Summary

  • An intermediary file must prove a commercial chain, not merely contain forms. The business should establish ownership, qualifications, reputation, government connections, conflicts, scope, deliverables, pricing, payment destination and continuing need. A completed questionnaire cannot compensate for missing evidence that services were performed or that the recipient of funds matched the approved partner.

  • The UK resolution was a court-approved deferred prosecution agreement. The Serious Fraud Office and Rolls-Royce agreed facts and terms, and the Crown Court decided that the agreement was in the interests of justice and proportionate. That conditional corporate resolution was not an ordinary trial conviction, an acquittal or a judgment against every individual mentioned in the surrounding record.

  • The US resolution had its own charging instrument, admissions and completion process. A criminal information was filed, prosecution was deferred under a separate agreement, and the information was later dismissed after the government represented that the company had met the agreement’s requirements. US dismissal after performance did not erase the admissions or certify future compliance effectiveness.

  • Brazilian coordination cannot be reduced to a line in either DPA. The Brazilian resolution was a distinct legal instrument with its own authority and terms. Amounts credited across resolutions should not be added again as separate social loss or treated as if one forum adjudicated another forum’s case.

  • Corporate and individual responsibility require separate records. The US Department of Justice reported guilty pleas by specified individuals and charges against others in a Rolls-Royce-related scheme. A plea establishes only the pleading defendant’s admitted conduct. An indictment is an allegation carrying the presumption of innocence. Neither status is inherited from the corporate DPA.

  • Completion is a procedural milestone, not a permanent effectiveness certificate. Payment, cooperation, reporting and independent-review requirements can justify expiry and dismissal. Stakeholders still need evidence that ownership checks, service verification, payment controls, speak-up, monitoring and board challenge continue to work under commercial pressure.

  • Business units remain responsible even when compliance approves the partner. Sales and programme leaders know why an intermediary is proposed and whether deliverables are real. Compliance supplies independent challenge and minimum standards; it cannot become the owner of commercial truth or a signature used to transfer accountability away from revenue leaders.

The event boundary: legitimate intermediation and unacceptable opacity

Global engineering contracts can take years to develop. Customers may need technical explanation, financing coordination, local regulatory knowledge, installation support, maintenance planning or supply-chain capability. A company may use consultants, distributors, advisers, introducers or other third parties for lawful reasons. The control objective is not to prohibit every intermediary. It is to ensure that the relationship has a documented purpose, a qualified and transparent counterparty, defensible compensation and evidence of performance.

The Serious Fraud Office’s Rolls-Royce DPA publication page assembles the agreement, statement of facts, judicial judgment and later compliance material. The index helps preserve instrument boundaries. It should not be cited as if the page itself made every factual finding. Each underlying document has a specific role: the parties’ agreement, agreed narrative, court’s approval reasoning, financial calculations and procedural completion.

The event involved multiple business sectors, jurisdictions, periods and intermediary arrangements. That complexity creates two opposite risks. One is under-generalisation: treating every episode as isolated, so no group-wide control owner sees common weaknesses in due diligence, service evidence, commission approval and escalation. The other is over-generalisation: implying that every third party, employee, country or sale was corrupt. Accountability requires a shared control framework and actor-specific legal attribution.

A defensible intermediary population begins with definitions. “Agent,” “consultant,” “adviser,” “distributor” and “offset partner” can carry different legal and commercial roles, but labels cannot determine risk. A distributor that takes title may still be used primarily for introductions. A consultant paid for market intelligence may interact with public officials. A joint-venture partner may nominate a subcontractor. The system should classify functions, contacts, payment flows and public-decision exposure rather than accept the contract title.

The business case should state what internal capability is missing, why a third party is needed, the expected deliverables, duration and alternatives. Vague descriptions such as “business development support” or “market assistance” are not enough for a high-risk engagement. The requestor should identify the customer programme, decision process, government touchpoints, projected contract value and proposed fee formula. Compliance can then challenge a concrete proposition instead of reviewing an abstract relationship.

What the UK DPA established

The UK deferred prosecution agreement suspended prosecution on specified terms. It set financial, cooperation and compliance obligations, identified the relevant corporate entity and incorporated the agreed statement of facts. A DPA is neither an informal promise nor an ordinary conviction. It depends on judicial approval, continued performance and the possibility of prosecution if its terms are breached.

That legal form shapes accurate reporting. The company did not emerge from a contested criminal trial with findings on every count. Nor did the agreement mean the conduct was legally untested or irrelevant. The parties accepted a detailed factual basis, and a court assessed the proposed resolution. The correct description retains both features: conditional corporate resolution and serious agreed facts.

