Categories
Blog

THE BERKO TRIAL – PART 4: When Red Flags Become Evidence: Transaction Controls from the Berko Trial

Today in Part 4, I want to focus on some of the compliance lessons from the Asante Berko FCPA trial. The compliance lesson from the Berko trial is not simply that employees should not pay bribes. Every code of conduct already says that. The harder question is whether the compliance program can interrupt the operating pattern: a politically connected intermediary, milestone-linked invoices, personal email, cash discussions, incomplete diligence answers, and a commercial team under pressure to close. These were some of the questions that Goldman Sachs faced and successfully answered.

That is where policy becomes performance. Trial reporting described a legitimate infrastructure project surrounded by evidence that prosecutors said showed corrupt intent and concealment. The same emails, diligence questions, payment records, and escalation decisions that once lived inside a transaction later became evidence before a jury. For compliance professionals, the case is a control map. It shows where a high-risk deal can be tested, paused, corrected, or stopped before red flags mature into criminal exposure.

Begin With the Business Model

Your business justification should begin with how the deal is expected to work, not with a standard questionnaire. In the Berko transaction, commercial urgency, a major public need, concentrated government discretion, substantial projected fees, and local intermediaries all increased the risk profile. None of those facts establishes bribery. Together, however, they demand a more disciplined control environment.

The deal team should be required to explain the legitimate path to success. Which officials control each approval? Which regulatory, legislative, and contractual milestones must occur? What service does every intermediary perform? How is that service connected to value rather than access? Where could commercial pressure tempt someone to bypass the process?

This is consistent with the DOJ Evaluation of Corporate Compliance Programs (ECCP), which asks whether a company understands its business from a commercial perspective and devotes appropriate attention and resources to high-risk transactions. A generic country score is not enough. The risk assessment must reflect the transaction’s economics, approval structure, counterparties, compensation model, technology, and pressure points.

Make Third-Party Diligence Operational

Third-party diligence often fails because it is treated as an onboarding event. The questionnaire is completed, screening is run, a risk rating is assigned, and the business moves on. High-risk public-sector work requires continuous control.

Before engagement, the company should document the business rationale, beneficial ownership, politically exposed person and family links, qualifications, reputation, service scope, deliverables, compensation, payment terms, and proposed bank account. Compensation should be benchmarked against the actual work. Enhanced review should apply when fees are success-based, tied to government milestones, disproportionate to services, routed through unrelated entities or individuals, or connected to officials who control approvals.

After onboarding, controls must follow the intermediary into contracting, invoicing, payment, and monitoring. The DOJ guidance asks whether the company understands the business rationale, confirms that services were actually performed, assesses whether compensation is appropriate, tracks red flags, uses audit rights, and manages third parties throughout the relationship. The relevant question is not whether the intermediary passed diligence once. It is whether the relationship still makes sense when the invoice arrives.

Control the Channels Where Business Occurs

Personal email is not proof of bribery. The Berko facts were more specific. According to the trial reporting, sensitive payment discussions occurred through personal accounts. At the same time, routine deal work proceeded through corporate systems, and one exchange referred to the monitoring of a Goldman account. The control issue was the combination of channel separation, sensitive content, and knowledge of monitoring.

Companies need clear rules for personal email, messaging applications, approved mobile platforms, and bring-your-own-device arrangements. Those rules require technical support: approved-channel design, retention settings, monitoring consistent with law, exception approval, employee attestations, and escalation when business moves outside the system. The program should also test whether records can actually be collected and preserved across the jurisdictions where the company operates.

The ECCP asks how companies manage and preserve business communications on personal devices and messaging platforms. The DOJ Corporate Enforcement and Voluntary Self-Disclosure Policy (VSD) likewise identifies appropriate controls over personal and ephemeral communications as part of timely remediation. A policy that cannot preserve the evidence it covers is not an effective control.

