Categories
FCPA Compliance Report

FCPA Compliance Report: Data Analytics in Compliance: Lessons from Scoular

In this episode, Tom Fox welcomes back Vince Walden, CEO of konaAI, which is the sponsor of this podcast series. Vince is well known for his leadership in data analytics, machine learning, and AI, and we take a deep dive into all of these topics through the lens of the Scoular FCPA Enforcement action.

The Scoular case is a unique learning tool for using data analytics, machine learning, and AI for compliance. In this matter, roughly 2,000 near-$2,000 payments were tied to customs brokerage activity. This case illustrates broader uses of data analytics beyond numbers, including mining unstructured text in invoice and payment-description fields (e.g., repeated terms like “re-inspection fee” and Spanish phrases) and linking it to structured AP data.

Walden explains how combining structured and unstructured data reduces investigator bias, how round-dollar and repetitive payments to high-risk vendors can be continuously risk scored using hundreds of tests, and how machine learning can “find more like this” across large transaction populations. We discuss integrating communications data when available, using monitoring within typical 30–60-day payment cycles to prevent payments, supporting self-disclosure decisions amid DOJ guidance, and launching a minimum viable analytics program by starting with AP spend, invoices, POs, and payments pulled from ERP systems.

Key highlights:

  • Structured vs. Unstructured Data
  • Red Flags Round Dollars
  • Text Mining and Three Lines
  • Transactional Fingerprints
  • Machine Learning for Compliance
  • Linking Comms and Payments
  • Prevention Through Monitoring
  • Continuous Improvement and ROI
  • Self-Disclosure and Culture Data
  • 90-Day Analytics Roadmap

Resources:

konaAI

Vince Walden on LinkedIn

Tom Fox

Instagram

Facebook

YouTube

Twitter

LinkedIn

To learn about the intersection of Sherlock Holmes and the modern compliance professional, check out Tom’s latest book, The Game is Afoot-What Sherlock Holmes Teaches About Risk, Ethics and Investigations on Amazon.com.

Categories
Blog

Scoular DPA Part 5: From Reinspection Fees to Executive Signatures: Final Lessons from Scoular

From Reinspection Fees to Executive Signatures: Final Lessons from Scoular

The Scoular Company FCPA enforcement action began with a deceptively simple fact pattern. Customs brokers allegedly paid Mexican officials approximately $2,000 per train so agricultural shipments could cross the border despite adverse inspection findings. The brokers invoiced the payments to Scoular as “reinspection fees.” That description, however, was only the first layer of the case.

Across this blog post series, Scoular Company became a study in third-party risk, internal controls, cartel exposure, off-channel communications, facilitating payments, data analytics, voluntary disclosure, remediation, DOJ oversight, and executive accountability. Each article examined one part of the control environment. Taken together, they tell a larger story about how bribery becomes normalized inside an operating process and what a company must do when that process fails.

The source distinction matters. I have now posted two series on the enforcement action. The first series relied on the DOJ Press Release, which announced the resolution and described the government’s allegations and conclusions. The second series relied on the formal Deferred Prosecution Agreement (DPA), in which Scoular admitted, accepted, and stipulated that the facts were true. The DPA did not merely add detail. It changed the evidentiary foundation of the analysis.

I.              Series One: Lessons From the DOJ Press Release

a.     A Small Payment Became an Enterprise Control Failure

The Press Release series began with the mechanics of the scheme. According to the DOJ announcement, the conduct ran from 2013 through 2019, involved more than $400,000 in bribes, and enabled Scoular to avoid more than $6.5 million in fees and costs. Scoular entered a three-year DPA and agreed to pay a $9,769,521 criminal penalty and $414,351 in forfeiture.

The compliance lesson was never the size of one payment. It was repetition. A recurring round-dollar charge, submitted by customs brokers, approved over six years, and recorded under a plausible description became part of the company’s operating model.

The phrase “reinspection fee” demonstrated why invoice controls must examine commercial substance. A three-way match can confirm that an invoice, purchase order, and approval agree. It cannot establish that the underlying service was legitimate. For a high-risk customs payment, the control must ask what government action occurred, who received the money, whether an official fee schedule supports the amount, and what happened to the shipment after payment.

This also exposed the limits of onboarding due diligence. Screening a broker and obtaining an anti-corruption certification are only the beginning. Effective third-party management connects onboarding to invoices, transaction monitoring, business outcomes, periodic review, audit rights, and termination decisions.

b.    Cartel Risk Expanded the Compliance Perimeter

The Press Release stated that a portion of the bribe payments ultimately benefited individuals associated with a cartel operating at the U.S.-Mexico border, although the DOJ said Scoular Company and its employees did not know of that connection.

In an episode of the FCPA Compliance Report,  Matt Ellis discussed a broader question. Traditional anti-corruption diligence focuses on government-facing intermediaries, ownership, political exposure, adverse media, and government relationships. Organized-crime connections may not appear in a corporate registry or screening database.

The lesson was not that every cross-border transaction benefits a cartel. It was that companies must understand the environment in which their money, goods, and third parties move. Customs brokers, trucking companies, warehouses, security providers, labor contractors, and subcontractors can create overlapping corruption, money-laundering, sanctions, trade, security, and organized-crime risks.

c.     WhatsApp Was Part of the Control Environment

The Press Release series also examined WhatsApp and other communications used to discuss shipments and payments. The critical point was not that employees selected an unapproved application. It was that the substantive business decision could occur in a private message while the formal system recorded only the resulting invoice. Ellis emphasized that enforcement priorities may change, but evidence does not. A WhatsApp message can establish knowledge, authorization, concealment, or control circumvention even without a standalone off-channel communications charge.

