Categories
Trekking Through Compliance

Trekking Through Compliance: Episode 55 – Out of Time: Due Diligence Lessons from ‘Assignment: Earth

If there is one constant in the universe, it is that business, regulations, and politics never stand still. Each new venture, partnership, or acquisition brings a fresh set of risks, obligations, and opportunities. Yet too often, organizations approach due diligence as a box-checking exercise when, in truth, it is the essential safeguard that ensures they are not letting an unknown variable derail their mission. Nowhere is this more cleverly dramatized than in the Star Trek TOS episode “Assignment: Earth,” where the Enterprise crew finds themselves conducting the ultimate form of due diligence, investigating the mysterious Gary Seven and the true risks he poses to Earth’s future.

Lesson 1: Verify Identity—Trust, But Always Confirm

Illustrated by: When Gary Seven appears on the Enterprise, he claims to be a human agent from the future, sent to prevent Earth’s destruction. His credentials, demeanor, and even physiology confound the crew.

Compliance Lesson: In every business deal, knowing exactly who you are dealing with is non-negotiable. Vendors, acquisition targets, third-party agents, and partners all come with their backgrounds and histories.

Lesson 2: Investigate the Full Scope—Understand Intent, Capability, and History

Illustrated by: The crew’s investigation into Gary Seven doesn’t stop with his identity.

Compliance Lesson: Surface-level information often fails to reveal the entire story. In business, a potential partner’s capabilities and intent matter as much as their identity. Due diligence is not just about who someone is but what they are capable of and what they plan to do with that capability.

Lesson 3: Control Information—Monitor and Secure Sensitive Data

Illustrated by: Much of “Assignment: Earth” revolves around the management of sensitive information.

Compliance Lesson: Whether you are acquiring a company or onboarding a supplier, data security is central to modern due diligence. The risks of data leaks, cyber-attacks, or inadvertent disclosure can be devastating, especially if sensitive deal information falls into the wrong hands.

Lesson 4: Expect the Unexpected—Adapt When New Risks Emerge

Illustrated by: Kirk and Spock’s plan to detain Gary Seven is upended when he escapes and races to sabotage a nuclear missile test that could ignite World War III.

Compliance Lesson: Due diligence is not a static process. The best-laid plans are often disrupted by new information, sudden market fluctuations, or the revelation of previously unknown risks.

Lesson 5: Assess Impact and Alignment—Consider the Broader Consequences

Illustrated by: As the story unfolds, the crew realizes that Gary Seven’s actions, though seemingly dangerous, are intended to prevent an even greater catastrophe.

Compliance Lesson: Effective due diligence requires looking beyond the transaction itself. Will this deal, partnership, or acquisition align with your company’s mission, values, and long-term strategy? What are the potential downstream consequences?

Final ComplianceLog Reflections

Assignment: Earth” might masquerade as a playful, spy-themed episode, but at its heart it is a meditation on trust, investigation, and the unpredictability of risk. For compliance professionals, its lessons ring true across the decades. Due diligence is not a one-time task, nor is it a matter of simply collecting signatures and ticking boxes. It is an ongoing, multi-dimensional practice rooted in skepticism, curiosity, and a willingness to adapt.

Resources:

Excruciatingly Detailed Plot Summary by Eric W. Weisstein

MissionLogPodcast.com

Memory Alpha

Fiona is an AI-generated voice

Categories
Blog

What Gary Seven and Assignment Earth Teach Us About Due Diligence

If there is one constant in the universe, it is that business, regulations, and politics never stand still. Each new venture, partnership, or acquisition brings a fresh set of risks, obligations, and opportunities. Yet too often, organizations approach due diligence as a box-checking exercise when, in truth, it is the essential safeguard that ensures they are not letting an unknown variable derail their mission. Nowhere is this more cleverly dramatized than in the Star Trek TOS episode “Assignment: Earth,” where the Enterprise crew finds themselves conducting the ultimate form of due diligence, investigating the mysterious Gary Seven and the true risks he poses to Earth’s future.

With its spy-fi trappings, high-stakes secrets, and moral ambiguity, “Assignment: Earth” is a goldmine for compliance professionals seeking fresh insights into what robust due diligence truly requires. Today, we beam down and explore five timeless lessons from this episode, each rooted in a scene that every compliance leader should remember the next time a critical business decision looms.

Lesson 1: Verify Identity—Trust, But Always Confirm

Illustrated by: When Gary Seven appears on the Enterprise, he claims to be a human agent from the future, sent to prevent Earth’s destruction. His credentials, demeanor, and even physiology confound the crew. Spock’s scans confirm some aspects, but other elements remain mysterious. Kirk is forced to weigh trust against hard evidence, deciding that until Seven’s story is verified, he must remain under close observation.

Compliance Lesson: In every business deal, knowing exactly who you are dealing with is non-negotiable. Vendors, acquisition targets, third-party agents, and partners each have their own backgrounds and histories. “Assignment: Earth” illustrates the risks of acting on assumptions or charm; as the Enterprise crew learns, even the most convincing story requires verification. For compliance teams, this means robust onboarding processes, identity verification, and background checks not only at the outset but throughout the relationship. Trust is good; verification is better.