Give Compliance Real Stop Authority

Escalation is not effective if compliance can ask questions but cannot pause the transaction. High-risk deals need defined hard stops. Examples include incomplete beneficial ownership, inconsistent diligence answers, refusal to identify service providers, unexplained compensation, undisclosed PEP relationships, requests for cash, payments to personal or nominee accounts, and destination changes without a credible business reason.

A hard stop does not require the company to abandon every transaction containing a red flag. It requires the risk to be resolved before money or value moves. The control framework should identify who may impose a pause, who may clear it, whether any override is permitted, what evidence supports an override, and which risk decisions require senior escalation.

Trial testimony reportedly described months of compliance questions about the Ghanaian intermediary and inconsistent or incomplete answers, followed by Goldman’s withdrawal from the contemplated financing. That sequence should not be converted into a claim that every control operated early enough or that the company was legally exonerated. The more useful lesson is that the decision trail mattered. It documented the questions, the resistance, the escalation, and the exit.

Connect Diligence, Invoices, and Money

Many programs distribute the relevant facts across separate systems. Procurement sees the contract. Compliance sees the screening. Accounts payable sees the invoice. Treasury sees the destination account. Investigations see the allegation. No one sees the complete pattern.

Payment controls should require proof of service, account-name matching, country and entity consistency, independent approval for destination changes, and tight restrictions on cash. Analytics should flag round-dollar invoices, duplicate invoice numbers, payment splitting, milestone-timed consulting fees, payments to employees or related parties, high-risk correspondent routes, and transfers followed by cash withdrawals.

The decisive step is integration. Due diligence, PEP screening, contracting, procurement, accounts payable, treasury, and case-management data should be capable of producing a transaction-level view. That view allows compliance to ask whether a payment is not only properly approved but also commercially credible.

Build an Evidence-Grade Record

The defense’s most forceful theme was the missing last mile: no downstream bank record showing money reaching a Ghanaian official, no alleged recipient on the witness stand, and no eyewitness to a bribe. The jury nevertheless convicted Berko on all three charged counts. For an internal investigation, the lesson cuts both ways. Suspicion is not proof, but weak tracing can leave the company unable to determine what happened.

Preserve native emails, attachments, metadata, messaging exports, payment records, approval histories, translations, and custodial provenance—record who made each factual determination and what evidence supported it. For multilingual material, preserve the original, use qualified translators, document dialect and ambiguity, and maintain a process for reviewing disputed language. Financial tracing should move from payer to intermediary to ultimate recipient, including related-party accounts and cash conversion.

The current FCPA enforcement guidelines emphasize individual misconduct and caution against attributing nonspecific malfeasance to corporate structures. That makes an evidence-grade corporate record especially important. It can help separate an individual’s conduct from the organization’s response while also showing whether the program was designed and implemented effectively.

Test the Controls Before the Crisis

An effective program does not promise that no misconduct will ever occur. DOJ recognizes that even a strong program may fail to prevent an offense. The question is whether the program is risk-based, detects concerns, responds promptly, and improves from experience.

Replay a recent public-sector transaction against the Berko pattern. Could the company identify every approval-controlling official and intermediary? Would milestone-linked payments trigger review? Could compliance pause the deal? Would personal email activity be detected and preserved? Could investigators trace funds beyond the first intermediary? Measure time from red flag to pause, overdue enhanced diligence, unresolved PEP issues, payment exceptions, control overrides, and closure of remediation.

The practical takeaways are clear. Commercial urgency calls for greater discipline, not reduced scrutiny. Third-party diligence must remain connected to invoices, payments, monitoring, and escalation. Off-channel communications become an intent and preservation issue when combined with sensitive content and known monitoring. A deal exit matters, but an earlier hard stop may reduce exposure and preserve more business value.

Join us tomorrow as we conclude our 5-part series by moving the transaction to the enterprise. In it, we will explore such questions as who owns these controls, who funds and tests them, how accountability is imposed, and what your Board of Directors should demand as evidence that the program works in practice.

