Categories
AI Today in 5

AI Today in 5: August 7, 2026, The Perfect Pringle Edition

Welcome to AI Today in 5, the newest addition to the Compliance Podcast Network. Each day, Tom Fox will bring you 5 stories about AI to start your day. Sit back, enjoy a cup of morning coffee, and listen in to AI Today in 5. All from the Compliance Podcast Network. Each day, we consider five stories from the business world, compliance, ethics, risk management, leadership, or general interest about AI.

Top AI stories include:

  1. Talk, don’t type to prompt. (FT)
  2. China AI surging in Africa. (NYT)
  3. The quest to make the perfect Pringle. (WSJ)
  4. Compliance for government contractors using AI. (The National Law Review)
  5. The voice compliance challenge. (FinTech Global)

For more information on the use of AI in compliance programs, Tom Fox’s new book, Upping Your Game, is available. You can purchase a copy of the book on ⁠Amazon.com⁠.

To learn about the intersection of Sherlock Holmes and the modern compliance professional, check out Tom’s latest book, The Game is Afoot-What Sherlock Holmes Teaches About Risk, Ethics and Investigations on ⁠Amazon.com⁠.

Categories
Blog

The Price of Ignorance: Five Due Diligence Lessons from Star Trek’s “Elaan of Troyius”

Today, let’s set our phasers to “analyze” and travel back to one of Star Trek: The Original Series’ most underrated diplomatic dramas: “Elaan of Troyius.” This episode is not just a space opera of culture clashes, hidden agendas, and diplomatic peril; it is a near-perfect parable for compliance professionals wrestling with the eternal question: Why is due diligence mandatory when considering a new business partner?

For those who have not revisited this classic, the USS Enterprise is assigned a high-stakes diplomatic mission: transport Elaan, the tempestuous Dohlman of Elas, to the planet Troyius, where her arranged marriage will seal a peace treaty between two warring worlds. As tensions flare between Elaan’s culture and that of the Federation, Captain Kirk, Spock, and the crew quickly realize that more than just a wedding is at stake; hidden motivations, subterfuge, and cross-cultural misunderstandings threaten to unravel the entire peace process. What seems a straightforward escort mission rapidly reveals layers of complexity and risk.

Let’s get into the heart of the episode and draw out five compliance lessons that every organization should heed before it signs that next contract.

Lesson 1: First Impressions Are Deceptive: Always Probe Deeper

Illustrated by: Elaan’s arrival is marked by dramatic displays of power, arrogance, and cultural superiority. The Federation diplomats are immediately intimidated and distracted by her forceful presence and sharp temperament.

Compliance Lesson. How many times have we seen organizations swept off their feet by a potential partner’s surface credentials, market reputation, or charismatic leadership? In “Elaan of Troyius,” Kirk and his crew quickly learn that initial impressions, whether good or bad, can conceal much deeper realities. Due diligence is your organization’s safeguard against falling for the “Elaan effect”: the temptation to trust a partner’s public image without digging into their true character, operational practices, or hidden risks.

What should you do now? Do not accept a new partner at face value. Investigate their ownership structure, past conduct, litigation history, financial health, and compliance record. Unmasking the reality behind the reputation is the first step.

Lesson 2: Cultural Blind Spots: Understand the Landscape Before You Leap

Illustrated by: The cultural gap between Elaan and the Federation nearly derails the mission. Misunderstandings abound, from differing customs around authority and gender to fundamental misalignments in values. The crew is blindsided by these gaps, leading to avoidable conflict.

Compliance Lesson. Entering into any partnership without understanding your partner’s culture, whether corporate, regional, or national, is asking for trouble. Seemingly minor cultural mismatches can lead to miscommunication, legal violations, or ethical lapses. In cross-border or third-party relationships, this risk is magnified: local customs may hide corrupt practices, labor abuses, or anti-competitive behaviors.

What should you do now? Include cultural and ethical risk assessments as part of your due diligence. Engage local experts, conduct interviews, and be ready to adapt your approach to fit the landscape without compromising your core values.

Lesson 3: Hidden Agendas and Sabotage: Trust, But Verify

Illustrated by: The mission is sabotaged by Elaan’s retinue; her bodyguard conspires with the Klingons, hiding a device that compromises the Enterprise’s defenses. Kirk is nearly assassinated, and the entire mission teeters on the brink of disaster because no one anticipated internal betrayal.

Compliance Lesson. When evaluating new partners, you must assume that unseen risks may be lurking just below the surface. These could take the form of undisclosed beneficial ownership, connections to sanctioned parties, or corrupt insiders. Even a trusted contact within a partner organization can turn out to be a risk factor if not properly vetted. In “Elaan of Troyius,” failure to probe the intentions and backgrounds of all involved parties nearly results in catastrophe.

What should you do now? Conduct background checks not just on the company, but also on key personnel, agents, and ultimate beneficial owners. Use open-source intelligence, watchlists, and external investigators as needed. “Trust, but verify” is not simply good (Ronald Reagan) advice; it is mandatory.

