Categories
FCPA Compliance Report

FCPA Compliance Report: Data Analytics in Compliance: Lessons from Scoular

In this episode, Tom Fox welcomes back Vince Walden, CEO of konaAI, which is the sponsor of this podcast series. Vince is well known for his leadership in data analytics, machine learning, and AI, and we take a deep dive into all of these topics through the lens of the Scoular FCPA Enforcement action.

The Scoular case is a unique learning tool for using data analytics, machine learning, and AI for compliance. In this matter, roughly 2,000 near-$2,000 payments were tied to customs brokerage activity. This case illustrates broader uses of data analytics beyond numbers, including mining unstructured text in invoice and payment-description fields (e.g., repeated terms like “re-inspection fee” and Spanish phrases) and linking it to structured AP data.

Walden explains how combining structured and unstructured data reduces investigator bias, how round-dollar and repetitive payments to high-risk vendors can be continuously risk scored using hundreds of tests, and how machine learning can “find more like this” across large transaction populations. We discuss integrating communications data when available, using monitoring within typical 30–60-day payment cycles to prevent payments, supporting self-disclosure decisions amid DOJ guidance, and launching a minimum viable analytics program by starting with AP spend, invoices, POs, and payments pulled from ERP systems.

Key highlights:

  • Structured vs. Unstructured Data
  • Red Flags Round Dollars
  • Text Mining and Three Lines
  • Transactional Fingerprints
  • Machine Learning for Compliance
  • Linking Comms and Payments
  • Prevention Through Monitoring
  • Continuous Improvement and ROI
  • Self-Disclosure and Culture Data
  • 90-Day Analytics Roadmap

Resources:

konaAI

Vince Walden on LinkedIn

Tom Fox

Instagram

Facebook

YouTube

Twitter

LinkedIn

To learn about the intersection of Sherlock Holmes and the modern compliance professional, check out Tom’s latest book, The Game is Afoot-What Sherlock Holmes Teaches About Risk, Ethics and Investigations on Amazon.com.

Categories
Blog

Scoular DPA Part 5: From Reinspection Fees to Executive Signatures: Final Lessons from Scoular

From Reinspection Fees to Executive Signatures: Final Lessons from Scoular

The Scoular Company FCPA enforcement action began with a deceptively simple fact pattern. Customs brokers allegedly paid Mexican officials approximately $2,000 per train so agricultural shipments could cross the border despite adverse inspection findings. The brokers invoiced the payments to Scoular as “reinspection fees.” That description, however, was only the first layer of the case.

Across this blog post series, Scoular Company became a study in third-party risk, internal controls, cartel exposure, off-channel communications, facilitating payments, data analytics, voluntary disclosure, remediation, DOJ oversight, and executive accountability. Each article examined one part of the control environment. Taken together, they tell a larger story about how bribery becomes normalized inside an operating process and what a company must do when that process fails.

The source distinction matters. I have now posted two series on the enforcement action. The first series relied on the DOJ Press Release, which announced the resolution and described the government’s allegations and conclusions. The second series relied on the formal Deferred Prosecution Agreement (DPA), in which Scoular admitted, accepted, and stipulated that the facts were true. The DPA did not merely add detail. It changed the evidentiary foundation of the analysis.

I.              Series One: Lessons From the DOJ Press Release

a.     A Small Payment Became an Enterprise Control Failure

The Press Release series began with the mechanics of the scheme. According to the DOJ announcement, the conduct ran from 2013 through 2019, involved more than $400,000 in bribes, and enabled Scoular to avoid more than $6.5 million in fees and costs. Scoular entered a three-year DPA and agreed to pay a $9,769,521 criminal penalty and $414,351 in forfeiture.

The compliance lesson was never the size of one payment. It was repetition. A recurring round-dollar charge, submitted by customs brokers, approved over six years, and recorded under a plausible description became part of the company’s operating model.

The phrase “reinspection fee” demonstrated why invoice controls must examine commercial substance. A three-way match can confirm that an invoice, purchase order, and approval agree. It cannot establish that the underlying service was legitimate. For a high-risk customs payment, the control must ask what government action occurred, who received the money, whether an official fee schedule supports the amount, and what happened to the shipment after payment.

This also exposed the limits of onboarding due diligence. Screening a broker and obtaining an anti-corruption certification are only the beginning. Effective third-party management connects onboarding to invoices, transaction monitoring, business outcomes, periodic review, audit rights, and termination decisions.

b.    Cartel Risk Expanded the Compliance Perimeter

The Press Release stated that a portion of the bribe payments ultimately benefited individuals associated with a cartel operating at the U.S.-Mexico border, although the DOJ said Scoular Company and its employees did not know of that connection.

In an episode of the FCPA Compliance Report,  Matt Ellis discussed a broader question. Traditional anti-corruption diligence focuses on government-facing intermediaries, ownership, political exposure, adverse media, and government relationships. Organized-crime connections may not appear in a corporate registry or screening database.