Resources:

United States v. Berko, No. 1:20-cr-00328-DG, Indictment, ECF No. 3 (E.D.N.Y. filed Aug. 26, 2020)

Stewart Bishop, “Goldman Jury Sees Cash Talk in Energy Deal Email Deluge,” Law360, Aug. 1, 2026; Stewart Bishop, “Goldman Exec Was Linchpin to Ghana Bribery Ploy, Jury Told,” Law360, Aug. 5, 2026.

Stewart Bishop, “Ex-Goldman Exec Convicted of Ghana Bribery Plot,” Law360, Aug. 6, 2026. Supplied trial reporting.

U.S. Attorney’s Office for the Eastern District of New York, “Former Goldman Sachs Investment Banker Convicted of Foreign Bribery and Money Laundering,” Aug. 6, 2026, DOJ Press Release.

Stewart Bishop, “Goldman Jury Sees Undercover Video as Bribe Trial Nears End,” Law360, Aug. 4, 2026—supplied trial reporting.

Stewart Bishop, “Shady Power Deal Used in Goldman Compliance Prep, Jury Told,” Law360, July 29, 2026

Stewart Bishop, “Like Milli Vanilli, Goldman FCPA Case Is a Ruse, Jury Told,” Law360, July 28, 2026.

SEC Final Judgment against Asante Berko

SEC Complaint against Asante Berko

DOJ Evaluation of Corporate Compliance Programs

DOJ Corporate Enforcement and Voluntary Self-Disclosure Policy

Categories
FCPA Compliance Report

FCPA Compliance Report: Managing Compliance and National Security Risks When Doing Business in the DRC, Part 2

In this episode, Tom Fox welcomes David Simon, Partner at Foley & Lardner; Jack Korba, Of Counsel at Foley & Lardner; and Olivier Bustin, a Partner at Pinsent Masons, to discuss doing business in and with the Democratic Republic of the Congo (DRC). This is the second part of a two-part series on this topic, which presents a detailed approach to evaluating and managing travel to a high-risk country or region.

They discuss how companies investing in high-risk jurisdictions like the Democratic Republic of the Congo should treat diligence as ongoing risk management, using tailored controls, audits, and continuous monitoring informed by geopolitical developments and government/regulatory priorities (including signals such as announcements and sector focus, such as critical minerals). The speakers emphasize pragmatism: accepting some ambiguity while designing jurisdiction-specific compliance frameworks, rather than placing standard programs on “autopilot” and maintaining active C-suite and board engagement. They stress building and documenting a rational, risk-tolerant decision process that can be explained to regulators (e.g., DOJ/SEC), including knowing counterparties and local dynamics, implementing real controls, and escalating decisions appropriately. Key pitfalls to avoid include overcommitting to projects beyond risk tolerance and entering transactions without sufficient preparation. The panel also urges compliance leaders not to be paralyzed by fear, to shape opportunities early, and to note market opportunities and signals of U.S. engagement, such as financing for the Lobito railway corridor.

Key highlights:

  • Ongoing Risk Controls
  • Pragmatism In High Risk
  • Regulator Ready Diligence
  • Mistakes To Avoid
  • Where To Start

Resources:

David Simon

Jack Korba

Olivier Bustin

Foley & Lardner

Pinsent Masons

The Democratic Republic of the Congo as a Near-Term Strategic Opportunity for U.S. Companies Part 1

Part 2

Part 3

Tom Fox

Instagram

Facebook

YouTube

Twitter

LinkedIn

To learn about the intersection of Sherlock Holmes and the modern compliance professional, check out my latest book, The Game is Afoot-What Sherlock Holmes Teaches About Risk, Ethics and Investigations on Amazon.com.

Categories
Blog

Charlie X: Power Without Boundaries – A Compliance Nightmare

Today, we explore the explosive volatility of Charlie X—a story about unchecked power, emotional instability, and the dire consequences of failing to enforce rules and structure. Charlie Evans, a teenage orphan raised by aliens, is taken aboard the Enterprise, possessing extraordinary telekinetic abilities but lacking social training, emotional discipline, and accountability. That combination proves disastrous. We consider how Charlie’s descent into violence mirrors risks faced by compliance professionals when misconduct is ignored, misbehavior is tolerated, and power is given without oversight. In today’s corporate world, “Charlie X” is less about space and more about leadership responsibility, psychological safety, and early intervention.

