Categories
FCPA Compliance Report

FCPA Compliance Report: Matt Ellis Wrap-Up from Cartels, FTO Risk, and Corporate Compliance Conference

In this episode, Tom Fox welcomes back Matt Ellis of Miller & Chevalier to recap ACI’s inaugural two-day Cartel Conference in Washington, DC, highlighting an unusually collaborative, high-energy atmosphere around emerging cartel/TCO/FTO compliance risks in Latin America.

They discuss DOJ’s Scoular FCPA action as illustrating the long tail of enforcement and a high bar for managing cartel-related and national security risks, while noting the DPA’s remedial steps focus more on traditional anti-corruption controls than TCO/FTO-specific guidance. Government participants emphasized a “whole of government” approach, voluntary disclosure, and potential public-private engagement (including embassy attachés and Treasury) in high-risk scenarios. Key themes included narrow duress defenses, complex “imposter” risks, evolving due diligence beyond traditional screening using data/anomaly detection and local intelligence, and the need to integrate compliance across AML, sanctions, security, and supply chain given severe reputational and business consequences of terrorist or cartel support.

Key highlights:

  • Conference Vibe and Energy
  • Scoular FCPA Case Takeaways
  • When to Engage Government
  • Duress Defense and Safety Payments
  • Cartel-Focused Due Diligence
  • AML Lessons for Banks
  • Breaking Silos in Compliance
  • Parallels to Early FCPA Era
  • National Security Stakes

Resources:

ACI National FCPA and Global Anti-Corruption Conference, December 10-11 at the Gaylord National Resort & Convention Center, Washington, DC

Matt Ellis on LinkedIn

Tom Fox

Instagram

Facebook

YouTube

Twitter

LinkedIn

To learn about the intersection of Sherlock Holmes and the modern compliance professional, check out my latest book, The Game is Afoot-What Sherlock Holmes Teaches About Risk, Ethics and Investigations on Amazon.com.

Categories
Compliance Into the Weeds

Compliance into the Weeds: Scoular Company FCPA Settlement: Cartel Links, Border Trade Risks, and Compliance Lessons

The award-winning Compliance into the Weeds is the only weekly podcast that takes a deep dive into a compliance-related topic, literally going into the weeds to explore it more fully. Looking for some hard-hitting insights on compliance? Look no further than Compliance into the Weeds! In this episode of Compliance into the Weeds, Tom Fox and Matt Kelly discuss the recent FCPA resolution with the Scoular Company. Both Tom and Matt have blogged on this matter, so check out the Resources link below for additional discussions.

The recent FCPA enforcement action against Scoular Company involved a $10.2 million payment and a three-year deferred prosecution agreement over bribes by third-party customs brokers to Mexican border officials to expedite cross-border shipments. DOJ emphasized alleged cartel connections, including a strong statement from the U.S. Attorney for the Western District of Texas, which raised questions about expanded local U.S. attorney involvement and how cartel or potential FTO designations could heighten trade and compliance risks. The company received no voluntary self-disclosure credit but got a 25% discount, with remediation cited (including dropping brokers and strengthening tone at the top). They highlight off-channel WhatsApp use, the lack of released key documents (DPA, statement of facts, criminal information), and practical compliance takeaways on third-party oversight, data analytics, and risk assessments.

Resources:

Matt in Radical Compliance

Tom in FCPA Compliance and Ethics Blog

Tom

Instagram

Facebook

YouTube

Twitter

LinkedIn

A multi-award-winning podcast, Compliance into the Weeds was most recently honored as one of the Top 25 Regulatory Compliance Podcasts, a Top 10 Business Law Podcast, and a Top 12 Risk Management Podcast. Compliance into the Weeds has been conferred the Davey, Communicator, and W3 Awards, all for podcast excellence.

Categories
Blog

Scoular’s $10 Million FCPA Resolution: Compliance Lessons Learned

We conclude our review of the Scoular Company FCPA enforcement action with a full lessons-learned blog post. We are still awaiting the DPA and Criminal Information, so the details of the case come from the Department of Justice (DOJ) Press Release.

A $2,000 payment can disappear inside a global supply chain. Repeated, train-by-train, authorized by employees, routed through customs brokers, discussed on WhatsApp, disguised as a “reinspection fee,” and reimbursed for six years, it becomes an operating model. That is the central lesson from The Scoular Company Foreign Corrupt Practices Act resolution.