Lesson 4: Emotional Reactions Cloud Judgment: Stay Objective

Illustrated by: Kirk finds himself emotionally entangled with Elaan after being exposed to her tears, which act as a potent love potion. His objectivity and command judgment are compromised at a critical moment, nearly dooming the ship.

Compliance Lesson. Emotional responses, from excitement about a lucrative new market to personal connections with a partner’s leadership, can cloud even the best compliance professional’s judgment. In “Elaan of Troyius,” emotional manipulation nearly brings down the Federation’s flagship. In real-world business, emotional bias can cause teams to overlook red flags, downplay risks, or shortcut due diligence.

What should you do now? Build structured, objective due diligence processes that minimize the risk of bias. Use checklists, outside counsel, and independent reviews to ensure no one is “drunk on the deal.” Compliance must be immune to infatuation.

Lesson 5: The Price of Ignorance: Remediation Is Harder Than Prevention

Illustrated by: Only after chaos erupts do Kirk and the crew scramble to uncover the source of their problems, a hidden device sabotaging the Enterprise’s engines. They’re forced into a desperate race against time to fix what could have been prevented.

Compliance Lesson. If you do not invest in rigorous due diligence up front, you will inevitably spend much more time, money, and resources cleaning up the mess after something goes wrong. Investigations, regulatory fines, lost business opportunities, and reputational damage are all far more expensive than preventative action. Just as Kirk would rather have found the sabotage before launch, compliance professionals must treat prevention as their first line of defense.

What should you do now? View due diligence as an investment, not a cost. The price of ignorance, missed risks, surprise violations, or regulatory enforcement will always exceed the price of preparedness.

Final ComplianceLog Reflections

Elaan of Troyius” is a warning to any organization tempted to “wing it” when evaluating a new business partner. Diplomacy, optimism, and trust are essential, but they are not substitutes for due diligence. Hidden risks, cultural misunderstandings, and emotional biases can turn opportunity into disaster in a heartbeat. Kirk and the crew of the Enterprise ultimately succeed not because of luck, but because they confront hard truths, adapt, and persevere. In the world of corporate compliance, the same rules apply.

So, the next time your organization eyes a shiny new partnership, ask yourself: Are we seeing only what we want to see? Or are we committed to the hard work of real due diligence, the only sure path to success, and to a future where both sides prosper?

Resources:

⁠⁠Excruciatingly Detailed Plot Summary by Eric W. Weisstein⁠⁠

⁠⁠MissionLogPodcast.com⁠⁠

⁠⁠Memory Alpha

Categories
Blog

Scoular DPA Part 5: From Reinspection Fees to Executive Signatures: Final Lessons from Scoular

From Reinspection Fees to Executive Signatures: Final Lessons from Scoular

The Scoular Company FCPA enforcement action began with a deceptively simple fact pattern. Customs brokers allegedly paid Mexican officials approximately $2,000 per train so agricultural shipments could cross the border despite adverse inspection findings. The brokers invoiced the payments to Scoular as “reinspection fees.” That description, however, was only the first layer of the case.

Across this blog post series, Scoular Company became a study in third-party risk, internal controls, cartel exposure, off-channel communications, facilitating payments, data analytics, voluntary disclosure, remediation, DOJ oversight, and executive accountability. Each article examined one part of the control environment. Taken together, they tell a larger story about how bribery becomes normalized inside an operating process and what a company must do when that process fails.

The source distinction matters. I have now posted two series on the enforcement action. The first series relied on the DOJ Press Release, which announced the resolution and described the government’s allegations and conclusions. The second series relied on the formal Deferred Prosecution Agreement (DPA), in which Scoular admitted, accepted, and stipulated that the facts were true. The DPA did not merely add detail. It changed the evidentiary foundation of the analysis.

I.              Series One: Lessons From the DOJ Press Release

a.     A Small Payment Became an Enterprise Control Failure

The Press Release series began with the mechanics of the scheme. According to the DOJ announcement, the conduct ran from 2013 through 2019, involved more than $400,000 in bribes, and enabled Scoular to avoid more than $6.5 million in fees and costs. Scoular entered a three-year DPA and agreed to pay a $9,769,521 criminal penalty and $414,351 in forfeiture.

The compliance lesson was never the size of one payment. It was repetition. A recurring round-dollar charge, submitted by customs brokers, approved over six years, and recorded under a plausible description became part of the company’s operating model.

The phrase “reinspection fee” demonstrated why invoice controls must examine commercial substance. A three-way match can confirm that an invoice, purchase order, and approval agree. It cannot establish that the underlying service was legitimate. For a high-risk customs payment, the control must ask what government action occurred, who received the money, whether an official fee schedule supports the amount, and what happened to the shipment after payment.

This also exposed the limits of onboarding due diligence. Screening a broker and obtaining an anti-corruption certification are only the beginning. Effective third-party management connects onboarding to invoices, transaction monitoring, business outcomes, periodic review, audit rights, and termination decisions.

b.    Cartel Risk Expanded the Compliance Perimeter

The Press Release stated that a portion of the bribe payments ultimately benefited individuals associated with a cartel operating at the U.S.-Mexico border, although the DOJ said Scoular Company and its employees did not know of that connection.

