Categories
AI Today in 5

AI Today in 5: July 21, 2026, The ChatBot Love is in the Air Edition

Welcome to AI Today in 5, the newest addition to the Compliance Podcast Network. Each day, Tom Fox will bring you 5 stories about AI to start your day. Sit back, enjoy a cup of morning coffee, and listen in to AI Today In 5. All, from the Compliance Podcast Network. Each day, we consider five stories from the business world, compliance, ethics, risk management, leadership, or general interest about AI.

Top AI stories include:

  1. Digital supply chains and cybersecurity. (CySecurity News)
  2. Dating apps have an AI problem. (Bloomberg)
  3. AliExpress fined $629MM by EU. (WSJ)
  4. AI as catalyst for compliance innovation. (Law.com)
  5. Worrying about hallucinations. (FinTechGlobal)

For more information on the use of AI in compliance programs, Tom Fox’s new book, Upping Your Game, is available. You can purchase a copy of the book on ⁠Amazon.com⁠.

To learn about the intersection of Sherlock Holmes and the modern compliance professional, check out Tom’s latest book, The Game is Afoot-What Sherlock Holmes Teaches About Risk, Ethics and Investigations on ⁠Amazon.com⁠.

Categories
Innovation in Compliance

Innovation in Compliance: Governing AI Well Deepens Enterprise Risk Strategy

Welcome to the award-winning Innovation in Compliance. In this episode, Tom welcomes back Gerry Zack, and they discuss the growing use of AI in compliance and the launch of Eastward AI.

Gerry Zack brings a practical, cautionary perspective to AI-powered compliance and risk management, shaped by 18 months of advising organizations on how AI is being used in real compliance programs. He sees AI already embedded in functions like hotline support, policy-to-risk mapping, website scanning, behavioral analytics, transaction monitoring, and even parts of investigations, while warning against overreliance on it in sensitive investigative work. As one of the architects of Eastward AI, he helped evolve the platform from a CSRD and double-materiality tool into a flexible compliance and enterprise risk management solution that supports frameworks such as COSO ERM, DOJ guidelines, ISO 37301, and ISO 31000. Overall, Zack believes the real opportunity lies in reducing organizational paralysis, using AI responsibly, and connecting compliance more closely with HR, IT, and other risk functions to strengthen leadership and decision-making.

Resources:

Gerry Zack on LinkedIn

RiskTrek

Eastward AI

Tom Fox

Instagram

Facebook

YouTube

Twitter

LinkedIn

Categories
Daily Compliance News

Daily Compliance News: July 21, 2026, The Merger Paused Edition

Welcome to the Daily Compliance News. Each day, Tom Fox, the Voice of Compliance, brings you compliance-related stories to start your day. Sit back, enjoy a cup of morning coffee, and listen in to the Daily Compliance News. All, from the Compliance Podcast Network. Each day, we consider four stories from the business world, compliance, ethics, risk management, leadership, or general interest for the compliance professional.

Top stories include:

  • Judge pauses Paramount/Warner Bros merger.  (NYT)
  • Digital supply chains and cybersecurity. (CySecurity News)
  • AliExpress fined $629MM by EU. (WSJ)
  • Indonesia losing the fight against corruption. (Bloomberg)

To learn about the intersection of Sherlock Holmes and the modern compliance professional, check out Tom’s latest book, The Game is Afoot-What Sherlock Holmes Teaches About Risk, Ethics and Investigations on Amazon.com.

Categories
Red Flags Rising

Red Flags Rising: S01 E42: The De Minimis Rule and the Challenge of “Weathervane” Regulatory Language

Mike and Brent tackle the “de minimis” rule under the U.S. Export Administration Regulations (EAR), which would exempt certain below-threshold-value U.S. items from EAR requirements. Three recent enforcement actions, all in 2026 and collectively imposing just under $300 million in penalties, underscore the perils of potentially misapplying the rule. Mike and Brent introduce the concept of “weathervane” regulatory language that can sway with the geopolitical and enforcement winds (2:59); the potential relevance of companies’ approaches to transfer pricing and country-of-origin (4:40); the relevance of old-fashioned arithmetic to identifying common numerator and denominator pitfalls (9:10); the recent enforcement action that included an unusually lengthy exposition by the U.S. Bureau of Industry & Security (BIS) of its interpretation of the de minimis rule (15:38); and the parallels to BIS’s rediscovery of the “high probability” standard (18:56). Mike and Brent conclude with the latest installment of Brent Carlson’s “Managing Up” segment (24:41).

