Categories
Blog

Scoular DPA Part 5: From Reinspection Fees to Executive Signatures: Final Lessons from Scoular

From Reinspection Fees to Executive Signatures: Final Lessons from Scoular

The Scoular Company FCPA enforcement action began with a deceptively simple fact pattern. Customs brokers allegedly paid Mexican officials approximately $2,000 per train so agricultural shipments could cross the border despite adverse inspection findings. The brokers invoiced the payments to Scoular as “reinspection fees.” That description, however, was only the first layer of the case.

Across this blog post series, Scoular Company became a study in third-party risk, internal controls, cartel exposure, off-channel communications, facilitating payments, data analytics, voluntary disclosure, remediation, DOJ oversight, and executive accountability. Each article examined one part of the control environment. Taken together, they tell a larger story about how bribery becomes normalized inside an operating process and what a company must do when that process fails.

The source distinction matters. I have now posted two series on the enforcement action. The first series relied on the DOJ Press Release, which announced the resolution and described the government’s allegations and conclusions. The second series relied on the formal Deferred Prosecution Agreement (DPA), in which Scoular admitted, accepted, and stipulated that the facts were true. The DPA did not merely add detail. It changed the evidentiary foundation of the analysis.

I.              Series One: Lessons From the DOJ Press Release

a.     A Small Payment Became an Enterprise Control Failure

The Press Release series began with the mechanics of the scheme. According to the DOJ announcement, the conduct ran from 2013 through 2019, involved more than $400,000 in bribes, and enabled Scoular to avoid more than $6.5 million in fees and costs. Scoular entered a three-year DPA and agreed to pay a $9,769,521 criminal penalty and $414,351 in forfeiture.

The compliance lesson was never the size of one payment. It was repetition. A recurring round-dollar charge, submitted by customs brokers, approved over six years, and recorded under a plausible description became part of the company’s operating model.

The phrase “reinspection fee” demonstrated why invoice controls must examine commercial substance. A three-way match can confirm that an invoice, purchase order, and approval agree. It cannot establish that the underlying service was legitimate. For a high-risk customs payment, the control must ask what government action occurred, who received the money, whether an official fee schedule supports the amount, and what happened to the shipment after payment.

This also exposed the limits of onboarding due diligence. Screening a broker and obtaining an anti-corruption certification are only the beginning. Effective third-party management connects onboarding to invoices, transaction monitoring, business outcomes, periodic review, audit rights, and termination decisions.

b.    Cartel Risk Expanded the Compliance Perimeter

The Press Release stated that a portion of the bribe payments ultimately benefited individuals associated with a cartel operating at the U.S.-Mexico border, although the DOJ said Scoular Company and its employees did not know of that connection.

In an episode of the FCPA Compliance Report,  Matt Ellis discussed a broader question. Traditional anti-corruption diligence focuses on government-facing intermediaries, ownership, political exposure, adverse media, and government relationships. Organized-crime connections may not appear in a corporate registry or screening database.

The lesson was not that every cross-border transaction benefits a cartel. It was that companies must understand the environment in which their money, goods, and third parties move. Customs brokers, trucking companies, warehouses, security providers, labor contractors, and subcontractors can create overlapping corruption, money-laundering, sanctions, trade, security, and organized-crime risks.

c.     WhatsApp Was Part of the Control Environment

The Press Release series also examined WhatsApp and other communications used to discuss shipments and payments. The critical point was not that employees selected an unapproved application. It was that the substantive business decision could occur in a private message while the formal system recorded only the resulting invoice. Ellis emphasized that enforcement priorities may change, but evidence does not. A WhatsApp message can establish knowledge, authorization, concealment, or control circumvention even without a standalone off-channel communications charge.

A defensible program must identify the applications employees actually use, define which business activities may occur there, preserve relevant records, address local privacy and employment law, and enforce violations consistently. The company must also be able to connect communications with payment records, inspection results, shipment identifiers, approval logs, and bank data.

