Categories
Compliance Into the Weeds

Compliance into the Weeds: Compliance Implications of DOJ’s New Fraud Division and McDonald Memo

The award-winning Compliance into the Weeds is the only weekly podcast that takes a deep dive into compliance-related topics, literally going into the weeds to explore them in greater depth and uncover hard-hitting insights. Look no further than Compliance into the Weeds! In this episode of Compliance into the Weeds, Tom Fox and Matt Kelly discuss the DOJ’s “McDonald Memo.”

This DOJ Memo outlines a new Trump administration fraud division that broadly claims jurisdiction over “all types of fraud,” potentially reshaping DOJ enforcement and creating uncertainty about overlapping authority with existing divisions (e.g., antitrust). They review five priority areas: a. public trust/financial integrity fraud (procurement, bid rigging, grants, social welfare), b. healthcare fraud, c. internal revenue fraud, d. global trade and commerce fraud (tariffs/customs), and e. an undefined “corporate misconduct” category. From a compliance perspective, they urge companies to reassess risk areas (healthcare, importers, and government contractors), strengthen third-party oversight and documentation, and “pressure test” compliance programs with transparency and recordkeeping. They also warn that politicized enforcement and unclear guidance—such as on cartel-related liability—complicate compliance strategy and may tempt leaders to treat settlements as a cost of doing business.

Key highlights:

  • McDonald Memo Overview
  • Fraud Division Scope and Uncertainty
  • Five Fraud Categories Explained
  • Corporate Misconduct Questions
  • Compliance Program Impacts
  • Documentation as Defense
  • Mexico Cartels and Strict Liability

Resources

Matt in Radical Compliance

Tom

Instagram

Facebook

YouTube

Twitter

LinkedIn

A multi-award-winning podcast, Compliance into the Weeds was most recently honored as one of the Top 25 Regulatory Compliance Podcasts, a ⁠Top 10 Business Law Podcast⁠, and ⁠a Top 12 Risk Management Podcast⁠. Compliance into the Weeds has received Davey, Communicator, and W3 Awards, all for podcast excellence. 

Categories
Blog

THE BERKO TRIAL – PART 5: From Case Study to Control Test: A Berko Compliance Playbook for CCOs and Boards

Today we conclude our 5-part deep dive into the Asante Berko trial and guilty verdict, using the trial not simply as a case study but as a mechanism to pressure-test your compliance regime.

A compliance program is not effective because the company eventually exits a troubled transaction. It is effective when leaders can show how quickly the system identified the risk, who had authority to act, whether related conduct was contained, what the investigation established, and how the organization changed afterward.

That is the governance test presented by the Berko trial. Prosecutors built their case from emails, payment patterns, personal communications, compliance questions, recorded statements, and financial evidence. The defense attacked the missing last mile. The jury convicted Asante Berko on all three counts in just over three hours. For CCOs and boards, the final lesson is not to retry the case. It is to determine whether their own program could identify the same pattern, develop reliable facts, impose accountability, and respond at the speed enforcement policy now demands.

Start With the Three Questions That Matter

The DOJ Evaluation of Corporate Compliance Programs (ECCP) organizes program effectiveness around three questions. (1) Is the program well designed? (2) Is it applied earnestly and in good faith, with adequate resources and authority? (3) Does it work in practice? Those questions should frame the board’s review of the Berko fact pattern.

A written third-party policy answers the first question only in part. The second asks whether compliance can pause a revenue-producing transaction, obtain records, challenge senior employees, and reach the board without management filtering. The third asks for outcomes: when the warning signs appeared, did the organization find them, act on them, preserve the evidence, and fix the control weakness?

The governance failure is often not the absence of a rule. It is the gap between ownership and authority. Management owns business conduct and risk decisions. The CCO advises, challenges, monitors, and escalates. Internal audit provides independent assurance. The board oversees the system and management’s response. If every party assumes another function owns the hard decision, the control exists on paper but fails in operation.

Align Incentives, Conflicts, and Consequences

High-risk transactions require a clear view of personal incentives. Employees should disclose and pre-clear outside interests, referral compensation, client-paid benefits, expected success fees, and post-employment opportunities connected to current transactions. Offboarding should preserve relevant data, review pending payments, close access, identify continuing client contacts, and obtain certifications concerning outside interests and retained information.

Compensation deserves the same scrutiny as third-party payments. A bonus plan that rewards closing without measuring risk quality invites employees to treat compliance as a cost of delay. Risk-adjusted incentives should account for diligence completion, control compliance, escalation quality, and the durability of the business outcome. The ECCP asks whether companies use incentives for ethical conduct and apply discipline consistently across seniority, geography, and business unit. It also asks whether compensation can be deferred, reduced, canceled, or recouped when misconduct is established, subject to applicable law.

Consequence management must reach more than the direct actor. A credible process examines supervisory failure, tolerated red flags, obstruction, and failure to install or use safeguards. It applies the same decision framework to rainmakers and junior employees. The board should receive trend information showing investigation cycle times, substantiation rates, disciplinary consistency, repeat issues, and whether managers were held accountable for control failures.

Build Investigation and Speak-Up Readiness

The defense’s attack on the Berko evidence offers an investigation lesson. A source may have motives. A recording may require translation. Emails may lack a witness who can explain context. Payments may be traceable to an intermediary but not to an ultimate recipient. Those are reasons to investigate carefully, not reasons to dismiss an allegation.

Separate source credibility from objective proof. Preserve native emails, attachments, metadata, messaging records, payment instructions, approval histories, and device data. Trace funds beyond the first recipient. Document translation choices, dialect issues, investigative prompting, and competing interpretations. Interview witnesses who can explain both the transaction and the communications. Record what was established, what remained disputed, and why each conclusion was reached.

Design the process before the crisis. Define triage criteria, independence, privilege, preservation, scope approval, board escalation, investigation timing, root-cause analysis, and remediation ownership. Provide reporting channels that employees and third parties know, trust, and can use without retaliation. DOJ treats a trusted reporting mechanism and timely, properly scoped, objective, and documented investigations as hallmarks of an effective program.

Prepare the Disclosure Decision Before the Clock Starts

Voluntary disclosure should not be improvised during a board emergency. The company needs a protocol that identifies decision owners, the role of counsel, the facts required, preservation steps, the escalation path, and the method for assessing seriousness, pervasiveness, seniority, ongoing harm, and potential collateral consequences.

The March 2026 Department-wide Corporate Enforcement and Voluntary Self-Disclosure Policy (VSD) makes speed commercially significant. It provides a declination path when a company voluntarily self-discloses to the appropriate DOJ component, fully cooperates, timely and appropriately remediates, and lacks disqualifying aggravating circumstances, although prosecutorial discretion and the policy’s definitions still control. The policy also contains an exception for a whistleblower who reports both internally and to DOJ. A company may remain eligible if it reports as soon as reasonably practicable, no later than 120 days after the internal report, and satisfies the other requirements.

That is not a 120-day permission slip to wait. The operating standard is speed with discipline. The company must stop continuing harm, preserve evidence, protect privilege, develop facts, and keep decision-makers informed. A tabletop exercise should test whether the organization can do all five while the disclosure window is running.

Give the Board Evidence, Not Activity Counts

Boards do not need every hotline allegation or third-party file. They need a risk-based view of whether the system works. Reporting should cover high-risk transactions proceeding with incomplete diligence, unresolved politically exposed person relationships, payment holds, management overrides, aged investigations, remediation slippage, repeat control failures, off-channel communication exceptions, and risk acceptances by senior leaders.

Metrics should show speed, quality, and outcomes. Track time from red flag to triage, triage to transaction pause, allegation to investigation plan, finding to discipline, and remediation commitment to validated closure. Measure whether the company can match high-risk payments to legitimate services, verified beneficial owners, approved accounts, and evidence of performance. Show whether control testing changed behavior, not simply whether employees completed training.

The CCO should have regular direct access to the board or responsible committee, including private sessions when appropriate. The board should understand the CCO’s authority, resources, data access, and unresolved requests. DOJ asks what information directors examined, whether compliance concerns stopped or changed transactions, and whether compliance has the stature and autonomy to function effectively.

