Categories
Blog

Scoular’s $10 Million FCPA Resolution: When a “Re-inspection Fee” Becomes a Bribe

A $2,000 payment can look insignificant inside a global supply chain. Repeated train by train, approved by employees, routed through customs brokers, disguised on invoices, and paid for six years, it becomes something else entirely. For The Scoular Company, it became a Foreign Corrupt Practices Act enforcement action carrying more than $10 million in penalties and forfeiture, a three-year deferred prosecution agreement, continuing cooperation obligations, and periodic reporting to the Department of Justice.

The case is an important warning for every company engaged in cross-border trade. Customs brokers are not merely logistics providers. Border payments are not merely operational expenses. A mislabeled invoice is not merely an accounting problem. Each may represent an interconnected risk across anti-corruption, internal control, third-party, and national security.

The Scheme: $2,000 per Train

According to the DOJ Press Release (the full DPA is not yet available), between 2013 and 2019, Scoular used customs brokers to move shipments of corn and other agricultural products from the United States to Mexico. Mexican authorities inspected those shipments for dirt, soil, and other impurities. When inspectors identified problems, Scoular’s customs brokers allegedly paid Mexican officials approximately $2,000 per train to ensure that the shipments crossed the border.

The brokers then invoiced those payments back to Scoular as “reinspection fees.” Scoular paid the invoices. This was not an isolated facilitation payment or a rogue third party operating beyond the company’s knowledge. According to the court documents, Scoular employees authorized the payments, directed the brokers, and communicated about the shipments and bribes through WhatsApp and other channels.

The numbers demonstrate the business impact:

  • More than $400,000 in bribes authorized
  • More than $6.5 million in avoided fees and costs
  • A $9,769,521 criminal penalty
  • $414,351 in forfeiture
  • A three-year DPA

The company was charged with conspiracy to violate the FCPA’s anti-bribery provisions.

The Invoice Description Was a Compliance Red Flag

The phrase “reinspection fee” should be at the center of every compliance discussion about this case. The brokers did not invoice Scoular for bribes. They used a description that appeared facially connected to a legitimate customs process. That description allowed the payments to move through the company’s financial system.

This is how corruption frequently enters the books and records. It appears as:

  • Expediting fees
  • Administrative charges
  • Local processing costs
  • Customs support
  • Special handling
  • Reinspection fees
  • Consulting services

The compliance question is not whether the description sounds legitimate. The question is whether the company can establish what service was performed, who performed it, why the payment was necessary, how the amount was calculated, and who ultimately received the money. Accounts payable controls that merely match an invoice to a purchase order will not detect this type of scheme. Effective controls must examine the commercial substance of high-risk payments.

For customs-related expenses, companies should require supporting government documentation, published fee schedules, proof of service, payment to an authorized government account where appropriate, and enhanced approval for unusual or recurring charges.

Third-Party Due Diligence Is Only the Beginning

The Scoular resolution also demonstrates the limits of onboarding due diligence. A company can screen a customs broker, obtain certifications, execute an anti-corruption clause, and still face substantial FCPA exposure. The real question is what happens after the third party begins work. The answer is that the real work of compliance begins when the third-party contract is signed.

Customs brokers operate at the intersection of government interaction, time-sensitive business demands, discretionary enforcement, and local pressure. That makes them inherently high risk. An effective third-party management program should connect the following:

  • Initial due diligence
  • Contractual controls
  • Transaction monitoring
  • Invoice testing
  • Business justification
  • Periodic recertification
  • Audit rights
  • Compliance training
  • Offboarding decisions

The DOJ credited Scoular for strengthening risk-based screening and approval requirements, adding anti-corruption and audit-right provisions to contracts, and improving monitoring procedures. The company also eliminated customs brokers associated with the Mexican reinspection payments. Due diligence is not and cannot remain a static file. It must become a continuing control system tied to actual payments and operational conduct.

