Categories
FCPA Compliance Report

Compliance into the Weeds: Scoular Company FCPA Settlement: Cartel Links, Border Trade Risks, and Compliance Lessons

The award-winning Compliance into the Weeds is the only weekly podcast that takes a deep dive into a compliance-related topic, literally going into the weeds to explore it more fully. Looking for some hard-hitting insights on compliance? Look no further than Compliance into the Weeds! In this episode of Compliance into the Weeds, Tom Fox and Matt Kelly discuss the recent FCPA resolution with the Scoular Company. Both Tom and Matt have blogged on this matter, so check out the Resources link below for additional discussions.

The recent FCPA enforcement action against Scoular Company involved a $10.2 million payment and a three-year deferred prosecution agreement over bribes by third-party customs brokers to Mexican border officials to expedite cross-border shipments. DOJ emphasized alleged cartel connections, including a strong statement from the U.S. Attorney for the Western District of Texas, which raised questions about expanded local U.S. attorney involvement and how cartel or potential FTO designations could heighten trade and compliance risks. The company received no voluntary self-disclosure credit but got a 25% discount, with remediation cited (including dropping brokers and strengthening tone at the top). They highlight off-channel WhatsApp use, the lack of released key documents (DPA, statement of facts, criminal information), and practical compliance takeaways on third-party oversight, data analytics, and risk assessments.

Resources:

Matt in Radical Compliance

Tom in FCPA Compliance and Ethics Blog

Tom

Instagram

Facebook

YouTube

Twitter

LinkedIn

A multi-award-winning podcast, Compliance into the Weeds was most recently honored as one of the Top 25 Regulatory Compliance Podcasts, a Top 10 Business Law Podcast, and a Top 12 Risk Management Podcast. Compliance into the Weeds has been conferred the Davey, Communicator, and W3 Awards, all for podcast excellence.

Categories
Blog

Scoular’s $10 Million FCPA Resolution: Compliance Lessons Learned

We conclude our review of the Scoular Company FCPA enforcement action with a full lessons-learned blog post. We are still awaiting the DPA and Criminal Information, so the details of the case come from the Department of Justice (DOJ) Press Release.

A $2,000 payment can disappear inside a global supply chain. Repeated, train-by-train, authorized by employees, routed through customs brokers, discussed on WhatsApp, disguised as a “reinspection fee,” and reimbursed for six years, it becomes an operating model. That is the central lesson from The Scoular Company Foreign Corrupt Practices Act resolution.

The DOJ announced that Scoular Company would pay more than $10 million to resolve an investigation into bribes paid to Mexican officials between 2013 and 2019. The company entered into a three-year deferred prosecution agreement, agreed to a $9,769,521 criminal penalty and $414,351 in forfeiture, and accepted continuing cooperation, compliance, and reporting obligations.

Across this blog post series, we examined four dimensions of the case: customs brokers and payment controls, cartel and national-security risk, off-channel communications, and the facilitating-payments exception. Read together with my podcast conversation with Matt Ellis, they reveal a single conclusion. Compliance must follow the complete transaction, from the business pressure that creates the payment to the third party that delivers it, the message that authorizes it, the invoice that conceals it, and the ultimate recipient who benefits.

The Scheme Hid in Plain Sight

According to the DOJ, Scoular Company relied on customs brokers to move corn and other agricultural products from the United States into Mexico. Mexican authorities inspected the shipments for dirt, soil, and other impurities. When inspections identified problems, Scoular Company employees directed brokers to pay officials approximately $2,000 per train so the shipments could cross the border. The brokers invoiced the payments back to Scoular Company as “reinspection fees,” and Scoular paid them. In total, the company authorized more than $400,000 in bribes and avoided more than $6.5 million in fees and costs.

The invoice description is the first major lesson. “Reinspection fee” sounded like it was connected to a legitimate customs process. Yet an accounts-payable control that merely matches an approved vendor, purchase order, and plausible service description tests paperwork, not substance.

Effective payment controls should require the company to identify the government agency involved, match the charge to a specific shipment and inspection, compare the amount with an official fee schedule, obtain proof of service, confirm the payee, and document the business justification. Repeated round-dollar charges, unusual success rates, rapid clearance after special payments, and fees unsupported by government records should trigger review.

Follow the money, measure the time, and test the outcome. That is how ordinary transaction data becomes an anti-corruption control.

A Licensed Broker Is Still a High-Risk Third Party

Customs brokers should never be treated as low-risk administrative providers simply because they are licensed or legally required. They interact with government officials, operate under commercial pressure, and can impose charges that distant finance personnel cannot easily verify.

Initial due diligence remains necessary, but it is only the beginning. Companies must connect screening, contracting, invoice testing, transaction monitoring, recertification, training, audit rights, and offboarding. The real test is not whether the third-party file was complete on the day of onboarding. It is whether the company understands how the broker behaves after the contract is signed.

The DOJ credited Scoular Company with eliminating brokers associated with the Mexican reinspection payments, strengthening risk-based screening and approvals, adding anti-corruption and audit-rights provisions, revising controls for high-risk transactions, and using software tools to improve monitoring. That remediation changed the operating model rather than merely revising a policy.

Cartel Risk Changes the Compliance Perimeter

The most consequential part of the DOJ announcement may be its national-security framing. The government determined that, without Scoular Company or its employees knowing it, a portion of the bribes benefited persons associated with a cartel’s criminal operations at the U.S.-Mexico border.

U.S. Attorney Justin R. Simmons stated that American companies engaged in cross-border trade bear responsibility for operating without benefiting cartels or threatening national security. Ellis challenged the literal breadth of the statement during our podcast discussion. Legitimate trade crosses the border every day without companies knowingly paying cartels. Nevertheless, he agreed that the statement signals a more demanding compliance environment.

Ellis explained that the cartel and transnational criminal organization risk is broader than the traditional FCPA risk. Anti-corruption diligence often concentrates on government touchpoints and intermediaries. Organized crime may be hidden inside transportation providers, suppliers, customers, labor relationships, security services, subcontractors, and local routes.

Traditional database screening may not reveal those connections. Ellis emphasized contextual diligence: speak with employees on the ground, examine local security concerns, understand regional criminal activity, investigate facts that do not add up, and adjust operations when warning signs emerge. Companies do not need perfect knowledge. They need a documented story of reasonable measures, credible escalation, and risk-based decisions.

The practical consequence is an integrated risk assessment. Anti-corruption, sanctions, anti-money laundering, trade compliance, physical security, supply chain, and third-party risk cannot remain in separate silos when the same payment may touch all of them.

WhatsApp Was Part of the Control Environment

The DOJ said Scoular Company employees communicated about shipments and bribes through WhatsApp and other means. WhatsApp was therefore not a side issue. It allegedly carried the knowledge and direction behind transactions later recorded as legitimate reinspection charges.

An informal application becomes a business system when employees use it to direct third parties, approve payments, or resolve customs problems. Enterprise controls can be bypassed when the substantive decision occurs in a private chat, and the formal system records only the sanitized result.

