Categories
Blog

What Gary Seven and Assignment Earth Teach Us About Due Diligence

If there is one constant in the universe, it is that business, regulations, and politics never stand still. Each new venture, partnership, or acquisition brings a fresh set of risks, obligations, and opportunities. Yet too often, organizations approach due diligence as a box-checking exercise when, in truth, it is the essential safeguard that ensures they are not letting an unknown variable derail their mission. Nowhere is this more cleverly dramatized than in the Star Trek TOS episode “Assignment: Earth,” where the Enterprise crew finds themselves conducting the ultimate form of due diligence, investigating the mysterious Gary Seven and the true risks he poses to Earth’s future.

With its spy-fi trappings, high-stakes secrets, and moral ambiguity, “Assignment: Earth” is a goldmine for compliance professionals seeking fresh insights into what robust due diligence truly requires. Today, we beam down and explore five timeless lessons from this episode, each rooted in a scene that every compliance leader should remember the next time a critical business decision looms.

Lesson 1: Verify Identity—Trust, But Always Confirm

Illustrated by: When Gary Seven appears on the Enterprise, he claims to be a human agent from the future, sent to prevent Earth’s destruction. His credentials, demeanor, and even physiology confound the crew. Spock’s scans confirm some aspects, but other elements remain mysterious. Kirk is forced to weigh trust against hard evidence, deciding that until Seven’s story is verified, he must remain under close observation.

Compliance Lesson: In every business deal, knowing exactly who you are dealing with is non-negotiable. Vendors, acquisition targets, third-party agents, and partners each have their own backgrounds and histories. “Assignment: Earth” illustrates the risks of acting on assumptions or charm; as the Enterprise crew learns, even the most convincing story requires verification. For compliance teams, this means robust onboarding processes, identity verification, and background checks not only at the outset but throughout the relationship. Trust is good; verification is better.

What should you do? Deploy enhanced due diligence for high-risk or high-impact relationships. Use independent sources, cross-check credentials, and don’t hesitate to pause the process if any red flags arise.

Lesson 2: Investigate the Full Scope—Understand Intent, Capability, and History

Illustrated by: The crew’s investigation into Gary Seven doesn’t stop with his identity. They probe his capabilities, his advanced technology, his mysterious “servo,” and the highly sophisticated computer at his headquarters. Spock and Kirk ask probing questions about Seven’s mission, intent, and track record.

Compliance Lesson: Surface-level information often fails to reveal the entire story. In business, a potential partner’s capabilities and intent matter as much as their identity. Due diligence is not just about who someone is, but also what they are capable of and what they plan to do with that capability. A company’s operational strengths, compliance record, and ethical history all inform future risk. Teams must go beyond public filings and financials. Look for operational gaps, management weaknesses, and track records of regulatory engagement. Just as Kirk and Spock dig into Gary Seven’s motives and methods, compliance officers should investigate all relevant dimensions.

What should you do? Expand your checklist: evaluate litigation history, regulatory fines, press coverage, key executive backgrounds, and past compliance breaches. Interview multiple stakeholders to triangulate intent.

Lesson 3: Control Information—Monitor and Secure Sensitive Data

Illustrated by: Much of “Assignment: Earth” revolves around the management of sensitive information. Seven’s computer contains data that could alter the fate of the planet. Both Seven and the Enterprise crew are vigilant about access, using encryption, voice authentication, and physical security to ensure information is only available to those with a legitimate need.

Compliance Lesson: Whether you are acquiring a company or onboarding a supplier, data security is central to modern due diligence. The risks of data leaks, cyberattacks, or inadvertent disclosure can be devastating, especially if sensitive deal information falls into the wrong hands. Therefore, it is crucial to monitor who has access to key data during the diligence phase. Implement robust information barriers and control access to confidential material. Make cybersecurity a core part of your diligence process.

What should you do? Require non-disclosure agreements from all parties. Use secure data rooms and audit access logs. Include cybersecurity posture and data protection history in every due diligence report.