The DOJ announced that Scoular Company would pay more than $10 million to resolve an investigation into bribes paid to Mexican officials between 2013 and 2019. The company entered into a three-year deferred prosecution agreement, agreed to a $9,769,521 criminal penalty and $414,351 in forfeiture, and accepted continuing cooperation, compliance, and reporting obligations.

Across this blog post series, we examined four dimensions of the case: customs brokers and payment controls, cartel and national-security risk, off-channel communications, and the facilitating-payments exception. Read together with my podcast conversation with Matt Ellis, they reveal a single conclusion. Compliance must follow the complete transaction, from the business pressure that creates the payment to the third party that delivers it, the message that authorizes it, the invoice that conceals it, and the ultimate recipient who benefits.

The Scheme Hid in Plain Sight

According to the DOJ, Scoular Company relied on customs brokers to move corn and other agricultural products from the United States into Mexico. Mexican authorities inspected the shipments for dirt, soil, and other impurities. When inspections identified problems, Scoular Company employees directed brokers to pay officials approximately $2,000 per train so the shipments could cross the border. The brokers invoiced the payments back to Scoular Company as “reinspection fees,” and Scoular paid them. In total, the company authorized more than $400,000 in bribes and avoided more than $6.5 million in fees and costs.

The invoice description is the first major lesson. “Reinspection fee” sounded like it was connected to a legitimate customs process. Yet an accounts-payable control that merely matches an approved vendor, purchase order, and plausible service description tests paperwork, not substance.

Effective payment controls should require the company to identify the government agency involved, match the charge to a specific shipment and inspection, compare the amount with an official fee schedule, obtain proof of service, confirm the payee, and document the business justification. Repeated round-dollar charges, unusual success rates, rapid clearance after special payments, and fees unsupported by government records should trigger review.

Follow the money, measure the time, and test the outcome. That is how ordinary transaction data becomes an anti-corruption control.

A Licensed Broker Is Still a High-Risk Third Party

Customs brokers should never be treated as low-risk administrative providers simply because they are licensed or legally required. They interact with government officials, operate under commercial pressure, and can impose charges that distant finance personnel cannot easily verify.

Initial due diligence remains necessary, but it is only the beginning. Companies must connect screening, contracting, invoice testing, transaction monitoring, recertification, training, audit rights, and offboarding. The real test is not whether the third-party file was complete on the day of onboarding. It is whether the company understands how the broker behaves after the contract is signed.

The DOJ credited Scoular Company with eliminating brokers associated with the Mexican reinspection payments, strengthening risk-based screening and approvals, adding anti-corruption and audit-rights provisions, revising controls for high-risk transactions, and using software tools to improve monitoring. That remediation changed the operating model rather than merely revising a policy.

Cartel Risk Changes the Compliance Perimeter

The most consequential part of the DOJ announcement may be its national-security framing. The government determined that, without Scoular Company or its employees knowing it, a portion of the bribes benefited persons associated with a cartel’s criminal operations at the U.S.-Mexico border.

U.S. Attorney Justin R. Simmons stated that American companies engaged in cross-border trade bear responsibility for operating without benefiting cartels or threatening national security. Ellis challenged the literal breadth of the statement during our podcast discussion. Legitimate trade crosses the border every day without companies knowingly paying cartels. Nevertheless, he agreed that the statement signals a more demanding compliance environment.

Ellis explained that the cartel and transnational criminal organization risk is broader than the traditional FCPA risk. Anti-corruption diligence often concentrates on government touchpoints and intermediaries. Organized crime may be hidden inside transportation providers, suppliers, customers, labor relationships, security services, subcontractors, and local routes.

Traditional database screening may not reveal those connections. Ellis emphasized contextual diligence: speak with employees on the ground, examine local security concerns, understand regional criminal activity, investigate facts that do not add up, and adjust operations when warning signs emerge. Companies do not need perfect knowledge. They need a documented story of reasonable measures, credible escalation, and risk-based decisions.

The practical consequence is an integrated risk assessment. Anti-corruption, sanctions, anti-money laundering, trade compliance, physical security, supply chain, and third-party risk cannot remain in separate silos when the same payment may touch all of them.

