Categories
Blog

Returning to Venezuela: Part 1 – Bribery, Corruption and the Risks You Must Confront Before You Enter

When US energy companies talk about returning to Venezuela, the conversation almost always starts with opportunity. Yet the CEO of Exxon has said Venezuela is ‘uninvestible’. There is another set of problems that every corporate compliance team will face if their company decides to enter the Brazilian market. For the compliance professional, it must start with corruption. Not episodic corruption. Not bad actors at the margins. Systemic, embedded, institutionalized corruption that touches government agencies, state-owned enterprises, procurement systems, and the judiciary. This is not a theoretical risk. It is the operating environment.

The Department of Justice (DOJ) has made clear in the Evaluation of Corporate Compliance Programs (ECCP) that high-risk jurisdictions require tailored, well-resourced, and empowered compliance programs. Venezuela is the textbook example of why. Over the next several blog posts, we will explore key issues every company and CCO will face when considering whether to enter (or re-enter) Venezuela. In Parts 1 and 2, I will consider the top 10 anti-bribery/anti-corruption (ABC) risks a compliance professional will face. (Part 1, risks 1-5; Part 2, risks 6-10). We will then consider AML risk, export control and trade sanctions, security risks, and end with operational risks.

1. Systemic Corruption Is the Baseline Condition

Risk

Venezuela is not a market where corruption appears as an exception. It is the default condition against which all business activity must be measured. For compliance professionals, this means risk assessments cannot ask whether corruption exists. They must assume it does and ask where pressure will arise. Licensing, customs, inspections, labor issues, utilities, and currency all present opportunities for improper advantage. Boards must understand this upfront. Entering Venezuela without acknowledging systemic corruption is not optimism. It is a governance failure.

Compliance Framework Response

Before addressing individual risks, the compliance function must establish baseline principles governing how risk is assessed and managed in Venezuela.

  1. Assume corruption pressure exists. The risk assessment does not ask if corruption will arise, but where and how.
  2. Controls must be operational, not theoretical. Policies without authority, monitoring, and escalation are not controls.
  3. Risk ownership must be explicit. Every risk category has a business owner, a compliance owner, and a board oversight hook.
  4. Boards govern risk; they do not run operations. Oversight is mandatory. Tactical interference is prohibited.

2. PdVSA as a Prominent and Persistent Risk

Risk

Any discussion of bribery risk in Venezuela must begin with Petróleos de Venezuela S.A. (PdVSA), which has been at the center of some of the most significant corruption schemes in modern enforcement history, involving contracts, invoices, intermediaries, and payment routing. Indeed, 10 years ago, I wrote that it would cost a fortune to schedule and confirm a meeting. But companies make the mistake of treating PdVSA as a single risk node. In reality, it is a network risk. Joint ventures, service contracts, maintenance agreements, and procurement relationships all radiate outward, exposing the organization to corruption. If your counterparty touches PdVSA, you have inherited PdVSA risk.

Compliance Framework Response

The starting point is a Venezuela-specific bribery and corruption risk assessment, refreshed whenever business scope, counterparties, or operating conditions change.

This assessment must:

  • Map all government touchpoints.
  • Identify all third parties by function, not just by name;
  • Distinguish systemic risk from transactional risk; and
  • Flag PdVSA exposure explicitly.

Outputs are not static reports. They are control design inputs.

3. Joint Ventures and Service Contracts: Shared Risk, Shared Liability

Risk

Joint ventures are often framed as risk mitigation tools. In Venezuela, they frequently do the opposite. Local partners may be politically connected. Governance structures may be opaque. Control rights may be illusory. Compliance professionals must scrutinize who appoints management, who controls procurement, and who interacts with government officials. Under the ECCP, regulators ask whether compliance has authority commensurate with risk. In a Venezuelan JV, symbolic compliance oversight is not enough.

Compliance Framework Response

1. Assessment Controls

  • Government interaction mapping by function and frequency
  • Identification of pressure points where discretion exists
  • Historical analysis of delays, denials, or unexplained variability

2. Management Controls

  • Pre-approval requirements for all government-facing interactions
  • Clear prohibitions on facilitation payments
  • Mandatory escalation for any demand tied to speed, access, or discretion

Monitoring

  • Trend analysis of approvals and delays
  • Comparison of processing times across regions or projects

1. Board Oversight Questions

  • Where do we face the highest government discretion risk?
  • What interactions cannot proceed without a compliance sign-off?