Ellis noted that a complete WhatsApp ban may be unrealistic in Latin America. The better approach is to map actual use and define what may occur on each platform. Logistical coordination may be permitted. Government interactions, payment approvals, contractual commitments, and exceptions should remain in controlled systems with retention and audit trails.

Companies must also be able to preserve and retrieve business communications lawfully from company and personal devices. Policies should address device replacement, departing employees, legal holds, privacy and employment requirements, refusal of access, and consistent discipline. The decisive question is not whether a policy exists. It is whether the company can obtain the evidence when an investigation begins.

Why These Were Not Facilitation Payments

The $2,000 amount and the customs setting may tempt employees to use the phrase “facilitation payment.” That label does not fit. The FCPA’s narrow exception covers payments intended to expedite routine, nondiscretionary governmental action that the payer is already entitled to receive. Scheduling an inspection may be routine. Paying an official to disregard a failed inspection is not.

The Scoular Company payments allegedly changed the result. The shipments had identified impurities, and the payments allowed trains to cross despite those findings. The company received a substantial business advantage by avoiding more than $6.5 million in costs. A facilitation payment is not defined by size, local custom, commercial urgency, or invoice terminology. A third party cannot create an exception unavailable to the principal. Nor does an anti-bribery exception excuse false accounting. Even a qualifying payment must be accurately recorded and supported by adequate internal controls.

Ellis’s discussion of extortion reinforces the operational lesson, although extortion and facilitation are distinct doctrines. One or two emergency payments may present a different analysis from a chain of payments continuing over years. Repetition transforms an asserted accommodation into a business process. Companies must respond by escalating, rerouting, changing providers, investigating, and remediating.

Cooperation Still Matters

Scoular Company did not receive voluntary self-disclosure credit because it did not report the conduct to the DOJ in a timely manner. It did receive cooperation credit for its internal investigation, factual presentations, identification of involved individuals, production and organization of evidence, and provision of counsel for current employees, despite early deficiencies.

The resulting criminal penalty reflected a 25 percent reduction from the bottom of the applicable sentencing guidelines range. The lesson is straightforward. Missing the voluntary disclosure window does not render later cooperation irrelevant, but cooperation is not a substitute for timely self-disclosure. The Scoular Company resolution is not four separate compliance stories. It is one story about how pressure, third parties, communications, accounting, and emerging national-security risks converged inside an ordinary business process.

The enduring lesson is equally integrated: know the broker, validate the payment, preserve the message, understand the route, and test the outcome. That is how compliance moves from policy to proof.

Categories
Blog

Nothing Crosses the Border: Scoular and the New Compliance Burden for Mexico Supply Chains

“Nothing crosses into or out of Mexico without the approval and payment to Mexican drug cartels. American businesses that engage in any cross-border trade bear a significant amount of responsibility to do so without benefitting those cartels and without threatening our national security,” said U.S. Attorney Justin R. Simmons for the Western District of Texas. “The bribery scheme in which the Scoular Company engaged demonstrates the dangerous corporate corruption we in the Western District of Texas are committed to fighting on behalf of the American people.”

This is not a quote from The Onion, but it is an extraordinary statement from a United States Attorney. It is not confined to companies that knowingly pay cartels. It is not limited to businesses operating in cartel-controlled industries. It speaks broadly to American companies engaged in cross-border trade with Mexico.

The statement appeared in the Department of Justice’s Press Release announcing that The Scoular Company would pay more than $10 million to resolve an FCPA investigation involving payments to Mexican officials. According to the DOJ, customs brokers paid approximately $2,000 per train to allow shipments of corn and other products to cross the border despite inspections identifying dirt, soil, and other impurities. The payments were invoiced back to Scoular as “reinspection fees.” The enforcement message extends far beyond Scoular. Every U.S. company importing goods from Mexico should take notice.

Cartels and the UFLPA

One of the few laws that demands such an approach is the Uyghur Forced Labor Prevention Act (UFLPA), which targets goods made, whole or in part, by forced labor in the Xinjiang region of China or made by forced labor in other parts of China by Uighurs or other minorities. It is designed to operate as a de facto trade ban on goods from China’s Jing Jang region. US businesses will face a heavy burden to overcome the presumption of forced labor. It is perhaps the most significant US law addressing forced labor, and it has the most tangible repercussions companies can face. Under the UFLPA, the key is your documentation for US Customs and Border Protection. Travis Miller has noted that this means if you are “asking companies to look back into where the actual sand came from that got turned into the silica, that got turned into the semiconductor, that got turned into the circuit board, that got turned into the device that finds its way into your laptop. There’s just never been anything like it.”

The UFLPA and its guidance weave together existing business processes. The UFLPA emerged from the America Supply Chain Executive Order in the US/China trade war, which focused on semiconductors, critical raw materials, and elements that are the subject of the extractives. To comply with it, you could not actually start unless you already had a product compliance program in place. This means that if you do not know the bill of materials, do not have an approved vendor list, or do not know where your components are manufactured, you cannot prove compliance. This may well be the approach the Trump Administration takes under FTOs in Mexico and other locations in Central and Latin America.

Is Every Cross-Border Company Benefiting a Cartel?

In my podcast discussion with Matt Ellis, Latin America Practice Lead at Miller & Chevalier, Ellis challenged the literal breadth of the government’s statement. He noted that companies move legitimate goods between the United States and Mexico every hour without knowingly benefiting drug cartels. It would be inaccurate to conclude that every cross-border transaction involves a cartel payment.

Nevertheless, Ellis called the statement striking. He raised the question every CCO should now be considering: Is the DOJ establishing a new compliance standard for companies doing business across the U.S.-Mexico border? The statement does not create a new statute, regulation, or formal presumption of liability. Yet prosecutorial statements communicate enforcement expectations. Here, the expectation appears to be that American businesses must understand not only who their immediate third parties are, but also whether their supply chain activities could provide economic benefits to organized crime.

That puts pressure on importers in three ways. First, companies may face greater scrutiny over customs brokers, logistics providers, trucking companies, warehouses, security providers, labor organizations, and other parties supporting Mexican operations. Second, companies may be expected to investigate the downstream destination of payments, even when there is no obvious cartel connection. Third, the government may examine whether compliance programs integrate anti-corruption controls with sanctions, anti-money laundering, trade compliance, supply chain security, and organized-crime risk.

The question will no longer be limited to whether the company intended to pay a bribe. Prosecutors may also ask whether the company reasonably understood the environment in which its money and goods were moving.

Traditional Third-Party Due Diligence May Not Be Enough

Ellis made one of the most important observations of our discussion: standard third-party screening may not identify cartel connections. Conventional anti-corruption due diligence focuses heavily on government-facing intermediaries. Companies screen owners and principals, search adverse media, identify politically exposed persons, review government relationships, obtain certifications, and include anti-corruption language in contracts. Those measures remain necessary. They may not be sufficient for organized-crime risk.

Cartel affiliations are rarely disclosed in a corporate registry. A logistics provider may appear legitimate while making payment for protection. A trucking company may operate in a region controlled by a criminal organization. A supplier may use subcontractors with undisclosed local connections. A customer, warehouse, labor group, or security provider may be vulnerable to criminal infiltration.