A defensible program must identify the applications employees actually use, define which business activities may occur there, preserve relevant records, address local privacy and employment law, and enforce violations consistently. The company must also be able to connect communications with payment records, inspection results, shipment identifiers, approval logs, and bank data.

Facilitation Payments Did Not Fit the Facts

The Press Release series then addressed why the payments were not protected as facilitating payments. The FCPA exception is narrow. It may cover a payment intended to expedite a routine, nondiscretionary governmental act that the company is already entitled to receive. Scheduling an inspection may be routine. Paying an official to disregard a failed inspection is not. The alleged Scoular payments did not change timing. They changed the outcome and enabled shipments to cross despite findings of dirt, soil, and other impurities.

Amount, urgency, local custom, invoice wording, and use of a third party do not create the exception. Nor does the exception authorize a false accounting entry. A company that permits facilitating payments must still confront local law, accurate books and records, approval controls, and the practical difficulty of asking employees to make a narrow legal distinction under commercial pressure.

II.   Lessons From the DPA and Admitted Facts

a.     The DPA Showed How the Scheme Became Normal

The DPA blog post series began by distinguishing allegations in the Press Release from facts Scoular Company admitted. The Statement of Facts showed that stricter Mexican inspections created operational pressure (IE., more or new/different risks) in 2013. A broker proposed a fee on every train and promised that Scoular Company would “not have a single risk of adverse determinations.” The proposal was discussed at Scoular Company’s Kansas office and then replicated through additional brokers and border crossings.

The communications removed ambiguity. Employees discussed soil findings, special payments, trains released after inspections, and situations in which “normal procedures are not working.” By 2018, a communication referred to offering officials more than was normally given. These facts showed normalization. The scheme was not simply a broker’s unauthorized act. It became a repeatable process linking operational pressure, management knowledge, third parties, communications, invoices, approvals, and favorable business outcomes.

b.    Stopping the Conduct Was Not Self-Disclosure

The DPA disclosed that internal reports emerged in 2019 and Scoular Company changed its practices and ended direct engagement with the brokers. Yet the company did not receive voluntary self-disclosure credit because it did not voluntarily and timely report the conduct. The DPA does not reveal the company’s internal debate so that speculation would be inappropriate. It does establish a governance lesson. An internal report starts two clocks: the investigation clock and the disclosure-decision clock. Stopping the conduct is remediation. It is not a substitute for a documented, timely decision about disclosure.

Scoular later received cooperation and remediation credit, including a 25 percent reduction from the bottom of the applicable Sentencing Guidelines range. That outcome demonstrates that missing voluntary-disclosure credit does not make later cooperation irrelevant. It also demonstrates that the two forms of credit are not interchangeable.

c.     Executive Signatures Became the Final Control

The DPA’s attachments translated compliance expectations into personal executive responsibility. They required compliance access to the board, adequate authority and resources, incentives and discipline, third-party business-rationale documentation, verification of services, reasonable compensation, data access, root-cause analysis, and remediation.

They also required two distinct certifications. The CEO and CFO must certify disclosure obligations. The CEO and Chief Legal Officer must certify the truth and completeness of DOJ reports and the design of the anti-corruption compliance program. The certification language references potential exposure under 18 U.S.C. §§ 1001 and 1519 for materially false statements or records.

The signature is therefore not ceremonial. It requires an evidence chain from front-line controls through management testing to board oversight.

d.    Data Analytics Connects Both Series

Vince Walden’s analysis supplied the final detection lesson. No single anomaly proves bribery. The stronger signal is a sequence: an adverse inspection, an unusual recurring broker payment, and a favorable shipment release.

The words “reinspection fee” were searchable. The approximately $2,000 round-dollar amount was testable. The brokers, routes, inspection outcomes, timing, and releases were linkable. Communications could then provide context. Analytics should rank anomalies for human investigation, not declare guilt by algorithm.

This is where internal controls become dynamic. The company should test transaction text, payment amounts, vendor concentration, duplicate descriptions, approval patterns, inspection results, clearance timing, and user access together. Every substantiated alert should improve the next rule, risk model, training decision, and control test.

e.     Compliance Takeaways

  1. Treat the process as the risk unit. Review the third party, payment, message, inspection, route, approval, accounting entry, and business outcome together.
  2. Test substance, not labels. Require evidence of the service performed, the lawful basis for the fee, the recipient, the calculation, and the official result.
  3. Expand third-party risk beyond corruption screening. Integrate organized-crime, sanctions, anti-money-laundering, trade, security, and supply-chain intelligence where the risk profile requires it.
  4. Govern communications as business records. Know which channels employees use, restrict substantive approvals to controlled systems, preserve records, and test retrieval before an investigation.
  5. Create a disclosure decision protocol. Define who evaluates material facts, what information is needed, when senior management and the board are briefed, and how the decision is documented.
  6. Use analytics to connect events. Build monitoring around sequences and outcomes, then route alerts to trained investigators with access to operational, financial, and communications data.
  7. Make certifications evidence-based. Executive signers and boards should demand documented control testing, root-cause analysis, remediation status, and unresolved exceptions before signing.

The final lesson from Scoular Company is that bribery rarely sits in one control. It moves through an operating system. An effective compliance program must see that system, test it continuously, and ensure that the people who oversee it can stand behind the evidence.