BIS “Guidelines for De Minimis Rules”

Contact Brent: brent@redflagsrising.com

More about Brent: www.redflagsrising.com/founder

Connect with Brent on LinkedIn

Contact Mike: michael.huneke@morganlewis.com

More about Mike

Connect with Mike on LinkedIn

The enforcement actions can all be found at www.bis.gov

Categories
Blog

Nothing Crosses the Border: Scoular and the New Compliance Burden for Mexico Supply Chains

“Nothing crosses into or out of Mexico without the approval and payment to Mexican drug cartels. American businesses that engage in any cross-border trade bear a significant amount of responsibility to do so without benefitting those cartels and without threatening our national security,” said U.S. Attorney Justin R. Simmons for the Western District of Texas. “The bribery scheme in which the Scoular Company engaged demonstrates the dangerous corporate corruption we in the Western District of Texas are committed to fighting on behalf of the American people.”

This is not a quote from The Onion, but it is an extraordinary statement from a United States Attorney. It is not confined to companies that knowingly pay cartels. It is not limited to businesses operating in cartel-controlled industries. It speaks broadly to American companies engaged in cross-border trade with Mexico.

The statement appeared in the Department of Justice’s Press Release announcing that The Scoular Company would pay more than $10 million to resolve an FCPA investigation involving payments to Mexican officials. According to the DOJ, customs brokers paid approximately $2,000 per train to allow shipments of corn and other products to cross the border despite inspections identifying dirt, soil, and other impurities. The payments were invoiced back to Scoular as “reinspection fees.” The enforcement message extends far beyond Scoular. Every U.S. company importing goods from Mexico should take notice.

Cartels and the UFLPA

One of the few laws that demands such an approach is the Uyghur Forced Labor Prevention Act (UFLPA), which targets goods made, whole or in part, by forced labor in the Xinjiang region of China or made by forced labor in other parts of China by Uighurs or other minorities. It is designed to operate as a de facto trade ban on goods from China’s Jing Jang region. US businesses will face a heavy burden to overcome the presumption of forced labor. It is perhaps the most significant US law addressing forced labor, and it has the most tangible repercussions companies can face. Under the UFLPA, the key is your documentation for US Customs and Border Protection. Travis Miller has noted that this means if you are “asking companies to look back into where the actual sand came from that got turned into the silica, that got turned into the semiconductor, that got turned into the circuit board, that got turned into the device that finds its way into your laptop. There’s just never been anything like it.”

The UFLPA and its guidance weave together existing business processes. The UFLPA emerged from the America Supply Chain Executive Order in the US/China trade war, which focused on semiconductors, critical raw materials, and elements that are the subject of the extractives. To comply with it, you could not actually start unless you already had a product compliance program in place. This means that if you do not know the bill of materials, do not have an approved vendor list, or do not know where your components are manufactured, you cannot prove compliance. This may well be the approach the Trump Administration takes under FTOs in Mexico and other locations in Central and Latin America.

Is Every Cross-Border Company Benefiting a Cartel?

In my podcast discussion with Matt Ellis, Latin America Practice Lead at Miller & Chevalier, Ellis challenged the literal breadth of the government’s statement. He noted that companies move legitimate goods between the United States and Mexico every hour without knowingly benefiting drug cartels. It would be inaccurate to conclude that every cross-border transaction involves a cartel payment.

Nevertheless, Ellis called the statement striking. He raised the question every CCO should now be considering: Is the DOJ establishing a new compliance standard for companies doing business across the U.S.-Mexico border? The statement does not create a new statute, regulation, or formal presumption of liability. Yet prosecutorial statements communicate enforcement expectations. Here, the expectation appears to be that American businesses must understand not only who their immediate third parties are, but also whether their supply chain activities could provide economic benefits to organized crime.

