Categories
Blog

The Scoular DPA Part 3: The Data Was Talking – Data Analytics and the Scoular Bribery Scheme

The Scoular Company bribery scheme was hidden, but it was not invisible. For six years, customs brokers paid Mexican officials approximately $2,000 per train so Scoular Company shipments could cross the border despite adverse inspections. The brokers invoiced the payments back to Scoular as “reinspection fees.” In total, Scoular Company admitted that it authorized $414,351 in bribes and avoided approximately $6.5 million in fees and costs. Those facts describe an FCPA violation. They also describe a data pattern.

I had the opportunity to visit with Vince Walden, CEO of KonaAI, about the Scoular Company FCPA enforcement action from a data analytics perspective. He identified the feature that should command every CCO’s attention: people concealing misconduct often record it consistently. They may avoid the word “bribe,” but they still need a repeatable description that allows the payment to be processed, reconciled, and found again. At Scoular Company, that description was “reinspection fee.”

Walden’s observation goes to the heart of modern compliance. Illegal conduct may be concealed from the compliance department while remaining visible in accounts payable, journal entries, invoices, purchase orders, shipment records, and communications. The control failure occurs when those systems hold the evidence, but the company never asks the data the right questions.

Consistency Can Become the Fraudster’s Fingerprint

Walden observed that accountants value consistency because consistent classifications support accurate reporting. Fraudsters and their enablers can exploit the same discipline. A bookkeeper cannot label a payment “bribe expense.” The payment still needs a code, description, vendor, amount, approver, account, and business purpose. If the scheme continues, the participants need a method they can repeat. That repetition creates a fingerprint.

Suspicious terms in payment descriptions and journal entries are among the most useful anti-corruption monitoring tests. His examples included phrases such as “friend fee,” “government payment,” and “miscellaneous.” The precise word will vary by company and geography. The analytical principle does not.

The company should identify unusual language, then connect it to the transaction behind it. Even if the language is not unusual, its repeated use might form a pattern worth exploring. A word cloud may provide a useful visual starting point. Keyword searches, natural-language processing, and risk dictionaries can scale the review across thousands of invoices and expense reports. Yet the purpose is not to find one forbidden word. It is to identify language that is unusual for the business, unusually frequent for one vendor, or correlated with a high-risk outcome. “Reinspection fee” was facially plausible. Repetition changed its meaning.

The First Test Was Hiding in Plain Sight

An elementary analytic (As in Elementary, my dear Watson) would have grouped customs-related payments by invoice description, vendor, amount, port, and frequency. That test could have asked:

  • How often does “reinspection fee” appear?
  • Which brokers submit the charge?
  • Is the amount repeatedly near $2,000?
  • Which employees approve it?
  • Does it appear only on trains with an inspection problem?
  • What happens to the shipment immediately after payment?

No single answer proves bribery. Together, the answers can create a compelling reason to investigate. The recurring round-dollar amount matters. Legitimate inspection costs often vary with the service, product, weight, time, port, or government fee schedule. A repeated $2,000 charge across multiple transactions may indicate a fixed unofficial tariff rather than the cost of a legitimate service.

The description also matters. If “reinspection fee” was not found in an approved government schedule, lacked official documentation, or appeared only in broker invoices rather than government receipts, the control should have required escalation before payment. Finally, the outcome matters most. If trains that failed inspection were consistently released after the fee, the company had more than an accounting anomaly. It had a payment linked to a favorable exercise of government discretion.

Connect the Payment to the Business Outcome

Traditional controls often examine whether an invoice matches a purchase order and whether an authorized employee approved it. A bribery scheme can satisfy both tests when employees are participating in the misconduct.

Data analytics must therefore test commercial substance, not merely procedural completion.

For Scoular Company, the decisive data model would connect five sources:

  • Inspection data: date, result, impurity identified, inspector, agency, and reinspection history.
  • Shipment data: train identifier, product, port, broker, delay, release time, and disposition.
  • Payment data: invoice description, amount, general-ledger account, supporting documents, approver, and payment date.
  • Third-party data: broker risk rating, contract terms, bank account, audit rights, ownership, and compensation history.
  • Communications data: relevant emails, WhatsApp records lawfully available to the company, and other business messages.

With those sources joined, compliance could test whether a $2,000 broker charge followed an adverse inspection and then by rapid release of the train. It could compare release rates for shipments with and without the payment. It could identify which brokers, ports, and employees produced unusually favorable clearance outcomes. That sequence is the analytic signature of the scheme: failed inspection, unusual payment, successful release.

Build a Layered Anti-Bribery Analytics Program

A mature program should not depend on one keyword or one dashboard. It should use several complementary tests.

Text analytics. Search invoice narratives, journal entries, purchase orders, and expense descriptions for high-risk terms, euphemisms, spelling variants, and unusual phrases. The risk dictionary should reflect the company’s markets and evolve with investigations.

Transaction analytics. Flag recurring round-dollar payments, duplicate or near-duplicate invoices, payments just below approval thresholds, split payments, weekend postings, manual journal entries, and charges lacking official receipts.

Vendor analytics. Compare customs brokers by fee frequency, payment descriptions, clearance rate, failed-inspection rate, use of subcontractors, changes in bank accounts, and concentration under particular employees or business units.

Outcome analytics. Test whether payments are statistically associated with permits, inspections, releases, tax outcomes, contract awards, or other favorable government actions. This moves the review from what the invoice says to what the payment accomplished.

Sequence analytics. Measure the time between an adverse event, a payment request, approval, payment, and favorable resolution. Short, repeated intervals can reveal a designed process.

Communications analytics. Where lawful and consistent with company policy, match high-risk transactions to messages about urgency, guarantees, officials, inspections, exceptions, or payments. A suspicious invoice can corroborate a message, and a message can explain the invoice.

Network analytics. Map relationships among employees, brokers, bank accounts, ports, approvers, and government touchpoints. Shared bank accounts, common addresses, unusual subcontractors, or recurring approval chains can expose concealed connections.

These tests should create ranked alerts, not automated accusations. Analytics identifies anomalies. Trained reviewers determine whether the transaction has a legitimate explanation, requires more evidence, or warrants an investigation.

Continuous Monitoring Is a Governance Choice

Walden’s closing advice was simple: keep innovating and keep running the analytics. The word “running” matters. As in continuously. A one-time review performed after a subpoena is forensic reconstruction. A risk-based test operating monthly, weekly, or at the point of payment is a compliance control.

Continuous monitoring does not mean surveillance of every employee or review of every transaction. It means that known high-risk processes receive repeatable testing at a frequency aligned with the risk. Customs payments, government-facing third parties, failed inspections, and manual financial entries deserve more attention than ordinary low-risk purchases.

The program also needs governance. Compliance and internal audit should agree on data ownership, alert thresholds, reviewer responsibilities, escalation standards, documentation, privacy requirements, and feedback loops. Finance must help validate legitimate payment patterns. The business must explain operational outcomes. Technology must maintain data quality and access. Legal must ensure that communications monitoring is lawful.

Most importantly, the board should ask whether compliance has direct access to the data. A dashboard built from incomplete information can create false assurance. If broker invoices sit in one system, inspection results in another, shipment releases in a third, and WhatsApp messages outside company retention, the organization sees fragments while the scheme operates across the seams.

Internal Controls Must Learn From Every Alert

Data analytics is not a substitute for internal controls. They supplement each other, as data analytics is a way to test whether those controls work and where they fail. An alert concerning a reinspection fee should trigger questions about official documentation, approved fee schedules, broker contracts, audit rights, segregation of duties, approval thresholds, and the economic rationale for the charge. If the review confirms misconduct, root-cause analysis should determine why the payment passed through accounts payable, why the broker remained active, why inspections and payment data were not connected, and whether incentives rewarded shipment clearance over compliance.