This means companies should broaden the universe of third parties subject to risk-based review. For Mexican supply chains, that universe may include:

  • Suppliers
  • Customers
  • Customs brokers
  • Freight forwarders
  • Trucking companies
  • Warehouses
  • Security companies
  • Local consultants
  • Port and terminal service providers
  • Labor contractors
  • Union representatives
  • Subcontractors
  • Last-mile transportation providers

The legal requirement to use a licensed customs broker should not reduce scrutiny. As Ellis noted, mandatory licensing can sometimes create a false sense of security. A government license does not replace a company’s responsibility to understand how the broker operates.

Contextual Due Diligence Becomes Essential

If database screening cannot reliably identify cartel connections, companies need a contextual approach. This begins by examining where the third party will operate and what criminal activity is associated with that region. Relevant questions include:

  • Is the location known for cartel activity?
  • Are particular highways or transportation corridors subject to roadblocks or protection payments?
  • Is the region associated with fentanyl production, human trafficking, fuel theft, cargo theft, or smuggling?
  • Are unusual labor or union arrangements present?
  • Does the vendor use subcontractors that have not been disclosed?
  • Are payment requests made in cash or to unrelated accounts?
  • Is the third party reluctant to explain its security or transportation arrangements?
  • Does the third party promise an unrealistic customs clearance rate?
  • Are employees instructed not to ask questions about local payments?

Companies must also listen to their employees on the ground. Local personnel may understand risks that do not appear in formal databases. They know the regional rumors, transportation practices, local power structures, and third parties that other companies avoid.

This presents another compliance challenge. Local employees may fear retaliation if they report suspected cartel connections. A company’s speak-up system must provide credible confidentiality, escalation, and protection measures. A hotline is not enough if employees believe that raising a concern will endanger them or their families.

The New Standard Is Demonstrable Reasonableness

Companies cannot guarantee that no peso in a complex Mexican supply chain will ever reach a cartel-affiliated person. Prosecutors should not expect the impossible. They can expect companies to identify their risks, conduct reasonable diligence, monitor high-risk transactions, respond to warning signs, preserve relevant communications, and improve controls when new information emerges.

That is the pressure created by the Scoular resolution. Companies must be able to demonstrate that they made a serious, documented, and risk-based effort to prevent their operations from benefiting criminal organizations. The compliance burden is moving from a narrow inquiry into government-facing intermediaries toward a broader examination of the entire supply chain ecosystem.

Actions for CCOs

CCOs should consider five immediate steps:

  1. Expand Mexico-related risk assessments beyond traditional FCPA intermediaries.
  2. Map the complete supply chain, including subcontractors and transportation routes.
  3. Test customs-broker invoices and recurring border-related payments.
  4. Incorporate regional cartel intelligence and local employee knowledge into due diligence.
  5. Brief the board on the convergence of corruption, sanctions, organized crime, and national security risk.

The Scoular resolution does not establish that every company importing goods from Mexico is paying a cartel. It does put every such company on notice that the DOJ may ask what it did to make sure it was not. That is a significant change in compliance expectations. But look to your response to the UFLPA and see if you can find guidance from that compliance issue. Regardless, companies need to respond accordingly.

Categories
FCPA Compliance Report

FCPA Compliance Report: The Scoular FCPA Enforcement Action: Customs Bribes, Cartel Links, and New Compliance Expectations

Welcome to the award-winning FCPA Compliance Report, the longest-running podcast in compliance. In this episode, Tom welcomes back Matt Ellis to discuss a newly announced FCPA enforcement action involving Scoular Company.

The case invoiced about $400,000 in payments labeled as “reinspection fees” to Mexican customs and food inspectors to move agricultural goods across the Mexico–U.S. border. border, allegedly generating over $6.5 million in avoided costs and raising concerns about cartel-linked beneficiaries. They discuss why customs and customs brokers are recurring high-risk areas in Mexico, how long-running employee involvement suggests broader controls and tone-from-the-top failures, and why these payments are not facilitation payments under Mexican law and given discretionary official acts. Ellis emphasizes analytics on customs documents and broker invoices, stronger third-party diligence beyond traditional screening to address cartel/TCO risks, and defensible governance for WhatsApp/off-channel communications. Despite no voluntary self-disclosure, the company received cooperation credit and a 25% fine reduction, and Ellis previews an ACI conference focused on cartels, TCOs, and compliance in Latin America.

Key highlights:

  • Border Bribes and Safety Risks
  • Controls Failures and Monitoring
  • Data Analytics Red Flags
  • Facilitation Payment Myth
  • DOJ Cartel Warning and Implications
  • Rethinking Due Diligence for Cartels
  • WhatsApp and Messaging Governance
  • Cooperation, Credit, and Remediation

Resources:

Cartels, TCOs and Compliance in Latin America, July 20-21

Matt Ellis on LinkedIn

Tom Fox

Instagram

Facebook

YouTube

Twitter

LinkedIn

The FCPA Compliance Report was recently named the world’s best business ethics podcast by FeedSpot.

Categories
Blog

Scoular’s $10 Million FCPA Resolution: When a “Re-inspection Fee” Becomes a Bribe

A $2,000 payment can look insignificant inside a global supply chain. Repeated train by train, approved by employees, routed through customs brokers, disguised on invoices, and paid for six years, it becomes something else entirely. For The Scoular Company, it became a Foreign Corrupt Practices Act enforcement action carrying more than $10 million in penalties and forfeiture, a three-year deferred prosecution agreement, continuing cooperation obligations, and periodic reporting to the Department of Justice.

The case is an important warning for every company engaged in cross-border trade. Customs brokers are not merely logistics providers. Border payments are not merely operational expenses. A mislabeled invoice is not merely an accounting problem. Each may represent an interconnected risk across anti-corruption, internal control, third-party, and national security.

The Scheme: $2,000 per Train

According to the DOJ Press Release (the full DPA is not yet available), between 2013 and 2019, Scoular used customs brokers to move shipments of corn and other agricultural products from the United States to Mexico. Mexican authorities inspected those shipments for dirt, soil, and other impurities. When inspectors identified problems, Scoular’s customs brokers allegedly paid Mexican officials approximately $2,000 per train to ensure that the shipments crossed the border.

The brokers then invoiced those payments back to Scoular as “reinspection fees.” Scoular paid the invoices. This was not an isolated facilitation payment or a rogue third party operating beyond the company’s knowledge. According to the court documents, Scoular employees authorized the payments, directed the brokers, and communicated about the shipments and bribes through WhatsApp and other channels.

The numbers demonstrate the business impact:

  • More than $400,000 in bribes authorized
  • More than $6.5 million in avoided fees and costs
  • A $9,769,521 criminal penalty
  • $414,351 in forfeiture
  • A three-year DPA

The company was charged with conspiracy to violate the FCPA’s anti-bribery provisions.

The Invoice Description Was a Compliance Red Flag

The phrase “reinspection fee” should be at the center of every compliance discussion about this case. The brokers did not invoice Scoular for bribes. They used a description that appeared facially connected to a legitimate customs process. That description allowed the payments to move through the company’s financial system.