Lesson 4: Expect the Unexpected—Adapt When New Risks Emerge

Illustrated by: Kirk and Spock’s plan to detain Gary Seven is upended when he escapes and races to sabotage a nuclear missile test that could ignite World War III. The crew must adapt instantly, using every tool and resource at their disposal to prevent disaster, even as their understanding of the mission’s stakes evolves in real time.

Compliance Lesson: Due diligence is not a static process. The best-laid plans are often disrupted by new information, sudden market fluctuations, or the revelation of previously unknown risks. Teams must be nimble, ready to reassess, escalate, and change course as new facts emerge. Establish protocols for escalating concerns and adjusting timelines when red flags appear. Build flexibility into your diligence process; sometimes, a deal should slow down or even pause while serious concerns are addressed.

What should you do? Schedule interim reviews, not just final sign-offs. Empower team members to call for additional investigation when new risks emerge, and document all changes to scope and focus.

Lesson 5: Assess Impact and Alignment—Consider the Broader Consequences

Illustrated by: As the story unfolds, the crew realizes that Gary Seven’s actions, though seemingly dangerous, are intended to prevent an even greater catastrophe. Kirk must weigh the consequences of intervening or not, understanding that the impact goes beyond the immediate crisis and could shape the entire future of humanity.

Compliance Lesson: Effective due diligence requires looking beyond the transaction itself. Will this deal, partnership, or acquisition align with your company’s mission, values, and long-term strategy? What are the potential downstream consequences? Does the opportunity support or threaten your compliance culture? Kirk’s willingness to consider the broader impact rather than just “following the rules” mirrors the best compliance thinking. Evaluate not just the legal and financial implications, but the reputational, cultural, and strategic impacts as well.

What should you do? Be sure to include cultural fit, values alignment, and long-term strategy in your final diligence reports. Consult with leadership about potential impacts, positive and negative, before greenlighting a deal.

Final ComplianceLog Reflections

Assignment: Earth” might masquerade as a playful, spy-themed episode, but at its heart it is a meditation on trust, investigation, and the unpredictability of risk. For compliance professionals, its lessons ring true across the decades. Due diligence is not a one-time task, nor is it a matter of simply collecting signatures and ticking boxes. It is an ongoing, multi-dimensional practice rooted in skepticism, curiosity, and a willingness to adapt.

In today’s business environment, the threats and opportunities you face are more complex than ever. The partners, acquisitions, and investments you pursue all come with hidden variables. Like Kirk and his crew, your mission is to look deeper, ask more challenging questions, protect sensitive information, and never lose sight of the broader impact your decisions have on the world.

The next time your organization faces a pivotal deal or partnership, remember the spirit of “Assignment: Earth” and conduct your due diligence with the rigor, flexibility, and ethical perspective that the future demands.

Resources:

Excruciatingly Detailed Plot Summary by Eric W. Weisstein

MissionLogPodcast.com

Memory Alpha

Categories
Trekking Through Compliance

Trekking Through Compliance: Episode 54 – Beneath the Surface: Uncovering M&A Risk with Guidance from ‘Bread and Circuses’

If there is one area in business where risk, opportunity, and culture collide, it is in mergers and acquisitions. The promise of new markets, talent, and technology is always balanced against the possibility of hidden liabilities, clashing values, and operational chaos. In the world of corporate compliance, no moment is more perilous or more revealing than when companies come together.

Star Trek: The Original Series’ episode “Bread and Circuses” offers an unlikely but fitting parable for M&A compliance professionals. Here are five key compliance-related M&A due diligence lessons from “Bread and Circuses.”

Lesson 1: Go Beyond Surface Appearances—Assess the True Culture

Illustrated by: On the planet 892-IV, Kirk and his landing party discover an authoritarian state built on forced entertainment and oppression.

Compliance M&A Lesson: It is easy to be seduced by a target company’s top-line numbers, glossy facilities, and impressive management presentations. However, proper due diligence requires a thorough examination beneath the surface.

Lesson 2: Identify Hidden Liabilities—Don’t Ignore the Risks Beneath the Entertainment

Illustrated by: The population of 892-IV, which is kept docile through violent gladiatorial games that serve as literal bread and circuses.

Compliance M&A Lesson: Effective due diligence involves identifying these concealed dangers. Compliance professionals must review litigation histories, regulatory filings, and environmental and safety records, as well as ongoing investigations and audits, to ensure compliance.