In an episode of the FCPA Compliance Report,  Matt Ellis discussed a broader question. Traditional anti-corruption diligence focuses on government-facing intermediaries, ownership, political exposure, adverse media, and government relationships. Organized-crime connections may not appear in a corporate registry or screening database.

The lesson was not that every cross-border transaction benefits a cartel. It was that companies must understand the environment in which their money, goods, and third parties move. Customs brokers, trucking companies, warehouses, security providers, labor contractors, and subcontractors can create overlapping corruption, money-laundering, sanctions, trade, security, and organized-crime risks.

c.     WhatsApp Was Part of the Control Environment

The Press Release series also examined WhatsApp and other communications used to discuss shipments and payments. The critical point was not that employees selected an unapproved application. It was that the substantive business decision could occur in a private message while the formal system recorded only the resulting invoice. Ellis emphasized that enforcement priorities may change, but evidence does not. A WhatsApp message can establish knowledge, authorization, concealment, or control circumvention even without a standalone off-channel communications charge.

A defensible program must identify the applications employees actually use, define which business activities may occur there, preserve relevant records, address local privacy and employment law, and enforce violations consistently. The company must also be able to connect communications with payment records, inspection results, shipment identifiers, approval logs, and bank data.

Facilitation Payments Did Not Fit the Facts

The Press Release series then addressed why the payments were not protected as facilitating payments. The FCPA exception is narrow. It may cover a payment intended to expedite a routine, nondiscretionary governmental act that the company is already entitled to receive. Scheduling an inspection may be routine. Paying an official to disregard a failed inspection is not. The alleged Scoular payments did not change timing. They changed the outcome and enabled shipments to cross despite findings of dirt, soil, and other impurities.

Amount, urgency, local custom, invoice wording, and use of a third party do not create the exception. Nor does the exception authorize a false accounting entry. A company that permits facilitating payments must still confront local law, accurate books and records, approval controls, and the practical difficulty of asking employees to make a narrow legal distinction under commercial pressure.

II.   Lessons From the DPA and Admitted Facts

a.     The DPA Showed How the Scheme Became Normal

The DPA blog post series began by distinguishing allegations in the Press Release from facts Scoular Company admitted. The Statement of Facts showed that stricter Mexican inspections created operational pressure (IE., more or new/different risks) in 2013. A broker proposed a fee on every train and promised that Scoular Company would “not have a single risk of adverse determinations.” The proposal was discussed at Scoular Company’s Kansas office and then replicated through additional brokers and border crossings.

The communications removed ambiguity. Employees discussed soil findings, special payments, trains released after inspections, and situations in which “normal procedures are not working.” By 2018, a communication referred to offering officials more than was normally given. These facts showed normalization. The scheme was not simply a broker’s unauthorized act. It became a repeatable process linking operational pressure, management knowledge, third parties, communications, invoices, approvals, and favorable business outcomes.

b.    Stopping the Conduct Was Not Self-Disclosure

The DPA disclosed that internal reports emerged in 2019 and Scoular Company changed its practices and ended direct engagement with the brokers. Yet the company did not receive voluntary self-disclosure credit because it did not voluntarily and timely report the conduct. The DPA does not reveal the company’s internal debate so that speculation would be inappropriate. It does establish a governance lesson. An internal report starts two clocks: the investigation clock and the disclosure-decision clock. Stopping the conduct is remediation. It is not a substitute for a documented, timely decision about disclosure.

Scoular later received cooperation and remediation credit, including a 25 percent reduction from the bottom of the applicable Sentencing Guidelines range. That outcome demonstrates that missing voluntary-disclosure credit does not make later cooperation irrelevant. It also demonstrates that the two forms of credit are not interchangeable.

c.     Executive Signatures Became the Final Control

The DPA’s attachments translated compliance expectations into personal executive responsibility. They required compliance access to the board, adequate authority and resources, incentives and discipline, third-party business-rationale documentation, verification of services, reasonable compensation, data access, root-cause analysis, and remediation.

They also required two distinct certifications. The CEO and CFO must certify disclosure obligations. The CEO and Chief Legal Officer must certify the truth and completeness of DOJ reports and the design of the anti-corruption compliance program. The certification language references potential exposure under 18 U.S.C. §§ 1001 and 1519 for materially false statements or records.

The signature is therefore not ceremonial. It requires an evidence chain from front-line controls through management testing to board oversight.

d.    Data Analytics Connects Both Series

Vince Walden’s analysis supplied the final detection lesson. No single anomaly proves bribery. The stronger signal is a sequence: an adverse inspection, an unusual recurring broker payment, and a favorable shipment release.

The words “reinspection fee” were searchable. The approximately $2,000 round-dollar amount was testable. The brokers, routes, inspection outcomes, timing, and releases were linkable. Communications could then provide context. Analytics should rank anomalies for human investigation, not declare guilt by algorithm.