The lesson was not that every cross-border transaction benefits a cartel. It was that companies must understand the environment in which their money, goods, and third parties move. Customs brokers, trucking companies, warehouses, security providers, labor contractors, and subcontractors can create overlapping corruption, money-laundering, sanctions, trade, security, and organized-crime risks.

c.     WhatsApp Was Part of the Control Environment

The Press Release series also examined WhatsApp and other communications used to discuss shipments and payments. The critical point was not that employees selected an unapproved application. It was that the substantive business decision could occur in a private message while the formal system recorded only the resulting invoice. Ellis emphasized that enforcement priorities may change, but evidence does not. A WhatsApp message can establish knowledge, authorization, concealment, or control circumvention even without a standalone off-channel communications charge.

A defensible program must identify the applications employees actually use, define which business activities may occur there, preserve relevant records, address local privacy and employment law, and enforce violations consistently. The company must also be able to connect communications with payment records, inspection results, shipment identifiers, approval logs, and bank data.

Facilitation Payments Did Not Fit the Facts

The Press Release series then addressed why the payments were not protected as facilitating payments. The FCPA exception is narrow. It may cover a payment intended to expedite a routine, nondiscretionary governmental act that the company is already entitled to receive. Scheduling an inspection may be routine. Paying an official to disregard a failed inspection is not. The alleged Scoular payments did not change timing. They changed the outcome and enabled shipments to cross despite findings of dirt, soil, and other impurities.

Amount, urgency, local custom, invoice wording, and use of a third party do not create the exception. Nor does the exception authorize a false accounting entry. A company that permits facilitating payments must still confront local law, accurate books and records, approval controls, and the practical difficulty of asking employees to make a narrow legal distinction under commercial pressure.

II.   Lessons From the DPA and Admitted Facts

a.     The DPA Showed How the Scheme Became Normal

The DPA blog post series began by distinguishing allegations in the Press Release from facts Scoular Company admitted. The Statement of Facts showed that stricter Mexican inspections created operational pressure (IE., more or new/different risks) in 2013. A broker proposed a fee on every train and promised that Scoular Company would “not have a single risk of adverse determinations.” The proposal was discussed at Scoular Company’s Kansas office and then replicated through additional brokers and border crossings.

The communications removed ambiguity. Employees discussed soil findings, special payments, trains released after inspections, and situations in which “normal procedures are not working.” By 2018, a communication referred to offering officials more than was normally given. These facts showed normalization. The scheme was not simply a broker’s unauthorized act. It became a repeatable process linking operational pressure, management knowledge, third parties, communications, invoices, approvals, and favorable business outcomes.

b.    Stopping the Conduct Was Not Self-Disclosure

The DPA disclosed that internal reports emerged in 2019 and Scoular Company changed its practices and ended direct engagement with the brokers. Yet the company did not receive voluntary self-disclosure credit because it did not voluntarily and timely report the conduct. The DPA does not reveal the company’s internal debate so that speculation would be inappropriate. It does establish a governance lesson. An internal report starts two clocks: the investigation clock and the disclosure-decision clock. Stopping the conduct is remediation. It is not a substitute for a documented, timely decision about disclosure.

Scoular later received cooperation and remediation credit, including a 25 percent reduction from the bottom of the applicable Sentencing Guidelines range. That outcome demonstrates that missing voluntary-disclosure credit does not make later cooperation irrelevant. It also demonstrates that the two forms of credit are not interchangeable.

c.     Executive Signatures Became the Final Control

The DPA’s attachments translated compliance expectations into personal executive responsibility. They required compliance access to the board, adequate authority and resources, incentives and discipline, third-party business-rationale documentation, verification of services, reasonable compensation, data access, root-cause analysis, and remediation.

They also required two distinct certifications. The CEO and CFO must certify disclosure obligations. The CEO and Chief Legal Officer must certify the truth and completeness of DOJ reports and the design of the anti-corruption compliance program. The certification language references potential exposure under 18 U.S.C. §§ 1001 and 1519 for materially false statements or records.

The signature is therefore not ceremonial. It requires an evidence chain from front-line controls through management testing to board oversight.

d.    Data Analytics Connects Both Series

Vince Walden’s analysis supplied the final detection lesson. No single anomaly proves bribery. The stronger signal is a sequence: an adverse inspection, an unusual recurring broker payment, and a favorable shipment release.

The words “reinspection fee” were searchable. The approximately $2,000 round-dollar amount was testable. The brokers, routes, inspection outcomes, timing, and releases were linkable. Communications could then provide context. Analytics should rank anomalies for human investigation, not declare guilt by algorithm.

This is where internal controls become dynamic. The company should test transaction text, payment amounts, vendor concentration, duplicate descriptions, approval patterns, inspection results, clearance timing, and user access together. Every substantiated alert should improve the next rule, risk model, training decision, and control test.

e.     Compliance Takeaways

  1. Treat the process as the risk unit. Review the third party, payment, message, inspection, route, approval, accounting entry, and business outcome together.
  2. Test substance, not labels. Require evidence of the service performed, the lawful basis for the fee, the recipient, the calculation, and the official result.
  3. Expand third-party risk beyond corruption screening. Integrate organized-crime, sanctions, anti-money-laundering, trade, security, and supply-chain intelligence where the risk profile requires it.
  4. Govern communications as business records. Know which channels employees use, restrict substantive approvals to controlled systems, preserve records, and test retrieval before an investigation.
  5. Create a disclosure decision protocol. Define who evaluates material facts, what information is needed, when senior management and the board are briefed, and how the decision is documented.
  6. Use analytics to connect events. Build monitoring around sequences and outcomes, then route alerts to trained investigators with access to operational, financial, and communications data.
  7. Make certifications evidence-based. Executive signers and boards should demand documented control testing, root-cause analysis, remediation status, and unresolved exceptions before signing.