Lesson 3: Map Third-Party and Supply Chain Risks—Everyone in the Arena Matters

Illustrated by: Kirk discovers that the planet’s leader, Merikus, is a missing Starfleet captain who has chosen to assimilate rather than resist.

Compliance M&A Lesson: No company operates in isolation. A target company’s third-party relationships, joint ventures, and supply chains can be sources of immense risk; think FCPA, anti-bribery, human rights violations, or simply the risk of operational disruption.

Lesson 4: Understand Local Laws, Customs, and Power Structures—Context Is Everything

Illustrated by: Spock and McCoy are baffled by the local laws and power dynamics.

Compliance M&A Lesson: Every M&A deal is shaped by its legal, regulatory, and cultural context. Don’t assume what works in your home country will transfer easily.

Lesson 5: Don’t Underestimate the Human Element—Values and Ethics Matter

Illustrated by: Throughout the episode, it is the values and resolve of the Enterprise crew and the oppressed “Children of the Sun” that make resistance to tyranny possible. The episode ends not with a technical solution, but with an ethical stand.

Compliance M&A Lesson: Values alignment is not just a “soft” factor; it’s a predictor of post-merger success and resilience in a crisis.

Final ComplianceLog Reflections

Bread and Circuses” is more than just a classic science fiction adventure. It is a powerful parable for today’s compliance professional navigating the high-stakes world of mergers and acquisitions. For compliance officers, the episode’s narrative reinforces that adequate due diligence must go far beyond the numbers and surface-level impressions. It requires a holistic investigation into the culture, values, and relationships that truly define an organization. The success or failure of a merger often hinges on the ability to identify hidden liabilities, assess third-party and supply chain risks, and deeply understand the legal and regulatory landscape unique to each deal.

Resources:

Excruciatingly Detailed Plot Summary by Eric W. Weisstein

MissionLogPodcast.com

Memory Alpha

Categories
Daily Compliance News

Daily Compliance News: July 24, 2026, The All WSJ Edition

Welcome to the Daily Compliance News. Each day, Tom Fox, the Voice of Compliance, brings you compliance-related stories to start your day. Sit back, enjoy a cup of morning coffee, and listen in to the Daily Compliance News. All from the Compliance Podcast Network. Each day, we consider four stories from the business world, compliance, ethics, risk management, leadership, or general interest for the compliance professional.

Top stories include:

  • New IRS boss spied on co-workers at JPMorgan. (WSJ)
  • Google says AI is helping workers, not replacing them. (WSJ)
  • EU fines Google $1bn. (WSJ)
  • Lloyd’s says former CEO was too cozy with a subordinate. (WSJ)

To learn about the intersection of Sherlock Holmes and the modern compliance professional, check out Tom’s latest book, The Game is Afoot-What Sherlock Holmes Teaches About Risk, Ethics and Investigations on Amazon.com.

Categories
AI Today in 5

AI Today in 5: July 24, 2026, The It’s All About the Data Edition

Welcome to AI Today in 5, the newest addition to the Compliance Podcast Network. Each day, Tom Fox will bring you 5 stories about AI to start your day. Sit back, enjoy a cup of morning coffee, and listen in to AI Today in 5. All from the Compliance Podcast Network. Each day, we consider five stories from the business world, compliance, ethics, risk management, leadership, or general interest about AI.

Top AI stories include:

  1. Google says AI is helping workers. (WSJ)
  2. AI confidence outpaces adoption. (HealthCareFinance)
  3. AI is only as smart as the data. (Forbes)
  4. AI capture is the foundation of compliance. (UCToday)
  5. AI compliance failures could cost dearly. (FinTechGlobal)

For more information on the use of AI in compliance programs, Tom Fox’s new book, Upping Your Game, is available. You can purchase a copy of the book on ⁠Amazon.com⁠.

To learn about the intersection of Sherlock Holmes and the modern compliance professional, check out Tom’s latest book, The Game is Afoot-What Sherlock Holmes Teaches About Risk, Ethics and Investigations on ⁠Amazon.com⁠.