WhatsApp Was Part of the Control Environment

The DOJ said Scoular Company employees communicated about shipments and bribes through WhatsApp and other means. WhatsApp was therefore not a side issue. It allegedly carried the knowledge and direction behind transactions later recorded as legitimate reinspection charges.

An informal application becomes a business system when employees use it to direct third parties, approve payments, or resolve customs problems. Enterprise controls can be bypassed when the substantive decision occurs in a private chat, and the formal system records only the sanitized result.

Ellis noted that a complete WhatsApp ban may be unrealistic in Latin America. The better approach is to map actual use and define what may occur on each platform. Logistical coordination may be permitted. Government interactions, payment approvals, contractual commitments, and exceptions should remain in controlled systems with retention and audit trails.

Companies must also be able to preserve and retrieve business communications lawfully from company and personal devices. Policies should address device replacement, departing employees, legal holds, privacy and employment requirements, refusal of access, and consistent discipline. The decisive question is not whether a policy exists. It is whether the company can obtain the evidence when an investigation begins.

Why These Were Not Facilitation Payments

The $2,000 amount and the customs setting may tempt employees to use the phrase “facilitation payment.” That label does not fit. The FCPA’s narrow exception covers payments intended to expedite routine, nondiscretionary governmental action that the payer is already entitled to receive. Scheduling an inspection may be routine. Paying an official to disregard a failed inspection is not.

The Scoular Company payments allegedly changed the result. The shipments had identified impurities, and the payments allowed trains to cross despite those findings. The company received a substantial business advantage by avoiding more than $6.5 million in costs. A facilitation payment is not defined by size, local custom, commercial urgency, or invoice terminology. A third party cannot create an exception unavailable to the principal. Nor does an anti-bribery exception excuse false accounting. Even a qualifying payment must be accurately recorded and supported by adequate internal controls.

Ellis’s discussion of extortion reinforces the operational lesson, although extortion and facilitation are distinct doctrines. One or two emergency payments may present a different analysis from a chain of payments continuing over years. Repetition transforms an asserted accommodation into a business process. Companies must respond by escalating, rerouting, changing providers, investigating, and remediating.

Cooperation Still Matters

Scoular Company did not receive voluntary self-disclosure credit because it did not report the conduct to the DOJ in a timely manner. It did receive cooperation credit for its internal investigation, factual presentations, identification of involved individuals, production and organization of evidence, and provision of counsel for current employees, despite early deficiencies.

The resulting criminal penalty reflected a 25 percent reduction from the bottom of the applicable sentencing guidelines range. The lesson is straightforward. Missing the voluntary disclosure window does not render later cooperation irrelevant, but cooperation is not a substitute for timely self-disclosure. The Scoular Company resolution is not four separate compliance stories. It is one story about how pressure, third parties, communications, accounting, and emerging national-security risks converged inside an ordinary business process.

The enduring lesson is equally integrated: know the broker, validate the payment, preserve the message, understand the route, and test the outcome. That is how compliance moves from policy to proof.

Categories
Blog

Nothing Crosses the Border: Scoular and the New Compliance Burden for Mexico Supply Chains

“Nothing crosses into or out of Mexico without the approval and payment to Mexican drug cartels. American businesses that engage in any cross-border trade bear a significant amount of responsibility to do so without benefitting those cartels and without threatening our national security,” said U.S. Attorney Justin R. Simmons for the Western District of Texas. “The bribery scheme in which the Scoular Company engaged demonstrates the dangerous corporate corruption we in the Western District of Texas are committed to fighting on behalf of the American people.”

This is not a quote from The Onion, but it is an extraordinary statement from a United States Attorney. It is not confined to companies that knowingly pay cartels. It is not limited to businesses operating in cartel-controlled industries. It speaks broadly to American companies engaged in cross-border trade with Mexico.

The statement appeared in the Department of Justice’s Press Release announcing that The Scoular Company would pay more than $10 million to resolve an FCPA investigation involving payments to Mexican officials. According to the DOJ, customs brokers paid approximately $2,000 per train to allow shipments of corn and other products to cross the border despite inspections identifying dirt, soil, and other impurities. The payments were invoiced back to Scoular as “reinspection fees.” The enforcement message extends far beyond Scoular. Every U.S. company importing goods from Mexico should take notice.