The final lesson from Scoular Company is that bribery rarely sits in one control. It moves through an operating system. An effective compliance program must see that system, test it continuously, and ensure that the people who oversee it can stand behind the evidence.

Categories
Blog

The Scoular DPA Part 3: The Data Was Talking – Data Analytics and the Scoular Bribery Scheme

The Scoular Company bribery scheme was hidden, but it was not invisible. For six years, customs brokers paid Mexican officials approximately $2,000 per train so Scoular Company shipments could cross the border despite adverse inspections. The brokers invoiced the payments back to Scoular as “reinspection fees.” In total, Scoular Company admitted that it authorized $414,351 in bribes and avoided approximately $6.5 million in fees and costs. Those facts describe an FCPA violation. They also describe a data pattern.

I had the opportunity to visit with Vince Walden, CEO of KonaAI, about the Scoular Company FCPA enforcement action from a data analytics perspective. He identified the feature that should command every CCO’s attention: people concealing misconduct often record it consistently. They may avoid the word “bribe,” but they still need a repeatable description that allows the payment to be processed, reconciled, and found again. At Scoular Company, that description was “reinspection fee.”

Walden’s observation goes to the heart of modern compliance. Illegal conduct may be concealed from the compliance department while remaining visible in accounts payable, journal entries, invoices, purchase orders, shipment records, and communications. The control failure occurs when those systems hold the evidence, but the company never asks the data the right questions.

Consistency Can Become the Fraudster’s Fingerprint

Walden observed that accountants value consistency because consistent classifications support accurate reporting. Fraudsters and their enablers can exploit the same discipline. A bookkeeper cannot label a payment “bribe expense.” The payment still needs a code, description, vendor, amount, approver, account, and business purpose. If the scheme continues, the participants need a method they can repeat. That repetition creates a fingerprint.

Suspicious terms in payment descriptions and journal entries are among the most useful anti-corruption monitoring tests. His examples included phrases such as “friend fee,” “government payment,” and “miscellaneous.” The precise word will vary by company and geography. The analytical principle does not.

The company should identify unusual language, then connect it to the transaction behind it. Even if the language is not unusual, its repeated use might form a pattern worth exploring. A word cloud may provide a useful visual starting point. Keyword searches, natural-language processing, and risk dictionaries can scale the review across thousands of invoices and expense reports. Yet the purpose is not to find one forbidden word. It is to identify language that is unusual for the business, unusually frequent for one vendor, or correlated with a high-risk outcome. “Reinspection fee” was facially plausible. Repetition changed its meaning.

The First Test Was Hiding in Plain Sight

An elementary analytic (As in Elementary, my dear Watson) would have grouped customs-related payments by invoice description, vendor, amount, port, and frequency. That test could have asked:

  • How often does “reinspection fee” appear?
  • Which brokers submit the charge?
  • Is the amount repeatedly near $2,000?
  • Which employees approve it?
  • Does it appear only on trains with an inspection problem?
  • What happens to the shipment immediately after payment?

No single answer proves bribery. Together, the answers can create a compelling reason to investigate. The recurring round-dollar amount matters. Legitimate inspection costs often vary with the service, product, weight, time, port, or government fee schedule. A repeated $2,000 charge across multiple transactions may indicate a fixed unofficial tariff rather than the cost of a legitimate service.

The description also matters. If “reinspection fee” was not found in an approved government schedule, lacked official documentation, or appeared only in broker invoices rather than government receipts, the control should have required escalation before payment. Finally, the outcome matters most. If trains that failed inspection were consistently released after the fee, the company had more than an accounting anomaly. It had a payment linked to a favorable exercise of government discretion.

Connect the Payment to the Business Outcome

Traditional controls often examine whether an invoice matches a purchase order and whether an authorized employee approved it. A bribery scheme can satisfy both tests when employees are participating in the misconduct.

Data analytics must therefore test commercial substance, not merely procedural completion.

For Scoular Company, the decisive data model would connect five sources:

  • Inspection data: date, result, impurity identified, inspector, agency, and reinspection history.
  • Shipment data: train identifier, product, port, broker, delay, release time, and disposition.
  • Payment data: invoice description, amount, general-ledger account, supporting documents, approver, and payment date.
  • Third-party data: broker risk rating, contract terms, bank account, audit rights, ownership, and compensation history.
  • Communications data: relevant emails, WhatsApp records lawfully available to the company, and other business messages.

With those sources joined, compliance could test whether a $2,000 broker charge followed an adverse inspection and then by rapid release of the train. It could compare release rates for shipments with and without the payment. It could identify which brokers, ports, and employees produced unusually favorable clearance outcomes. That sequence is the analytic signature of the scheme: failed inspection, unusual payment, successful release.

