Categories
Blog

Connected Compliance: Part 2 – From Risk Register to Risk Radar

An effective compliance program is not a collection of disconnected policies, training modules, hotline reports, and investigation files. It is an operating system. Culture determines whether employees will use it. Risk assessment tells the organization where it must adapt. Investigations test whether the system responds credibly. Whistleblower programs reveal whether employees trust it enough to speak. Blog 1 examined communication as the control that connects those elements. In this Part 2, we examine what compliance must do with the intelligence that communication produces.

The traditional risk assessment was built for a world that moved more slowly. Compliance gathered a group of leaders, reviewed enforcement trends, scored familiar risks, produced a heat map, and returned to the exercise the following year. That process still has value, but it is no longer enough.

Today, a new market restriction, customer demand, artificial intelligence deployment, supply-chain disruption, sanctions measure, or data rule can alter the company’s risk profile before the annual plan is approved. The central question is therefore not whether the organization has a risk register. It is whether compliance has a risk radar that can detect change, decide what matters, assign ownership, and translate the signal into action.

Every Compliance Risk Has a Political Dimension

Compliance obligations do not develop in a vacuum. They reflect choices made by governments about national security, trade, technology, labor, privacy, corruption, competition, and corporate accountability. For a multinational company, those choices may conflict, overlap, or change with little notice. Particularly in this political age, the single most-used byword is volatility.

That makes geopolitical awareness a compliance capability. It does not require the CCO to become a foreign-policy analyst. It requires the compliance function to understand how political priorities can become legal obligations, enforcement pressure, customer expectations, or operational constraints. Export controls can reshape product access. Sanctions can alter payment and counterparty risk. Forced-labor requirements can reach deep into a supply chain. AI rules can change how a business collects data, develops products, and makes decisions.

The practical lesson is that legal change is often the last stage in a longer policy development process. Compliance should monitor the earlier signals: legislative proposals, agency speeches, enforcement patterns, trade measures, customer questions, supplier difficulties, and operational workarounds. These indicators do not all demand a program change, but they should enter a disciplined triage process.

What the DOJ Is Really Asking

The Department of Justice has made dynamic risk assessment part of the effectiveness inquiry. The 2024 Evaluation of Corporate Compliance Programs (ECCP) directs prosecutors to consider “emerging risks as internal and external circumstances impacting the company’s risk profile evolve.” This risk profile can change due to factors outside a company’s control or its own business decisions. Moreover, the ECCP language moves risk assessment beyond a scheduled document and into continuous management.

DOJ then asks: “Is the company’s approach to risk management proactive or reactive?” The distinction is critical. A reactive program updates controls after a failure, enforcement action, or audit finding. A proactive program uses operational information across functions to identify change before misconduct occurs. The ECCP also asks whether periodic review is merely a point-in-time exercise or draws on continuing access to operational data, and whether the results lead to updates in policies, procedures, and controls.

The enforcement question is not whether the company predicted every development. No program can. The question is whether the company had a reasonable process for identifying material changes, directing resources to higher-risk areas, documenting its decisions, and revising the program over time.

Build the Risk Radar From Multiple Signals

A dynamic risk process begins with a wider field of vision. Regulatory alerts and outside counsel updates are useful, but they show only part of the environment. Some of the earliest warnings come from inside the business. Sales may see unusual customer demands in a new market. Procurement may find suppliers unable to provide origin information. Finance may identify payment routes that no longer fit the expected transaction. Information security may discover employees using unapproved AI tools. Human resources may raise concerns about retaliation or pressure related to performance targets. Audit may identify recurring exceptions. Hotline reports and investigations may reveal a pattern that a heat map missed.

Compliance should bring these signals together through a repeatable cadence. A quarterly cross-functional review can examine changes in the business model, geography, products, third parties, technology, enforcement, and employee concerns. High-velocity risks may require monthly or event-driven review. The objective is not to create another committee. It is to establish a reliable place where weak signals are compared, challenged, and assigned.

Or simply look at the changes wrought by the Trump Administration in 2026 alone. Venezuela is now open for business. How about the Democratic Republic of Congo? See here and here. Of course there is Iran, but you have to ask what week it is and are we doing business with Iran or are we at war with Iran.

Give One Person the Clock

Emerging risks often fall between organizational boxes. Legal understands the rule. Compliance sees the control issue. Operations owns the process. Procurement controls the supplier relationship. Technology owns the system. To use a well-worn maxim, if everyone is in charge, no one is in charge. In the corporate world, when everyone is generally responsible, no one is specifically accountable. This is both why and where compliance needs to step up its game.

Every material risk needs a named owner with the authority to convene the necessary functions, set deadlines, escalate disagreements, and report on the disposition. That person does not perform every task. The owner keeps the clock, maintains the decision record, and ensures that the issue does not disappear between meetings.

Governance should also define escalation triggers. A credible framework identifies which developments require immediate executive attention, which can be handled through a working group, and which should remain under observation. Without thresholds, organizations either under-escalate material risk or flood leadership with undeveloped issues.

Use a Two-Speed Assessment

Not every signal requires an enterprise-wide risk assessment. Compliance needs two speeds. The first is rapid triage. A small group of subject-matter experts identifies the potential legal obligation, affected operations, time horizon, severity, available data, current controls, and immediate containment needs. This is where AI can play a key role in compliance, essentially superforecasting risks to enable quick, efficient risk management strategies when volatility hits. Additionally, such an approach may lead to a decision to monitor, take interim action, or launch a deeper review.

The second is formal assessment. Complex or high-impact risks may require structured interviews, data analysis, control testing, external counsel, forensic support, or scenario planning. The deeper process should be proportionate to the exposure, not triggered simply because the issue is new. This two-speed model protects agility without sacrificing rigor. It also creates evidence that the company made a reasoned decision. A short written triage record can show what information was considered, who participated, why the company chose its response, and when the issue will be reviewed again.

Convert Assessment Into Real Controls

The most common failure is not the inability to identify risk. It is the failure to convert assessment into a viable risk management strategy and then to implement, monitor, and improve your business operations. A new questionnaire, certification, or policy may create documentation, but documentation alone does not mitigate the underlying exposure.

Consider third-party risk. A supplier questionnaire can identify missing information, but the control lies in what happens next: enhanced diligence, contractual protection, source verification, payment restrictions, audit rights, monitoring, remediation, or a decision not to proceed. The same principle applies to AI. An AI-use policy matters, but effective governance also requires an inventory of use cases, approval gates, data controls, human oversight, testing, monitoring, and accountability.

Each response should identify the control objective, owner, implementation date, evidence, and testing method. Compliance should also ask what existing control can be adapted before building a separate program. Strong governance, escalation, training, data access, and investigation processes are reusable infrastructure across risk domains.

Resource allocation is part of that conversion. If a changing risk profile calls for deeper third-party monitoring, faster export review, or additional AI oversight, the organization must decide what people, technology, and budget will support the response. Compliance cannot claim to be risk-based when yesterday’s priorities continue to dictate today’s resources. The allocation decision, including any accepted constraint, should be visible and documented.

