Categories
Blog

THE BERKO TRIAL – PART 1: The Digital Trail: How Prosecutors Built the Berko Bribery Case

A bribery case does not always arrive with a signed receipt. In the trial of former Goldman Sachs banker Asante Berko, prosecutors presented something different: a mosaic of evidence. They placed before the jury a high-value public project, politically connected intermediaries, payments tied to transaction milestones, personal email accounts, disputed consulting invoices, cash withdrawals, a recorded lunch conversation, and an individual who allegedly stood to receive millions.

Over the next five days, I will be taking a deep dive into this trial to see how the prosecution was able to convince a jury of the defendant’s guilt so quickly. The verdict was rendered in just over 3 hours, which tells you the jury did not doubt as to the defendant’s guilt. This blog post series is based upon the excellent reporting of Law360 reporter Stewart Bishop and additional source documents and resources from the Department of Justice (DOJ) and Securities and Exchange Commission (SEC).

The government’s burden was to prove the charged crimes beyond a reasonable doubt. Its strategy was to show that the evidence did not consist of isolated red flags. Each category corroborated the others. Taken together, prosecutors argued, the pattern demonstrated opportunity, corrupt intent, concealment, and personal gain.

A National Crisis and a High-Stakes Deal

The story began with a legitimate and urgent business need. Ghana had suffered widespread power shortages, and its government was seeking projects capable of adding generation quickly. Aksa Enerji Uretim A.S., a Turkish energy company and Goldman client, pursued an agreement to build and operate a power plant. The commercial stakes were substantial. Goldman contemplated arranging approximately $190 million in financing for Aksa and a $75 million letter of credit for Ghana. Goldman also held an approximately 16 percent interest in Aksa. The indictment alleged projected fees of approximately $10.3 million for the loan and more than $1 million for the letter of credit.

Berko was central to the business effort. A dual citizen of the United States and Ghana, he worked in the structured-finance group of Goldman’s United Kingdom subsidiary and had relationships with senior Ghanaian officials. Prosecutors argued that he connected three critical groups: the commercial client seeking the project, the local intermediaries who claimed access, and the public officials whose approvals were required. That role gave the government its organizing theory. Berko was not presented as a participant at the edge of the transaction. He was presented as the linchpin.

The Email Trail

The most important prosecution evidence was documentary. More than 300 emails were admitted during the nine-day trial. Prosecutors used their language, timing, recipients, and communication channels to construct a chronology of the alleged scheme. One September 2015 email shown to the jury stated that Parliament had been paid by Berko and discussed approximately $46,000 that he allegedly paid. Other messages addressed payments associated with the Ministry of Power, regulators, power-team personnel, travel, and parliamentary approval. In a July 2015 exchange over the size and timing of payments, Berko wrote that he was managing a relationship expected to pay everyone millions.

The government argued that these exchanges became more incriminating when compared with Berko’s ordinary deal communications. Routine transaction work went through Goldman’s systems. Sensitive payment discussions appeared in personal accounts. In February 2016, prosecutors showed the jury two emails sent 14 minutes apart. One used Berko’s Goldman account for ordinary deal business. The other used Gmail and instructed recipients to communicate there because his Goldman account was monitored. Personal email alone does not prove bribery. The government’s point was more precise. When an employee knows that the official system is monitored, moves sensitive discussions to a private channel, and then uses that channel for payment conversations linked to public approvals, the channel choice may support an inference of concealment.

Money That Followed Milestones

The prosecution next aligned communications with transaction events and financial flows. The indictment alleged that intermediaries used false consulting invoices to obtain reimbursement for bribes and routed funds from Turkey to Ghana through correspondent accounts in New York.

The chronology was central to the prosecution’s case. In April 2015, as the parties pushed toward execution of the emergency power agreement, an intermediary issued a $500,000 invoice. Emails allegedly discussed using part of that money to pay a Ghanaian official, and a $500,000 wire followed. Later that month, five Ghanaian officials traveled to Turkey to inspect equipment. The indictment alleged that their expenses were covered and each received $5,000.

When a senior Ghanaian official signed the agreement in May 2015, another invoice for $1.5 million was issued the same day. A $1.5 million transfer followed later that month. After Parliament ratified the agreement in July, emails discussed a $250,000 reimbursement request that included payments connected to Parliament, the Ministry of Power, regulators, engineers, travel, and Berko personally.

At trial, a government summary witness walked jurors through charts tracing funds from Aksa accounts in Turkey to accounts associated with intermediaries, Berko, and others. The records did not show the final transfer to every alleged official. Prosecutors answered that gap by pointing to evidence that cash was used to complete and conceal the payments. The amounts require discipline. The indictment alleged more than $700,000 in bribes. DOJ stated after the verdict that the government proved more than $1 million in bribes at trial.[1][5] Those figures come from different stages of the case and should remain separately attributed.

The Recorded Lunch

The recording supplied another form of corroboration. In November 2016, an FBI-assisted source met Berko at a London restaurant. The conversation moved among English, Twi, and Ghanaian Pidgin English, and the jury received a translated transcript. In one exchange, the source asked about a former energy minister. Berko replied that “KD got one million.” In another discussion, framed around a hypothetical investment, Berko initially said it was not good to pay the individuals under discussion. When asked for the best way to pay them, however, he answered, “Cash,” and said he could obtain $1 million from a bank.

The prosecution used these statements to reinforce its reading of the emails and money flows. The recording did not stand alone. It supplied the government’s alleged final piece of context: the same person who used private email for sensitive payments and appeared throughout the deal chronology also discussed a million-dollar payment to an energy minister and the practical use of cash. The source’s incentives, the FBI’s preparation of the conversation, translation issues, and the hypothetical framing were substantial defense subjects. They will be examined in Part 2. For the government’s case, the point was corroboration.

When Compliance Became Evidence

Goldman’s compliance response became part of the prosecution’s proof and, in my mind, one of the key components of the government’s overall presentation to the jury, as it was essentially evidence from an outside party to the transaction. Amandine Martin, who worked with Berko on the transaction, testified that Goldman spent months seeking explanations for payments to the Ghanaian intermediary. According to her testimony, the answers did not match information previously provided, and Aksa’s chief executive eventually responded that the company did not have time for the questions. Goldman withdrew from the transaction and did not provide the planned financing. Goldman was not charged in the criminal case. Prosecutors nevertheless used the compliance record to argue that Berko understood the risks and the institution’s rules, knew that his communications were monitored, and failed to correct allegedly false or incomplete explanations about the intermediary.

This is the first compliance lesson of the series: a control is also a record. Questions, responses, escalation, monitoring, and the decision to exit can later become evidence of what an employee knew, what the company challenged, and how the organization responded.

The Government’s Mosaic Holds

After approximately three hours of deliberation, the jury convicted Berko on all three counts: conspiracy to violate the FCPA, a substantive FCPA violation, and money laundering conspiracy. He was remanded pending sentencing. The general verdict does not tell us which email, payment path, witness, or recorded statement the jury found most persuasive. It also does not convert every factual assertion in the government’s narrative into a special finding. It does establish that the jury found the charged elements proven beyond a reasonable doubt.

That is the power of a circumstantial case. The government did not ask the jury to rely on one dramatic piece of evidence. It asked jurors to see a single pattern across communications, payments, timing, conduct, compliance warnings, and alleged concealment. The jury accepted that case.

Join us tomorrow in Part 2 where we will examine the defense’s answer: if the government said bribes went “up and down the chain,” where was the last mile showing money reaching a public official?

Resources:

United States v. Berko, No. 1:20-cr-00328-DG, Indictment, ECF No. 3 (E.D.N.Y. filed Aug. 26, 2020)

Stewart Bishop, “Goldman Jury Sees Cash Talk in Energy Deal Email Deluge,” Law360, Aug. 1, 2026; Stewart Bishop, “Goldman Exec Was Linchpin to Ghana Bribery Ploy, Jury Told,” Law360, Aug. 5, 2026.

Stewart Bishop, “Ex-Goldman Exec Convicted of Ghana Bribery Plot,” Law360, Aug. 6, 2026. Supplied trial reporting.

U.S. Attorney’s Office for the Eastern District of New York, “Former Goldman Sachs Investment Banker Convicted of Foreign Bribery and Money Laundering,” Aug. 6, 2026, DOJ Press Release.

Stewart Bishop, “Goldman Jury Sees Undercover Video as Bribe Trial Nears End,” Law360, Aug. 4, 2026—supplied trial reporting.

Stewart Bishop, “Shady Power Deal Used in Goldman Compliance Prep, Jury Told,” Law360, July 29, 2026

SEC Final Judgment against Asante Berko

SEC Complaint against Asante Berko

Categories
Blog

Scoular DPA Part 5: From Reinspection Fees to Executive Signatures: Final Lessons from Scoular

From Reinspection Fees to Executive Signatures: Final Lessons from Scoular

The Scoular Company FCPA enforcement action began with a deceptively simple fact pattern. Customs brokers allegedly paid Mexican officials approximately $2,000 per train so agricultural shipments could cross the border despite adverse inspection findings. The brokers invoiced the payments to Scoular as “reinspection fees.” That description, however, was only the first layer of the case.