Categories
Blog

Beyond the Arena: M&A Due Diligence Lessons from Star Trek’s ‘Bread and Circuses’

If there is one area in business where risk, opportunity, and culture collide, it is in mergers and acquisitions. The promise of new markets, talent, and technology is always balanced against the possibility of hidden liabilities, clashing values, and operational chaos. In the world of corporate compliance, no moment is more perilous or more revealing than when companies come together.

Star Trek: The Original Series’ episode “Bread and Circuses” offers an unlikely but fitting parable for M&A compliance professionals. The Enterprise crew stumbles upon a planet with a civilization that mirrors Ancient Rome: gladiatorial games, a rigid class system, and a society that on the surface appears functional but underneath hides deep ethical and existential fault lines. As Captain Kirk, Mr. Spock, and Dr. McCoy navigate the complexities of this alien world, compliance professionals can draw out critical lessons for conducting effective due diligence in the high-stakes world of mergers and acquisitions.

Here are five key compliance-related M&A due diligence lessons from “Bread and Circuses.”

Lesson 1: Go Beyond Surface Appearances—Assess the True Culture

Illustrated by: On the planet 892-IV, Kirk and his landing party are initially impressed by the planet’s technological advancement. It boasts twentieth-century comforts, such as television, cars, and an advanced infrastructure. Yet, beneath the veneer, they discover an authoritarian state built on forced entertainment and oppression.

Compliance M&A Lesson: It is easy to be seduced by a target company’s top-line numbers, glossy facilities, and impressive management presentations. However, true due diligence requires a thorough examination beneath the surface. What’s the real culture? Is there a hidden culture of fear, ethical lapses, or compliance gaps? Cultural misalignment is one of the top reasons M&A deals fail. The Enterprise’s discovery of “Rome with cars” is a reminder to go beyond the show. Investigate how employees act when management isn’t around, what values truly drive decisions, and whether there’s a “bread and circuses” dynamic masking underlying dysfunction.

What should you do? Interview employees at every level, not just leadership. Review whistleblower hotlines, past HR investigations, and third-party reviews to reveal what may be hidden.

Lesson 2: Identify Hidden Liabilities—Don’t Ignore the Risks Beneath the Entertainment

Illustrated by: The population of 892-IV, which is kept docile through violent gladiatorial games that serve as literal bread and circuses. The ruling class avoids unrest by distracting the masses, but the peace is an illusion. When Kirk, Spock, and McCoy are thrust into the games, the underlying brutality and danger become clear.

Compliance M&A Lesson: In any transaction, there may be hidden liabilities—such as ongoing investigations, regulatory risks, potential litigation, or toxic business practices that have been overlooked or concealed. The “games” may keep things running, but only until something disrupts the balance. Effective due diligence involves identifying and addressing these hidden dangers. Compliance professionals must review litigation histories, regulatory filings, and environmental and safety records, as well as ongoing investigations and audits.

What should you do? First, do not be distracted by “good news only” presentations.

Request full disclosure of pending investigations, lawsuits, and regulatory actions. Utilize forensic audits and data analytics to examine financials and operational practices thoroughly.

Lesson 3: Map Third-Party and Supply Chain Risks—Everyone in the Arena Matters

Illustrated by: Kirk discovers that the planet’s leader, Merikus, is a missing Starfleet captain who has chosen to assimilate rather than resist. He justifies his choices as necessary for survival, but his complicity also enables oppression and exposes him to risk.

Compliance M&A Lesson: No company operates in isolation. A target company’s third-party relationships, joint ventures, and supply chains can be sources of immense risk, including FCPA, anti-bribery, human rights violations, and operational disruptions. Merikus’s collaboration illustrates how easily “good people” can enable unfavorable outcomes when incentives are misaligned. Map out all third-party relationships and conduct risk-based due diligence on significant partners.

What should you do? Consider the reputational and regulatory risks that the combined entity could pose. Are there red flags in high-risk geographies or industries? Implement a robust third-party due diligence program pre- and post-acquisition. Prioritize high-risk vendors and intermediaries for enhanced review.