Key Highlights and Star Trek Case Studies:

1. The Responsibilities of Power—Strength Without Structure

This is illustrated by Charlie turning crew members into nothingness when they anger him.

Charlie is gifted with tremendous abilities but lacks any ethical framework or boundaries. This is a vivid metaphor for what happens when individuals inside an organization gain influence or access without training or accountability. Think of an unmonitored executive with access to financial controls or an engineer with override access but no compliance training—a ticking time bomb.

2. Training and Supervision—It’s Not Optional, It’s Essential

This is illustrated by Kirk’s attempt to guide Charlie and his later regret at not recognizing the full scope of the risk.

Charlie’s guardianship was left to chance, with no proper onboarding and no safety protocols. Sound familiar? In corporate compliance, onboarding isn’t just about day one—it’s about culture shaping. Organizations must ensure that individuals with a higher risk potential receive both guidance and oversight from the outset.

3. Unpredictable Behavior and Ethical Culture—From Red Flag to Alarm Bell

This is illustrated by Charlie’s mood swings and escalating aggression, which are repeatedly ignored until it’s too late.

The crew notices early signs, such as jealousy and possessiveness, but tolerates them. This reflects the real-world danger of brushing off early signs of a toxic culture. A strong compliance function identifies behavioral red flags before they escalate into corporate crises.

4. Communication and Escalation Protocols—Say Something, Do Something

This is illustrated by Janice Rand’s discomfort and unease around Charlie, which she initially tries to manage on her own.

Rand’s growing fear underscores the difficulty of speaking up, especially when someone powerful appears to be protected. Her reluctance reminds us that a speak-up culture is not automatic. Companies must establish genuine channels for complaints, empower employees to utilize them, and respond promptly and transparently.

5. Crisis Management—Too Late is Still Too Late

This is illustrated by the crew’s loss of control of the Enterprise, which forced alien intervention to remove Charlie.

The crew fails to contain the situation internally. It takes external, godlike beings to restore order—a cautionary tale for compliance leaders. If a company waits until the crisis has gone public or regulatory bodies step in, internal credibility is lost. Crisis planning and early intervention are crucial in protecting the organization before outside authorities are required to intervene.

Final ComplianceLog Reflections

Charlie X reminds us that power without oversight is perilous, that emotional and psychological health must be part of our compliance focus, and that red flags must not be ignored simply because they come wrapped in charm or vulnerability. Compliance is not simply about policies, procedures, or even rules but rather readiness, responsiveness, and respect for the human element.

Resources:

Excruciatingly Detailed Plot Summary by Eric W. Weisstein

MissionLogPodcast.com

Memory Alpha

Categories
FCPA Compliance Report

FCPA Compliance Report: Judicial Discretion, Sentencing Advocacy, and a Proactive Compliance Model: Joseph De Gregorio – Part 2

In this episode, Tom Fox welcomes former Wall Street trader Joseph De Gregorio, who was federally convicted and now applies a “compliance rebuild” methodology to demonstrate genuine remediation under legal scrutiny. This is Part 2 of a two-part podcast series.

In Part 2, we cover how federal judges exercise broad discretion despite sentencing guidelines and often form views before the court based on the pre-sentence report and sentencing memorandum, with probation officers’ impressions shaped by a detailed defendant letter and authentic allocution; judges emphasize post-offense conduct and may discount lawyer advocacy. Joseph then summarizes patterns from 400+ white-collar cases, arguing that structural failures precede cultural and operational failures, and introducing the “access to scrutiny ratio” as the most predictive risk indicator. He lists five warning signals: unscrutinized top performers, known but unmapped monitoring gaps, unmanaged performance pressure, quietly resolved senior incidents, and compensation rewarding results without method (noting DOJ’s September 2024 ECCP update). He outlines a proactive Compliance Rebuild approach using human failure audits, reverse access audits, directional speak-up analysis, and DOJ-aligned prosecution simulations.

