustrated by: Elaan’s arrival is marked by dramatic displays of power, arrogance, and cultural superiority. The Federation diplomats are immediately intimidated and distracted by her forceful presence and sharp temperament.

Compliance Lesson. How many times have we seen organizations swept off their feet by a potential partner’s surface credentials, market reputation, or charismatic leadership? In “Elaan of Troyius,” Kirk and his crew quickly learn that initial impressions, whether good or bad, can conceal much deeper realities. Due diligence is your organization’s safeguard against falling for the “Elaan effect”: the temptation to trust a partner’s public image without digging into their true character, operational practices, or hidden risks.

What should you do now? Do not accept a new partner at face value. Investigate their ownership structure, past conduct, litigation history, financial health, and compliance record. Unmasking the reality behind the reputation is the first step.

Lesson 2: Cultural Blind Spots: Understand the Landscape Before You Leap

Illustrated by: The cultural gap between Elaan and the Federation nearly derails the mission. Misunderstandings abound, from differing customs around authority and gender to fundamental misalignments in values. The crew is blindsided by these gaps, leading to avoidable conflict.

Compliance Lesson. Entering into any partnership without understanding your partner’s culture, whether corporate, regional, or national, is asking for trouble. Seemingly minor cultural mismatches can lead to miscommunication, legal violations, or ethical lapses. In cross-border or third-party relationships, this risk is magnified: local customs may hide corrupt practices, labor abuses, or anti-competitive behaviors.

What should you do now? Include cultural and ethical risk assessments as part of your due diligence. Engage local experts, conduct interviews, and be ready to adapt your approach to fit the landscape without compromising your core values.

Lesson 3: Hidden Agendas and Sabotage: Trust, But Verify

Illustrated by: The mission is sabotaged by Elaan’s retinue; her bodyguard conspires with the Klingons, hiding a device that compromises the Enterprise’s defenses. Kirk is nearly assassinated, and the entire mission teeters on the brink of disaster because no one anticipated internal betrayal.

Compliance Lesson. When evaluating new partners, you must assume that unseen risks may be lurking just below the surface. These could take the form of undisclosed beneficial ownership, connections to sanctioned parties, or corrupt insiders. Even a trusted contact within a partner organization can turn out to be a risk factor if not properly vetted. In “Elaan of Troyius,” failure to probe the intentions and backgrounds of all involved parties nearly results in catastrophe.

What should you do now? Conduct background checks not just on the company, but also on key personnel, agents, and ultimate beneficial owners. Use open-source intelligence, watchlists, and external investigators as needed. “Trust, but verify” is not simply good (Ronald Reagan) advice; it is mandatory.

Lesson 4: Emotional Reactions Cloud Judgment: Stay Objective

Illustrated by: Kirk finds himself emotionally entangled with Elaan after being exposed to her tears, which act as a potent love potion. His objectivity and command judgment are compromised at a critical moment, nearly dooming the ship.

Compliance Lesson. Emotional responses, from excitement about a lucrative new market to personal connections with a partner’s leadership, can cloud even the best compliance professional’s judgment. In “Elaan of Troyius,” emotional manipulation nearly brings down the Federation’s flagship. In real-world business, emotional bias can cause teams to overlook red flags, downplay risks, or shortcut due diligence.

What should you do now? Build structured, objective due diligence processes that minimize the risk of bias. Use checklists, outside counsel, and independent reviews to ensure no one is “drunk on the deal.” Compliance must be immune to infatuation.

Lesson 5: The Price of Ignorance: Remediation Is Harder Than Prevention

Illustrated by: Only after chaos erupts do Kirk and the crew scramble to uncover the source of their problems, a hidden device sabotaging the Enterprise’s engines. They’re forced into a desperate race against time to fix what could have been prevented.

Compliance Lesson. If you do not invest in rigorous due diligence up front, you will inevitably spend much more time, money, and resources cleaning up the mess after something goes wrong. Investigations, regulatory fines, lost business opportunities, and reputational damage are all far more expensive than preventative action. Just as Kirk would rather have found the sabotage before launch, compliance professionals must treat prevention as their first line of defense.

What should you do now? View due diligence as an investment, not a cost. The price of ignorance, missed risks, surprise violations, or regulatory enforcement will always exceed the price of preparedness.

Final ComplianceLog Reflections

Elaan of Troyius” is a warning to any organization tempted to “wing it” when evaluating a new business partner. Diplomacy, optimism, and trust are essential, but they are not substitutes for due diligence. Hidden risks, cultural misunderstandings, and emotional biases can turn opportunity into disaster in a heartbeat. Kirk and the crew of the Enterprise ultimately succeed not because of luck, but because they confront hard truths, adapt, and persevere. In the world of corporate compliance, the same rules apply.