Run a 30/60/90-Day Berko Stress Test

Days 1 to 30: Replay one recent high-risk public-sector transaction against the Berko pattern. Inventory intermediaries, beneficial owners, politically exposed person relationships, success fees, conflicts, personal-email exceptions, cash exposure, payment destinations, incomplete diligence, and overrides. Identify which facts the current systems can retrieve and which depend on manual reconstruction.

Days 31 to 60: Close the most important design gaps. Add hard stops, fee benchmarking, conflict attestations, off-channel controls, evidence-preservation rules, payment analytics, investigation protocols, and an escalation matrix giving compliance documented pause authority. Assign one accountable owner and a deadline to each remediation item.

Days 61 to 90: Test the program. Sample transactions, trace selected payments end to end, test the hotline from intake through closure, and conduct an investigation and voluntary-disclosure tabletop. Present the results to senior management and the board, including accepted risks, overdue actions, resource needs, and evidence that completed remediation operates in practice.

The board should ask, “Which Berko warning signs would we detect today?” How quickly could we freeze a payment? Who may override compliance, and what evidence is required? Can investigators collect personal-device communications lawfully and preserve multilingual evidence? Which repeated control failures have affected compensation or promotion?

The CCO should ask one final question: Would our program find this pattern because the controls work, or only because an external source eventually brings it to us?

This Berko FCPA trial blog post series began with the prosecution’s evidentiary mosaic and the defense’s missing-last-mile challenge. It ends with a practical conclusion. Compliance evidence becomes trial evidence. A defensible program must create that evidence through authority, trusted reporting, disciplined investigations, consistent accountability, measurable remediation, and active board oversight. That is how a case study becomes a control test and how a control test becomes proof that the program works.

Resources:

United States v. Berko, No. 1:20-cr-00328-DG, Indictment, ECF No. 3 (E.D.N.Y. filed Aug. 26, 2020)

Stewart Bishop, “Goldman Jury Sees Cash Talk in Energy Deal Email Deluge,” Law360, Aug. 1, 2026; Stewart Bishop, “Goldman Exec Was Linchpin to Ghana Bribery Ploy, Jury Told,” Law360, Aug. 5, 2026.

Stewart Bishop, “Ex-Goldman Exec Convicted of Ghana Bribery Plot,” Law360, Aug. 6, 2026. Supplied trial reporting.

U.S. Attorney’s Office for the Eastern District of New York, “Former Goldman Sachs Investment Banker Convicted of Foreign Bribery and Money Laundering,” Aug. 6, 2026, DOJ Press Release.

Stewart Bishop, “Goldman Jury Sees Undercover Video as Bribe Trial Nears End,” Law360, Aug. 4, 2026. Supplied trial reporting.

Stewart Bishop, “Shady Power Deal Used in Goldman Compliance Prep, Jury Told,” Law360, July 29, 2026

Stewart Bishop, “Like Milli Vanilli, Goldman FCPA Case Is a Ruse, Jury Told,” Law360, July 28, 2026.

SEC Final Judgment against Asante Berko

SEC Complaint against Asante Berko

DOJ Evaluation of Corporate Compliance Programs

DOJ Corporate Enforcement and Voluntary Self-Disclosure Policy

Categories
Blog

THE BERKO TRIAL – PART 4: When Red Flags Become Evidence: Transaction Controls from the Berko Trial

Today in Part 4, I want to focus on some of the compliance lessons from the Asante Berko FCPA trial. The compliance lesson from the Berko trial is not simply that employees should not pay bribes. Every code of conduct already says that. The harder question is whether the compliance program can interrupt the operating pattern: a politically connected intermediary, milestone-linked invoices, personal email, cash discussions, incomplete diligence answers, and a commercial team under pressure to close. These were some of the questions that Goldman Sachs faced and successfully answered.

That is where policy becomes performance. Trial reporting described a legitimate infrastructure project surrounded by evidence that prosecutors said showed corrupt intent and concealment. The same emails, diligence questions, payment records, and escalation decisions that once lived inside a transaction later became evidence before a jury. For compliance professionals, the case is a control map. It shows where a high-risk deal can be tested, paused, corrected, or stopped before red flags mature into criminal exposure.

Begin With the Business Model

Your business justification should begin with how the deal is expected to work, not with a standard questionnaire. In the Berko transaction, commercial urgency, a major public need, concentrated government discretion, substantial projected fees, and local intermediaries all increased the risk profile. None of those facts establishes bribery. Together, however, they demand a more disciplined control environment.

The deal team should be required to explain the legitimate path to success. Which officials control each approval? Which regulatory, legislative, and contractual milestones must occur? What service does every intermediary perform? How is that service connected to value rather than access? Where could commercial pressure tempt someone to bypass the process?

This is consistent with the DOJ Evaluation of Corporate Compliance Programs (ECCP), which asks whether a company understands its business from a commercial perspective and devotes appropriate attention and resources to high-risk transactions. A generic country score is not enough. The risk assessment must reflect the transaction’s economics, approval structure, counterparties, compensation model, technology, and pressure points.

Make Third-Party Diligence Operational

Third-party diligence often fails because it is treated as an onboarding event. The questionnaire is completed, screening is run, a risk rating is assigned, and the business moves on. High-risk public-sector work requires continuous control.

Before engagement, the company should document the business rationale, beneficial ownership, politically exposed person and family links, qualifications, reputation, service scope, deliverables, compensation, payment terms, and proposed bank account. Compensation should be benchmarked against the actual work. Enhanced review should apply when fees are success-based, tied to government milestones, disproportionate to services, routed through unrelated entities or individuals, or connected to officials who control approvals.

After onboarding, controls must follow the intermediary into contracting, invoicing, payment, and monitoring. The DOJ guidance asks whether the company understands the business rationale, confirms that services were actually performed, assesses whether compensation is appropriate, tracks red flags, uses audit rights, and manages third parties throughout the relationship. The relevant question is not whether the intermediary passed diligence once. It is whether the relationship still makes sense when the invoice arrives.

Control the Channels Where Business Occurs

Personal email is not proof of bribery. The Berko facts were more specific. According to the trial reporting, sensitive payment discussions occurred through personal accounts. At the same time, routine deal work proceeded through corporate systems, and one exchange referred to the monitoring of a Goldman account. The control issue was the combination of channel separation, sensitive content, and knowledge of monitoring.

Companies need clear rules for personal email, messaging applications, approved mobile platforms, and bring-your-own-device arrangements. Those rules require technical support: approved-channel design, retention settings, monitoring consistent with law, exception approval, employee attestations, and escalation when business moves outside the system. The program should also test whether records can actually be collected and preserved across the jurisdictions where the company operates.

The ECCP asks how companies manage and preserve business communications on personal devices and messaging platforms. The DOJ Corporate Enforcement and Voluntary Self-Disclosure Policy (VSD) likewise identifies appropriate controls over personal and ephemeral communications as part of timely remediation. A policy that cannot preserve the evidence it covers is not an effective control.

Give Compliance Real Stop Authority

Escalation is not effective if compliance can ask questions but cannot pause the transaction. High-risk deals need defined hard stops. Examples include incomplete beneficial ownership, inconsistent diligence answers, refusal to identify service providers, unexplained compensation, undisclosed PEP relationships, requests for cash, payments to personal or nominee accounts, and destination changes without a credible business reason.

A hard stop does not require the company to abandon every transaction containing a red flag. It requires the risk to be resolved before money or value moves. The control framework should identify who may impose a pause, who may clear it, whether any override is permitted, what evidence supports an override, and which risk decisions require senior escalation.

Trial testimony reportedly described months of compliance questions about the Ghanaian intermediary and inconsistent or incomplete answers, followed by Goldman’s withdrawal from the contemplated financing. That sequence should not be converted into a claim that every control operated early enough or that the company was legally exonerated. The more useful lesson is that the decision trail mattered. It documented the questions, the resistance, the escalation, and the exit.

Connect Diligence, Invoices, and Money

Many programs distribute the relevant facts across separate systems. Procurement sees the contract. Compliance sees the screening. Accounts payable sees the invoice. Treasury sees the destination account. Investigations see the allegation. No one sees the complete pattern.

Payment controls should require proof of service, account-name matching, country and entity consistency, independent approval for destination changes, and tight restrictions on cash. Analytics should flag round-dollar invoices, duplicate invoice numbers, payment splitting, milestone-timed consulting fees, payments to employees or related parties, high-risk correspondent routes, and transfers followed by cash withdrawals.