4. Procurement as the First Corruption Flashpoint

Risk

Procurement is where corruption pressure materializes fastest. Vendors expect to be paid for access. Officials expect influence. Intermediaries promise to “make things happen.” This is even more true in Venezuela. This is where third parties begin to matter and where compliance must be in place before contracts are signed. Retrospective diligence does not cure a corrupted procurement process. Boards should demand visibility into how vendors are selected, not just who they are.

Compliance Framework Response

1. Assessment Controls

  • Explicit identification of direct and indirect PdVSA touchpoints
  • Mapping of PdVSA influence over pricing, approvals, and payments
  • Review of historical enforcement patterns tied to similar structures

2. Management Controls

  • Enhanced due diligence for any counterparty touching PdVSA
  • Compliance approval of all PdVSA-facing contract terms
  • Segregation of duties around invoicing and change orders

Monitoring

  • Continuous review of intermediaries interacting with PdVSA
  • Red flag monitoring for unusual invoice timing or routing
  1. Board Oversight Questions
  2. How are PdVSA’s risks different from those of other SOEs we engage with?
  3. What controls exist beyond standard third-party diligence?

5. The Illusion of “Routine” Government Interaction

Risk

Companies often underestimate corruption risk by labeling interactions as routine: inspections, permits, customs clearances, utilities, and labor approvals. And yes, the DOJ has said it will back off on enforcement of small payments, which may be traditionally made, but in Venezuela, routine functions are often monetized.  Compliance programs must draw hard lines early and firmly.

Compliance Framework Response

1. Assessment Controls

  • Governance and control-rights analysis
  • Identification of who appoints management and controls procurement
  • Mapping of partner government relationships

2. Management Controls

  • Contractual compliance rights with audit and termination authority
  • Compliance veto power over high-risk activities
  • Mandatory training for JV-appointed personnel

Monitoring

  • Periodic compliance audits of JV operations
  • Review of partner interactions with officials

1. Board Oversight Questions

  • Where do we lack real compliance leverage in our JVs?
  • Are control rights aligned with our risk exposure?

Join us tomorrow as we look at ABC risks 6-10, including third parties, extortion, organized crime, currency issues, and a weak rule of law.

Categories
Daily Compliance News

Daily Compliance News: January 7, 2026, The 6 Years in Singapore Edition

Welcome to the Daily Compliance News. Each day, Tom Fox, the Voice of Compliance, brings you compliance-related stories to start your day. Sit back, enjoy a cup of morning coffee, and listen in to the Daily Compliance News. All, from the Compliance Podcast Network. Each day, we consider four stories from the business world, compliance, ethics, risk management, leadership, or general interest for the compliance professional.

Top stories include:

  • Energy companies are cautious about Venezuela. (NYT)
  • Malaysia to up the ABC ante. (DW)
  • British national sentenced to 6 years in jail over Wirecard fraud. (FT)
  • How corporate security has changed. (WSJ)
Categories
Daily Compliance News

Daily Compliance News: December 12, 2025, The All New York Times Edition

Welcome to the Daily Compliance News. Each day, Tom Fox, the Voice of Compliance, brings you compliance-related stories to start your day. Sit back, enjoy a cup of morning coffee, and listen in to the Daily Compliance News. All, from the Compliance Podcast Network. Each day, we consider four stories from the business world, compliance, ethics, risk management, leadership, or general interest for the compliance professional.

Top stories include:

  • ABC protests topple the Bulgarian government. (NYT)
  • French tennis player suspended for 20 years over corruption. (NYT)
  • UM coach fired over affair with staffer. (NYT)
  • Trump puts the DOJ in a no-win position over Warner Bros.(NYT)

The Daily Compliance News has been honored as the No. 2 in Best Regulatory Compliance Podcasts category.