What should you do? Deploy enhanced due diligence for high-risk or high-impact relationships. Use independent sources, cross-check credentials, and don’t hesitate to pause the process if any red flags arise.

Lesson 2: Investigate the Full Scope—Understand Intent, Capability, and History

Illustrated by: The crew’s investigation into Gary Seven doesn’t stop with his identity. They probe his capabilities, his advanced technology, his mysterious “servo,” and the highly sophisticated computer at his headquarters. Spock and Kirk ask probing questions about Seven’s mission, intent, and track record.

Compliance Lesson: Surface-level information often fails to reveal the entire story. In business, a potential partner’s capabilities and intent matter as much as their identity. Due diligence is not just about who someone is, but also what they are capable of and what they plan to do with that capability. A company’s operational strengths, compliance record, and ethical history all inform future risk. Teams must go beyond public filings and financials. Look for operational gaps, management weaknesses, and track records of regulatory engagement. Just as Kirk and Spock dig into Gary Seven’s motives and methods, compliance officers should investigate all relevant dimensions.

What should you do? Expand your checklist: evaluate litigation history, regulatory fines, press coverage, key executive backgrounds, and past compliance breaches. Interview multiple stakeholders to triangulate intent.

Lesson 3: Control Information—Monitor and Secure Sensitive Data

Illustrated by: Much of “Assignment: Earth” revolves around the management of sensitive information. Seven’s computer contains data that could alter the fate of the planet. Both Seven and the Enterprise crew are vigilant about access, using encryption, voice authentication, and physical security to ensure information is only available to those with a legitimate need.

Compliance Lesson: Whether you are acquiring a company or onboarding a supplier, data security is central to modern due diligence. The risks of data leaks, cyberattacks, or inadvertent disclosure can be devastating, especially if sensitive deal information falls into the wrong hands. Therefore, it is crucial to monitor who has access to key data during the diligence phase. Implement robust information barriers and control access to confidential material. Make cybersecurity a core part of your diligence process.

What should you do? Require non-disclosure agreements from all parties. Use secure data rooms and audit access logs. Include cybersecurity posture and data protection history in every due diligence report.

Lesson 4: Expect the Unexpected—Adapt When New Risks Emerge

Illustrated by: Kirk and Spock’s plan to detain Gary Seven is upended when he escapes and races to sabotage a nuclear missile test that could ignite World War III. The crew must adapt instantly, using every tool and resource at their disposal to prevent disaster, even as their understanding of the mission’s stakes evolves in real time.

Compliance Lesson: Due diligence is not a static process. The best-laid plans are often disrupted by new information, sudden market fluctuations, or the revelation of previously unknown risks. Teams must be nimble, ready to reassess, escalate, and change course as new facts emerge. Establish protocols for escalating concerns and adjusting timelines when red flags appear. Build flexibility into your diligence process; sometimes, a deal should slow down or even pause while serious concerns are addressed.

What should you do? Schedule interim reviews, not just final sign-offs. Empower team members to call for additional investigation when new risks emerge, and document all changes to scope and focus.

Lesson 5: Assess Impact and Alignment—Consider the Broader Consequences

Illustrated by: As the story unfolds, the crew realizes that Gary Seven’s actions, though seemingly dangerous, are intended to prevent an even greater catastrophe. Kirk must weigh the consequences of intervening or not, understanding that the impact goes beyond the immediate crisis and could shape the entire future of humanity.

Compliance Lesson: Effective due diligence requires looking beyond the transaction itself. Will this deal, partnership, or acquisition align with your company’s mission, values, and long-term strategy? What are the potential downstream consequences? Does the opportunity support or threaten your compliance culture? Kirk’s willingness to consider the broader impact rather than just “following the rules” mirrors the best compliance thinking. Evaluate not just the legal and financial implications, but the reputational, cultural, and strategic impacts as well.

What should you do? Be sure to include cultural fit, values alignment, and long-term strategy in your final diligence reports. Consult with leadership about potential impacts, positive and negative, before greenlighting a deal.

Final ComplianceLog Reflections

Assignment: Earth” might masquerade as a playful, spy-themed episode, but at its heart it is a meditation on trust, investigation, and the unpredictability of risk. For compliance professionals, its lessons ring true across the decades. Due diligence is not a one-time task, nor is it a matter of simply collecting signatures and ticking boxes. It is an ongoing, multi-dimensional practice rooted in skepticism, curiosity, and a willingness to adapt.

In today’s business environment, the threats and opportunities you face are more complex than ever. The partners, acquisitions, and investments you pursue all come with hidden variables. Like Kirk and his crew, your mission is to look deeper, ask more challenging questions, protect sensitive information, and never lose sight of the broader impact your decisions have on the world.

The next time your organization faces a pivotal deal or partnership, remember the spirit of “Assignment: Earth” and conduct your due diligence with the rigor, flexibility, and ethical perspective that the future demands.

Resources:

Excruciatingly Detailed Plot Summary by Eric W. Weisstein

MissionLogPodcast.com

Memory Alpha

Categories
Blog

Scoular’s $10 Million FCPA Resolution: When a “Re-inspection Fee” Becomes a Bribe

A $2,000 payment can look insignificant inside a global supply chain. Repeated train by train, approved by employees, routed through customs brokers, disguised on invoices, and paid for six years, it becomes something else entirely. For The Scoular Company, it became a Foreign Corrupt Practices Act enforcement action carrying more than $10 million in penalties and forfeiture, a three-year deferred prosecution agreement, continuing cooperation obligations, and periodic reporting to the Department of Justice.