Facilitation Payments Did Not Fit the Facts

The Press Release series then addressed why the payments were not protected as facilitating payments. The FCPA exception is narrow. It may cover a payment intended to expedite a routine, nondiscretionary governmental act that the company is already entitled to receive. Scheduling an inspection may be routine. Paying an official to disregard a failed inspection is not. The alleged Scoular payments did not change timing. They changed the outcome and enabled shipments to cross despite findings of dirt, soil, and other impurities.

Amount, urgency, local custom, invoice wording, and use of a third party do not create the exception. Nor does the exception authorize a false accounting entry. A company that permits facilitating payments must still confront local law, accurate books and records, approval controls, and the practical difficulty of asking employees to make a narrow legal distinction under commercial pressure.

II.   Lessons From the DPA and Admitted Facts

a.     The DPA Showed How the Scheme Became Normal

The DPA blog post series began by distinguishing allegations in the Press Release from facts Scoular Company admitted. The Statement of Facts showed that stricter Mexican inspections created operational pressure (IE., more or new/different risks) in 2013. A broker proposed a fee on every train and promised that Scoular Company would “not have a single risk of adverse determinations.” The proposal was discussed at Scoular Company’s Kansas office and then replicated through additional brokers and border crossings.

The communications removed ambiguity. Employees discussed soil findings, special payments, trains released after inspections, and situations in which “normal procedures are not working.” By 2018, a communication referred to offering officials more than was normally given. These facts showed normalization. The scheme was not simply a broker’s unauthorized act. It became a repeatable process linking operational pressure, management knowledge, third parties, communications, invoices, approvals, and favorable business outcomes.

b.    Stopping the Conduct Was Not Self-Disclosure

The DPA disclosed that internal reports emerged in 2019 and Scoular Company changed its practices and ended direct engagement with the brokers. Yet the company did not receive voluntary self-disclosure credit because it did not voluntarily and timely report the conduct. The DPA does not reveal the company’s internal debate so that speculation would be inappropriate. It does establish a governance lesson. An internal report starts two clocks: the investigation clock and the disclosure-decision clock. Stopping the conduct is remediation. It is not a substitute for a documented, timely decision about disclosure.

Scoular later received cooperation and remediation credit, including a 25 percent reduction from the bottom of the applicable Sentencing Guidelines range. That outcome demonstrates that missing voluntary-disclosure credit does not make later cooperation irrelevant. It also demonstrates that the two forms of credit are not interchangeable.

c.     Executive Signatures Became the Final Control

The DPA’s attachments translated compliance expectations into personal executive responsibility. They required compliance access to the board, adequate authority and resources, incentives and discipline, third-party business-rationale documentation, verification of services, reasonable compensation, data access, root-cause analysis, and remediation.

They also required two distinct certifications. The CEO and CFO must certify disclosure obligations. The CEO and Chief Legal Officer must certify the truth and completeness of DOJ reports and the design of the anti-corruption compliance program. The certification language references potential exposure under 18 U.S.C. §§ 1001 and 1519 for materially false statements or records.

The signature is therefore not ceremonial. It requires an evidence chain from front-line controls through management testing to board oversight.

d.    Data Analytics Connects Both Series

Vince Walden’s analysis supplied the final detection lesson. No single anomaly proves bribery. The stronger signal is a sequence: an adverse inspection, an unusual recurring broker payment, and a favorable shipment release.

The words “reinspection fee” were searchable. The approximately $2,000 round-dollar amount was testable. The brokers, routes, inspection outcomes, timing, and releases were linkable. Communications could then provide context. Analytics should rank anomalies for human investigation, not declare guilt by algorithm.