Every closed alert should improve the system. Confirmed concerns should add new keywords, vendor attributes, transaction patterns, and outcome measures. Legitimate transactions should help refine thresholds and reduce noise. This is how a compliance program becomes adaptive rather than static.

Questions for CCOs

CCOs should ask:

  • Which payment descriptions recur in our highest-risk government-facing processes?
  • Can we connect invoices to inspections, permits, customs outcomes, and shipment releases?
  • Which third parties generate unusually favorable results after unusual payments?
  • Are alert reviewers trained to investigate commercial substance, not merely paperwork?
  • How quickly does a confirmed issue change our controls and analytics?

The Bottom Line

Scoular Company’s bribery scheme did not require a sophisticated algorithm to detect. It required the company to notice a repeated phrase, a recurring amount, a high-risk broker, an adverse inspection, and a favorable government outcome. Walden’s lesson is that concealment often creates consistency, and consistency creates data. The task of compliance is to convert that data into a question early enough to matter.

Follow the words. Test the amount. Connect the outcome. Then channel your inner Sherlock Holmes and investigate what the pattern is telling you.

Categories
Blog

The Scoular DPA: Part 2 – A Journey Through Non-Disclosure

The Scoular Company Deferred Prosecution Agreement (DPA) presents a difficult but essential lesson for every Chief Compliance Officer and board: stopping misconduct is not the same as voluntarily disclosing it. This might seem as self-evident as anything in compliance, but it is a critical component of this case.

The Statement of Facts says that internal reports alleging improper business practices connected to the Mexican inspection fees arose in 2019. Scoular then changed its grain-shipment practices and terminated its direct engagement with the customs brokers involved. Those steps addressed the immediate conduct. They did not produce voluntary self-disclosure credit. That misstep cost Scoular Company millions, potentially leading to a full declination.

The DPA states that Scoular did not receive credit under the DOJ Corporate Enforcement and Voluntary Self-Disclosure Policy (VSP) because it did not “voluntarily and timely disclose” the conduct to the Fraud Section. That single sentence creates the central governance question in Blog Post Part 2: What must happen after a credible internal report reaches the company? An internal allegation starts an investigative clock. The company must preserve evidence, protect against retaliation, assess immediate risk, and establish enough facts to make responsible decisions. It also starts a disclosure clock.

The VSP encourages companies to report potential wrongdoing at the earliest possible time, even before an internal investigation is complete. To qualify as a voluntary self-disclosure, a report must be made in good faith to the appropriate DOJ component, concern misconduct not already known to the Department, occur without a preexisting disclosure obligation, precede an imminent threat of disclosure or government investigation, and be made within a reasonably prompt time after the company becomes aware of the misconduct.

The burden of demonstrating timeliness rests with the company. This does not mean a company must call the DOJ the moment an untested allegation enters the hotline. It does mean disclosure cannot wait until every interview, legal conclusion, and remediation project is complete. The investigation and disclosure analyses must proceed together.

The DPA Tells Us the Result, Not the Internal Debate

The agreement does not explain who received the 2019 reports, how the allegations were investigated, when senior management or the board learned of them, or why Scoular did not make a qualifying disclosure. It does not tell us whether the company made a deliberate decision not to report. What the DPA does establish is the outcome. Internal reports arose. The company changed its practices and terminated direct broker relationships. The company did not voluntarily and timely disclose the conduct to the Fraud Section and therefore received no voluntary disclosure credit.

That sequence is enough to demonstrate a control lesson. A company can remediate an operational problem and still leave the enforcement decision unresolved. The response requires four distinct workstreams:

  • Stopping the conduct prevents additional harm.
  • Investigating the conduct determines what happened and which controls failed.
  • Remediating the controls reduces recurrence risk.
  • Evaluating disclosure determines whether, when, where, and how the company should approach enforcement authorities. This fourth step is arguably the most important and must be reached with great speed, perhaps as little as two weeks after initial determination.

A Disclosure Needs a Decision Process

Disclosure decisions should not depend on one executive’s instinct or on the hope that remediation will close the matter. The company needs a defined escalation structure involving legal, compliance, internal audit, finance, and appropriate senior management. Depending on the seriousness of the facts, the audit committee or another independent board committee may need to oversee the decision.

For an FCPA matter involving customs brokers, repeated payments, government officials, inaccurate invoice descriptions, senior personnel, and multiple years of conduct, the disclosure analysis should address:

  • What credible facts are known now?
  • Is the misconduct continuing?
  • Which individuals and third parties may be involved?
  • Are the books and records inaccurate?
  • Is there evidence of management participation, approval, condonation, or willful ignorance?
  • Has a whistleblower, auditor, regulator, bank, business partner, or foreign authority already received the same information?
  • Is there an imminent threat that the DOJ will learn of the conduct?
  • What additional facts are necessary to make a disclosure decision?
  • When will the decision be revisited?
  • Who has authority to decide, and how will the reasoning be documented?

The objective is not to create a paper defense for a predetermined result. It is to establish a disciplined process that forces the company to confront timing, uncertainty, accountability, and enforcement exposure.

Disclosure Does Not Require a Finished Investigation

One reason companies may delay is the understandable fear of reporting facts that are incomplete or later prove wrong. The DOJ policy addresses that concern directly. It encourages early disclosure even when the company has not completed its internal investigation. The company can report the misconduct known at that stage, identify the limits of its current knowledge, preserve credibility by avoiding unsupported conclusions, and provide rolling updates as the investigation develops.

That approach requires discipline. The initial disclosure should distinguish facts from allegations, describe preservation and remediation steps, and explain the investigative plan. Later presentations should attribute facts to specific sources and identify individuals regardless of seniority.

Waiting for certainty can eliminate the benefit the company hoped to secure. A whistleblower may contact the government, a third party may cooperate, or the payment may surface in another investigation. Once the DOJ already knows or disclosure is imminent, the analysis changes. The business lesson is straightforward. Uncertainty calls for a staged disclosure strategy, not an indefinite pause.

Cooperation Still Mattered

Scoular Company lost the disclosure benefit, but the DPA demonstrates that the company could still earn meaningful credit. The DOJ credited Scoular with conducting an internal investigation, making detailed factual presentations, identifying individuals involved, producing and organizing requested materials, securing counsel for current employees, and providing all relevant facts known to it.

Voluntary self-disclosure, cooperation, and remediation are separate pillars. A company that misses the first can still create value through the other two. The DPA also notes “certain deficiencies in the early part of the investigation.” It does not identify those deficiencies, and they should not be guessed. Their inclusion nevertheless sends a message: cooperation is judged across the life of the investigation, not merely by the quality of the final presentation.

The current DOJ policy makes the standard explicit. A company starts at zero cooperation credit and earns credit through specific actions: scope, quality, impact, and timing matter. A failure to cooperate fully at the earliest opportunity may reduce the credit available later. For CCOs and boards, the lesson is that recovery remains possible, but delay has a price.

Remediation Changed How the Business Operated

Scoular also received credit for substantial remediation. The company increased compliance engagement with the business, used external compliance maturity and anti-corruption risk assessments, restructured the compliance function, and incorporated senior leadership oversight. It eliminated customs brokers associated with reinspection fees, strengthened risk-based review and monitoring with software tools, revised policies, enhanced third-party screening and approvals, added anti-corruption and audit-right provisions to contracts, improved financial controls for high-risk transactions, and delivered general and targeted training.

These measures went beyond terminating vendors. They addressed governance, third-party management, payment controls, monitoring, technology, policies, and training. That breadth matters because remediation must be tied to root cause. If the misconduct was enabled by commercial pressure, broker dependence, misleading invoices, weak transaction validation, and fragmented data, another annual training course will not solve the problem.

The Economic Difference Was Significant

Scoular entered into a three-year DPA and agreed to pay a $9,769,521 criminal penalty and $414,351 in forfeiture. The DPA states that the penalty reflected a 25 percent reduction from the applicable low-end amount. A footnote explains that the statutory alternative-fine cap, based on twice the approximately $6.513 million gross gain, constrained the otherwise higher Guidelines minimum.