Categories
Blog

The Scoular DPA Part 3: The Data Was Talking – Data Analytics and the Scoular Bribery Scheme

The Scoular Company bribery scheme was hidden, but it was not invisible. For six years, customs brokers paid Mexican officials approximately $2,000 per train so Scoular Company shipments could cross the border despite adverse inspections. The brokers invoiced the payments back to Scoular as “reinspection fees.” In total, Scoular Company admitted that it authorized $414,351 in bribes and avoided approximately $6.5 million in fees and costs. Those facts describe an FCPA violation. They also describe a data pattern.

I had the opportunity to visit with Vince Walden, CEO of KonaAI, about the Scoular Company FCPA enforcement action from a data analytics perspective. He identified the feature that should command every CCO’s attention: people concealing misconduct often record it consistently. They may avoid the word “bribe,” but they still need a repeatable description that allows the payment to be processed, reconciled, and found again. At Scoular Company, that description was “reinspection fee.”

Walden’s observation goes to the heart of modern compliance. Illegal conduct may be concealed from the compliance department while remaining visible in accounts payable, journal entries, invoices, purchase orders, shipment records, and communications. The control failure occurs when those systems hold the evidence, but the company never asks the data the right questions.

Consistency Can Become the Fraudster’s Fingerprint

Walden observed that accountants value consistency because consistent classifications support accurate reporting. Fraudsters and their enablers can exploit the same discipline. A bookkeeper cannot label a payment “bribe expense.” The payment still needs a code, description, vendor, amount, approver, account, and business purpose. If the scheme continues, the participants need a method they can repeat. That repetition creates a fingerprint.

Suspicious terms in payment descriptions and journal entries are among the most useful anti-corruption monitoring tests. His examples included phrases such as “friend fee,” “government payment,” and “miscellaneous.” The precise word will vary by company and geography. The analytical principle does not.

The company should identify unusual language, then connect it to the transaction behind it. Even if the language is not unusual, its repeated use might form a pattern worth exploring. A word cloud may provide a useful visual starting point. Keyword searches, natural-language processing, and risk dictionaries can scale the review across thousands of invoices and expense reports. Yet the purpose is not to find one forbidden word. It is to identify language that is unusual for the business, unusually frequent for one vendor, or correlated with a high-risk outcome. “Reinspection fee” was facially plausible. Repetition changed its meaning.

The First Test Was Hiding in Plain Sight

An elementary analytic (As in Elementary, my dear Watson) would have grouped customs-related payments by invoice description, vendor, amount, port, and frequency. That test could have asked:

  • How often does “reinspection fee” appear?
  • Which brokers submit the charge?
  • Is the amount repeatedly near $2,000?
  • Which employees approve it?
  • Does it appear only on trains with an inspection problem?
  • What happens to the shipment immediately after payment?

No single answer proves bribery. Together, the answers can create a compelling reason to investigate. The recurring round-dollar amount matters. Legitimate inspection costs often vary with the service, product, weight, time, port, or government fee schedule. A repeated $2,000 charge across multiple transactions may indicate a fixed unofficial tariff rather than the cost of a legitimate service.

The description also matters. If “reinspection fee” was not found in an approved government schedule, lacked official documentation, or appeared only in broker invoices rather than government receipts, the control should have required escalation before payment. Finally, the outcome matters most. If trains that failed inspection were consistently released after the fee, the company had more than an accounting anomaly. It had a payment linked to a favorable exercise of government discretion.

Connect the Payment to the Business Outcome

Traditional controls often examine whether an invoice matches a purchase order and whether an authorized employee approved it. A bribery scheme can satisfy both tests when employees are participating in the misconduct.

Data analytics must therefore test commercial substance, not merely procedural completion.

For Scoular Company, the decisive data model would connect five sources:

  • Inspection data: date, result, impurity identified, inspector, agency, and reinspection history.
  • Shipment data: train identifier, product, port, broker, delay, release time, and disposition.
  • Payment data: invoice description, amount, general-ledger account, supporting documents, approver, and payment date.
  • Third-party data: broker risk rating, contract terms, bank account, audit rights, ownership, and compensation history.
  • Communications data: relevant emails, WhatsApp records lawfully available to the company, and other business messages.

With those sources joined, compliance could test whether a $2,000 broker charge followed an adverse inspection and then by rapid release of the train. It could compare release rates for shipments with and without the payment. It could identify which brokers, ports, and employees produced unusually favorable clearance outcomes. That sequence is the analytic signature of the scheme: failed inspection, unusual payment, successful release.

Build a Layered Anti-Bribery Analytics Program

A mature program should not depend on one keyword or one dashboard. It should use several complementary tests.

Text analytics. Search invoice narratives, journal entries, purchase orders, and expense descriptions for high-risk terms, euphemisms, spelling variants, and unusual phrases. The risk dictionary should reflect the company’s markets and evolve with investigations.

Transaction analytics. Flag recurring round-dollar payments, duplicate or near-duplicate invoices, payments just below approval thresholds, split payments, weekend postings, manual journal entries, and charges lacking official receipts.

Vendor analytics. Compare customs brokers by fee frequency, payment descriptions, clearance rate, failed-inspection rate, use of subcontractors, changes in bank accounts, and concentration under particular employees or business units.

Outcome analytics. Test whether payments are statistically associated with permits, inspections, releases, tax outcomes, contract awards, or other favorable government actions. This moves the review from what the invoice says to what the payment accomplished.

Sequence analytics. Measure the time between an adverse event, a payment request, approval, payment, and favorable resolution. Short, repeated intervals can reveal a designed process.

Communications analytics. Where lawful and consistent with company policy, match high-risk transactions to messages about urgency, guarantees, officials, inspections, exceptions, or payments. A suspicious invoice can corroborate a message, and a message can explain the invoice.