WhatsApp Was Part of the Business Process

Scoular employees allegedly communicated about the shipments and payments through WhatsApp and other channels. This fact should concern every CCO. When employees use personal devices or ephemeral messaging platforms to conduct high-risk business, the company may lose visibility into precisely the communications it most needs to monitor, preserve, and produce.

The answer is not necessarily to prohibit every messaging application. The answer is to establish a defensible governance model addressing the following:

  • Permitted communication platforms
  • Business-record retention
  • Preservation during investigations
  • Access to relevant communications
  • Training for high-risk employees
  • Monitoring based on legal and privacy requirements
  • Consequences for circumventing approved systems

A policy without technical controls, employee training, and consistent enforcement is unlikely to satisfy prosecutors. Messaging governance must reflect how employees actually conduct business.

Corruption Is Now a National Security Issue

The most significant feature of the case may be the DOJ’s treatment of cartel risk. The government determined that a portion of the bribe payments ultimately benefited individuals associated with a cartel operating at the U.S.-Mexico border. The DOJ stated that neither Scoular nor its employees knew about that connection. That lack of knowledge did not eliminate the seriousness of the issue.

Indeed, in the DOJ Press Release, U.S. Attorney Justin R. Simmons for the Western District of Texas was quoted as follows, “Nothing crosses into or out of Mexico without the approval and payment to Mexican drug cartels.” Further, any American businesses that engage in any cross-border trade bear a significant amount of responsibility to do so without benefitting those cartels and without threatening our national security.”

The enforcement message is clear: companies operating in high-risk border regions must consider where third-party payments may ultimately flow. A payment intended to resolve a customs problem can expose a party to corruption, money laundering, sanctions, organized crime, and national security risks. This means anti-corruption risk assessments can no longer operate in isolation. Compliance teams should integrate information from the following:

  • Anti-money laundering reviews
  • Sanctions screening
  • Security functions
  • Trade compliance
  • Supply chain risk management
  • Third-party intelligence
  • Government investigations
  • Adverse media monitoring

The government is examining the complete risk created by a payment, not merely the employee’s immediate objective.

No Voluntary Disclosure Credit, but Meaningful Cooperation Credit

Scoular did not receive voluntary self-disclosure credit because it did not promptly report the conduct to the DOJ Fraud Section. It did, however, receive credit for cooperation. The DOJ cited Scoular’s internal investigation, factual presentations, identification of individuals involved, document production, organization of evidence, and provision of counsel for current employees. The DOJ also acknowledged deficiencies during the early stages of the investigation.

After considering the company’s cooperation and remediation, the DOJ imposed a criminal penalty reflecting a 25 percent reduction from the bottom of the applicable sentencing guidelines range. This is a valuable lesson in enforcement mathematics. Missing the opportunity for voluntary disclosure does not make subsequent cooperation irrelevant. Companies can still improve outcomes through credible investigation, evidence preservation, individual accountability, timely remediation, and the organized production of information.

Yet cooperation credit is not the equivalent of voluntary disclosure credit. The decision window following discovery of potential misconduct remains critical.

Remediation Must Change the Operating Model

Scoular’s remediation went beyond issuing a new policy. According to the DOJ, the company:

  • Conducted an external compliance maturity assessment and anti-corruption risk assessment
  • Restructured its compliance function
  • Increased senior leadership oversight
  • Eliminated brokers connected to the payments
  • Strengthened risk-based monitoring through software tools
  • Revised its Code of Conduct and key compliance policies
  • Improved third-party screening and approvals
  • Added anti-corruption and audit-rights provisions
  • Revised financial controls for high-risk transactions
  • Delivered general and targeted anti-corruption training

This is the type of remediation contemplated by the DOJ’s Evaluation of Corporate Compliance Programs. It addresses root causes, resources, governance, controls, technology, training, and business ownership.

The key is operational impact. The company must be able to demonstrate that the same conduct could not pass through the organization today without being detected or escalated.