The decisive step is integration. Due diligence, PEP screening, contracting, procurement, accounts payable, treasury, and case-management data should be capable of producing a transaction-level view. That view allows compliance to ask whether a payment is not only properly approved but also commercially credible.

Build an Evidence-Grade Record

The defense’s most forceful theme was the missing last mile: no downstream bank record showing money reaching a Ghanaian official, no alleged recipient on the witness stand, and no eyewitness to a bribe. The jury nevertheless convicted Berko on all three charged counts. For an internal investigation, the lesson cuts both ways. Suspicion is not proof, but weak tracing can leave the company unable to determine what happened.

Preserve native emails, attachments, metadata, messaging exports, payment records, approval histories, translations, and custodial provenance—record who made each factual determination and what evidence supported it. For multilingual material, preserve the original, use qualified translators, document dialect and ambiguity, and maintain a process for reviewing disputed language. Financial tracing should move from payer to intermediary to ultimate recipient, including related-party accounts and cash conversion.

The current FCPA enforcement guidelines emphasize individual misconduct and caution against attributing nonspecific malfeasance to corporate structures. That makes an evidence-grade corporate record especially important. It can help separate an individual’s conduct from the organization’s response while also showing whether the program was designed and implemented effectively.

Test the Controls Before the Crisis

An effective program does not promise that no misconduct will ever occur. DOJ recognizes that even a strong program may fail to prevent an offense. The question is whether the program is risk-based, detects concerns, responds promptly, and improves from experience.

Replay a recent public-sector transaction against the Berko pattern. Could the company identify every approval-controlling official and intermediary? Would milestone-linked payments trigger review? Could compliance pause the deal? Would personal email activity be detected and preserved? Could investigators trace funds beyond the first intermediary? Measure time from red flag to pause, overdue enhanced diligence, unresolved PEP issues, payment exceptions, control overrides, and closure of remediation.

The practical takeaways are clear. Commercial urgency calls for greater discipline, not reduced scrutiny. Third-party diligence must remain connected to invoices, payments, monitoring, and escalation. Off-channel communications become an intent and preservation issue when combined with sensitive content and known monitoring. A deal exit matters, but an earlier hard stop may reduce exposure and preserve more business value.

Join us tomorrow as we conclude our 5-part series by moving the transaction to the enterprise. In it, we will explore such questions as who owns these controls, who funds and tests them, how accountability is imposed, and what your Board of Directors should demand as evidence that the program works in practice.

Resources:

United States v. Berko, No. 1:20-cr-00328-DG, Indictment, ECF No. 3 (E.D.N.Y. filed Aug. 26, 2020)

Stewart Bishop, “Goldman Jury Sees Cash Talk in Energy Deal Email Deluge,” Law360, Aug. 1, 2026; Stewart Bishop, “Goldman Exec Was Linchpin to Ghana Bribery Ploy, Jury Told,” Law360, Aug. 5, 2026.

Stewart Bishop, “Ex-Goldman Exec Convicted of Ghana Bribery Plot,” Law360, Aug. 6, 2026. Supplied trial reporting.

U.S. Attorney’s Office for the Eastern District of New York, “Former Goldman Sachs Investment Banker Convicted of Foreign Bribery and Money Laundering,” Aug. 6, 2026, DOJ Press Release.

Stewart Bishop, “Goldman Jury Sees Undercover Video as Bribe Trial Nears End,” Law360, Aug. 4, 2026—supplied trial reporting.

Stewart Bishop, “Shady Power Deal Used in Goldman Compliance Prep, Jury Told,” Law360, July 29, 2026

Stewart Bishop, “Like Milli Vanilli, Goldman FCPA Case Is a Ruse, Jury Told,” Law360, July 28, 2026.

SEC Final Judgment against Asante Berko

SEC Complaint against Asante Berko

DOJ Evaluation of Corporate Compliance Programs

DOJ Corporate Enforcement and Voluntary Self-Disclosure Policy

Categories
Blog

THE BERKO TRIAL – PART 3: What the Jury Decided: Reading the Berko Verdict Without Overreading It

We continue our deep dive into the Asante Berko FCPA conviction. Today we consider the jury’s verdict. The jury returned three guilty verdicts. That is the decisive legal result, but it is not a line-by-line adoption of the prosecution’s closing argument. For compliance professionals, the discipline is to hold both propositions at once. The government proved the charged crimes beyond a reasonable doubt. Yet the general verdict does not tell us which email the jurors found decisive, how they interpreted every payment, or whether they accepted every factual statement later included in the government’s announcement. That distinction is not lawyerly hedging. It is the foundation of a credible enforcement analysis.

Three Convictions, One Clear Result

After a nine-day trial, a federal jury convicted Asante Kwaku Berko of conspiracy to violate the Foreign Corrupt Practices Act (FCPA), a substantive FCPA violation, and conspiracy to commit money laundering. Federal criminal verdicts must be unanimous. The jury therefore agreed that the government had proved the elements of each of the three counts submitted to it under the court’s instructions. Moreover, the jury convicted in just over three hours, which in a major criminal case is an extraordinarily short jury deliberation.

At a high level, the conspiracy verdict established Berko’s knowing participation in an agreement to violate the FCPA. The substantive verdict established criminal responsibility for the charged corrupt-payment offense. The money laundering conspiracy verdict established participation in an agreement to move funds internationally to promote FCPA violations. The indictment identifies the statutory theories and alleged conduct, but it remains a charging document. It is not a substitute for the jury instructions or the verdict itself.

The result also defeated the defense’s central trial position. The defense argued that the government had not proved the last mile between funds paid to intermediaries and funds received by Ghanaian officials. No alleged recipient testified. No Ghanaian witness took the stand. No downstream bank record showed a payment to an official. The jury nevertheless found the government’s complete proof sufficient beyond a reasonable doubt. That is what the verdict establishes. The boundaries are equally important.

A General Verdict Is Not a Set of Special Findings

A general verdict answers the ultimate question on each count: guilty or not guilty. It does not ordinarily explain the jury’s reasoning. It does not identify which witness the jurors credited, which inference they drew from a particular email, or what weight they assigned to the undercover recording.

That means we should not write that the jury separately found every alleged recipient, every alleged payment amount, or every characterization of an intermediary to be true. We can say that prosecutors presented those facts and argued those inferences. We can say that the defense disputed them. We can say that the jury convicted on all three counts. Those are distinct propositions, and sound compliance writing should keep them distinct.

The same rule applies to intent. The jury’s verdict necessarily reflects a finding of the criminal intent required by the instructions for each count. It does not disclose whether jurors inferred that intent primarily from off-channel communications, milestone-timed payments, cash withdrawals, the recorded lunch, Berko’s alleged personal compensation, the interaction with Goldman’s compliance process, or the cumulative force of all of them. The verdict is conclusive as to guilt at this stage. It is silent about the internal path the jury took to reach that result.

How the Mosaic Answered the Missing Last Mile

The government’s case did not depend on one witness producing a receipt for a bribe. It offered multiple streams of circumstantial evidence: more than 300 emails, separate personal and corporate communication channels, transfers to intermediaries, financial-flow charts, payments aligned with government approvals, compliance questions, cash discussions, and a secretly recorded lunch.

The defense tested each stream separately. Emails lacked testimony from their participants. Payments stopped short of the alleged officials. The confidential source had potential incentives. The recorded conversation involved prompting, translation, and hypothetical facts. Goldman’s withdrawal reflected a corporate risk judgment, not the criminal burden of proof.

The jury rejected reasonable doubt. The most supportable inference is that the combined evidence overcame the defense’s missing-link argument. That remains an inference because the jurors did not issue an explanation. Still, it offers an important proof lesson: independent evidence streams can corroborate one another even when no single item tells the whole story. For a compliance investigation, that lesson cuts both ways. A red flag is not a legal element, and a collection of suspicions does not automatically prove misconduct. But communications, transaction timing, money flows, control circumvention, and personal benefit can become mutually reinforcing. The analytical task is to test whether the pieces converge, conflict, or merely sit beside one another.