This is where internal controls become dynamic. The company should test transaction text, payment amounts, vendor concentration, duplicate descriptions, approval patterns, inspection results, clearance timing, and user access together. Every substantiated alert should improve the next rule, risk model, training decision, and control test.

e.     Compliance Takeaways

  1. Treat the process as the risk unit. Review the third party, payment, message, inspection, route, approval, accounting entry, and business outcome together.
  2. Test substance, not labels. Require evidence of the service performed, the lawful basis for the fee, the recipient, the calculation, and the official result.
  3. Expand third-party risk beyond corruption screening. Integrate organized-crime, sanctions, anti-money-laundering, trade, security, and supply-chain intelligence where the risk profile requires it.
  4. Govern communications as business records. Know which channels employees use, restrict substantive approvals to controlled systems, preserve records, and test retrieval before an investigation.
  5. Create a disclosure decision protocol. Define who evaluates material facts, what information is needed, when senior management and the board are briefed, and how the decision is documented.
  6. Use analytics to connect events. Build monitoring around sequences and outcomes, then route alerts to trained investigators with access to operational, financial, and communications data.
  7. Make certifications evidence-based. Executive signers and boards should demand documented control testing, root-cause analysis, remediation status, and unresolved exceptions before signing.

The final lesson from Scoular Company is that bribery rarely sits in one control. It moves through an operating system. An effective compliance program must see that system, test it continuously, and ensure that the people who oversee it can stand behind the evidence.

Categories
Everything Compliance

Everything Compliance: The Prime Ministers, Shoes, Corruption and the Board Edition

Welcome to a revamped Everything Compliance. We have a new host, Adam Turteltaub, and a new panelist, Rebecca Walker, who joins returning regulars Matt Kelly, Jonathan Armstrong, and Karen Moore for the next iteration of Everything Compliance.

  • Matt Kelly analyzes the Scoular Company FCPA enforcement action.
  • Karen Moore reviews a recent pay discrimination case in Oregon.
  • Jonathan Armstrong discusses the change of Prime Minister in the UK and what it means for compliance.
  • Rebecca Walker looks at the current status of law and cases related to Board oversight.

The members of Everything Compliance are:

The award-winning Everything Compliance is a part of the Compliance Podcast Network.

Categories
AI Today in 5

AI Today in 5: August 6, 2026, The Who Takes the Fall Edition

Welcome to AI Today in 5, the newest addition to the Compliance Podcast Network. Each day, Tom Fox will bring you 5 stories about AI to start your day. Sit back, enjoy a cup of morning coffee, and listen in to AI Today in 5. All from the Compliance Podcast Network. Each day, we consider five stories from the business world, compliance, ethics, risk management, leadership, or general interest about AI.

Top AI stories include:

  1. EU must do more. (FT)
  2. White House readies AI framework. (NYT)
  3. AI went rogue yet again. (WSJ)
  4. Rethinking AI and KYC. (FinTechGlobal)
  5. AI can do the work but the human takes the fall. (FinTechGlobal)

For more information on the use of AI in compliance programs, Tom Fox’s new book, Upping Your Game, is available. You can purchase a copy of the book on ⁠Amazon.com⁠.

To learn about the intersection of Sherlock Holmes and the modern compliance professional, check out Tom’s latest book, The Game is Afoot-What Sherlock Holmes Teaches About Risk, Ethics and Investigations on ⁠Amazon.com⁠.

Categories
Trekking Through Compliance

Trekking Through Compliance: Episode 67 – The Human Element in Compliance: CCO Takeaways from ‘The Empath’

Today we set a course for one of Star Trek: The Original Series’ most underrated yet profound episodes: “The Empath.” As compliance professionals, we know that the heart of any effective compliance program is its leadership. The Hallmarks of an Effective Compliance Program, from the FCPA Resource Guide, 2nd edition, require that the CCO possess the “appropriate expertise” to do the job. But what does that mean, and how does a leader’s expertise transcend mere technical skill to encompass the human, ethical, and cultural challenges inherent to the compliance function?

As we explore five critical lessons for compliance officers from “The Empath,” you will observe that true expertise for a CCO is not simply about credentials or technical know-how; rather, it is about the deeper qualities that empower a leader to guide organizations through pain, ambiguity, and risk.

Lesson 1: Beyond the Resume: The CCO as Empathic Leader

Illustrated by: Gem learns not through technical means, but by direct connection and deep feeling.

Compliance Lesson. Expertise is more than certifications, legal degrees, or audit experience. The most effective CCOs bring an “empathic intelligence” to their work, a capacity to understand the pressures, fears, and motivations of employees at all levels.

Lesson 2: Courage Under Pressure: The CCO Must Withstand the Ultimate Test

Illustrated by: The episode asks, who dares to stand up, even when it hurts?

Compliance Lesson. CCO expertise is proven under fire. This means the ability to stand firm when pressured by powerful business leaders, to deliver hard truths to the Board, and to make unpopular recommendations in the face of potential personal or professional blowback.

Lesson 3: Interdisciplinary Skillset: Bridging Science and Compassion

Illustrated by: The Enterprise officers combine analytical thinking with compassion, helping Gem grow by demonstrating both logic and heart.

Compliance Lesson. A truly effective CCO integrates hard skills with the “soft skills” of persuasion, relationship-building, and cultural sensitivity.