The case is an important warning for every company engaged in cross-border trade. Customs brokers are not merely logistics providers. Border payments are not merely operational expenses. A mislabeled invoice is not merely an accounting problem. Each may represent an interconnected risk across anti-corruption, internal control, third-party, and national security.

The Scheme: $2,000 per Train

According to the DOJ Press Release (the full DPA is not yet available), between 2013 and 2019, Scoular used customs brokers to move shipments of corn and other agricultural products from the United States to Mexico. Mexican authorities inspected those shipments for dirt, soil, and other impurities. When inspectors identified problems, Scoular’s customs brokers allegedly paid Mexican officials approximately $2,000 per train to ensure that the shipments crossed the border.

The brokers then invoiced those payments back to Scoular as “reinspection fees.” Scoular paid the invoices. This was not an isolated facilitation payment or a rogue third party operating beyond the company’s knowledge. According to the court documents, Scoular employees authorized the payments, directed the brokers, and communicated about the shipments and bribes through WhatsApp and other channels.

The numbers demonstrate the business impact:

  • More than $400,000 in bribes authorized
  • More than $6.5 million in avoided fees and costs
  • A $9,769,521 criminal penalty
  • $414,351 in forfeiture
  • A three-year DPA

The company was charged with conspiracy to violate the FCPA’s anti-bribery provisions.

The Invoice Description Was a Compliance Red Flag

The phrase “reinspection fee” should be at the center of every compliance discussion about this case. The brokers did not invoice Scoular for bribes. They used a description that appeared facially connected to a legitimate customs process. That description allowed the payments to move through the company’s financial system.

This is how corruption frequently enters the books and records. It appears as:

  • Expediting fees
  • Administrative charges
  • Local processing costs
  • Customs support
  • Special handling
  • Reinspection fees
  • Consulting services

The compliance question is not whether the description sounds legitimate. The question is whether the company can establish what service was performed, who performed it, why the payment was necessary, how the amount was calculated, and who ultimately received the money. Accounts payable controls that merely match an invoice to a purchase order will not detect this type of scheme. Effective controls must examine the commercial substance of high-risk payments.

For customs-related expenses, companies should require supporting government documentation, published fee schedules, proof of service, payment to an authorized government account where appropriate, and enhanced approval for unusual or recurring charges.

Third-Party Due Diligence Is Only the Beginning

The Scoular resolution also demonstrates the limits of onboarding due diligence. A company can screen a customs broker, obtain certifications, execute an anti-corruption clause, and still face substantial FCPA exposure. The real question is what happens after the third party begins work. The answer is that the real work of compliance begins when the third-party contract is signed.

Customs brokers operate at the intersection of government interaction, time-sensitive business demands, discretionary enforcement, and local pressure. That makes them inherently high risk. An effective third-party management program should connect the following:

  • Initial due diligence
  • Contractual controls
  • Transaction monitoring
  • Invoice testing
  • Business justification
  • Periodic recertification
  • Audit rights
  • Compliance training
  • Offboarding decisions

The DOJ credited Scoular for strengthening risk-based screening and approval requirements, adding anti-corruption and audit-right provisions to contracts, and improving monitoring procedures. The company also eliminated customs brokers associated with the Mexican reinspection payments. Due diligence is not and cannot remain a static file. It must become a continuing control system tied to actual payments and operational conduct.

WhatsApp Was Part of the Business Process

Scoular employees allegedly communicated about the shipments and payments through WhatsApp and other channels. This fact should concern every CCO. When employees use personal devices or ephemeral messaging platforms to conduct high-risk business, the company may lose visibility into precisely the communications it most needs to monitor, preserve, and produce.

The answer is not necessarily to prohibit every messaging application. The answer is to establish a defensible governance model addressing the following:

  • Permitted communication platforms
  • Business-record retention
  • Preservation during investigations
  • Access to relevant communications
  • Training for high-risk employees
  • Monitoring based on legal and privacy requirements
  • Consequences for circumventing approved systems

A policy without technical controls, employee training, and consistent enforcement is unlikely to satisfy prosecutors. Messaging governance must reflect how employees actually conduct business.

Corruption Is Now a National Security Issue

The most significant feature of the case may be the DOJ’s treatment of cartel risk. The government determined that a portion of the bribe payments ultimately benefited individuals associated with a cartel operating at the U.S.-Mexico border. The DOJ stated that neither Scoular nor its employees knew about that connection. That lack of knowledge did not eliminate the seriousness of the issue.

Indeed, in the DOJ Press Release, U.S. Attorney Justin R. Simmons for the Western District of Texas was quoted as follows, “Nothing crosses into or out of Mexico without the approval and payment to Mexican drug cartels.” Further, any American businesses that engage in any cross-border trade bear a significant amount of responsibility to do so without benefitting those cartels and without threatening our national security.”