Three Dollar Figures, Three Source Regimes

The amounts associated with the case show why attribution matters. The 2020 indictment alleged that Berko and others caused more than $700,000 in bribes to be transferred to Ghanaian officials. DOJ stated after the verdict that the government proved more than $1 million in bribes at trial. The SEC’s civil complaint alleged that the Turkish energy company transferred at least $2.5 million to a Ghana-based intermediary, all or most of which was used for bribes. Those are not interchangeable totals. They arise from different documents, legal proceedings, time periods, and descriptions of the money flow. The $2.5 million figure concerns transfers to an intermediary. The other figures describe alleged or trial-proven bribes. Some sums may overlap, but the public sources do not support collapsing them into one number.

The SEC matter adds another essential qualifier. Berko consented to the 2021 final judgment without admitting or denying the complaint’s allegations, except as specifically provided for bankruptcy purposes. The judgment imposed an injunction and required $275,000 in disgorgement plus $54,163.92 in prejudgment interest. It did not convert every allegation in the SEC complaint into a generally admitted fact. This source discipline is central to compliance credibility. Indictments allege. Trial evidence supports arguments. Advocates characterize. Verdicts decide counts. Civil settlements may resolve claims without admissions. A strong analysis identifies the category before drawing the lesson.

The Verdict Is an Endpoint and a Starting Point

The trial reporting states that the jury deliberated for approximately three hours and that sentencing was scheduled for November 10, 2026. Berko was remanded pending sentencing. Post-trial motions, sentencing proceedings, and any appeal could add to the record, so the procedural status should be checked again before publication. Things do not bode well for Asante at this point.

For now, the legal conclusion is clear. Berko was convicted on all three counts submitted to the jury. The editorial conclusion should be equally clear. The verdict establishes criminal liability at trial, not a special finding on every email, payment, witness, amount, or corporate-control question in the surrounding narrative. That is not a limitation on the importance of the case. It is how serious compliance professionals preserve trust. They distinguish what is known, what was argued, what was disputed, what was decided, and what remains an inference.

Join us tomorrow for Part 4, as we will move from verdict discipline to transaction discipline: whether a functioning compliance program could have identified and interrupted the pattern earlier.

Resources:

United States v. Berko, No. 1:20-cr-00328-DG, Indictment, ECF No. 3 (E.D.N.Y. filed Aug. 26, 2020)

Stewart Bishop, “Goldman Jury Sees Cash Talk in Energy Deal Email Deluge,” Law360, Aug. 1, 2026; Stewart Bishop, “Goldman Exec Was Linchpin to Ghana Bribery Ploy, Jury Told,” Law360, Aug. 5, 2026.

Stewart Bishop, “Ex-Goldman Exec Convicted of Ghana Bribery Plot,” Law360, Aug. 6, 2026. Supplied trial reporting.

U.S. Attorney’s Office for the Eastern District of New York, “Former Goldman Sachs Investment Banker Convicted of Foreign Bribery and Money Laundering,” Aug. 6, 2026, DOJ Press Release.

Stewart Bishop, “Goldman Jury Sees Undercover Video as Bribe Trial Nears End,” Law360, Aug. 4, 2026. Supplied trial reporting.

Stewart Bishop, “Shady Power Deal Used in Goldman Compliance Prep, Jury Told,” Law360, July 29, 2026

Stewart Bishop, “Like Milli Vanilli, Goldman FCPA Case Is a Ruse, Jury Told,” Law360, July 28, 2026.

SEC Final Judgment against Asante Berko

SEC Complaint against Asante Berko

Categories
Blog

THE BERKO TRIAL – PART 2: The Missing Last Mile: How the Defense Challenged the Berko Case

Yesterday in Part One of our series on the Asante Berko FCPA trial and conviction, we examined the prosecution’s mosaic. Today in Part 2, we ask the defense question that cut across every category of proof: Where was the bribe?

The Department of Justice (DOJ) had more than 300 emails, payments to intermediaries, financial-flow charts, compliance concerns, and a secretly recorded lunch. The defense argued that the case still lacked its last mile. No alleged recipient testified. No Ghanaian witness took the stand. No eyewitness described a bribe. No bank record showed money reaching a public official. None of the participants in the email chains explained their meaning to the jury.

That position did not prevail. Only after approximately three hours of deliberation did the jury convict Asante Kwaku Berko on conspiracy to violate the FCPA, a substantive FCPA violation, and a money laundering conspiracy. But a fair account of the trial requires more than repeating the result. It requires understanding why the defense believed suspicious conduct and compliance red flags did not add up to proof beyond a reasonable doubt.

Red Flags Are Not the Elements of a Crime

The defense began with the burden of proof. A high-risk intermediary, personal email, opaque invoices, and cash discussions may justify enhanced diligence, an internal investigation, or a decision to exit a transaction. They do not, standing alone, prove corrupt intent or participation in a bribery agreement. Defense attorney Robert Boone told jurors that the government had years to find a witness or record connecting the money to an official. The courtroom presentation, he argued, was impressive, but the underlying proof was missing. The government’s financial charts traced money from Aksa accounts in Turkey to Tricorp, Berko, and others. According to the defense, those charts stopped before showing a transfer to any alleged public-official recipient.

Prosecutors answered that cash completed the path and concealed the payments. The defense response was that an explanation for missing evidence is not the same as the evidence itself. The last-mile gap was not necessarily a claim that a bank receipt was required for every charged theory. It was an attack on the inferences the government asked the jury to draw about agreement, knowledge, purpose, and authorization.

A Scam, Not a Conspiracy

The defense supplied an alternative explanation for the intermediaries’ demands. Tricorp’s principals, Boone argued, saw outsiders pursuing a valuable project and used claims of political access and urgent payment needs to extract money. They were running a shakedown, not carrying out a bribery agreement.

The emails gave that theory something to work with. In one April 2015 message, a Tricorp principal demanded $500,000 immediately and insisted that unspecified necessities had to be handled. Other exchanges reflected disagreements over amounts, timing, and what had supposedly been promised. Boone characterized the demands as exaggerated and unreliable, comparing them to familiar advance-fee scams.

That distinction was critical. If an intermediary falsely claimed that officials had been or needed to be paid, an email repeating that claim might document the intermediary’s sales pitch rather than an actual bribe. Even the reported statement that Berko had paid Parliament came from a Tricorp principal. The defense asked the jury to consider whether the speaker was reporting a fact or using the language of a scam to justify another reimbursement.

The prosecution had a powerful answer: Berko was not merely copied on one stray message. His communications, payment negotiations, channel choices, and recorded statements appeared throughout the chronology. Still, the defense theory targeted an important evidentiary question. Before accepting an intermediary’s statement as proof, who made it, why, and with what first-hand knowledge?

A Legitimate Project With Commercial Logic

The underlying project was real. Ghana was confronting serious electricity shortages and wanted to add 1,000 megawatts of generating capacity quickly. Aksa later obtained financing from Barclays and a Turkish bank after Goldman withdrew, and its 370-megawatt plant entered commercial operation.

The defense used those facts to challenge motive. Ghana needed available power, Aksa could supply it, and other financial institutions ultimately supported the project. Boone put the point bluntly: Why would a qualified company need to bribe a government that was desperate for electricity?

Commercial merit is not a defense to bribery. Legitimate projects can still be advanced through corrupt means. Yet the project’s reality gave the defense a noncriminal explanation for meetings, urgency, large fees, and intense communications. The government had to prove that the conduct crossed the line from hard-driving project execution into corrupt payment activity.

Hundreds of Emails, but No Voice From the Chain

The prosecution treated the emails as the scheme speaking for itself. The defense treated them as fragments without context. FBI Special Agent Ryan Collins introduced much of the correspondence, but Boone emphasized that Collins did not participate in the exchanges and did not know what the writers meant. No participant in the chains took the stand to explain the language.

That allowed the defense to challenge words such as “payment,” “millions,” “fees,” and “cash.” Depending on purpose and recipient, those terms can describe legitimate compensation, reimbursement, or financing. Similarly, using Gmail for business after acknowledging that a Goldman account was monitored could demonstrate poor judgment, policy evasion, or concealment. The defense argued that the criminal inference depended on what the communications concerned, not the platform alone. This was also the weakness in the defense position. The messages were numerous, contemporaneous, and aligned with transaction milestones. An alternative interpretation had to explain the full pattern, not merely establish that individual phrases were ambiguous.

Testing the Recorded Lunch

The recorded lunch carried the drama of a direct conversation, but the defense attacked its context and origin. The unnamed source first approached the SEC, later assisted the FBI, and was described at trial as the genesis of the investigation. The defense argued that possible eligibility for an SEC whistleblower award created a financial incentive. According to the reporting, the source did not testify, and defense filings asserted that the source had supplied false information to investigators.