Treat Change Management as a Control

A technically correct response can still fail if employees do not understand it or the business cannot implement it. New requirements frequently collide with established incentives, systems, customer commitments, and local practice. Change management should therefore be part of the control design. Explain why the risk changed. Identify which decisions and workflows are affected. Train the employees and gatekeepers who must act differently. Provide a practical escalation route. Test understanding. Gather feedback. Then revise the process when implementation exposes friction or unintended consequences. For a full discussion of change management as a compliance control, listen to the podcast Ronnie Feldman and I did with Caveni Wong on this episode of Creativity and Compliance.

This is where blog post 1’s communication discipline comes into play. Compliance cannot adapt to risk through broadcast messages alone. It needs a two-way channel that tells employees what changed and tells compliance whether the response works in practice.

Measure Adaptation, Not Activity

The number of risk meetings or completed assessments says little about effectiveness. Better measures test whether the organization moves from signal to decision and from decision to control. Useful indicators include the time required to triage a material development, percentage of actions with named owners and deadlines, overdue remediation, control implementation and testing results, repeat exceptions, unresolved ownership disputes, and lessons incorporated from investigations.

Compliance should also examine whether resources shifted when risk shifted. A program that identifies a higher risk but leaves staffing, monitoring, and controls unchanged has produced analysis without management. The result should be a closed loop: detect, assess, assign, mitigate, test, and learn. That loop turns risk assessment from an annual artifact into a management process.

That transition is where program credibility is tested. Join us tomorrow as we consider how organizations scope investigations, preserve independence, establish consistency, document decisions, and convert findings into remediation. A dynamic risk process helps the company see the signal. A credible investigation determines what happened and what the organization must do next.

Bonus Questions for Compliance Professionals

  1. Which internal and external signals can change the company’s risk profile between formal assessments?
  2. Who has specific ownership for emerging risks that cross legal, compliance, operations, procurement, finance, and technology?
  3. What criteria determine whether an issue is monitored, triaged, escalated, or formally assessed?
  4. Can the company show how a recent risk assessment changed a policy, control, resource allocation, or business decision?
  5. Do substantive mitigation and ongoing monitoring support questionnaires and certifications?
  6. How quickly can the organization move from a weak signal to a documented decision?
  7. What recent investigation finding should change the current risk assessment?
Categories
Blog

The $2,000 Question: Why Scoular’s Bribes Were Not Facilitation Payment

We continue our exploration of the Scoular FCPA enforcement action. We are still awaiting the DPA and Criminal Information, so the details of the case are based on the Department of Justice (DOJ) Press Release. Today we take up a topic little commented on anymore, but this enforcement action provides an opportunity to discuss, review, and explore facilitation payments.

The phrase “facilitation payment” is one of the most dangerous phrases in anti-corruption compliance. It sounds technical. It sounds modest. It can make an improper payment appear to be a recognized cost of moving goods through a difficult market. When a customs broker says that a small payment is necessary to get a train across the border, the business may hear urgency, local custom, and operational necessity.

The Foreign Corrupt Practices Act hears a different question: Was the official merely being paid to perform a routine act that the company was already entitled to receive, or was the payment intended to change the official’s decision and secure an improper business advantage? That distinction resolves the issue in The Scoular Company enforcement action.

According to the Department of Justice, Mexican inspections found dirt, soil, and other impurities in Scoular shipments. Scoular employees then directed customs brokers to pay Mexican officials approximately $2,000 per train so the shipments would cross the border despite those findings. The brokers invoiced the payments back to Scoular as “reinspection fees.” The alleged payments did not accelerate a routine action. They changed the result of an inspection. That is why the facilitation payments exception does not apply.

The Exception Is Narrow by Design

The original 1977 FCPA excluded payments for duties that were essentially ministerial or clerical. Congress revised the statute in 1988 and defined the modern exception for facilitating or expediting payments made to secure the performance of “routine governmental action.”

The statute gives examples:

  • Obtaining permits, licenses, or other official documents needed to do business
  • Processing government papers such as visas and work orders
  • Providing police protection or mail service
  • Scheduling inspections connected with contract performance or the transit of goods
  • Providing telephone, power, or water service
  • Loading and unloading cargo
  • Protecting perishable products from deterioration

The list can mislead a hurried business employee. Inspections and cargo appear in the statute. Scoular involved inspections and cargo. That superficial similarity is not enough. Congress expressly excluded decisions about awarding new business or continuing business with a particular party. The core principle is that routine governmental action does not include discretionary decisions that are the functional equivalent of obtaining or retaining business or securing an improper advantage. The exception is about speeding up the official’s performance of an existing duty. It is not about purchasing a favorable decision.

What a Facilitation Payment Is

A true facilitation payment has four characteristics.

  1. Routine. The governmental act is routine. The official performs it in the ordinary and customary manner. The act does not require a substantive judgment about whether the company has met a legal or regulatory standard.
  2. Entitled. The payer is already entitled to the action. The official has no lawful basis to deny the service. The payment changes timing, not entitlement.
  3. No Discretion. The official exercises no meaningful discretion. The official may control the pace of processing, but not the substantive outcome.
  4. Intent. The purpose is to expedite performance. It is not to influence an official to ignore a violation, reverse an adverse decision, waive a requirement, or confer a competitive advantage.

Consider the difference between scheduling an inspection and passing one. A small payment to move an inspection request from an ignored pile into the ordinary scheduling process may fall within the statutory language, subject to all the other legal and policy risks. A payment to persuade the inspector to overlook contamination does not. The first payment seeks action. The second purchases an outcome.

What a Facilitation Payment Is Not

A facilitation payment is not defined by amount. The FCPA contains no safe harbor for $20, $200, or $2,000. A small bribe remains a bribe when its purpose is to influence discretion. It is not defined by local custom. “Everyone pays it” is evidence of a risk of corruption, not a legal defense. It is not defined by urgency. Perishable goods, demurrage, customer demands, and production interruptions can create enormous pressure. Commercial pressure does not convert a discretionary government decision into a ministerial act.

The name on the invoice does not define it. “Reinspection fee,” “expediting charge,” “special handling,” and “administrative support” are descriptions. Compliance must determine what the money was actually used for. It is not created because a third party made the payment. The FCPA reaches indirect payments and authorizations through agents. A customs broker cannot manufacture an exception that the principal could not claim directly. Finally, it is not a blanket authorization for customs payments. Customs functions combine routine processing with significant official discretion. Scheduling an inspection may be routine. Deciding that contaminated goods can enter the country is not.

Apply the test to Scoular

The DOJ’s allegations make the application straightforward.

The shipments had failed a substantive condition

Mexican law subjected the agricultural shipments to inspection for dirt, soil, and other impurities. According to the DOJ, inspections found those conditions. The company was therefore not waiting for an official to perform a duty it had already satisfied. It faced an adverse regulatory result.

The payments changed the outcome

The brokers allegedly paid officials to ensure that the trains crossed despite the inspection findings. That is the exercise of official discretion. The payments were not made merely to schedule or complete a reinspection. They allegedly caused officials to permit entry notwithstanding the problem.