The enforcement message is clear: companies operating in high-risk border regions must consider where third-party payments may ultimately flow. A payment intended to resolve a customs problem can expose a party to corruption, money laundering, sanctions, organized crime, and national security risks. This means anti-corruption risk assessments can no longer operate in isolation. Compliance teams should integrate information from the following:

  • Anti-money laundering reviews
  • Sanctions screening
  • Security functions
  • Trade compliance
  • Supply chain risk management
  • Third-party intelligence
  • Government investigations
  • Adverse media monitoring

The government is examining the complete risk created by a payment, not merely the employee’s immediate objective.

No Voluntary Disclosure Credit, but Meaningful Cooperation Credit

Scoular did not receive voluntary self-disclosure credit because it did not promptly report the conduct to the DOJ Fraud Section. It did, however, receive credit for cooperation. The DOJ cited Scoular’s internal investigation, factual presentations, identification of individuals involved, document production, organization of evidence, and provision of counsel for current employees. The DOJ also acknowledged deficiencies during the early stages of the investigation.

After considering the company’s cooperation and remediation, the DOJ imposed a criminal penalty reflecting a 25 percent reduction from the bottom of the applicable sentencing guidelines range. This is a valuable lesson in enforcement mathematics. Missing the opportunity for voluntary disclosure does not make subsequent cooperation irrelevant. Companies can still improve outcomes through credible investigation, evidence preservation, individual accountability, timely remediation, and the organized production of information.

Yet cooperation credit is not the equivalent of voluntary disclosure credit. The decision window following discovery of potential misconduct remains critical.

Remediation Must Change the Operating Model

Scoular’s remediation went beyond issuing a new policy. According to the DOJ, the company:

  • Conducted an external compliance maturity assessment and anti-corruption risk assessment
  • Restructured its compliance function
  • Increased senior leadership oversight
  • Eliminated brokers connected to the payments
  • Strengthened risk-based monitoring through software tools
  • Revised its Code of Conduct and key compliance policies
  • Improved third-party screening and approvals
  • Added anti-corruption and audit-rights provisions
  • Revised financial controls for high-risk transactions
  • Delivered general and targeted anti-corruption training

This is the type of remediation contemplated by the DOJ’s Evaluation of Corporate Compliance Programs. It addresses root causes, resources, governance, controls, technology, training, and business ownership.

The key is operational impact. The company must be able to demonstrate that the same conduct could not pass through the organization today without being detected or escalated.

Questions for CCOs

CCOs should ask:

  • Do recurring payments cluster around specific ports, brokers, officials, products, or inspection events?
  • Are vague payment descriptions automatically escalated?
  • Does compliance have access to customs, logistics, and accounts payable data?
  • Are high-risk brokers periodically reviewed after onboarding?
  • Has the company tested whether audit rights can actually be exercised?
  • Is there a rapid escalation process for deciding whether potential misconduct should be voluntarily disclosed?

The Bottom Line

The Scoular case was not simply about customs brokers paying officials. It was about an operational process that allegedly normalized bribery, an invoicing system that disguised the payments, employees who communicated through informal channels, and third-party funds that ultimately touched cartel-linked actors.

For compliance professionals, the lesson is direct: follow the payment, test the business justification, examine the communication channel, and understand the complete risk ecosystem. A $2,000 “reinspection fee” may be small enough to escape executive attention. It is not small enough to escape the FCPA.

Categories
Blog

The Odyssey and Compliance, Part 3 – Circe’s Island: Third-Party Influence and Culture Capture

We continue our series of compliance lessons from The Odyssey. Today, we consider the tale of Circe’s Island and how third parties can not simply influence but also capture organizations.

Odysseus had seen danger before. He had survived war, storms, and the occasional poor travel decision that would have caused any modern risk committee to request an immediate meeting. But then he came to Circe’s island, where the threat did not begin with open violence. It began with hospitality. Circe welcomed Odysseus’s men. She offered food. She offered a drink. She offered comfort. Then, in one of the more memorable compliance-adjacent transformations in Greek mythology, she turned them into swine.

Subtle? Not especially. Useful for corporate compliance? Absolutely. In the corporate world, third parties rarely transform employees into literal pigs. That would at least make the investigation easier. The modern version is quieter. A consultant becomes indispensable. A reseller knows “how things work here.” A lobbyist explains that the official process is for amateurs. A distributor normalizes side payments. A strategic partner begins to shape internal decisions. A vendor’s gifts, favors, travel, and access slowly change what employees consider acceptable.

No one wakes up and says, “Today I shall surrender my professional judgment.” Instead, judgment softens and then stretches. Then outsourced. That is Circe’s island.

The Corporate Translation

Circe is the consultant, agent, lobbyist, reseller, distributor, broker, introducer, or strategic partner who makes questionable conduct feel sophisticated. She does not have to say, “Break the rules.” That would be too obvious. She says something more dangerous:

“This is how business is done.”

“Everyone uses this structure.”

“You are being too rigid.”

“The policy was not written for this situation.”

“You can trust me.”

“We have relationships you do not have.”

That is the language of culture capture. The third party does not merely provide a service. The third party begins to influence the organization’s standards. This is why third-party risk is not just a procurement issue. It is not just an anti-bribery issue. It is not just a contracting issue. It is a cultural issue. The most dangerous third parties do not always demand a bribe. Sometimes they simply change what your people think is normal.