Key highlights:

  • Pre-Sentence Reports Matter
  • Patterns Across 400 Cases
  • Five Compliance Warning Signals
  • Prosecution Simulation Stress Test
  • DOJ Evaluation Questions and Red Flags

Resources:

Joseph De Gregorio – Founder, JN Advisor™ Maximum Sentence Reduction – Minimum Time Served

📋 Initial Consultation: https://forms.gle/2fLczk7bbwM7KSaP6

Bloomberg Law Contributor: “How to Get a Judge to Reduce Your Client’s White-Collar Sentence” – Bloomberg Law 

Bloomberg Tax Contributor: Tax Fraud Sentencing Has a Gap Defense Attorneys Are Missing

Featured Expert: American Bar Association

Featured Sentencing Mitigation Expert: Law360

Featured Expert on Us Weekly with 5x Emmy Award Winning Journalist Kristin Thorne for her “Uncovered” Series Click Link For Full Video

https://www.usmagazine.com/crime-news/news/federal-sentencing-strategist-reveals-why-some-real-housewives-stars-commit-fraud/

Tom Fox

Instagram

Facebook

YouTube

Twitter

LinkedIn

Interested in the intersection of Sherlock Holmes and modern compliance? Check out my latest book, The Game is Afoot in Compliance.

Categories
FCPA Compliance Report

FCPA Compliance Report: From DOJ’s 7 Compliance Pillars to Sentencing Mitigation: Joseph De Gregorio’s Compliance Rebuild Framework – Part 1

In this episode, Tom Fox welcomes former Wall Street trader Joseph De Gregorio, who was federally convicted and now applies a “compliance rebuild” methodology to demonstrate genuine remediation under legal scrutiny. This is Part 1 of a two-part podcast series.

Using the Matthew Bowyer illegal sports betting case, Joseph explains the federal pre-sentence interview and pre-sentence report (PSR) process, emphasizing that the probation officer’s credibility assessment and PSR narrative heavily influence sentencing and downstream treatment across the federal system. He describes submitting a 3,500-word personal narrative before the PSR interview, which was attached in full and cited by the judge as mitigation, resulting in a one-year-and-a-day sentence rather than the government’s four-year request. Joseph maps DOJ’s seven corporate compliance program dimensions to individuals via a personal compliance manual, independent accountability structure, credentialed education, verifiable monitoring, documented transparency, voluntary discipline actions, and a post-sentencing continuous improvement plan centered on victims-first accountability.

Key highlights:

  • Joseph’s Wall Street Past
  • The Boyer Betting Case
  • What is a PSR, and why does it drive sentencing
  • Preparing for the Interview
  • From Corporations to Individuals
  • Seven Pillars Framework

Resources:

Joseph De Gregorio – Founder, JN Advisor™ Maximum Sentence Reduction – Minimum Time Served

📋 Initial Consultation: https://forms.gle/2fLczk7bbwM7KSaP6

Bloomberg Law Contributor: “How to Get a Judge to Reduce Your Client’s White-Collar Sentence” – Bloomberg Law 

Bloomberg Tax Contributor: Tax Fraud Sentencing Has a Gap Defense Attorneys Are Missing

Featured Expert: American Bar Association

Featured Sentencing Mitigation Expert: Law360

Featured Expert on Us Weekly with 5x Emmy Award Winning Journalist Kristin Thorne for her “Uncovered” Series Click Link For Full Video

https://www.usmagazine.com/crime-news/news/federal-sentencing-strategist-reveals-why-some-real-housewives-stars-commit-fraud/

Tom Fox

Instagram

Facebook

YouTube

Twitter

LinkedIn

Interested in the intersection of Sherlock Holmes and modern compliance? Check out my latest book, The Game is Afoot in Compliance.