Questions for CCOs

CCOs should ask:

  • Do recurring payments cluster around specific ports, brokers, officials, products, or inspection events?
  • Are vague payment descriptions automatically escalated?
  • Does compliance have access to customs, logistics, and accounts payable data?
  • Are high-risk brokers periodically reviewed after onboarding?
  • Has the company tested whether audit rights can actually be exercised?
  • Is there a rapid escalation process for deciding whether potential misconduct should be voluntarily disclosed?

The Bottom Line

The Scoular case was not simply about customs brokers paying officials. It was about an operational process that allegedly normalized bribery, an invoicing system that disguised the payments, employees who communicated through informal channels, and third-party funds that ultimately touched cartel-linked actors.

For compliance professionals, the lesson is direct: follow the payment, test the business justification, examine the communication channel, and understand the complete risk ecosystem. A $2,000 “reinspection fee” may be small enough to escape executive attention. It is not small enough to escape the FCPA.

Categories
Blog

Security, Extortion, and the New Compliance Mandate in Cartel-Driven Markets

This blog continues our series on the ACI Forum on Cartels, TCOs, and Compliance in Latin America and why it is so timely. What we are seeing across the region is not simply another enforcement trend. It is a structural change in the way compliance officers, boards, legal departments, security teams, and business leaders must assess and manage risk. The issue is where security, extortion, compliance, and enterprise risk management now sit at the same table.

The key point is one that every compliance professional has heard after a failure: “We did not see that coming.” In most cases, that statement does not mean the risk was invisible. It means the organization was not looking in the right way. It had a preconceived view of its threat environment. It relied on familiar dashboards. It accepted old assumptions. It conducted a risk assessment that confirmed management’s beliefs rather than testing them. That is not a security problem alone. That is a compliance failure.

Cartel Risk Is Now an Enterprise Risk

The designation of certain cartels and criminal organizations as Foreign Terrorist Organizations and Specially Designated Global Terrorists has changed the risk conversation. Executive Order 14157 established a process for certain international cartels and other organizations to be designated as FTOs or SDGTs and described international cartels as a national security threat beyond traditional organized crime, including through infiltration of governments across the Western Hemisphere. OFAC also lists an alert on international cartels designated as FTOs and SDGTs as part of its counterterrorism sanctions resources. (OFAC)

For CCOs, this means cartel and TCO exposure cannot be treated as a regional security issue or as a one-time sanctions-screening exercise. It must be integrated into risk assessments, third-party management, contract review, internal controls, HR, community relations, logistics, government affairs, and crisis response.

True threat assessment begins by stepping back, looking at the full operating environment, and then breaking the risk down by function. The Department of Justice has made clear that compliance programs must be robust, well-resourced, and empowered, and that companies are expected to continuously review and update compliance programs to account for emerging risk factors. A static, annual, checklist-driven risk assessment is not fit for a cartel-driven operating environment.

THIRA as a Compliance Tool

One of the most useful concepts in the attached article is the use of Threat and Hazard Identification and Risk Assessment, or THIRA. THIRA began in the public-sector preparedness world, but its discipline translates well into corporate compliance. FEMA describes THIRA as a three-step risk assessment process that helps communities identify the risks of greatest concern and determine the capabilities needed to address them. FEMA also notes that identifying and assessing risk should be a key input into planning and that plans must be risk-informed.

For compliance professionals, that is the point. Do not begin with the control. Begin with the threat. What could happen? Who could exploit the business model? What routes, facilities, vendors, unions, brokers, security providers, customers, or local officials create exposure? What happens if a logistics route becomes unsafe, a vendor is coerced, a local union is compromised, a government permit is delayed unless a payment is made, or a security provider is connected to criminal actors?

THIRA-style analysis forces a company to model realistic scenarios, assess consequences, and then determine whether it can respond. That means authority, communications, escalation, training, legal review, security protocols, financial controls, and board reporting must all be stress-tested before the crisis.