Lesson 4: The Power of Sacrifice: Prioritizing the Mission Over Personal Gain

Illustrated by: McCoy’s selflessness teaches Gem that true empathy means accepting risk for the sake of others’ well-being.

Compliance Lesson. The CCO role demands a willingness to prioritize the organization’s long-term health, even when it may come at the cost of short-term popularity or personal advancement.

Lesson 5: Teaching and Transforming: The CCO as Culture Carrier

Illustrated by: By the episode’s conclusion, Gem is transformed by the example set by the Enterprise crew. She learns to act, not just to feel, demonstrating that real change comes from both internalizing values and taking decisive action.

Compliance Lesson. A CCO’s expertise is measured not only in what they know but also in how effectively they teach, mentor, and shape the organization’s culture—the enterprise.

Final ComplianceLog Reflections

The Empath” reminds us that leadership in compliance, like leadership in the Enterprise, requires more than technical skill. It requires empathy, courage, interdisciplinary knowledge, sacrifice, and the ability to teach and inspire. The DOJ’s Hallmarks of an Effective Compliance Program make it clear: a CCO must have the appropriate expertise to do the job, and that expertise is as much about the heart as the head.

In evaluating, supporting, or stepping into the CCO role, remember Gem’s journey. The greatest expertise lies not only in knowing the rules but also in living them and in helping others do the same, especially when the path is hard. Empathic leadership is not a luxury; it is a requirement for building compliance programs that endure.

Resources:

⁠⁠Excruciatingly Detailed Plot Summary by Eric W. Weisstein⁠⁠

⁠⁠MissionLogPodcast.com⁠⁠

⁠⁠Memory Alpha

Fiona is an AI-generated voice

Categories
Daily Compliance News

Daily Compliance News: August 6, 2026, The $100bn Refund Edition

Welcome to the Daily Compliance News. Each day, Tom Fox, the Voice of Compliance, brings you compliance-related stories to start your day. Sit back, enjoy a cup of morning coffee, and listen in to the Daily Compliance News. All from the Compliance Podcast Network. Each day, we consider four stories from the business world: compliance, ethics, risk management, leadership, or general interest for the compliance professional.

Top stories include:

  • Former Ukrainian ambassador to the US under corruption investigation.  (EuroNews)
  • Illegal tariff refunds hit $100bn. (CNBC)
  • Women spearheading resistance to Infantino. (Reuters)
  • Use a mentor for some honesty. (FT)

To learn about the intersection of Sherlock Holmes and the modern compliance professional, check out Tom’s latest book, The Game is Afoot-What Sherlock Holmes Teaches About Risk, Ethics and Investigations on Amazon.com.

Categories
Blog

Empathy, Expertise, and the CCO: Five Lessons from Star Trek’s “The Empath”

Today, we set a course for one of Star Trek: The Original Series’ most underrated yet profound episodes: “The Empath.” As compliance professionals, we know that the heart of any effective compliance program is its leadership. The Hallmarks of an Effective Compliance Program, from the FCPA Resource Guide, 2nd edition, Justice, require that the Chief Compliance Officer (CCO) possess the “appropriate expertise” to do the job. But what does that mean, and how does a leader’s expertise transcend mere technical skill to encompass the human, ethical, and cultural challenges inherent to the compliance function?

Let’s use “The Empath” as our guide. This visually striking and emotionally powerful episode puts Captain Kirk, Dr. McCoy, and Mr. Spock in the hands of alien scientists who subject them and a mysterious, silent woman named Gem to a series of moral and physical trials. At its core, the episode explores the transformative power of empathy, self-sacrifice, and moral courage.

As we explore five critical lessons for compliance officers from “The Empath,” you will observe that true expertise for a CCO is not simply about credentials or technical know-how; rather, it is about the deeper qualities that empower a leader to guide organizations through pain, ambiguity, and risk.

Lesson 1: Beyond the Resume: The CCO as Empathic Leader

Illustrated by: Gem, the titular empath, can sense and even absorb the pain of others, experiencing their suffering as if it were her own. She learns not through technical means, but by direct connection and deep feeling.

Compliance Lesson. Expertise is more than certifications, legal degrees, or audit experience. The most effective CCOs bring an “empathic intelligence” to their work, a capacity to understand the pressures, fears, and motivations of employees at all levels. Just as Gem could not help without first connecting to others’ pain, a CCO must be attuned to the human element behind every compliance risk. This empathy allows the CCO to anticipate issues before they become crises, to speak credibly to leadership about real risks, and to create a culture where people feel safe reporting concerns.

What should you do now? When evaluating CCO expertise, look beyond the resume. Ask: Does this person have the emotional intelligence to sense the cultural currents within the organization? Can they “walk the decks” and listen with intention? Empathy is not optional; it is essential.

Lesson 2: Courage Under Pressure: The CCO Must Withstand the Ultimate Test

Illustrated by: In “The Empath,” Kirk, Spock, and McCoy are subjected to torturous experiments designed to test their moral fiber. Dr. McCoy, in particular, volunteers to endure pain so others may be spared. The episode asks, Who dares to stand up, even when it hurts?