The company obtained a substantial business benefit

The DOJ said Scoular authorized more than $400,000 in bribes and avoided more than $6.5 million in fees and costs. The benefit was not faster paperwork alone. It was the avoidance of consequences associated with shipments that did not satisfy inspection requirements. That economic reality matters. A payment that yields more than $16 in avoided costs per dollar spent looks less like clerical acceleration and more like a mechanism for obtaining an improper advantage.

The conduct was repeated and organized

The scheme allegedly continued from 2013 through 2019 and involved multiple customs brokers. Scoular employees directed the payments, discussed them via WhatsApp and other channels, and paid the brokers’ reimbursement invoices.

In my podcast with Matt Ellis of Miller & Chevalier, Ellis addressed repeated payments in the related context of extortion. He explained that one or two emergency payments may present a different analysis, but a chain of payments over time makes reliance on a defense far more difficult. Extortion and facilitation payments are distinct legal doctrines. Still, Ellis’s practical point applies with full force here. Repetition changes the compliance story. A recurring payment is not an emergency response. It becomes part of the operating model.

The invoices did not call the payments what they were

The brokers allegedly invoiced the bribes as reinspection fees. Even a payment that qualifies for the narrow anti-bribery exception must be accurately reflected in an issuer’s books and records. The exception is not permission to conceal the true nature of an expenditure. This creates a central compliance paradox. Employees may resist recording a “facilitation payment to customs official” because the description raises legal, ethical, and local-law concerns. They may then use a vague or misleading account description, creating separate books and records and internal control risks. The invoice label in Scoular did not solve the problem. It became evidence of it.

Do Not Confuse Facilitation With Extortion

Companies must also distinguish the facilitation-payments exception from an extortion or duress analysis. A facilitation payment concerns the nature of the governmental action. Was it routine and nondiscretionary? Extortion concerns coercion. Was an individual facing a genuine threat to life, health, safety, or liberty? Ordinary economic pressure, such as delay costs or lost business, generally does not carry the same significance as a threat of physical harm.

Ellis stressed that companies confronting cartel and extortion risks should examine whether an event is isolated, whether alternative routes or providers exist, what remediation was undertaken, and whether management changed the conditions that allowed the payments to continue. His broader advice was that a company must be able to tell a credible story of reasonable measures and operational adjustment. Scoular’s alleged six-year payment pattern is difficult to reconcile with that story. The operational response was not to stop, reroute, escalate, or remediate. It was allegedly to reimburse the brokers and continue moving trains.

The Accounting Provisions Remain

Another recurring error is to assume that an anti-bribery exception eliminates all FCPA risk. It does not. The FCPA’s accounting provisions require issuers to keep books and records that accurately and fairly reflect transactions and to maintain adequate internal accounting controls. A payment may fall outside the anti-bribery prohibition and still create liability if it is mischaracterized, hidden in a miscellaneous account, or made through controls that do not provide reasonable assurance of proper authorization and recording. The DOJ FCPA Resource Guide 2nd edition explains these requirements and the government’s narrow approach to the exception.

That is why a company policy that allows facilitation payments creates operational difficulties. Employees must make fine legal distinctions under pressure, document a payment that may violate local law, obtain appropriate approval, and record the transaction transparently. Many companies reasonably prohibit facilitation payments altogether. The legal exception is so narrow, and the collateral risks so substantial, that a global ban is often easier to explain, control, and test.

A Better Customs Control

When a broker describes a payment as a facilitation payment, compliance should treat the statement as the starting point for the inquiry.

The company should ask:

  1. What exact government action is requested?
  2. Is the company already legally entitled to that action?
  3. Does the official have discretion over the outcome?
  4. Has an inspection, permit, or application already produced an adverse result?
  5. Will the payment change only timing, or will it change the result?
  6. Is the amount supported by a published fee schedule and an official receipt?
  7. Who will receive the money?
  8. Is the payment lawful under local law and permitted by company policy?
  9. How will it be recorded in the books?
  10. Has the same broker, port, product, or payment description appeared before?

If the business cannot answer those questions before payment, it should not rely on the exception.

Questions for CCOs and the Final Lesson

CCOs should ask whether employees understand the difference between scheduling an inspection and buying a successful inspection. They should test customs invoices for recurring round-dollar charges, match fees to official documents, and review whether brokers produce unusually favorable outcomes after special payments.

The Scoular lesson is simple. A payment does not become permissible because it is small, customary, urgent, or routed through a broker. It qualifies for the FCPA’s narrow exception only when it expedites a routine, nondiscretionary action that the company is already entitled to receive. Scoular’s alleged payments did something very different. They caused officials to allow shipments across the border despite failed inspections, avoided millions of dollars in costs, and were disguised as reinspection fees.

That was not facilitation. It was the business purpose of the bribery scheme.

Categories
Blog

What Scoular Teaches About Off-Channel Communications, Investigations, and Compliance Program Effectiveness

WhatsApp was not a footnote in The Scoular Company FCPA resolution. It was part of the operating system of the alleged bribery scheme. According to the Department of Justice Press Release (we are still waiting on the DPA and Criminal Information), Scoular Company employees communicated about shipments and bribes through WhatsApp and other means. Today I want to explore the issue of off-channel communication and what it means for your compliance program.

The compliance lesson is not simply that Scoular Company employees used WhatsApp. It is that an informal communications channel became embedded in a high-risk business process involving customs officials, third-party brokers, payment approvals, and financial records. Once that happens, messaging governance is no longer an information technology issue. It is an anti-corruption control.

Off-Channel Became the Business Channel

The phrase “off-channel” can be misleading. If employees regularly use WhatsApp to authorize payments, direct third parties, and solve customs problems, the application is not outside the business. It is where the business is being conducted. That distinction matters.

A company may have excellent controls inside its enterprise resource planning system. It may require purchase orders, segregation of duties, invoice matching, and documented approvals. Those controls can be bypassed if the substantive decision is made in a private chat and the formal system merely records the result. At Scoular Company, the reinspection invoice was one side of the control failure. The WhatsApp discussion was the other one.

The invoice gave the payment a facially legitimate description. The messaging channel allegedly supplied the knowledge, direction, and authorization behind it. Compliance teams should test both sides together. A recurring round-dollar customs charge becomes more significant when matched to a message asking a broker to get a train released. A failed inspection becomes more significant when followed by an off-channel approval and immediate border clearance. Communications analytics and transaction analytics should not operate as separate disciplines.

Enforcement Priorities Can Change. Evidence Does Not.

In my podcast with Matteson Ellis, Member and Latin America Practice Lead at Miller & Chevalier, we addressed the shift in federal enforcement attention surrounding off-channel communications. Ellis made the more durable point: even when a regulator changes its emphasis, WhatsApp messages remain evidence of knowledge, intent, authorization, concealment, and circumvention of control.