That puts pressure on importers in three ways. First, companies may face greater scrutiny over customs brokers, logistics providers, trucking companies, warehouses, security providers, labor organizations, and other parties supporting Mexican operations. Second, companies may be expected to investigate the downstream destination of payments, even when there is no obvious cartel connection. Third, the government may examine whether compliance programs integrate anti-corruption controls with sanctions, anti-money laundering, trade compliance, supply chain security, and organized-crime risk.

The question will no longer be limited to whether the company intended to pay a bribe. Prosecutors may also ask whether the company reasonably understood the environment in which its money and goods were moving.

Traditional Third-Party Due Diligence May Not Be Enough

Ellis made one of the most important observations of our discussion: standard third-party screening may not identify cartel connections. Conventional anti-corruption due diligence focuses heavily on government-facing intermediaries. Companies screen owners and principals, search adverse media, identify politically exposed persons, review government relationships, obtain certifications, and include anti-corruption language in contracts. Those measures remain necessary. They may not be sufficient for organized-crime risk.

Cartel affiliations are rarely disclosed in a corporate registry. A logistics provider may appear legitimate while making payment for protection. A trucking company may operate in a region controlled by a criminal organization. A supplier may use subcontractors with undisclosed local connections. A customer, warehouse, labor group, or security provider may be vulnerable to criminal infiltration.

This means companies should broaden the universe of third parties subject to risk-based review. For Mexican supply chains, that universe may include:

  • Suppliers
  • Customers
  • Customs brokers
  • Freight forwarders
  • Trucking companies
  • Warehouses
  • Security companies
  • Local consultants
  • Port and terminal service providers
  • Labor contractors
  • Union representatives
  • Subcontractors
  • Last-mile transportation providers

The legal requirement to use a licensed customs broker should not reduce scrutiny. As Ellis noted, mandatory licensing can sometimes create a false sense of security. A government license does not replace a company’s responsibility to understand how the broker operates.

Contextual Due Diligence Becomes Essential

If database screening cannot reliably identify cartel connections, companies need a contextual approach. This begins by examining where the third party will operate and what criminal activity is associated with that region. Relevant questions include:

  • Is the location known for cartel activity?
  • Are particular highways or transportation corridors subject to roadblocks or protection payments?
  • Is the region associated with fentanyl production, human trafficking, fuel theft, cargo theft, or smuggling?
  • Are unusual labor or union arrangements present?
  • Does the vendor use subcontractors that have not been disclosed?
  • Are payment requests made in cash or to unrelated accounts?
  • Is the third party reluctant to explain its security or transportation arrangements?
  • Does the third party promise an unrealistic customs clearance rate?
  • Are employees instructed not to ask questions about local payments?

Companies must also listen to their employees on the ground. Local personnel may understand risks that do not appear in formal databases. They know the regional rumors, transportation practices, local power structures, and third parties that other companies avoid.

This presents another compliance challenge. Local employees may fear retaliation if they report suspected cartel connections. A company’s speak-up system must provide credible confidentiality, escalation, and protection measures. A hotline is not enough if employees believe that raising a concern will endanger them or their families.

The New Standard Is Demonstrable Reasonableness

Companies cannot guarantee that no peso in a complex Mexican supply chain will ever reach a cartel-affiliated person. Prosecutors should not expect the impossible. They can expect companies to identify their risks, conduct reasonable diligence, monitor high-risk transactions, respond to warning signs, preserve relevant communications, and improve controls when new information emerges.

That is the pressure created by the Scoular resolution. Companies must be able to demonstrate that they made a serious, documented, and risk-based effort to prevent their operations from benefiting criminal organizations. The compliance burden is moving from a narrow inquiry into government-facing intermediaries toward a broader examination of the entire supply chain ecosystem.

Actions for CCOs

CCOs should consider five immediate steps:

  1. Expand Mexico-related risk assessments beyond traditional FCPA intermediaries.
  2. Map the complete supply chain, including subcontractors and transportation routes.
  3. Test customs-broker invoices and recurring border-related payments.
  4. Incorporate regional cartel intelligence and local employee knowledge into due diligence.
  5. Brief the board on the convergence of corruption, sanctions, organized crime, and national security risk.