The Paperwork Trap

Most companies have a third-party process. There is a questionnaire. There is a risk rating. There is a certification. There is a contract clause. Somewhere, there may even be a spreadsheet with conditional formatting, because nothing says “control environment” like a cell turning amber. These tools matter. But paperwork alone does not manage influence.

A company can collect every form and still miss the real risk. Whom is this third party influencing? Who inside the company is advocating for them? Why are they needed? What access do they have? What discretion do they exercise? Are they interacting with government officials, customers, healthcare professionals, regulators, state-owned entities, procurement teams, or other sensitive stakeholders? Are they being paid in a way that makes sense? Are they actually doing the work? Are they unusually close to the decision-maker?

The DOJ’s Evaluation of Corporate Compliance Programs (ECCP) asks whether companies apply risk-based due diligence to third-party relationships and understand the qualifications, associations, business rationale, reputation, compensation, and actual services performed by third parties. It also asks whether companies engage in ongoing monitoring through refreshed due diligence, training, audits, or certifications.

That is the point. Third-party compliance is not a one-time onboarding ritual. It is a relationship management discipline. Circe’s danger was not that she existed. The danger was that Odysseus’s men entered her house without understanding the risk.

Gifts, Hospitality, and the Slow Erosion of Judgment

Gifts and hospitality are often discussed as if the only question is whether the amount is above or below a policy threshold. That is too narrow. A meal may be permissible and still influential. A conference invitation may be properly approved and still create pressure. A vendor-sponsored trip may be documented and still tilt the relationship. A series of small favors may do more damage to independence than one obviously improper gift.

Compliance officers understand this. Business leaders sometimes resist it because influence is uncomfortable to discuss. No one wants to admit that lunch, access, flattery, or convenience can affect judgment. We prefer to believe we are all rational actors, floating above human weakness like minor gods with expense reports. We are not.

Behavioral ethics teaches a humbler lesson: people are influenced by relationships, reciprocity, loyalty, fatigue, social norms, and self-interest. A third party who becomes a friend, fixer, sponsor, or “trusted guide” can reshape decisions without issuing a single improper instruction.

That is why gifts-and-hospitality controls should look beyond monetary value. They should examine frequency, timing, recipient role, pending decisions, public-sector touchpoints, tender activity, regulatory matters, and cumulative patterns. The better question is not only, “Was this gift allowed? “The better question is, “What might this gift be trying to make feel normal? ”

Conflicts of Interest: Circe with a Business Card

Conflicts of interest are another form of enchantment. The employee recommends a vendor owned by a family member. A manager hires a consultant whom he previously employed. A procurement lead has a side investment in a supplier. A sales executive pushes a reseller because the reseller has promised future employment. A board member has ties to a strategic partner.

Often, the conflicted person does not experience the conflict as corruption. They experience it as trust.

“I know them.”

“They are good people.”

“They understand our business.”

“This will move faster.”

That may all be true. It may also be irrelevant. Conflicts do not require proof that someone acted dishonestly. A conflict means that personal interest may interfere with, or appear to interfere with, professional judgment. In compliance, appearance matters because trust matters. Circe did not need to tell the crew they were compromised. They simply became something other than what they had been. That is what unmanaged conflicts do. They transform decision-makers into advocates for interests they may not even fully recognize.

Risk-Based Due Diligence Means Asking Better Questions

A strong third-party program should be risk-based. That does not mean treating every vendor like a potential international crime syndicate. It means applying the right level of scrutiny to the right relationship. The office coffee supplier probably does not need the same review as a customs broker, government-facing consultant, high-commission sales agent, data processor, clinical partner, reseller, lobbyist, or distributor in a high-risk market.

Risk-based due diligence should ask direct questions:

What will this third party do for us?

Why do we need them?

Who selected them?

What relationships do they bring?

How will they be paid?

What access will they receive?

What decisions can they influence?

What laws, regulations, or policy areas do they touch?

What red flags appeared, and how were they resolved?

The ECCP also emphasizes risk assessment across factors such as business partners, third-party use, gifts, travel, entertainment, and other areas that may contribute to the risk of misconduct. That is a useful reminder: third-party risk rarely travels alone. It often brings friends. Gifts risk. Conflicts are risky. Books-and-records risk. Data risk. Sanctions risk. Cyber risk. Antitrust risk. Fraud risk. Reputational risk. Circe’s island is crowded.

Training the People Who Meet Circe

Third-party policies are necessary, but people need training before they sit across the table from Circe. Sales teams need to understand the red flags for resellers and agents. Procurement teams need to spot conflicts and unusual payment terms. Finance needs to recognize vague invoices, round-dollar payments, split payments, and services that cannot be verified. Legal needs to ensure that contracts describe real services and include rights to audit, termination, compliance, and cooperation. Business sponsors need to understand that “I trust them” is not due diligence.

The ECCP asks whether training and communications are tailored to the audience and whether companies provide practical guidance, case studies, and ways for employees to get ethics advice as issues arise. It also contemplates training for appropriate agents and business partners. That is exactly right.