Network analytics. Map relationships among employees, brokers, bank accounts, ports, approvers, and government touchpoints. Shared bank accounts, common addresses, unusual subcontractors, or recurring approval chains can expose concealed connections.

These tests should create ranked alerts, not automated accusations. Analytics identifies anomalies. Trained reviewers determine whether the transaction has a legitimate explanation, requires more evidence, or warrants an investigation.

Continuous Monitoring Is a Governance Choice

Walden’s closing advice was simple: keep innovating and keep running the analytics. The word “running” matters. As in continuously. A one-time review performed after a subpoena is forensic reconstruction. A risk-based test operating monthly, weekly, or at the point of payment is a compliance control.

Continuous monitoring does not mean surveillance of every employee or review of every transaction. It means that known high-risk processes receive repeatable testing at a frequency aligned with the risk. Customs payments, government-facing third parties, failed inspections, and manual financial entries deserve more attention than ordinary low-risk purchases.

The program also needs governance. Compliance and internal audit should agree on data ownership, alert thresholds, reviewer responsibilities, escalation standards, documentation, privacy requirements, and feedback loops. Finance must help validate legitimate payment patterns. The business must explain operational outcomes. Technology must maintain data quality and access. Legal must ensure that communications monitoring is lawful.

Most importantly, the board should ask whether compliance has direct access to the data. A dashboard built from incomplete information can create false assurance. If broker invoices sit in one system, inspection results in another, shipment releases in a third, and WhatsApp messages outside company retention, the organization sees fragments while the scheme operates across the seams.

Internal Controls Must Learn From Every Alert

Data analytics is not a substitute for internal controls. They supplement each other, as data analytics is a way to test whether those controls work and where they fail. An alert concerning a reinspection fee should trigger questions about official documentation, approved fee schedules, broker contracts, audit rights, segregation of duties, approval thresholds, and the economic rationale for the charge. If the review confirms misconduct, root-cause analysis should determine why the payment passed through accounts payable, why the broker remained active, why inspections and payment data were not connected, and whether incentives rewarded shipment clearance over compliance.

Every closed alert should improve the system. Confirmed concerns should add new keywords, vendor attributes, transaction patterns, and outcome measures. Legitimate transactions should help refine thresholds and reduce noise. This is how a compliance program becomes adaptive rather than static.

Questions for CCOs

CCOs should ask:

  • Which payment descriptions recur in our highest-risk government-facing processes?
  • Can we connect invoices to inspections, permits, customs outcomes, and shipment releases?
  • Which third parties generate unusually favorable results after unusual payments?
  • Are alert reviewers trained to investigate commercial substance, not merely paperwork?
  • How quickly does a confirmed issue change our controls and analytics?

The Bottom Line

Scoular Company’s bribery scheme did not require a sophisticated algorithm to detect. It required the company to notice a repeated phrase, a recurring amount, a high-risk broker, an adverse inspection, and a favorable government outcome. Walden’s lesson is that concealment often creates consistency, and consistency creates data. The task of compliance is to convert that data into a question early enough to matter.

Follow the words. Test the amount. Connect the outcome. Then channel your inner Sherlock Holmes and investigate what the pattern is telling you.

Categories
Blog

Compliance Analytics at Warp Speed: Lessons in Proactivity from Errand of Mercy

Star Trek’s “Errand of Mercy” has long captivated viewers with its profound examination of conflict, diplomacy, and the limitations of perception. While it might not seem immediately apparent, this episode is rich in insights for the corporate compliance community, particularly in data analytics. Let’s delve into five key data analytics lessons derived from this timeless story, specifically tailored for today’s compliance professionals.

Lesson 1: Data-Driven Awareness Prevents Miscalculations

Illustrated by: Captain Kirk and Mr. Spock initially underestimate the Organians, perceiving them as primitive due to surface-level observations. Only later do they realize that Organians possess profound power and knowledge far beyond initial assessments.

Compliance Lesson: Compliance professionals must avoid superficial analyses and surface-level assessments, just as Kirk and Spock learned not to judge the Organians by outward appearances. Too often, organizations base critical decisions on incomplete or surface-level information. In compliance, this can lead to overlooking systemic risks, misjudging third-party partners, or misunderstanding evolving regulatory threats.

Data-driven awareness is the antidote to this danger. Leveraging advanced analytics, compliance teams can dig deeper into transactional data, employee behavior, vendor histories, and external market signals. Analytics allow organizations to uncover patterns and anomalies that the naked eye might miss, providing early warnings of compliance gaps, fraud, or ethical blind spots. Importantly, robust analytics mitigate the impact of human bias, reducing over-reliance on gut instinct or anecdotal evidence.

By developing dashboards, risk heatmaps, and tailored reporting tools, compliance professionals empower themselves and business leaders to make better, evidence-based decisions. The ultimate lesson: Only through continuous data-driven vigilance can organizations prevent costly miscalculations and ensure their compliance posture is based on reality, not perception.

Lesson 2: Real-Time Analytics Facilitate Prompt Intervention

Illustrated by: During their initial stay, the Organians repeatedly attempt to deflect Federation and Klingon aggression, intervening subtly and promptly as conflicts arise.

Compliance Lesson: In an era of rapid digital transactions and globalized operations, waiting for quarterly or annual compliance reviews is no longer sufficient. Real-time data analytics is transforming the compliance function from a reactive, after-the-fact process to a dynamic, proactive engine for risk prevention. By monitoring financial transactions, communication patterns, and operational workflows in real time, compliance teams can identify red flags, policy breaches, or suspicious activity as soon as they arise.