Ellis observed that the DOJ press release suggests Scoular’s internal investigation obtained access to relevant WhatsApp communications. That access was important because retrieving such data can be difficult, particularly when employees use personal devices, local privacy law limits review, or messages have not been retained. His conclusion should command the attention of every CCO. The off-channel issue may have become quieter, but the Scoular resolution can be read as bringing it back to the center of corporate investigations. A prosecutor does not need a standalone recordkeeping case to use a WhatsApp message as proof of an FCPA violation.

The 2024 ECCP Provides the Road Map

The DOJ’s 2024 Evaluation of Corporate Compliance Programs (ECCP) does not demand a single technology solution. It asks whether the company’s approach is reasonable for its business needs and risk profile. That is the correct standard because messaging use varies by country, function, and commercial reality. The ECCP organizes the inquiry around three practical areas:

  • Communication channels. What electronic channels do employees actually use? How does use vary by jurisdiction and business function? What retention and deletion settings apply, and why did the company permit them?
  • Policy environment. Can the company preserve communications when devices are replaced? What do privacy, security, employment, and bring-your-own-device rules permit? Can the company review business messages on personal devices, and are employees required to transfer business records into company systems?
  • Risk management. Has the company ever exercised its access rights? What happens when an employee refuses access or violates the policy? Has messaging use impaired an investigation or the company’s response to prosecutors?

These are effectiveness questions. A written prohibition will not satisfy them if the business routinely ignores it, managers approve transactions in private chats, and the company cannot retrieve the records when misconduct surfaces.

A Defensible Program Starts With Commercial Reality

Ellis explained that an outright WhatsApp ban may not be practical in Latin America, where the application is widely used for business. A policy that conflicts with how employees, customers, and third parties actually work may drive communications further underground. The better approach is to define what may occur on the platform.

Ellis suggested limiting WhatsApp to logistical and administrative communications while keeping substantive commercial transactions and approvals inside controlled systems. That distinction is particularly important for customs payments, discounts, government interactions, third-party instructions, and exceptions to standard procedures.

A defensible framework should include the following controls:

  • Map actual use: Survey high-risk functions and jurisdictions to determine which applications, devices, disappearing-message settings, and informal groups employees use.
  • Classify communications: Separate low-risk logistics from approvals, commitments, payment decisions, government interactions, and other substantive business records.
  • Build technical access: Use company-managed devices or approved enterprise integrations where appropriate so business communications can be retained, searched, placed on legal hold, and produced.
  • Address local law: Analyze privacy, employment, consent, monitoring, and data-transfer requirements before an investigation begins. The access right must be lawful and operational.
  • Create preservation protocols: Define what occurs when an employee changes devices, leaves the company, becomes subject to a legal hold, or refuses access to business communications.
  • Enforce the rules: Test compliance, investigate violations, apply consequences consistently, and examine whether supervisors tolerated or encouraged off-channel approvals.

Investigations Must Be Ready Before the Message Disappears

Off-channel governance is tested in the first hours of an investigation. The company must identify relevant custodians, devices, applications, group chats, backup settings, linked desktops, and cloud accounts. It must issue a preservation notice that employees understand and implement. It must also determine whether consent, works council consultation, or another local-law step is required before collecting data.

The investigative team should not examine messaging data in isolation. It should connect communications to:

  • Accounts-payable records
  • Customs broker invoices
  • Inspection results
  • Shipment identifiers
  • Clearance times
  • Approval logs
  • Bank data

This is where Scoular Company FCPA enforcement action becomes a model for a broader control lesson. The message can explain the invoice, and the invoice can corroborate the message. Ellis emphasized the value of having protocols ready before access is needed. That is critical. Negotiating employee consent, locating backups, and determining ownership of a device after a subpoena or whistleblower allegation arrives is not a defensible strategy. It is a delay, and delay can destroy evidence and cooperation.

Boards Should Treat Messaging as a Governance Risk

Boards do not need to select the retention platform or approve device settings. They do need assurance that management understands how high-risk business is actually conducted and can preserve the evidence required to investigate misconduct. The board should receive more than confirmation that a policy exists. It should receive information on:

  • Policy exceptions
  • Control testing
  • Employee violations
  • Disciplinary outcomes
  • Collection failures
  • Investigation delays
  • High-risk jurisdictions and functions

For companies operating across the U.S.-Mexico border, customs, logistics, sales, procurement, and government-facing teams deserve particular attention. This is an oversight issue. If management cannot retrieve communications involving payments to government-facing third parties, the company may be unable to determine what occurred, identify responsible individuals, remediate the control failure, or cooperate effectively with prosecutors.

Questions for CCOs

  1. Which messaging platforms do employees and third parties actually use in our highest-risk markets?
  2. Can an employee approve a customs payment, direct a broker, or authorize an exception through WhatsApp?
  3. Can we lawfully and promptly preserve and retrieve business messages from company and personal devices?
  4. Have we tested those capabilities through a mock investigation or legal hold?
  5. Do transaction-monitoring reviews incorporate relevant messaging evidence when an anomaly is escalated?
  6. Have we disciplined employees and supervisors for circumventing approved channels?

The Bottom Line

Scoular Company did not become an off-channel communications case because employees happened to use WhatsApp. WhatsApp mattered because employees allegedly used it to facilitate and discuss a bribery scheme that operated through customs brokers and disguised invoices for six years. That is the compliance lesson. The channel, the payment, the third party, and the business outcome must be viewed as one control environment.

Companies should not ask whether WhatsApp is good or bad. They should ask whether the communications occurring there are permitted, preserved, accessible, monitored on a risk basis, and connected to the company’s formal approval and financial systems. If the company cannot answer those questions, its most important business records may be sitting on the device it controls least.

Categories
Blog

Scoular’s $10 Million FCPA Resolution: When a “Re-inspection Fee” Becomes a Bribe

A $2,000 payment can look insignificant inside a global supply chain. Repeated train by train, approved by employees, routed through customs brokers, disguised on invoices, and paid for six years, it becomes something else entirely. For The Scoular Company, it became a Foreign Corrupt Practices Act enforcement action carrying more than $10 million in penalties and forfeiture, a three-year deferred prosecution agreement, continuing cooperation obligations, and periodic reporting to the Department of Justice.

The case is an important warning for every company engaged in cross-border trade. Customs brokers are not merely logistics providers. Border payments are not merely operational expenses. A mislabeled invoice is not merely an accounting problem. Each may represent an interconnected risk across anti-corruption, internal control, third-party, and national security.

The Scheme: $2,000 per Train

According to the DOJ Press Release (the full DPA is not yet available), between 2013 and 2019, Scoular used customs brokers to move shipments of corn and other agricultural products from the United States to Mexico. Mexican authorities inspected those shipments for dirt, soil, and other impurities. When inspectors identified problems, Scoular’s customs brokers allegedly paid Mexican officials approximately $2,000 per train to ensure that the shipments crossed the border.

The brokers then invoiced those payments back to Scoular as “reinspection fees.” Scoular paid the invoices. This was not an isolated facilitation payment or a rogue third party operating beyond the company’s knowledge. According to the court documents, Scoular employees authorized the payments, directed the brokers, and communicated about the shipments and bribes through WhatsApp and other channels.