Across this blog post series, Scoular Company became a study in third-party risk, internal controls, cartel exposure, off-channel communications, facilitating payments, data analytics, voluntary disclosure, remediation, DOJ oversight, and executive accountability. Each article examined one part of the control environment. Taken together, they tell a larger story about how bribery becomes normalized inside an operating process and what a company must do when that process fails.

The source distinction matters. I have now posted two series on the enforcement action. The first series relied on the DOJ Press Release, which announced the resolution and described the government’s allegations and conclusions. The second series relied on the formal Deferred Prosecution Agreement (DPA), in which Scoular admitted, accepted, and stipulated that the facts were true. The DPA did not merely add detail. It changed the evidentiary foundation of the analysis.

I.              Series One: Lessons From the DOJ Press Release

a.     A Small Payment Became an Enterprise Control Failure

The Press Release series began with the mechanics of the scheme. According to the DOJ announcement, the conduct ran from 2013 through 2019, involved more than $400,000 in bribes, and enabled Scoular to avoid more than $6.5 million in fees and costs. Scoular entered a three-year DPA and agreed to pay a $9,769,521 criminal penalty and $414,351 in forfeiture.

The compliance lesson was never the size of one payment. It was repetition. A recurring round-dollar charge, submitted by customs brokers, approved over six years, and recorded under a plausible description became part of the company’s operating model.

The phrase “reinspection fee” demonstrated why invoice controls must examine commercial substance. A three-way match can confirm that an invoice, purchase order, and approval agree. It cannot establish that the underlying service was legitimate. For a high-risk customs payment, the control must ask what government action occurred, who received the money, whether an official fee schedule supports the amount, and what happened to the shipment after payment.

This also exposed the limits of onboarding due diligence. Screening a broker and obtaining an anti-corruption certification are only the beginning. Effective third-party management connects onboarding to invoices, transaction monitoring, business outcomes, periodic review, audit rights, and termination decisions.

b.    Cartel Risk Expanded the Compliance Perimeter

The Press Release stated that a portion of the bribe payments ultimately benefited individuals associated with a cartel operating at the U.S.-Mexico border, although the DOJ said Scoular Company and its employees did not know of that connection.

In an episode of the FCPA Compliance Report,  Matt Ellis discussed a broader question. Traditional anti-corruption diligence focuses on government-facing intermediaries, ownership, political exposure, adverse media, and government relationships. Organized-crime connections may not appear in a corporate registry or screening database.

The lesson was not that every cross-border transaction benefits a cartel. It was that companies must understand the environment in which their money, goods, and third parties move. Customs brokers, trucking companies, warehouses, security providers, labor contractors, and subcontractors can create overlapping corruption, money-laundering, sanctions, trade, security, and organized-crime risks.

c.     WhatsApp Was Part of the Control Environment

The Press Release series also examined WhatsApp and other communications used to discuss shipments and payments. The critical point was not that employees selected an unapproved application. It was that the substantive business decision could occur in a private message while the formal system recorded only the resulting invoice. Ellis emphasized that enforcement priorities may change, but evidence does not. A WhatsApp message can establish knowledge, authorization, concealment, or control circumvention even without a standalone off-channel communications charge.

A defensible program must identify the applications employees actually use, define which business activities may occur there, preserve relevant records, address local privacy and employment law, and enforce violations consistently. The company must also be able to connect communications with payment records, inspection results, shipment identifiers, approval logs, and bank data.

Facilitation Payments Did Not Fit the Facts

The Press Release series then addressed why the payments were not protected as facilitating payments. The FCPA exception is narrow. It may cover a payment intended to expedite a routine, nondiscretionary governmental act that the company is already entitled to receive. Scheduling an inspection may be routine. Paying an official to disregard a failed inspection is not. The alleged Scoular payments did not change timing. They changed the outcome and enabled shipments to cross despite findings of dirt, soil, and other impurities.

Amount, urgency, local custom, invoice wording, and use of a third party do not create the exception. Nor does the exception authorize a false accounting entry. A company that permits facilitating payments must still confront local law, accurate books and records, approval controls, and the practical difficulty of asking employees to make a narrow legal distinction under commercial pressure.

II.   Lessons From the DPA and Admitted Facts

a.     The DPA Showed How the Scheme Became Normal

The DPA blog post series began by distinguishing allegations in the Press Release from facts Scoular Company admitted. The Statement of Facts showed that stricter Mexican inspections created operational pressure (IE., more or new/different risks) in 2013. A broker proposed a fee on every train and promised that Scoular Company would “not have a single risk of adverse determinations.” The proposal was discussed at Scoular Company’s Kansas office and then replicated through additional brokers and border crossings.

The communications removed ambiguity. Employees discussed soil findings, special payments, trains released after inspections, and situations in which “normal procedures are not working.” By 2018, a communication referred to offering officials more than was normally given. These facts showed normalization. The scheme was not simply a broker’s unauthorized act. It became a repeatable process linking operational pressure, management knowledge, third parties, communications, invoices, approvals, and favorable business outcomes.

b.    Stopping the Conduct Was Not Self-Disclosure

The DPA disclosed that internal reports emerged in 2019 and Scoular Company changed its practices and ended direct engagement with the brokers. Yet the company did not receive voluntary self-disclosure credit because it did not voluntarily and timely report the conduct. The DPA does not reveal the company’s internal debate so that speculation would be inappropriate. It does establish a governance lesson. An internal report starts two clocks: the investigation clock and the disclosure-decision clock. Stopping the conduct is remediation. It is not a substitute for a documented, timely decision about disclosure.

Scoular later received cooperation and remediation credit, including a 25 percent reduction from the bottom of the applicable Sentencing Guidelines range. That outcome demonstrates that missing voluntary-disclosure credit does not make later cooperation irrelevant. It also demonstrates that the two forms of credit are not interchangeable.

c.     Executive Signatures Became the Final Control

The DPA’s attachments translated compliance expectations into personal executive responsibility. They required compliance access to the board, adequate authority and resources, incentives and discipline, third-party business-rationale documentation, verification of services, reasonable compensation, data access, root-cause analysis, and remediation.

They also required two distinct certifications. The CEO and CFO must certify disclosure obligations. The CEO and Chief Legal Officer must certify the truth and completeness of DOJ reports and the design of the anti-corruption compliance program. The certification language references potential exposure under 18 U.S.C. §§ 1001 and 1519 for materially false statements or records.

The signature is therefore not ceremonial. It requires an evidence chain from front-line controls through management testing to board oversight.

d.    Data Analytics Connects Both Series

Vince Walden’s analysis supplied the final detection lesson. No single anomaly proves bribery. The stronger signal is a sequence: an adverse inspection, an unusual recurring broker payment, and a favorable shipment release.

The words “reinspection fee” were searchable. The approximately $2,000 round-dollar amount was testable. The brokers, routes, inspection outcomes, timing, and releases were linkable. Communications could then provide context. Analytics should rank anomalies for human investigation, not declare guilt by algorithm.

This is where internal controls become dynamic. The company should test transaction text, payment amounts, vendor concentration, duplicate descriptions, approval patterns, inspection results, clearance timing, and user access together. Every substantiated alert should improve the next rule, risk model, training decision, and control test.

e.     Compliance Takeaways

  1. Treat the process as the risk unit. Review the third party, payment, message, inspection, route, approval, accounting entry, and business outcome together.
  2. Test substance, not labels. Require evidence of the service performed, the lawful basis for the fee, the recipient, the calculation, and the official result.
  3. Expand third-party risk beyond corruption screening. Integrate organized-crime, sanctions, anti-money-laundering, trade, security, and supply-chain intelligence where the risk profile requires it.
  4. Govern communications as business records. Know which channels employees use, restrict substantive approvals to controlled systems, preserve records, and test retrieval before an investigation.
  5. Create a disclosure decision protocol. Define who evaluates material facts, what information is needed, when senior management and the board are briefed, and how the decision is documented.
  6. Use analytics to connect events. Build monitoring around sequences and outcomes, then route alerts to trained investigators with access to operational, financial, and communications data.
  7. Make certifications evidence-based. Executive signers and boards should demand documented control testing, root-cause analysis, remediation status, and unresolved exceptions before signing.

The final lesson from Scoular Company is that bribery rarely sits in one control. It moves through an operating system. An effective compliance program must see that system, test it continuously, and ensure that the people who oversee it can stand behind the evidence.

Categories
Blog

The Scoular DPA Part 4: The Signature Is the Control – Executive Accountability in the Scoular DPA

The Scoular Company Deferred Prosecution Agreement (DPA) ends where every effective compliance program should begin: accountability. The agreement does not leave anti-corruption compliance solely with the Chief Compliance Officer, legal department, or internal audit. It assigns responsibilities throughout the enterprise, then requires senior executives to certify that the company has met its disclosure and compliance obligations.

The CEO signs twice. The Chief Financial Officer signs the disclosure certification. The Chief Legal Officer signs the compliance certification. Each certification is expressly treated as a material statement and representation for purposes of 18 U.S.C. Sections 1001 and 1519. A compliance program is not effective because someone owns it. It is effective when executives can reasonably rely on tested evidence and personally stand behind the result.

Attachment C Creates an Accountability System

Attachment C contains the minimum elements Scoular must maintain in its anti-corruption compliance program. Read separately, they look familiar: risk assessment, policies, training, reporting, investigations, incentives, discipline, third-party management, testing, data access, and remediation. Read together, they create an accountability system.