Categories
GSK in China: 13 Years Later

GSK In China: 13 Years Later – Where Was the Board? Director Oversight and Doing Business in China

Thirteen years after the GSK China scandal exploded onto the global stage, its lessons remain as urgent as ever for compliance professionals and business leaders. In this podcast series, we revisit the case not simply as corporate history, but as a living cautionary tale about culture, incentives, third parties, investigations, and governance. Each episode explores what went wrong, why it went wrong, and how those failures still echo in today’s compliance and ethics landscape. Join me as we unpack the scandal and draw practical lessons for building stronger, more resilient organizations. This episode examines why major bribery scandals occur “under the board’s nose,” using GSK as a launching point to explain directors’ legal and practical compliance responsibilities.

It traces oversight duties under Delaware law, highlighting Caremark’s good-faith duty to ensure information and reporting systems, Stone v. Ritter’s standard for liability for sustained or systematic oversight failure, and the business judgment rule. It contrasts “check-the-box” programs with risk-based oversight via the Piat case, where formal compliance masked illegal conduct embedded in business plans. The discussion ties board expectations to FCPA guidance hallmarks, emphasizing tone at the top, empowered compliance functions with direct board access, DOJ/SEC scrutiny, and SEC Reg. S-K 407 risk-oversight disclosures, and potential disgorgement. It then focuses on China as a high-risk environment, third-party intermediary exposure, and M&A “deal-breaker” dilemmas requiring rigorous pre- and post-acquisition diligence, concluding with the paradox that boards may be incentivized toward plausible deniability. Our hosts are Timothy and Fiona.

Key highlights:

  • Compliance Starts at the Top
  • Caremark Duty Explained
  • FCPA Hallmarks for Boards
  • Passive Board Era Ends
  • Plausible Deniability Paradox

Resources:

GSK in China: A Game Changer for Compliance on Amazon.com

GSK in China: Anti-Bribery Enforcement Goes Global on Amazon.com

Tom Fox

Instagram

Facebook

YouTube

Twitter

LinkedIn

Ed. Note: Notebook LM created the voices of the hosts, Timothy and Fiona, based on text written by Tom Fox

Categories
Blog

Returning to Venezuela: Part 5 – AML Risk and the Final Compliance Test

In this five-part series, I have walked through the core compliance risks US energy companies will face as they consider a return to Venezuela. We began with bribery and corruption and the long shadow of PdVSA (Parts 1 & 2). We moved through export controls (Part 3), security risks (Part 4), and the broader operational and strategic challenges of working in one of the most complex risk environments in the world. But this final post is different. Money laundering risk is not simply another risk category. It is the connective tissue that binds all the others together.

If bribery is how improper value enters the system, money laundering is how it is disguised, moved, and legitimized. If export control violations create pressure to reroute goods or payments, money laundering techniques make that rerouting possible. If security risks require local intermediaries, cash payments, or opaque vendors, those same decisions create AML exposure. For the compliance professional, money laundering risk in Venezuela is the capstone test of whether the program actually works.

The Regulatory Frame: FinCEN, ECCP, and Correspondent Banking Reality

Any AML discussion must start with expectations. US regulators have been explicit. The AML program pillars articulated by the Financial Crimes Enforcement Network (FinCEN) are not optional abstractions. They are operational requirements: risk-based controls, internal policies, independent testing, training, and designated responsibility.

Overlay that with the Department of Justice Evaluation of Corporate Compliance Programs (ECCP), which asks whether controls are designed, implemented, tested, and actually effective. Then add the reality of correspondent banking risk. Even if a US energy company does not directly move funds through US banks, its banking partners will apply US standards. Banks do not absorb Venezuela’s risk on behalf of their customers. They de-risk. Compliance failures upstream become frozen accounts downstream. This is why AML must be treated as an enterprise risk, not a compliance side project.

Operating Under Licenses Does Not Reduce AML Risk

This blog assumes that operations occur under general licenses, specific licenses, or wind-down authorizations issued by the Office of Foreign Assets Control. That matters for sanctions analysis, but it does not reduce AML exposure. Licenses permit activity. They do not cleanse counterparties, validate payment flows, or excuse weak controls. In fact, licensed activity often attracts heightened scrutiny because regulators know companies will push forward aggressively once permission is granted.