The numbers demonstrate the business impact:

  • More than $400,000 in bribes authorized
  • More than $6.5 million in avoided fees and costs
  • A $9,769,521 criminal penalty
  • $414,351 in forfeiture
  • A three-year DPA

The company was charged with conspiracy to violate the FCPA’s anti-bribery provisions.

The Invoice Description Was a Compliance Red Flag

The phrase “reinspection fee” should be at the center of every compliance discussion about this case. The brokers did not invoice Scoular for bribes. They used a description that appeared facially connected to a legitimate customs process. That description allowed the payments to move through the company’s financial system.

This is how corruption frequently enters the books and records. It appears as:

  • Expediting fees
  • Administrative charges
  • Local processing costs
  • Customs support
  • Special handling
  • Reinspection fees
  • Consulting services

The compliance question is not whether the description sounds legitimate. The question is whether the company can establish what service was performed, who performed it, why the payment was necessary, how the amount was calculated, and who ultimately received the money. Accounts payable controls that merely match an invoice to a purchase order will not detect this type of scheme. Effective controls must examine the commercial substance of high-risk payments.

For customs-related expenses, companies should require supporting government documentation, published fee schedules, proof of service, payment to an authorized government account where appropriate, and enhanced approval for unusual or recurring charges.

Third-Party Due Diligence Is Only the Beginning

The Scoular resolution also demonstrates the limits of onboarding due diligence. A company can screen a customs broker, obtain certifications, execute an anti-corruption clause, and still face substantial FCPA exposure. The real question is what happens after the third party begins work. The answer is that the real work of compliance begins when the third-party contract is signed.

Customs brokers operate at the intersection of government interaction, time-sensitive business demands, discretionary enforcement, and local pressure. That makes them inherently high risk. An effective third-party management program should connect the following:

  • Initial due diligence
  • Contractual controls
  • Transaction monitoring
  • Invoice testing
  • Business justification
  • Periodic recertification
  • Audit rights
  • Compliance training
  • Offboarding decisions

The DOJ credited Scoular for strengthening risk-based screening and approval requirements, adding anti-corruption and audit-right provisions to contracts, and improving monitoring procedures. The company also eliminated customs brokers associated with the Mexican reinspection payments. Due diligence is not and cannot remain a static file. It must become a continuing control system tied to actual payments and operational conduct.

WhatsApp Was Part of the Business Process

Scoular employees allegedly communicated about the shipments and payments through WhatsApp and other channels. This fact should concern every CCO. When employees use personal devices or ephemeral messaging platforms to conduct high-risk business, the company may lose visibility into precisely the communications it most needs to monitor, preserve, and produce.

The answer is not necessarily to prohibit every messaging application. The answer is to establish a defensible governance model addressing the following:

  • Permitted communication platforms
  • Business-record retention
  • Preservation during investigations
  • Access to relevant communications
  • Training for high-risk employees
  • Monitoring based on legal and privacy requirements
  • Consequences for circumventing approved systems

A policy without technical controls, employee training, and consistent enforcement is unlikely to satisfy prosecutors. Messaging governance must reflect how employees actually conduct business.

Corruption Is Now a National Security Issue

The most significant feature of the case may be the DOJ’s treatment of cartel risk. The government determined that a portion of the bribe payments ultimately benefited individuals associated with a cartel operating at the U.S.-Mexico border. The DOJ stated that neither Scoular nor its employees knew about that connection. That lack of knowledge did not eliminate the seriousness of the issue.

Indeed, in the DOJ Press Release, U.S. Attorney Justin R. Simmons for the Western District of Texas was quoted as follows, “Nothing crosses into or out of Mexico without the approval and payment to Mexican drug cartels.” Further, any American businesses that engage in any cross-border trade bear a significant amount of responsibility to do so without benefitting those cartels and without threatening our national security.”

The enforcement message is clear: companies operating in high-risk border regions must consider where third-party payments may ultimately flow. A payment intended to resolve a customs problem can expose a party to corruption, money laundering, sanctions, organized crime, and national security risks. This means anti-corruption risk assessments can no longer operate in isolation. Compliance teams should integrate information from the following:

  • Anti-money laundering reviews
  • Sanctions screening
  • Security functions
  • Trade compliance
  • Supply chain risk management
  • Third-party intelligence
  • Government investigations
  • Adverse media monitoring

The government is examining the complete risk created by a payment, not merely the employee’s immediate objective.

No Voluntary Disclosure Credit, but Meaningful Cooperation Credit

Scoular did not receive voluntary self-disclosure credit because it did not promptly report the conduct to the DOJ Fraud Section. It did, however, receive credit for cooperation. The DOJ cited Scoular’s internal investigation, factual presentations, identification of individuals involved, document production, organization of evidence, and provision of counsel for current employees. The DOJ also acknowledged deficiencies during the early stages of the investigation.

After considering the company’s cooperation and remediation, the DOJ imposed a criminal penalty reflecting a 25 percent reduction from the bottom of the applicable sentencing guidelines range. This is a valuable lesson in enforcement mathematics. Missing the opportunity for voluntary disclosure does not make subsequent cooperation irrelevant. Companies can still improve outcomes through credible investigation, evidence preservation, individual accountability, timely remediation, and the organized production of information.

Yet cooperation credit is not the equivalent of voluntary disclosure credit. The decision window following discovery of potential misconduct remains critical.

Remediation Must Change the Operating Model

Scoular’s remediation went beyond issuing a new policy. According to the DOJ, the company:

  • Conducted an external compliance maturity assessment and anti-corruption risk assessment
  • Restructured its compliance function
  • Increased senior leadership oversight
  • Eliminated brokers connected to the payments
  • Strengthened risk-based monitoring through software tools
  • Revised its Code of Conduct and key compliance policies
  • Improved third-party screening and approvals
  • Added anti-corruption and audit-rights provisions
  • Revised financial controls for high-risk transactions
  • Delivered general and targeted anti-corruption training

This is the type of remediation contemplated by the DOJ’s Evaluation of Corporate Compliance Programs. It addresses root causes, resources, governance, controls, technology, training, and business ownership.

The key is operational impact. The company must be able to demonstrate that the same conduct could not pass through the organization today without being detected or escalated.

Questions for CCOs

CCOs should ask:

  • Do recurring payments cluster around specific ports, brokers, officials, products, or inspection events?
  • Are vague payment descriptions automatically escalated?
  • Does compliance have access to customs, logistics, and accounts payable data?
  • Are high-risk brokers periodically reviewed after onboarding?
  • Has the company tested whether audit rights can actually be exercised?
  • Is there a rapid escalation process for deciding whether potential misconduct should be voluntarily disclosed?

The Bottom Line

The Scoular case was not simply about customs brokers paying officials. It was about an operational process that allegedly normalized bribery, an invoicing system that disguised the payments, employees who communicated through informal channels, and third-party funds that ultimately touched cartel-linked actors.

For compliance professionals, the lesson is direct: follow the payment, test the business justification, examine the communication channel, and understand the complete risk ecosystem. A $2,000 “reinspection fee” may be small enough to escape executive attention. It is not small enough to escape the FCPA.