This is where internal controls become dynamic. The company should test transaction text, payment amounts, vendor concentration, duplicate descriptions, approval patterns, inspection results, clearance timing, and user access together. Every substantiated alert should improve the next rule, risk model, training decision, and control test.

e.     Compliance Takeaways

  1. Treat the process as the risk unit. Review the third party, payment, message, inspection, route, approval, accounting entry, and business outcome together.
  2. Test substance, not labels. Require evidence of the service performed, the lawful basis for the fee, the recipient, the calculation, and the official result.
  3. Expand third-party risk beyond corruption screening. Integrate organized-crime, sanctions, anti-money-laundering, trade, security, and supply-chain intelligence where the risk profile requires it.
  4. Govern communications as business records. Know which channels employees use, restrict substantive approvals to controlled systems, preserve records, and test retrieval before an investigation.
  5. Create a disclosure decision protocol. Define who evaluates material facts, what information is needed, when senior management and the board are briefed, and how the decision is documented.
  6. Use analytics to connect events. Build monitoring around sequences and outcomes, then route alerts to trained investigators with access to operational, financial, and communications data.
  7. Make certifications evidence-based. Executive signers and boards should demand documented control testing, root-cause analysis, remediation status, and unresolved exceptions before signing.

The final lesson from Scoular Company is that bribery rarely sits in one control. It moves through an operating system. An effective compliance program must see that system, test it continuously, and ensure that the people who oversee it can stand behind the evidence.

Categories
Compliance Into the Weeds

Compliance into the Weeds: Scoular Company FCPA Settlement: Cartel Links, Border Trade Risks, and Compliance Lessons

The award-winning Compliance into the Weeds is the only weekly podcast that takes a deep dive into a compliance-related topic, literally going into the weeds to explore it more fully. Looking for some hard-hitting insights on compliance? Look no further than Compliance into the Weeds! In this episode of Compliance into the Weeds, Tom Fox and Matt Kelly discuss the recent FCPA resolution with the Scoular Company. Both Tom and Matt have blogged on this matter, so check out the Resources link below for additional discussions.

The recent FCPA enforcement action against Scoular Company involved a $10.2 million payment and a three-year deferred prosecution agreement over bribes by third-party customs brokers to Mexican border officials to expedite cross-border shipments. DOJ emphasized alleged cartel connections, including a strong statement from the U.S. Attorney for the Western District of Texas, which raised questions about expanded local U.S. attorney involvement and how cartel or potential FTO designations could heighten trade and compliance risks. The company received no voluntary self-disclosure credit but got a 25% discount, with remediation cited (including dropping brokers and strengthening tone at the top). They highlight off-channel WhatsApp use, the lack of released key documents (DPA, statement of facts, criminal information), and practical compliance takeaways on third-party oversight, data analytics, and risk assessments.

Resources:

Matt in Radical Compliance

Tom in FCPA Compliance and Ethics Blog

Tom

Instagram

Facebook

YouTube

Twitter

LinkedIn

A multi-award-winning podcast, Compliance into the Weeds was most recently honored as one of the Top 25 Regulatory Compliance Podcasts, a Top 10 Business Law Podcast, and a Top 12 Risk Management Podcast. Compliance into the Weeds has been conferred the Davey, Communicator, and W3 Awards, all for podcast excellence.

Categories
Blog

Scoular’s $10 Million FCPA Resolution: Compliance Lessons Learned

We conclude our review of the Scoular Company FCPA enforcement action with a full lessons-learned blog post. We are still awaiting the DPA and Criminal Information, so the details of the case come from the Department of Justice (DOJ) Press Release.

A $2,000 payment can disappear inside a global supply chain. Repeated, train-by-train, authorized by employees, routed through customs brokers, discussed on WhatsApp, disguised as a “reinspection fee,” and reimbursed for six years, it becomes an operating model. That is the central lesson from The Scoular Company Foreign Corrupt Practices Act resolution.

The DOJ announced that Scoular Company would pay more than $10 million to resolve an investigation into bribes paid to Mexican officials between 2013 and 2019. The company entered into a three-year deferred prosecution agreement, agreed to a $9,769,521 criminal penalty and $414,351 in forfeiture, and accepted continuing cooperation, compliance, and reporting obligations.

Across this blog post series, we examined four dimensions of the case: customs brokers and payment controls, cartel and national-security risk, off-channel communications, and the facilitating-payments exception. Read together with my podcast conversation with Matt Ellis, they reveal a single conclusion. Compliance must follow the complete transaction, from the business pressure that creates the payment to the third party that delivers it, the message that authorizes it, the invoice that conceals it, and the ultimate recipient who benefits.