Continuous Monitoring Is Not Optional

In ordinary compliance discussions, “continuous monitoring” can sound like a best practice phrase. In a high-threat environment, it is an operating necessity. The attached article notes that threats can change by the hour, routes can become unsafe, infrastructure can fail, and misinformation can spread intentionally.

The compliance parallel is direct. A company cannot rely only on lagging indicators, annual certifications, or publicly available reports. In cartel-influenced markets, yesterday’s intelligence can create today’s exposure. The risk function must have access to live operational data, hotline reports, security intelligence, payment anomalies, logistics disruptions, vendor changes, law enforcement alerts, and local business intelligence.

This also requires delegated authority. If compliance or security sees a threat but lacks authority to pause activity, reroute shipments, reject a vendor, escalate a payment, or stop a transaction, the program is underpowered. Policies without authority are not controls. They are artifacts.

The Board’s Role: Oversight, Not Assumption

Boards must also recalibrate. Duncan’s point that boards often understand risk exists but do not always understand their lane should resonate with every CCO. The board’s role is not to manage routes, approve security plans, or second-guess local threat intelligence. Its role is to ensure that management has identified the risk, defined risk tolerance, resourced the response, assigned authority, and created reliable reporting.

In cartel-driven markets, the board should ask, “Where are we operating in areas of criminal influence?” Which third parties are essential to those operations? How do we know they are not compromised? What payments, donations, sponsorships, logistics arrangements, or security relationships create exposure? What is our escalation protocol if an employee, vendor, union representative, community leader, or government official signals coercion?

Risk tolerance must be written, debated, approved, and revisited. Silence is not neutrality. It is permission.

Security Is a Compliance Function

The attached article makes another crucial point: security is not just physical. Insider threats, personal vulnerabilities, substance abuse, coercion, espionage, poor training, and cultural dysfunction all create compliance exposure. Employees must understand not only what the rules are but also why the rules matter and how criminal organizations exploit weak points.

In Venezuela, the State Department’s June 27, 2026, advisory tells travelers to reconsider travel because of crime, kidnapping, terrorism, poor health infrastructure, and natural disaster risk, and it identifies Tren de Aragua and Cartel de los Soles as FTOs that started in Venezuela and continue to operate. The same advisory states that the U.S. government has extremely limited capacity to provide emergency services to U.S. citizens, especially outside Caracas.  That is a board-level fact pattern. It affects duty of care, insurance, crisis response, employee travel, third-party security, incident reporting, and operational continuity.

Build the Threat Hub

The most practical recommendation is to create a threat hub. It should be a cross-functional forum where legal, finance, operations, security, compliance, and other functions review threats, vulnerabilities, and operational changes. This is precisely what mature compliance should look like in a high-risk market.

The threat hub should review incidents, routes, payments, vendor changes, customer anomalies, government interactions, community demands, employee reports, and security intelligence. It should have the authority to escalate. It should report to management and the board. It should test crisis plans through realistic exercises.

Practical takeaways

First, refresh the risk assessment now. Second, add THIRA-style scenario planning to cartel and TCO risk. Third, empower compliance and security to act in real time. Fourth, review third parties, major contracts, customers, logistics providers, unions, community intermediaries, and security vendors. Fifth, educate the board on its oversight role and require explicit risk tolerance.

The final lesson is simple. In high-threat markets, static programs fail. Assumptions kill preparedness. Authority matters. Culture is defined by what leaders tolerate. The choice for every company is whether to learn before or after the crisis.

This conversation makes clear that security, compliance, and risk are not separate disciplines. They are different lenses on the same problem: how organizations survive and succeed in uncertain environments. Security has taken on even greater importance in Venezuela as President Trump has announced the US will not provide any security to US companies returning to the country.