Do not train employees only on the policy. Train them in the moment. The moment when the consultant says the invoice needs to be vague. The moment when the distributor asks for payment to an offshore account. The moment when the lobbyist says no one can know about the meeting. The moment when the vendor offers to fly the team to a “strategy session” at a resort, suspiciously light on strategy. The moment when the business sponsor says, “Compliance is slowing this down.” That is where the program either works or becomes decorative.

What a Better Program Does

A better third-party program examines influence, not just paperwork. It connects due diligence, contracting, training, payment controls, gifts and hospitality, conflict disclosures, monitoring, audits, and termination rights. It reviews third-party activity after onboarding. It checks whether services were actually performed. It compares compensation to market value. It looks for unusual payment structures. It refreshes diligence when risk changes. It trains business sponsors, not just compliance staff. It monitors the internal champions who may become too close to the third party they manage.

Most importantly, it permits employees to be skeptical. Not cynical. Skeptical. There is a difference. Cynicism says everyone is corrupt. Skepticism says facts, controls, and accountability should support trust. Odysseus survived Circe because he received a warning, protection, and guidance before walking into the risk. Your employees need the same, preferably without needing Hermes to appear with magical herbs.

The Compliance Takeaway

Circe’s island is not just a story about transformation. It is a story about influence. Third parties can help companies grow, enter new markets, solve complex problems, and operate more effectively. Many are essential. Many are ethical. Many know things the company genuinely needs to know. But a third party should never become a substitute for the company’s judgment. When a consultant, agent, reseller, lobbyist, vendor, or strategic partner begins to redefine what is acceptable, the company has moved from third-party management to third-party capture.

That is the lesson for compliance officers and business leaders. Do not ask only whether the forms are complete. Ask whether the relationship is changing behavior. Ask whether gifts, conflicts, access, dependence, or pressure are making questionable conduct feel normal. Ask whether employees still know where the company’s standards end and Circe’s influence begins. Because in business, as in mythology, transformation rarely announces itself. One day, your people are professionals exercising independent judgment. The next day, they are defending the island.

Join us on Thursday for Post 4, where we consider The Cattle of Helios: Non-Negotiables and Control Breaches.

Categories
GSK in China: 13 Years Later

GSK In China: 13 Years Later – After the Humphreys Verdict: Managing Third-Party Risk When You Can’t Verify

Thirteen years after the GSK China scandal exploded onto the global stage, its lessons remain as urgent as ever for compliance professionals and business leaders. In this podcast series, we revisit the case not simply as corporate history, but as a living cautionary tale about culture, incentives, third parties, investigations, and governance. Each episode explores what went wrong, why it went wrong, and how those failures still echo in today’s compliance and ethics landscape. Join me as we unpack the scandal and draw practical lessons for building stronger, more resilient organizations. In this episode, we take a deep dive into the 2013 GSK China bribery scandal and examine why it remains one of the most important case studies in corporate compliance, governance, and culture. Our hosts are Timothy and Fiona.

The episode examines how multinational companies should manage third-party relationships and compliance in opaque markets like China when traditional intelligence-gathering is curtailed by privacy laws, using the case of corporate investigators Peter Humphreys and his wife Ying Zeng, who were hired by GSK to investigate a sex-tape scandal but were convicted and imprisoned for purchasing Chinese citizens’ personal data. The discussion highlights how the verdict created operational uncertainty for due diligence, M&A, supplier vetting, and anti-bribery efforts, and notes Humphrey’s claim that GSK withheld the fact that it faced internal whistleblower allegations of corruption. Drawing on DOJ expectations and an SCCE framework, it argues for shifting from “vet and forget” to continuous third-party management across five steps, reinforcing business justification, questionnaires, contracts, and ongoing oversight with mitigations like capped commissions, detailed invoice review, early audits, and use of public records and in-person interviews.

Key highlights:

  • Why Verification Matters
  • Privacy Laws Change Everything
  • When Partners Refuse Disclosure
  • Build Your Own Intelligence
  • Contract Controls and Oversight

Resources:

GSK in China: A Game Changer for Compliance on Amazon.com

GSK in China: Anti-Bribery Enforcement Goes Global on Amazon.com

Tom Fox

Instagram

Facebook

YouTube

Twitter

LinkedIn

Ed. Note: the voices of the hosts, Timothy and Fiona, were created by Notebook LM based upon text written by Tom Fox

Categories
31 Days to More Effective Compliance Programs

31 Days to a More Effective Compliance Program: Day 22 – Level of Due Diligence

Welcome to 31 Days to a More Effective Compliance Program. Over this 31-day series in January 2026, Tom Fox will post a key component of a best-practice compliance program each day. By the end of January, you will have enough information to create, design, or enhance a compliance program. Each podcast will be short, at 6-8 minutes, with three key takeaways that you can implement at little or no cost to help update your compliance program. I hope you will join each day in January for this exploration of best practices in compliance. In today’s Day 22 episode, we consider the levels of due diligence you should use when investigating third parties.

Key highlights:

  • What are the levels of Due Diligence?
  • When is each level appropriate?
  • Key Takeaways

Resources:

Listeners to this podcast can receive a 20% discount on The Compliance Handbook, 6th edition, by clicking here.