The DPA does not say what disposition Scoular would have received after a qualifying disclosure. It would be improper to rewrite the resolution with hypothetical facts.

The current department-wide CEP nevertheless shows why the distinction matters. A company that voluntarily self-discloses, fully cooperates, timely remediates, and has no disqualifying aggravating circumstances is placed on a declination path. A good-faith self-report that narrowly misses the policy’s technical requirements can still lead to an NPA, a term shorter than three years, no monitor, and a reduction of 50 to 75 percent from the low end. Companies outside those paths remain subject to prosecutorial discretion, with a reduction capped at 50 percent.

Scoular received a DPA, a three-year term, and a 25 percent reduction. The numbers turn disclosure governance into a business issue. The decision affects resolution form, penalty exposure, duration, oversight, reputation, management time, and the company’s ability to move beyond the misconduct.

Questions for CCOs

CCOs should ask:

  • Does every credible allegation involving government payments trigger a documented disclosure analysis?
  • Who owns the disclosure clock while the investigation proceeds?
  • Can legal and compliance make an early report without waiting for a completed investigation?
  • Are facts, assumptions, open questions, and decision deadlines documented separately?
  • Have we tested the process through a tabletop exercise involving a whistleblower, a third party, and an imminent government inquiry?

The Scoular DPA does not establish why the company missed voluntary disclosure credit. It does establish that internal reporting, operational remediation, and voluntary disclosure are not interchangeable. When a credible allegation arrives, the company must stop the conduct, investigate the facts, remediate the controls, and make a timely, documented disclosure decision. Doing three of those four things can still leave substantial value on the table.

Join us tomorrow for Part 3, where we will examine how a robust internal control system paired with a robust data analytics overview can help a company avoid a Scoular Company-type series of failures.

Categories
Blog

The Scoular DPA: Part 1 – From Suelo to the Bribery System at Scoular

My earlier analysis of The Scoular Company FCPA enforcement action necessarily relied on the Department of Justice Press Release. That release described the government’s allegations. The formal Deferred Prosecution Agreement (DPA) expands the footing of the discussion. We are no longer working only from a prosecutor’s summary. We now have a detailed chronology of facts the company formally admitted.

Those facts reveal a scheme connecting stricter Mexican inspections, commercial pressure, employees, multiple customs brokers, a meeting at a company office, invoices, wire payments, WhatsApp, and millions in avoided costs. The central compliance lesson is normalization. A corrupt proposal became a repeatable business process. Over the next four blog posts, I will be taking a deep dive into the DPA, what it tells us, and what we must speculate on.

The Scheme Began With a Change in Enforcement

Scoular transported corn and other agricultural products from the United States into Mexico. Those trains were inspected by Mexico’s Secretariat of Agriculture and Rural Development, referred to in the DPA by its former name, SAGARPA.

Inspectors looked for dirt, soil, and other impurities, sometimes described as “suelo.” SAGARPA approval was required before a train could enter Mexico. When inspectors detected suelo, the agency could delay entry, and the shipment could incur fumigation and demurrage costs.

Beginning around 2013, Mexican authorities conducted the inspections more rigorously. The result was more soil findings in Scoular shipments and greater exposure to delay, fumigation, and demurrage. This legitimate business problem called for better product controls and contingency planning. It also created pressure that made a corrupt alternative attractive.

Compliance failures often begin here. Regulation becomes more rigorous, costs increase, and delivery commitments are threatened. The governance question is whether management improves the process or finds a way around the control. This demonstrates why a continuous risk assessment is so critical; when your risks change, you need to perform an updated risk assessment.

The Proposal Was a Guarantee Against Adverse Decisions

In June 2013, customs broker Carlos Leopoldo Alvelais contacted a Scoular sales employee and a Scoular senior manager. According to the DPA, he proposed a procedure under which Scoular would pay a fee on every train. The purpose was not ambiguous. The proposal was designed to ensure that Scoular would “not have a single risk of adverse determinations from Mexican inspectors.” That sentence captures the scheme.

A legitimate broker can prepare documents, coordinate an inspection, and challenge an incorrect result. It cannot guarantee that a regulated company will never receive an adverse decision. A promise of zero regulatory failure should be treated as a red flag, not a service level. James Min made this clear with his risk matrix for assessing risk in customs broker clearance rates. If a customs broker offers you a 100% success rate – to quote Monty Python from The Holy Grail: Run Away Run Away, do not walk away.

The DPA says that, later in June 2013, Alvelais traveled to Scoular’s Kansas office and met with Scoular employees and others. After that meeting, he began paying bribes to Mexican officials and invoicing Scoular for reimbursement. The invoices described the payments as “REVISION SAGARPA PROCESS” (Reinspection Fees herein), generally in round amounts of $2,000.

The Kansas meeting is a significant new fact. The arrangement was not confined to an informal exchange between a local employee and a broker at a remote border crossing. The broker presented the approach at a company office. After the meeting, the payments began. This speaks to a serious failure in an overall compliance program: failure in communication, failure in training, failure in risk assessments, failure in internal controls, and failure in overall compliance visibility into the business operations of an organization it is supposed to keep in compliance.

At a minimum, when a high-risk third party visits a company office to propose a government-facing payment process, the arrangement should require a documented business rationale, legal and compliance review, a payment protocol, and supporting evidence. Without those controls, the meeting can move misconduct into the company’s operating structure. This basic failure led to catastrophe for Scoular Company.

The Payment Process Was Replicated

The DPA places a sales employee and a senior manager who worked on international grain sales and shipments at the center of the conduct. They authorized reimbursement of Reinspection Fees to Alvelais and his companies while knowing that at least part of the money would be used to bribe Mexican border officials. The objective was to ensure that Scoular trains passed inspection without the fumigation, demurrage, and other costs associated with soil findings and failed inspections.

But it got worse from there. Scoular then replicated the approach with two other customs brokers. That replication is critical. This was not simply a broker corrupting a customer. Company personnel took a method used with one broker and extended it to additional agents. The model followed the business.

The DPA describes cash payments of up to $2,000 per train. Scoular employees and agents coordinated the scheme through email, messaging applications, and other communications. Invoices were transmitted, and Scoular caused payments to be made by wire. The scheme therefore had all the components of a functioning process:

  • A recurring commercial problem
  • A third-party payment mechanism
  • Employee knowledge and authorization
  • Multiple participating brokers
  • Standard invoice descriptions
  • Company reimbursement
  • Off-channel and conventional communications
  • A measurable business benefit

Each component could look ordinary when reviewed separately. Together, they formed the bribery scheme.

The Communications Made the Purpose Clear

The admitted communications are especially instructive because they connect payment, knowledge, and outcome. In August 2015, an Alvelais employee informed a Scoular employee that inspectors had detected soil in a train. The train was nevertheless released without delay, and the account would include a $2,000 charge. In October 2015, a Scoular employee sent a WhatsApp message to the senior manager stating that Alvelais would provide a favorable rate and guarantee that no train headed to a particular buyer would be stopped for soil. Another October 2015 communication listed “Dispatch of merchandise in the presence of soil” at $2,000 per shipment.

Later that month, a Scoular employee reported that the broker was doing everything possible to move a shipment, but an inspector’s supervisors were in town and “normal procedures” were not working. By 2018, the language was even more direct. During an exchange concerning pests detected in a shipment, an Alvelais employee wrote that the broker had offered more than it normally gave and the officials had not accepted it. A Scoular employee responded by asking why the broker was requesting double if the issue was fixed for soil.

These communications defeat any claim that employees believed they were paying published government fees. They describe adverse findings, guarantees against stopped trains, and payments beyond ordinary amounts. No single record tells the complete story. The invoice supplies the accounting description, the message supplies intent, the inspection record supplies the regulatory event, and the release time supplies the outcome. Investigations and monitoring must connect all four.