Directors and senior management must provide strong, explicit, and visible support through actions and words. Middle management must reinforce that commitment in day-to-day operations. One or more senior corporate executives must oversee the anti-corruption program and have authority to report directly to internal audit, the board, or an appropriate board committee.

Those officials must also have adequate autonomy from management and sufficient resources, authority, and senior leadership support. This is more demanding than tone at the top. It asks whether compliance can challenge the business, reach the board, obtain data, investigate allegations, and require remediation when commercial pressure is greatest.

In the DPA, the admitted conduct involved customs brokers, failed inspections, disguised invoices, communications, and recurring business benefits. An empowered compliance function must connect those facts across organizational boundaries. Formal reporting access means little if the function lacks the people, technology, information, or standing to do that work.

Compensation and Discipline Make Culture Measurable

Attachment C requires compliance criteria in compensation and bonus systems. It also requires disciplinary procedures to be applied consistently and fairly, regardless of an individual’s position or perceived importance. Those provisions address the incentives that can turn a workaround into an operating model.

If a logistics team is rewarded only for delivery speed, it may treat a delayed train as failure. If a senior manager receives credit for avoiding demurrage but no consequence for bypassing controls, the company has placed its real values inside the compensation plan. Training cannot overcome incentives that point in the opposite direction.

Scoular must therefore do more than add a generic compliance factor to an annual review. It should define the behaviors that affect compensation, document how compliance input changes an award, and test whether consequences are applied upward as well as downward. The board should examine outcomes. Who lost compensation? Who received recognition for escalating a concern? Were supervisors assessed for misconduct they tolerated or failed to detect? Did seniority affect the consequence? Culture becomes credible when employees can see that ethical conduct affects careers, compensation, and promotion.

Third-Party Accountability Requires Proof of Work

The bribery scheme operated through customs brokers. Attachment C responds directly to that risk. Scoular Company must document the business rationale for using a third party, assess reputation and foreign-official relationships, describe services specifically in the contract, confirm that the work was actually performed, and determine whether compensation is reasonable for the industry and geography. Ongoing monitoring may include updated due diligence, training, audits, and annual certifications. This is an operating control, not a procurement checklist.

An approved broker, executed contract, and completed screening report do not establish that a reinspection occurred or that a payment was legitimate. The business owner must be accountable for the service, finance must validate the invoice, compliance must assess red flags, and internal audit must test whether the control works. The central question is not whether the broker passed onboarding. It is whether the company knows what the broker did with its money.

Data Access Connects Oversight to Evidence

Attachment C requires compliance and control personnel to have sufficient direct or indirect access to relevant data for timely and effective transaction monitoring and testing. It also requires root-cause analysis of misconduct and the sharing of systemic issues, control failures, and remediation with management as appropriate. That obligation connects the program to the certifications.

Executives cannot make a defensible representation about program effectiveness if compliance cannot obtain accounts-payable data, broker records, shipment information, inspection results, communications, investigation files, and audit findings. The company cannot certify complete disclosure if allegations remain fragmented across the hotline, internal audit, legal, due diligence, and business systems. Data access is therefore an accountability issue. It determines whether management can see the whole risk picture before signing.

Two Certifications, Two Different Questions

The DPA requires two certifications at the end of its term.

The CEO and CFO Certify Disclosure

Attachment E requires the CEO and CFO to certify that Scoular has disclosed any evidence or allegations required by the DPA, including qualifying FCPA or Foreign Extortion Prevention Act matters involving employees or agents.

The form expressly reaches information identified through the compliance and controls program, whistleblower channel, internal audit reports, due diligence, investigations, or other processes.

The CFO’s inclusion is significant. Disclosure is not treated as a legal department judgment alone. The certification requires an enterprise process capable of gathering information from finance, controls, audit, compliance, investigations, and the business.

Before signing, the CEO and CFO should know what allegations were received, how they were triaged, which matters were investigated, what remains open, and how the company determined whether each matter was reportable.

The CEO and CLO Certify the Program

Attachment F requires the CEO and Chief Legal Officer to certify that Scoular’s DOJ reports are “true, accurate, and complete.” They must also certify, based on their review and understanding, that the company has implemented a program meeting Attachment C and that the program is reasonably designed to detect and prevent anti-corruption violations throughout Scoular’s operations. That is not a promise that misconduct will never occur. No compliance program can guarantee that result.

It is a representation about design, implementation, coverage, and the quality of the reports submitted to the government. The signatories therefore need evidence that the program operates across the enterprise, including in high-risk markets and functions. The CCO may build and test much of that evidence, but the CCO does not sign Attachment F. The DPA places the final representation with the CEO and CLO.

Sections 1001 and 1519 Change the Sign-Off Process

Both certification forms state that they constitute material statements and representations for purposes of Section 1001 and records or documents for purposes of Section 1519. That language should create rigor, not panic. It does not mean an executive should refuse to sign because testing found exceptions. A credible program should find weaknesses. The question is whether the certification and supporting reports accurately describe the program, testing, findings, remediation, and remaining limitations.

The greater risk is a ceremonial sign-off supported by filtered information, unresolved contradictions, narrow testing, or undocumented assumptions. Scoular Company should treat certification as a process rather than an event. That process should include:

  1. A written certification standard tied to each representation in Attachments E and F;
  2. Sub-certifications from the leaders who own finance, compliance, legal, internal audit, investigations, human resources, procurement, and high-risk operations;
  3. A complete inventory of allegations, investigations, audit issues, control exceptions, remediation items, and DOJ commitments;
  4. Independent challenge of management’s evidence and closure decisions;
  5. Documented treatment of qualifications, unresolved matters, and contrary evidence; and
  6. Audit committee review before the executives sign.

Sub-certifications should support executive diligence without diluting executive responsibility. The purpose is to create a reliable chain of evidence from the operational control to the final signature.

The Board Must Oversee the Evidence

The board does not sign Attachments E or F. Its oversight role is nevertheless central. The board authorized the DPA, and Attachment C gives the anti-corruption function access to the board or an appropriate committee. The board should use that access to test whether management’s certification process is credible.

Directors should not ask only whether the company is on schedule. They should ask what evidence could prevent a certification, which findings remain open, whether management has limited the scope of testing, and whether compliance, legal, finance, and internal audit agree on the facts. This is also a Caremark-style oversight lesson. Board-level information systems must bring significant compliance risks and red flags to directors, particularly during a formal government resolution. A dashboard should not replace discussion of disputed findings, repeat issues, overdue remediation, or business resistance.

Is It Real or Is It Memorex

I acknowledge there is a contrary view of this which comes to us from my Compliance into the Weeds co-host, Matt Kelly. In a blog post entitled Scoular DPA Unveiled, Doesn’t Help, he questions why the company CCO is not required to certify the DPA. It could be, as Kelly writes, that “an agriculture supply business with 1,250 employees and $7.3 billion in revenue — even has a chief compliance officer; maybe it doesn’t, and the chief legal office also holds the CCO role.” He goes on to write, “Then again, if a company’s chief legal officer pulls double duty as the chief compliance officer too, and that’s why he or she is signing the certification — doesn’t that whole arrangement run contrary to the spirit of what the Justice Department wants to see for an empowered and autonomous compliance function?” He concludes by asking, “But if we’re now letting companies sign prosecution agreements where they commit to a strong, independent, empowered compliance function, except for the part that you don’t even have an actual chief compliance officer — then what are we even doing here, people?” [Emphasis supplied]

The Scoular Company website lists the Chief Legal Officer as Tim Manning, whose duties include leading “ Scoular’s legal team and serves as principal advisor on legal, risk, compliance, governance, and other matters to Scoular’s Senior Leadership Team and Board of Directors. He also has oversight of Scoular’s real estate function.” It appears the CCO and GC functions are wrapped into one person’s job description.

The Bottom Line on Accountability

We began this week’s blog post series with the admitted facts from the DPA: a payment process designed to prevent adverse customs decisions. It then examined the missed voluntary-disclosure window and a deep dive into how the use of data analytics and internal controls could have caught the FCPA violation. Today we end with the signatures. Scoular Company’s DPA demonstrates that executive accountability is not an abstract statement about culture. It is built through access, resources, incentives, discipline, third-party controls, data, testing, root-cause analysis, and complete reporting. The signature is not the beginning of accountability. It is the final confirmation that accountability has operated throughout the company, at least during the term of the DPA.

Categories
Blog

The Scoular DPA Part 3: The Data Was Talking – Data Analytics and the Scoular Bribery Scheme

The Scoular Company bribery scheme was hidden, but it was not invisible. For six years, customs brokers paid Mexican officials approximately $2,000 per train so Scoular Company shipments could cross the border despite adverse inspections. The brokers invoiced the payments back to Scoular as “reinspection fees.” In total, Scoular Company admitted that it authorized $414,351 in bribes and avoided approximately $6.5 million in fees and costs. Those facts describe an FCPA violation. They also describe a data pattern.