Categories
Blog

Cartels, TCOs, and Compliance in Latin America: Why 2026 Is a Watershed Moment

For compliance professionals, some years mark an evolution. Others mark a turning point. In 2026, corporate compliance in Latin America has reached that turning point. For the past two decades, most companies approached regional risk through a familiar lens: anti-corruption. The focus was on government touchpoints, customs interactions, licensing, permits, state-owned enterprises, and third-party intermediaries. That framework is still important. But it is no longer sufficient.

Today, the risk landscape has expanded dramatically. Cartels, transnational criminal organizations, foreign terrorist organization designations, sanctions, anti-money laundering exposure, and supply chain infiltration have all moved to the center of the compliance conversation. What was once a specialized concern has become a board-level issue.

That is why the upcoming ACI Forum on Cartels, TCOs, and Compliance in Latin America is so timely. It is also why compliance officers need to understand that this is not simply another enforcement trend. It is a structural change in how risk must be assessed, governed, and managed. I recently had the opportunity to visit with Matt Ellis, Member at Miller & Chevalier and co-Chair of the Forum. You can listen to Ellis’ remarks on this episode of the FCPA Compliance Report on the Compliance Podcast Network.

The New Risk Equation

The Trump administration has made clear that cartels, fentanyl trafficking, organized crime, and the influence of China in Latin America are policy priorities. That focus has brought multiple enforcement tools to bear, including sanctions, anti-money laundering authorities, FTO designations, and a broader integration of these issues into the compliance and enforcement landscape.

Ellis said that companies, the old model of regional compliance risk must be rethought. The issue is no longer limited to whether a payment was made to a foreign official. The question now is whether a company’s supply chain, transportation provider, security arrangement, or local commercial partner could create exposure under anti-terrorism, sanctions, or AML frameworks.

Mexico Is the Opening Chapter, Not the Whole Book

Much of the current focus is on Mexico, and for good reason. That is where the enforcement spotlight is currently brightest. But compliance professionals should not make the mistake of thinking this challenge begins and ends there.

The risks extend across Latin America, including Central America, Venezuela, Colombia, Brazil, Panama, and other markets where cartel activity, organized crime influence, sanctions risk, or opaque commercial structures may create significant exposure. Each country carries its own risk profile, but the common lesson is clear. Mexico may be the first chapter, but it will not be the last.

For boards and executive teams, that means regional strategy must be reviewed through a broader lens. Market entry, third-party engagement, logistics routes, security providers, and local partnerships all need to be reassessed.

Why the Supply Chain Has Become a Compliance Flashpoint

One of the most important lessons from this discussion is that cartel risk can be embedded in the supply chain. This is where compliance professionals need to recalibrate their thinking. In the anti-corruption world, companies typically focus on agents, distributors, customs brokers, and other third parties that have direct government interactions. In the cartel and TCO context, risk can be embedded within ordinary business operations. Transportation vendors, warehouse providers, local suppliers, labor relationships, and security services may all present hidden risk if they are controlled by, connected to, or exploited by organized crime.

That changes the role of compliance. Procurement, logistics, operations, and security can no longer be treated as peripheral functions. They are now front-line participants in risk identification and mitigation. This is where the compliance function must show leadership. The CCO must bring these disciplines together and translate legal and enforcement developments into practical operational controls.

Due Diligence Must Move Beyond Check-the-Box

If there is one message compliance professionals should take from Ellis’ podcast, it is this: traditional due diligence is not enough. In anti-corruption compliance, companies have become skilled at identifying common red flags. They know how to screen for politically exposed persons, government connections, unusual payment terms, and opaque ownership structures. Those tools still matter, but they will not always surface cartel-linked risk. Organized crime does not announce itself in a database hit.

Instead, companies need a more nuanced and operationally grounded approach. Are there local security concerns being raised by employees? Are there unusual labor dynamics in a region where those patterns do not make commercial sense? Is there persistent chatter about a vendor, route, or business partner that cannot be ignored? Are operations in a community producing concerns that legal and compliance have not fully explored? These are not traditional diligence questions, but they are increasingly the right ones.

Under the DOJ’s Evaluation of Corporate Compliance Programs (ECCP), regulators continue to ask whether a company’s program is designed, implemented, and tested in a manner that addresses actual risk. This is precisely where program effectiveness will now be measured in high-risk operations in Latin America.

The Importance of Listening to the People on the Ground

One of the most practical insights from the interview was the emphasis on local intelligence. Employees who live and work in these communities often know far more than any desktop diligence report will reveal.

That point should resonate deeply with compliance professionals. A company’s speak-up culture is not simply about hotline metrics or case closure rates. It is about whether employees trust the organization enough to raise concerns that may not yet fit into a neat legal category. It is about whether the company listens when local personnel say that something does not add up. This is where compliance, culture, and internal controls intersect.

If a company has not built mechanisms to capture and escalate local concerns, then it is not simply missing information. It is missing one of the most effective risk detection tools available to it. These are not abstract governance questions. They go directly to program effectiveness, risk ownership, and business sustainability.

A Whole-of-Government Enforcement Model

Another important takeaway is the multidimensional nature of this risk environment. In the FCPA era, companies often focused on the DOJ and the SEC. That framework no longer captures the full picture. Now the compliance professional must think across Treasury, OFAC, FinCEN, Homeland Security, DEA, and other agencies, all of which may be interested in the same underlying conduct. This level of coordination matters because it means the government’s expectations are no longer siloed. Enforcement, intelligence, sanctions, and AML concerns can converge quickly. For compliance officers, this demands a more integrated risk management model. Silos within the company will not work when the government itself operates in a coordinated manner.

Is There More Room for Government Engagement?

One of the more interesting themes from the discussion was whether companies may have more room to engage with the government than they traditionally would in the anti-corruption context. That does not mean every issue should be self-disclosed. It does mean that in high-risk environments, thoughtful engagement may sometimes be part of a sound compliance strategy.

The key is judgment. No company should rush into a conversation with the government without understanding the facts and the implications. But where risks are ambiguous, stakes are high, and the legal regimes overlap, strategic dialogue may help demonstrate good faith, show the absence of criminal intent, and allow a company to explain the reasonable steps it is taking. That is not leniency. That is credibility.

The Bottom Line

This is the next generation of Latin America compliance risk. It does not replace anti-corruption compliance. It expands it, hardens it, and operationalizes it. The lesson for compliance professionals is clear. You cannot address cartel and TCO risk with yesterday’s playbook. You need broader risk assessments, deeper third-party diligence, stronger local reporting channels, tighter cross-functional coordination, and more informed board oversight.

In 2026, the companies that succeed will not be the ones with the longest policy manuals. They will be the ones who can demonstrate a compliance program built for the reality of where they operate. For the CCO, that is the challenge. For the board, that is the oversight mandate. For the business, that is the cost of operating responsibly in a changed enforcement environment. The future of compliance in Latin America is already here. The only question is whether your program is ready for it.