Categories
Daily Compliance News

Daily Compliance News: October 9, 2025, The More Scrutiny Edition

Welcome to the Daily Compliance News. Each day, Tom Fox, the Voice of Compliance, brings you compliance-related stories to start your day. Sit back, enjoy a cup of morning coffee, and listen in to the Daily Compliance News. All, from the Compliance Podcast Network. Each day, we consider four stories from the business world, including compliance, ethics, risk management, leadership, or general interest, relevant to the compliance professional.

Top stories include:

  • House Dems increase scrutiny of Homan over bribe allegations. (Axios)
  • Marcos names ally to ABC ombudsman. (SCMP)
  • Insurers balk about AI exposures. (FT)
  • Musk settles ex-Twitter execs’ bonus lawsuit. (Reuters)
Categories
Daily Compliance News

Daily Compliance News: October 6, 2025, The Corny Capitalism Edition

Welcome to the Daily Compliance News. Each day, Tom Fox, the Voice of Compliance, brings you compliance-related stories to start your day. Sit back, enjoy a cup of morning coffee, and listen in to the Daily Compliance News. All, from the Compliance Podcast Network. Each day, we consider four stories from the business world, including compliance, ethics, risk management, leadership, or general interest, relevant to the compliance professional.

Top stories include:

  • Saudi mega-construction project under ABC investigation. (Semafor)
  • PE and the ethics of drug research. (NYT)
  • $100MM wine fraud in NYC. (Bloomberg)
  • Crony capitalism and corruption. (NPR)
Categories
FCPA Compliance Report

FCPA Compliance Report – Pat Poitevin on Transforming Corporate Compliance: Leveraging AI and Building Ethical Cultures

Join Tom Fox as he welcomes Pat Poitevin, a compliance veteran with extensive experience in enforcement, consulting, and academia. Pat shares his professional journey, beginning with his work at the Royal Canadian Mounted Police (RCMP), and discusses the importance of establishing strong ethics and compliance cultures within organizations. He emphasizes the role of AI in transforming compliance functions and enhancing the effectiveness of risk management. Pat also touches on the future of compliance, talent acquisition, and the impact of technology on business ethics. The conversation offers valuable insights for compliance professionals looking to refine their programs and align them with business strategies for sustained growth.

Key highlights:

  • Current Projects and Focus Areas
  • Building a Strong Ethics and Compliance Culture
  • Leveraging AI in Compliance
  • Compliance Strategies for Geopolitical and Technological Changes
  • Balancing Policies and Human Behavior
  • Future of Compliance and Technology

Resources 

Pat Poitevin

🔸 LinkedIn: Pat Poitevin

🔸 Consulting Firm: Active Compliance and Ethics Group (ACEG)

Tom Fox

Instagram

Facebook

YouTube

Twitter

LinkedIn

For more information on the use of AI in Compliance programs, my new book, Upping Your Game. You can purchase a copy of the book on Amazon.com

Categories
Daily Compliance News

Daily Compliance News: October 2, 2025, The Cook Can Stay Edition

Welcome to the Daily Compliance News. Each day, Tom Fox, the Voice of Compliance, brings you compliance-related stories to start your day. Sit back, enjoy a cup of morning coffee, and listen in to the Daily Compliance News. All, from the Compliance Podcast Network. Each day, we consider four stories from the business world, including compliance, ethics, risk management, leadership, or general interest, relevant to the compliance professional.

Top stories include:

  • Meta to mine AI to create ads. (FT)
  • World ABC fight lessened by the US withdrawal. (The Conversation)
  • South Africa and Nigeria poised to exit dirty money list. (Bloomberg)
  • Supreme Court says FED Governor can stay until ruling. (Reuters)
Categories
Everything Compliance - Shout Outs and Rants

Everything Compliance: Shout Outs & Rants: Episode 160, The What Next Edition

Welcome to this Edition of award-winning Everything Compliance. In this episode, we have the sextet of Matt Kelly, Jonathan Marks, Jonathan Armstrong, Karen Woody, and Karen Moore, with Tom Fox, the Compliance Evangelist, sitting in as host.