I had the opportunity to visit with Vince Walden, CEO of KonaAI, about the Scoular Company FCPA enforcement action from a data analytics perspective. He identified the feature that should command every CCO’s attention: people concealing misconduct often record it consistently. They may avoid the word “bribe,” but they still need a repeatable description that allows the payment to be processed, reconciled, and found again. At Scoular Company, that description was “reinspection fee.”

Walden’s observation goes to the heart of modern compliance. Illegal conduct may be concealed from the compliance department while remaining visible in accounts payable, journal entries, invoices, purchase orders, shipment records, and communications. The control failure occurs when those systems hold the evidence, but the company never asks the data the right questions.

Consistency Can Become the Fraudster’s Fingerprint

Walden observed that accountants value consistency because consistent classifications support accurate reporting. Fraudsters and their enablers can exploit the same discipline. A bookkeeper cannot label a payment “bribe expense.” The payment still needs a code, description, vendor, amount, approver, account, and business purpose. If the scheme continues, the participants need a method they can repeat. That repetition creates a fingerprint.

Suspicious terms in payment descriptions and journal entries are among the most useful anti-corruption monitoring tests. His examples included phrases such as “friend fee,” “government payment,” and “miscellaneous.” The precise word will vary by company and geography. The analytical principle does not.

The company should identify unusual language, then connect it to the transaction behind it. Even if the language is not unusual, its repeated use might form a pattern worth exploring. A word cloud may provide a useful visual starting point. Keyword searches, natural-language processing, and risk dictionaries can scale the review across thousands of invoices and expense reports. Yet the purpose is not to find one forbidden word. It is to identify language that is unusual for the business, unusually frequent for one vendor, or correlated with a high-risk outcome. “Reinspection fee” was facially plausible. Repetition changed its meaning.

The First Test Was Hiding in Plain Sight

An elementary analytic (As in Elementary, my dear Watson) would have grouped customs-related payments by invoice description, vendor, amount, port, and frequency. That test could have asked:

  • How often does “reinspection fee” appear?
  • Which brokers submit the charge?
  • Is the amount repeatedly near $2,000?
  • Which employees approve it?
  • Does it appear only on trains with an inspection problem?
  • What happens to the shipment immediately after payment?

No single answer proves bribery. Together, the answers can create a compelling reason to investigate. The recurring round-dollar amount matters. Legitimate inspection costs often vary with the service, product, weight, time, port, or government fee schedule. A repeated $2,000 charge across multiple transactions may indicate a fixed unofficial tariff rather than the cost of a legitimate service.

The description also matters. If “reinspection fee” was not found in an approved government schedule, lacked official documentation, or appeared only in broker invoices rather than government receipts, the control should have required escalation before payment. Finally, the outcome matters most. If trains that failed inspection were consistently released after the fee, the company had more than an accounting anomaly. It had a payment linked to a favorable exercise of government discretion.

Connect the Payment to the Business Outcome

Traditional controls often examine whether an invoice matches a purchase order and whether an authorized employee approved it. A bribery scheme can satisfy both tests when employees are participating in the misconduct.

Data analytics must therefore test commercial substance, not merely procedural completion.

For Scoular Company, the decisive data model would connect five sources:

  • Inspection data: date, result, impurity identified, inspector, agency, and reinspection history.
  • Shipment data: train identifier, product, port, broker, delay, release time, and disposition.
  • Payment data: invoice description, amount, general-ledger account, supporting documents, approver, and payment date.
  • Third-party data: broker risk rating, contract terms, bank account, audit rights, ownership, and compensation history.
  • Communications data: relevant emails, WhatsApp records lawfully available to the company, and other business messages.

With those sources joined, compliance could test whether a $2,000 broker charge followed an adverse inspection and then by rapid release of the train. It could compare release rates for shipments with and without the payment. It could identify which brokers, ports, and employees produced unusually favorable clearance outcomes. That sequence is the analytic signature of the scheme: failed inspection, unusual payment, successful release.

Build a Layered Anti-Bribery Analytics Program

A mature program should not depend on one keyword or one dashboard. It should use several complementary tests.

Text analytics. Search invoice narratives, journal entries, purchase orders, and expense descriptions for high-risk terms, euphemisms, spelling variants, and unusual phrases. The risk dictionary should reflect the company’s markets and evolve with investigations.

Transaction analytics. Flag recurring round-dollar payments, duplicate or near-duplicate invoices, payments just below approval thresholds, split payments, weekend postings, manual journal entries, and charges lacking official receipts.

Vendor analytics. Compare customs brokers by fee frequency, payment descriptions, clearance rate, failed-inspection rate, use of subcontractors, changes in bank accounts, and concentration under particular employees or business units.

Outcome analytics. Test whether payments are statistically associated with permits, inspections, releases, tax outcomes, contract awards, or other favorable government actions. This moves the review from what the invoice says to what the payment accomplished.

Sequence analytics. Measure the time between an adverse event, a payment request, approval, payment, and favorable resolution. Short, repeated intervals can reveal a designed process.

Communications analytics. Where lawful and consistent with company policy, match high-risk transactions to messages about urgency, guarantees, officials, inspections, exceptions, or payments. A suspicious invoice can corroborate a message, and a message can explain the invoice.

Network analytics. Map relationships among employees, brokers, bank accounts, ports, approvers, and government touchpoints. Shared bank accounts, common addresses, unusual subcontractors, or recurring approval chains can expose concealed connections.

These tests should create ranked alerts, not automated accusations. Analytics identifies anomalies. Trained reviewers determine whether the transaction has a legitimate explanation, requires more evidence, or warrants an investigation.

Continuous Monitoring Is a Governance Choice

Walden’s closing advice was simple: keep innovating and keep running the analytics. The word “running” matters. As in continuously. A one-time review performed after a subpoena is forensic reconstruction. A risk-based test operating monthly, weekly, or at the point of payment is a compliance control.

Continuous monitoring does not mean surveillance of every employee or review of every transaction. It means that known high-risk processes receive repeatable testing at a frequency aligned with the risk. Customs payments, government-facing third parties, failed inspections, and manual financial entries deserve more attention than ordinary low-risk purchases.

The program also needs governance. Compliance and internal audit should agree on data ownership, alert thresholds, reviewer responsibilities, escalation standards, documentation, privacy requirements, and feedback loops. Finance must help validate legitimate payment patterns. The business must explain operational outcomes. Technology must maintain data quality and access. Legal must ensure that communications monitoring is lawful.

Most importantly, the board should ask whether compliance has direct access to the data. A dashboard built from incomplete information can create false assurance. If broker invoices sit in one system, inspection results in another, shipment releases in a third, and WhatsApp messages outside company retention, the organization sees fragments while the scheme operates across the seams.

Internal Controls Must Learn From Every Alert

Data analytics is not a substitute for internal controls. They supplement each other, as data analytics is a way to test whether those controls work and where they fail. An alert concerning a reinspection fee should trigger questions about official documentation, approved fee schedules, broker contracts, audit rights, segregation of duties, approval thresholds, and the economic rationale for the charge. If the review confirms misconduct, root-cause analysis should determine why the payment passed through accounts payable, why the broker remained active, why inspections and payment data were not connected, and whether incentives rewarded shipment clearance over compliance.

Every closed alert should improve the system. Confirmed concerns should add new keywords, vendor attributes, transaction patterns, and outcome measures. Legitimate transactions should help refine thresholds and reduce noise. This is how a compliance program becomes adaptive rather than static.

Questions for CCOs

CCOs should ask:

  • Which payment descriptions recur in our highest-risk government-facing processes?
  • Can we connect invoices to inspections, permits, customs outcomes, and shipment releases?
  • Which third parties generate unusually favorable results after unusual payments?
  • Are alert reviewers trained to investigate commercial substance, not merely paperwork?
  • How quickly does a confirmed issue change our controls and analytics?

The Bottom Line

Scoular Company’s bribery scheme did not require a sophisticated algorithm to detect. It required the company to notice a repeated phrase, a recurring amount, a high-risk broker, an adverse inspection, and a favorable government outcome. Walden’s lesson is that concealment often creates consistency, and consistency creates data. The task of compliance is to convert that data into a question early enough to matter.

Follow the words. Test the amount. Connect the outcome. Then channel your inner Sherlock Holmes and investigate what the pattern is telling you.

Categories
Blog

The Scoular DPA: Part 2 – A Journey Through Non-Disclosure

The Scoular Company Deferred Prosecution Agreement (DPA) presents a difficult but essential lesson for every Chief Compliance Officer and board: stopping misconduct is not the same as voluntarily disclosing it. This might seem as self-evident as anything in compliance, but it is a critical component of this case.

The Statement of Facts says that internal reports alleging improper business practices connected to the Mexican inspection fees arose in 2019. Scoular then changed its grain-shipment practices and terminated its direct engagement with the customs brokers involved. Those steps addressed the immediate conduct. They did not produce voluntary self-disclosure credit. That misstep cost Scoular Company millions, potentially leading to a full declination.

The DPA states that Scoular did not receive credit under the DOJ Corporate Enforcement and Voluntary Self-Disclosure Policy (VSP) because it did not “voluntarily and timely disclose” the conduct to the Fraud Section. That single sentence creates the central governance question in Blog Post Part 2: What must happen after a credible internal report reaches the company? An internal allegation starts an investigative clock. The company must preserve evidence, protect against retaliation, assess immediate risk, and establish enough facts to make responsible decisions. It also starts a disclosure clock.