Check out the ACI Forum on Cartels, TCOs, and Compliance in Latin America by clicking here. You can receive a 10% off the price by using the Discount Code D10-999-CPN26.

ACI is the sponsor of today’s blog.

Categories
FCPA Compliance Report

FCPA Compliance Report: Matt Ellis on Cartels, FTO Risk, and Corporate Compliance in Latin America

In this episode, Tom Fox welcomes Matt Ellis of Miller & Chevalier about the ACI “Cartels, TCOs and Compliance in Latin America” forum (July 20–21, Washington, DC) and why cartel/TCO/FTO risk is a timely 2026 compliance priority.

Ellis describes the Trump administration’s focus on cartels, fentanyl, China’s influence, and the expanded enforcement toolkit—FCPA guidance linking to cartel activity, sanctions, AML actions (including FinCEN orders against Mexican financial institutions), and cartel FTO designations implicating the Anti-Terrorism Act. They discuss how cartels infiltrate supply chains, creating “material support” exposure, and why due diligence must go beyond traditional screening to on-the-ground intelligence and nuanced red flags. Ellis notes government interest in compliance expectations, extortion-payment considerations, the Lafarge/ISIS example, anticipated investigations, broader regional risk (Mexico, Venezuela, Colombia, Brazil), and increased multi-agency coordination and potential dialogue with U.S. authorities.

Key highlights:

  • Why This Conference Now
  • Due Diligence Goes Deeper
  • Extortion and Self-Reporting
  • Beyond Mexico Regional Risks
  • Whole-of-Government Focus
  • When to Engage Government

Resources:

Cartels, TCOs and Compliance in Latin America, July 20-21

Matt Ellis on LinkedIn

Tom Fox

Instagram

Facebook

YouTube

Twitter

LinkedIn

To learn about the intersection of Sherlock Holmes and the modern compliance professional, check out Tom’s latest book, The Game is Afoot-What Sherlock Holmes Teaches About Risk, Ethics and Investigations on Amazon.com.

Categories
Blog

Returning to Venezuela: Why “Yes, If” Is the Only Defensible Compliance Answer

Most of you readers know that sometimes when I get going on a project, it (the project, not me) just keeps on growing. What started as a podcast with Matt Ellis on the risks of going back into Venezuela expanded out into a series of podcasts on the FCPA Compliance Report and with Mike DeBernardis on All Things Investigations. The podcasts led to a five-part blog post series on the same topic in the FCPA Compliance and Ethics Blog. I then needed to expand the blogs into a book and provide forms, checklists, frameworks, and deployment packs for compliance professionals to help them think through the issues presented in Venezuela and in other similarly high-risk jurisdictions.

All of that has led to the only book on how to return to Venezuela, Returning to Venezuela: The Compliance Guide to Yes, If (Title inspired by Mike DeBernardis). It is available in both print and eBook versions on Amazon.com.

When companies talk about returning to Venezuela, the conversation almost always begins with opportunity. Oil reserves. Market access. First-mover advantage. What the book Returning to Venezuela does is effectively reset that conversation where it belongs for compliance professionals: with reality. It is a disciplined, compliance-first analysis of what it actually means to operate in one of the world’s highest-risk jurisdictions.

The core message is uncompromising but straightforward: Venezuela is not a place for optimism, informal controls, or siloed compliance. It is a stress test. If your compliance program can function there, it can function anywhere. If it cannot, no license, policy, or assurance letter will save you. The book is not a warning label about Venezuela. It is a working manual for how a compliance function should assess risk, design controls, and govern decision-making before commercial momentum takes over.

Step One: Reframing the Risk Assessment

The first way a compliance professional should use Returning to Venezuela is to recalibrate how risk assessments are performed. Traditional country risk assessments often ask abstract questions: corruption perception scores, sanctions status, and enforcement history. Those inputs are necessary, but insufficient. Returning to Venezuela pushes compliance professionals to replace abstract scoring with operational mapping.

Instead of asking whether Venezuela is high risk, the framework asks:

  • Where will government discretion arise?
  • Where can delay be monetized?
  • Where does the business depend on intermediaries?
  • Where does value move, pause, or change form?

This is a critical shift. Risk is no longer treated as a country attribute. It becomes a process attribute. Compliance professionals can use Returning to Venezuela’s structure to redesign their risk assessment around real business steps: procurement, logistics, payment, security, licensing, and dispute resolution.

Step Two: Identifying Pressure Points Before They Become Incidents

Returning to Venezuela is especially useful in helping compliance professionals identify pressure points, not just risk categories. Pressure points are moments where the business is most likely to face demands for improper value, shortcuts, or exceptions. Procurement is one. Customs clearance is another. Security access, utilities, labor approvals, and payment routing are others.

Using Returning to Venezuela, compliance professionals can document:

  • Where pressure is expected;
  • Who owns the decision at that point?
  • What escalation looks like; and
  • When refusal or exit becomes mandatory.

This transforms compliance from a reactive role into a proactive role in designing decision architecture.

Step Three: Using the Checklists as Control Gates, Not Paper Artifacts

A common compliance failure is treating red flags as documentation exercises rather than control mechanisms. One of the strengths of Returning to Venezuela is that its red flags are designed as gates, not records. Each checklist answers a single question: Is this activity governable under our current assumptions?

Compliance professionals can deploy these checklists at defined moments:

  • Market entry discussions
  • Vendor and JV selection
  • Transaction structuring
  • Payment and banking design
  • Security and logistics planning

If a red flag cannot be cleared, the activity cannot proceed. That discipline is what makes the framework defensible. It also protects compliance officers personally, because decisions are anchored in documented governance rather than informal judgment.

Step Four: Integrating Risk Domains Instead of Managing Them in Silos

Another way compliance professionals should use Returning to Venezuela is as a blueprint for breaking down internal silos. The book makes clear that in Venezuela, corruption, export controls, AML, sanctions, security, and extortion are not separate risks. They are interconnected expressions of the same operating pressure. Treating them separately guarantees blind spots.

Practically, this means compliance can use the book to justify:

  • Integrated risk reviews instead of sequential sign-offs;
  • Shared escalation forums across functions;
  • Unified monitoring rather than separate dashboards; and
  • Common exit triggers across risk domains.

This is particularly important for AML. Returning to Venezuela positions money laundering risk not as a standalone compliance obligation, but as the capstone test of whether the entire framework works.

Step Five: Structuring Board Oversight Around Decisions, Not Updates

Too often, boards receive high-level compliance updates that provide comfort but not clarity. Returning to Venezuela gives compliance professionals a way to reframe board oversight around decisions, not reports. Using the board materials and decision templates, compliance can:

  • Force explicit risk acceptance;
  • Document assumptions that underpin approvals;
  • Secure delegated authority to pause or exit operations; and
  • Establish clear revisit and escalation triggers.

This protects both the organization and the compliance function. When conditions change, the discussion is no longer “Why did this happen? ” but “Which assumption failed, and what decision does that trigger? ” That is governance functioning as intended.