Categories
All Things Investigations

All Things Investigations – Navigating Compliance Challenges in Venezuela’s Energy Sector

Welcome to the Hughes Hubbard Anti-Corruption & Internal Investigations Practice Group’s podcast, All Things Investigation. In this podcast, host Tom Fox welcomes back Mike DeBernardis to discuss the implications of entering Venezuela for energy companies and the historical precedents.

They explore the return of US energy companies to the Venezuelan market and historical precedents, such as the Iraq Oil-for-Food Program, post-2003 Iraq, and the 1990s Russian market opening, to identify the risks and the necessary compliance measures. Key insights include the importance of stringent third-party controls, understanding the nuances of dealing with state-owned entities such as PdVSA, and having a robust risk management strategy. The conversation underscores the critical need for compliance professionals to thoroughly understand business operations to build effective compliance programs in high-risk environments.

Key highlights:

  • Challenges and Opportunities in Venezuela
  • Historical Parallels: Iraq Oil for Food Program
  • Lessons from Post-2003 Iraq
  • Comparing Venezuela to 1990s Russia
  • Counseling Clients on High-Risk Opportunities

Resources:

Hughes Hubbard & Reed website

Mike DeBernardis

Categories
Blog

The Michigan Man, Part 1 – From Winning Program to Institutional Crisis

There are moments when an organization confronts a crisis so severe that it overwhelms every narrative it once controlled. The University of Michigan now finds itself in precisely that moment. What began as a continuation of compliance issues stemming from the sign-stealing scandal has rapidly escalated into something far more serious, far more painful, and far more destabilizing. This is no longer a story about NCAA rules or institutional embarrassment. It is a story about human failure, organizational breakdown, and the real-world consequences of ignoring warning signs.

As compliance professionals, our instinct is to move quickly to frameworks, root causes, and lessons learned. That work will come later in this series. But first, it is essential to set out the facts as they are currently known and to acknowledge the human cost embedded in every paragraph of this story. This story is far beyond compliance and ethics, but it is a true human tragedy. But it will also show how such a human tragedy could have been prevented if the basic tenets of organizational compliance and ethics had been followed.

All resources cited in this four-part series are listed at the end of this blog post. Finally, this writing is personal, as I am a UM graduate.

The Rise of Sherrone Moore

Sherrone Moore’s ascent within the University of Michigan football program appeared, at least on the surface, to be a model of internal succession. Moore joined Jim Harbaugh’s staff in 2018 and rose steadily through the ranks, ultimately serving as offensive coordinator during Michigan’s 2023 national championship season. When Harbaugh departed for the NFL, Moore was promoted to head coach, a decision widely praised as ensuring continuity and stability.

Moore was not simply a coach. He was a symbol. His emotional post-game interview after a victory over Penn State, while Harbaugh was suspended, became an iconic moment for Michigan fans. He embodied loyalty, perseverance, and what many referred to as the “Michigan Man” ethos. ESPN

Yet even at the time of his promotion, Moore’s record was not unblemished. He had already been implicated in the Connor Stalions sign-stealing investigation and had received NCAA suspensions for deleting text messages during that inquiry. Those issues were treated by the university and much of the fan base as technical compliance matters rather than as indicators of deeper governance or integrity risks. Slate

That framing now appears deeply flawed.

The Inappropriate Relationship Investigation

According to reporting by The AthleticESPNSlate, and The Wall Street Journal, the University of Michigan received an anonymous tip earlier in 2025 alleging an inappropriate relationship between Moore and a female football staffer. The university retained Jenner & Block, an outside counsel, to conduct an investigation. Initially, both Moore and the staffer denied any relationship, and investigators reported that insufficient evidence existed to substantiate the claim.

That changed dramatically in December 2025. Prosecutors allege that the staffer disclosed corroborating evidence confirming a multi-year intimate relationship after she ended it earlier that week. At that point, the university determined that Moore had violated institutional policy and terminated him for cause, avoiding a reported $14 million buyout. The Athletic

This was not merely an employment decision. It was the spark that ignited a cascading crisis.

The Criminal Charges

Within hours of his dismissal, Moore’s personal situation escalated into a criminal matter. Prosecutors allege that Moore went to the staffer’s residence without permission, entered through an unlocked door, and engaged in a confrontation during which he picked up scissors and butter knives and threatened to harm himself. According to court statements, Moore allegedly made repeated statements such as “I am going to kill myself” and “My blood is on your hands. The Athletic

Moore was subsequently charged with felony third-degree home invasion and misdemeanor charges of stalking and breaking. He was taken into custody, evaluated at a hospital, and later released on bond with GPS monitoring and a requirement that he continue mental health treatment. A probable cause hearing is scheduled for January 2026.

At this point, it bears stating plainly: these are allegations, and Moore has pleaded not guilty. The legal process will determine criminal responsibility. However, from an organizational perspective, the damage has already been done.

The Expanding Institutional Investigation

What began as an inquiry into Moore’s conduct has now broadened into a comprehensive review of the University of Michigan athletic department. University leadership has confirmed that Jenner & Block’s mandate has expanded to examine how the athletic department handled the Moore matter and other recent scandals, including the sign-stealing investigation and prior misconduct by football staffers. ESPN

Interim President Domenico Grasso has publicly called for anyone with relevant information to come forward, emphasizing that “all of the facts here must be known.” Athletic Director Warde Manuel remains in his position for now, but multiple reports note that his leadership and oversight are under intense scrutiny.