The VSP encourages companies to report potential wrongdoing at the earliest possible time, even before an internal investigation is complete. To qualify as a voluntary self-disclosure, a report must be made in good faith to the appropriate DOJ component, concern misconduct not already known to the Department, occur without a preexisting disclosure obligation, precede an imminent threat of disclosure or government investigation, and be made within a reasonably prompt time after the company becomes aware of the misconduct.

The burden of demonstrating timeliness rests with the company. This does not mean a company must call the DOJ the moment an untested allegation enters the hotline. It does mean disclosure cannot wait until every interview, legal conclusion, and remediation project is complete. The investigation and disclosure analyses must proceed together.

The DPA Tells Us the Result, Not the Internal Debate

The agreement does not explain who received the 2019 reports, how the allegations were investigated, when senior management or the board learned of them, or why Scoular did not make a qualifying disclosure. It does not tell us whether the company made a deliberate decision not to report. What the DPA does establish is the outcome. Internal reports arose. The company changed its practices and terminated direct broker relationships. The company did not voluntarily and timely disclose the conduct to the Fraud Section and therefore received no voluntary disclosure credit.

That sequence is enough to demonstrate a control lesson. A company can remediate an operational problem and still leave the enforcement decision unresolved. The response requires four distinct workstreams:

  • Stopping the conduct prevents additional harm.
  • Investigating the conduct determines what happened and which controls failed.
  • Remediating the controls reduces recurrence risk.
  • Evaluating disclosure determines whether, when, where, and how the company should approach enforcement authorities. This fourth step is arguably the most important and must be reached with great speed, perhaps as little as two weeks after initial determination.

A Disclosure Needs a Decision Process

Disclosure decisions should not depend on one executive’s instinct or on the hope that remediation will close the matter. The company needs a defined escalation structure involving legal, compliance, internal audit, finance, and appropriate senior management. Depending on the seriousness of the facts, the audit committee or another independent board committee may need to oversee the decision.

For an FCPA matter involving customs brokers, repeated payments, government officials, inaccurate invoice descriptions, senior personnel, and multiple years of conduct, the disclosure analysis should address:

  • What credible facts are known now?
  • Is the misconduct continuing?
  • Which individuals and third parties may be involved?
  • Are the books and records inaccurate?
  • Is there evidence of management participation, approval, condonation, or willful ignorance?
  • Has a whistleblower, auditor, regulator, bank, business partner, or foreign authority already received the same information?
  • Is there an imminent threat that the DOJ will learn of the conduct?
  • What additional facts are necessary to make a disclosure decision?
  • When will the decision be revisited?
  • Who has authority to decide, and how will the reasoning be documented?

The objective is not to create a paper defense for a predetermined result. It is to establish a disciplined process that forces the company to confront timing, uncertainty, accountability, and enforcement exposure.

Disclosure Does Not Require a Finished Investigation

One reason companies may delay is the understandable fear of reporting facts that are incomplete or later prove wrong. The DOJ policy addresses that concern directly. It encourages early disclosure even when the company has not completed its internal investigation. The company can report the misconduct known at that stage, identify the limits of its current knowledge, preserve credibility by avoiding unsupported conclusions, and provide rolling updates as the investigation develops.

That approach requires discipline. The initial disclosure should distinguish facts from allegations, describe preservation and remediation steps, and explain the investigative plan. Later presentations should attribute facts to specific sources and identify individuals regardless of seniority.

Waiting for certainty can eliminate the benefit the company hoped to secure. A whistleblower may contact the government, a third party may cooperate, or the payment may surface in another investigation. Once the DOJ already knows or disclosure is imminent, the analysis changes. The business lesson is straightforward. Uncertainty calls for a staged disclosure strategy, not an indefinite pause.

Cooperation Still Mattered

Scoular Company lost the disclosure benefit, but the DPA demonstrates that the company could still earn meaningful credit. The DOJ credited Scoular with conducting an internal investigation, making detailed factual presentations, identifying individuals involved, producing and organizing requested materials, securing counsel for current employees, and providing all relevant facts known to it.

Voluntary self-disclosure, cooperation, and remediation are separate pillars. A company that misses the first can still create value through the other two. The DPA also notes “certain deficiencies in the early part of the investigation.” It does not identify those deficiencies, and they should not be guessed. Their inclusion nevertheless sends a message: cooperation is judged across the life of the investigation, not merely by the quality of the final presentation.

The current DOJ policy makes the standard explicit. A company starts at zero cooperation credit and earns credit through specific actions: scope, quality, impact, and timing matter. A failure to cooperate fully at the earliest opportunity may reduce the credit available later. For CCOs and boards, the lesson is that recovery remains possible, but delay has a price.

Remediation Changed How the Business Operated

Scoular also received credit for substantial remediation. The company increased compliance engagement with the business, used external compliance maturity and anti-corruption risk assessments, restructured the compliance function, and incorporated senior leadership oversight. It eliminated customs brokers associated with reinspection fees, strengthened risk-based review and monitoring with software tools, revised policies, enhanced third-party screening and approvals, added anti-corruption and audit-right provisions to contracts, improved financial controls for high-risk transactions, and delivered general and targeted training.

These measures went beyond terminating vendors. They addressed governance, third-party management, payment controls, monitoring, technology, policies, and training. That breadth matters because remediation must be tied to root cause. If the misconduct was enabled by commercial pressure, broker dependence, misleading invoices, weak transaction validation, and fragmented data, another annual training course will not solve the problem.

The Economic Difference Was Significant

Scoular entered into a three-year DPA and agreed to pay a $9,769,521 criminal penalty and $414,351 in forfeiture. The DPA states that the penalty reflected a 25 percent reduction from the applicable low-end amount. A footnote explains that the statutory alternative-fine cap, based on twice the approximately $6.513 million gross gain, constrained the otherwise higher Guidelines minimum.

The DPA does not say what disposition Scoular would have received after a qualifying disclosure. It would be improper to rewrite the resolution with hypothetical facts.

The current department-wide CEP nevertheless shows why the distinction matters. A company that voluntarily self-discloses, fully cooperates, timely remediates, and has no disqualifying aggravating circumstances is placed on a declination path. A good-faith self-report that narrowly misses the policy’s technical requirements can still lead to an NPA, a term shorter than three years, no monitor, and a reduction of 50 to 75 percent from the low end. Companies outside those paths remain subject to prosecutorial discretion, with a reduction capped at 50 percent.

Scoular received a DPA, a three-year term, and a 25 percent reduction. The numbers turn disclosure governance into a business issue. The decision affects resolution form, penalty exposure, duration, oversight, reputation, management time, and the company’s ability to move beyond the misconduct.

Questions for CCOs

CCOs should ask:

  • Does every credible allegation involving government payments trigger a documented disclosure analysis?
  • Who owns the disclosure clock while the investigation proceeds?
  • Can legal and compliance make an early report without waiting for a completed investigation?
  • Are facts, assumptions, open questions, and decision deadlines documented separately?
  • Have we tested the process through a tabletop exercise involving a whistleblower, a third party, and an imminent government inquiry?

The Scoular DPA does not establish why the company missed voluntary disclosure credit. It does establish that internal reporting, operational remediation, and voluntary disclosure are not interchangeable. When a credible allegation arrives, the company must stop the conduct, investigate the facts, remediate the controls, and make a timely, documented disclosure decision. Doing three of those four things can still leave substantial value on the table.

Join us tomorrow for Part 3, where we will examine how a robust internal control system paired with a robust data analytics overview can help a company avoid a Scoular Company-type series of failures.

Categories
FCPA Compliance Report

FCPA Compliance Report: Matt Ellis Wrap-Up from Cartels, FTO Risk, and Corporate Compliance Conference

In this episode, Tom Fox welcomes back Matt Ellis of Miller & Chevalier to recap ACI’s inaugural two-day Cartel Conference in Washington, DC, highlighting an unusually collaborative, high-energy atmosphere around emerging cartel/TCO/FTO compliance risks in Latin America.

They discuss DOJ’s Scoular FCPA action as illustrating the long tail of enforcement and a high bar for managing cartel-related and national security risks, while noting the DPA’s remedial steps focus more on traditional anti-corruption controls than TCO/FTO-specific guidance. Government participants emphasized a “whole of government” approach, voluntary disclosure, and potential public-private engagement (including embassy attachés and Treasury) in high-risk scenarios. Key themes included narrow duress defenses, complex “imposter” risks, evolving due diligence beyond traditional screening using data/anomaly detection and local intelligence, and the need to integrate compliance across AML, sanctions, security, and supply chain given severe reputational and business consequences of terrorist or cartel support.

Key highlights:

  • Conference Vibe and Energy
  • Scoular FCPA Case Takeaways
  • When to Engage Government
  • Duress Defense and Safety Payments
  • Cartel-Focused Due Diligence
  • AML Lessons for Banks
  • Breaking Silos in Compliance
  • Parallels to Early FCPA Era
  • National Security Stakes

Resources:

ACI National FCPA and Global Anti-Corruption Conference, December 10-11 at the Gaylord National Resort & Convention Center, Washington, DC

Matt Ellis on LinkedIn

Tom Fox

Instagram

Facebook

YouTube

Twitter

LinkedIn

To learn about the intersection of Sherlock Holmes and the modern compliance professional, check out my latest book, The Game is Afoot-What Sherlock Holmes Teaches About Risk, Ethics and Investigations on Amazon.com.