Build a Layered Anti-Bribery Analytics Program

A mature program should not depend on one keyword or one dashboard. It should use several complementary tests.

Text analytics. Search invoice narratives, journal entries, purchase orders, and expense descriptions for high-risk terms, euphemisms, spelling variants, and unusual phrases. The risk dictionary should reflect the company’s markets and evolve with investigations.

Transaction analytics. Flag recurring round-dollar payments, duplicate or near-duplicate invoices, payments just below approval thresholds, split payments, weekend postings, manual journal entries, and charges lacking official receipts.

Vendor analytics. Compare customs brokers by fee frequency, payment descriptions, clearance rate, failed-inspection rate, use of subcontractors, changes in bank accounts, and concentration under particular employees or business units.

Outcome analytics. Test whether payments are statistically associated with permits, inspections, releases, tax outcomes, contract awards, or other favorable government actions. This moves the review from what the invoice says to what the payment accomplished.

Sequence analytics. Measure the time between an adverse event, a payment request, approval, payment, and favorable resolution. Short, repeated intervals can reveal a designed process.

Communications analytics. Where lawful and consistent with company policy, match high-risk transactions to messages about urgency, guarantees, officials, inspections, exceptions, or payments. A suspicious invoice can corroborate a message, and a message can explain the invoice.

Network analytics. Map relationships among employees, brokers, bank accounts, ports, approvers, and government touchpoints. Shared bank accounts, common addresses, unusual subcontractors, or recurring approval chains can expose concealed connections.

These tests should create ranked alerts, not automated accusations. Analytics identifies anomalies. Trained reviewers determine whether the transaction has a legitimate explanation, requires more evidence, or warrants an investigation.

Continuous Monitoring Is a Governance Choice

Walden’s closing advice was simple: keep innovating and keep running the analytics. The word “running” matters. As in continuously. A one-time review performed after a subpoena is forensic reconstruction. A risk-based test operating monthly, weekly, or at the point of payment is a compliance control.

Continuous monitoring does not mean surveillance of every employee or review of every transaction. It means that known high-risk processes receive repeatable testing at a frequency aligned with the risk. Customs payments, government-facing third parties, failed inspections, and manual financial entries deserve more attention than ordinary low-risk purchases.

The program also needs governance. Compliance and internal audit should agree on data ownership, alert thresholds, reviewer responsibilities, escalation standards, documentation, privacy requirements, and feedback loops. Finance must help validate legitimate payment patterns. The business must explain operational outcomes. Technology must maintain data quality and access. Legal must ensure that communications monitoring is lawful.

Most importantly, the board should ask whether compliance has direct access to the data. A dashboard built from incomplete information can create false assurance. If broker invoices sit in one system, inspection results in another, shipment releases in a third, and WhatsApp messages outside company retention, the organization sees fragments while the scheme operates across the seams.

Internal Controls Must Learn From Every Alert

Data analytics is not a substitute for internal controls. They supplement each other, as data analytics is a way to test whether those controls work and where they fail. An alert concerning a reinspection fee should trigger questions about official documentation, approved fee schedules, broker contracts, audit rights, segregation of duties, approval thresholds, and the economic rationale for the charge. If the review confirms misconduct, root-cause analysis should determine why the payment passed through accounts payable, why the broker remained active, why inspections and payment data were not connected, and whether incentives rewarded shipment clearance over compliance.

Every closed alert should improve the system. Confirmed concerns should add new keywords, vendor attributes, transaction patterns, and outcome measures. Legitimate transactions should help refine thresholds and reduce noise. This is how a compliance program becomes adaptive rather than static.

Questions for CCOs

CCOs should ask:

  • Which payment descriptions recur in our highest-risk government-facing processes?
  • Can we connect invoices to inspections, permits, customs outcomes, and shipment releases?
  • Which third parties generate unusually favorable results after unusual payments?
  • Are alert reviewers trained to investigate commercial substance, not merely paperwork?
  • How quickly does a confirmed issue change our controls and analytics?

The Bottom Line

Scoular Company’s bribery scheme did not require a sophisticated algorithm to detect. It required the company to notice a repeated phrase, a recurring amount, a high-risk broker, an adverse inspection, and a favorable government outcome. Walden’s lesson is that concealment often creates consistency, and consistency creates data. The task of compliance is to convert that data into a question early enough to matter.

Follow the words. Test the amount. Connect the outcome. Then channel your inner Sherlock Holmes and investigate what the pattern is telling you.

Categories
Blog

AI, Compliance, and the Missing “Why”: Highlights from the Compliance Week AI Conference

If there was one clear message coming out of Compliance Week’s January 2026 AI conference, The Leading Edge: Applying AI and Data Analytics in E&C, it was not about tools, vendors, or futuristic promises. It was about discipline. More specifically, it was about something compliance professionals have preached for decades and are now being pressured to skip: the “why.”