The Scheme Continued Into 2019

The DPA identifies three invoices from 2019:

  • A $3,000 “SAGARPA process” fee from an Alvelais company
  • A $1,750 “Other Inspection” fee from a second customs broker
  • A 35,000 Mexican peso “SERVICIOS DE SAGAR” fee, approximately $1,835, from a third customs broker

Scoular promptly paid each invoice.

The changing descriptions are a lesson in internal control design. A monitoring rule limited to “reinspection fee” would have missed “SAGARPA process,” “Other Inspection,” and “SERVICIOS DE SAGAR.” Compliance analytics must identify families of risk, not merely exact words.

The DPA says that internal reports alleging improper business practices connected to the SAGARPA fees arose in 2019. Scoular then changed its practices for grain shipments into Mexico and terminated direct engagement with the customs brokers involved.

That response ended the factual chronology, but it opens the next compliance question: what happened between the internal reports and the DOJ resolution, and why did Scoular receive no voluntary self-disclosure credit? That will be the focus of Part 2.

The Economics Show Why the Scheme Endured

Between approximately 2015 and 2019, Scoular authorized $414,351 in bribes to bypass inspections and secure unhindered passage into Mexico. The company avoided approximately $6,513,014 in demurrage and related costs. That is more than $15 in avoided costs for every dollar paid in bribes.

The ratio does not excuse the conduct. It explains the incentive that allowed it to become embedded. A $2,000 charge could appear small against the cost of a delayed train, while the accumulated benefit rewarded the business process that produced the misconduct. This is why compliance cannot evaluate customs payments only by individual transaction value. The relevant indicators include frequency, round amounts, timing, inspection outcome, avoided cost, broker success rate, and management awareness.

The Compliance Failure Was Normalized

The Scoular Statement of Facts shows how misconduct can become ordinary:

  • External enforcement became more rigorous.
  • The business faced higher costs and delays.
  • A broker proposed a fee-based solution.
  • The broker met with employees at a company office, and payments followed.
  • Brokers paid officials and invoiced Scoular.
  • Employees authorized reimbursement.
  • The approach expanded to other brokers.
  • Messages and invoices developed a shared vocabulary.
  • The business received predictable passage and high avoided costs.
  • The process continued until internal reports surfaced.

The DPA does not describe a control that failed once. It describes an alternative control environment that operated for years.

The DPA sharpens the Scoular lesson. The scheme was not simply a series of border bribes. It was a business process built to eliminate the risk of adverse government decisions. When a third party offers that result, compliance should assume the risk has not disappeared. It has merely been transferred into a payment, an invoice, and a promise that deserves immediate scrutiny.

Join us tomorrow, where we take a deep dive into the Scoular Company’s failure to self-disclose and the long-term ramifications.

Categories
Compliance Into the Weeds

Compliance into the Weeds: Scoular Company FCPA Settlement: Cartel Links, Border Trade Risks, and Compliance Lessons

The award-winning Compliance into the Weeds is the only weekly podcast that takes a deep dive into a compliance-related topic, literally going into the weeds to explore it more fully. Looking for some hard-hitting insights on compliance? Look no further than Compliance into the Weeds! In this episode of Compliance into the Weeds, Tom Fox and Matt Kelly discuss the recent FCPA resolution with the Scoular Company. Both Tom and Matt have blogged on this matter, so check out the Resources link below for additional discussions.

The recent FCPA enforcement action against Scoular Company involved a $10.2 million payment and a three-year deferred prosecution agreement over bribes by third-party customs brokers to Mexican border officials to expedite cross-border shipments. DOJ emphasized alleged cartel connections, including a strong statement from the U.S. Attorney for the Western District of Texas, which raised questions about expanded local U.S. attorney involvement and how cartel or potential FTO designations could heighten trade and compliance risks. The company received no voluntary self-disclosure credit but got a 25% discount, with remediation cited (including dropping brokers and strengthening tone at the top). They highlight off-channel WhatsApp use, the lack of released key documents (DPA, statement of facts, criminal information), and practical compliance takeaways on third-party oversight, data analytics, and risk assessments.

Resources:

Matt in Radical Compliance

Tom in FCPA Compliance and Ethics Blog

Tom

Instagram

Facebook

YouTube

Twitter

LinkedIn

A multi-award-winning podcast, Compliance into the Weeds was most recently honored as one of the Top 25 Regulatory Compliance Podcasts, a Top 10 Business Law Podcast, and a Top 12 Risk Management Podcast. Compliance into the Weeds has been conferred the Davey, Communicator, and W3 Awards, all for podcast excellence.

Categories
Blog

Scoular’s $10 Million FCPA Resolution: Compliance Lessons Learned

We conclude our review of the Scoular Company FCPA enforcement action with a full lessons-learned blog post. We are still awaiting the DPA and Criminal Information, so the details of the case come from the Department of Justice (DOJ) Press Release.

A $2,000 payment can disappear inside a global supply chain. Repeated, train-by-train, authorized by employees, routed through customs brokers, discussed on WhatsApp, disguised as a “reinspection fee,” and reimbursed for six years, it becomes an operating model. That is the central lesson from The Scoular Company Foreign Corrupt Practices Act resolution.

The DOJ announced that Scoular Company would pay more than $10 million to resolve an investigation into bribes paid to Mexican officials between 2013 and 2019. The company entered into a three-year deferred prosecution agreement, agreed to a $9,769,521 criminal penalty and $414,351 in forfeiture, and accepted continuing cooperation, compliance, and reporting obligations.

Across this blog post series, we examined four dimensions of the case: customs brokers and payment controls, cartel and national-security risk, off-channel communications, and the facilitating-payments exception. Read together with my podcast conversation with Matt Ellis, they reveal a single conclusion. Compliance must follow the complete transaction, from the business pressure that creates the payment to the third party that delivers it, the message that authorizes it, the invoice that conceals it, and the ultimate recipient who benefits.

The Scheme Hid in Plain Sight

According to the DOJ, Scoular Company relied on customs brokers to move corn and other agricultural products from the United States into Mexico. Mexican authorities inspected the shipments for dirt, soil, and other impurities. When inspections identified problems, Scoular Company employees directed brokers to pay officials approximately $2,000 per train so the shipments could cross the border. The brokers invoiced the payments back to Scoular Company as “reinspection fees,” and Scoular paid them. In total, the company authorized more than $400,000 in bribes and avoided more than $6.5 million in fees and costs.

The invoice description is the first major lesson. “Reinspection fee” sounded like it was connected to a legitimate customs process. Yet an accounts-payable control that merely matches an approved vendor, purchase order, and plausible service description tests paperwork, not substance.

Effective payment controls should require the company to identify the government agency involved, match the charge to a specific shipment and inspection, compare the amount with an official fee schedule, obtain proof of service, confirm the payee, and document the business justification. Repeated round-dollar charges, unusual success rates, rapid clearance after special payments, and fees unsupported by government records should trigger review.

Follow the money, measure the time, and test the outcome. That is how ordinary transaction data becomes an anti-corruption control.

A Licensed Broker Is Still a High-Risk Third Party

Customs brokers should never be treated as low-risk administrative providers simply because they are licensed or legally required. They interact with government officials, operate under commercial pressure, and can impose charges that distant finance personnel cannot easily verify.

Initial due diligence remains necessary, but it is only the beginning. Companies must connect screening, contracting, invoice testing, transaction monitoring, recertification, training, audit rights, and offboarding. The real test is not whether the third-party file was complete on the day of onboarding. It is whether the company understands how the broker behaves after the contract is signed.

The DOJ credited Scoular Company with eliminating brokers associated with the Mexican reinspection payments, strengthening risk-based screening and approvals, adding anti-corruption and audit-rights provisions, revising controls for high-risk transactions, and using software tools to improve monitoring. That remediation changed the operating model rather than merely revising a policy.