Categories
Blog

The Scoular DPA: Part 1 – From Suelo to the Bribery System at Scoular

My earlier analysis of The Scoular Company FCPA enforcement action necessarily relied on the Department of Justice Press Release. That release described the government’s allegations. The formal Deferred Prosecution Agreement (DPA) expands the footing of the discussion. We are no longer working only from a prosecutor’s summary. We now have a detailed chronology of facts the company formally admitted.

Those facts reveal a scheme connecting stricter Mexican inspections, commercial pressure, employees, multiple customs brokers, a meeting at a company office, invoices, wire payments, WhatsApp, and millions in avoided costs. The central compliance lesson is normalization. A corrupt proposal became a repeatable business process. Over the next four blog posts, I will be taking a deep dive into the DPA, what it tells us, and what we must speculate on.

The Scheme Began With a Change in Enforcement

Scoular transported corn and other agricultural products from the United States into Mexico. Those trains were inspected by Mexico’s Secretariat of Agriculture and Rural Development, referred to in the DPA by its former name, SAGARPA.

Inspectors looked for dirt, soil, and other impurities, sometimes described as “suelo.” SAGARPA approval was required before a train could enter Mexico. When inspectors detected suelo, the agency could delay entry, and the shipment could incur fumigation and demurrage costs.

Beginning around 2013, Mexican authorities conducted the inspections more rigorously. The result was more soil findings in Scoular shipments and greater exposure to delay, fumigation, and demurrage. This legitimate business problem called for better product controls and contingency planning. It also created pressure that made a corrupt alternative attractive.

Compliance failures often begin here. Regulation becomes more rigorous, costs increase, and delivery commitments are threatened. The governance question is whether management improves the process or finds a way around the control. This demonstrates why a continuous risk assessment is so critical; when your risks change, you need to perform an updated risk assessment.

The Proposal Was a Guarantee Against Adverse Decisions

In June 2013, customs broker Carlos Leopoldo Alvelais contacted a Scoular sales employee and a Scoular senior manager. According to the DPA, he proposed a procedure under which Scoular would pay a fee on every train. The purpose was not ambiguous. The proposal was designed to ensure that Scoular would “not have a single risk of adverse determinations from Mexican inspectors.” That sentence captures the scheme.

A legitimate broker can prepare documents, coordinate an inspection, and challenge an incorrect result. It cannot guarantee that a regulated company will never receive an adverse decision. A promise of zero regulatory failure should be treated as a red flag, not a service level. James Min made this clear with his risk matrix for assessing risk in customs broker clearance rates. If a customs broker offers you a 100% success rate – to quote Monty Python from The Holy Grail: Run Away Run Away, do not walk away.

The DPA says that, later in June 2013, Alvelais traveled to Scoular’s Kansas office and met with Scoular employees and others. After that meeting, he began paying bribes to Mexican officials and invoicing Scoular for reimbursement. The invoices described the payments as “REVISION SAGARPA PROCESS” (Reinspection Fees herein), generally in round amounts of $2,000.

The Kansas meeting is a significant new fact. The arrangement was not confined to an informal exchange between a local employee and a broker at a remote border crossing. The broker presented the approach at a company office. After the meeting, the payments began. This speaks to a serious failure in an overall compliance program: failure in communication, failure in training, failure in risk assessments, failure in internal controls, and failure in overall compliance visibility into the business operations of an organization it is supposed to keep in compliance.

At a minimum, when a high-risk third party visits a company office to propose a government-facing payment process, the arrangement should require a documented business rationale, legal and compliance review, a payment protocol, and supporting evidence. Without those controls, the meeting can move misconduct into the company’s operating structure. This basic failure led to catastrophe for Scoular Company.

The Payment Process Was Replicated

The DPA places a sales employee and a senior manager who worked on international grain sales and shipments at the center of the conduct. They authorized reimbursement of Reinspection Fees to Alvelais and his companies while knowing that at least part of the money would be used to bribe Mexican border officials. The objective was to ensure that Scoular trains passed inspection without the fumigation, demurrage, and other costs associated with soil findings and failed inspections.

But it got worse from there. Scoular then replicated the approach with two other customs brokers. That replication is critical. This was not simply a broker corrupting a customer. Company personnel took a method used with one broker and extended it to additional agents. The model followed the business.

The DPA describes cash payments of up to $2,000 per train. Scoular employees and agents coordinated the scheme through email, messaging applications, and other communications. Invoices were transmitted, and Scoular caused payments to be made by wire. The scheme therefore had all the components of a functioning process:

  • A recurring commercial problem
  • A third-party payment mechanism
  • Employee knowledge and authorization
  • Multiple participating brokers
  • Standard invoice descriptions
  • Company reimbursement
  • Off-channel and conventional communications
  • A measurable business benefit

Each component could look ordinary when reviewed separately. Together, they formed the bribery scheme.

The Communications Made the Purpose Clear

The admitted communications are especially instructive because they connect payment, knowledge, and outcome. In August 2015, an Alvelais employee informed a Scoular employee that inspectors had detected soil in a train. The train was nevertheless released without delay, and the account would include a $2,000 charge. In October 2015, a Scoular employee sent a WhatsApp message to the senior manager stating that Alvelais would provide a favorable rate and guarantee that no train headed to a particular buyer would be stopped for soil. Another October 2015 communication listed “Dispatch of merchandise in the presence of soil” at $2,000 per shipment.

Later that month, a Scoular employee reported that the broker was doing everything possible to move a shipment, but an inspector’s supervisors were in town and “normal procedures” were not working. By 2018, the language was even more direct. During an exchange concerning pests detected in a shipment, an Alvelais employee wrote that the broker had offered more than it normally gave and the officials had not accepted it. A Scoular employee responded by asking why the broker was requesting double if the issue was fixed for soil.

These communications defeat any claim that employees believed they were paying published government fees. They describe adverse findings, guarantees against stopped trains, and payments beyond ordinary amounts. No single record tells the complete story. The invoice supplies the accounting description, the message supplies intent, the inspection record supplies the regulatory event, and the release time supplies the outcome. Investigations and monitoring must connect all four.

The Scheme Continued Into 2019

The DPA identifies three invoices from 2019:

  • A $3,000 “SAGARPA process” fee from an Alvelais company
  • A $1,750 “Other Inspection” fee from a second customs broker
  • A 35,000 Mexican peso “SERVICIOS DE SAGAR” fee, approximately $1,835, from a third customs broker

Scoular promptly paid each invoice.

The changing descriptions are a lesson in internal control design. A monitoring rule limited to “reinspection fee” would have missed “SAGARPA process,” “Other Inspection,” and “SERVICIOS DE SAGAR.” Compliance analytics must identify families of risk, not merely exact words.

The DPA says that internal reports alleging improper business practices connected to the SAGARPA fees arose in 2019. Scoular then changed its practices for grain shipments into Mexico and terminated direct engagement with the customs brokers involved.

That response ended the factual chronology, but it opens the next compliance question: what happened between the internal reports and the DOJ resolution, and why did Scoular receive no voluntary self-disclosure credit? That will be the focus of Part 2.

The Economics Show Why the Scheme Endured

Between approximately 2015 and 2019, Scoular authorized $414,351 in bribes to bypass inspections and secure unhindered passage into Mexico. The company avoided approximately $6,513,014 in demurrage and related costs. That is more than $15 in avoided costs for every dollar paid in bribes.

The ratio does not excuse the conduct. It explains the incentive that allowed it to become embedded. A $2,000 charge could appear small against the cost of a delayed train, while the accumulated benefit rewarded the business process that produced the misconduct. This is why compliance cannot evaluate customs payments only by individual transaction value. The relevant indicators include frequency, round amounts, timing, inspection outcome, avoided cost, broker success rate, and management awareness.

The Compliance Failure Was Normalized

The Scoular Statement of Facts shows how misconduct can become ordinary:

  • External enforcement became more rigorous.
  • The business faced higher costs and delays.
  • A broker proposed a fee-based solution.
  • The broker met with employees at a company office, and payments followed.
  • Brokers paid officials and invoiced Scoular.
  • Employees authorized reimbursement.
  • The approach expanded to other brokers.
  • Messages and invoices developed a shared vocabulary.
  • The business received predictable passage and high avoided costs.
  • The process continued until internal reports surfaced.

The DPA does not describe a control that failed once. It describes an alternative control environment that operated for years.

The DPA sharpens the Scoular lesson. The scheme was not simply a series of border bribes. It was a business process built to eliminate the risk of adverse government decisions. When a third party offers that result, compliance should assume the risk has not disappeared. It has merely been transferred into a payment, an invoice, and a promise that deserves immediate scrutiny.

Join us tomorrow, where we take a deep dive into the Scoular Company’s failure to self-disclose and the long-term ramifications.

Categories
Blog

Connected Compliance: Part 5 – From Signals to Trust: Why Compliance Must Operate as One System

We conclude our series on various components of connected compliance by pulling them all together in an integrated whole. An effective compliance program is often described through its components: policies, training, risk assessment, reporting channels, investigations, discipline, and monitoring. That description is accurate, but incomplete. It tells us what the program contains. It does not tell us how the program works.