The FBI also identified subjects for the source to raise before the November 2016 meeting. One was cash. The resulting video was grainy, the restaurant was noisy, and the conversation moved among English, Twi, and Ghanaian Pidgin English. Jurors relied in part on a translated transcript.

The defense emphasized that the cash exchange arose during an apparently hypothetical discussion involving investors, Ghanaian stock, and a botanical garden. Berko initially said paying the people under discussion was not a good thing. Only after the source asked for the best way to pay did Berko answer that cash could be used.

The government’s strongest response was Berko’s own reported language, including his statement that “KD got one million” and his assurance that he could obtain a large amount of cash.[4] Source motive did not erase those words. The defense attack went to whether the source’s prompting, translation, and hypothetical setup changed their meaning.

Corporate Withdrawal Was Not a Criminal Verdict

Goldman’s review produced genuine concerns. Amandine Martin testified that Aksa’s explanations for payments to Tricorp did not match earlier information and that months of questions did not produce satisfactory answers. Goldman withdrew and earned nothing from the contemplated financing. For the defense, that corporate decision showed a risk-control judgment, not proof of Berko’s guilt. Businesses act before uncertainty is resolved because they do not apply the criminal standard of proof. Other lenders later financed the project, reinforcing the defense position that the transaction had commercial substance.

The distinction matters. A company may properly stop a transaction when diligence cannot resolve serious red flags. A jury must decide whether the government proved the charged crime beyond a reasonable doubt. Those are different decisions made for different purposes.

The Missing Link and the Complete Pattern

The jury rejected the defense position and returned guilty verdicts on all three counts. The general verdict does not disclose why. It does not tell us whether jurors found the emails decisive, credited the cash explanation, accepted the recorded statements at face value, or concluded that all of the evidence corroborated itself.

The defense nevertheless framed the trial’s central proof contest. The government had to turn red flags into criminal evidence. The defense had to offer an innocent explanation capable of accounting for the complete record: the emails, milestone timing, intermediary payments, off-channel communications, compliance interactions, financial flows, and recorded lunch. Identifying a missing link can create reasonable doubt. But the alternative theory must also explain why every other link appears to point in the same direction. In Berko, the jury concluded that the government carried its burden.

Join us tomorrow for Part 3, where we will consider what those three guilty verdicts legally established, what a general verdict leaves unresolved, and why compliance professionals should resist turning a verdict into factual findings the jury never made.

Resources:

United States v. Berko, No. 1:20-cr-00328-DG, Indictment, ECF No. 3 (E.D.N.Y. filed Aug. 26, 2020)

Stewart Bishop, “Goldman Jury Sees Cash Talk in Energy Deal Email Deluge,” Law360, Aug. 1, 2026; Stewart Bishop, “Goldman Exec Was Linchpin to Ghana Bribery Ploy, Jury Told,” Law360, Aug. 5, 2026.

Stewart Bishop, “Ex-Goldman Exec Convicted of Ghana Bribery Plot,” Law360, Aug. 6, 2026. Supplied trial reporting.

U.S. Attorney’s Office for the Eastern District of New York, “Former Goldman Sachs Investment Banker Convicted of Foreign Bribery and Money Laundering,” Aug. 6, 2026, DOJ Press Release.

Stewart Bishop, “Goldman Jury Sees Undercover Video as Bribe Trial Nears End,” Law360, Aug. 4, 2026—supplied trial reporting.

Stewart Bishop, “Shady Power Deal Used in Goldman Compliance Prep, Jury Told,” Law360, July 29, 2026

Stewart Bishop, “Like Milli Vanilli, Goldman FCPA Case Is a Ruse, Jury Told,” Law360, July 28, 2026.

SEC Final Judgment against Asante Berko

SEC Complaint against Asante Berko

Categories
FCPA Compliance Report

FCPA Compliance Report: The Berko Verdict with Mike Volkov

In this episode, Tom Fox welcomes back his good friend and colleague Mike Volkov and takes a deep dive into the Asante Berko FCPA guilty verdict.

They question why Berko went to trial given the strength of the case, discuss the power of recorded statements like requests to use private email, and highlight Goldman Sachs compliance personnel as corroborating witnesses after the firm stopped the transaction and disclosed it. They conclude with compliance lessons that include rigorous deal due diligence, escalation of red flags, sampling internal communications, and monitoring attempts to move discussions off-channel.

Key highlights:

  • Quick Jury Verdict
  • Recordings And Emails
  • Goldman Compliance Witness
  • Sentencing Trial Penalty
  • SEC Settlement Strategy
  • Compliance Lessons Red Flags

Resources:

Berko Trial Blog Post series on FCPA Compliance and Ethics Report

Mike Volkov on LinkedIn

Tom Fox

Instagram

Facebook

YouTube

Twitter

LinkedIn

To learn about the intersection of Sherlock Holmes and the modern compliance professional, check out Tom’s latest book, The Game is Afoot-What Sherlock Holmes Teaches About Risk, Ethics and Investigations on Amazon.com.

Categories
Blog

THE BERKO TRIAL – PART 1: The Digital Trail: How Prosecutors Built the Berko Bribery Case

A bribery case does not always arrive with a signed receipt. In the trial of former Goldman Sachs banker Asante Berko, prosecutors presented something different: a mosaic of evidence. They placed before the jury a high-value public project, politically connected intermediaries, payments tied to transaction milestones, personal email accounts, disputed consulting invoices, cash withdrawals, a recorded lunch conversation, and an individual who allegedly stood to receive millions.

Over the next five days, I will be taking a deep dive into this trial to see how the prosecution was able to convince a jury of the defendant’s guilt so quickly. The verdict was rendered in just over 3 hours, which tells you the jury did not doubt as to the defendant’s guilt. This blog post series is based upon the excellent reporting of Law360 reporter Stewart Bishop and additional source documents and resources from the Department of Justice (DOJ) and Securities and Exchange Commission (SEC).

The government’s burden was to prove the charged crimes beyond a reasonable doubt. Its strategy was to show that the evidence did not consist of isolated red flags. Each category corroborated the others. Taken together, prosecutors argued, the pattern demonstrated opportunity, corrupt intent, concealment, and personal gain.

A National Crisis and a High-Stakes Deal

The story began with a legitimate and urgent business need. Ghana had suffered widespread power shortages, and its government was seeking projects capable of adding generation quickly. Aksa Enerji Uretim A.S., a Turkish energy company and Goldman client, pursued an agreement to build and operate a power plant. The commercial stakes were substantial. Goldman contemplated arranging approximately $190 million in financing for Aksa and a $75 million letter of credit for Ghana. Goldman also held an approximately 16 percent interest in Aksa. The indictment alleged projected fees of approximately $10.3 million for the loan and more than $1 million for the letter of credit.

Berko was central to the business effort. A dual citizen of the United States and Ghana, he worked in the structured-finance group of Goldman’s United Kingdom subsidiary and had relationships with senior Ghanaian officials. Prosecutors argued that he connected three critical groups: the commercial client seeking the project, the local intermediaries who claimed access, and the public officials whose approvals were required. That role gave the government its organizing theory. Berko was not presented as a participant at the edge of the transaction. He was presented as the linchpin.

The Email Trail

The most important prosecution evidence was documentary. More than 300 emails were admitted during the nine-day trial. Prosecutors used their language, timing, recipients, and communication channels to construct a chronology of the alleged scheme. One September 2015 email shown to the jury stated that Parliament had been paid by Berko and discussed approximately $46,000 that he allegedly paid. Other messages addressed payments associated with the Ministry of Power, regulators, power-team personnel, travel, and parliamentary approval. In a July 2015 exchange over the size and timing of payments, Berko wrote that he was managing a relationship expected to pay everyone millions.

The government argued that these exchanges became more incriminating when compared with Berko’s ordinary deal communications. Routine transaction work went through Goldman’s systems. Sensitive payment discussions appeared in personal accounts. In February 2016, prosecutors showed the jury two emails sent 14 minutes apart. One used Berko’s Goldman account for ordinary deal business. The other used Gmail and instructed recipients to communicate there because his Goldman account was monitored. Personal email alone does not prove bribery. The government’s point was more precise. When an employee knows that the official system is monitored, moves sensitive discussions to a private channel, and then uses that channel for payment conversations linked to public approvals, the channel choice may support an inference of concealment.