Cartel Risk Changes the Compliance Perimeter

The most consequential part of the DOJ announcement may be its national-security framing. The government determined that, without Scoular Company or its employees knowing it, a portion of the bribes benefited persons associated with a cartel’s criminal operations at the U.S.-Mexico border.

U.S. Attorney Justin R. Simmons stated that American companies engaged in cross-border trade bear responsibility for operating without benefiting cartels or threatening national security. Ellis challenged the literal breadth of the statement during our podcast discussion. Legitimate trade crosses the border every day without companies knowingly paying cartels. Nevertheless, he agreed that the statement signals a more demanding compliance environment.

Ellis explained that the cartel and transnational criminal organization risk is broader than the traditional FCPA risk. Anti-corruption diligence often concentrates on government touchpoints and intermediaries. Organized crime may be hidden inside transportation providers, suppliers, customers, labor relationships, security services, subcontractors, and local routes.

Traditional database screening may not reveal those connections. Ellis emphasized contextual diligence: speak with employees on the ground, examine local security concerns, understand regional criminal activity, investigate facts that do not add up, and adjust operations when warning signs emerge. Companies do not need perfect knowledge. They need a documented story of reasonable measures, credible escalation, and risk-based decisions.

The practical consequence is an integrated risk assessment. Anti-corruption, sanctions, anti-money laundering, trade compliance, physical security, supply chain, and third-party risk cannot remain in separate silos when the same payment may touch all of them.

WhatsApp Was Part of the Control Environment

The DOJ said Scoular Company employees communicated about shipments and bribes through WhatsApp and other means. WhatsApp was therefore not a side issue. It allegedly carried the knowledge and direction behind transactions later recorded as legitimate reinspection charges.

An informal application becomes a business system when employees use it to direct third parties, approve payments, or resolve customs problems. Enterprise controls can be bypassed when the substantive decision occurs in a private chat, and the formal system records only the sanitized result.

Ellis noted that a complete WhatsApp ban may be unrealistic in Latin America. The better approach is to map actual use and define what may occur on each platform. Logistical coordination may be permitted. Government interactions, payment approvals, contractual commitments, and exceptions should remain in controlled systems with retention and audit trails.

Companies must also be able to preserve and retrieve business communications lawfully from company and personal devices. Policies should address device replacement, departing employees, legal holds, privacy and employment requirements, refusal of access, and consistent discipline. The decisive question is not whether a policy exists. It is whether the company can obtain the evidence when an investigation begins.

Why These Were Not Facilitation Payments

The $2,000 amount and the customs setting may tempt employees to use the phrase “facilitation payment.” That label does not fit. The FCPA’s narrow exception covers payments intended to expedite routine, nondiscretionary governmental action that the payer is already entitled to receive. Scheduling an inspection may be routine. Paying an official to disregard a failed inspection is not.

The Scoular Company payments allegedly changed the result. The shipments had identified impurities, and the payments allowed trains to cross despite those findings. The company received a substantial business advantage by avoiding more than $6.5 million in costs. A facilitation payment is not defined by size, local custom, commercial urgency, or invoice terminology. A third party cannot create an exception unavailable to the principal. Nor does an anti-bribery exception excuse false accounting. Even a qualifying payment must be accurately recorded and supported by adequate internal controls.

Ellis’s discussion of extortion reinforces the operational lesson, although extortion and facilitation are distinct doctrines. One or two emergency payments may present a different analysis from a chain of payments continuing over years. Repetition transforms an asserted accommodation into a business process. Companies must respond by escalating, rerouting, changing providers, investigating, and remediating.

Cooperation Still Matters

Scoular Company did not receive voluntary self-disclosure credit because it did not report the conduct to the DOJ in a timely manner. It did receive cooperation credit for its internal investigation, factual presentations, identification of involved individuals, production and organization of evidence, and provision of counsel for current employees, despite early deficiencies.

The resulting criminal penalty reflected a 25 percent reduction from the bottom of the applicable sentencing guidelines range. The lesson is straightforward. Missing the voluntary disclosure window does not render later cooperation irrelevant, but cooperation is not a substitute for timely self-disclosure. The Scoular Company resolution is not four separate compliance stories. It is one story about how pressure, third parties, communications, accounting, and emerging national-security risks converged inside an ordinary business process.

The enduring lesson is equally integrated: know the broker, validate the payment, preserve the message, understand the route, and test the outcome. That is how compliance moves from policy to proof.

Categories
Blog

The $2,000 Question: Why Scoular’s Bribes Were Not Facilitation Payment

We continue our exploration of the Scoular FCPA enforcement action. We are still awaiting the DPA and Criminal Information, so the details of the case are based on the Department of Justice (DOJ) Press Release. Today we take up a topic little commented on anymore, but this enforcement action provides an opportunity to discuss, review, and explore facilitation payments.

The phrase “facilitation payment” is one of the most dangerous phrases in anti-corruption compliance. It sounds technical. It sounds modest. It can make an improper payment appear to be a recognized cost of moving goods through a difficult market. When a customs broker says that a small payment is necessary to get a train across the border, the business may hear urgency, local custom, and operational necessity.

The Foreign Corrupt Practices Act hears a different question: Was the official merely being paid to perform a routine act that the company was already entitled to receive, or was the payment intended to change the official’s decision and secure an improper business advantage? That distinction resolves the issue in The Scoular Company enforcement action.

According to the Department of Justice, Mexican inspections found dirt, soil, and other impurities in Scoular shipments. Scoular employees then directed customs brokers to pay Mexican officials approximately $2,000 per train so the shipments would cross the border despite those findings. The brokers invoiced the payments back to Scoular as “reinspection fees.” The alleged payments did not accelerate a routine action. They changed the result of an inspection. That is why the facilitation payments exception does not apply.

The Exception Is Narrow by Design

The original 1977 FCPA excluded payments for duties that were essentially ministerial or clerical. Congress revised the statute in 1988 and defined the modern exception for facilitating or expediting payments made to secure the performance of “routine governmental action.”

The statute gives examples:

  • Obtaining permits, licenses, or other official documents needed to do business
  • Processing government papers such as visas and work orders
  • Providing police protection or mail service
  • Scheduling inspections connected with contract performance or the transit of goods
  • Providing telephone, power, or water service
  • Loading and unloading cargo
  • Protecting perishable products from deterioration

The list can mislead a hurried business employee. Inspections and cargo appear in the statute. Scoular involved inspections and cargo. That superficial similarity is not enough. Congress expressly excluded decisions about awarding new business or continuing business with a particular party. The core principle is that routine governmental action does not include discretionary decisions that are the functional equivalent of obtaining or retaining business or securing an improper advantage. The exception is about speeding up the official’s performance of an existing duty. It is not about purchasing a favorable decision.

What a Facilitation Payment Is

A true facilitation payment has four characteristics.

  1. Routine. The governmental act is routine. The official performs it in the ordinary and customary manner. The act does not require a substantive judgment about whether the company has met a legal or regulatory standard.
  2. Entitled. The payer is already entitled to the action. The official has no lawful basis to deny the service. The payment changes timing, not entitlement.
  3. No Discretion. The official exercises no meaningful discretion. The official may control the pace of processing, but not the substantive outcome.
  4. Intent. The purpose is to expedite performance. It is not to influence an official to ignore a violation, reverse an adverse decision, waive a requirement, or confer a competitive advantage.

Consider the difference between scheduling an inspection and passing one. A small payment to move an inspection request from an ignored pile into the ordinary scheduling process may fall within the statutory language, subject to all the other legal and policy risks. A payment to persuade the inspector to overlook contamination does not. The first payment seeks action. The second purchases an outcome.