Compliance Lesson. CCO expertise is proven under fire. In practice, this means the ability to stand firm when pressured by powerful business leaders, to deliver hard truths to the Board, and to make unpopular recommendations in the face of potential personal or professional blowback. The DOJ’s 10 Hallmarks require CCOs who can operate with autonomy and independence, not simply as figureheads or “window dressing.” True expertise reveals itself when the stakes are high, and the right answer is the hard one.

What should you do now? Your CCO must be someone who will put the organization’s integrity first, even at personal cost. The “ultimate test” for a CCO is not a certification but the ability to hold the line when ethical principles are threatened.

Lesson 3: Interdisciplinary Skillset: Bridging Science and Compassion

Illustrated by: The Vians, the alien scientists, are coldly rational, treating their subjects as experimental variables. In contrast, the Enterprise officers combine analytical thinking with compassion, helping Gem grow by demonstrating both logic and heart.

Compliance Lesson. A CCO’s expertise must bridge multiple disciplines. Today’s compliance challenges touch on law, accounting, behavioral science, technology, communications, and global business. But technical expertise is only half the equation. A truly effective CCO integrates hard skills with the “soft skills” of persuasion, relationship-building, and cultural sensitivity. Like Kirk and Spock, who blend analysis and empathy to navigate the Vians’ trials, a CCO must translate regulatory requirements into messages that resonate and motivate across the organization.

What should you do now? Evaluate CCO candidates for both their cross-disciplinary knowledge and their ability to synthesize and communicate complex concepts persuasively. Expertise means connecting dots and connecting with people.

Lesson 4: The Power of Sacrifice: Prioritizing the Mission Over Personal Gain

Illustrated by: McCoy’s willingness to sacrifice himself for Kirk and Spock is a turning point—both for Gem and the Vians. His selflessness teaches Gem that true empathy means accepting risk for the sake of others’ well-being.

Compliance Lesson. The CCO role demands a willingness to prioritize the organization’s long-term health, even when it may come at the cost of short-term popularity or personal advancement. This can mean blowing the whistle on powerful stakeholders, accepting the possibility of career setbacks, or simply shouldering the emotional burden of being the “corporate conscience.” The DOJ expects companies to empower CCOs with the independence to act—because true expertise includes the courage to make sacrifices for the greater good.

What should you do now? Ask not only whether your CCO is capable, but whether they are willing to accept the risks of leadership. Expertise means prioritizing the mission even when the cost is high.

Lesson 5: Teaching and Transforming: The CCO as Culture Carrier

Illustrated by: By the episode’s conclusion, Gem is transformed by the example set by the Enterprise crew. She learns to act, not just to feel, demonstrating that real change comes from both internalizing values and taking decisive action.

Compliance Lesson. A CCO’s expertise is measured not only in what they know but also in how effectively they teach, mentor, and shape the organization’s culture. Just as Gem evolved through the guidance of Kirk and McCoy, so too must a CCO help others grow, empowering managers, employees, and even Board members to become stewards of compliance. Expertise is contagious: a strong CCO leaves a legacy of ethical leadership throughout the enterprise.

What should you do now?

Does your CCO inspire others to act with integrity? Are they a “culture carrier,” modeling the behaviors and values they wish to see at every level? True expertise is reflected in the transformation of others.

Final ComplianceLog Reflections

The Empath” reminds us that leadership in compliance, like leadership in the enterprise, requires more than technical skill. It requires empathy, courage, interdisciplinary knowledge, sacrifice, and the ability to teach and inspire. The DOJ’s Hallmarks of an Effective Compliance Program make it clear: a CCO must have the appropriate expertise to do the job, and that expertise is as much about the heart as the head.

In evaluating, supporting, or stepping into the CCO role, remember Gem’s journey. The greatest expertise lies not only in knowing the rules but in living them and in helping others do the same, especially when the path is hard. Empathic leadership is not a luxury; it is a requirement for building compliance programs that endure.

Resources:

⁠⁠Excruciatingly Detailed Plot Summary by Eric W. Weisstein⁠⁠

⁠⁠MissionLogPodcast.com⁠⁠

⁠⁠Memory Alpha

Categories
Hill Country Authors

Hill Country Authors Podcast: Heath Hamrick on Texas Coaching, Small-Town Community, and Writing “Play Like He Would”

Welcome to a new season of the award-winning Hill Country Authors Podcast, sponsored by Stoney Creek Publishing. In this podcast, Hill Country resident Tom Fox visits with authors who live in and write about the Texas Hill Country. Tom Fox interviews Texas educator and longtime coach Heath Hamrick about his books, including Worse Than You Think and Play Like He Would.

Hamrick describes growing up in a multigenerational Texas coaching family and moving across the state and explains how Play Like He Would was shaped by witnessing his father coach and by a small-town tragedy in which a player, Jason Yancey, died on the field from an undetected enlarged heart. He contrasts his emotions then and now as a father, discusses coaches as surrogate fathers or big brothers who lead through care rather than yelling, and reflects on educators who change lives by sparking interest and truly seeing students. He argues real-life “how we move forward” stories matter more than Hollywood endings, defines legacy as lasting impact on students, and praises Stoney Creek Publishing’s support while describing revisiting decades-old drafts with a new perspective.