Lesson 4: Understand Local Laws, Customs, and Power Structures—Context Is Everything

Illustrated by: Spock and McCoy are baffled by the local laws and power dynamics. What seems irrational by Federation standards makes sense only in the context of this world’s history and social structure. Understanding these nuances proves vital for their survival and escape.

Compliance M&A Lesson: Every M&A deal is shaped by its legal, regulatory, and cultural context. Don’t assume what works in your home country will transfer easily. Local labor laws, anti-corruption regimes, data privacy rules, and unwritten power structures can significantly impact an integration. A failure to appreciate these nuances can result in compliance violations, regulatory penalties, or reputational damage after the deal closes. Contextual awareness—legal and cultural—is non-negotiable.

What should you do? Partner with local counsel and compliance experts to conduct a jurisdiction-by-jurisdiction review. Document and plan for local regulatory requirements in the integration roadmap.

Lesson 5: Don’t Underestimate the Human Element—Values and Ethics Matter

Illustrated by: Throughout the episode, it is the values and resolve of the Enterprise crew—and the oppressed “Children of the Sun”—that make resistance to tyranny possible. The episode ends not with a technical solution, but with an ethical stand.

Compliance M&A Lesson: No due diligence checklist can substitute for evaluating the ethical climate and values of a target organization. Are there tone-at-the-top issues? Does the company reward ethical behavior or cut corners? Is there a history of retaliation against whistleblowers? Ultimately, mergers are about people, bringing together teams, customers, and cultures. Values alignment isn’t just a “soft” factor; it’s a predictor of post-merger success and resilience in a crisis.

What should you do? Include values and ethical culture assessments in your due diligence. Leverage employee surveys, exit interviews, and culture audits to gauge whether ethics are truly embedded.

Final ComplianceLog Reflections

Bread and Circuses” is more than just a classic science fiction adventure. It is a powerful parable for today’s compliance professional navigating the high-stakes world of mergers and acquisitions. As the Enterprise crew discovers, the trappings of prosperity and modernity can easily mask underlying risks, cultural misalignments, and ethical fault lines that, if left unexamined, can undermine even the most promising deal.

For compliance officers, the episode’s narrative reinforces that effective due diligence must go far beyond the numbers and surface-level impressions. It requires a holistic investigation into the culture, values, and relationships that truly define an organization. The success or failure of a merger often hinges on the ability to identify hidden liabilities, assess third-party and supply chain risks, and deeply understand the legal and regulatory landscape unique to each deal. Just as

Kirk and his team had to adapt to a world with its own rules and power structures. Compliance professionals must approach every transaction with humility, curiosity, and an unwavering commitment to ethical standards. In the arena of M&A, organizations that thrive are those that embrace rigorous, context-driven due diligence, protecting not only their assets but also their reputation and long-term success. The “arena” of M&A is as perilous as any gladiatorial contest. With rigorous, holistic due diligence, compliance officers can ensure their organizations don’t become unwitting spectators to someone else’s bread-and-circuses.

Resources:

Excruciatingly Detailed Plot Summary by Eric W. Weisstein

MissionLogPodcast.com

Memory Alpha

Categories
AI in Healthcare

AI in Healthcare: Five Healthcare AI Stories You Need to Know This Week – July 24, 2026

Welcome to AI in Healthcare in 5 Stories. This podcast is a weekly briefing on the five most important AI developments shaping healthcare, medicine, and life sciences. Each week, Tom Fox breaks down the latest stories on clinical innovation, regulation, privacy, compliance, patient safety, and operational transformation through a practical, business-focused lens. Designed for healthcare compliance professionals, executives, legal teams, clinicians, and industry leaders, the podcast moves beyond headlines to explain what each development means in the real world.

The top five stories for the week ending July 24, 2026, include:

  1. AI confidence outpaces adoption. (HealthCareFinance)
  2. 3 must-reads on AI in healthcare. (HealthExec)
  3. AI and last-mile delivery. (PharmTech)
  4. AI and operational accountability. (RSM)
  5. Healthcare needs to simplify its AI stack. (HealthcareITNews)

For more information on the use of AI in Compliance programs, Tom Fox’s new book, Upping Your Game, is available. You can purchase a copy of the book on Amazon.com.