What a Facilitation Payment Is Not

A facilitation payment is not defined by amount. The FCPA contains no safe harbor for $20, $200, or $2,000. A small bribe remains a bribe when its purpose is to influence discretion. It is not defined by local custom. “Everyone pays it” is evidence of a risk of corruption, not a legal defense. It is not defined by urgency. Perishable goods, demurrage, customer demands, and production interruptions can create enormous pressure. Commercial pressure does not convert a discretionary government decision into a ministerial act.

The name on the invoice does not define it. “Reinspection fee,” “expediting charge,” “special handling,” and “administrative support” are descriptions. Compliance must determine what the money was actually used for. It is not created because a third party made the payment. The FCPA reaches indirect payments and authorizations through agents. A customs broker cannot manufacture an exception that the principal could not claim directly. Finally, it is not a blanket authorization for customs payments. Customs functions combine routine processing with significant official discretion. Scheduling an inspection may be routine. Deciding that contaminated goods can enter the country is not.

Apply the test to Scoular

The DOJ’s allegations make the application straightforward.

The shipments had failed a substantive condition

Mexican law subjected the agricultural shipments to inspection for dirt, soil, and other impurities. According to the DOJ, inspections found those conditions. The company was therefore not waiting for an official to perform a duty it had already satisfied. It faced an adverse regulatory result.

The payments changed the outcome

The brokers allegedly paid officials to ensure that the trains crossed despite the inspection findings. That is the exercise of official discretion. The payments were not made merely to schedule or complete a reinspection. They allegedly caused officials to permit entry notwithstanding the problem.

The company obtained a substantial business benefit

The DOJ said Scoular authorized more than $400,000 in bribes and avoided more than $6.5 million in fees and costs. The benefit was not faster paperwork alone. It was the avoidance of consequences associated with shipments that did not satisfy inspection requirements. That economic reality matters. A payment that yields more than $16 in avoided costs per dollar spent looks less like clerical acceleration and more like a mechanism for obtaining an improper advantage.

The conduct was repeated and organized

The scheme allegedly continued from 2013 through 2019 and involved multiple customs brokers. Scoular employees directed the payments, discussed them via WhatsApp and other channels, and paid the brokers’ reimbursement invoices.

In my podcast with Matt Ellis of Miller & Chevalier, Ellis addressed repeated payments in the related context of extortion. He explained that one or two emergency payments may present a different analysis, but a chain of payments over time makes reliance on a defense far more difficult. Extortion and facilitation payments are distinct legal doctrines. Still, Ellis’s practical point applies with full force here. Repetition changes the compliance story. A recurring payment is not an emergency response. It becomes part of the operating model.

The invoices did not call the payments what they were

The brokers allegedly invoiced the bribes as reinspection fees. Even a payment that qualifies for the narrow anti-bribery exception must be accurately reflected in an issuer’s books and records. The exception is not permission to conceal the true nature of an expenditure. This creates a central compliance paradox. Employees may resist recording a “facilitation payment to customs official” because the description raises legal, ethical, and local-law concerns. They may then use a vague or misleading account description, creating separate books and records and internal control risks. The invoice label in Scoular did not solve the problem. It became evidence of it.

Do Not Confuse Facilitation With Extortion

Companies must also distinguish the facilitation-payments exception from an extortion or duress analysis. A facilitation payment concerns the nature of the governmental action. Was it routine and nondiscretionary? Extortion concerns coercion. Was an individual facing a genuine threat to life, health, safety, or liberty? Ordinary economic pressure, such as delay costs or lost business, generally does not carry the same significance as a threat of physical harm.

Ellis stressed that companies confronting cartel and extortion risks should examine whether an event is isolated, whether alternative routes or providers exist, what remediation was undertaken, and whether management changed the conditions that allowed the payments to continue. His broader advice was that a company must be able to tell a credible story of reasonable measures and operational adjustment. Scoular’s alleged six-year payment pattern is difficult to reconcile with that story. The operational response was not to stop, reroute, escalate, or remediate. It was allegedly to reimburse the brokers and continue moving trains.

The Accounting Provisions Remain

Another recurring error is to assume that an anti-bribery exception eliminates all FCPA risk. It does not. The FCPA’s accounting provisions require issuers to keep books and records that accurately and fairly reflect transactions and to maintain adequate internal accounting controls. A payment may fall outside the anti-bribery prohibition and still create liability if it is mischaracterized, hidden in a miscellaneous account, or made through controls that do not provide reasonable assurance of proper authorization and recording. The DOJ FCPA Resource Guide 2nd edition explains these requirements and the government’s narrow approach to the exception.

That is why a company policy that allows facilitation payments creates operational difficulties. Employees must make fine legal distinctions under pressure, document a payment that may violate local law, obtain appropriate approval, and record the transaction transparently. Many companies reasonably prohibit facilitation payments altogether. The legal exception is so narrow, and the collateral risks so substantial, that a global ban is often easier to explain, control, and test.

A Better Customs Control

When a broker describes a payment as a facilitation payment, compliance should treat the statement as the starting point for the inquiry.

The company should ask:

  1. What exact government action is requested?
  2. Is the company already legally entitled to that action?
  3. Does the official have discretion over the outcome?
  4. Has an inspection, permit, or application already produced an adverse result?
  5. Will the payment change only timing, or will it change the result?
  6. Is the amount supported by a published fee schedule and an official receipt?
  7. Who will receive the money?
  8. Is the payment lawful under local law and permitted by company policy?
  9. How will it be recorded in the books?
  10. Has the same broker, port, product, or payment description appeared before?

If the business cannot answer those questions before payment, it should not rely on the exception.

Questions for CCOs and the Final Lesson

CCOs should ask whether employees understand the difference between scheduling an inspection and buying a successful inspection. They should test customs invoices for recurring round-dollar charges, match fees to official documents, and review whether brokers produce unusually favorable outcomes after special payments.

The Scoular lesson is simple. A payment does not become permissible because it is small, customary, urgent, or routed through a broker. It qualifies for the FCPA’s narrow exception only when it expedites a routine, nondiscretionary action that the company is already entitled to receive. Scoular’s alleged payments did something very different. They caused officials to allow shipments across the border despite failed inspections, avoided millions of dollars in costs, and were disguised as reinspection fees.

That was not facilitation. It was the business purpose of the bribery scheme.

Categories
Blog

What Scoular Teaches About Off-Channel Communications, Investigations, and Compliance Program Effectiveness

WhatsApp was not a footnote in The Scoular Company FCPA resolution. It was part of the operating system of the alleged bribery scheme. According to the Department of Justice Press Release (we are still waiting on the DPA and Criminal Information), Scoular Company employees communicated about shipments and bribes through WhatsApp and other means. Today I want to explore the issue of off-channel communication and what it means for your compliance program.

The compliance lesson is not simply that Scoular Company employees used WhatsApp. It is that an informal communications channel became embedded in a high-risk business process involving customs officials, third-party brokers, payment approvals, and financial records. Once that happens, messaging governance is no longer an information technology issue. It is an anti-corruption control.

Off-Channel Became the Business Channel

The phrase “off-channel” can be misleading. If employees regularly use WhatsApp to authorize payments, direct third parties, and solve customs problems, the application is not outside the business. It is where the business is being conducted. That distinction matters.

A company may have excellent controls inside its enterprise resource planning system. It may require purchase orders, segregation of duties, invoice matching, and documented approvals. Those controls can be bypassed if the substantive decision is made in a private chat and the formal system merely records the result. At Scoular Company, the reinspection invoice was one side of the control failure. The WhatsApp discussion was the other one.

The invoice gave the payment a facially legitimate description. The messaging channel allegedly supplied the knowledge, direction, and authorization behind it. Compliance teams should test both sides together. A recurring round-dollar customs charge becomes more significant when matched to a message asking a broker to get a train released. A failed inspection becomes more significant when followed by an off-channel approval and immediate border clearance. Communications analytics and transaction analytics should not operate as separate disciplines.