This expansion matters. It signals that the university itself recognizes that Moore’s actions cannot be isolated from the environment in which they occurred.

Beyond Compliance: The Human Tragedy

It would be a profound mistake to reduce this story to a checklist of policy violations.

At the center of this crisis are people whose lives have been irreversibly altered. Moore is a married father of three whose career has collapsed in public view. His family faces humiliation, uncertainty, and emotional trauma that will not disappear with headlines. Prosecutors describe the staffer at the center of the allegations as someone who felt terrorized and unsafe, a position no employee should ever occupy. University of Michigan players have lost their head coach midseason, forcing them to process personal loyalty, public scandal, and institutional chaos simultaneously. There is also the culture of an entire university athletic department, which not only allowed such behavior but also tolerated and even celebrated it by promoting Moore to Head Coach.

The broader Michigan community, alumni, students, and fans are also stakeholders in this tragedy. For an institution that has long traded on its image of integrity and moral leadership, the reputational damage cuts deeply. Being a ‘Michigan Man’ was meant to stand for something—something positive, that you did things in the right way, and you personally held yourself to a higher standard. As The Wall Street Journal observed, this is no longer a college football story. It is “agony in Ann Arbor. I certainly echo that feeling personally.

A Pattern, Not an Anomaly

The most troubling aspect of the facts as currently known is how familiar they feel. The Moore scandal follows a series of incidents involving Michigan athletics over recent years, including the Stalions’ sign-stealing operation, multiple staff arrests, internal HR complaints, and even a federal indictment of a former assistant coach for accessing student-athletes’ private data. WSJ

The issue may not be any single actor but rather an entrenched culture that has historically insulated powerful figures from accountability. Slate: When organizations repeatedly frame misconduct as isolated events, they fail to confront systemic risk.

Why This Matters for Compliance Professionals

For compliance professionals, this case is already instructive even before we reach lessons learned. It demonstrates how compliance failures often emerge not as sudden collapses but as accumulations of ignored signals. It shows how reputational capital built over decades can evaporate in a matter of days. Most importantly, it reminds us that behind every policy failure are human beings who bear the consequences.

While there will be others who say ‘I told you so’ or want to bring the vaunted Michigan Man down a peg or two, the lessons from this scandal and human tragedy are no less important for your team, your school, and your university.

In the next installment of this series, I will turn directly to Sherrone Moore’s individual compliance and ethics violations, including his conduct during the sign-stealing investigation and his alleged misrepresentations to investigators. That analysis is necessary. But it should never obscure the reality that this story is about far more than rules. Compliance exists to protect people, institutions, and trust. When it fails, the cost is measured not only in fines or sanctions but also in lives disrupted and communities shaken.

Resources:

The Terrible Mess at Michigan Football, by Jason Gay, writing in the Wall Street Journal.

Ex-Michigan coach Sherrone Moore charged with home invasion, stalking, breaking—Austin Meek and Sam Jane writing in The Athletic.

Fire Everybody—Alex Kirshner, writing in Slate.

Source: Michigan begins a review of the athletic department, by Dan Wetzel and Pete Thamel, writing for ESPN.

Categories
Compliance Tip of the Day

Compliance Tip of the Day – Due Diligence

Welcome to “Compliance Tip of the Day,” the podcast that brings you daily insights and practical advice for navigating the ever-evolving landscape of compliance and regulatory requirements. Whether you’re a seasoned compliance professional or just starting your journey, we aim to provide you with bite-sized, actionable tips to help you stay on top of your compliance game. Join us as we explore the latest industry trends, share best practices, and demystify complex compliance issues to keep your organization on the right side of the law. Tune in daily for your dose of compliance wisdom, and let’s make compliance a little less daunting, one tip at a time.

This week, we are reviewing the third-party risk management process. Today, we focus on due diligence.

For more on this topic, check out The Compliance Handbook: A Guide to Operationalizing your Compliance Program, 6th edition, which LexisNexis recently released. It is available here.

Categories
FCPA Compliance Report

FCPA Compliance Report – Virna Di Palma on The Evolution of Third-Party Risk Management and the Role of AI

Welcome to the award-winning FCPA Compliance Report, the longest-running podcast in compliance. In this episode, Tom Fox welcomes Virna di Palma, Head of Global Content and Brand at Ethixbase360.

Virna offers insights into her extensive background in third-party risk management, with a focus on FCPA compliance and the evolution of due diligence. They discuss the ongoing importance of third-party risk management, recent shifts in FCPA enforcement, and the growing impact of new regulations on corporate compliance. Virna highlights the transformative role of automation and AI in enhancing compliance programs while emphasizing the need for human analysis. The conversation also addresses emerging issues, such as modern slavery and sustainability, and explores how organizations can optimize investments in risk management to drive business growth and resilience.

Key highlights:

  • Importance of Third-Party Risk Management
  • Impact of FCPA Enforcement Pause
  • Technological Advancements in Compliance
  • Human Rights and Modern Slavery
  • Future of Third-Party Risk Management

Resources:

Virna Di Palma on LinkedIn

Ethixbase360

Tom Fox

Instagram

Facebook

YouTube

Twitter

LinkedIn