This is how corruption frequently enters the books and records. It appears as:

  • Expediting fees
  • Administrative charges
  • Local processing costs
  • Customs support
  • Special handling
  • Reinspection fees
  • Consulting services

The compliance question is not whether the description sounds legitimate. The question is whether the company can establish what service was performed, who performed it, why the payment was necessary, how the amount was calculated, and who ultimately received the money. Accounts payable controls that merely match an invoice to a purchase order will not detect this type of scheme. Effective controls must examine the commercial substance of high-risk payments.

For customs-related expenses, companies should require supporting government documentation, published fee schedules, proof of service, payment to an authorized government account where appropriate, and enhanced approval for unusual or recurring charges.

Third-Party Due Diligence Is Only the Beginning

The Scoular resolution also demonstrates the limits of onboarding due diligence. A company can screen a customs broker, obtain certifications, execute an anti-corruption clause, and still face substantial FCPA exposure. The real question is what happens after the third party begins work. The answer is that the real work of compliance begins when the third-party contract is signed.

Customs brokers operate at the intersection of government interaction, time-sensitive business demands, discretionary enforcement, and local pressure. That makes them inherently high risk. An effective third-party management program should connect the following:

  • Initial due diligence
  • Contractual controls
  • Transaction monitoring
  • Invoice testing
  • Business justification
  • Periodic recertification
  • Audit rights
  • Compliance training
  • Offboarding decisions

The DOJ credited Scoular for strengthening risk-based screening and approval requirements, adding anti-corruption and audit-right provisions to contracts, and improving monitoring procedures. The company also eliminated customs brokers associated with the Mexican reinspection payments. Due diligence is not and cannot remain a static file. It must become a continuing control system tied to actual payments and operational conduct.

WhatsApp Was Part of the Business Process

Scoular employees allegedly communicated about the shipments and payments through WhatsApp and other channels. This fact should concern every CCO. When employees use personal devices or ephemeral messaging platforms to conduct high-risk business, the company may lose visibility into precisely the communications it most needs to monitor, preserve, and produce.

The answer is not necessarily to prohibit every messaging application. The answer is to establish a defensible governance model addressing the following:

  • Permitted communication platforms
  • Business-record retention
  • Preservation during investigations
  • Access to relevant communications
  • Training for high-risk employees
  • Monitoring based on legal and privacy requirements
  • Consequences for circumventing approved systems

A policy without technical controls, employee training, and consistent enforcement is unlikely to satisfy prosecutors. Messaging governance must reflect how employees actually conduct business.

Corruption Is Now a National Security Issue

The most significant feature of the case may be the DOJ’s treatment of cartel risk. The government determined that a portion of the bribe payments ultimately benefited individuals associated with a cartel operating at the U.S.-Mexico border. The DOJ stated that neither Scoular nor its employees knew about that connection. That lack of knowledge did not eliminate the seriousness of the issue.

Indeed, in the DOJ Press Release, U.S. Attorney Justin R. Simmons for the Western District of Texas was quoted as follows, “Nothing crosses into or out of Mexico without the approval and payment to Mexican drug cartels.” Further, any American businesses that engage in any cross-border trade bear a significant amount of responsibility to do so without benefitting those cartels and without threatening our national security.”

The enforcement message is clear: companies operating in high-risk border regions must consider where third-party payments may ultimately flow. A payment intended to resolve a customs problem can expose a party to corruption, money laundering, sanctions, organized crime, and national security risks. This means anti-corruption risk assessments can no longer operate in isolation. Compliance teams should integrate information from the following:

  • Anti-money laundering reviews
  • Sanctions screening
  • Security functions
  • Trade compliance
  • Supply chain risk management
  • Third-party intelligence
  • Government investigations
  • Adverse media monitoring

The government is examining the complete risk created by a payment, not merely the employee’s immediate objective.

No Voluntary Disclosure Credit, but Meaningful Cooperation Credit

Scoular did not receive voluntary self-disclosure credit because it did not promptly report the conduct to the DOJ Fraud Section. It did, however, receive credit for cooperation. The DOJ cited Scoular’s internal investigation, factual presentations, identification of individuals involved, document production, organization of evidence, and provision of counsel for current employees. The DOJ also acknowledged deficiencies during the early stages of the investigation.

After considering the company’s cooperation and remediation, the DOJ imposed a criminal penalty reflecting a 25 percent reduction from the bottom of the applicable sentencing guidelines range. This is a valuable lesson in enforcement mathematics. Missing the opportunity for voluntary disclosure does not make subsequent cooperation irrelevant. Companies can still improve outcomes through credible investigation, evidence preservation, individual accountability, timely remediation, and the organized production of information.

Yet cooperation credit is not the equivalent of voluntary disclosure credit. The decision window following discovery of potential misconduct remains critical.

Remediation Must Change the Operating Model

Scoular’s remediation went beyond issuing a new policy. According to the DOJ, the company:

  • Conducted an external compliance maturity assessment and anti-corruption risk assessment
  • Restructured its compliance function
  • Increased senior leadership oversight
  • Eliminated brokers connected to the payments
  • Strengthened risk-based monitoring through software tools
  • Revised its Code of Conduct and key compliance policies
  • Improved third-party screening and approvals
  • Added anti-corruption and audit-rights provisions
  • Revised financial controls for high-risk transactions
  • Delivered general and targeted anti-corruption training

This is the type of remediation contemplated by the DOJ’s Evaluation of Corporate Compliance Programs. It addresses root causes, resources, governance, controls, technology, training, and business ownership.

The key is operational impact. The company must be able to demonstrate that the same conduct could not pass through the organization today without being detected or escalated.

Questions for CCOs

CCOs should ask:

  • Do recurring payments cluster around specific ports, brokers, officials, products, or inspection events?
  • Are vague payment descriptions automatically escalated?
  • Does compliance have access to customs, logistics, and accounts payable data?
  • Are high-risk brokers periodically reviewed after onboarding?
  • Has the company tested whether audit rights can actually be exercised?
  • Is there a rapid escalation process for deciding whether potential misconduct should be voluntarily disclosed?

The Bottom Line

The Scoular case was not simply about customs brokers paying officials. It was about an operational process that allegedly normalized bribery, an invoicing system that disguised the payments, employees who communicated through informal channels, and third-party funds that ultimately touched cartel-linked actors.

For compliance professionals, the lesson is direct: follow the payment, test the business justification, examine the communication channel, and understand the complete risk ecosystem. A $2,000 “reinspection fee” may be small enough to escape executive attention. It is not small enough to escape the FCPA.

Categories
Blog

Security, Extortion, and the New Compliance Mandate in Cartel-Driven Markets

This blog continues our series on the ACI Forum on Cartels, TCOs, and Compliance in Latin America and why it is so timely. What we are seeing across the region is not simply another enforcement trend. It is a structural change in the way compliance officers, boards, legal departments, security teams, and business leaders must assess and manage risk. The issue is where security, extortion, compliance, and enterprise risk management now sit at the same table.