In a recent episode of the podcast From the Editor’s Desk, I sat down with Compliance Week Editor in Chief Aaron Nicodemus to gather his reflections on the conference and its implications for compliance leaders. What emerged was not a story about artificial intelligence replacing compliance, but about AI exposing weaknesses in how organizations make decisions, manage pressure from the top, and integrate ethics into innovation. For compliance professionals, the discussion was a reminder that AI is not a technology problem. It is a governance problem.

The Step Everyone Is Skipping: Why Before What

One of the most striking takeaways from the conference came from Jen Gennai, former AI Ethics and Compliance Advisor at Google. Her message was deceptively simple: companies are skipping the “why.” Organizations are rushing to implement AI tools without first articulating what problem they are trying to solve or why AI is the appropriate solution. Instead of defining the use case and then selecting the right tool, teams are buying technology first and hoping value emerges later.

For compliance professionals, this should sound uncomfortably familiar. Risk management, third-party due diligence, investigations; every mature compliance process begins with a defined purpose. There is a reason the first step in the third-party risk management process is the Business Rationale. This is the ‘why’, requiring a business sponsor to explain why your organization needs a new or different business partner. Yet when AI enters the picture, that discipline often evaporates. The result is experimentation without accountability and pilots without strategy.

The irony is that compliance already knows how to do this. The failure is not a lack of knowledge; it is pressure.

Tone at the Top, Revisited: Pressure Without Direction

According to a recent Compliance Week and konaAI study released at the conference, more than 60 percent of compliance officers feel pressure from the board or C-suite to “use AI.” Not to use it in a specific way. Not to achieve a defined outcome. To use it. This top-down mandate creates a new kind of compliance risk. When leadership demands adoption without guidance, teams feel compelled to move quickly, sometimes cutting corners they would never cut in other risk domains.

This is not inherently nefarious. Boards are doing what they believe is necessary to keep their organizations competitive. But pressure without clarity creates the conditions for poor governance. Compliance leaders must recognize this moment not as a threat, but as an opening. Because when leadership says “use AI,” compliance has an opportunity to respond with structure: identify manual pain points, define defensible use cases, and align AI deployment with existing policies and ethical standards. The mandate may be broad, but the implementation can and should be deliberate.

Humans in the Loop: Why Oversight Is Not Optional

Another recurring theme from the conference was the danger of letting AI evaluate AI. Scaling tools without human oversight compounds error. One flawed assumption becomes many. Bias multiplies. Outputs drift. The lesson here is not anti-technology; it is pro-governance. AI works best when humans remain embedded throughout the lifecycle: selecting tools, defining scope, reviewing outputs, and deciding whether the system is working at all.

This aligns squarely with long-standing compliance principles. Judgment-heavy decisions, investigations, escalations, and remediations must remain human. Attempting to automate them introduces fairness and defensibility risks that no compliance program can explain away after the fact. AI should accelerate compliance work, not absolve responsibility for it.

Trust and Integrity: The Core Compliance Tension with AI

The most profound tension discussed at the conference was philosophical. Compliance programs are built on trust and integrity. AI, by contrast, is often perceived as opaque, untrustworthy, and occasionally wrong. This creates a credibility problem.

Why would a compliance function that spends years telling employees to act ethically, verify sources, and question assumptions deploy a tool that fabricates answers or cannot explain its reasoning? If compliance cannot articulate why an AI system aligns with the organization’s ethical standards, it should not be deployed, no matter how efficient it appears to be. Trust is not just about outputs. It extends to inputs, data quality, and understanding how systems interact with information. AI amplifies what it is given. Bad data does not improve through automation; it spreads faster.

Iteration Over Perfection: Learning Is Part of the Process

A healthy counterpoint emerged as well: AI is not a one-shot deployment. It requires iteration. Early failures are not proof that AI does not work; they are evidence that learning has begun. Several speakers emphasized that AI improves through feedback. Teams must be willing to correct it, teach it, and refine its outputs over time. Compliance professionals who abandon tools after one or two imperfect attempts misunderstand how the technology functions.

That said, iteration does not excuse carelessness. Learning must occur within guardrails: governance frameworks, usage boundaries, and documentation matter more, not less, when tools evolve.

Compliance as Value Creator, Not Speed Bump

One of the most encouraging insights from the conference was how AI is reshaping compliance’s role inside organizations. When compliance is involved early, before tools are rolled out, it becomes a partner in innovation rather than an obstacle.

Nicodemus pointed out companies like Robinhood, and Hemma Lomax, Deputy General Counsel, Vice President, and Head of Business Integrity at DocuSign, illustrated this point clearly. Compliance teams that embed themselves in product development and operational change help shape tools that work within ethical and regulatory boundaries from the start. That credibility compounds.

Lomax noted that at DocuSign, she and her compliance teams have gone further, creating AI agents that perform defined tasks continuously, with built-in ethical guardrails. When these tools are handed to new users, the hard questions have already been answered. This is how compliance becomes a competitive advantage; not by saying no, but by helping the business say yes safely.

No Experts, Only Practitioners

Another refreshing theme from the conference was humility. No one claimed to be an AI expert. Especially not in compliance. That matters. When technologies move quickly, false certainty is dangerous. Compliance professionals should not be intimidated by those who claim mastery. Instead, they should lean into their strengths: skepticism, documentation, and principled decision-making. AI does not require omniscience. It requires informed judgment.