This enables immediate investigation, escalation, or remediation long before minor issues escalate into major violations or regulatory crises. Advanced alert systems and AI-powered monitoring platforms now allow the simultaneous tracking of thousands of compliance data points, prioritizing high-risk incidents for human review. Furthermore, real-time analytics support a culture of ongoing accountability, where employees and leaders understand that compliance is not just a box to check but a living, breathing part of business operations. The lesson from the Organians: Subtle, timely intervention can often prevent conflict, just as prompt, real-time analytics can avert disaster in the compliance landscape.

Lesson 3: Predictive Analytics Enhance Proactive Compliance

Illustrated by: Ultimately, the Organians demonstrate foresight and predictive awareness, recognizing the likely outcomes of Federation and Klingon hostilities and intervening proactively to avoid widespread disaster.

Compliance Lesson: The best compliance programs don’t just react to problems—they anticipate them. Predictive analytics is the frontier of proactive compliance, empowering teams to leverage historical data, risk modeling, and machine learning to forecast future threats. By analyzing trends in internal investigations, audit findings, whistleblower reports, and external regulatory actions, compliance professionals can identify emerging risk patterns before they fully materialize. This capability allows organizations to adjust controls, update training, and allocate resources with maximum impact.

For example, predictive models can highlight geographic regions or business units with an elevated risk profile, enabling preemptive audits or targeted messaging. Predictive analytics also supports dynamic risk scoring, enabling compliance teams to reassess exposure as new data becomes available continually. In the same way that the Organians foresaw and diffused conflict before it erupted, compliance professionals equipped with predictive analytics can guide their organizations around regulatory minefields, reducing both the likelihood and the impact of violations. The key takeaway: In compliance, as in diplomacy, foresight is a powerful tool.

Lesson 4: The Value of Integrating Diverse Data Sources

Illustrated by Kirk and Spock initially relying primarily on their direct observations and Federation reports, neglecting potentially valuable alternative perspectives and data points that might have informed a more nuanced understanding of the Organians.

Compliance Lesson: Siloed data is the enemy of effective compliance. In a world of complex operations, no single data source can provide the complete picture of an organization’s compliance risk. Integrating diverse data streams, including financial records, employee activity logs, whistleblower submissions, market intelligence, third-party assessments, and even social media, enables compliance teams to connect the dots that might otherwise remain isolated. Modern compliance analytics platforms are designed to ingest, normalize, and cross-reference multiple data types, revealing relationships and outliers that static spreadsheets cannot.

By triangulating information from various internal and external sources, organizations enhance the accuracy of their risk assessments, refine investigative outcomes, and identify root causes more quickly. Integration also breaks down barriers between business units, legal, audit, and compliance, fostering a culture of transparency and shared responsibility. The failure to consider alternative perspectives, as demonstrated by Kirk and Spock, is a cautionary tale: Only by synthesizing the broadest possible range of data can compliance leaders ensure that their risk management strategies are as robust and adaptive as the business environment demands.

Lesson 5: Ethical Data Use and Transparency Build Trust

Illustrated by: In the episode’s resolution, the Organians reveal their true nature transparently, clearly communicating their intentions and reasons for their actions, which ultimately earns the trust and respect of both Federation and Klingon representatives.

Compliance Lesson: In an age of big data, artificial intelligence, and heightened regulatory scrutiny, ethical stewardship of data is both a legal requirement and a business imperative. Compliance teams must ensure that their use of data analytics adheres to the highest standards of privacy, security, and fairness. This includes not only complying with applicable regulations (such as GDPR, CCPA, and others) but also establishing clear policies around consent, data retention, and access controls.

Transparency is key; organizations should be open with employees, customers, and regulators about what data is collected, how it is analyzed, and for what purposes. Regular communication and training reinforce trust and demonstrate a commitment to responsible data governance. When stakeholders understand and believe in the integrity of an organization’s data practices, the credibility of the compliance program is strengthened. The Organians’ transparent reveal is a reminder: Trust is earned through clarity and honesty, both in science fiction and in today’s data-driven compliance world.

Final ComplianceLog Reflections

“Errand of Mercy” offers a valuable allegory for contemporary compliance professionals, highlighting the importance of thorough analysis, real-time intervention capabilities, predictive insights, diverse data integration, and ethical transparency. By embracing these data analytics lessons, compliance teams can significantly enhance their organization’s ability to proactively manage and mitigate risks. In today’s complex regulatory landscape, harnessing sophisticated analytics capabilities is not merely advantageous; it is essential. As Kirk and Spock’s ultimate realization in “Errand of Mercy” shows, understanding beyond surface appearances and leveraging deep analytical insights can make all the difference in navigating compliance challenges effectively.

Resources:

Excruciatingly Detailed Plot Summary by Eric W. Weisstein

MissionLogPodcast.com

Memory Alpha

Categories
TechLaw10

TechLaw10: Episode 300 with Special Guest Tom Fox

In this special episode of TechLaw10, Punter Southall Law’s Jonathan Armstrong and Eric Sinrod, Professor and Duane Morris LLP attorney, chat with special guest Tom Fox. This is episode 300 in the popular TechLaw10 series. You can listen to earlier podcasts here. 

Tom Fox is the founder of the Compliance Podcast Network. He has been a leading litigation lawyer, a General Counsel, and a Chief Compliance Officer. He is now an Independent Consultant, assisting companies with anti-corruption and anti-bribery compliance and international transaction issues. He specializes in bringing business solutions to compliance problems. Tom is the author of the award-winning FCPA Compliance and Ethics Blog and the international best-selling book “Lessons Learned on Compliance and Ethics.” His podcasts have won numerous awards, including the W3, Davey, Communicator, and Webby awards for podcasting excellence.