The deeper lesson from this series is that compliance effectiveness lives in the connections. Communication, risk sensing, investigations, and whistleblower programs are not separate workstreams that happen to sit under the same organizational chart. They are parts of one information-and-accountability system. Each part produces information that another part must receive, interpret, and convert into action.

That is the integrated argument. Compliance is truly connected because risk moves through an organization as a signal before it becomes an event. An employee question, customer request, control exception, supplier problem, unusual payment, new technology use, or hotline report may be the first indication that the company’s risk profile has changed. The program succeeds when it can move that information through a disciplined cycle: listen, assess, assign, investigate, remediate, communicate, and learn.

The program fails when the signal dies at a handoff.

The Seams Are Where Compliance Breaks

Most companies do not lack compliance activity. They lack reliable movement between activities. Training may be completed, but recurring questions never reach the risk assessment. A hotline may capture an allegation, but intake and investigation teams may use different priorities. An investigation may identify a control weakness, but the remediation owner may not be named. A new policy may be issued, but compliance may never test whether employees understand the change. Each function can report progress while the overall system remains ineffective.

This is why silos create more than inefficiency. They create control risk. A program can look mature by function and still fail as a system because no one owns the transfer of information, the decision deadline, or the feedback loop. Compliance professionals should therefore examine the seams: Who receives the signal? Who decides what it means? Who owns the response? What evidence confirms completion? Who tests whether the response worked? How does the lesson return to employees, managers, controls, and the risk assessment? Those are not administrative questions. They are the architecture of effectiveness.

Compliance Is an Information System

Communication is the first connection because it moves information in both directions. It tells employees what the organization expects, but it also tells compliance what employees are experiencing. Questions, requests for advice, training discussions, manager escalations, surveys, and workplace observations are all risk data. Communication becomes a control when it does more than broadcast. It creates a dependable exchange.

That information must then enter a dynamic risk process. Risk assessment is not merely a periodic exercise that ranks known categories. It is the organization’s method for deciding which signals require monitoring, immediate containment, deeper review, new controls, or additional resources. The quality of that decision depends on access to operational information across functions.

The Department of Justice (DOJ) makes this connection explicit in its 2024 Evaluation of Corporate Compliance Programs (ECCP). The ECCP asks whether periodic risk review is limited to a point-in-time snapshot or is based on “continuous access to operational data and information across functions.” It also asks whether the results lead to updates in policies, procedures, and controls. The enforcement lesson is straightforward: information must move, and it must change the program.

Compliance Is Also an Accountability System

Information alone does not create effectiveness. The organization must make decisions and assign responsibility. When a risk signal becomes an allegation, the investigation process establishes reliable facts. A credible investigation determines scope, protects evidence, preserves independence, treats witnesses fairly, reaches a supported conclusion, and identifies root causes. Its value is not limited to deciding whether one person violated a policy. It should reveal what the organization must change.

This is the point where accountability often weakens. A case may close when a report is issued, even though the control failure remains. Discipline may address the individual without addressing incentives, supervision, access rights, third-party oversight, or prior warnings. Recommendations may be accepted without an owner, deadline, testing plan, or escalation route.

A connected program treats investigation closure as the beginning of remediation. Findings should feed risk assessment, control design, training, management reporting, and resource allocation. Remediation should then be tested, and the result should be documented. If the company cannot show how a material finding changed the program, it has created a record of the past, not a control for the future.

Trust Is Both an Input and an Outcome

The whistleblower program completes the system because it determines whether critical information enters at all. A hotline provides access, but employees decide whether the reporting system is credible. Their decision is shaped by manager behavior, confidentiality practices, investigation quality, anti-retaliation protection, communication during the process, and what they observe after a concern is raised.

Trust is therefore not a soft cultural benefit sitting outside internal control. It is an operating condition for detection. Employees who believe that reporting is unsafe or futile will withhold information. The company then loses the opportunity to address misconduct early, protect people, preserve evidence, and reduce loss. Trust is also an outcome of the company’s response. A respectful intake, timely triage, fair investigation, consistent accountability, active anti-retaliation monitoring, and appropriate closure communication strengthen the next employee’s willingness to speak. A mishandled matter does the opposite. Every case affects the future supply of risk information.

The ECCP captures this end-to-end logic. It calls for an “efficient and trusted mechanism” for anonymous or confidential reporting, asks whether reporting and investigation information is analyzed for patterns and compliance weaknesses, and asks whether the company tests hotline effectiveness by tracking a report from start to finish. That is a systems test. It examines the full journey, not the existence of a vendor platform.

Think in Loops, Not Lines

Compliance professionals should stop viewing the program as a sequence that ends when a task is completed. Training does not end with completion. Risk assessment does not end with a heat map. An investigation does not end with a finding. A report does not end when the case is closed.

Each activity must create an output for the next decision and a feedback path to the earlier controls. Communication produces risk intelligence. Risk assessment prioritizes that intelligence. Reporting channels supply allegations and weak signals. Investigations convert allegations into facts and root causes. Remediation changes controls and accountability. Communication then explains the change, and monitoring tests whether it worked. The experience shapes culture and determines whether employees will use the system again.

This loop also changes the role of the compliance professional. The CCO does not need to own every business risk or perform every task. The CCO must help design and steward the system that connects them. That means establishing decision rights, information-sharing protocols, escalation thresholds, common taxonomies, remediation ownership, testing standards, and reporting that shows whether the loop is moving.

The practical objective is not centralization. It is coordinated accountability. Legal, human resources, internal audit, finance, security, procurement, technology, and business leaders may own different decisions. Compliance should ensure that the handoffs are explicit and that no material issue disappears between functions.

Measure the Health of the Cycle

Traditional metrics often count isolated activity: training completions, policy attestations, number of reports, cases closed, or risk assessments performed. Those measures remain useful, but they do not show whether the system is connected. A stronger dashboard measures movement and learning. How long does it take to move a material signal to a decision? What percentage of remediation actions has a named owner, deadline, evidence requirement, and testing plan? How often do investigation findings change the risk assessment? Which recurring employee questions lead to policy or training changes? Are reporter updates timely? Are retaliation concerns monitored after closure? Do repeat issues decline after remediation?

These measures test whether compliance converts information into action and action into improved performance. They also expose stalled handoffs. A long delay between investigation closure and remediation, for example, is not simply a case-management issue. It is a weakness in the connected program.

From Culture to Credibility

The best compliance programs do not eliminate uncertainty, misconduct, or failure. They create a reliable way to identify change, surface concerns, establish facts, make accountable decisions, and learn. That reliability is what turns stated values into operating culture.

Compliance is truly connected because culture affects reporting, reporting affects risk visibility, risk assessment affects resource allocation, investigations affect accountability, remediation affects controls, and communication affects whether employees trust the system enough to use it again. No element can be fully effective on its own.

The final question for compliance professionals is therefore not whether every component exists. It is whether the components exchange information, preserve accountability, and improve one another. When they do, compliance becomes more than a collection of requirements. It becomes a business system that turns signals into decisions, decisions into controls, and controls into credibility.

Bonus Questions for Compliance Professionals

  1. Where are material compliance signals most likely to stall or disappear in the current program?
  2. Who owns the transfer from employee concern to risk decision, and from investigation finding to tested remediation?
  3. Can the organization trace a recent issue from first signal through final control improvement?
  4. Which functions use different taxonomies, priorities, or case thresholds in ways that weaken handoffs?
  5. What evidence shows that reporting and investigation data changed risk assessment, resources, policies, or controls?
  6. Do current metrics reveal system delays and repeat weaknesses, or only completed activity?
  7. How does the organization communicate lessons without compromising confidentiality?
  8. What recent employee experience strengthened or weakened trust in the compliance system?
Categories
Daily Compliance News

Daily Compliance News: July 30, 2026, The Milli Vanilli Edition

Welcome to the Daily Compliance News. Each day, Tom Fox, the Voice of Compliance, brings you compliance-related stories to start your day. Sit back, enjoy a cup of morning coffee, and listen in to the Daily Compliance News. All from the Compliance Podcast Network. Each day, we consider four stories from the business world, compliance, ethics, risk management, leadership, or general interest for the compliance professional.

Top AI stories include:

  • Defense lawyers claim DOJ FCPA case is a ‘Milli Vanilli’ offering.  (Law360) sub req’d
  • eBay and execs agree to pay $55.7 MM in settlement for harassment. (Law360) sub req’d
  • Teva can’t whine about agreed-to admissions. (Law360) sub req’d
  • 1st Circuit skeptical that hiring SW is a lie detector. (Law360) sub req’d

To learn about the intersection of Sherlock Holmes and the modern compliance professional, check out Tom’s latest book, The Game is Afoot-What Sherlock Holmes Teaches About Risk, Ethics and Investigations on Amazon.com.

Categories
Blog

Connected Compliance: Part 4 – From Hotline to Trust

An effective compliance program is not a collection of disconnected policies, training modules, hotline reports, and investigation files. It is an operating system. Culture determines whether employees will use it. Risk assessment tells the organization where it must adapt. Investigations test whether the system responds credibly. Whistleblower programs reveal whether employees trust them enough to speak. In Blog Post 1, we considered communication as a compliance control. Blog Post 2 showed how operational signals create a dynamic risk radar. In Blog Post 3, we explained why every investigation is a test of governance and culture. This final installment examines the front door to the entire system: the reporting program.