To learn about the intersection of Sherlock Holmes and the modern compliance professional, check out Tom’s latest book, The Game is Afoot-What Sherlock Holmes Teaches About Risk, Ethics and Investigations on Amazon.com.

Categories
2 Gurus Talk Compliance

2 Gurus Talk Compliance – Episode 80 – The Corruption Edition

What happens when two top compliance commentators get together? They talk compliance, of course. Join Tom Fox and Kristy Grant-Hart in 2 Gurus Talk Compliance as they discuss the latest compliance issues in this week’s episode!

Stories This Week Include:

  • Blueprint for successful AI AML implementation.
  • Reverse information paradox
  • How corruption rots civil society and the economy
  • Kathryn Ruemmler says not so fast; what say Goldman Sachs?
  • Americans want a solution to corruption 
  • Alibaba to pay $600MM
  • Shein and Temu hit in crackdown
  • McKinsey shakes up Board after scandals
  • Compliance Author gets 10 years
  • Florida Woman police officer arrested for fake motorcycle plate

Resources:

Kristy

Kristy Grant-Hart on LinkedIn

Order Kristy’s updated, 10-year new edition of How to Be a Wildly Effective Compliance Officer by clicking here.

Tom

Check out the top compliance handbook, The Compliance Handbook, 7th edition, published by LexisNexis. Visit the LexisNexis® Store at https://lexisnexis.com/fox20

To save 20% on The Compliance Handbook: A Guide to Operationalizing Your Compliance Program, please reference or enter promotion code: FOX20.

Offer expires December 31, 2026. Offer applies to new orders only, before shipping and taxes are calculated and shipped to a U.S. address. A discount will be applied to each applicable product after the code FOX20 is entered. Discount does not apply to current subscriptions, renewals, or updates. Certain exclusions and other restrictions may apply. Void where prohibited. View full terms here.

Instagram

Facebook

YouTube

Twitter

LinkedIn

Categories
Creativity and Compliance

Creativity and Compliance: Change Management, Fun, and User Experience: Driving Engagement in Compliance

Tom Fox and Ronnie Feldman host Caveni Wong on Creativity and Compliance to discuss how change management principles align with ethics and compliance by focusing on influencing behavior rather than prioritizing “defensibility” alone.

Wong describes her 20-year compliance career across consulting, service providers, and in-house roles, plus change management work at Ernst & Young and IBM. The group emphasizes stakeholder involvement, relationship-building, and user experience (UX) across the full risk management lifecycle, arguing that engaging, creative, and appropriately short training and communication improve attention, retention, approachability, and trust. Wong shares examples like creative visuals, World Cup goalie analogies, and “two truths and a lie” during M&A integration to humanize compliance and build credibility with leaders. They discuss measuring effectiveness via evaluations, recall questions, engagement, increased speak-ups, and more HR/compliance inquiries, concluding that compliance success depends on not forgetting people.

 

Key highlights:

  • Compliance Meets Change
  • Beyond Training to Risk
  • Human Connection at Work
  • Creative Training Examples
  • User Experience Focus
  • Measuring Real Impact

Resources:

Ronnie

Caveni Wong

On LinkedIn

Principle Compliance

Tom

Instagram

Facebook

YouTube

Twitter

LinkedIn

Creativity and Compliance is a multiple podcast award-winning show and was recently honored as one of the Top 35 Podcasts on Creativity by Feedspot.

Categories
AI in Financial Services in 5 Stories

AI in Financial Services in 5 Stories – Week Ending July 24, 2026

Welcome to AI in Financial Services in 5 Stories. A practical weekly roundup of the five most important AI developments affecting banking, insurance, payments, asset management, and fintech. Each Friday, Tom Fox will break down the top stories that matter most through the lenses of compliance, risk management, governance, and business strategy. Designed for compliance professionals, executives, legal teams, and financial services leaders, it goes beyond headlines to explain why each development matters in a highly regulated industry. The result is a concise weekly briefing that helps listeners stay current on AI innovation while asking sharper questions about oversight, accountability, and trust.