The Scoular resolution does not establish that every company importing goods from Mexico is paying a cartel. It does put every such company on notice that the DOJ may ask what it did to make sure it was not. That is a significant change in compliance expectations. But look to your response to the UFLPA and see if you can find guidance from that compliance issue. Regardless, companies need to respond accordingly.

Categories
AI Today in 5

AI Today in 5: July 20, 2026, The AI Making Job Harder Edition

Welcome to AI Today in 5, the newest addition to the Compliance Podcast Network. Each day, Tom Fox will bring you 5 stories about AI to start your day. Sit back, enjoy a cup of morning coffee, and listen in to AI Today In 5. All, from the Compliance Podcast Network. Each day, we consider five stories from the business world, compliance, ethics, risk management, leadership, or general interest about AI.

Top AI stories include:

  1. NY state bills could create AI compliance obligations. (The National Law Review)
  2. GRC professionals say AI makes their jobs harder. (CCI)
  3. AI for tighter supply chain compliance. (SupplyChainDive)
  4. Pastors using AI to write sermons. (WSJ)
  5. Compliance as a commercial lever. (FinTechGlobal)

For more information on the use of AI in compliance programs, Tom Fox’s new book, Upping Your Game, is available. You can purchase a copy of the book on ⁠Amazon.com⁠.

To learn about the intersection of Sherlock Holmes and the modern compliance professional, check out Tom’s latest book, The Game is Afoot-What Sherlock Holmes Teaches About Risk, Ethics and Investigations on ⁠Amazon.com⁠.

Categories
FCPA Compliance Report

FCPA Compliance Report: The Scoular FCPA Enforcement Action: Customs Bribes, Cartel Links, and New Compliance Expectations

Welcome to the award-winning FCPA Compliance Report, the longest-running podcast in compliance. In this episode, Tom welcomes back Matt Ellis to discuss a newly announced FCPA enforcement action involving Scoular Company.

The case invoiced about $400,000 in payments labeled as “reinspection fees” to Mexican customs and food inspectors to move agricultural goods across the Mexico–U.S. border. border, allegedly generating over $6.5 million in avoided costs and raising concerns about cartel-linked beneficiaries. They discuss why customs and customs brokers are recurring high-risk areas in Mexico, how long-running employee involvement suggests broader controls and tone-from-the-top failures, and why these payments are not facilitation payments under Mexican law and given discretionary official acts. Ellis emphasizes analytics on customs documents and broker invoices, stronger third-party diligence beyond traditional screening to address cartel/TCO risks, and defensible governance for WhatsApp/off-channel communications. Despite no voluntary self-disclosure, the company received cooperation credit and a 25% fine reduction, and Ellis previews an ACI conference focused on cartels, TCOs, and compliance in Latin America.

Key highlights:

  • Border Bribes and Safety Risks
  • Controls Failures and Monitoring
  • Data Analytics Red Flags
  • Facilitation Payment Myth
  • DOJ Cartel Warning and Implications
  • Rethinking Due Diligence for Cartels
  • WhatsApp and Messaging Governance
  • Cooperation, Credit, and Remediation

Resources:

Cartels, TCOs and Compliance in Latin America, July 20-21

Matt Ellis on LinkedIn

Tom Fox

Instagram

Facebook

YouTube

Twitter

LinkedIn

The FCPA Compliance Report was recently named the world’s best business ethics podcast by FeedSpot.

Categories
Daily Compliance News

Daily Compliance News: July 20, 2026, The Farewell to the World Cup Edition

Welcome to the Daily Compliance News. Each day, Tom Fox, the Voice of Compliance, brings you compliance-related stories to start your day. Sit back, enjoy a cup of morning coffee, and listen in to the Daily Compliance News. All, from the Compliance Podcast Network. Each day, we consider four stories from the business world, compliance, ethics, risk management, leadership, or general interest for the compliance professional.