The Scheme Hid in Plain Sight

According to the DOJ, Scoular Company relied on customs brokers to move corn and other agricultural products from the United States into Mexico. Mexican authorities inspected the shipments for dirt, soil, and other impurities. When inspections identified problems, Scoular Company employees directed brokers to pay officials approximately $2,000 per train so the shipments could cross the border. The brokers invoiced the payments back to Scoular Company as “reinspection fees,” and Scoular paid them. In total, the company authorized more than $400,000 in bribes and avoided more than $6.5 million in fees and costs.

The invoice description is the first major lesson. “Reinspection fee” sounded like it was connected to a legitimate customs process. Yet an accounts-payable control that merely matches an approved vendor, purchase order, and plausible service description tests paperwork, not substance.

Effective payment controls should require the company to identify the government agency involved, match the charge to a specific shipment and inspection, compare the amount with an official fee schedule, obtain proof of service, confirm the payee, and document the business justification. Repeated round-dollar charges, unusual success rates, rapid clearance after special payments, and fees unsupported by government records should trigger review.

Follow the money, measure the time, and test the outcome. That is how ordinary transaction data becomes an anti-corruption control.

A Licensed Broker Is Still a High-Risk Third Party

Customs brokers should never be treated as low-risk administrative providers simply because they are licensed or legally required. They interact with government officials, operate under commercial pressure, and can impose charges that distant finance personnel cannot easily verify.

Initial due diligence remains necessary, but it is only the beginning. Companies must connect screening, contracting, invoice testing, transaction monitoring, recertification, training, audit rights, and offboarding. The real test is not whether the third-party file was complete on the day of onboarding. It is whether the company understands how the broker behaves after the contract is signed.

The DOJ credited Scoular Company with eliminating brokers associated with the Mexican reinspection payments, strengthening risk-based screening and approvals, adding anti-corruption and audit-rights provisions, revising controls for high-risk transactions, and using software tools to improve monitoring. That remediation changed the operating model rather than merely revising a policy.

Cartel Risk Changes the Compliance Perimeter

The most consequential part of the DOJ announcement may be its national-security framing. The government determined that, without Scoular Company or its employees knowing it, a portion of the bribes benefited persons associated with a cartel’s criminal operations at the U.S.-Mexico border.

U.S. Attorney Justin R. Simmons stated that American companies engaged in cross-border trade bear responsibility for operating without benefiting cartels or threatening national security. Ellis challenged the literal breadth of the statement during our podcast discussion. Legitimate trade crosses the border every day without companies knowingly paying cartels. Nevertheless, he agreed that the statement signals a more demanding compliance environment.

Ellis explained that the cartel and transnational criminal organization risk is broader than the traditional FCPA risk. Anti-corruption diligence often concentrates on government touchpoints and intermediaries. Organized crime may be hidden inside transportation providers, suppliers, customers, labor relationships, security services, subcontractors, and local routes.

Traditional database screening may not reveal those connections. Ellis emphasized contextual diligence: speak with employees on the ground, examine local security concerns, understand regional criminal activity, investigate facts that do not add up, and adjust operations when warning signs emerge. Companies do not need perfect knowledge. They need a documented story of reasonable measures, credible escalation, and risk-based decisions.

The practical consequence is an integrated risk assessment. Anti-corruption, sanctions, anti-money laundering, trade compliance, physical security, supply chain, and third-party risk cannot remain in separate silos when the same payment may touch all of them.

WhatsApp Was Part of the Control Environment

The DOJ said Scoular Company employees communicated about shipments and bribes through WhatsApp and other means. WhatsApp was therefore not a side issue. It allegedly carried the knowledge and direction behind transactions later recorded as legitimate reinspection charges.

An informal application becomes a business system when employees use it to direct third parties, approve payments, or resolve customs problems. Enterprise controls can be bypassed when the substantive decision occurs in a private chat, and the formal system records only the sanitized result.