Money That Followed Milestones

The prosecution next aligned communications with transaction events and financial flows. The indictment alleged that intermediaries used false consulting invoices to obtain reimbursement for bribes and routed funds from Turkey to Ghana through correspondent accounts in New York.

The chronology was central to the prosecution’s case. In April 2015, as the parties pushed toward execution of the emergency power agreement, an intermediary issued a $500,000 invoice. Emails allegedly discussed using part of that money to pay a Ghanaian official, and a $500,000 wire followed. Later that month, five Ghanaian officials traveled to Turkey to inspect equipment. The indictment alleged that their expenses were covered and each received $5,000.

When a senior Ghanaian official signed the agreement in May 2015, another invoice for $1.5 million was issued the same day. A $1.5 million transfer followed later that month. After Parliament ratified the agreement in July, emails discussed a $250,000 reimbursement request that included payments connected to Parliament, the Ministry of Power, regulators, engineers, travel, and Berko personally.

At trial, a government summary witness walked jurors through charts tracing funds from Aksa accounts in Turkey to accounts associated with intermediaries, Berko, and others. The records did not show the final transfer to every alleged official. Prosecutors answered that gap by pointing to evidence that cash was used to complete and conceal the payments. The amounts require discipline. The indictment alleged more than $700,000 in bribes. DOJ stated after the verdict that the government proved more than $1 million in bribes at trial.[1][5] Those figures come from different stages of the case and should remain separately attributed.

The Recorded Lunch

The recording supplied another form of corroboration. In November 2016, an FBI-assisted source met Berko at a London restaurant. The conversation moved among English, Twi, and Ghanaian Pidgin English, and the jury received a translated transcript. In one exchange, the source asked about a former energy minister. Berko replied that “KD got one million.” In another discussion, framed around a hypothetical investment, Berko initially said it was not good to pay the individuals under discussion. When asked for the best way to pay them, however, he answered, “Cash,” and said he could obtain $1 million from a bank.

The prosecution used these statements to reinforce its reading of the emails and money flows. The recording did not stand alone. It supplied the government’s alleged final piece of context: the same person who used private email for sensitive payments and appeared throughout the deal chronology also discussed a million-dollar payment to an energy minister and the practical use of cash. The source’s incentives, the FBI’s preparation of the conversation, translation issues, and the hypothetical framing were substantial defense subjects. They will be examined in Part 2. For the government’s case, the point was corroboration.

When Compliance Became Evidence

Goldman’s compliance response became part of the prosecution’s proof and, in my mind, one of the key components of the government’s overall presentation to the jury, as it was essentially evidence from an outside party to the transaction. Amandine Martin, who worked with Berko on the transaction, testified that Goldman spent months seeking explanations for payments to the Ghanaian intermediary. According to her testimony, the answers did not match information previously provided, and Aksa’s chief executive eventually responded that the company did not have time for the questions. Goldman withdrew from the transaction and did not provide the planned financing. Goldman was not charged in the criminal case. Prosecutors nevertheless used the compliance record to argue that Berko understood the risks and the institution’s rules, knew that his communications were monitored, and failed to correct allegedly false or incomplete explanations about the intermediary.

This is the first compliance lesson of the series: a control is also a record. Questions, responses, escalation, monitoring, and the decision to exit can later become evidence of what an employee knew, what the company challenged, and how the organization responded.

The Government’s Mosaic Holds

After approximately three hours of deliberation, the jury convicted Berko on all three counts: conspiracy to violate the FCPA, a substantive FCPA violation, and money laundering conspiracy. He was remanded pending sentencing. The general verdict does not tell us which email, payment path, witness, or recorded statement the jury found most persuasive. It also does not convert every factual assertion in the government’s narrative into a special finding. It does establish that the jury found the charged elements proven beyond a reasonable doubt.

That is the power of a circumstantial case. The government did not ask the jury to rely on one dramatic piece of evidence. It asked jurors to see a single pattern across communications, payments, timing, conduct, compliance warnings, and alleged concealment. The jury accepted that case.

Join us tomorrow in Part 2 where we will examine the defense’s answer: if the government said bribes went “up and down the chain,” where was the last mile showing money reaching a public official?

Resources:

United States v. Berko, No. 1:20-cr-00328-DG, Indictment, ECF No. 3 (E.D.N.Y. filed Aug. 26, 2020)

Stewart Bishop, “Goldman Jury Sees Cash Talk in Energy Deal Email Deluge,” Law360, Aug. 1, 2026; Stewart Bishop, “Goldman Exec Was Linchpin to Ghana Bribery Ploy, Jury Told,” Law360, Aug. 5, 2026.

Stewart Bishop, “Ex-Goldman Exec Convicted of Ghana Bribery Plot,” Law360, Aug. 6, 2026. Supplied trial reporting.

U.S. Attorney’s Office for the Eastern District of New York, “Former Goldman Sachs Investment Banker Convicted of Foreign Bribery and Money Laundering,” Aug. 6, 2026, DOJ Press Release.

Stewart Bishop, “Goldman Jury Sees Undercover Video as Bribe Trial Nears End,” Law360, Aug. 4, 2026—supplied trial reporting.

Stewart Bishop, “Shady Power Deal Used in Goldman Compliance Prep, Jury Told,” Law360, July 29, 2026

SEC Final Judgment against Asante Berko

SEC Complaint against Asante Berko

Categories
Blog

The Scoular DPA Part 3: The Data Was Talking – Data Analytics and the Scoular Bribery Scheme

The Scoular Company bribery scheme was hidden, but it was not invisible. For six years, customs brokers paid Mexican officials approximately $2,000 per train so Scoular Company shipments could cross the border despite adverse inspections. The brokers invoiced the payments back to Scoular as “reinspection fees.” In total, Scoular Company admitted that it authorized $414,351 in bribes and avoided approximately $6.5 million in fees and costs. Those facts describe an FCPA violation. They also describe a data pattern.

I had the opportunity to visit with Vince Walden, CEO of KonaAI, about the Scoular Company FCPA enforcement action from a data analytics perspective. He identified the feature that should command every CCO’s attention: people concealing misconduct often record it consistently. They may avoid the word “bribe,” but they still need a repeatable description that allows the payment to be processed, reconciled, and found again. At Scoular Company, that description was “reinspection fee.”

Walden’s observation goes to the heart of modern compliance. Illegal conduct may be concealed from the compliance department while remaining visible in accounts payable, journal entries, invoices, purchase orders, shipment records, and communications. The control failure occurs when those systems hold the evidence, but the company never asks the data the right questions.

Consistency Can Become the Fraudster’s Fingerprint

Walden observed that accountants value consistency because consistent classifications support accurate reporting. Fraudsters and their enablers can exploit the same discipline. A bookkeeper cannot label a payment “bribe expense.” The payment still needs a code, description, vendor, amount, approver, account, and business purpose. If the scheme continues, the participants need a method they can repeat. That repetition creates a fingerprint.

Suspicious terms in payment descriptions and journal entries are among the most useful anti-corruption monitoring tests. His examples included phrases such as “friend fee,” “government payment,” and “miscellaneous.” The precise word will vary by company and geography. The analytical principle does not.

The company should identify unusual language, then connect it to the transaction behind it. Even if the language is not unusual, its repeated use might form a pattern worth exploring. A word cloud may provide a useful visual starting point. Keyword searches, natural-language processing, and risk dictionaries can scale the review across thousands of invoices and expense reports. Yet the purpose is not to find one forbidden word. It is to identify language that is unusual for the business, unusually frequent for one vendor, or correlated with a high-risk outcome. “Reinspection fee” was facially plausible. Repetition changed its meaning.

The First Test Was Hiding in Plain Sight

An elementary analytic (As in Elementary, my dear Watson) would have grouped customs-related payments by invoice description, vendor, amount, port, and frequency. That test could have asked:

  • How often does “reinspection fee” appear?
  • Which brokers submit the charge?
  • Is the amount repeatedly near $2,000?
  • Which employees approve it?
  • Does it appear only on trains with an inspection problem?
  • What happens to the shipment immediately after payment?