In Venezuela, licensed operations still involve high-risk state actors, politically exposed persons, weak financial institutions, and a long history of financial opacity. From an AML perspective, licenses are a starting gun, not a shield.

PdVSA as a Multi-Vector AML Risk

As we have previously noted, PdVSA must be treated not as a single counterparty risk but as multiple overlapping AML risk vectors. First, there is trade-based money laundering. Oil shipments are uniquely vulnerable to pricing manipulation, volume misstatements, phantom cargoes, and circular trading. In Venezuela, these risks are amplified by distressed infrastructure, a history of sanctions, and reliance on intermediaries.

Second, there is an intermediary risk. Shipping companies, charterers, port agents, and customs facilitators often operate through layered ownership structures. The farther one moves from the wellhead, the less transparency exists. Third, there is a risk to the payment structure. Delayed payments, in-kind arrangements, and third-country settlement accounts create fertile ground for laundering illicit proceeds. When oil becomes currency, AML controls must follow the barrel, not the invoice.

Venezuelan, Crypto, and Third-Country Banking Risk

Venezuelan banks operate under severe constraints. Many lack robust AML systems, and even well-intentioned institutions face talent shortages and technology gaps. As a result, payments often move through third-country banks. These arrangements create several red flags: unusual routing, non-USD transactions, inconsistent settlement timelines, and opaque beneficiary information. Each red flag increases the likelihood of SAR filings and banking friction. Compliance professionals must understand that correspondent banks apply their own risk lens. If they are uncomfortable, they will exit. That operational disruption becomes a compliance failure.

Crypto and alternative payment mechanisms are not edge cases in Venezuela. They are practical responses to currency instability, banking limitations, and sanctions pressure. From an AML standpoint, crypto introduces wallet anonymity, cross-border velocity, and limited recourse once funds move. Any use of crypto, whether by the company or its third parties, must be explicitly prohibited or tightly controlled. Silence is not neutrality. Silence is exposure.

Third Parties: Where AML, Bribery, and Security Collide

Local agents, logistics providers, customs brokers, and security vendors represent the highest combined risk in Venezuela. These third parties often operate in cash-intensive environments, maintain close ties to government actors, and perform functions critical to business continuity. Family-owned and politically connected vendors demand enhanced due diligence. That means beneficial ownership verification, source-of-funds analysis, ongoing monitoring, and contractual audit rights. Initial diligence alone is insufficient. Relationships evolve, and risk escalates quickly.

This is where the bribery blog, the security blog, and this AML blog converge. The same third party that creates bribery risk also creates money laundering risk. Controls must be integrated, not siloed.

The Operational Reality: This Is Manageable If You Manage It

Despite these risks, this is not a counsel of despair. US companies have operated in high-risk jurisdictions before. The key is realism. AML programs in Venezuela cannot rely on annual certifications, static risk assessments, or generic policies. They require transaction-level visibility, real-time escalation, and empowered compliance personnel. Friction with the business is inevitable and necessary.

Venezuela-Specific AML Operational Checklist

Below is a practical, compliance-focused checklist for operating in Venezuela:

Risk Assessment

  • Conduct a Venezuela-specific AML risk assessment tied to operations, not geography alone
  • Map payment flows end-to-end, including third-country routing
  • Identify trade-based money laundering scenarios tied to oil shipments

Policies and Controls

  • Prohibit unauthorized crypto usage explicitly
  • Require documented economic justification for all intermediaries
  • Establish clear escalation thresholds for delayed or rerouted payments

Third-Party Due Diligence

  • Perform enhanced due diligence on all local agents, logistics providers, customs brokers, and security vendors
  • Verify beneficial ownership and political exposure
  • Assess the source of funds and expected transaction behavior

