Categories
Blog

The Scoular DPA Part 4: The Signature Is the Control – Executive Accountability in the Scoular DPA

The Scoular Company Deferred Prosecution Agreement (DPA) ends where every effective compliance program should begin: accountability. The agreement does not leave anti-corruption compliance solely with the Chief Compliance Officer, legal department, or internal audit. It assigns responsibilities throughout the enterprise, then requires senior executives to certify that the company has met its disclosure and compliance obligations.

The CEO signs twice. The Chief Financial Officer signs the disclosure certification. The Chief Legal Officer signs the compliance certification. Each certification is expressly treated as a material statement and representation for purposes of 18 U.S.C. Sections 1001 and 1519. A compliance program is not effective because someone owns it. It is effective when executives can reasonably rely on tested evidence and personally stand behind the result.

Attachment C Creates an Accountability System

Attachment C contains the minimum elements Scoular must maintain in its anti-corruption compliance program. Read separately, they look familiar: risk assessment, policies, training, reporting, investigations, incentives, discipline, third-party management, testing, data access, and remediation. Read together, they create an accountability system.

Directors and senior management must provide strong, explicit, and visible support through actions and words. Middle management must reinforce that commitment in day-to-day operations. One or more senior corporate executives must oversee the anti-corruption program and have authority to report directly to internal audit, the board, or an appropriate board committee.

Those officials must also have adequate autonomy from management and sufficient resources, authority, and senior leadership support. This is more demanding than tone at the top. It asks whether compliance can challenge the business, reach the board, obtain data, investigate allegations, and require remediation when commercial pressure is greatest.

In the DPA, the admitted conduct involved customs brokers, failed inspections, disguised invoices, communications, and recurring business benefits. An empowered compliance function must connect those facts across organizational boundaries. Formal reporting access means little if the function lacks the people, technology, information, or standing to do that work.

Compensation and Discipline Make Culture Measurable

Attachment C requires compliance criteria in compensation and bonus systems. It also requires disciplinary procedures to be applied consistently and fairly, regardless of an individual’s position or perceived importance. Those provisions address the incentives that can turn a workaround into an operating model.

If a logistics team is rewarded only for delivery speed, it may treat a delayed train as failure. If a senior manager receives credit for avoiding demurrage but no consequence for bypassing controls, the company has placed its real values inside the compensation plan. Training cannot overcome incentives that point in the opposite direction.

Scoular must therefore do more than add a generic compliance factor to an annual review. It should define the behaviors that affect compensation, document how compliance input changes an award, and test whether consequences are applied upward as well as downward. The board should examine outcomes. Who lost compensation? Who received recognition for escalating a concern? Were supervisors assessed for misconduct they tolerated or failed to detect? Did seniority affect the consequence? Culture becomes credible when employees can see that ethical conduct affects careers, compensation, and promotion.

Third-Party Accountability Requires Proof of Work

The bribery scheme operated through customs brokers. Attachment C responds directly to that risk. Scoular Company must document the business rationale for using a third party, assess reputation and foreign-official relationships, describe services specifically in the contract, confirm that the work was actually performed, and determine whether compensation is reasonable for the industry and geography. Ongoing monitoring may include updated due diligence, training, audits, and annual certifications. This is an operating control, not a procurement checklist.

An approved broker, executed contract, and completed screening report do not establish that a reinspection occurred or that a payment was legitimate. The business owner must be accountable for the service, finance must validate the invoice, compliance must assess red flags, and internal audit must test whether the control works. The central question is not whether the broker passed onboarding. It is whether the company knows what the broker did with its money.

Data Access Connects Oversight to Evidence

Attachment C requires compliance and control personnel to have sufficient direct or indirect access to relevant data for timely and effective transaction monitoring and testing. It also requires root-cause analysis of misconduct and the sharing of systemic issues, control failures, and remediation with management as appropriate. That obligation connects the program to the certifications.

Executives cannot make a defensible representation about program effectiveness if compliance cannot obtain accounts-payable data, broker records, shipment information, inspection results, communications, investigation files, and audit findings. The company cannot certify complete disclosure if allegations remain fragmented across the hotline, internal audit, legal, due diligence, and business systems. Data access is therefore an accountability issue. It determines whether management can see the whole risk picture before signing.