The Vibe Shift: From Fear to Engagement

Perhaps the most telling insight came not from the stage, but from the hallways. Compared to earlier events, the mood around AI has shifted. Compliance professionals are no longer crossing their arms in resistance. They recognize the benefits and risks and want to engage. No one believes AI will disappear. The debate is no longer whether to use it, but how. Some organizations will lean in aggressively. Others will move cautiously. All will need compliance to guide those choices. The most effective analogy offered was this: AI is like a very confident intern. Smart. Fast. Occasionally wrong. Useful, but never in charge.

Conclusion: AI Is a Compliance Opportunity, If Compliance Leads

The Compliance Week AI conference made one thing clear: AI is not undermining compliance. It is testing it. Programs that lack clarity, governance, or confidence will struggle. Programs that know who they are, what they stand for, and how they make decisions will thrive. For compliance professionals, the question is not whether AI belongs at the table. It already sits there. The real question is whether compliance will claim its seat, not as a roadblock, but as the function that ensures innovation aligns with integrity. That is not a burden. It is an opportunity.

Categories
ACI FCPA Conference 2025

ACI Post Conference Reflections: Vince Walden on AI and Data Analytics in Anti-Corruption Compliance

By special arrangement with ACI, I was able to record several participants, speakers, panelists, and moderators from the recently concluded ACI FCPA and Global Anti-Corruption Conference held at the Gaylord near Washington, DC. This podcast details the guest’s experience at the event. In the first of our series, I visit with Vince Walden, President of konaAI, a Covasant company.

Walden provides a detailed recap of the pre-conference workshop, which was focused on AI and Data Analytics for anti-corruption compliance. Key sessions discussed include best practices for data collection and cleansing, the journey of AI implementation, and leveraging machine learning for compliance. Walden highlights the importance of viewing data analytics as a continuous business process rather than a project and wraps up with discussions on AI governance and ethical use. The episode concludes with Walden sharing his experiences and reflections on the successful event.

Key highlights:

  • Keynote Speakers and Highlights
  • Data Integrity and Validation
  • AI Implementation Journeys
  • Crash and Learn: Lessons from Failures
  • Advanced AI Techniques and Tools
  • Generative AI and Practical Demonstrations
  • AI Governance and Ethical Use
Categories
ACI FCPA Conference 2025

ACI-FCPA Conference Speaker Preview Series – Bryan Judice on Next Gen Tools for Next Gen Risks

In this episode of the ACI-FCPA and Global Anti-Corruption Conference Speaker Podcasts series, Bryan Judice discusses his presentation at ACI’s Forum on AI and Data Analytics for Anti-Corruption Compliance, which will be held on Tuesday, December 2.

Some of the issues the panel will discuss are:

  • Agentic AI tools for fraud risk management;
  • The increased importance of data analytics in fraud prevention.
  • Cutting-edge AI strategies for fraud risk management into 2026 and beyond.

I hope you can join me at the ACI–FCPA Conference. This year’s event will take place on December 3-4 at the Gaylord National Resort & Convention Center in National Harbor, Maryland, near Washington, D.C. The lineup of this year’s event is simply first-rate, featuring some of the top FCPA professionals, white-collar attorneys, and compliance practitioners in the field.

The 2025 program is being completely redesigned to help your organization stay agile, responsive, and ahead of the curve. Expect a dynamic agenda shaped by real-world priorities, practical takeaways, and the most cutting-edge thinking in compliance—led by a faculty of global practitioners with boots on the ground, encountering the very risks that come across your desk.

Please join me at the event. For information on the event, click here. Listeners of this podcast will receive a discount by using the code D10-999-CPN26.

Categories
ACI FCPA Conference 2025

ACI-FCPA Conference Speaker Preview Series – Vince Walden on the Cutting Edge Use of Agentic AI for Compliance

In this episode of the ACI-FCPA and Global Anti-Corruption Conference Speaker Podcasts series, Vince Walden discusses his presentation at ACI’s Forum on AI and Data Analytics for Anti-Corruption Compliance, which will be held on Tuesday, December 2.

Some of the issues the panel will discuss are:

  • Agentic AI strategies for compliance;
  • The increased importance of data analytics in fraud prevention.
  • Cutting-edge AI strategies into 2026 and beyond.

I hope you can join me at the ACI–FCPA Conference. This year’s event will take place on December 3-4 at the Gaylord National Resort & Convention Center in National Harbor, Maryland, near Washington, D.C. The lineup of this year’s event is simply first-rate, featuring some of the top FCPA professionals, white-collar attorneys, and compliance practitioners in the field.

The 2025 program is being completely redesigned to help your organization stay agile, responsive, and ahead of the curve. Expect a dynamic agenda shaped by real-world priorities, practical takeaways, and the most cutting-edge thinking in compliance—led by a faculty of global practitioners with boots on the ground, encountering the very risks that come across your desk.

Please join me at the event. For information on the event, click here. Listeners of this podcast will receive a discount by using the code D10-999-CPN26.

Categories
Blog

Reimagining Compliance: What Happens When Every Risk Has an AI Assistant?

