The Scoular FCPA Case: What It Means for Third-Party Due Diligence and Cartel Risk

Compliance Implications of Scoular FCPA Settlement blog

The Scoular FCPA settlement announced by the US Department of Justice in July 2026 has already generated considerable discussion, including debate over whether it truly demonstrates the Department of Justice’s (DOJ) increased focus on cartel activity. Regardless, the case raises broader questions about the scope of third-party due diligence, particularly when corruption risk may intersect with other forms of criminal activity.

Scoular entered into a three-year deferred prosecution agreement (DPA) with the DOJ after employees directed customs brokers to make payments to Mexican officials to allow agricultural shipments to cross the US-Mexico border despite failed inspections. The brokers paid approximately $2,000 per shipment and invoiced the payments back to Scoular as “reinspection fees.” In total, Scoular authorized more than $400,000 in bribes and avoided more than $6.5 million in fees and costs. Under the settlement, Scoular agreed to pay approximately $9.8 million in penalties and more than $400,000 in forfeiture, as well as continue enhancements to its compliance and ethics program.
 
The underlying FCPA violation is straightforward. What has attracted more attention is DOJ’s statement that, unbeknownst to Scoular or its employees, a portion of the bribes ultimately benefited individuals associated with the criminal operations of a cartel at the US-Mexico border.
 
That assertion aligns closely with DOJ’s current FCPA enforcement priorities, which expressly identify foreign bribery that facilitates the operations of cartels and transnational criminal organizations (TCOs) as an area of focus. But there is also uncertainty surrounding the connection. The cartel link does not appear in the criminal information filed against Scoular, and the publicly available record provides little detail about who ultimately benefited from the payments or how they were connected to cartel activity.
 
For compliance teams, that uncertainty may itself be instructive.

Expand the scope of enhanced due diligence

Third parties that interact frequently with government officials, facilitate customs or border processes, obtain permits or licenses, or make payments on a company’s behalf already warrant heightened scrutiny from an anti-corruption perspective. Where those activities take place in regions with significant cartel or organized-crime activity, the risk assessment may need to go further.
 
That can include examining the third party’s operating footprint and local relationships; understanding whether it uses subcontractors, sub-agents or other intermediaries; identifying who is authorized to make payments on the company’s behalf; and considering whether the geography or activity creates exposure to organized crime or designated entities.
 
It also means understanding the commercial mechanics of the relationship. What services is the third party actually providing? What fees should reasonably be expected? Who can authorize additional payments? Where does the money go?
Repeated “reinspection,” facilitation, handling, expediting or miscellaneous fees should immediately raise a red flag and prompt questions about the underlying service, the recipient of the payment, the reason it was necessary and the supporting documentation.
 
Turning every third-party review in a cartel-active region into an investigation of local criminal networks is both unrealistic and unnecessary. What matters is knowing what to look for and recognizing when multiple risk indicators justify additional due diligence.
 
Sanctions and watchlist screening should also account for cartel-related risk. Companies should confirm that their screening data incorporates relevant cartel designations and associated individuals and entities, particularly as US authorities continue to expand the use of counterterrorism and counternarcotics sanctions authorities in this area.

Connect due diligence to transaction controls

In the Scoular case, the customs brokers weren’t peripheral vendors to be screened and approved once. They were making payments on Scoular’s behalf, which the brokers then invoiced back to the company as “reinspection fees.” The conduct continued over several years.
 
Information from due diligence and monitoring must be translated into controls around what a third party is actually permitted to do. Otherwise, it’s ineffective.
 
This is also where transaction data can become an important source of risk intelligence. Repeated exceptional charges, vague descriptions, payments that fall outside agreed fee structures, unusual reimbursement requests or changes in payment patterns can provide information that conventional screening will not.
 
DOJ specifically credited Scoular’s subsequent efforts to strengthen risk-based third-party screening and approval requirements, enhance monitoring procedures, introduce anti-corruption and audit-right provisions into third-party contracts, and revise financial controls relating to high-risk transactions.
 
The lesson is therefore to connect what a company knows about a third party’s risk to how the relationship and its transactions are controlled.

Consider risk categories together

Scoular also demonstrates the limitations of evaluating third-party risks separately.
 
A relationship that begins as an anti-bribery concern may also create exposure to organized crime, sanctions, money laundering, human rights, reputational or even national security risks. And those risks may not be apparent when the third party is first engaged.
 
This is particularly significant as the US government has expanded its use of counterterrorism and sanctions authorities against cartels and associated individuals and entities. In 2025, the US designated several Mexican cartels as Foreign Terrorist Organizations (FTOs) and Specially Designated Global Terrorists (SDGTs). The designation landscape has continued to expand. In July 2026, for example, the Juárez Cartel and Los Viagras were designated as FTOs and SDGTs, and in September, the US Treasury imposed additional sanctions on individuals and entities linked to the Sinaloa Cartel, including networks associated with its Los Mayos faction and corruption in Baja California.
 
Combined with DOJ’s stated focus on foreign bribery involving cartels and TCOs, these developments give companies operating in affected markets an additional reason to consider cartel exposure alongside more traditional anti-bribery risks.
 
Scoular is ultimately a reminder that knowing your third party is only the starting point. Effective due diligence also requires understanding how it operates, the parties it engages with, how money moves through the relationship, and when those factors warrant a closer look. While companies cannot be expected to identify every unknown actor that may ultimately benefit from a transaction, they can build risk-based programs that recognize when additional questions need to be asked and additional controls applied.
Turn Risk to Resilience
Get the 360° visibility you need to protect your business and move faster
Share via
Copy link
Powered by Social Snap