The UK statement of facts describes conduct across business lines and country episodes, including intermediary arrangements and internal responses. Its detail is useful for control design because it shows how risks can recur in different organizational settings. It does not establish that every relationship in the same country or sector shared the described features, and it should not be used to pronounce guilt on people who were not parties to the DPA.

Country narratives should stay separated in a compliance data model. Each engagement needs its own entity, intermediary, beneficial owners, business sponsor, customer, public-official exposure, contract, invoices, payments, services, red flags, approvals and investigation status. Group-level analysis can then identify recurring patterns without losing the evidence necessary for a fair actor-specific decision.

The DPA also makes cooperation a governance issue. A company facing potential misconduct must preserve records, stop inappropriate conduct, support lawful disclosure and investigate without contaminating individual rights. Cooperation is not simply transferring a document archive. Authorities need reliable provenance, explanations of systems, transaction maps, translations and access to knowledgeable witnesses. The board must oversee the process when allegations may implicate senior or dispersed business leadership.

Judicial approval and public-interest reasoning

The Crown Court’s approval judgment considered whether the proposed UK DPA was in the interests of justice and whether its terms were fair, reasonable and proportionate. The judgment discussed seriousness, cooperation, corporate change, collateral consequences and the financial outcome. Its function was to approve or reject the DPA, not to conduct trials of every employee or intermediary.

Judicial scrutiny is a crucial accountability control because prosecutors and companies cannot privately determine the public sufficiency of a DPA. The court examines why deferral is justified despite serious conduct and whether the sanction reflects the circumstances. That scrutiny should be reported precisely. “Court approved” does not mean “court convicted,” while “deferred” does not mean “no legal consequence.”

The financial components require their own dictionary. The judgment’s Appendix A records count-level calculations and the structure of the financial outcome. Penalty, disgorgement, costs, compensation and amounts credited in another jurisdiction serve different purposes. They are not direct measures of procurement distortion, taxpayer harm, competitor loss or the cost of weakened trust.

The discount applied in a negotiated resolution should not be described as a reward detached from public interest. Cooperation, early admissions and remediation can reduce investigative burden and improve recovery, while the court must still ensure proportionality. A governance analysis should examine the stated reasons rather than infer that cooperation either erased the conduct or made the company uniquely blameworthy.

The judgment also demonstrates why board change and programme reform matter but cannot become reputation evidence alone. Leadership replacement, new controls and cooperation help a court assess whether deferral can protect the public. They remain claims about governance trajectory. Operating effectiveness must be shown later through samples, exceptions, refusals, discipline and independent testing.

The separate US criminal resolution

The Department of Justice’s Rolls-Royce case page provides the official US docket path. It links the information, DPA, press announcement and later dismissal documents. The page is a procedural index; propositions about charges, admissions, obligations and dismissal should follow the controlling instruments.

The US criminal information was a filed charging instrument alleging a conspiracy within US jurisdiction. A criminal information is not a trial verdict. In the DPA structure, it defines the charge whose prosecution is deferred and must be read alongside the company’s admissions and contractual commitments.

The US deferred prosecution agreement contains the company’s agreement, factual admissions, penalty, cooperation and compliance undertakings. It has a separate defendant, jurisdictional basis, facts and term from the UK DPA. A sentence taken from the US statement should not be attributed to the SFO or treated as a Brazilian factual finding merely because the resolutions were coordinated.

The Department’s coordinated-resolution announcement summarized the US penalty, admissions, cooperation assessment and credit for related resolutions. A “global” total is a useful headline only when its components are disclosed. If a Brazilian amount was credited against another penalty, counting both the credited amount and the gross figure as cash paid overstates the economic result.

Coordination does not create one global court. UK prosecutors applied UK law under a UK DPA approved by a UK court. US prosecutors filed a US charge and entered a US DPA supervised in the relevant US court. Brazilian authorities used their own instrument. A compliance team should therefore maintain a jurisdiction matrix with conduct, entities, legal provisions, dates, payments, credits, reporting and closure criteria.

Brazil remains a distinct legal track

The UK and US authority records identify a Brazilian resolution and describe coordination. This article does not reproduce a Brazilian agreement that is not among the frozen sources. It therefore limits Brazilian propositions to what those official instruments say: another authority participated in the coordinated outcome and amounts were treated according to the stated credit arrangements.

That restraint prevents a common error. A description of another jurisdiction’s agreement inside a US or UK document is evidence that the describing authority considered it, but it is not a substitute for the local instrument’s complete terms. Questions about Brazilian parties, admissions, beneficiaries, monitoring, payment status or legal effect require the Brazilian source itself.