Ellis noted that a complete WhatsApp ban may be unrealistic in Latin America. The better approach is to map actual use and define what may occur on each platform. Logistical coordination may be permitted. Government interactions, payment approvals, contractual commitments, and exceptions should remain in controlled systems with retention and audit trails.

Companies must also be able to preserve and retrieve business communications lawfully from company and personal devices. Policies should address device replacement, departing employees, legal holds, privacy and employment requirements, refusal of access, and consistent discipline. The decisive question is not whether a policy exists. It is whether the company can obtain the evidence when an investigation begins.

Why These Were Not Facilitation Payments

The $2,000 amount and the customs setting may tempt employees to use the phrase “facilitation payment.” That label does not fit. The FCPA’s narrow exception covers payments intended to expedite routine, nondiscretionary governmental action that the payer is already entitled to receive. Scheduling an inspection may be routine. Paying an official to disregard a failed inspection is not.

The Scoular Company payments allegedly changed the result. The shipments had identified impurities, and the payments allowed trains to cross despite those findings. The company received a substantial business advantage by avoiding more than $6.5 million in costs. A facilitation payment is not defined by size, local custom, commercial urgency, or invoice terminology. A third party cannot create an exception unavailable to the principal. Nor does an anti-bribery exception excuse false accounting. Even a qualifying payment must be accurately recorded and supported by adequate internal controls.

Ellis’s discussion of extortion reinforces the operational lesson, although extortion and facilitation are distinct doctrines. One or two emergency payments may present a different analysis from a chain of payments continuing over years. Repetition transforms an asserted accommodation into a business process. Companies must respond by escalating, rerouting, changing providers, investigating, and remediating.

Cooperation Still Matters

Scoular Company did not receive voluntary self-disclosure credit because it did not report the conduct to the DOJ in a timely manner. It did receive cooperation credit for its internal investigation, factual presentations, identification of involved individuals, production and organization of evidence, and provision of counsel for current employees, despite early deficiencies.

The resulting criminal penalty reflected a 25 percent reduction from the bottom of the applicable sentencing guidelines range. The lesson is straightforward. Missing the voluntary disclosure window does not render later cooperation irrelevant, but cooperation is not a substitute for timely self-disclosure. The Scoular Company resolution is not four separate compliance stories. It is one story about how pressure, third parties, communications, accounting, and emerging national-security risks converged inside an ordinary business process.

The enduring lesson is equally integrated: know the broker, validate the payment, preserve the message, understand the route, and test the outcome. That is how compliance moves from policy to proof.

Categories
Life with GDPR

Life With GDPR: WhatsApp Breach: Hospital’s GDPR Failures Exposed

Tom Fox and Jonathan Armstrong, renowned experts in cyber security, co-host the award-winning Life with GDPR. The recent controversy surrounding Nigel Farage’s banking situation highlights the risks and compliance challenges faced by the banking industry in relation to data protection. In this episode, Tom and Jonathan discuss a data breach in a Scottish hospital during the COVID-19 pandemic.

The breach occurred when hospital staff shared patient details on WhatsApp, raising concerns about GDPR compliance. The hospital informed the ICO about the breach but chose not to notify affected patients, highlighting the need for appropriate advice and support when making such decisions. The conversation also explores communication challenges in internal investigations and the privacy and security risks of platforms like WhatsApp. It emphasizes the importance of organizations adapting to the preferences of digital native employees and conducting data protection impact assessments. The podcast also highlights the importance of effective policies, training, and proactive phishing training to prevent cyber-attacks and protect sensitive information.

 

Key Takeaways:

  • Data breach in Scottish hospital
  • The Challenges of Communication in Internal Investigations
  • Importance of Policies and Training
  • Phishing Training Effectiveness

Resources

For more information on the issues raised in this podcast, check out the Cordery Compliance News Section. For more information on Cordery Compliance, go to their website here. Also, check out the GDPR Navigator, one of the top resources for GDPR Compliance, by clicking here.

Connect with Tom Fox

Connect with Jonathan Armstrong