Transaction Monitoring

  • Monitor oil pricing, volumes, and delivery discrepancies
  • Flag unusual settlement patterns or changes in banking instructions
  • Integrate AML alerts with sanctions and export control monitoring

Training and Culture

  • Provide targeted AML training for operations, finance, and procurement teams
  • Reinforce speak-up mechanisms tied to payment and logistics concerns

Testing and Auditing

  • Conduct targeted audits focused on high-risk transactions
  • Test controls against realistic laundering typologies
  • Document remediation and program enhancements

AML as the Series Capstone

This series has shown that returning to Venezuela is not a single compliance decision. It is a systems test. Money laundering risk sits at the center of that test because it exposes weaknesses everywhere else. If your AML program can function effectively in Venezuela, it can function anywhere. If it cannot, no license, policy, or assurance letter will save it. This is doable. But only if compliance is brought in early, appropriately resourced, and empowered to say yes, if.

Categories
Data Driven Compliance

The Uses of Data Driven Compliance: Part 2 – Profiles of a Corrupt Payment

Welcome to Data Driven Compliance. In this podcast, we discuss how to use data to improve and enhance the effectiveness of your compliance program, creating greater business efficiency and leading to a higher return on investment for your compliance regime. Join host Tom Fox as he explores how data will drive your compliance program to the next level. This podcast is sponsored by Kona AI.

I recently had the opportunity to visit with Vince Walden, founder and CEO of KonaAI, for a podcast series on the uses of data driven compliance. Over these five podcasts, we will discuss generative AI and ChatGPT in compliance, the profiles of corrupt payments, making the business case for data-driven compliance, what to ask for and how to ask for it, and some success stories. In Part 2, we explore the profiles of corrupt payments.

Vince Walden is an expert in identifying high-risk payments and preventing corporate corruption. His belief in the ability of data analysis and collaboration to find patterns and warning signs shapes his viewpoint on these issues. He shares his experience from a research project where companies collaborated anonymously to analyze the profiles of improper payments, using risk-scoring transactions and applying anti-corruption tests to identify high-risk attributes. Vince emphasizes the importance of transparency and access to data to proactively investigate suspicious activities, serving as a guardrail to prevent potential corruption. Join Tom Fox and Vince Walden as they delve deeper into this topic on this Data Driven Compliance podcast episode.

Key Highlights:

  • Attributes of High-Risk Payments Analysis
  • Uncovering Suspicious Sales Spikes in Poland
  • Detecting Improper Payments with Data Analysis

Resources:

Connect with Vince Walden on LinkedIn

Check out Kona AI

Connect with Tom Fox on LinkedIn

Categories
Daily Compliance News

December 17, 2022 – The Lavish Life Style Edition

Welcome to the Daily Compliance News. Each day, Tom Fox, the Voice of Compliance, brings you four compliance-related stories to start your day. Sit back, enjoy a cup of morning coffee and listen to the Daily Compliance News. All from the Compliance Podcast Network.

Stories we are following in today’s edition of Daily Compliance News:

  • When does a lavish lifestyle = Red Flags? (NYT)
  • Amazon agrees to business practice changes in the EU. (NYT)
  • DFS issues guidance for banks on crypto. (WSJ)
  • Crypto has made corruption worse. (The Guardian)
Categories
GalloCast

Gallocast – Episode 5

Welcome to the GalloCast. You have heard of the Manningcast in football. Now we have the GalloCast in compliance. The two top brothers in compliance, Nick and Gio Gallo, come together for a free-form exploration of compliance topics. It is a great insight on compliance brought to you by the co-CEOs of Ethico. Fun, witty, and insightful with a dash of the two brothers throughout. It’s like listening to the Brothers Gallo talk compliance at the dinner table. Hosted by Tom Fox, the Voice of Compliance.

Topics in this episode include:

  • FTX
  • Elizabeth Holmes was sentenced. End of an era in tech?
  • Compliance program incentives and clawbacks.
  • Assessing culture.
  • Monaco Memo

Resources

Nick Gallo on LinkedIn

Gio Gallo on LinkedIn

Ethico