Top stories include:

  • FT hands out its awards for the best and worst of the 2026 World Cup. (FT)
  • China Development Bank President under investigation for corruption. (AP News)
  • DOJ pulling back on white-collar crime enforcement. (WSJ)
  • Scoular pays a $10MM fine for FCPA violations. (Rural Radio)

To learn about the intersection of Sherlock Holmes and the modern compliance professional, check out Tom’s latest book, The Game is Afoot-What Sherlock Holmes Teaches About Risk, Ethics and Investigations on Amazon.com.

Categories
Trekking Through Compliance

Trekking Through Compliance: Episode 50 – Ethics Lessons from ‘Patterns of Force’ for the Modern Compliance Professional

One of the defining strengths of Star Trek: The Original Series (TOS) is its willingness to confront the thorniest questions of morality, leadership, and power. Few episodes tackle these issues as directly or as provocatively as “Patterns of Force.” For compliance professionals, “Patterns of Force” offers a cautionary tale about the dangers of compromising ethical principles, even for seemingly pragmatic reasons. The story serves as a powerful reminder that organizations cannot pursue “efficiency” or “success” at the expense of their core values. The lessons are as relevant for today’s boardrooms and C-suites as they are for starships in the 23rd century.

Lesson 1: The Danger of Ethical Shortcuts—The Ends Never Justify the Means

Illustrated by: John Gill, the Federation historian, justifies the creation of a Nazi-like regime on Ekos by arguing that it is the “most efficient state Earth ever knew.”

Compliance Lesson: One of the oldest ethical traps is believing that good intentions justify unethical means. John Gill’s fatal error is to separate efficiency from morality, imagining that a “system” can be controlled and its inherent evils contained.

Lesson 2: Leadership Responsibility—Ethics Must Flow from the Top

Illustrated by: Throughout the episode, the regime’s horror is magnified by the passivity and silence of John Gill, who, under the manipulation of his subordinate Melakon, allows atrocities to proceed. Gill’s abdication of responsibility is a direct contributor to the disaster.

Compliance Lesson: Tone at the top is not a cliché; it is a living, breathing necessity. Leaders who abdicate their ethical responsibilities or look the other way empower bad actors and create environments where misconduct flourishes.

Lesson 3: Unintended Consequences—Control Over Ethical Outcomes is an Illusion

Illustrated by: Gill’s initial plan is to use the Nazi system “without the hate.” But he is quickly manipulated by Melakon, who exploits the machinery of power for his ends.

Compliance Lesson: Rationalizing minor code of conduct violations or tolerating small acts of corruption can quickly escalate beyond your ability to contain them.

Lesson 4: The Importance of Speaking Up—Silence Enables Unethical Behavior

Illustrated by: On Ekos, many citizens and officials are complicit in the regime’s crimes, not through malice but through silence and inaction.

Compliance Lesson: A culture of silence is fertile ground for ethical misconduct. If employees feel they cannot speak up or if whistleblowers are punished or ignored, misconduct becomes normalized.

Lesson 5: Vigilance Against Ethical Blind Spots—History Repeats if We Forget

Illustrated by: The episode closes with a pointed warning that “the price of liberty is eternal vigilance.”

Compliance Lesson: Patterns of Force” reminds us that even the best intentions can lead to disaster if we forget the lessons of the past.

Final ComplianceLog Reflections

Patterns of Force” remains a chilling, relevant parable for compliance professionals. It warns us that even the noblest intentions can go awry when ethical principles are sacrificed for expedience or efficiency. The lessons are clear. As compliance officers, our mission is to ensure that our organizations stay true to their core values, never allowing expediency, pressure, or misguided reasoning to compromise our ethical bearings. In the words of Captain Kirk, “The first duty of every Starfleet officer is to the truth.” For us, the first duty of every compliance professional is to ethics, no matter the circumstances.

Resources:

Excruciatingly Detailed Plot Summary by Eric W. Weisstein

MissionLogPodcast.com

Memory Alpha

Categories
Blog

Scoular’s $10 Million FCPA Resolution: When a “Re-inspection Fee” Becomes a Bribe

A $2,000 payment can look insignificant inside a global supply chain. Repeated train by train, approved by employees, routed through customs brokers, disguised on invoices, and paid for six years, it becomes something else entirely. For The Scoular Company, it became a Foreign Corrupt Practices Act enforcement action carrying more than $10 million in penalties and forfeiture, a three-year deferred prosecution agreement, continuing cooperation obligations, and periodic reporting to the Department of Justice.