Key highlights:

  • Life as a Texas Educator
  • Tragedy on the Field
  • Discipline Without Yelling
  • Coaching for Leaders
  • Teachers Who Matter
  • Real Life, Not Hollywood
  • Legacy of Teaching & Writing After 20 Years

Resources: 

Order Play Like He Would on:

TamuPress

Amazon

Stoney Creek Publishing

Follow Heath Hamrick on:

Facebook

Instagram

Stoney Creek Publishing Profile

Podcast Cover Art

Nancy Huffman Fine Art

Tom Fox

Instagram

Facebook

YouTube

Twitter

LinkedIn

Categories
Blog

The Scoular DPA Part 4: The Signature Is the Control – Executive Accountability in the Scoular DPA

The Scoular Company Deferred Prosecution Agreement (DPA) ends where every effective compliance program should begin: accountability. The agreement does not leave anti-corruption compliance solely with the Chief Compliance Officer, legal department, or internal audit. It assigns responsibilities throughout the enterprise, then requires senior executives to certify that the company has met its disclosure and compliance obligations.

The CEO signs twice. The Chief Financial Officer signs the disclosure certification. The Chief Legal Officer signs the compliance certification. Each certification is expressly treated as a material statement and representation for purposes of 18 U.S.C. Sections 1001 and 1519. A compliance program is not effective because someone owns it. It is effective when executives can reasonably rely on tested evidence and personally stand behind the result.

Attachment C Creates an Accountability System

Attachment C contains the minimum elements Scoular must maintain in its anti-corruption compliance program. Read separately, they look familiar: risk assessment, policies, training, reporting, investigations, incentives, discipline, third-party management, testing, data access, and remediation. Read together, they create an accountability system.

Directors and senior management must provide strong, explicit, and visible support through actions and words. Middle management must reinforce that commitment in day-to-day operations. One or more senior corporate executives must oversee the anti-corruption program and have authority to report directly to internal audit, the board, or an appropriate board committee.

Those officials must also have adequate autonomy from management and sufficient resources, authority, and senior leadership support. This is more demanding than tone at the top. It asks whether compliance can challenge the business, reach the board, obtain data, investigate allegations, and require remediation when commercial pressure is greatest.

In the DPA, the admitted conduct involved customs brokers, failed inspections, disguised invoices, communications, and recurring business benefits. An empowered compliance function must connect those facts across organizational boundaries. Formal reporting access means little if the function lacks the people, technology, information, or standing to do that work.

Compensation and Discipline Make Culture Measurable

Attachment C requires compliance criteria in compensation and bonus systems. It also requires disciplinary procedures to be applied consistently and fairly, regardless of an individual’s position or perceived importance. Those provisions address the incentives that can turn a workaround into an operating model.

If a logistics team is rewarded only for delivery speed, it may treat a delayed train as failure. If a senior manager receives credit for avoiding demurrage but no consequence for bypassing controls, the company has placed its real values inside the compensation plan. Training cannot overcome incentives that point in the opposite direction.

Scoular must therefore do more than add a generic compliance factor to an annual review. It should define the behaviors that affect compensation, document how compliance input changes an award, and test whether consequences are applied upward as well as downward. The board should examine outcomes. Who lost compensation? Who received recognition for escalating a concern? Were supervisors assessed for misconduct they tolerated or failed to detect? Did seniority affect the consequence? Culture becomes credible when employees can see that ethical conduct affects careers, compensation, and promotion.

Third-Party Accountability Requires Proof of Work

The bribery scheme operated through customs brokers. Attachment C responds directly to that risk. Scoular Company must document the business rationale for using a third party, assess reputation and foreign-official relationships, describe services specifically in the contract, confirm that the work was actually performed, and determine whether compensation is reasonable for the industry and geography. Ongoing monitoring may include updated due diligence, training, audits, and annual certifications. This is an operating control, not a procurement checklist.

An approved broker, executed contract, and completed screening report do not establish that a reinspection occurred or that a payment was legitimate. The business owner must be accountable for the service, finance must validate the invoice, compliance must assess red flags, and internal audit must test whether the control works. The central question is not whether the broker passed onboarding. It is whether the company knows what the broker did with its money.

Data Access Connects Oversight to Evidence

Attachment C requires compliance and control personnel to have sufficient direct or indirect access to relevant data for timely and effective transaction monitoring and testing. It also requires root-cause analysis of misconduct and the sharing of systemic issues, control failures, and remediation with management as appropriate. That obligation connects the program to the certifications.

Executives cannot make a defensible representation about program effectiveness if compliance cannot obtain accounts-payable data, broker records, shipment information, inspection results, communications, investigation files, and audit findings. The company cannot certify complete disclosure if allegations remain fragmented across the hotline, internal audit, legal, due diligence, and business systems. Data access is therefore an accountability issue. It determines whether management can see the whole risk picture before signing.

Two Certifications, Two Different Questions

The DPA requires two certifications at the end of its term.