So, the next time your organization eyes a shiny new partnership, ask yourself: Are we seeing only what we want to see? Or are we committed to the hard work of real due diligence, the only sure path to success, and to a future where both sides prosper?

Resources:

⁠⁠Excruciatingly Detailed Plot Summary by Eric W. Weisstein⁠⁠

⁠⁠MissionLogPodcast.com⁠⁠

⁠⁠Memory Alpha

Categories
Blog

Scoular DPA Part 5: From Reinspection Fees to Executive Signatures: Final Lessons from Scoular

From Reinspection Fees to Executive Signatures: Final Lessons from Scoular

The Scoular Company FCPA enforcement action began with a deceptively simple fact pattern. Customs brokers allegedly paid Mexican officials approximately $2,000 per train so agricultural shipments could cross the border despite adverse inspection findings. The brokers invoiced the payments to Scoular as “reinspection fees.” That description, however, was only the first layer of the case.

Across this blog post series, Scoular Company became a study in third-party risk, internal controls, cartel exposure, off-channel communications, facilitating payments, data analytics, voluntary disclosure, remediation, DOJ oversight, and executive accountability. Each article examined one part of the control environment. Taken together, they tell a larger story about how bribery becomes normalized inside an operating process and what a company must do when that process fails.

The source distinction matters. I have now posted two series on the enforcement action. The first series relied on the DOJ Press Release, which announced the resolution and described the government’s allegations and conclusions. The second series relied on the formal Deferred Prosecution Agreement (DPA), in which Scoular admitted, accepted, and stipulated that the facts were true. The DPA did not merely add detail. It changed the evidentiary foundation of the analysis.

I.              Series One: Lessons From the DOJ Press Release

a.     A Small Payment Became an Enterprise Control Failure

The Press Release series began with the mechanics of the scheme. According to the DOJ announcement, the conduct ran from 2013 through 2019, involved more than $400,000 in bribes, and enabled Scoular to avoid more than $6.5 million in fees and costs. Scoular entered a three-year DPA and agreed to pay a $9,769,521 criminal penalty and $414,351 in forfeiture.

The compliance lesson was never the size of one payment. It was repetition. A recurring round-dollar charge, submitted by customs brokers, approved over six years, and recorded under a plausible description became part of the company’s operating model.

The phrase “reinspection fee” demonstrated why invoice controls must examine commercial substance. A three-way match can confirm that an invoice, purchase order, and approval agree. It cannot establish that the underlying service was legitimate. For a high-risk customs payment, the control must ask what government action occurred, who received the money, whether an official fee schedule supports the amount, and what happened to the shipment after payment.

This also exposed the limits of onboarding due diligence. Screening a broker and obtaining an anti-corruption certification are only the beginning. Effective third-party management connects onboarding to invoices, transaction monitoring, business outcomes, periodic review, audit rights, and termination decisions.

b.    Cartel Risk Expanded the Compliance Perimeter

The Press Release stated that a portion of the bribe payments ultimately benefited individuals associated with a cartel operating at the U.S.-Mexico border, although the DOJ said Scoular Company and its employees did not know of that connection.

In an episode of the FCPA Compliance Report,  Matt Ellis discussed a broader question. Traditional anti-corruption diligence focuses on government-facing intermediaries, ownership, political exposure, adverse media, and government relationships. Organized-crime connections may not appear in a corporate registry or screening database.

The lesson was not that every cross-border transaction benefits a cartel. It was that companies must understand the environment in which their money, goods, and third parties move. Customs brokers, trucking companies, warehouses, security providers, labor contractors, and subcontractors can create overlapping corruption, money-laundering, sanctions, trade, security, and organized-crime risks.

c.     WhatsApp Was Part of the Control Environment

The Press Release series also examined WhatsApp and other communications used to discuss shipments and payments. The critical point was not that employees selected an unapproved application. It was that the substantive business decision could occur in a private message while the formal system recorded only the resulting invoice. Ellis emphasized that enforcement priorities may change, but evidence does not. A WhatsApp message can establish knowledge, authorization, concealment, or control circumvention even without a standalone off-channel communications charge.

A defensible program must identify the applications employees actually use, define which business activities may occur there, preserve relevant records, address local privacy and employment law, and enforce violations consistently. The company must also be able to connect communications with payment records, inspection results, shipment identifiers, approval logs, and bank data.

Facilitation Payments Did Not Fit the Facts

The Press Release series then addressed why the payments were not protected as facilitating payments. The FCPA exception is narrow. It may cover a payment intended to expedite a routine, nondiscretionary governmental act that the company is already entitled to receive. Scheduling an inspection may be routine. Paying an official to disregard a failed inspection is not. The alleged Scoular payments did not change timing. They changed the outcome and enabled shipments to cross despite findings of dirt, soil, and other impurities.