He is the author of the seminal text The Compliance Handbook, now in its 3rd edition, published by LexisNexis. He is a well-known and frequent speaker on compliance and ethics issues, social media use, and corporate leadership.

Jonathan, Eric, & Tom discuss several issues, including the following:

  • The use of data analytics & data science
  • The use of data & tech in investigations
  • The ITA Airways case and the need to conduct investigations properly and in compliance with GDPR
  • The issues with bribery & corruption
  • The regulation of AI
  • Italy’s AI law
  • A new case in Munich on AI liability
  • How podcasting has changed the legal profession
  • The changes in education & how people learn

Jonathan talks about the EU AI Act. There are FAQs on that here: https://bit.ly/euaifaq. There is also a glossary of AI terms here.

Jonathan also talks about Italy’s AI law—the details for that are here

You can find out more about Tom Fox here.

Eric Sinrod’s details can be found here, and Jonathan Armstrong’s details are available here.

Categories
Trekking Through Compliance

Trekking Through Compliance: Episode 26 – Lessons in Data Analytics from Errand of Mercy

Star Trek’s “Errand of Mercy” has long captivated viewers with its profound examination of conflict, diplomacy, and the limitations of perception. While it might not seem immediately apparent, this episode is rich in insights for the corporate compliance community, particularly in data analytics. Let’s delve into five key data analytics lessons derived from this timeless story, specifically tailored for today’s compliance professionals.

Lesson 1: Data-Driven Awareness Prevents Miscalculations

Illustrated by Captain Kirk and Mr. Spock, they initially underestimate the Organians, perceiving them as primitive due to surface-level observations. Only later do they realize that Organians possess profound power and knowledge far beyond initial assessments.

Compliance Lesson: Compliance professionals must avoid superficial analyses and surface-level assessments. Utilizing comprehensive data analytics enables organizations to understand deeper patterns, accurately predict potential risks, and make informed strategic decisions.

Lesson 2: Real-Time Analytics Facilitate Prompt Intervention

Illustrated by: During their initial stay, the Organians repeatedly attempt to deflect Federation and Klingon aggression, intervening subtly and promptly as conflicts arise.

Compliance Lesson: Effective compliance management increasingly depends on real-time data analytics to facilitate rapid intervention and corrective actions. Organizations require systems that deliver real-time or near-real-time insights into compliance violations and risks, enabling them to respond promptly and effectively.

Lesson 3: Predictive Analytics Enhance Proactive Compliance

Illustrated by: Ultimately, the Organians demonstrate foresight and predictive awareness, recognizing the likely outcomes of Federation and Klingon hostilities and intervening proactively to avoid widespread disaster.

Compliance Lesson: Predictive analytics significantly strengthens proactive compliance initiatives. Leveraging historical data, machine learning algorithms, and risk modeling allows compliance teams to anticipate potential compliance issues before they become significant problems.

Lesson 4: The Value of Integrating Diverse Data Sources

Illustrated by Kirk and Spock initially relying primarily on their direct observations and Federation reports, neglecting potentially valuable alternative perspectives and data points that might have informed a more nuanced understanding of the Organians.

Compliance Lesson: Integrating diverse data sources into compliance analytics significantly enhances the accuracy and effectiveness of decision-making. Organizations should draw on a wide array of data, including internal audit reports, third-party risk assessments, whistleblower reports, and industry-wide compliance trends, to inform their decision-making.

Lesson 5: Ethical Data Use and Transparency Build Trust

Illustrated by: In the episode’s resolution, the Organians reveal their true nature transparently, clearly communicating their intentions and reasons for their actions, which ultimately earns the trust and respect of both Federation and Klingon representatives.

Compliance Lesson: The ethical and transparent use of data is fundamental in maintaining stakeholder trust and ensuring regulatory compliance. Organizations must ensure that their data analytics practices align with privacy regulations, data ethics standards, and transparency principles.

Final ComplianceLog Reflections

“Errand of Mercy” offers a valuable allegory for contemporary compliance professionals, highlighting the importance of in-depth analysis, real-time intervention capabilities, predictive insights, diverse data integration, and ethical transparency. By embracing these data analytics lessons, compliance teams can significantly enhance their organization’s ability to proactively manage and mitigate risks. In today’s complex regulatory landscape, harnessing sophisticated analytics capabilities is not merely advantageous; it is essential. As Kirk and Spock’s ultimate realization in “Errand of Mercy” shows, understanding beyond surface appearances and leveraging deep analytical insights can make all the difference in navigating compliance challenges effectively.

Resources:

Excruciatingly Detailed Plot Summary by Eric W. Weisstein

MissionLogPodcast.com

Memory Alpha

Categories
FCPA Compliance Report

FCPA Compliance Report: The Role of AI and Data Analytics in Compliance: Preview of The Leading Edge with Roxanne Bras Petraeus and Andrew McBride

Today, we have a special edition of the FCPA Compliance Report, previewing speakers and presentations at the upcoming Compliance Week event, The Leading Edge: Applying AI and Data Analytics in E&C, to be held at The Westin Fort Lauderdale on January 28 and 29. In this episode, Tom Fox is joined by Roxanne Bras Petraeus, CEO of Ethena, and Andrew McBride, Founder & CEO of Integrity Bridge LLC, to discuss their presentation, “Seeing is Believing: Live AI Demos for Ethics and Compliance Leaders.