Cartels and the UFLPA

One of the few laws that demands such an approach is the Uyghur Forced Labor Prevention Act (UFLPA), which targets goods made, whole or in part, by forced labor in the Xinjiang region of China or made by forced labor in other parts of China by Uighurs or other minorities. It is designed to operate as a de facto trade ban on goods from China’s Jing Jang region. US businesses will face a heavy burden to overcome the presumption of forced labor. It is perhaps the most significant US law addressing forced labor, and it has the most tangible repercussions companies can face. Under the UFLPA, the key is your documentation for US Customs and Border Protection. Travis Miller has noted that this means if you are “asking companies to look back into where the actual sand came from that got turned into the silica, that got turned into the semiconductor, that got turned into the circuit board, that got turned into the device that finds its way into your laptop. There’s just never been anything like it.”

The UFLPA and its guidance weave together existing business processes. The UFLPA emerged from the America Supply Chain Executive Order in the US/China trade war, which focused on semiconductors, critical raw materials, and elements that are the subject of the extractives. To comply with it, you could not actually start unless you already had a product compliance program in place. This means that if you do not know the bill of materials, do not have an approved vendor list, or do not know where your components are manufactured, you cannot prove compliance. This may well be the approach the Trump Administration takes under FTOs in Mexico and other locations in Central and Latin America.

Is Every Cross-Border Company Benefiting a Cartel?

In my podcast discussion with Matt Ellis, Latin America Practice Lead at Miller & Chevalier, Ellis challenged the literal breadth of the government’s statement. He noted that companies move legitimate goods between the United States and Mexico every hour without knowingly benefiting drug cartels. It would be inaccurate to conclude that every cross-border transaction involves a cartel payment.

Nevertheless, Ellis called the statement striking. He raised the question every CCO should now be considering: Is the DOJ establishing a new compliance standard for companies doing business across the U.S.-Mexico border? The statement does not create a new statute, regulation, or formal presumption of liability. Yet prosecutorial statements communicate enforcement expectations. Here, the expectation appears to be that American businesses must understand not only who their immediate third parties are, but also whether their supply chain activities could provide economic benefits to organized crime.

That puts pressure on importers in three ways. First, companies may face greater scrutiny over customs brokers, logistics providers, trucking companies, warehouses, security providers, labor organizations, and other parties supporting Mexican operations. Second, companies may be expected to investigate the downstream destination of payments, even when there is no obvious cartel connection. Third, the government may examine whether compliance programs integrate anti-corruption controls with sanctions, anti-money laundering, trade compliance, supply chain security, and organized-crime risk.

The question will no longer be limited to whether the company intended to pay a bribe. Prosecutors may also ask whether the company reasonably understood the environment in which its money and goods were moving.

Traditional Third-Party Due Diligence May Not Be Enough

Ellis made one of the most important observations of our discussion: standard third-party screening may not identify cartel connections. Conventional anti-corruption due diligence focuses heavily on government-facing intermediaries. Companies screen owners and principals, search adverse media, identify politically exposed persons, review government relationships, obtain certifications, and include anti-corruption language in contracts. Those measures remain necessary. They may not be sufficient for organized-crime risk.

Cartel affiliations are rarely disclosed in a corporate registry. A logistics provider may appear legitimate while making payment for protection. A trucking company may operate in a region controlled by a criminal organization. A supplier may use subcontractors with undisclosed local connections. A customer, warehouse, labor group, or security provider may be vulnerable to criminal infiltration.

This means companies should broaden the universe of third parties subject to risk-based review. For Mexican supply chains, that universe may include:

  • Suppliers
  • Customers
  • Customs brokers
  • Freight forwarders
  • Trucking companies
  • Warehouses
  • Security companies
  • Local consultants
  • Port and terminal service providers
  • Labor contractors
  • Union representatives
  • Subcontractors
  • Last-mile transportation providers

The legal requirement to use a licensed customs broker should not reduce scrutiny. As Ellis noted, mandatory licensing can sometimes create a false sense of security. A government license does not replace a company’s responsibility to understand how the broker operates.