Enforcement Priorities Can Change. Evidence Does Not.

In my podcast with Matteson Ellis, Member and Latin America Practice Lead at Miller & Chevalier, we addressed the shift in federal enforcement attention surrounding off-channel communications. Ellis made the more durable point: even when a regulator changes its emphasis, WhatsApp messages remain evidence of knowledge, intent, authorization, concealment, and circumvention of control.

Ellis observed that the DOJ press release suggests Scoular’s internal investigation obtained access to relevant WhatsApp communications. That access was important because retrieving such data can be difficult, particularly when employees use personal devices, local privacy law limits review, or messages have not been retained. His conclusion should command the attention of every CCO. The off-channel issue may have become quieter, but the Scoular resolution can be read as bringing it back to the center of corporate investigations. A prosecutor does not need a standalone recordkeeping case to use a WhatsApp message as proof of an FCPA violation.

The 2024 ECCP Provides the Road Map

The DOJ’s 2024 Evaluation of Corporate Compliance Programs (ECCP) does not demand a single technology solution. It asks whether the company’s approach is reasonable for its business needs and risk profile. That is the correct standard because messaging use varies by country, function, and commercial reality. The ECCP organizes the inquiry around three practical areas:

  • Communication channels. What electronic channels do employees actually use? How does use vary by jurisdiction and business function? What retention and deletion settings apply, and why did the company permit them?
  • Policy environment. Can the company preserve communications when devices are replaced? What do privacy, security, employment, and bring-your-own-device rules permit? Can the company review business messages on personal devices, and are employees required to transfer business records into company systems?
  • Risk management. Has the company ever exercised its access rights? What happens when an employee refuses access or violates the policy? Has messaging use impaired an investigation or the company’s response to prosecutors?

These are effectiveness questions. A written prohibition will not satisfy them if the business routinely ignores it, managers approve transactions in private chats, and the company cannot retrieve the records when misconduct surfaces.

A Defensible Program Starts With Commercial Reality

Ellis explained that an outright WhatsApp ban may not be practical in Latin America, where the application is widely used for business. A policy that conflicts with how employees, customers, and third parties actually work may drive communications further underground. The better approach is to define what may occur on the platform.

Ellis suggested limiting WhatsApp to logistical and administrative communications while keeping substantive commercial transactions and approvals inside controlled systems. That distinction is particularly important for customs payments, discounts, government interactions, third-party instructions, and exceptions to standard procedures.

A defensible framework should include the following controls:

  • Map actual use: Survey high-risk functions and jurisdictions to determine which applications, devices, disappearing-message settings, and informal groups employees use.
  • Classify communications: Separate low-risk logistics from approvals, commitments, payment decisions, government interactions, and other substantive business records.
  • Build technical access: Use company-managed devices or approved enterprise integrations where appropriate so business communications can be retained, searched, placed on legal hold, and produced.
  • Address local law: Analyze privacy, employment, consent, monitoring, and data-transfer requirements before an investigation begins. The access right must be lawful and operational.
  • Create preservation protocols: Define what occurs when an employee changes devices, leaves the company, becomes subject to a legal hold, or refuses access to business communications.
  • Enforce the rules: Test compliance, investigate violations, apply consequences consistently, and examine whether supervisors tolerated or encouraged off-channel approvals.

Investigations Must Be Ready Before the Message Disappears

Off-channel governance is tested in the first hours of an investigation. The company must identify relevant custodians, devices, applications, group chats, backup settings, linked desktops, and cloud accounts. It must issue a preservation notice that employees understand and implement. It must also determine whether consent, works council consultation, or another local-law step is required before collecting data.

The investigative team should not examine messaging data in isolation. It should connect communications to:

  • Accounts-payable records
  • Customs broker invoices
  • Inspection results
  • Shipment identifiers
  • Clearance times
  • Approval logs
  • Bank data

This is where Scoular Company FCPA enforcement action becomes a model for a broader control lesson. The message can explain the invoice, and the invoice can corroborate the message. Ellis emphasized the value of having protocols ready before access is needed. That is critical. Negotiating employee consent, locating backups, and determining ownership of a device after a subpoena or whistleblower allegation arrives is not a defensible strategy. It is a delay, and delay can destroy evidence and cooperation.

Boards Should Treat Messaging as a Governance Risk

Boards do not need to select the retention platform or approve device settings. They do need assurance that management understands how high-risk business is actually conducted and can preserve the evidence required to investigate misconduct. The board should receive more than confirmation that a policy exists. It should receive information on:

  • Policy exceptions
  • Control testing
  • Employee violations
  • Disciplinary outcomes
  • Collection failures
  • Investigation delays
  • High-risk jurisdictions and functions

For companies operating across the U.S.-Mexico border, customs, logistics, sales, procurement, and government-facing teams deserve particular attention. This is an oversight issue. If management cannot retrieve communications involving payments to government-facing third parties, the company may be unable to determine what occurred, identify responsible individuals, remediate the control failure, or cooperate effectively with prosecutors.

Questions for CCOs

  1. Which messaging platforms do employees and third parties actually use in our highest-risk markets?
  2. Can an employee approve a customs payment, direct a broker, or authorize an exception through WhatsApp?
  3. Can we lawfully and promptly preserve and retrieve business messages from company and personal devices?
  4. Have we tested those capabilities through a mock investigation or legal hold?
  5. Do transaction-monitoring reviews incorporate relevant messaging evidence when an anomaly is escalated?
  6. Have we disciplined employees and supervisors for circumventing approved channels?

The Bottom Line

Scoular Company did not become an off-channel communications case because employees happened to use WhatsApp. WhatsApp mattered because employees allegedly used it to facilitate and discuss a bribery scheme that operated through customs brokers and disguised invoices for six years. That is the compliance lesson. The channel, the payment, the third party, and the business outcome must be viewed as one control environment.

Companies should not ask whether WhatsApp is good or bad. They should ask whether the communications occurring there are permitted, preserved, accessible, monitored on a risk basis, and connected to the company’s formal approval and financial systems. If the company cannot answer those questions, its most important business records may be sitting on the device it controls least.

Categories
Blog

Nothing Crosses the Border: Scoular and the New Compliance Burden for Mexico Supply Chains

“Nothing crosses into or out of Mexico without the approval and payment to Mexican drug cartels. American businesses that engage in any cross-border trade bear a significant amount of responsibility to do so without benefitting those cartels and without threatening our national security,” said U.S. Attorney Justin R. Simmons for the Western District of Texas. “The bribery scheme in which the Scoular Company engaged demonstrates the dangerous corporate corruption we in the Western District of Texas are committed to fighting on behalf of the American people.”

This is not a quote from The Onion, but it is an extraordinary statement from a United States Attorney. It is not confined to companies that knowingly pay cartels. It is not limited to businesses operating in cartel-controlled industries. It speaks broadly to American companies engaged in cross-border trade with Mexico.

The statement appeared in the Department of Justice’s Press Release announcing that The Scoular Company would pay more than $10 million to resolve an FCPA investigation involving payments to Mexican officials. According to the DOJ, customs brokers paid approximately $2,000 per train to allow shipments of corn and other products to cross the border despite inspections identifying dirt, soil, and other impurities. The payments were invoiced back to Scoular as “reinspection fees.” The enforcement message extends far beyond Scoular. Every U.S. company importing goods from Mexico should take notice.

Cartels and the UFLPA

One of the few laws that demands such an approach is the Uyghur Forced Labor Prevention Act (UFLPA), which targets goods made, whole or in part, by forced labor in the Xinjiang region of China or made by forced labor in other parts of China by Uighurs or other minorities. It is designed to operate as a de facto trade ban on goods from China’s Jing Jang region. US businesses will face a heavy burden to overcome the presumption of forced labor. It is perhaps the most significant US law addressing forced labor, and it has the most tangible repercussions companies can face. Under the UFLPA, the key is your documentation for US Customs and Border Protection. Travis Miller has noted that this means if you are “asking companies to look back into where the actual sand came from that got turned into the silica, that got turned into the semiconductor, that got turned into the circuit board, that got turned into the device that finds its way into your laptop. There’s just never been anything like it.”