The case is an important warning for every company engaged in cross-border trade. Customs brokers are not merely logistics providers. Border payments are not merely operational expenses. A mislabeled invoice is not merely an accounting problem. Each may represent an interconnected risk across anti-corruption, internal control, third-party, and national security.

The Scheme: $2,000 per Train

According to the DOJ Press Release (the full DPA is not yet available), between 2013 and 2019, Scoular used customs brokers to move shipments of corn and other agricultural products from the United States to Mexico. Mexican authorities inspected those shipments for dirt, soil, and other impurities. When inspectors identified problems, Scoular’s customs brokers allegedly paid Mexican officials approximately $2,000 per train to ensure that the shipments crossed the border.

The brokers then invoiced those payments back to Scoular as “reinspection fees.” Scoular paid the invoices. This was not an isolated facilitation payment or a rogue third party operating beyond the company’s knowledge. According to the court documents, Scoular employees authorized the payments, directed the brokers, and communicated about the shipments and bribes through WhatsApp and other channels.

The numbers demonstrate the business impact:

  • More than $400,000 in bribes authorized
  • More than $6.5 million in avoided fees and costs
  • A $9,769,521 criminal penalty
  • $414,351 in forfeiture
  • A three-year DPA

The company was charged with conspiracy to violate the FCPA’s anti-bribery provisions.

The Invoice Description Was a Compliance Red Flag

The phrase “reinspection fee” should be at the center of every compliance discussion about this case. The brokers did not invoice Scoular for bribes. They used a description that appeared facially connected to a legitimate customs process. That description allowed the payments to move through the company’s financial system.

This is how corruption frequently enters the books and records. It appears as:

  • Expediting fees
  • Administrative charges
  • Local processing costs
  • Customs support
  • Special handling
  • Reinspection fees
  • Consulting services

The compliance question is not whether the description sounds legitimate. The question is whether the company can establish what service was performed, who performed it, why the payment was necessary, how the amount was calculated, and who ultimately received the money. Accounts payable controls that merely match an invoice to a purchase order will not detect this type of scheme. Effective controls must examine the commercial substance of high-risk payments.

For customs-related expenses, companies should require supporting government documentation, published fee schedules, proof of service, payment to an authorized government account where appropriate, and enhanced approval for unusual or recurring charges.

Third-Party Due Diligence Is Only the Beginning

The Scoular resolution also demonstrates the limits of onboarding due diligence. A company can screen a customs broker, obtain certifications, execute an anti-corruption clause, and still face substantial FCPA exposure. The real question is what happens after the third party begins work. The answer is that the real work of compliance begins when the third-party contract is signed.

Customs brokers operate at the intersection of government interaction, time-sensitive business demands, discretionary enforcement, and local pressure. That makes them inherently high risk. An effective third-party management program should connect the following:

  • Initial due diligence
  • Contractual controls
  • Transaction monitoring
  • Invoice testing
  • Business justification
  • Periodic recertification
  • Audit rights
  • Compliance training
  • Offboarding decisions

The DOJ credited Scoular for strengthening risk-based screening and approval requirements, adding anti-corruption and audit-right provisions to contracts, and improving monitoring procedures. The company also eliminated customs brokers associated with the Mexican reinspection payments. Due diligence is not and cannot remain a static file. It must become a continuing control system tied to actual payments and operational conduct.

WhatsApp Was Part of the Business Process

Scoular employees allegedly communicated about the shipments and payments through WhatsApp and other channels. This fact should concern every CCO. When employees use personal devices or ephemeral messaging platforms to conduct high-risk business, the company may lose visibility into precisely the communications it most needs to monitor, preserve, and produce.

The answer is not necessarily to prohibit every messaging application. The answer is to establish a defensible governance model addressing the following:

  • Permitted communication platforms
  • Business-record retention
  • Preservation during investigations
  • Access to relevant communications
  • Training for high-risk employees
  • Monitoring based on legal and privacy requirements
  • Consequences for circumventing approved systems

A policy without technical controls, employee training, and consistent enforcement is unlikely to satisfy prosecutors. Messaging governance must reflect how employees actually conduct business.