This week’s stories include the following:

  1. Prediction markets and AI: Is compliance ready? (FinTechGlobal)
  2. AI is only as smart as the data. (Forbes)
  3. This time is different. (Crunchbase News)
  4. AI in fintech: use cases.(Intuit)
  5. How financial services are using AI in 2026. (RSM)

For more information on the use of AI in Compliance programs, Tom Fox’s new book, Upping Your Game, is available. You can purchase a copy of the book on Amazon.com.

To learn about the intersection of Sherlock Holmes and the modern compliance professional, check out Tom’s latest book, The Game is Afoot-What Sherlock Holmes Teaches About Risk, Ethics and Investigations on Amazon.com.

Categories
Blog

Scoular’s $10 Million FCPA Resolution: Compliance Lessons Learned

We conclude our review of the Scoular Company FCPA enforcement action with a full lessons-learned blog post. We are still awaiting the DPA and Criminal Information, so the details of the case come from the Department of Justice (DOJ) Press Release.

A $2,000 payment can disappear inside a global supply chain. Repeated, train-by-train, authorized by employees, routed through customs brokers, discussed on WhatsApp, disguised as a “reinspection fee,” and reimbursed for six years, it becomes an operating model. That is the central lesson from The Scoular Company Foreign Corrupt Practices Act resolution.

The DOJ announced that Scoular Company would pay more than $10 million to resolve an investigation into bribes paid to Mexican officials between 2013 and 2019. The company entered into a three-year deferred prosecution agreement, agreed to a $9,769,521 criminal penalty and $414,351 in forfeiture, and accepted continuing cooperation, compliance, and reporting obligations.

Across this blog post series, we examined four dimensions of the case: customs brokers and payment controls, cartel and national-security risk, off-channel communications, and the facilitating-payments exception. Read together with my podcast conversation with Matt Ellis, they reveal a single conclusion. Compliance must follow the complete transaction, from the business pressure that creates the payment to the third party that delivers it, the message that authorizes it, the invoice that conceals it, and the ultimate recipient who benefits.

The Scheme Hid in Plain Sight

According to the DOJ, Scoular Company relied on customs brokers to move corn and other agricultural products from the United States into Mexico. Mexican authorities inspected the shipments for dirt, soil, and other impurities. When inspections identified problems, Scoular Company employees directed brokers to pay officials approximately $2,000 per train so the shipments could cross the border. The brokers invoiced the payments back to Scoular Company as “reinspection fees,” and Scoular paid them. In total, the company authorized more than $400,000 in bribes and avoided more than $6.5 million in fees and costs.

The invoice description is the first major lesson. “Reinspection fee” sounded like it was connected to a legitimate customs process. Yet an accounts-payable control that merely matches an approved vendor, purchase order, and plausible service description tests paperwork, not substance.

Effective payment controls should require the company to identify the government agency involved, match the charge to a specific shipment and inspection, compare the amount with an official fee schedule, obtain proof of service, confirm the payee, and document the business justification. Repeated round-dollar charges, unusual success rates, rapid clearance after special payments, and fees unsupported by government records should trigger review.

Follow the money, measure the time, and test the outcome. That is how ordinary transaction data becomes an anti-corruption control.

A Licensed Broker Is Still a High-Risk Third Party

Customs brokers should never be treated as low-risk administrative providers simply because they are licensed or legally required. They interact with government officials, operate under commercial pressure, and can impose charges that distant finance personnel cannot easily verify.

Initial due diligence remains necessary, but it is only the beginning. Companies must connect screening, contracting, invoice testing, transaction monitoring, recertification, training, audit rights, and offboarding. The real test is not whether the third-party file was complete on the day of onboarding. It is whether the company understands how the broker behaves after the contract is signed.

The DOJ credited Scoular Company with eliminating brokers associated with the Mexican reinspection payments, strengthening risk-based screening and approvals, adding anti-corruption and audit-rights provisions, revising controls for high-risk transactions, and using software tools to improve monitoring. That remediation changed the operating model rather than merely revising a policy.

Cartel Risk Changes the Compliance Perimeter

The most consequential part of the DOJ announcement may be its national-security framing. The government determined that, without Scoular Company or its employees knowing it, a portion of the bribes benefited persons associated with a cartel’s criminal operations at the U.S.-Mexico border.