In the not-so-distant past, corporate compliance programs relied on checklists, policies, and manual monitoring. The work was often reactive, responding to investigations, answering hotline calls, or conducting after-the-fact audits. But a quiet revolution is underway, and it’s reshaping how compliance teams operate. At the forefront of that change is konaAI’s “Agent Persona Development” framework, an AI-first approach that builds digital compliance assistants to manage and integrate every aspect of the compliance function. (Full disclosure-I do consulting work with KonaAI.)

Think of it as a digital compliance department. Yet one that specialized in AI “agents’ power,” each designed for a specific compliance function: investigations, vendor risk, sales monitoring, hotline activity, culture analytics, and policy management. Together, they do not simply automate tasks. These agents collaborate, connect, and learn from each other to create a dynamic, adaptive compliance ecosystem.

From Silos to Systems: A Unified Compliance Architecture

Every compliance officer knows the pain of siloed data. Investigations live in one platform. Vendor risk data lives in another. Hotlines in yet another. The result? Compliance professionals spend more time assembling the puzzle than interpreting its meaning.

The agentic compliance model solves this problem by connecting all data sources into a single, coordinated team. Each agent, here named Stan, Linda, Sonny, Raquel, Penny, Eva, and Lohitha, specializes in a domain but operates as part of an integrated system. The connective tissue between them is data intelligence and coordination.

Imagine Stan, your Investigations Assistant, flagging a conflict-of-interest case that ties to a vendor relationship. That information is instantly shared with Linda, your Vendor Risk Assistant, who analyzes the vendor’s compliance history, transaction monitoring data, and third-party risk profile. Meanwhile, Raquel, the Hotline Assistant, tracks if related reports have surfaced through the speak-up channel. The result of all this? A holistic view of compliance risk is automated, cross-referenced, and proactive.

Stan: The Investigations Assistant

Stan embodies what every compliance investigator aspires to be. An intelligent aide who never sleeps, forgets, or misses a data point. Stan integrates internal and external data sources, including company policies and investigation databases, with the DOJ’s 2024 ECCP, ACFE materials, and COSO’s Fraud Risk Management Guide.

Ask Stan a question, such as, “Show me all open investigations that may create FCPA exposure.” From this, he provides a risk-ranked summary that includes historical parallels, policy context, and regulatory benchmarks. He can even prepare a work plan aligned with your company policy and external best practices from the DOJ or ACFE. Stan does not simply collect data; he contextualizes it. He helps compliance officers investigate smarter, not harder.

Linda: The Vendor Risk Assistant

Third-party risk remains one of the most persistent challenges in compliance. Linda, your Vendor Risk Assistant, takes this problem head-on. Her expertise spans due diligence, pre-approvals, contract compliance, and ongoing transaction monitoring. She integrates with internal vendor systems, third-party management databases, and external compliance resources to assess exposure in real-time.

The beauty of Linda’s design lies in its adaptability. She tailors due diligence workflows by vendor type, whether a distributor, reseller, or agent, and ensures that every onboarding process meets both regulatory and internal standards. For compliance officers, this means never again wondering if a new vendor slipped through without being properly screened. With Linda, every vendor relationship becomes traceable, accountable, and continuously monitored.

Sonny: The Salesforce Monitoring Assistant

Compliance risks do not only lurk in third parties; they also reside within the sales process. That is where Sonny, the Salesforce Monitoring Assistant, enters. Sonny watches for anomalous discounts, returns, or contract terms that deviate from policy or suggest improper inducements. He can correlate sales behavior with AML data, customer risk ratings, or unusual payment timing, flagging red flags before they turn into violations. In industries where sales velocity can outpace oversight, Sonny acts as a digital compliance co-pilot, ensuring every deal passes the smell test.

Raquel: The Hotline Monitoring Assistant

Your hotline is only as strong as your ability to interpret what comes through it. Enter Raquel, your Hotline Monitoring Assistant. She provides real-time visibility into speak-up data, tracking status updates, response times, and patterns in report types. She can identify trends, such as an uptick in retaliation claims or conflicts-of-interest reports in a specific region, and alert compliance to investigate systemic issues. Raquel not only manages data; she transforms it into insight. She makes the hotline an accurate intelligence tool rather than a reactive mechanism.

Eva: The Policy and Compliance Assistant

Every compliance team fields the same daily questions: Can I accept this gift?Do I need pre-approval for this travel?Is this vendor on the restricted list? Eva, the Policy and Compliance Assistant, is responsible for addressing these inquiries. She utilizes generative AI to interpret company policies and provide real-time guidance tailored to role, geography, and transaction context. In essence, Eva decentralizes compliance expertise, making every employee a click away from the right decision. For global organizations, she’s a force multiplier for consistency and confidence.

Penny: The Culture and Survey Assistant

Culture remains one of the most elusive compliance metrics, until now. Penny, the Culture and Survey Assistant, turns employee feedback and social sentiment into measurable insights. She monitors survey results, internal communications, and social media signals to identify cultural trends and shifts in sentiment. Penny can even draft company social posts aligned with tone and messaging history, supporting transparent internal communication strategies. For Chief Compliance Officers, Penny provides what was once impossible: a real-time view of organizational ethics and morale.