  1. Matt Kelly shouts Boston Mayoral candidate Josh Craft, who bowed out of the race.
  2. Jonathan Marks shouts out to Sheinelle Jones, all those who lost loved ones to cancer, and cancer victim caregivers.
  3. Jonathan Armstrong shouts out to the Grand Ole Opry.
  4. Karen Moore rants about ABC and Disney’s decision to suspend Jimmy Kimmel.
  5. Karen Woody shouts out to the Netflix show Adolescence, which swept the Emmys.
  6. Tom Fox shouts out the Community Foundation of the Hill Country, which took in over $100MM in donations for victims of the July 4 flood in 30 days.

The members of Everything Compliance are:

The host, producer, and sometime panelist of Everything Compliance is Tom Fox, the Voice of Compliance. He can be reached at tfox@tfoxlaw.com.  The award-winning Everything Compliance is a part of the Compliance Podcast Network.

Categories
AI Today in 5

AI Today in 5: September 15, 2025, The AI as ABC Minister Episode

Welcome to AI Today in 5, the newest edition to the Compliance Podcast Network. Each day, Tom Fox will bring you 5 stories about AI, so start your day, sit back, enjoy a cup of morning coffee, and listen in to the AI Today In 5, all from the Compliance Podcast Network. Each day, we consider four stories from the business world, compliance, ethics, risk management, leadership, or general interest related to AI.

Top AI stories include:

  • Albania appoints AI as the first Minister of ABC. (BBC)
  • AI compliance deadlines looming. (Bloomberg Law)
  • AI Doomers are losing. (Bloomberg)
  • Promises and perils of Agentic AI. (CCI)
  • Finance teams double the use of AI. (CCI)

For more information on the use of AI in Compliance programs, my new book, Upping Your Game. You can purchase a copy of the book on Amazon.com.

Categories
Blog

From Controls to Culture: Building Anti-Corruption Programs that Address Fraud, Waste, and Abuse

Fraud, waste, and abuse are not just buzzwords in the government sector. They represent a real continuum of risk that every private sector company must confront. In fact, when designing or refreshing an anti-corruption compliance program, these three categories should not be seen as separate from bribery and corruption risks; they are integral to them. Bribery schemes thrive in environments where fraud is unchecked, where waste is tolerated, and where abuse of authority is normalized.

A truly effective anti-corruption compliance program, therefore, must address fraud, waste, and abuse head-on. Each requires different tools, but all rest on the same foundation: clear expectations, adequate controls, data-driven monitoring, and a culture of accountability. Yesterday, we took a deep dive into the three concepts behind fraud, waste, and abuse. Today, we continue our primer on fraud, waste, and abuse for the compliance professional by exploring how compliance professionals can operationalize their ABC framework to help fight these corporate scourges.

1. Fraud Prevention: Strengthening the Control Environment

Fraud sits at the heart of most corruption schemes. Bribery rarely occurs without the use of falsified invoices, fraudulent expense reports, or deceptive third-party contracts. That’s why fraud prevention measures must be embedded directly into your anti-corruption compliance program.

Practical steps include:

  • Segregation of duties. No single employee should have the authority to control both vendor approval and invoice payment. Splitting responsibilities closes off avenues for concealment.
  • Mandatory rotations or vacations. Employees in high-risk positions, such as procurement or finance, should be required to take periodic breaks. This not only reduces burnout but also increases the chance of uncovering irregularities.
  • Third-party due diligence. Vendors, distributors, and consultants are often used as conduits for corrupt payments. Screening them for red flags of fraud and corruption is essential.
  • Hotlines and reporting mechanisms. Anonymous channels encourage employees to report fraudulent or corrupt activity before it escalates.

Finally, modern fraud prevention is inseparable from data analytics. Reviewing transactions for anomalies in billing, procurement, or travel can help compliance officers identify both fraudulent activity and corruption red flags early.

2. Waste Reduction: Linking Efficiency to Integrity

Waste may not sound like a corruption risk at first, but it often creates the environment in which corrupt practices thrive. When organizations tolerate careless spending or redundant processes, they signal that accountability is optional. Waste becomes the fertile soil in which corruption can take root.