For compliance professionals, the takeaway is simple but uncomfortable. Static programs fail. Assumptions kill preparedness. Authority matters. Culture is shaped by what leaders tolerate. And boards must be educated partners, not distant overseers. In high-threat environments, failure is immediate and unforgiving. In corporate compliance, it is slower, but no less certain.

The choice, as always, is whether to learn before the crisis or after it.

The Cartels, TCOs & Compliance in Latin American conference will feature these topics and many more. For information and registration, click here. For the complete agenda, click here. You can receive 10% off the price by using the Discount Code D10-999-CPN26.

ACI is the sponsor of today’s blog.

Categories
Blog

Cartels, TCOs, and Compliance in Latin America: Why 2026 Is a Watershed Moment

For compliance professionals, some years mark an evolution. Others mark a turning point. In 2026, corporate compliance in Latin America has reached that turning point. For the past two decades, most companies approached regional risk through a familiar lens: anti-corruption. The focus was on government touchpoints, customs interactions, licensing, permits, state-owned enterprises, and third-party intermediaries. That framework is still important. But it is no longer sufficient.

Today, the risk landscape has expanded dramatically. Cartels, transnational criminal organizations, foreign terrorist organization designations, sanctions, anti-money laundering exposure, and supply chain infiltration have all moved to the center of the compliance conversation. What was once a specialized concern has become a board-level issue.

That is why the upcoming ACI Forum on Cartels, TCOs, and Compliance in Latin America is so timely. It is also why compliance officers need to understand that this is not simply another enforcement trend. It is a structural change in how risk must be assessed, governed, and managed. I recently had the opportunity to visit with Matt Ellis, Member at Miller & Chevalier and co-Chair of the Forum. You can listen to Ellis’ remarks on this episode of the FCPA Compliance Report on the Compliance Podcast Network.

The New Risk Equation

The Trump administration has made clear that cartels, fentanyl trafficking, organized crime, and the influence of China in Latin America are policy priorities. That focus has brought multiple enforcement tools to bear, including sanctions, anti-money laundering authorities, FTO designations, and a broader integration of these issues into the compliance and enforcement landscape.

Ellis said that companies, the old model of regional compliance risk must be rethought. The issue is no longer limited to whether a payment was made to a foreign official. The question now is whether a company’s supply chain, transportation provider, security arrangement, or local commercial partner could create exposure under anti-terrorism, sanctions, or AML frameworks.

Mexico Is the Opening Chapter, Not the Whole Book

Much of the current focus is on Mexico, and for good reason. That is where the enforcement spotlight is currently brightest. But compliance professionals should not make the mistake of thinking this challenge begins and ends there.

The risks extend across Latin America, including Central America, Venezuela, Colombia, Brazil, Panama, and other markets where cartel activity, organized crime influence, sanctions risk, or opaque commercial structures may create significant exposure. Each country carries its own risk profile, but the common lesson is clear. Mexico may be the first chapter, but it will not be the last.

For boards and executive teams, that means regional strategy must be reviewed through a broader lens. Market entry, third-party engagement, logistics routes, security providers, and local partnerships all need to be reassessed.

Why the Supply Chain Has Become a Compliance Flashpoint

One of the most important lessons from this discussion is that cartel risk can be embedded in the supply chain. This is where compliance professionals need to recalibrate their thinking. In the anti-corruption world, companies typically focus on agents, distributors, customs brokers, and other third parties that have direct government interactions. In the cartel and TCO context, risk can be embedded within ordinary business operations. Transportation vendors, warehouse providers, local suppliers, labor relationships, and security services may all present hidden risk if they are controlled by, connected to, or exploited by organized crime.

That changes the role of compliance. Procurement, logistics, operations, and security can no longer be treated as peripheral functions. They are now front-line participants in risk identification and mitigation. This is where the compliance function must show leadership. The CCO must bring these disciplines together and translate legal and enforcement developments into practical operational controls.