Two Certifications, Two Different Questions

The DPA requires two certifications at the end of its term.

The CEO and CFO Certify Disclosure

Attachment E requires the CEO and CFO to certify that Scoular has disclosed any evidence or allegations required by the DPA, including qualifying FCPA or Foreign Extortion Prevention Act matters involving employees or agents.

The form expressly reaches information identified through the compliance and controls program, whistleblower channel, internal audit reports, due diligence, investigations, or other processes.

The CFO’s inclusion is significant. Disclosure is not treated as a legal department judgment alone. The certification requires an enterprise process capable of gathering information from finance, controls, audit, compliance, investigations, and the business.

Before signing, the CEO and CFO should know what allegations were received, how they were triaged, which matters were investigated, what remains open, and how the company determined whether each matter was reportable.

The CEO and CLO Certify the Program

Attachment F requires the CEO and Chief Legal Officer to certify that Scoular’s DOJ reports are “true, accurate, and complete.” They must also certify, based on their review and understanding, that the company has implemented a program meeting Attachment C and that the program is reasonably designed to detect and prevent anti-corruption violations throughout Scoular’s operations. That is not a promise that misconduct will never occur. No compliance program can guarantee that result.

It is a representation about design, implementation, coverage, and the quality of the reports submitted to the government. The signatories therefore need evidence that the program operates across the enterprise, including in high-risk markets and functions. The CCO may build and test much of that evidence, but the CCO does not sign Attachment F. The DPA places the final representation with the CEO and CLO.

Sections 1001 and 1519 Change the Sign-Off Process

Both certification forms state that they constitute material statements and representations for purposes of Section 1001 and records or documents for purposes of Section 1519. That language should create rigor, not panic. It does not mean an executive should refuse to sign because testing found exceptions. A credible program should find weaknesses. The question is whether the certification and supporting reports accurately describe the program, testing, findings, remediation, and remaining limitations.

The greater risk is a ceremonial sign-off supported by filtered information, unresolved contradictions, narrow testing, or undocumented assumptions. Scoular Company should treat certification as a process rather than an event. That process should include:

  1. A written certification standard tied to each representation in Attachments E and F;
  2. Sub-certifications from the leaders who own finance, compliance, legal, internal audit, investigations, human resources, procurement, and high-risk operations;
  3. A complete inventory of allegations, investigations, audit issues, control exceptions, remediation items, and DOJ commitments;
  4. Independent challenge of management’s evidence and closure decisions;
  5. Documented treatment of qualifications, unresolved matters, and contrary evidence; and
  6. Audit committee review before the executives sign.

Sub-certifications should support executive diligence without diluting executive responsibility. The purpose is to create a reliable chain of evidence from the operational control to the final signature.

The Board Must Oversee the Evidence

The board does not sign Attachments E or F. Its oversight role is nevertheless central. The board authorized the DPA, and Attachment C gives the anti-corruption function access to the board or an appropriate committee. The board should use that access to test whether management’s certification process is credible.

Directors should not ask only whether the company is on schedule. They should ask what evidence could prevent a certification, which findings remain open, whether management has limited the scope of testing, and whether compliance, legal, finance, and internal audit agree on the facts. This is also a Caremark-style oversight lesson. Board-level information systems must bring significant compliance risks and red flags to directors, particularly during a formal government resolution. A dashboard should not replace discussion of disputed findings, repeat issues, overdue remediation, or business resistance.