Roxanne emphasizes the practical integration of AI within Ethena’s services and its utility for compliance leaders, while Andrew shares insights from his extensive experience in risk and compliance consulting. They highlight their upcoming presentation at The Leading Edge conference, where they will demonstrate 10 AI tools and discuss real-life use cases, opportunities, and limitations of AI in compliance. They also reflect on the evolving role of AI in data analytics and the need for transparency and data validation. Both guests express their eagerness to engage with compliance professionals and share practical insights to enhance the industry’s AI adoption.

Key highlights:

  • Preview of the Compliance Week Presentation
  • The Importance of Effective Training
  • AI’s Impact on Data Analytics in Compliance
  • Expectations for the Conference

Resources:

Compliance Week

The Leading Edge: Applying AI and Data Analytics in E&C conference, click here. Compliance Week is offering a 20% discount to the event for listeners of this podcast. Use the discount code TFOX at registration.

 Guests

Roxanne Bras Petraeus on LinkedIn

Ethena

Andrew McBride on LinkedIn

Integrity Bridge

Host

Tom Fox

Instagram

Facebook

YouTube

Twitter

LinkedIn

Categories
Blog

Greek Philosophers Week: Part 4 – Pythagoras and the Rise of Data Analytics and AI in Compliance

We continue our exploration of the origins of the modern corporate compliance organization in Part 4, looking at Pythagoras. Aristotle teaches compliance professionals how ethics are lived through judgment, habit, and daily decision-making. But modern organizations operate at a scale Aristotle could never have imagined. Thousands of transactions, third parties, employees, and decisions occur simultaneously across jurisdictions. At that scale, judgment alone is not enough. Measurement becomes essential. That is where Pythagoras enters the compliance conversation.

Pythagoras believed that reality could be understood through number, proportion, and harmony. He did not see numbers as cold abstractions but as tools to reveal the underlying truth. That belief sits squarely at the heart of modern compliance analytics, continuous monitoring, and artificial intelligence. The DOJ Evaluation of Corporate Compliance Programs (ECCP) increasingly reflects this Pythagorean turn, asking not only whether programs exist, but whether companies use data to test effectiveness, identify patterns, and evolve.

If Aristotle teaches us how people should behave, Pythagoras teaches us how to observe whether they actually do. Or as Vince Walden might say, it’s always about the numbers.

“All Is Number” and the Measurement of Compliance Effectiveness

Pythagoras’ famous assertion that “all is number” resonates strongly in today’s compliance environment. Modern programs rely on metrics to understand risk exposure, detect anomalies, and allocate resources. Hotline data, transaction monitoring, third-party risk scores, training completion rates, and investigation timelines are all numerical expressions of ethical behavior.

The ECCP explicitly asks whether companies track and analyze data to assess program effectiveness and, equally important, whether the compliance function has access to this data. The ECCP states, “Do compliance and control personnel have sufficient direct or indirect access to relevant sources of data to allow for timely and effective monitoring and/or testing of policies, controls, and transactions? ” This is not a technological preference. It is a governance expectation. Regulators understand that unmanaged data obscures risk, while well-designed analytics reveal it.

In daily operations, compliance professionals must decide what to measure and why. Pythagoras reminds us that numbers should illuminate reality, not replace it. Metrics must be chosen deliberately, tied to risk, and interpreted with care. Counting activity is easy. Measuring insight requires discipline. The ECCP goes on to ask the following questions: Is the company appropriately leveraging data analytics tools to create efficiencies in compliance operations and measure the effectiveness of components of compliance programs?

Proportion and the Danger of Over-Engineered Analytics

Pythagoras placed enormous importance on proportion and balance. Harmony emerged when relationships were mathematically sound. This lesson is critical for compliance programs rushing to adopt advanced analytics and AI. The ECCP expects data-driven compliance, but it does not reward excess, stating, “Is the company appropriately leveraging data analytics tools to create efficiencies in compliance operations and measure the effectiveness of components of compliance programs? ” Overly complex monitoring systems often generate false positives that overwhelm teams and erode trust with the business. Employees begin to see compliance as noise rather than guidance. Investigators drown in alerts rather than insights.

A Pythagorean approach demands proportionality. Analytics should scale to risk. High-risk transactions deserve deeper scrutiny. Low-risk activity should not consume disproportionate resources. AI models must be tuned to business reality, not theoretical perfection. Balance, not volume, produces effectiveness.

Harmony of Systems and Breaking Down Data Silos

Pythagoras believed that harmony arises when individual elements work together according to rational relationships. In compliance, this translates into integration. One of the most common failures in compliance analytics is fragmentation. Compliance data lives in one system. HR data in another. Finance and audit data elsewhere. Each tells a partial story. None reveals the whole picture.

The ECCP increasingly expects companies to connect these dots. Patterns of misconduct often emerge only when data sets are viewed together. For example, high sales pressure combined with weak supervision and delayed training may more accurately predict risk than any single metric. Daily compliance operations should therefore focus on integration. Data governance, cross-functional collaboration, and shared dashboards are not IT luxuries. They are an ethical infrastructure. Pythagoras teaches that truth emerges through harmony, not isolation.

AI in Compliance: Augmentation, Not Abdication

Pythagoras revered numbers, but he did not confuse measurement with wisdom. That distinction is critical as compliance programs adopt AI. Artificial intelligence can identify patterns humans miss. It can process a scale impossible for manual review. But it cannot understand intent, fairness, or ethical nuance. The ECCP implicitly acknowledges this by emphasizing human oversight, explainability, and accountability.