Practical steps include:

  • Cross-functional accountability. Compliance should collaborate with finance, procurement, and operations to ensure efficient allocation of resources.
  • Tracking key waste indicators. Duplicate software licenses, unnecessary travel expenses, or high energy consumption may not be fraudulent, but they represent vulnerabilities that can be exploited. Left unchecked, they normalize sloppy practices that corrupt employees can exploit.
  • Integrating waste metrics into compliance dashboards. If a business unit consistently demonstrates waste, it may also be vulnerable to bribery risks, particularly in operations that are heavily reliant on procurement.

By spotlighting waste, compliance leaders not only save the company money but also reinforce a culture of stewardship and integrity, two qualities that reduce the likelihood of corruption.

3. Abuse Control: Guarding Against the Gray Areas

Abuse often serves as the gateway to corruption. It thrives in gray zones, where managers stretch policies, exploit loopholes, or turn a blind eye to questionable behavior. Abuse may not always cross a legal line, but it corrodes culture and opens the door to bribery and unethical decision-making.

Practical steps include:

  • Tone from the top and middle. Executives and line managers alike must model integrity. If leaders exploit perks or bend rules, employees will assume similar behavior is acceptable in dealing with third parties.
  • Policy clarity. Abusive practices often hide in vague policies. For example, a travel policy that allows “reasonable upgrades” without definition invites abuse. Aligning policies with anti-corruption standards closes these loopholes.
  • Incentive structures. Embedding transparency and fairness into performance reviews and rewards ensures managers do not cut ethical corners to hit financial targets.

By shrinking the space in which abuse can thrive, companies make it more difficult for corrupt practices to become normalized.

4. Leverage Data Analytics: Uncovering Patterns Across Risk Categories

Corruption schemes are rarely isolated. They often weave together fraud, waste, and abuse. That’s why analytics should not be siloed. A robust anti-corruption program integrates monitoring across multiple risk vectors.

Practical applications include:

  • Travel and entertainment analytics. Reviewing expense reports can uncover fraudulent receipts, wasteful spending, or abusive upgrades. These same reports may also reveal bribery risks if entertainment involves government officials or high-risk clients.
  • Procurement analytics. Comparing vendor pricing across regions may reveal fraudulent invoicing, excessive costs (resulting in wasteful spending), or favoritism (abuse of power). It can also reveal third parties that may be used as conduits for corruption.
  • Cross-data integration. Linking procurement, HR, and finance data highlights unusual patterns. For example, a sudden spike in overtime in a high-risk market may flag both payroll abuse and potential red flags for corruption.

Data analytics transforms compliance from a reactive to a proactive discipline, catching issues before they metastasize into a full-blown corruption scandal.

5. Whistleblower Empowerment: The Human Early Warning System

Even the most advanced controls and analytics cannot replace human intelligence. Employees are the first to notice when fraud, waste, or abuse is occurring. But unless they feel safe speaking up, those observations remain hidden.

Practical steps include:

  • Robust reporting channels. Multiple options, including hotlines, digital portals, or direct reporting to compliance, all make it easier for employees to raise concerns.
  • Protection against retaliation. Employees must trust that speaking up won’t cost them their careers. Policies must be clear, and enforcement consistent.
  • Timely follow-up. When employees report fraud, waste, or abuse, prompt investigation and feedback demonstrate that the company takes reports seriously.

In the context of anti-corruption compliance, whistleblowers are invaluable. They can flag bribery schemes before external regulators or auditors uncover them.

Building Resilience by Tackling All Three

An anti-corruption compliance program that focuses only on bribery risks but ignores fraud, waste, and abuse is incomplete. Fraud fuels corruption, waste fosters the conditions where it flourishes, and abuse normalizes the behavior that enables it.

By embedding fraud prevention, waste reduction, abuse control, data analytics, and whistleblower empowerment into your anti-corruption framework, you create a resilient program that goes beyond compliance checklists. You demonstrate stewardship to shareholders, accountability to employees, and integrity to regulators.

The fight against corruption is not won by policing bribery alone. It is won by creating a culture where fraud, waste, and abuse cannot survive and where transparency, efficiency, and fairness are the norm. That is the true mandate for today’s compliance professional.