Contextual Due Diligence Becomes Essential

If database screening cannot reliably identify cartel connections, companies need a contextual approach. This begins by examining where the third party will operate and what criminal activity is associated with that region. Relevant questions include:

  • Is the location known for cartel activity?
  • Are particular highways or transportation corridors subject to roadblocks or protection payments?
  • Is the region associated with fentanyl production, human trafficking, fuel theft, cargo theft, or smuggling?
  • Are unusual labor or union arrangements present?
  • Does the vendor use subcontractors that have not been disclosed?
  • Are payment requests made in cash or to unrelated accounts?
  • Is the third party reluctant to explain its security or transportation arrangements?
  • Does the third party promise an unrealistic customs clearance rate?
  • Are employees instructed not to ask questions about local payments?

Companies must also listen to their employees on the ground. Local personnel may understand risks that do not appear in formal databases. They know the regional rumors, transportation practices, local power structures, and third parties that other companies avoid.

This presents another compliance challenge. Local employees may fear retaliation if they report suspected cartel connections. A company’s speak-up system must provide credible confidentiality, escalation, and protection measures. A hotline is not enough if employees believe that raising a concern will endanger them or their families.

The New Standard Is Demonstrable Reasonableness

Companies cannot guarantee that no peso in a complex Mexican supply chain will ever reach a cartel-affiliated person. Prosecutors should not expect the impossible. They can expect companies to identify their risks, conduct reasonable diligence, monitor high-risk transactions, respond to warning signs, preserve relevant communications, and improve controls when new information emerges.

That is the pressure created by the Scoular resolution. Companies must be able to demonstrate that they made a serious, documented, and risk-based effort to prevent their operations from benefiting criminal organizations. The compliance burden is moving from a narrow inquiry into government-facing intermediaries toward a broader examination of the entire supply chain ecosystem.

Actions for CCOs

CCOs should consider five immediate steps:

  1. Expand Mexico-related risk assessments beyond traditional FCPA intermediaries.
  2. Map the complete supply chain, including subcontractors and transportation routes.
  3. Test customs-broker invoices and recurring border-related payments.
  4. Incorporate regional cartel intelligence and local employee knowledge into due diligence.
  5. Brief the board on the convergence of corruption, sanctions, organized crime, and national security risk.

The Scoular resolution does not establish that every company importing goods from Mexico is paying a cartel. It does put every such company on notice that the DOJ may ask what it did to make sure it was not. That is a significant change in compliance expectations. But look to your response to the UFLPA and see if you can find guidance from that compliance issue. Regardless, companies need to respond accordingly.

Categories
FCPA Compliance Report

FCPA Compliance Report: Matt Ellis on Cartels, FTO Risk, and Corporate Compliance in Latin America

In this episode, Tom Fox welcomes Matt Ellis of Miller & Chevalier about the ACI “Cartels, TCOs and Compliance in Latin America” forum (July 20–21, Washington, DC) and why cartel/TCO/FTO risk is a timely 2026 compliance priority.

Ellis describes the Trump administration’s focus on cartels, fentanyl, China’s influence, and the expanded enforcement toolkit—FCPA guidance linking to cartel activity, sanctions, AML actions (including FinCEN orders against Mexican financial institutions), and cartel FTO designations implicating the Anti-Terrorism Act. They discuss how cartels infiltrate supply chains, creating “material support” exposure, and why due diligence must go beyond traditional screening to on-the-ground intelligence and nuanced red flags. Ellis notes government interest in compliance expectations, extortion-payment considerations, the Lafarge/ISIS example, anticipated investigations, broader regional risk (Mexico, Venezuela, Colombia, Brazil), and increased multi-agency coordination and potential dialogue with U.S. authorities.

Key highlights:

  • Why This Conference Now
  • Due Diligence Goes Deeper
  • Extortion and Self-Reporting
  • Beyond Mexico Regional Risks
  • Whole-of-Government Focus
  • When to Engage Government

Resources:

Cartels, TCOs and Compliance in Latin America, July 20-21

Matt Ellis on LinkedIn

Tom Fox

Instagram

Facebook

YouTube

Twitter

LinkedIn

To learn about the intersection of Sherlock Holmes and the modern compliance professional, check out Tom’s latest book, The Game is Afoot-What Sherlock Holmes Teaches About Risk, Ethics and Investigations on Amazon.com.