Due Diligence Must Move Beyond Check-the-Box

If there is one message compliance professionals should take from Ellis’ podcast, it is this: traditional due diligence is not enough. In anti-corruption compliance, companies have become skilled at identifying common red flags. They know how to screen for politically exposed persons, government connections, unusual payment terms, and opaque ownership structures. Those tools still matter, but they will not always surface cartel-linked risk. Organized crime does not announce itself in a database hit.

Instead, companies need a more nuanced and operationally grounded approach. Are there local security concerns being raised by employees? Are there unusual labor dynamics in a region where those patterns do not make commercial sense? Is there persistent chatter about a vendor, route, or business partner that cannot be ignored? Are operations in a community producing concerns that legal and compliance have not fully explored? These are not traditional diligence questions, but they are increasingly the right ones.

Under the DOJ’s Evaluation of Corporate Compliance Programs (ECCP), regulators continue to ask whether a company’s program is designed, implemented, and tested in a manner that addresses actual risk. This is precisely where program effectiveness will now be measured in high-risk operations in Latin America.

The Importance of Listening to the People on the Ground

One of the most practical insights from the interview was the emphasis on local intelligence. Employees who live and work in these communities often know far more than any desktop diligence report will reveal.

That point should resonate deeply with compliance professionals. A company’s speak-up culture is not simply about hotline metrics or case closure rates. It is about whether employees trust the organization enough to raise concerns that may not yet fit into a neat legal category. It is about whether the company listens when local personnel say that something does not add up. This is where compliance, culture, and internal controls intersect.

If a company has not built mechanisms to capture and escalate local concerns, then it is not simply missing information. It is missing one of the most effective risk detection tools available to it. These are not abstract governance questions. They go directly to program effectiveness, risk ownership, and business sustainability.

A Whole-of-Government Enforcement Model

Another important takeaway is the multidimensional nature of this risk environment. In the FCPA era, companies often focused on the DOJ and the SEC. That framework no longer captures the full picture. Now the compliance professional must think across Treasury, OFAC, FinCEN, Homeland Security, DEA, and other agencies, all of which may be interested in the same underlying conduct. This level of coordination matters because it means the government’s expectations are no longer siloed. Enforcement, intelligence, sanctions, and AML concerns can converge quickly. For compliance officers, this demands a more integrated risk management model. Silos within the company will not work when the government itself operates in a coordinated manner.

Is There More Room for Government Engagement?

One of the more interesting themes from the discussion was whether companies may have more room to engage with the government than they traditionally would in the anti-corruption context. That does not mean every issue should be self-disclosed. It does mean that in high-risk environments, thoughtful engagement may sometimes be part of a sound compliance strategy.

The key is judgment. No company should rush into a conversation with the government without understanding the facts and the implications. But where risks are ambiguous, stakes are high, and the legal regimes overlap, strategic dialogue may help demonstrate good faith, show the absence of criminal intent, and allow a company to explain the reasonable steps it is taking. That is not leniency. That is credibility.

The Bottom Line

This is the next generation of Latin America compliance risk. It does not replace anti-corruption compliance. It expands it, hardens it, and operationalizes it. The lesson for compliance professionals is clear. You cannot address cartel and TCO risk with yesterday’s playbook. You need broader risk assessments, deeper third-party diligence, stronger local reporting channels, tighter cross-functional coordination, and more informed board oversight.

In 2026, the companies that succeed will not be the ones with the longest policy manuals. They will be the ones who can demonstrate a compliance program built for the reality of where they operate. For the CCO, that is the challenge. For the board, that is the oversight mandate. For the business, that is the cost of operating responsibly in a changed enforcement environment. The future of compliance in Latin America is already here. The only question is whether your program is ready for it.

Check out the ACI Forum on Cartels, TCOs, and Compliance in Latin America by clicking here. You can receive a 10% off the price by using the Discount Code D10-999-CPN26.

ACI is the sponsor of today’s blog.