Is It Real or Is It Memorex

I acknowledge there is a contrary view of this which comes to us from my Compliance into the Weeds co-host, Matt Kelly. In a blog post entitled Scoular DPA Unveiled, Doesn’t Help, he questions why the company CCO is not required to certify the DPA. It could be, as Kelly writes, that “an agriculture supply business with 1,250 employees and $7.3 billion in revenue — even has a chief compliance officer; maybe it doesn’t, and the chief legal office also holds the CCO role.” He goes on to write, “Then again, if a company’s chief legal officer pulls double duty as the chief compliance officer too, and that’s why he or she is signing the certification — doesn’t that whole arrangement run contrary to the spirit of what the Justice Department wants to see for an empowered and autonomous compliance function?” He concludes by asking, “But if we’re now letting companies sign prosecution agreements where they commit to a strong, independent, empowered compliance function, except for the part that you don’t even have an actual chief compliance officer — then what are we even doing here, people?” [Emphasis supplied]

The Scoular Company website lists the Chief Legal Officer as Tim Manning, whose duties include leading “ Scoular’s legal team and serves as principal advisor on legal, risk, compliance, governance, and other matters to Scoular’s Senior Leadership Team and Board of Directors. He also has oversight of Scoular’s real estate function.” It appears the CCO and GC functions are wrapped into one person’s job description.

The Bottom Line on Accountability

We began this week’s blog post series with the admitted facts from the DPA: a payment process designed to prevent adverse customs decisions. It then examined the missed voluntary-disclosure window and a deep dive into how the use of data analytics and internal controls could have caught the FCPA violation. Today we end with the signatures. Scoular Company’s DPA demonstrates that executive accountability is not an abstract statement about culture. It is built through access, resources, incentives, discipline, third-party controls, data, testing, root-cause analysis, and complete reporting. The signature is not the beginning of accountability. It is the final confirmation that accountability has operated throughout the company, at least during the term of the DPA.

Categories
Blog

The Scoular DPA Part 3: The Data Was Talking – Data Analytics and the Scoular Bribery Scheme

The Scoular Company bribery scheme was hidden, but it was not invisible. For six years, customs brokers paid Mexican officials approximately $2,000 per train so Scoular Company shipments could cross the border despite adverse inspections. The brokers invoiced the payments back to Scoular as “reinspection fees.” In total, Scoular Company admitted that it authorized $414,351 in bribes and avoided approximately $6.5 million in fees and costs. Those facts describe an FCPA violation. They also describe a data pattern.

I had the opportunity to visit with Vince Walden, CEO of KonaAI, about the Scoular Company FCPA enforcement action from a data analytics perspective. He identified the feature that should command every CCO’s attention: people concealing misconduct often record it consistently. They may avoid the word “bribe,” but they still need a repeatable description that allows the payment to be processed, reconciled, and found again. At Scoular Company, that description was “reinspection fee.”

Walden’s observation goes to the heart of modern compliance. Illegal conduct may be concealed from the compliance department while remaining visible in accounts payable, journal entries, invoices, purchase orders, shipment records, and communications. The control failure occurs when those systems hold the evidence, but the company never asks the data the right questions.

Consistency Can Become the Fraudster’s Fingerprint

Walden observed that accountants value consistency because consistent classifications support accurate reporting. Fraudsters and their enablers can exploit the same discipline. A bookkeeper cannot label a payment “bribe expense.” The payment still needs a code, description, vendor, amount, approver, account, and business purpose. If the scheme continues, the participants need a method they can repeat. That repetition creates a fingerprint.

Suspicious terms in payment descriptions and journal entries are among the most useful anti-corruption monitoring tests. His examples included phrases such as “friend fee,” “government payment,” and “miscellaneous.” The precise word will vary by company and geography. The analytical principle does not.

The company should identify unusual language, then connect it to the transaction behind it. Even if the language is not unusual, its repeated use might form a pattern worth exploring. A word cloud may provide a useful visual starting point. Keyword searches, natural-language processing, and risk dictionaries can scale the review across thousands of invoices and expense reports. Yet the purpose is not to find one forbidden word. It is to identify language that is unusual for the business, unusually frequent for one vendor, or correlated with a high-risk outcome. “Reinspection fee” was facially plausible. Repetition changed its meaning.

The First Test Was Hiding in Plain Sight

An elementary analytic (As in Elementary, my dear Watson) would have grouped customs-related payments by invoice description, vendor, amount, port, and frequency. That test could have asked:

  • How often does “reinspection fee” appear?
  • Which brokers submit the charge?
  • Is the amount repeatedly near $2,000?
  • Which employees approve it?
  • Does it appear only on trains with an inspection problem?
  • What happens to the shipment immediately after payment?