The UFLPA and its guidance weave together existing business processes. The UFLPA emerged from the America Supply Chain Executive Order in the US/China trade war, which focused on semiconductors, critical raw materials, and elements that are the subject of the extractives. To comply with it, you could not actually start unless you already had a product compliance program in place. This means that if you do not know the bill of materials, do not have an approved vendor list, or do not know where your components are manufactured, you cannot prove compliance. This may well be the approach the Trump Administration takes under FTOs in Mexico and other locations in Central and Latin America.

Is Every Cross-Border Company Benefiting a Cartel?

In my podcast discussion with Matt Ellis, Latin America Practice Lead at Miller & Chevalier, Ellis challenged the literal breadth of the government’s statement. He noted that companies move legitimate goods between the United States and Mexico every hour without knowingly benefiting drug cartels. It would be inaccurate to conclude that every cross-border transaction involves a cartel payment.

Nevertheless, Ellis called the statement striking. He raised the question every CCO should now be considering: Is the DOJ establishing a new compliance standard for companies doing business across the U.S.-Mexico border? The statement does not create a new statute, regulation, or formal presumption of liability. Yet prosecutorial statements communicate enforcement expectations. Here, the expectation appears to be that American businesses must understand not only who their immediate third parties are, but also whether their supply chain activities could provide economic benefits to organized crime.

That puts pressure on importers in three ways. First, companies may face greater scrutiny over customs brokers, logistics providers, trucking companies, warehouses, security providers, labor organizations, and other parties supporting Mexican operations. Second, companies may be expected to investigate the downstream destination of payments, even when there is no obvious cartel connection. Third, the government may examine whether compliance programs integrate anti-corruption controls with sanctions, anti-money laundering, trade compliance, supply chain security, and organized-crime risk.

The question will no longer be limited to whether the company intended to pay a bribe. Prosecutors may also ask whether the company reasonably understood the environment in which its money and goods were moving.

Traditional Third-Party Due Diligence May Not Be Enough

Ellis made one of the most important observations of our discussion: standard third-party screening may not identify cartel connections. Conventional anti-corruption due diligence focuses heavily on government-facing intermediaries. Companies screen owners and principals, search adverse media, identify politically exposed persons, review government relationships, obtain certifications, and include anti-corruption language in contracts. Those measures remain necessary. They may not be sufficient for organized-crime risk.

Cartel affiliations are rarely disclosed in a corporate registry. A logistics provider may appear legitimate while making payment for protection. A trucking company may operate in a region controlled by a criminal organization. A supplier may use subcontractors with undisclosed local connections. A customer, warehouse, labor group, or security provider may be vulnerable to criminal infiltration.

This means companies should broaden the universe of third parties subject to risk-based review. For Mexican supply chains, that universe may include:

  • Suppliers
  • Customers
  • Customs brokers
  • Freight forwarders
  • Trucking companies
  • Warehouses
  • Security companies
  • Local consultants
  • Port and terminal service providers
  • Labor contractors
  • Union representatives
  • Subcontractors
  • Last-mile transportation providers

The legal requirement to use a licensed customs broker should not reduce scrutiny. As Ellis noted, mandatory licensing can sometimes create a false sense of security. A government license does not replace a company’s responsibility to understand how the broker operates.

Contextual Due Diligence Becomes Essential

If database screening cannot reliably identify cartel connections, companies need a contextual approach. This begins by examining where the third party will operate and what criminal activity is associated with that region. Relevant questions include:

  • Is the location known for cartel activity?
  • Are particular highways or transportation corridors subject to roadblocks or protection payments?
  • Is the region associated with fentanyl production, human trafficking, fuel theft, cargo theft, or smuggling?
  • Are unusual labor or union arrangements present?
  • Does the vendor use subcontractors that have not been disclosed?
  • Are payment requests made in cash or to unrelated accounts?
  • Is the third party reluctant to explain its security or transportation arrangements?
  • Does the third party promise an unrealistic customs clearance rate?
  • Are employees instructed not to ask questions about local payments?

Companies must also listen to their employees on the ground. Local personnel may understand risks that do not appear in formal databases. They know the regional rumors, transportation practices, local power structures, and third parties that other companies avoid.

This presents another compliance challenge. Local employees may fear retaliation if they report suspected cartel connections. A company’s speak-up system must provide credible confidentiality, escalation, and protection measures. A hotline is not enough if employees believe that raising a concern will endanger them or their families.

The New Standard Is Demonstrable Reasonableness

Companies cannot guarantee that no peso in a complex Mexican supply chain will ever reach a cartel-affiliated person. Prosecutors should not expect the impossible. They can expect companies to identify their risks, conduct reasonable diligence, monitor high-risk transactions, respond to warning signs, preserve relevant communications, and improve controls when new information emerges.

That is the pressure created by the Scoular resolution. Companies must be able to demonstrate that they made a serious, documented, and risk-based effort to prevent their operations from benefiting criminal organizations. The compliance burden is moving from a narrow inquiry into government-facing intermediaries toward a broader examination of the entire supply chain ecosystem.

Actions for CCOs

CCOs should consider five immediate steps:

  1. Expand Mexico-related risk assessments beyond traditional FCPA intermediaries.
  2. Map the complete supply chain, including subcontractors and transportation routes.
  3. Test customs-broker invoices and recurring border-related payments.
  4. Incorporate regional cartel intelligence and local employee knowledge into due diligence.
  5. Brief the board on the convergence of corruption, sanctions, organized crime, and national security risk.

The Scoular resolution does not establish that every company importing goods from Mexico is paying a cartel. It does put every such company on notice that the DOJ may ask what it did to make sure it was not. That is a significant change in compliance expectations. But look to your response to the UFLPA and see if you can find guidance from that compliance issue. Regardless, companies need to respond accordingly.

Categories
FCPA Compliance Report

FCPA Compliance Report: The Scoular FCPA Enforcement Action: Customs Bribes, Cartel Links, and New Compliance Expectations

Welcome to the award-winning FCPA Compliance Report, the longest-running podcast in compliance. In this episode, Tom welcomes back Matt Ellis to discuss a newly announced FCPA enforcement action involving Scoular Company.

The case invoiced about $400,000 in payments labeled as “reinspection fees” to Mexican customs and food inspectors to move agricultural goods across the Mexico–U.S. border. border, allegedly generating over $6.5 million in avoided costs and raising concerns about cartel-linked beneficiaries. They discuss why customs and customs brokers are recurring high-risk areas in Mexico, how long-running employee involvement suggests broader controls and tone-from-the-top failures, and why these payments are not facilitation payments under Mexican law and given discretionary official acts. Ellis emphasizes analytics on customs documents and broker invoices, stronger third-party diligence beyond traditional screening to address cartel/TCO risks, and defensible governance for WhatsApp/off-channel communications. Despite no voluntary self-disclosure, the company received cooperation credit and a 25% fine reduction, and Ellis previews an ACI conference focused on cartels, TCOs, and compliance in Latin America.

Key highlights:

  • Border Bribes and Safety Risks
  • Controls Failures and Monitoring
  • Data Analytics Red Flags
  • Facilitation Payment Myth
  • DOJ Cartel Warning and Implications
  • Rethinking Due Diligence for Cartels
  • WhatsApp and Messaging Governance
  • Cooperation, Credit, and Remediation

Resources:

Cartels, TCOs and Compliance in Latin America, July 20-21

Matt Ellis on LinkedIn

Tom Fox

Instagram

Facebook

YouTube

Twitter

LinkedIn

The FCPA Compliance Report was recently named the world’s best business ethics podcast by FeedSpot.