U.S. Attorney Justin R. Simmons stated that American companies engaged in cross-border trade bear responsibility for operating without benefiting cartels or threatening national security. Ellis challenged the literal breadth of the statement during our podcast discussion. Legitimate trade crosses the border every day without companies knowingly paying cartels. Nevertheless, he agreed that the statement signals a more demanding compliance environment.

Ellis explained that the cartel and transnational criminal organization risk is broader than the traditional FCPA risk. Anti-corruption diligence often concentrates on government touchpoints and intermediaries. Organized crime may be hidden inside transportation providers, suppliers, customers, labor relationships, security services, subcontractors, and local routes.

Traditional database screening may not reveal those connections. Ellis emphasized contextual diligence: speak with employees on the ground, examine local security concerns, understand regional criminal activity, investigate facts that do not add up, and adjust operations when warning signs emerge. Companies do not need perfect knowledge. They need a documented story of reasonable measures, credible escalation, and risk-based decisions.

The practical consequence is an integrated risk assessment. Anti-corruption, sanctions, anti-money laundering, trade compliance, physical security, supply chain, and third-party risk cannot remain in separate silos when the same payment may touch all of them.

WhatsApp Was Part of the Control Environment

The DOJ said Scoular Company employees communicated about shipments and bribes through WhatsApp and other means. WhatsApp was therefore not a side issue. It allegedly carried the knowledge and direction behind transactions later recorded as legitimate reinspection charges.

An informal application becomes a business system when employees use it to direct third parties, approve payments, or resolve customs problems. Enterprise controls can be bypassed when the substantive decision occurs in a private chat, and the formal system records only the sanitized result.

Ellis noted that a complete WhatsApp ban may be unrealistic in Latin America. The better approach is to map actual use and define what may occur on each platform. Logistical coordination may be permitted. Government interactions, payment approvals, contractual commitments, and exceptions should remain in controlled systems with retention and audit trails.

Companies must also be able to preserve and retrieve business communications lawfully from company and personal devices. Policies should address device replacement, departing employees, legal holds, privacy and employment requirements, refusal of access, and consistent discipline. The decisive question is not whether a policy exists. It is whether the company can obtain the evidence when an investigation begins.

Why These Were Not Facilitation Payments

The $2,000 amount and the customs setting may tempt employees to use the phrase “facilitation payment.” That label does not fit. The FCPA’s narrow exception covers payments intended to expedite routine, nondiscretionary governmental action that the payer is already entitled to receive. Scheduling an inspection may be routine. Paying an official to disregard a failed inspection is not.

The Scoular Company payments allegedly changed the result. The shipments had identified impurities, and the payments allowed trains to cross despite those findings. The company received a substantial business advantage by avoiding more than $6.5 million in costs. A facilitation payment is not defined by size, local custom, commercial urgency, or invoice terminology. A third party cannot create an exception unavailable to the principal. Nor does an anti-bribery exception excuse false accounting. Even a qualifying payment must be accurately recorded and supported by adequate internal controls.

Ellis’s discussion of extortion reinforces the operational lesson, although extortion and facilitation are distinct doctrines. One or two emergency payments may present a different analysis from a chain of payments continuing over years. Repetition transforms an asserted accommodation into a business process. Companies must respond by escalating, rerouting, changing providers, investigating, and remediating.

Cooperation Still Matters

Scoular Company did not receive voluntary self-disclosure credit because it did not report the conduct to the DOJ in a timely manner. It did receive cooperation credit for its internal investigation, factual presentations, identification of involved individuals, production and organization of evidence, and provision of counsel for current employees, despite early deficiencies.

The resulting criminal penalty reflected a 25 percent reduction from the bottom of the applicable sentencing guidelines range. The lesson is straightforward. Missing the voluntary disclosure window does not render later cooperation irrelevant, but cooperation is not a substitute for timely self-disclosure. The Scoular Company resolution is not four separate compliance stories. It is one story about how pressure, third parties, communications, accounting, and emerging national-security risks converged inside an ordinary business process.

The enduring lesson is equally integrated: know the broker, validate the payment, preserve the message, understand the route, and test the outcome. That is how compliance moves from policy to proof.