No single answer proves bribery. Together, the answers can create a compelling reason to investigate. The recurring round-dollar amount matters. Legitimate inspection costs often vary with the service, product, weight, time, port, or government fee schedule. A repeated $2,000 charge across multiple transactions may indicate a fixed unofficial tariff rather than the cost of a legitimate service.

The description also matters. If “reinspection fee” was not found in an approved government schedule, lacked official documentation, or appeared only in broker invoices rather than government receipts, the control should have required escalation before payment. Finally, the outcome matters most. If trains that failed inspection were consistently released after the fee, the company had more than an accounting anomaly. It had a payment linked to a favorable exercise of government discretion.

Connect the Payment to the Business Outcome

Traditional controls often examine whether an invoice matches a purchase order and whether an authorized employee approved it. A bribery scheme can satisfy both tests when employees are participating in the misconduct.

Data analytics must therefore test commercial substance, not merely procedural completion.

For Scoular Company, the decisive data model would connect five sources:

  • Inspection data: date, result, impurity identified, inspector, agency, and reinspection history.
  • Shipment data: train identifier, product, port, broker, delay, release time, and disposition.
  • Payment data: invoice description, amount, general-ledger account, supporting documents, approver, and payment date.
  • Third-party data: broker risk rating, contract terms, bank account, audit rights, ownership, and compensation history.
  • Communications data: relevant emails, WhatsApp records lawfully available to the company, and other business messages.

With those sources joined, compliance could test whether a $2,000 broker charge followed an adverse inspection and then by rapid release of the train. It could compare release rates for shipments with and without the payment. It could identify which brokers, ports, and employees produced unusually favorable clearance outcomes. That sequence is the analytic signature of the scheme: failed inspection, unusual payment, successful release.

Build a Layered Anti-Bribery Analytics Program

A mature program should not depend on one keyword or one dashboard. It should use several complementary tests.

Text analytics. Search invoice narratives, journal entries, purchase orders, and expense descriptions for high-risk terms, euphemisms, spelling variants, and unusual phrases. The risk dictionary should reflect the company’s markets and evolve with investigations.

Transaction analytics. Flag recurring round-dollar payments, duplicate or near-duplicate invoices, payments just below approval thresholds, split payments, weekend postings, manual journal entries, and charges lacking official receipts.

Vendor analytics. Compare customs brokers by fee frequency, payment descriptions, clearance rate, failed-inspection rate, use of subcontractors, changes in bank accounts, and concentration under particular employees or business units.

Outcome analytics. Test whether payments are statistically associated with permits, inspections, releases, tax outcomes, contract awards, or other favorable government actions. This moves the review from what the invoice says to what the payment accomplished.

Sequence analytics. Measure the time between an adverse event, a payment request, approval, payment, and favorable resolution. Short, repeated intervals can reveal a designed process.

Communications analytics. Where lawful and consistent with company policy, match high-risk transactions to messages about urgency, guarantees, officials, inspections, exceptions, or payments. A suspicious invoice can corroborate a message, and a message can explain the invoice.

Network analytics. Map relationships among employees, brokers, bank accounts, ports, approvers, and government touchpoints. Shared bank accounts, common addresses, unusual subcontractors, or recurring approval chains can expose concealed connections.

These tests should create ranked alerts, not automated accusations. Analytics identifies anomalies. Trained reviewers determine whether the transaction has a legitimate explanation, requires more evidence, or warrants an investigation.

Continuous Monitoring Is a Governance Choice

Walden’s closing advice was simple: keep innovating and keep running the analytics. The word “running” matters. As in continuously. A one-time review performed after a subpoena is forensic reconstruction. A risk-based test operating monthly, weekly, or at the point of payment is a compliance control.

Continuous monitoring does not mean surveillance of every employee or review of every transaction. It means that known high-risk processes receive repeatable testing at a frequency aligned with the risk. Customs payments, government-facing third parties, failed inspections, and manual financial entries deserve more attention than ordinary low-risk purchases.

The program also needs governance. Compliance and internal audit should agree on data ownership, alert thresholds, reviewer responsibilities, escalation standards, documentation, privacy requirements, and feedback loops. Finance must help validate legitimate payment patterns. The business must explain operational outcomes. Technology must maintain data quality and access. Legal must ensure that communications monitoring is lawful.

Most importantly, the board should ask whether compliance has direct access to the data. A dashboard built from incomplete information can create false assurance. If broker invoices sit in one system, inspection results in another, shipment releases in a third, and WhatsApp messages outside company retention, the organization sees fragments while the scheme operates across the seams.

Internal Controls Must Learn From Every Alert

Data analytics is not a substitute for internal controls. They supplement each other, as data analytics is a way to test whether those controls work and where they fail. An alert concerning a reinspection fee should trigger questions about official documentation, approved fee schedules, broker contracts, audit rights, segregation of duties, approval thresholds, and the economic rationale for the charge. If the review confirms misconduct, root-cause analysis should determine why the payment passed through accounts payable, why the broker remained active, why inspections and payment data were not connected, and whether incentives rewarded shipment clearance over compliance.

Every closed alert should improve the system. Confirmed concerns should add new keywords, vendor attributes, transaction patterns, and outcome measures. Legitimate transactions should help refine thresholds and reduce noise. This is how a compliance program becomes adaptive rather than static.

Questions for CCOs

CCOs should ask:

  • Which payment descriptions recur in our highest-risk government-facing processes?
  • Can we connect invoices to inspections, permits, customs outcomes, and shipment releases?
  • Which third parties generate unusually favorable results after unusual payments?
  • Are alert reviewers trained to investigate commercial substance, not merely paperwork?
  • How quickly does a confirmed issue change our controls and analytics?

The Bottom Line

Scoular Company’s bribery scheme did not require a sophisticated algorithm to detect. It required the company to notice a repeated phrase, a recurring amount, a high-risk broker, an adverse inspection, and a favorable government outcome. Walden’s lesson is that concealment often creates consistency, and consistency creates data. The task of compliance is to convert that data into a question early enough to matter.

Follow the words. Test the amount. Connect the outcome. Then channel your inner Sherlock Holmes and investigate what the pattern is telling you.

Categories
Blog

The Scoular DPA: Part 2 – A Journey Through Non-Disclosure

The Scoular Company Deferred Prosecution Agreement (DPA) presents a difficult but essential lesson for every Chief Compliance Officer and board: stopping misconduct is not the same as voluntarily disclosing it. This might seem as self-evident as anything in compliance, but it is a critical component of this case.

The Statement of Facts says that internal reports alleging improper business practices connected to the Mexican inspection fees arose in 2019. Scoular then changed its grain-shipment practices and terminated its direct engagement with the customs brokers involved. Those steps addressed the immediate conduct. They did not produce voluntary self-disclosure credit. That misstep cost Scoular Company millions, potentially leading to a full declination.

The DPA states that Scoular did not receive credit under the DOJ Corporate Enforcement and Voluntary Self-Disclosure Policy (VSP) because it did not “voluntarily and timely disclose” the conduct to the Fraud Section. That single sentence creates the central governance question in Blog Post Part 2: What must happen after a credible internal report reaches the company? An internal allegation starts an investigative clock. The company must preserve evidence, protect against retaliation, assess immediate risk, and establish enough facts to make responsible decisions. It also starts a disclosure clock.

The VSP encourages companies to report potential wrongdoing at the earliest possible time, even before an internal investigation is complete. To qualify as a voluntary self-disclosure, a report must be made in good faith to the appropriate DOJ component, concern misconduct not already known to the Department, occur without a preexisting disclosure obligation, precede an imminent threat of disclosure or government investigation, and be made within a reasonably prompt time after the company becomes aware of the misconduct.

The burden of demonstrating timeliness rests with the company. This does not mean a company must call the DOJ the moment an untested allegation enters the hotline. It does mean disclosure cannot wait until every interview, legal conclusion, and remediation project is complete. The investigation and disclosure analyses must proceed together.

The DPA Tells Us the Result, Not the Internal Debate

The agreement does not explain who received the 2019 reports, how the allegations were investigated, when senior management or the board learned of them, or why Scoular did not make a qualifying disclosure. It does not tell us whether the company made a deliberate decision not to report. What the DPA does establish is the outcome. Internal reports arose. The company changed its practices and terminated direct broker relationships. The company did not voluntarily and timely disclose the conduct to the Fraud Section and therefore received no voluntary disclosure credit.