The key point is one that every compliance professional has heard after a failure: “We did not see that coming.” In most cases, that statement does not mean the risk was invisible. It means the organization was not looking in the right way. It had a preconceived view of its threat environment. It relied on familiar dashboards. It accepted old assumptions. It conducted a risk assessment that confirmed management’s beliefs rather than testing them. That is not a security problem alone. That is a compliance failure.

Cartel Risk Is Now an Enterprise Risk

The designation of certain cartels and criminal organizations as Foreign Terrorist Organizations and Specially Designated Global Terrorists has changed the risk conversation. Executive Order 14157 established a process for certain international cartels and other organizations to be designated as FTOs or SDGTs and described international cartels as a national security threat beyond traditional organized crime, including through infiltration of governments across the Western Hemisphere. OFAC also lists an alert on international cartels designated as FTOs and SDGTs as part of its counterterrorism sanctions resources. (OFAC)

For CCOs, this means cartel and TCO exposure cannot be treated as a regional security issue or as a one-time sanctions-screening exercise. It must be integrated into risk assessments, third-party management, contract review, internal controls, HR, community relations, logistics, government affairs, and crisis response.

True threat assessment begins by stepping back, looking at the full operating environment, and then breaking the risk down by function. The Department of Justice has made clear that compliance programs must be robust, well-resourced, and empowered, and that companies are expected to continuously review and update compliance programs to account for emerging risk factors. A static, annual, checklist-driven risk assessment is not fit for a cartel-driven operating environment.

THIRA as a Compliance Tool

One of the most useful concepts in the attached article is the use of Threat and Hazard Identification and Risk Assessment, or THIRA. THIRA began in the public-sector preparedness world, but its discipline translates well into corporate compliance. FEMA describes THIRA as a three-step risk assessment process that helps communities identify the risks of greatest concern and determine the capabilities needed to address them. FEMA also notes that identifying and assessing risk should be a key input into planning and that plans must be risk-informed.

For compliance professionals, that is the point. Do not begin with the control. Begin with the threat. What could happen? Who could exploit the business model? What routes, facilities, vendors, unions, brokers, security providers, customers, or local officials create exposure? What happens if a logistics route becomes unsafe, a vendor is coerced, a local union is compromised, a government permit is delayed unless a payment is made, or a security provider is connected to criminal actors?

THIRA-style analysis forces a company to model realistic scenarios, assess consequences, and then determine whether it can respond. That means authority, communications, escalation, training, legal review, security protocols, financial controls, and board reporting must all be stress-tested before the crisis.

Continuous Monitoring Is Not Optional

In ordinary compliance discussions, “continuous monitoring” can sound like a best practice phrase. In a high-threat environment, it is an operating necessity. The attached article notes that threats can change by the hour, routes can become unsafe, infrastructure can fail, and misinformation can spread intentionally.

The compliance parallel is direct. A company cannot rely only on lagging indicators, annual certifications, or publicly available reports. In cartel-influenced markets, yesterday’s intelligence can create today’s exposure. The risk function must have access to live operational data, hotline reports, security intelligence, payment anomalies, logistics disruptions, vendor changes, law enforcement alerts, and local business intelligence.

This also requires delegated authority. If compliance or security sees a threat but lacks authority to pause activity, reroute shipments, reject a vendor, escalate a payment, or stop a transaction, the program is underpowered. Policies without authority are not controls. They are artifacts.

The Board’s Role: Oversight, Not Assumption

Boards must also recalibrate. Duncan’s point that boards often understand risk exists but do not always understand their lane should resonate with every CCO. The board’s role is not to manage routes, approve security plans, or second-guess local threat intelligence. Its role is to ensure that management has identified the risk, defined risk tolerance, resourced the response, assigned authority, and created reliable reporting.

In cartel-driven markets, the board should ask, “Where are we operating in areas of criminal influence?” Which third parties are essential to those operations? How do we know they are not compromised? What payments, donations, sponsorships, logistics arrangements, or security relationships create exposure? What is our escalation protocol if an employee, vendor, union representative, community leader, or government official signals coercion?

Risk tolerance must be written, debated, approved, and revisited. Silence is not neutrality. It is permission.

Security Is a Compliance Function

The attached article makes another crucial point: security is not just physical. Insider threats, personal vulnerabilities, substance abuse, coercion, espionage, poor training, and cultural dysfunction all create compliance exposure. Employees must understand not only what the rules are but also why the rules matter and how criminal organizations exploit weak points.

In Venezuela, the State Department’s June 27, 2026, advisory tells travelers to reconsider travel because of crime, kidnapping, terrorism, poor health infrastructure, and natural disaster risk, and it identifies Tren de Aragua and Cartel de los Soles as FTOs that started in Venezuela and continue to operate. The same advisory states that the U.S. government has extremely limited capacity to provide emergency services to U.S. citizens, especially outside Caracas.  That is a board-level fact pattern. It affects duty of care, insurance, crisis response, employee travel, third-party security, incident reporting, and operational continuity.

Build the Threat Hub

The most practical recommendation is to create a threat hub. It should be a cross-functional forum where legal, finance, operations, security, compliance, and other functions review threats, vulnerabilities, and operational changes. This is precisely what mature compliance should look like in a high-risk market.

The threat hub should review incidents, routes, payments, vendor changes, customer anomalies, government interactions, community demands, employee reports, and security intelligence. It should have the authority to escalate. It should report to management and the board. It should test crisis plans through realistic exercises.

Practical takeaways

First, refresh the risk assessment now. Second, add THIRA-style scenario planning to cartel and TCO risk. Third, empower compliance and security to act in real time. Fourth, review third parties, major contracts, customers, logistics providers, unions, community intermediaries, and security vendors. Fifth, educate the board on its oversight role and require explicit risk tolerance.

The final lesson is simple. In high-threat markets, static programs fail. Assumptions kill preparedness. Authority matters. Culture is defined by what leaders tolerate. The choice for every company is whether to learn before or after the crisis.

This conversation makes clear that security, compliance, and risk are not separate disciplines. They are different lenses on the same problem: how organizations survive and succeed in uncertain environments. Security has taken on even greater importance in Venezuela as President Trump has announced the US will not provide any security to US companies returning to the country.

For compliance professionals, the takeaway is simple but uncomfortable. Static programs fail. Assumptions kill preparedness. Authority matters. Culture is shaped by what leaders tolerate. And boards must be educated partners, not distant overseers. In high-threat environments, failure is immediate and unforgiving. In corporate compliance, it is slower, but no less certain.

The choice, as always, is whether to learn before the crisis or after it.

The Cartels, TCOs & Compliance in Latin American conference will feature these topics and many more. For information and registration, click here. For the complete agenda, click here. You can receive 10% off the price by using the Discount Code D10-999-CPN26.

ACI is the sponsor of today’s blog.