No single answer proves bribery. Together, the answers can create a compelling reason to investigate. The recurring round-dollar amount matters. Legitimate inspection costs often vary with the service, product, weight, time, port, or government fee schedule. A repeated $2,000 charge across multiple transactions may indicate a fixed unofficial tariff rather than the cost of a legitimate service.

The description also matters. If “reinspection fee” was not found in an approved government schedule, lacked official documentation, or appeared only in broker invoices rather than government receipts, the control should have required escalation before payment. Finally, the outcome matters most. If trains that failed inspection were consistently released after the fee, the company had more than an accounting anomaly. It had a payment linked to a favorable exercise of government discretion.

Connect the Payment to the Business Outcome

Traditional controls often examine whether an invoice matches a purchase order and whether an authorized employee approved it. A bribery scheme can satisfy both tests when employees are participating in the misconduct.

Data analytics must therefore test commercial substance, not merely procedural completion.

For Scoular Company, the decisive data model would connect five sources:

  • Inspection data: date, result, impurity identified, inspector, agency, and reinspection history.
  • Shipment data: train identifier, product, port, broker, delay, release time, and disposition.
  • Payment data: invoice description, amount, general-ledger account, supporting documents, approver, and payment date.
  • Third-party data: broker risk rating, contract terms, bank account, audit rights, ownership, and compensation history.
  • Communications data: relevant emails, WhatsApp records lawfully available to the company, and other business messages.

With those sources joined, compliance could test whether a $2,000 broker charge followed an adverse inspection and then by rapid release of the train. It could compare release rates for shipments with and without the payment. It could identify which brokers, ports, and employees produced unusually favorable clearance outcomes. That sequence is the analytic signature of the scheme: failed inspection, unusual payment, successful release.

Build a Layered Anti-Bribery Analytics Program

A mature program should not depend on one keyword or one dashboard. It should use several complementary tests.

Text analytics. Search invoice narratives, journal entries, purchase orders, and expense descriptions for high-risk terms, euphemisms, spelling variants, and unusual phrases. The risk dictionary should reflect the company’s markets and evolve with investigations.

Transaction analytics. Flag recurring round-dollar payments, duplicate or near-duplicate invoices, payments just below approval thresholds, split payments, weekend postings, manual journal entries, and charges lacking official receipts.

Vendor analytics. Compare customs brokers by fee frequency, payment descriptions, clearance rate, failed-inspection rate, use of subcontractors, changes in bank accounts, and concentration under particular employees or business units.

Outcome analytics. Test whether payments are statistically associated with permits, inspections, releases, tax outcomes, contract awards, or other favorable government actions. This moves the review from what the invoice says to what the payment accomplished.

Sequence analytics. Measure the time between an adverse event, a payment request, approval, payment, and favorable resolution. Short, repeated intervals can reveal a designed process.

Communications analytics. Where lawful and consistent with company policy, match high-risk transactions to messages about urgency, guarantees, officials, inspections, exceptions, or payments. A suspicious invoice can corroborate a message, and a message can explain the invoice.

Network analytics. Map relationships among employees, brokers, bank accounts, ports, approvers, and government touchpoints. Shared bank accounts, common addresses, unusual subcontractors, or recurring approval chains can expose concealed connections.

These tests should create ranked alerts, not automated accusations. Analytics identifies anomalies. Trained reviewers determine whether the transaction has a legitimate explanation, requires more evidence, or warrants an investigation.

Continuous Monitoring Is a Governance Choice

Walden’s closing advice was simple: keep innovating and keep running the analytics. The word “running” matters. As in continuously. A one-time review performed after a subpoena is forensic reconstruction. A risk-based test operating monthly, weekly, or at the point of payment is a compliance control.

Continuous monitoring does not mean surveillance of every employee or review of every transaction. It means that known high-risk processes receive repeatable testing at a frequency aligned with the risk. Customs payments, government-facing third parties, failed inspections, and manual financial entries deserve more attention than ordinary low-risk purchases.