Corruption Is Now a National Security Issue

The most significant feature of the case may be the DOJ’s treatment of cartel risk. The government determined that a portion of the bribe payments ultimately benefited individuals associated with a cartel operating at the U.S.-Mexico border. The DOJ stated that neither Scoular nor its employees knew about that connection. That lack of knowledge did not eliminate the seriousness of the issue.

Indeed, in the DOJ Press Release, U.S. Attorney Justin R. Simmons for the Western District of Texas was quoted as follows, “Nothing crosses into or out of Mexico without the approval and payment to Mexican drug cartels.” Further, any American businesses that engage in any cross-border trade bear a significant amount of responsibility to do so without benefitting those cartels and without threatening our national security.”

The enforcement message is clear: companies operating in high-risk border regions must consider where third-party payments may ultimately flow. A payment intended to resolve a customs problem can expose a party to corruption, money laundering, sanctions, organized crime, and national security risks. This means anti-corruption risk assessments can no longer operate in isolation. Compliance teams should integrate information from the following:

  • Anti-money laundering reviews
  • Sanctions screening
  • Security functions
  • Trade compliance
  • Supply chain risk management
  • Third-party intelligence
  • Government investigations
  • Adverse media monitoring

The government is examining the complete risk created by a payment, not merely the employee’s immediate objective.

No Voluntary Disclosure Credit, but Meaningful Cooperation Credit

Scoular did not receive voluntary self-disclosure credit because it did not promptly report the conduct to the DOJ Fraud Section. It did, however, receive credit for cooperation. The DOJ cited Scoular’s internal investigation, factual presentations, identification of individuals involved, document production, organization of evidence, and provision of counsel for current employees. The DOJ also acknowledged deficiencies during the early stages of the investigation.

After considering the company’s cooperation and remediation, the DOJ imposed a criminal penalty reflecting a 25 percent reduction from the bottom of the applicable sentencing guidelines range. This is a valuable lesson in enforcement mathematics. Missing the opportunity for voluntary disclosure does not make subsequent cooperation irrelevant. Companies can still improve outcomes through credible investigation, evidence preservation, individual accountability, timely remediation, and the organized production of information.

Yet cooperation credit is not the equivalent of voluntary disclosure credit. The decision window following discovery of potential misconduct remains critical.

Remediation Must Change the Operating Model

Scoular’s remediation went beyond issuing a new policy. According to the DOJ, the company:

  • Conducted an external compliance maturity assessment and anti-corruption risk assessment
  • Restructured its compliance function
  • Increased senior leadership oversight
  • Eliminated brokers connected to the payments
  • Strengthened risk-based monitoring through software tools
  • Revised its Code of Conduct and key compliance policies
  • Improved third-party screening and approvals
  • Added anti-corruption and audit-rights provisions
  • Revised financial controls for high-risk transactions
  • Delivered general and targeted anti-corruption training

This is the type of remediation contemplated by the DOJ’s Evaluation of Corporate Compliance Programs. It addresses root causes, resources, governance, controls, technology, training, and business ownership.

The key is operational impact. The company must be able to demonstrate that the same conduct could not pass through the organization today without being detected or escalated.

Questions for CCOs

CCOs should ask:

  • Do recurring payments cluster around specific ports, brokers, officials, products, or inspection events?
  • Are vague payment descriptions automatically escalated?
  • Does compliance have access to customs, logistics, and accounts payable data?
  • Are high-risk brokers periodically reviewed after onboarding?
  • Has the company tested whether audit rights can actually be exercised?
  • Is there a rapid escalation process for deciding whether potential misconduct should be voluntarily disclosed?

The Bottom Line

The Scoular case was not simply about customs brokers paying officials. It was about an operational process that allegedly normalized bribery, an invoicing system that disguised the payments, employees who communicated through informal channels, and third-party funds that ultimately touched cartel-linked actors.

For compliance professionals, the lesson is direct: follow the payment, test the business justification, examine the communication channel, and understand the complete risk ecosystem. A $2,000 “reinspection fee” may be small enough to escape executive attention. It is not small enough to escape the FCPA.