Categories
Blog

Cartels, Extortion, and the New FCPA Risk: Lessons from Millicom

For years, many companies treated cartel risk as a security issue rather than a compliance issue. That view is no longer sufficient. In Mexico, Central America, and Brazil, organized criminal groups do not simply threaten operations from outside the company. They can infiltrate markets through corrupted officials, cartel-linked intermediaries, compromised law enforcement, logistics providers, bankers, community leaders, and local political actors. This will be a significant topic at the upcoming ACI Cartels, TCOs & Compliance Conference in Latin America next month in Washington, D.C.

That is why the Millicom Cellular FCPA enforcement action is such an important enforcement lesson. The case was not simply about bribes paid to government officials. It was about the convergence of bribery, cartel money, cash controls, joint venture governance failures, political influence, money laundering, and accounting controls. The DOJ stated that TIGO Guatemala paid more than $118 million to resolve a long-running bribery investigation involving monthly cash bribes to Guatemalan members of Congress and that some cash used for bribe payments came from laundered narcotrafficking proceeds.

The Crossover Risk: When Cartel Risk Becomes FCPA Risk

The most dangerous risk is not always the obvious cartel member with a gun. It may be the official who is cartel-affiliated, cartel-controlled, cartel-compromised, or operating in a cartel-controlled territory. That person may hold a municipal permit, customs role, police function, legislative position, procurement seat, or regulatory gatekeeper role. For the company, the question is not only whether the demand comes from a public official. It is about whether the demand sits within a criminal ecosystem that can convert ordinary business activity into FCPA, AML, sanctions, books-and-records, internal controls, and even material support risks.

Mexico shows the point clearly. OSAC has warned that several Mexican transnational criminal organizations were designated as Foreign Terrorist Organizations and Specially Designated Global Terrorists and that paying extortion demands, including derecho de piso, can create material support concerns for U.S. organizations. Brazil presents a different but equally serious model. The U.K. Home Office reported that Brazil has more than 80 organized criminal groups, including the PCC and Comando Vermelho (CV), and that militia groups made up of current and former state agents extort populations under their control.

The US Treasury Department has described PCC as one of the largest organized crime groups in Latin America, involved in money laundering, extortion, murder-for-hire, and drug debt collection. Indeed, in May 2026, the US State Department designated both the PCC and CV as Foreign Terrorist Organizations.

Central America adds another layer. In a regional Extortion Report, the Global Initiative Against Transnational Organized Crime noted that corruption within state institutions is pervasive and that security officials may use institutional power to extort, while collusion by corrupt officials sustains extortion markets. That is the crossover risk for companies: the same demand can be an extortion event, a corruption event, and an accounting controls event.

Bribery Versus Extortion

The difference between a bribe and extortion is not always intuitive, but it is critical. A bribe is a corrupt payment made to obtain or retain business, secure an improper advantage, influence an official act, or induce the misuse of an official position. The payment can be requested by the official first. The fact that the official demanded the payment does not automatically make it extortion under the FCPA. The FCPA Resource Guide, 2nd edition, explains that corrupt intent exists when a payment is intended to induce the recipient to misuse an official position, including to obtain preferential legislation or regulations.

True extortion or duress is different. The FCPA Resource Guide states that payments made in response to true extortionate demands under imminent threat of physical harm do not give rise to FCPA liability because they are not made with corrupt intent or for the purpose of obtaining or retaining business. But the same guidance draws a hard line: mere economic coercion does not amount to extortion. A payment demanded as the price of market entry or contract award remains a bribery risk because the company can decide not to pay.

That distinction matters in cartel-heavy environments. A payment to stop an immediate threat to employees may be a duress-driven safety response. A payment to obtain a permit, avoid a regulatory delay, secure customs clearance, influence a municipal inspection, or win a contract is not transformed into lawful conduct merely because the official made the demand aggressively.

Derecho de Piso and Derecho de Paso

Derecho de Piso is generally understood as a criminal “floor tax” or protection payment required to operate in a territory. It may be demanded from retailers, agricultural producers, logistics companies, construction firms, miners, energy operators, or local distributors. Derecho de Paso means a “right of passage” payment, often framed as a toll to move people, trucks, cargo, or goods through a controlled area.

Both are dangerous because they blur lines. A company may believe it is facing a security threat. In reality, it may be funding a designated organization, recording a false business expense, using a third party as a payment conduit, or allowing a cartel-linked official to convert extortion into a corrupt advantage. The compliance lesson is not that employee safety should take a back seat. It should not. The lesson is that safety-driven decisions must still be documented truthfully, escalated appropriately, and controlled through legal, compliance, security, finance, and senior management.

Millicom as the Centerpiece

The Millicom FCPA enforcement action demonstrates how these risks manifest in practice. TIGO Guatemala’s scheme ran from at least 2012 to 2018 and involved efforts to influence Guatemalan legislators, including support for radiofrequency renewals and “Ley TIGO,” a telecommunications law that benefited the company. The company earned at least $58 million in profits from the schemes.

The mechanics were extraordinary. Cash was delivered by helicopter to the TIGO Guatemala helipad in duffel bags. A $15 million put-call execution fee was used as part of a bribery slush fund. A $12 million inflated contract and backdated invoices created the appearance of legitimate services. Most troubling, a banker laundered narcotrafficking proceeds and funneled cash to support TIGO Guatemala bribe payments.

This is the compliance lesson. The company did not face a single bad invoice. It faced a criminal infrastructure. Cash, shell companies, backdated contracts, cartel-linked funds, compromised governance, and political influence worked together. That is the modern FCPA risk environment in cartel-affected markets.

The Accounting Provisions Cannot Be an Afterthought

The FCPA accounting provisions are where many companies will face their hardest questions. The FCPA Resource Guide explains that issuers must keep books and records that accurately and fairly reflect transactions and maintain internal accounting controls sufficient to provide reasonable assurances over authorization, recording, accountability, and access to assets. It also states that it is never appropriate to mischaracterize transactions and that bribes are often hidden as consulting fees, commissions, petty cash withdrawals, vendor payments, or miscellaneous expenses.

This is especially important for extortion. A payment made under duress should never be hidden as a logistics fee, community relations expense, consulting payment, security charge, donation, customs support fee, or facilitation-style cost. Even where the anti-bribery analysis turns on duress, the books-and-records analysis turns on accuracy. The internal controls analysis turns on whether the company had reasonable controls over cash, third parties, approvals, documentation, payment channels, escalation, and post-event review.

Millicom’s remediation shows what DOJ expects after such a failure. DOJ credited remediation that included root cause analysis, termination of involved personnel, new management and compliance personnel, enhanced third-party onboarding and transaction monitoring, data analytics, testing of more than 250 transactions, an ephemeral messaging policy, training, a direct compliance reporting line, and an 800 percent increase in dedicated compliance headcount. The attached analysis rightly frames this as organizational reinvention rather than ordinary remediation.

The Cartels, TCOs & Compliance in Latin American conference will feature these topics and many more. For information and registration, click here. For a complete list of the agenda, click here. You can receive 10% off the price by using the Discount Code D10-999-CPN26.

ACI is the sponsor of today’s blog.