The program also needs governance. Compliance and internal audit should agree on data ownership, alert thresholds, reviewer responsibilities, escalation standards, documentation, privacy requirements, and feedback loops. Finance must help validate legitimate payment patterns. The business must explain operational outcomes. Technology must maintain data quality and access. Legal must ensure that communications monitoring is lawful.

Most importantly, the board should ask whether compliance has direct access to the data. A dashboard built from incomplete information can create false assurance. If broker invoices sit in one system, inspection results in another, shipment releases in a third, and WhatsApp messages outside company retention, the organization sees fragments while the scheme operates across the seams.

Internal Controls Must Learn From Every Alert

Data analytics is not a substitute for internal controls. They supplement each other, as data analytics is a way to test whether those controls work and where they fail. An alert concerning a reinspection fee should trigger questions about official documentation, approved fee schedules, broker contracts, audit rights, segregation of duties, approval thresholds, and the economic rationale for the charge. If the review confirms misconduct, root-cause analysis should determine why the payment passed through accounts payable, why the broker remained active, why inspections and payment data were not connected, and whether incentives rewarded shipment clearance over compliance.

Every closed alert should improve the system. Confirmed concerns should add new keywords, vendor attributes, transaction patterns, and outcome measures. Legitimate transactions should help refine thresholds and reduce noise. This is how a compliance program becomes adaptive rather than static.

Questions for CCOs

CCOs should ask:

  • Which payment descriptions recur in our highest-risk government-facing processes?
  • Can we connect invoices to inspections, permits, customs outcomes, and shipment releases?
  • Which third parties generate unusually favorable results after unusual payments?
  • Are alert reviewers trained to investigate commercial substance, not merely paperwork?
  • How quickly does a confirmed issue change our controls and analytics?

The Bottom Line

Scoular Company’s bribery scheme did not require a sophisticated algorithm to detect. It required the company to notice a repeated phrase, a recurring amount, a high-risk broker, an adverse inspection, and a favorable government outcome. Walden’s lesson is that concealment often creates consistency, and consistency creates data. The task of compliance is to convert that data into a question early enough to matter.

Follow the words. Test the amount. Connect the outcome. Then channel your inner Sherlock Holmes and investigate what the pattern is telling you.

Categories
FCPA Compliance Report

FCPA Compliance Report: Matt Ellis Wrap-Up from Cartels, FTO Risk, and Corporate Compliance Conference

In this episode, Tom Fox welcomes back Matt Ellis of Miller & Chevalier to recap ACI’s inaugural two-day Cartel Conference in Washington, DC, highlighting an unusually collaborative, high-energy atmosphere around emerging cartel/TCO/FTO compliance risks in Latin America.

They discuss DOJ’s Scoular FCPA action as illustrating the long tail of enforcement and a high bar for managing cartel-related and national security risks, while noting the DPA’s remedial steps focus more on traditional anti-corruption controls than TCO/FTO-specific guidance. Government participants emphasized a “whole of government” approach, voluntary disclosure, and potential public-private engagement (including embassy attachés and Treasury) in high-risk scenarios. Key themes included narrow duress defenses, complex “imposter” risks, evolving due diligence beyond traditional screening using data/anomaly detection and local intelligence, and the need to integrate compliance across AML, sanctions, security, and supply chain given severe reputational and business consequences of terrorist or cartel support.

Key highlights:

  • Conference Vibe and Energy
  • Scoular FCPA Case Takeaways
  • When to Engage Government
  • Duress Defense and Safety Payments
  • Cartel-Focused Due Diligence
  • AML Lessons for Banks
  • Breaking Silos in Compliance
  • Parallels to Early FCPA Era
  • National Security Stakes

Resources:

ACI National FCPA and Global Anti-Corruption Conference, December 10-11 at the Gaylord National Resort & Convention Center, Washington, DC

Matt Ellis on LinkedIn

Tom Fox

Instagram

Facebook

YouTube

Twitter

LinkedIn

To learn about the intersection of Sherlock Holmes and the modern compliance professional, check out my latest book, The Game is Afoot-What Sherlock Holmes Teaches About Risk, Ethics and Investigations on Amazon.com.