Step Six: Building a Repeatable Risk Management Framework

The final and most important way to use Returning to Venezuela is as a template, not a one-off Venezuela playbook. While the facts are Venezuela-specific, the framework is portable. Compliance professionals can lift this framework and apply it to:

  • Other high-risk markets;
  • Post-merger integration;
  • Sanctions-heavy environments; and
  • Complex third-party ecosystems.

The Appendices: The Operational Backbone of Returning to Venezuela: Yes, If

One of the defining features of Returning to Venezuela: The Compliance Guide to Yes, If is that it does not stop at analysis. The appendices convert risk identification into governance, decision-making, and operational control. They are not academic supplements. They are the machinery that makes a “yes, if” decision possible in practice.

Taken together, the appendices form an integrated compliance control stack designed for one purpose: to govern decision-making in an environment where corruption, coercion, sanctions, AML exposure, and weak rule of law are not edge cases but daily conditions.

Appendix A: One-Page Operational Checklists

Appendix A contains a series of one-page checklists, each focused on a distinct but interconnected risk domain. These are not policy summaries. They are operational gating tools meant to be used before decisions are made, not after problems occur.

Appendix B: The CCO Deployment Pack

Appendix B is written from the perspective of the Chief Compliance Officer and is explicitly operational. It is designed to be deployed internally to executive leadership, business sponsors, and control functions.

Appendix C: Board of Directors Materials

Appendix C is aimed squarely at directors and audit or compliance committees. Its function is not to educate boards on Venezuela generally but to structure how boards make, record, and revisit risk acceptance decisions.

Appendix D: Decision-Making Frameworks

Appendix D pulls together the logic underlying the entire book. It provides decision-making frameworks that force organizations to confront uncomfortable realities before committing resources.

How the Appendices Work Together

Individually, each appendix addresses a specific audience or function. Collectively, they form an integrated control system that aligns:

  • Operational decision-making.
  • Compliance authority.
  • Board oversight.
  • Exit discipline.

The appendices are designed to prevent the most common failure pattern in high-risk jurisdictions: waiting until conditions deteriorate before asking hard questions. By then, leverage is gone.

Final Thought

The most important contribution of Returning to Venezuela is that it does not accurately describe risk. It shows compliance professionals how to operate in the real world without surrendering control.

Used correctly, the book becomes a working tool:

  • To assess risk honestly;
  • To design controls that hold under pressure;
  • To align management and the board, and finally
  • To decide when “yes” becomes “no.”

For compliance professionals, that is not just risk management. It is about meeting the business in an operational setting with a risk management strategy for literally the highest risk on earth.

You can purchase Returning to Venezuela: The Compliance Guide to Yes, if on Amazon.com.

Categories
FCPA Compliance Report

FCPA Compliance Report: Going into Venezuela, Navigating the Corruption Risks, a Conversation with Matt Ellis

Welcome to the award-winning FCPA Compliance Report, the longest-running podcast in compliance. We take a short break from our 2-part series with Mike Volkov to review the issues arising from the Trump Administration’s invasion of Venezuela. Matt Ellis joins Tom Fox to look at what all this means for companies looking to do business in Venezuela.

They discuss the complex landscape of doing business in Venezuela, focusing on the rampant corruption, security challenges, and the implications of U.S. sanctions. They explore the risks associated with engaging with the national oil company, PdVSA, and the broader implications for U.S. companies considering re-entry into the Venezuelan market. The conversation also touches on Cuba’s role, international organizations, and the potential for infrastructure rebuilding in Venezuela, emphasizing the need for long-term strategies and careful risk management.

Key highlights:

  • Navigating Corruption and Security Risks in Business
  • Banking and Money Laundering Concerns
  • Cuba’s Role and Sanctions Implications
  • International Organizations and Corruption Regulations
  • Infrastructure Rebuilding in Venezuela
  • Long-term Strategies for Companies

Resources:

Matt Ellis on LinkedIn

Miller & Chevalier LLC

Tom Fox

Instagram

Facebook

YouTube

Twitter

LinkedIn

Categories
ACI FCPA Conference 2025

ACI-FCPA Conference Speaker Preview Series – Matt Ellis on FCPA Enforcement in Mexico

In this episode of the ACI-FCPA and Global Anti-Corruption Conference Speaker Podcasts series, Matt Ellis discusses his panel at the event, “The New FCPA Enforcement Focus in Mexico: A Look at How TCO/FTO Designations Could Impact Prosecutions, Coordination with U.S. Authorities, and the Risk Calculus for Businesses Operating There.”

Some of the issues the panel will discuss are:

  • The evolving enforcement landscape in Mexico.
  • The impact of FTO designations; and
  • Business risks and prosecutorial strategies going forward.

I hope you can join me at the ACI–FCPA Conference. This year’s event will take place on December 3-4 at the Gaylord National Resort & Convention Center in National Harbor, Maryland, near Washington, D.C. The lineup of this year’s event is simply first-rate, featuring some of the top FCPA professionals, white-collar attorneys, and compliance practitioners in the field.

The 2025 program is being completely redesigned to help your organization stay agile, responsive, and ahead of the curve. Expect a dynamic agenda shaped by real-world priorities, practical takeaways, and the most cutting-edge thinking in compliance—led by a faculty of global practitioners with boots on the ground, encountering the very risks that come across your desk.

Please join me at the event. For information on the event, click here. Listeners of this podcast will receive a discount by using the code D10-999-CPN26.

Categories
FCPA Compliance Report

FCPA Compliance Report – Navigating the Complexities of FTO Designations and Compliance in Mexico and Latin America

Welcome to the award-winning FCPA Compliance Report, the longest-running podcast on compliance. In this episode, Tom welcomes Tim O’Toole and Matt Ellis from Miller & Chevalier Chartered to discuss the significant implications of President Trump’s executive order designating Mexican drug cartels as foreign terrorist organizations (FTOs).

Tim and Matt elaborate on the heightened compliance risks and operational challenges now faced by companies operating in these regions. The conversation delves into the legal distinctions between Specially Designated Nationals (SDNs) and FTOs, the broad-ranging impact on industries such as agriculture and logistics, and the urgent need for robust risk assessment strategies to mitigate civil and criminal liabilities under U.S. law. They also explore the broader Latin American context and potential collateral consequences for U.S. and Latin American companies amid anticipations of increased regulatory scrutiny and enforcement actions. The discussion concludes with timely observations on recent U.S. Treasury directives aimed at curbing cartel money laundering activities, showcasing the lengths the administration is willing to go to combat these criminal enterprises.

Key highlights:

  • Executive Order and FTO Designation
  • Heightened Risks for Companies in Mexico
  • Complexities of Cartel Influence in Mexico
  • Risk Management Strategies for Companies
  • Broader Implications for Latin America
  • Potential Weaponization of FTO Designation
  • Corporate Compliance and Human Rights

Resources:

Designation of Cartels as FTOs Creates Heightened Risks for Companies Operating in Latin America

Miller & Chevalier

Tim O’Toole

Matt Ellis

Tom Fox

Instagram

Facebook

YouTube

Twitter

LinkedIn