Categories
Blog

Cartels, TCOs, and Compliance in Latin America: Why 2026 Is a Watershed Moment

For compliance professionals, some years mark an evolution. Others mark a turning point. In 2026, corporate compliance in Latin America has reached that turning point. For the past two decades, most companies approached regional risk through a familiar lens: anti-corruption. The focus was on government touchpoints, customs interactions, licensing, permits, state-owned enterprises, and third-party intermediaries. That framework is still important. But it is no longer sufficient.

Today, the risk landscape has expanded dramatically. Cartels, transnational criminal organizations, foreign terrorist organization designations, sanctions, anti-money laundering exposure, and supply chain infiltration have all moved to the center of the compliance conversation. What was once a specialized concern has become a board-level issue.

That is why the upcoming ACI Forum on Cartels, TCOs, and Compliance in Latin America is so timely. It is also why compliance officers need to understand that this is not simply another enforcement trend. It is a structural change in how risk must be assessed, governed, and managed. I recently had the opportunity to visit with Matt Ellis, Member at Miller & Chevalier and co-Chair of the Forum. You can listen to Ellis’ remarks on this episode of the FCPA Compliance Report on the Compliance Podcast Network.

The New Risk Equation

The Trump administration has made clear that cartels, fentanyl trafficking, organized crime, and the influence of China in Latin America are policy priorities. That focus has brought multiple enforcement tools to bear, including sanctions, anti-money laundering authorities, FTO designations, and a broader integration of these issues into the compliance and enforcement landscape.

Ellis said that companies, the old model of regional compliance risk must be rethought. The issue is no longer limited to whether a payment was made to a foreign official. The question now is whether a company’s supply chain, transportation provider, security arrangement, or local commercial partner could create exposure under anti-terrorism, sanctions, or AML frameworks.

Mexico Is the Opening Chapter, Not the Whole Book

Much of the current focus is on Mexico, and for good reason. That is where the enforcement spotlight is currently brightest. But compliance professionals should not make the mistake of thinking this challenge begins and ends there.

The risks extend across Latin America, including Central America, Venezuela, Colombia, Brazil, Panama, and other markets where cartel activity, organized crime influence, sanctions risk, or opaque commercial structures may create significant exposure. Each country carries its own risk profile, but the common lesson is clear. Mexico may be the first chapter, but it will not be the last.

For boards and executive teams, that means regional strategy must be reviewed through a broader lens. Market entry, third-party engagement, logistics routes, security providers, and local partnerships all need to be reassessed.

Why the Supply Chain Has Become a Compliance Flashpoint

One of the most important lessons from this discussion is that cartel risk can be embedded in the supply chain. This is where compliance professionals need to recalibrate their thinking. In the anti-corruption world, companies typically focus on agents, distributors, customs brokers, and other third parties that have direct government interactions. In the cartel and TCO context, risk can be embedded within ordinary business operations. Transportation vendors, warehouse providers, local suppliers, labor relationships, and security services may all present hidden risk if they are controlled by, connected to, or exploited by organized crime.

That changes the role of compliance. Procurement, logistics, operations, and security can no longer be treated as peripheral functions. They are now front-line participants in risk identification and mitigation. This is where the compliance function must show leadership. The CCO must bring these disciplines together and translate legal and enforcement developments into practical operational controls.

Due Diligence Must Move Beyond Check-the-Box

If there is one message compliance professionals should take from Ellis’ podcast, it is this: traditional due diligence is not enough. In anti-corruption compliance, companies have become skilled at identifying common red flags. They know how to screen for politically exposed persons, government connections, unusual payment terms, and opaque ownership structures. Those tools still matter, but they will not always surface cartel-linked risk. Organized crime does not announce itself in a database hit.

Instead, companies need a more nuanced and operationally grounded approach. Are there local security concerns being raised by employees? Are there unusual labor dynamics in a region where those patterns do not make commercial sense? Is there persistent chatter about a vendor, route, or business partner that cannot be ignored? Are operations in a community producing concerns that legal and compliance have not fully explored? These are not traditional diligence questions, but they are increasingly the right ones.

Under the DOJ’s Evaluation of Corporate Compliance Programs (ECCP), regulators continue to ask whether a company’s program is designed, implemented, and tested in a manner that addresses actual risk. This is precisely where program effectiveness will now be measured in high-risk operations in Latin America.

The Importance of Listening to the People on the Ground

One of the most practical insights from the interview was the emphasis on local intelligence. Employees who live and work in these communities often know far more than any desktop diligence report will reveal.

That point should resonate deeply with compliance professionals. A company’s speak-up culture is not simply about hotline metrics or case closure rates. It is about whether employees trust the organization enough to raise concerns that may not yet fit into a neat legal category. It is about whether the company listens when local personnel say that something does not add up. This is where compliance, culture, and internal controls intersect.

If a company has not built mechanisms to capture and escalate local concerns, then it is not simply missing information. It is missing one of the most effective risk detection tools available to it. These are not abstract governance questions. They go directly to program effectiveness, risk ownership, and business sustainability.

A Whole-of-Government Enforcement Model

Another important takeaway is the multidimensional nature of this risk environment. In the FCPA era, companies often focused on the DOJ and the SEC. That framework no longer captures the full picture. Now the compliance professional must think across Treasury, OFAC, FinCEN, Homeland Security, DEA, and other agencies, all of which may be interested in the same underlying conduct. This level of coordination matters because it means the government’s expectations are no longer siloed. Enforcement, intelligence, sanctions, and AML concerns can converge quickly. For compliance officers, this demands a more integrated risk management model. Silos within the company will not work when the government itself operates in a coordinated manner.

Is There More Room for Government Engagement?

One of the more interesting themes from the discussion was whether companies may have more room to engage with the government than they traditionally would in the anti-corruption context. That does not mean every issue should be self-disclosed. It does mean that in high-risk environments, thoughtful engagement may sometimes be part of a sound compliance strategy.

The key is judgment. No company should rush into a conversation with the government without understanding the facts and the implications. But where risks are ambiguous, stakes are high, and the legal regimes overlap, strategic dialogue may help demonstrate good faith, show the absence of criminal intent, and allow a company to explain the reasonable steps it is taking. That is not leniency. That is credibility.

The Bottom Line

This is the next generation of Latin America compliance risk. It does not replace anti-corruption compliance. It expands it, hardens it, and operationalizes it. The lesson for compliance professionals is clear. You cannot address cartel and TCO risk with yesterday’s playbook. You need broader risk assessments, deeper third-party diligence, stronger local reporting channels, tighter cross-functional coordination, and more informed board oversight.

In 2026, the companies that succeed will not be the ones with the longest policy manuals. They will be the ones who can demonstrate a compliance program built for the reality of where they operate. For the CCO, that is the challenge. For the board, that is the oversight mandate. For the business, that is the cost of operating responsibly in a changed enforcement environment. The future of compliance in Latin America is already here. The only question is whether your program is ready for it.

Check out the ACI Forum on Cartels, TCOs, and Compliance in Latin America by clicking here. You can receive a 10% off the price by using the Discount Code D10-999-CPN26.

ACI is the sponsor of today’s blog.