Categories
From the Editor's Desk

From the Editor’s Desk: Aaron Nicodemus Reflections on March and April in Compliance Week

In this episode of From the Editor’s Desk, Tom Fox sits down with Aaron Nicodemus for a lively and insightful look back at the biggest compliance stories from March, while also previewing the trends, enforcement issues, and events set to shape April. They also begin the countdown to the 2026 Compliance Week National Conference in May.

Tom and Aaron break down the fast-moving, policy-driven shifts in U.S. sanctions on Venezuela, Iran, and Russia, and explore how companies are balancing business opportunities with escalating geopolitical and compliance risks amid a volatile oil market. They spotlight Compliance Week’s feature on illegal mining, unpacking its deep connections to financial crime, corruption, and supply chain exposure. The conversation also examines a notable March FCPA declination under the DOJ’s new Corporate Enforcement Policy, focusing on what it signals about voluntary self-disclosure, remediation, cooperation credit, and the Department’s continued emphasis on prosecuting individuals. Along the way, they consider possible aggravating factors, including payments tied to designated criminal or terrorist groups, and what these developments may mean for the future of cross-border enforcement cooperation.

Looking ahead, Tom and Aaron preview the 2026 Compliance Week National Conference, taking place May 6–8 in Washington, DC, including awards finalists, anticipated remarks from DOJ and SEC officials, and timely sessions on AI, whistleblowers, and emerging compliance challenges. They also highlight the conference’s expanded commitment to new voices and share an early look at the Third Party Risk Management & Supply Chain Summit, coming October 26–28 in Chicago.

 

 Resources:

Aaron Nicodemus on LinkedIn

Compliance Week

Categories
2 Gurus Talk Compliance

2 Gurus Talk Compliance – Episode 71 – The Dog Bite Edition

What happens when two top compliance commentators get together? They talk compliance, of course. Join Tom Fox and Kristy Grant-Hart in 2 Gurus Talk Compliance as they discuss the latest compliance issues in this week’s episode!

Stories this week include:

  • The Sony Hack and the consequences of a bad decision. (WSJ)
  • What CEOs are most worried about. (NYT)
  • The dog bite defense fails as a former coal executive is convicted of FCPA violations. (Law360)
  • A KPMG partner was fired for using AI to cheat on a test about AI. (FT)
  • What is compliance reconciliation? (FinTechGlobal)
  • Terrorists: What Is the Risk Landscape for Multinationals Operating in Mexico? – (Corporate Compliance Insights)
  • Messy Retaliation Allegations at Binance – (Radical Compliance)
  • The Many Risks of Mandating Employee AI Usage – (Radical Compliance)
  • Workers Are Afraid AI Will Take Their Jobs. They’re Missing the Bigger Danger – (WSJ)
  • BODYCAM: Florida man arrested after bizarre forklift and ATM joyride through streets – (CBS 12)

Resources:

Kristy Grant-Hart on LinkedIn

Prove Your Worth

Tom

Instagram

Facebook

YouTube

Twitter

LinkedIn

Categories
ACI FCPA Conference 2025

ACI-FCPA Conference Speaker Preview Series – Ricardo Wagner de Araujo on Potential Trouble in your (Latin American) Supply Chain

In this episode of the ACI-FCPA and Global Anti-Corruption Conference Speaker Podcasts series, Ricardo Wagner de Araujo discusses his panel at the event, “Managing New Risks in Latin America: A Look at the Biggest Ways Cartels/TCOs Are Infiltrating Businesses and Supply Chains, and How Companies Are Responding.”

Some of the issues the panel will discuss are:

    • The changing risks in Latin America.
    • How TCOs and cartels exploit 3rd party relationships.
    • Tips for adapting your compliance programs in Latin America.

I hope you can join me at the ACI–FCPA Conference. This year’s event will take place on December 3-4 at the Gaylord National Resort & Convention Center in National Harbor, Maryland, near Washington, D.C. The lineup of this year’s event is simply first-rate, featuring some of the top FCPA professionals, white-collar attorneys, and compliance practitioners in the field.

The 2025 program is being completely redesigned to help your organization stay agile, responsive, and ahead of the curve. Expect a dynamic agenda shaped by real-world priorities, practical takeaways, and the most cutting-edge thinking in compliance—led by a faculty of global practitioners with boots on the ground, encountering the very risks that come across your desk.

Please join me at the event. For information on the event, click here. Listeners of this podcast will receive a discount by using the code D10-999-CPN26.