A Pythagorean compliance program treats AI as an instrument, not an authority. Algorithms inform decisions. Humans make them. Compliance professionals must understand how models work, what data they rely on, and where bias may emerge. Black-box systems that cannot be explained to regulators or boards undermine trust and increase risk. The lesson is clear. AI should strengthen judgment, not replace it.

Ethical Design of Metrics and Models

Pythagoras viewed mathematical relationships as expressions of order. In the context of compliance, this means that metrics and models must reflect ethical intent. What a company chooses to measure sends a signal. Measuring speed over quality encourages shortcuts. Measuring volume over impact encourages superficial activity. The ECCP asks whether metrics drive meaningful improvement or merely create the appearance of control, stating, “How is the company measuring the accuracy, precision, or recall of any data analytics models it is using? ”

In daily practice, compliance professionals must evaluate whether dashboards reflect what truly matters. Are metrics aligned with values? Do they incentivize the right behavior? Are they reviewed and refined as risks evolve? Pythagoras teaches that poorly designed numbers distort reality rather than reveal it.

5 Key Takeaways for the Compliance Professional

1. Data is foundational to modern compliance effectiveness.

Pythagoras teaches that numbers reveal truth when used correctly. The ECCP expects compliance programs to use data to assess risk and effectiveness. Daily operations should rely on metrics that illuminate behavior, not merely document activity. Thoughtful measurement enables early detection, targeted remediation, and informed decision-making across the organization.

2. Proportion is critical in analytics and AI deployment.

More data is not better data. Over-engineered systems overwhelm teams and erode credibility. A Pythagorean approach emphasizes balance. Analytics and AI should be scaled to risk and organizational maturity. Proportional systems produce insight without fatigue, supporting both effectiveness and trust.

3. Integrated data reveals systemic risk.

Isolated metrics tell incomplete stories. Pythagoras’ concept of harmony applies directly to compliance data integration. The ECCP increasingly expects cross-functional insight. Compliance professionals should work to connect data across compliance, HR, finance, and audit to identify patterns that go unnoticed in silos.

4. AI must augment, not replace, human judgment.

Numbers do not equal wisdom. AI tools support scale and pattern recognition, but ethical decisions require human oversight. The ECCP emphasizes accountability and explainability. Compliance professionals must understand, govern, and challenge AI outputs rather than defer to them.

5. Metrics are ethical choices.

What gets measured shapes behavior. Poorly designed metrics distort incentives and undermine values. Pythagoras reminds us that numbers carry moral weight. Compliance leaders must ensure metrics align with ethical goals and drive meaningful improvement, not superficial compliance.

From Pythagoras to Euclid: From Measurement to Proof

Pythagoras introduces compliance professionals to the power and peril of numbers. He shows how data, analytics, and AI can reveal patterns, test assumptions, and bring harmony to complex systems. But measurement alone is not enough. At some point, regulators, boards, and stakeholders will ask a harder question. Can you prove your program works?

That is where Euclid completes the journey. If Pythagoras teaches us how to measure compliance, Euclid teaches us how to structure it logically, define it precisely, and demonstrate effectiveness through proof rather than assertion. The Euclid post you have already written stands as the natural capstone to this series, translating philosophical insight into a compliance system that is coherent, defensible, and built to endure.

Pythagoras shows us how to see compliance through numbers. Euclid will show us how to organize those insights into a system that proves its own effectiveness. Join us tomorrow in our concluding blog post to find out how.

Categories
31 Days to More Effective Compliance Programs

31 Days to a More Effective Compliance Program: Day 4 – Building Effective Data Analytics Programs for Compliance

Welcome to 31 Days to a More Effective Compliance Program. Over this 31-day series in January 2026, Tom Fox will post a key component of a best-practice compliance program each day. By the end of January, you will have enough information to create, design, or enhance a compliance program. Each podcast will be short, at 6-8 minutes, with three key takeaways that you can implement at little or no cost to help update your compliance program. I hope you will join each day in January for this exploration of best practices in compliance. On Day 4, this episode focuses on defining the specific risks an organization wants to monitor, capturing relevant data creatively, and leveraging internal expertise to build effective data analytics programs.

Key highlights:

  • Defining and Identifying Risks
  • Innovative Data Capture and Internal Collaboration
  • Demonstrating Value to Senior Management

Resources:

Listeners to this podcast can receive a 20% discount on The Compliance Handbook, 6th edition, by clicking here.

Categories
ACI FCPA Conference 2025

ACI Post Conference Reflections: Vince Walden on AI and Data Analytics in Anti-Corruption Compliance

By special arrangement with ACI, I was able to record several participants, speakers, panelists, and moderators from the recently concluded ACI FCPA and Global Anti-Corruption Conference held at the Gaylord near Washington, DC. This podcast details the guest’s experience at the event. In the first of our series, I visit with Vince Walden, President of konaAI, a Covasant company.

Walden provides a detailed recap of the pre-conference workshop, which was focused on AI and Data Analytics for anti-corruption compliance. Key sessions discussed include best practices for data collection and cleansing, the journey of AI implementation, and leveraging machine learning for compliance. Walden highlights the importance of viewing data analytics as a continuous business process rather than a project and wraps up with discussions on AI governance and ethical use. The episode concludes with Walden sharing his experiences and reflections on the successful event.

Key highlights:

  • Keynote Speakers and Highlights
  • Data Integrity and Validation
  • AI Implementation Journeys
  • Crash and Learn: Lessons from Failures
  • Advanced AI Techniques and Tools
  • Generative AI and Practical Demonstrations
  • AI Governance and Ethical Use