Categories
FCPA Compliance Report

FCPA Compliance Report: Matt Ellis on Cartels, FTO Risk, and Corporate Compliance in Latin America

In this episode, Tom Fox welcomes Matt Ellis of Miller & Chevalier about the ACI “Cartels, TCOs and Compliance in Latin America” forum (July 20–21, Washington, DC) and why cartel/TCO/FTO risk is a timely 2026 compliance priority.

Ellis describes the Trump administration’s focus on cartels, fentanyl, China’s influence, and the expanded enforcement toolkit—FCPA guidance linking to cartel activity, sanctions, AML actions (including FinCEN orders against Mexican financial institutions), and cartel FTO designations implicating the Anti-Terrorism Act. They discuss how cartels infiltrate supply chains, creating “material support” exposure, and why due diligence must go beyond traditional screening to on-the-ground intelligence and nuanced red flags. Ellis notes government interest in compliance expectations, extortion-payment considerations, the Lafarge/ISIS example, anticipated investigations, broader regional risk (Mexico, Venezuela, Colombia, Brazil), and increased multi-agency coordination and potential dialogue with U.S. authorities.

Key highlights:

  • Why This Conference Now
  • Due Diligence Goes Deeper
  • Extortion and Self-Reporting
  • Beyond Mexico Regional Risks
  • Whole-of-Government Focus
  • When to Engage Government

Resources:

Cartels, TCOs and Compliance in Latin America, July 20-21

Matt Ellis on LinkedIn

Tom Fox

Instagram

Facebook

YouTube

Twitter

LinkedIn

To learn about the intersection of Sherlock Holmes and the modern compliance professional, check out Tom’s latest book, The Game is Afoot-What Sherlock Holmes Teaches About Risk, Ethics and Investigations on Amazon.com.

Categories
Blog

Millicom Cellular, Part 2: Lessons Learned on Cartels, Cash, and Control Failures

The Millicom Cellular FCPA enforcement action is not just another FCPA case. It is a case that signals a new frontier for compliance risk. It blends classic corrupt-payment schemes with organized crime, narcotrafficking proceeds, obstructed governance, and aggressive legislative capture. It is a wake-up call for compliance officers that the threat landscape is expanding in ways that require deeper operational controls, broader due diligence frameworks, and more sophisticated cross-functional collaboration.

In Part 1, we considered the underlying facts and FCPA violations of this matter. In Part 2, we examine what compliance professionals must take away from the case.

Lesson 1: Joint-Venture Governance Failures Are Not a Defense

Millicom Cellular held a 55 percent ownership stake in TIGO Guatemala, but the local partner exercised operational control and blocked Millicom Cellular from information and cooperation. The DOJ notes that Millicom Cellular voluntarily disclosed early concerns in 2015 but was unable to compel cooperation from local executives or obtain complete data. The result is a clear message:

Ownership without operational control equals enormous FCPA exposure.

Compliance professionals must:

  • Implement JV governance protocols that require access rights, audit rights, and cooperation language in shareholder agreements. Try to place your company’s representative as the CFO of the joint venture.
  • Establish escalation pathways if a partner obstructs investigations.
  • Treat “majority ownership without control” as a high-risk structure in compliance risk assessments.

Yet notwithstanding the foregoing, DOJ has made clear it will not accept a lack of control as an excuse for failing to detect corruption, especially when red flags are visible.

Lesson 2: Cash-Based Bribery Ecosystems Require a Different Kind of Monitoring

The bribery scheme ran almost entirely on cash: cash in duffel bags delivered by helicopter, cash laundered through drug traffickers, cash moved through shell companies, and cash withdrawn from banks in plastic bags. Traditional financial controls are almost useless in the face of an off-books cash economy. Compliance must be enhanced:

  • Controls around cash withdrawals
  • Monitoring of cash-intensive vendors
  • Patterns of invoicing irregularities
  • Real-time analytics on deviations in expense and procurement behavior

This is not a theoretical exercise. It is an operational reality for companies in high-risk jurisdictions.

Lesson 3: Cartel Exposure Is Emerging as a Corporate Compliance Obligation

This case represents one of the most explicit linkages between FCPA violations and narco-trafficking cash flows. The scheme not only involved bribes; it also involved bribes financed by organized crime. Compliance officers must now assume that criminal networks may view legitimate multinationals as conduits for illicit financial flows. This demands:

  • Enhanced beneficial-ownership checks
  • Screening for cartel-linked financial intermediaries
  • Deeper diligence on bankers, lawyers, and consultants
  • Country-level threat mapping that includes cartel and organized crime indicators

The DOJ has increasingly emphasized convergence risk between corruption, money laundering, and organized crime. The Millicom Cellular enforcement action is a prime example.

Lesson 4: “Influencing Legislation” Is a Red Flag, Not a Business Strategy

TIGO Guatemala sought legislative outcomes that would alter the national telecom law. That in itself is not illegal. What is unlawful is tying legislative outcomes to cash bribes, helicopter deliveries, and cartel-funded transactions. Compliance teams must scrutinize:

  • Payments to lobbyists, political consultants, and intermediaries
  • Relationships with legislators and political parties
  • Sponsorships, charitable donations, and community programs with political beneficiaries

Any effort to “shape legislation” must come with strict controls.

Lesson 5: Data Gaps Are Compliance Gaps

Millicom’s inability to obtain information access within its own joint venture delayed detection and undermined the credibility of its initial self-disclosure. Compliance professionals must demand:

  • Rights to data
  • Rights to conduct investigations
  • Rights to interview employees
  • The right to require cooperation from partners

A partner who denies access creates liability.

Lesson 6: Remediation Must Be Conducted Like a Corporate Transformation

Millicom’s remediation was extensive. It included:

  • Replacing senior personnel
  • Centralizing compliance oversight
  • Enhancing third-party onboarding and continuous monitoring
  • Adding data analytics
  • Conducting control testing across more than 250 transactions
  • Creating an ephemeral-messaging retention policy
  • Increasing compliance headcount by 800 percent (pages 5–6)

The DOJ’s description reads less like remediation and more like organizational reinvention. That is the expectation now. Compliance must treat remediation as a fully integrated operational overhaul.

Lesson 7: The DOJ Will Reopen Cases When New Evidence Emerges

The DOJ initially closed the investigation in 2018. It reopened the case in 2020 after uncovering new evidence from outside sources, including cartel-linked transactions. The message is clear:

  • Self-disclosure is not a shield when the company lacks visibility into misconduct.
  • Failure to detect ongoing wrongdoing can undermine trust and credit for cooperation.
  • Compliance must ensure continuous monitoring even after perceived risk has been reduced.

Conclusion: The New Compliance Mandate

The Millicom Cellular enforcement action demonstrates that compliance risk is no longer confined to corrupt payments. It now involves organized crime, cash-based bribery systems, cross-border laundering, political capture, and governance obstructions. Compliance professionals must operate with a broader risk lens, encompassing cartel risk, cash-economy vulnerabilities, high-risk political interactions, and joint-venture control structures. This is a key enforcement effort of the Trump Administration.

The future of compliance is not about preventing bribery alone. It is about defending the corporation from becoming an unwitting partner in a criminal enterprise.