The Compliance Imperative: Managing High-Risk Customs Brokers and Logistics Providers in Mexico (Part II of II)

Part one of this series examined how Mexican cartels function as a de facto taxing authority over certain border corridors, ports, and crossings, and how legitimate-looking fees paid to customs brokers and logistics providers can conceal payments that ultimately benefit criminal organizations. This second installment turns to what compliance programs actually need to do about it. If your company moves goods across the U.S.-Mexico border, directly or through intermediaries, treating customs brokerage and cross-border logistics as routine operational functions is no longer a defensible compliance posture. These relationships need to be managed as high-risk third-party engagements, with controls to match.

Start by Reclassifying the Relationship

The single most important step a compliance program can take is definitional. Customs brokers, freight forwarders, and trucking subcontractors operating at or near the border are not ordinary vendors. They interact directly with foreign government officials on your company’s behalf, they exercise discretion over how your money moves at the exact moment of a government interaction, and they often operate in territories where a criminal organization exerts real influence over who gets to do business and on what terms. That combination, government interaction, financial discretion, and territorial risk, is the textbook definition of a high-risk third party, and it should trigger the same tier of due diligence, contractual protection, and ongoing monitoring that a company would apply to a sales agent or a government relations consultant, not the lighter oversight typically reserved for logistics vendors.

Due Diligence Has to Go Beyond the Standard Questionnaire

Standard third-party due diligence, corporate registration checks, sanctions screening, adverse media searches, and a signed anti-corruption certification, will not surface cartel-related risk on its own. A customs broker can pass every one of those checks and still be operating in a territory where it is required to make payments to maintain its ability to function. Effective due diligence for border-facing intermediaries needs to add questions that are specific to this risk: what crossings, ports, and corridors does this broker actually operate through; what is known about the security and criminal environment in those specific locations; and does the broker’s fee structure include any recurring charges that cannot be tied to a published government fee schedule or documented government service.

Companies should also assess whether a broker has faced prior allegations or investigations tied to bribery, extortion, or organized crime involvement, not just whether the broker itself appears on a sanctions or designated party list. Cartel-related risk frequently sits one or two steps removed from the entities a standard sanctions screen would catch.

Test the Substance Behind Every Recurring Payment

The Scoular case demonstrated exactly how this risk hides in plain sight: a $2,000 per-train payment, invoiced as a reinspection fee, paid routinely for years. An accounts payable process that simply matches an invoice to a purchase order will never catch a payment like that. Compliance and finance functions need a joint protocol for testing high-risk recurring payments tied to customs, border crossings, and logistics: does this charge correspond to a published government fee schedule; is there documentary proof of the specific government service performed; does the amount vary in ways consistent with legitimate cost drivers, or is it suspiciously uniform across transactions; and can the broker or logistics provider explain, with supporting documentation, exactly what the payment purchased.

Any charge that cannot be answered with a documented, verifiable explanation should be escalated automatically, regardless of how small it appears relative to the overall relationship. Small, consistent payments are precisely the profile that both bribery schemes and cartel taxation tend to produce, because both function best when they stay below the threshold that would attract executive attention.

Build Real Contractual Protection, and Use It

Contracts with customs brokers, freight forwarders, and logistics providers operating in high-risk Mexico corridors should include specific anti-corruption representations and warranties, provisions addressing third-party subcontracting and payments made on the company’s behalf, and meaningful audit rights that the company actually intends to exercise. A contractual right that is never used provides no real protection and will not be viewed favorably by regulators evaluating whether a compliance program was effective in practice rather than on paper. Companies should periodically test whether their audit rights can actually be exercised in practice, requesting supporting documentation for high-risk payment categories and confirming that brokers and logistics partners will cooperate.

Get Compliance Real Visibility Into Operational Data

None of the controls above matter if the compliance function cannot see the data generated by border logistics operations. Compliance officers should have access to accounts payable records, customs and logistics data, and third-party payment patterns in a form that allows them to identify clustering around specific brokers, ports, crossings, or transaction types. A compliance program built entirely around policies and periodic risk assessments, without a live connection to the transactions flowing through high-risk operational functions, will miss exactly the kind of scheme that unfolds one routine, uniform payment at a time over the course of years.

Break Down the Silos Between Sanctions, AML, and Anti-Corruption Teams

Cartel-related risk in cross-border trade does not respect the traditional organizational boundaries between sanctions compliance, anti-money laundering, and anti-corruption functions. A payment that clears sanctions screening can still represent a bribery risk. A bribery scheme can still carry a downstream cartel nexus that only a different team’s data would reveal. Companies should establish a structured process for these functions to share information routinely, not just refer issues to one another after a problem has already surfaced, and should ensure that any risk assessment covering Mexico operations explicitly incorporates all three lenses rather than treating each as someone else’s job.

Govern Informal Communication Channels

Employees in the Scoular case discussed shipments and bribe payments over WhatsApp and other informal channels outside the company’s official systems. This is a recurring pattern in border-related misconduct, and it deserves specific attention for any employees or contractors managing customs and logistics relationships. Companies should establish clear policies on permitted communication channels for high-risk business functions, support those policies with technical controls, and train employees managing border operations on why informal channels create both a detection blind spot and, in an investigation, a discoverability problem.

Prepare for Look-Back Reviews

Because cartel designations and enforcement priorities are moving quickly, a relationship or payment pattern that looked acceptable eighteen months ago may implicate a different level of risk today. Companies with meaningful Mexico border operations should build periodic look-back reviews into their compliance calendar, reassessing existing broker and logistics relationships against the current designation landscape and enforcement environment, rather than relying solely on the due diligence conducted at the time a relationship was first established.

The Bottom Line

Customs brokerage and cross-border logistics have historically been managed as operational functions, prized for speed and cost efficiency rather than scrutinized for compliance risk. The Scoular case, and the broader enforcement trend connecting bribery to cartel-linked national security concerns, should end that approach for any company with meaningful exposure to the U.S.-Mexico border. The standard going forward has to be that every recurring border-related payment can be explained, documented, and defended, because the alternative, discovering after the fact that a routine cost of doing business was actually funding a criminal organization, is no longer a hypothetical risk. It is the fact pattern regulators are actively building cases around right now.

You may also like...

Leave a Reply

Your email address will not be published. Required fields are marked *