Amount, urgency, local custom, invoice wording, and use of a third party do not create the exception. Nor does the exception authorize a false accounting entry. A company that permits facilitating payments must still confront local law, accurate books and records, approval controls, and the practical difficulty of asking employees to make a narrow legal distinction under commercial pressure.

II.   Lessons From the DPA and Admitted Facts

a.     The DPA Showed How the Scheme Became Normal

The DPA blog post series began by distinguishing allegations in the Press Release from facts Scoular Company admitted. The Statement of Facts showed that stricter Mexican inspections created operational pressure (IE., more or new/different risks) in 2013. A broker proposed a fee on every train and promised that Scoular Company would “not have a single risk of adverse determinations.” The proposal was discussed at Scoular Company’s Kansas office and then replicated through additional brokers and border crossings.

The communications removed ambiguity. Employees discussed soil findings, special payments, trains released after inspections, and situations in which “normal procedures are not working.” By 2018, a communication referred to offering officials more than was normally given. These facts showed normalization. The scheme was not simply a broker’s unauthorized act. It became a repeatable process linking operational pressure, management knowledge, third parties, communications, invoices, approvals, and favorable business outcomes.

b.    Stopping the Conduct Was Not Self-Disclosure

The DPA disclosed that internal reports emerged in 2019 and Scoular Company changed its practices and ended direct engagement with the brokers. Yet the company did not receive voluntary self-disclosure credit because it did not voluntarily and timely report the conduct. The DPA does not reveal the company’s internal debate so that speculation would be inappropriate. It does establish a governance lesson. An internal report starts two clocks: the investigation clock and the disclosure-decision clock. Stopping the conduct is remediation. It is not a substitute for a documented, timely decision about disclosure.

Scoular later received cooperation and remediation credit, including a 25 percent reduction from the bottom of the applicable Sentencing Guidelines range. That outcome demonstrates that missing voluntary-disclosure credit does not make later cooperation irrelevant. It also demonstrates that the two forms of credit are not interchangeable.

c.     Executive Signatures Became the Final Control

The DPA’s attachments translated compliance expectations into personal executive responsibility. They required compliance access to the board, adequate authority and resources, incentives and discipline, third-party business-rationale documentation, verification of services, reasonable compensation, data access, root-cause analysis, and remediation.

They also required two distinct certifications. The CEO and CFO must certify disclosure obligations. The CEO and Chief Legal Officer must certify the truth and completeness of DOJ reports and the design of the anti-corruption compliance program. The certification language references potential exposure under 18 U.S.C. §§ 1001 and 1519 for materially false statements or records.

The signature is therefore not ceremonial. It requires an evidence chain from front-line controls through management testing to board oversight.

d.    Data Analytics Connects Both Series

Vince Walden’s analysis supplied the final detection lesson. No single anomaly proves bribery. The stronger signal is a sequence: an adverse inspection, an unusual recurring broker payment, and a favorable shipment release.

The words “reinspection fee” were searchable. The approximately $2,000 round-dollar amount was testable. The brokers, routes, inspection outcomes, timing, and releases were linkable. Communications could then provide context. Analytics should rank anomalies for human investigation, not declare guilt by algorithm.

This is where internal controls become dynamic. The company should test transaction text, payment amounts, vendor concentration, duplicate descriptions, approval patterns, inspection results, clearance timing, and user access together. Every substantiated alert should improve the next rule, risk model, training decision, and control test.

e.     Compliance Takeaways

  1. Treat the process as the risk unit. Review the third party, payment, message, inspection, route, approval, accounting entry, and business outcome together.
  2. Test substance, not labels. Require evidence of the service performed, the lawful basis for the fee, the recipient, the calculation, and the official result.
  3. Expand third-party risk beyond corruption screening. Integrate organized-crime, sanctions, anti-money-laundering, trade, security, and supply-chain intelligence where the risk profile requires it.
  4. Govern communications as business records. Know which channels employees use, restrict substantive approvals to controlled systems, preserve records, and test retrieval before an investigation.
  5. Create a disclosure decision protocol. Define who evaluates material facts, what information is needed, when senior management and the board are briefed, and how the decision is documented.
  6. Use analytics to connect events. Build monitoring around sequences and outcomes, then route alerts to trained investigators with access to operational, financial, and communications data.
  7. Make certifications evidence-based. Executive signers and boards should demand documented control testing, root-cause analysis, remediation status, and unresolved exceptions before signing.

The final lesson from Scoular Company is that bribery rarely sits in one control. It moves through an operating system. An effective compliance program must see that system, test it continuously, and ensure that the people who oversee it can stand behind the evidence.