The CEO and CFO Certify Disclosure

Attachment E requires the CEO and CFO to certify that Scoular has disclosed any evidence or allegations required by the DPA, including qualifying FCPA or Foreign Extortion Prevention Act matters involving employees or agents.

The form expressly reaches information identified through the compliance and controls program, whistleblower channel, internal audit reports, due diligence, investigations, or other processes.

The CFO’s inclusion is significant. Disclosure is not treated as a legal department judgment alone. The certification requires an enterprise process capable of gathering information from finance, controls, audit, compliance, investigations, and the business.

Before signing, the CEO and CFO should know what allegations were received, how they were triaged, which matters were investigated, what remains open, and how the company determined whether each matter was reportable.

The CEO and CLO Certify the Program

Attachment F requires the CEO and Chief Legal Officer to certify that Scoular’s DOJ reports are “true, accurate, and complete.” They must also certify, based on their review and understanding, that the company has implemented a program meeting Attachment C and that the program is reasonably designed to detect and prevent anti-corruption violations throughout Scoular’s operations. That is not a promise that misconduct will never occur. No compliance program can guarantee that result.

It is a representation about design, implementation, coverage, and the quality of the reports submitted to the government. The signatories therefore need evidence that the program operates across the enterprise, including in high-risk markets and functions. The CCO may build and test much of that evidence, but the CCO does not sign Attachment F. The DPA places the final representation with the CEO and CLO.

Sections 1001 and 1519 Change the Sign-Off Process

Both certification forms state that they constitute material statements and representations for purposes of Section 1001 and records or documents for purposes of Section 1519. That language should create rigor, not panic. It does not mean an executive should refuse to sign because testing found exceptions. A credible program should find weaknesses. The question is whether the certification and supporting reports accurately describe the program, testing, findings, remediation, and remaining limitations.

The greater risk is a ceremonial sign-off supported by filtered information, unresolved contradictions, narrow testing, or undocumented assumptions. Scoular Company should treat certification as a process rather than an event. That process should include:

  1. A written certification standard tied to each representation in Attachments E and F;
  2. Sub-certifications from the leaders who own finance, compliance, legal, internal audit, investigations, human resources, procurement, and high-risk operations;
  3. A complete inventory of allegations, investigations, audit issues, control exceptions, remediation items, and DOJ commitments;
  4. Independent challenge of management’s evidence and closure decisions;
  5. Documented treatment of qualifications, unresolved matters, and contrary evidence; and
  6. Audit committee review before the executives sign.

Sub-certifications should support executive diligence without diluting executive responsibility. The purpose is to create a reliable chain of evidence from the operational control to the final signature.

The Board Must Oversee the Evidence

The board does not sign Attachments E or F. Its oversight role is nevertheless central. The board authorized the DPA, and Attachment C gives the anti-corruption function access to the board or an appropriate committee. The board should use that access to test whether management’s certification process is credible.

Directors should not ask only whether the company is on schedule. They should ask what evidence could prevent a certification, which findings remain open, whether management has limited the scope of testing, and whether compliance, legal, finance, and internal audit agree on the facts. This is also a Caremark-style oversight lesson. Board-level information systems must bring significant compliance risks and red flags to directors, particularly during a formal government resolution. A dashboard should not replace discussion of disputed findings, repeat issues, overdue remediation, or business resistance.

Is It Real or Is It Memorex

I acknowledge there is a contrary view of this which comes to us from my Compliance into the Weeds co-host, Matt Kelly. In a blog post entitled Scoular DPA Unveiled, Doesn’t Help, he questions why the company CCO is not required to certify the DPA. It could be, as Kelly writes, that “an agriculture supply business with 1,250 employees and $7.3 billion in revenue — even has a chief compliance officer; maybe it doesn’t, and the chief legal office also holds the CCO role.” He goes on to write, “Then again, if a company’s chief legal officer pulls double duty as the chief compliance officer too, and that’s why he or she is signing the certification — doesn’t that whole arrangement run contrary to the spirit of what the Justice Department wants to see for an empowered and autonomous compliance function?” He concludes by asking, “But if we’re now letting companies sign prosecution agreements where they commit to a strong, independent, empowered compliance function, except for the part that you don’t even have an actual chief compliance officer — then what are we even doing here, people?” [Emphasis supplied]

The Scoular Company website lists the Chief Legal Officer as Tim Manning, whose duties include leading “ Scoular’s legal team and serves as principal advisor on legal, risk, compliance, governance, and other matters to Scoular’s Senior Leadership Team and Board of Directors. He also has oversight of Scoular’s real estate function.” It appears the CCO and GC functions are wrapped into one person’s job description.

The Bottom Line on Accountability

We began this week’s blog post series with the admitted facts from the DPA: a payment process designed to prevent adverse customs decisions. It then examined the missed voluntary-disclosure window and a deep dive into how the use of data analytics and internal controls could have caught the FCPA violation. Today we end with the signatures. Scoular Company’s DPA demonstrates that executive accountability is not an abstract statement about culture. It is built through access, resources, incentives, discipline, third-party controls, data, testing, root-cause analysis, and complete reporting. The signature is not the beginning of accountability. It is the final confirmation that accountability has operated throughout the company, at least during the term of the DPA.