Lohitha: The Data Insights and Coordination Assistant

Finally, Lohitha is the bridge that unites the entire agentic team. Her job is to break down data silos and cross-reference insights across all assistants. She identifies hidden correlations, such as the relationship between vendor risk issues flagged by Linda, policy exceptions logged by Eva, and hotline reports tracked by Raquel. Her analytics uncover patterns no human team could process in time. For compliance leaders, Lohitha’s coordination represents the holy grail: turning fragmented data into a unified risk narrative.

The Compliance Function of the Future: Agentic, Integrated, and Ethical

What does all this mean for the modern compliance professional? It means the days of reactive compliance are coming to an end. The agentic model transforms compliance from a back-office function into a strategic command center, powered by automation, analytics, and cross-functional insight.

It also raises the bar for governance. With such power comes a responsibility to ensure transparency, fairness, and accountability in the use of AI. Compliance must now govern the very tools that help it govern others. In short, the compliance officer of tomorrow will be both an ethicist and an engineer.

A Compliance Team That Never Sleeps

Imagine logging into your compliance dashboard tomorrow morning.

  • Stan has summarized last week’s investigations and flagged new DOJ-relevant trends.
  • Linda has updated your third-party risk heat map.
  • Sonny has identified unusual discount patterns in the Asia-Pacific region.
  • Raquel has summarized the hotline activity.
  • Eva has answered 300 employee policy queries in a single overnight shift.
  • Penny has mapped sentiment drops in one division.
  • And Lohitha has tied it all together into one narrative for your following board report.

This is not a compliance dream; rather, it is the next generation of AI-empowered governance. By adopting this model, compliance not only keeps up with change, but it leads it.

Final Thoughts

The Agent Persona Development model reimagines what those teammates can look like. Each persona represents a fusion of domain expertise, automation, and human insight working together to create a compliance program that is intelligent, scalable, and truly integrated. The bottom line has always been that compliance is not about checking boxes. It is about operationalizing compliance into business excellence. And with the right AI teammates, excellence is now within reach 24/7.

Categories
FCPA Compliance Report

FCPA Compliance Report – Vince Walden on Leveraging AI and Machine Learning for Fraud Detection

Welcome to the award-winning FCPA Compliance Report, the longest-running podcast in compliance. In this episode, Tom Fox welcomes back Vince Walden, CEO of konaAI, a Covasant company.

In this podcast, they take a deep dive into the UK’s Failure to Prevent Reporting (FTPR) offense, particularly in the context of vendor interactions and employee-third-party relations. Walden advocates for the implementation of robust compliance and fraud risk management programs, leveraging AI and machine learning to detect high-risk transactions and enhance business efficiency. He also highlights the global relevance of regulations like the UK Economic Crime and Corporate Transparency Act, stressing the necessity of robust fraud prevention measures to ensure compliance in a rapidly evolving legal landscape.

Key highlights:

  • Addressing Various Fraud Offenses Under ECCTA
  • Effective Fraud Prevention Procedures for Compliance Programs
  • Enhancing Fraud Risk Analysis in Financial Processes
  • Enhancing Fraud Detection Through Risk Assessment

Resources:

Vince Walden on LinkedIn

konaAI, a Covasant company

Click here for konaAI White Paper Rethinking Compliance: Practical Steps for Adapting to the UK’s New Fraud Legislation

Tom Fox

Instagram

Facebook

YouTube

Twitter

LinkedIn

For more information on the use of AI in Compliance programs, my new book, Upping Your Game. You can purchase a copy of the book on Amazon.com

Categories
Data Driven Compliance

Data Driven Compliance – Understanding the ECCTA and Its Impact on Fraud Prevention with Vince Walden

Welcome to Season 2 of the award-winning Data Driven Compliance. In this new season, we will look at the new Failure to Prevent Fraud offense. Join host Tom Fox as we explore this new law and how to comply with it through the lens of data driven compliance. This podcast is sponsored by konaAI. In this episode of Season 2, Tom Fox is joined by Vince Walden, CEO of konaAI.

In this episode, they take a deep dive into the details of the UK Economic Corporate Crime Transparency Act, specifically the ‘Failure to Prevent Fraud’ offense. Walden, bringing the perspective of a fraud examiner and CPA, discusses the types of fraud covered under the new law and its broad scope, affecting not just UK companies but also US subsidiaries of UK companies. Walden emphasizes the importance of fraud prevention compliance programs and outlines how effective data analytics and risk assessments can help companies prevent fraud. He also explores the integration of advanced technologies like AI in building robust fraud detection mechanisms. The conversation highlights that effective compliance leads to better business processes and profitability.

Key highlights:

  • Understanding Fraud Offenses Under the Act
  • The Broad Scope of the Act
  • Importance of Compliance Programs
  • Data Analytics in Fraud Risk Management
  • Future of Fraud Detection with AI

Resources:

Vince Walden on LinkedIn

konaAI, a Covasant company

Click here for konaAI White Paper Rethinking Compliance: Practical Steps for Adapting to the UK’s New Fraud Legislation

Connect with Tom Fox on LinkedIn