That sequence is enough to demonstrate a control lesson. A company can remediate an operational problem and still leave the enforcement decision unresolved. The response requires four distinct workstreams:

  • Stopping the conduct prevents additional harm.
  • Investigating the conduct determines what happened and which controls failed.
  • Remediating the controls reduces recurrence risk.
  • Evaluating disclosure determines whether, when, where, and how the company should approach enforcement authorities. This fourth step is arguably the most important and must be reached with great speed, perhaps as little as two weeks after initial determination.

A Disclosure Needs a Decision Process

Disclosure decisions should not depend on one executive’s instinct or on the hope that remediation will close the matter. The company needs a defined escalation structure involving legal, compliance, internal audit, finance, and appropriate senior management. Depending on the seriousness of the facts, the audit committee or another independent board committee may need to oversee the decision.

For an FCPA matter involving customs brokers, repeated payments, government officials, inaccurate invoice descriptions, senior personnel, and multiple years of conduct, the disclosure analysis should address:

  • What credible facts are known now?
  • Is the misconduct continuing?
  • Which individuals and third parties may be involved?
  • Are the books and records inaccurate?
  • Is there evidence of management participation, approval, condonation, or willful ignorance?
  • Has a whistleblower, auditor, regulator, bank, business partner, or foreign authority already received the same information?
  • Is there an imminent threat that the DOJ will learn of the conduct?
  • What additional facts are necessary to make a disclosure decision?
  • When will the decision be revisited?
  • Who has authority to decide, and how will the reasoning be documented?

The objective is not to create a paper defense for a predetermined result. It is to establish a disciplined process that forces the company to confront timing, uncertainty, accountability, and enforcement exposure.

Disclosure Does Not Require a Finished Investigation

One reason companies may delay is the understandable fear of reporting facts that are incomplete or later prove wrong. The DOJ policy addresses that concern directly. It encourages early disclosure even when the company has not completed its internal investigation. The company can report the misconduct known at that stage, identify the limits of its current knowledge, preserve credibility by avoiding unsupported conclusions, and provide rolling updates as the investigation develops.

That approach requires discipline. The initial disclosure should distinguish facts from allegations, describe preservation and remediation steps, and explain the investigative plan. Later presentations should attribute facts to specific sources and identify individuals regardless of seniority.

Waiting for certainty can eliminate the benefit the company hoped to secure. A whistleblower may contact the government, a third party may cooperate, or the payment may surface in another investigation. Once the DOJ already knows or disclosure is imminent, the analysis changes. The business lesson is straightforward. Uncertainty calls for a staged disclosure strategy, not an indefinite pause.

Cooperation Still Mattered

Scoular Company lost the disclosure benefit, but the DPA demonstrates that the company could still earn meaningful credit. The DOJ credited Scoular with conducting an internal investigation, making detailed factual presentations, identifying individuals involved, producing and organizing requested materials, securing counsel for current employees, and providing all relevant facts known to it.

Voluntary self-disclosure, cooperation, and remediation are separate pillars. A company that misses the first can still create value through the other two. The DPA also notes “certain deficiencies in the early part of the investigation.” It does not identify those deficiencies, and they should not be guessed. Their inclusion nevertheless sends a message: cooperation is judged across the life of the investigation, not merely by the quality of the final presentation.

The current DOJ policy makes the standard explicit. A company starts at zero cooperation credit and earns credit through specific actions: scope, quality, impact, and timing matter. A failure to cooperate fully at the earliest opportunity may reduce the credit available later. For CCOs and boards, the lesson is that recovery remains possible, but delay has a price.

Remediation Changed How the Business Operated

Scoular also received credit for substantial remediation. The company increased compliance engagement with the business, used external compliance maturity and anti-corruption risk assessments, restructured the compliance function, and incorporated senior leadership oversight. It eliminated customs brokers associated with reinspection fees, strengthened risk-based review and monitoring with software tools, revised policies, enhanced third-party screening and approvals, added anti-corruption and audit-right provisions to contracts, improved financial controls for high-risk transactions, and delivered general and targeted training.

These measures went beyond terminating vendors. They addressed governance, third-party management, payment controls, monitoring, technology, policies, and training. That breadth matters because remediation must be tied to root cause. If the misconduct was enabled by commercial pressure, broker dependence, misleading invoices, weak transaction validation, and fragmented data, another annual training course will not solve the problem.

The Economic Difference Was Significant

Scoular entered into a three-year DPA and agreed to pay a $9,769,521 criminal penalty and $414,351 in forfeiture. The DPA states that the penalty reflected a 25 percent reduction from the applicable low-end amount. A footnote explains that the statutory alternative-fine cap, based on twice the approximately $6.513 million gross gain, constrained the otherwise higher Guidelines minimum.

The DPA does not say what disposition Scoular would have received after a qualifying disclosure. It would be improper to rewrite the resolution with hypothetical facts.

The current department-wide CEP nevertheless shows why the distinction matters. A company that voluntarily self-discloses, fully cooperates, timely remediates, and has no disqualifying aggravating circumstances is placed on a declination path. A good-faith self-report that narrowly misses the policy’s technical requirements can still lead to an NPA, a term shorter than three years, no monitor, and a reduction of 50 to 75 percent from the low end. Companies outside those paths remain subject to prosecutorial discretion, with a reduction capped at 50 percent.

Scoular received a DPA, a three-year term, and a 25 percent reduction. The numbers turn disclosure governance into a business issue. The decision affects resolution form, penalty exposure, duration, oversight, reputation, management time, and the company’s ability to move beyond the misconduct.

Questions for CCOs

CCOs should ask:

  • Does every credible allegation involving government payments trigger a documented disclosure analysis?
  • Who owns the disclosure clock while the investigation proceeds?
  • Can legal and compliance make an early report without waiting for a completed investigation?
  • Are facts, assumptions, open questions, and decision deadlines documented separately?
  • Have we tested the process through a tabletop exercise involving a whistleblower, a third party, and an imminent government inquiry?

The Scoular DPA does not establish why the company missed voluntary disclosure credit. It does establish that internal reporting, operational remediation, and voluntary disclosure are not interchangeable. When a credible allegation arrives, the company must stop the conduct, investigate the facts, remediate the controls, and make a timely, documented disclosure decision. Doing three of those four things can still leave substantial value on the table.

Join us tomorrow for Part 3, where we will examine how a robust internal control system paired with a robust data analytics overview can help a company avoid a Scoular Company-type series of failures.

Categories
FCPA Compliance Report

FCPA Compliance Report: Matt Ellis Wrap-Up from Cartels, FTO Risk, and Corporate Compliance Conference

In this episode, Tom Fox welcomes back Matt Ellis of Miller & Chevalier to recap ACI’s inaugural two-day Cartel Conference in Washington, DC, highlighting an unusually collaborative, high-energy atmosphere around emerging cartel/TCO/FTO compliance risks in Latin America.

They discuss DOJ’s Scoular FCPA action as illustrating the long tail of enforcement and a high bar for managing cartel-related and national security risks, while noting the DPA’s remedial steps focus more on traditional anti-corruption controls than TCO/FTO-specific guidance. Government participants emphasized a “whole of government” approach, voluntary disclosure, and potential public-private engagement (including embassy attachés and Treasury) in high-risk scenarios. Key themes included narrow duress defenses, complex “imposter” risks, evolving due diligence beyond traditional screening using data/anomaly detection and local intelligence, and the need to integrate compliance across AML, sanctions, security, and supply chain given severe reputational and business consequences of terrorist or cartel support.

Key highlights:

  • Conference Vibe and Energy
  • Scoular FCPA Case Takeaways
  • When to Engage Government
  • Duress Defense and Safety Payments
  • Cartel-Focused Due Diligence
  • AML Lessons for Banks
  • Breaking Silos in Compliance
  • Parallels to Early FCPA Era
  • National Security Stakes

Resources:

ACI National FCPA and Global Anti-Corruption Conference, December 10-11 at the Gaylord National Resort & Convention Center, Washington, DC

Matt Ellis on LinkedIn

Tom Fox

Instagram

Facebook

YouTube

Twitter

LinkedIn

To learn about the intersection of Sherlock Holmes and the modern compliance professional, check out my latest book, The Game is Afoot-What Sherlock Holmes Teaches About Risk, Ethics and Investigations on Amazon.com.