A company can buy a hotline in an afternoon. It cannot buy employee trust. That distinction is the starting point for an effective whistleblower program. The platform, policy, telephone number, and case-management system are necessary infrastructure. They are not the program. The real program is the experience an employee anticipates before reporting and receives after doing so.

The answers do not come primarily from policy language. They come from what employees see happen to colleagues who raise concerns. A mishandled report can teach an entire workplace that silence is safer.

The First Report Is the Real Program Test

One of the easiest ways to discourage reporting is to do a poor job after a report arrives. An ignored allegation, confidentiality breach, unexplained delay, dismissive intake, or retaliation can do more damage than an outdated hotline poster.

This is why the reporting program and investigation process cannot be separated. Intake creates an expectation of action. Investigation determines whether that expectation is met. Follow-up determines what the reporter tells others about the experience. The process should begin with prompt acknowledgment. Whenever possible, a trained person should thank the reporter, gather clarifying information, explain next steps, and set realistic expectations. An automated receipt confirms that the technology worked. Personal contact demonstrates that the organization is listening.

What the DOJ Is Really Asking

The Department of Justice (DOJ) places confidential reporting within its evaluation of whether a compliance program is well designed. The 2024 Evaluation of Corporate Compliance Programs (ECCP) calls for an “efficient and trusted mechanism” for anonymous or confidential reports. The two words that matter most are efficient and trusted.

Efficiency requires accessible channels, proper routing, risk-based triage, qualified investigators, timely handling, documentation, and accountable remediation. Trust requires employees to believe that the company will take concerns seriously, limit information sharing, prevent retaliation, and respond consistently regardless of rank or commercial importance.

The DOJ asks whether employees know about the reporting mechanism, feel comfortable using it, and are willing to report misconduct. It also asks a difficult question: “Conversely, does the company use practices that tend to chill such reporting?” That directs compliance professionals beyond the hotline itself. Confidentiality agreements, manager behavior, performance systems, investigation delays, incentive structures, employment actions, and prior reporter experiences can all affect willingness to speak. The DOJ further asks whether the company tests hotline effectiveness by tracking a report from intake through disposition. This makes end-to-end testing a governance exercise, not a vendor-management task.

Design Channels Around the Workforce

A reporting system designed for headquarters may fail the people most likely to observe operational risk. Field employees, shift workers, remote personnel, contractors, and employees with limited computer access need channels that fit how they work. The answer is a meaningful choice. A mature program may include a telephone hotline, web portal, mobile access, email, QR codes, and in-person reporting to compliance, human resources, legal, internal audit, security, or management. Channels should be available in appropriate languages and accessible to employees with disabilities.

Placement matters. A QR code on an identification badge, break-room poster, or work-issued device may be more useful than a buried intranet link. A telephone line remains essential for employees who prefer to speak or lack reliable digital access. Many employees will first approach someone they trust. Compliance should analyze channel use by location, function, shift, language, and workforce type. A channel with no reports is not necessarily evidence that the location has no concerns. It may be evidence that the channel is unknown, inaccessible, or distrusted.

Make Speaking Up a Leadership Behavior

Tone at the top remains essential, but the employee’s immediate supervisor often controls the reporting climate. A chief executive may celebrate integrity while a frontline manager rolls their eyes, interrupts the employee, demands names, or warns that a report will hurt the team. The manager’s reaction becomes the company’s culture in that moment.

Managers need specific training. They should listen without investigating on the spot, avoid promises they cannot keep, preserve information, escalate promptly, and reinforce anti-retaliation expectations. A concern does not have to arrive through the hotline to require action. Leadership modeling should be visible. When leaders invite dissent, respond calmly to bad news, thank employees who identify risk, and communicate anonymized lessons, they show that speaking up protects the business. Regular field presence builds relationships, reveals access barriers, and provides context unavailable from a dashboard.

Tell the Truth About Confidentiality

Employees often use anonymity and confidentiality interchangeably, but they are different. An anonymous reporter does not disclose identity. Confidentiality means identity and related information are limited to people with a legitimate need to know. The company should never promise absolute secrecy when the facts make it impossible. In a small team, subject matter, timing, or witnesses may reveal who raised the concern. Overpromising creates a second breach of trust.

The better approach is candor. Explain that information will be restricted as far as reasonably possible, that some disclosure may be necessary to investigate fairly or meet legal obligations, and that retaliation is prohibited. Use role-based access, careful case notes, secure records, disciplined interview planning, and clear need-to-know rules. Confidentiality is not a slogan. It is an information-control process.

Communicate Without Compromising the Investigation

Silence during a long investigation can feel like indifference. Reporters do not need access to witness statements or confidential personnel decisions, but they do need evidence that the matter remains active. Set a communication cadence based on case risk and expected duration. Provide updates even when the update is that the review continues. Explain delays where appropriate, remind the reporter how to provide additional information, and repeat the anti-retaliation contact route.

At closure, confirm that the concern was reviewed and addressed as appropriate. Thank the reporter and reinforce anti-retaliation protection. The company may be unable to disclose findings or discipline, but it can close the human loop.

Treat Anti-Retaliation as an Active Control

An anti-retaliation policy is necessary, but it is not self-executing. Retaliation can be direct, such as termination, demotion, or loss of pay. It can also be subtle: exclusion from meetings, undesirable shifts, lost development opportunities, hostile supervision, damaged reputation, or social isolation. The company should assess retaliation risk throughout the matter. Compliance and human resources should preserve a baseline of the reporter’s role and treatment, monitor employment actions, schedule check-ins, and provide an escalation route outside the normal chain. Monitoring should continue after closure.

Protection does not mean immunity from legitimate performance management. It means employment decisions affecting a reporter receive appropriate review, are supported by contemporaneous evidence, and are not influenced by protected activity. When retaliation occurs, discipline should be prompt and visible enough, within confidentiality limits, to reinforce the rule.

Do Not Discredit the Difficult Messenger

Serial reporters and incomplete reports create operational challenges, but frequency, frustration, or poor drafting does not determine whether an allegation is true. Each concern should be assessed on its merits. A sparse report may still contain breadcrumbs. Investigators can review organizational charts, personnel changes, transactions, prior complaints, and control data before concluding that the matter cannot proceed. Multiple reports may reveal an unresolved environmental problem or weak earlier investigations.

Motivation can be relevant to credibility, but it should not replace evidence. Labeling someone a troublemaker is often an easy way to miss a difficult fact and an effective way to chill the next reporter.

Measure Trust, Not Just Volume

Hotline volume alone is a weak measure. A low number may reflect a healthy culture, a small risk population, inaccessible channels, fear, or lack of awareness. A rising number may reflect deteriorating conduct or growing confidence in the program. A useful dashboard combines volume with context: awareness and comfort survey results, reports by workforce segment, intake-to-acknowledgment time, triage time, case aging by risk, substantiation patterns, repeat allegations, reporter-update timeliness, retaliation concerns, remediation completion, and employee feedback after closure.

Compliance should test the entire system. Submit a controlled report, trace routing and access, review acknowledgments, confirm escalation rules, examine investigation handoffs, and verify closure and retention. Analyze whether reporting data changes risk assessment, controls, training, and resources. The objective is evidence that the program learns.

Closing the Connected Compliance Program

This four-part blog post series began with communication because employees cannot use a system they do not understand. It moved to dynamic risk assessment because organizations must recognize changing signals. It then examined investigations because allegations require independent facts, accountability, and remediation. Today we discussed whistleblower programs because none of those capabilities matter if people do not trust the company enough to speak. Join us tomorrow in our concluding Part 5 for a deeper discussion of how compliance truly is connected.

The connected compliance program is a loop. Communication builds awareness. Reporting supplies risk intelligence. Investigation converts allegations into reliable findings. Remediation improves controls. Feedback strengthens culture and makes future reporting more likely.

For the compliance professional, the final test is not whether the hotline exists. It is whether an employee facing a difficult choice believes that raising a concern will protect the organization, lead to a credible response, and not cost that employee a career. That is how a reporting channel becomes a trusted control and how culture becomes credibility.

Bonus Questions for Compliance Professionals

  1. Can every workforce segment access a reporting channel during the way and hours in which it actually works?
  2. Do employees know the available channels, understand external reporting rights, and say they feel comfortable using them?
  3. What happens during the first 24 hours after a report arrives, and who is accountable for acknowledgment, triage, and protection?
  4. Are managers trained to recognize and escalate concerns received outside formal reporting channels?
  5. Can the company show how reporter identity and case information are restricted to people with a legitimate need to know?
  6. How does the organization monitor direct and subtle retaliation during and after an investigation?
  7. Does the company communicate appropriately with reporters when an investigation is delayed and when it closes?
  8. Are serial, anonymous, and incomplete reports assessed on evidence and context rather than labels or assumptions?
  9. What reporting data has changed the risk assessment, controls, training, discipline, or resource allocation during the past year?
  10. Has the company recently tested one report from submission through routing, investigation, remediation, feedback, and retention?