For internal governance, the lesson is to avoid using a group settlement label as a closure shortcut. Legal teams need local completion evidence; finance needs reconciled payments and credits; compliance needs to know which remediation commitments apply where; and the board needs a consolidated view that preserves local differences. A single red-green dashboard should link to, not replace, the controlling orders and agreements.

Cross-border remediation also needs consistent minimum standards. A company should not permit a business unit in one jurisdiction to use a less rigorous intermediary file merely because another authority did not impose the same reporting language. Group standards should address ownership, service, payment and monitoring, while local procedures implement privacy, labour, procurement and data-transfer requirements.

Individual proceedings are not inherited from the company

The Department of Justice’s individual-case announcement reported that five people had been charged in a Rolls-Royce-related scheme and that specified defendants had pleaded guilty. The announcement is valuable precisely because it separates procedural status. A guilty plea carries an admitted factual basis for that defendant. An indictment contains allegations, and charged defendants retain the presumption of innocence unless and until guilt is established.

The company’s DPA admissions do not automatically establish an employee’s criminal intent. An organization can accept responsibility for conduct by personnel and control failures while individual cases require proof of personal acts and state of mind. Conversely, an individual plea does not establish that every colleague, intermediary or business unit participated.

A fair case register should include defendant, employing entity or role at the relevant time, charges, filing date, plea or trial status, admitted facts, sentencing, appeals and source. It should never use “the executives pleaded guilty” where only named individuals did so, or “five were convicted” when the official record distinguishes pleas from indictments.

This discipline protects both accountability and due process. Overbroad attribution can harm innocent employees and weaken confidence in investigations. Under-attribution—describing deliberate personal conduct only as a system failure—can obscure agency. The correct approach connects individual evidence to individual outcomes while also examining which controls and incentives allowed the conduct to occur.

Intermediary approval must begin with ownership and capability

Due diligence should establish the legal person receiving the engagement and money. Required evidence includes incorporation, registered address, beneficial ownership, directors, bank-account ownership, tax status and relationships with employees, customers and public officials. Screening should cover sanctions, enforcement, adverse information and conflicts, but name screening alone cannot establish commercial legitimacy.

Capability testing asks whether the proposed intermediary can perform the defined work. Relevant evidence may include technical staff, sector experience, licences, local facilities, past deliverables and references independently obtained. A newly formed company with no relevant employees should not be approved for a large commission merely because a senior commercial sponsor says its contacts are valuable.

Ownership and capability should be refreshed when facts change. A merger, new beneficial owner, new bank account, expanded territory, public-official appointment or unusual subcontractor can alter risk. The contract should require disclosure and allow audit or termination. Payments should stop while a material change remains unresolved.

Relatedness analysis should operate across the group. An intermediary rejected by one business unit must not be reintroduced under a spelling variation, affiliate or different contract type. A global identifier should connect entities, owners, addresses, phones, email domains, bank accounts and nominated subcontractors. Matches create review, not automatic guilt, because legitimate groups can share infrastructure.

Service evidence and commission proportionality

An approved partner is not a permanent entitlement to payment. Each invoice should identify deliverables tied to the contract and programme. Business owners must confirm receipt with evidence such as meeting records, analyses, technical coordination or other work product. Generic monthly invoices and retrospective activity summaries should not support high-risk commissions without corroboration.

Commercial teams should explain why the fee is proportionate. Percentage commissions can rise dramatically with contract value even when effort does not. Review should compare expected work, market practice, complexity, duration and alternatives. Success fees linked to public decisions carry heightened risk and may be prohibited or restricted. Deviations need independent approval and a recorded rationale.

Payment controls should verify that the beneficiary bank account belongs to the approved counterparty in the expected jurisdiction. Requests for cash, split payments, offshore accounts, unrelated third-party recipients or last-minute account changes require escalation. Treasury should receive the compliance status directly from the controlled system rather than a forwarded email from sales.

Service and payment evidence must join. A valid-looking deliverable does not justify funds sent to an unapproved recipient. A correct bank account does not prove work occurred. The transaction packet should contain the approved partner, contract, deliverable, invoice, service confirmation, fee calculation, tax treatment, payment instruction and final settlement record under one durable identifier.

Business-unit oversight cannot be outsourced to compliance

The business sponsor knows the customer, programme and reason for the intermediary. That sponsor should own the truth of the commercial need and service evidence. Compliance should define standards, conduct independent diligence, challenge red flags and possess veto or escalation authority. If compliance becomes the only accountable owner, sales leaders can treat approval as a warranty that transfers all later responsibility.

Civil aerospace, defence aerospace and energy units can have different customers, contracting cycles, technical needs and public-sector exposure. Group controls should be consistent in principle and tailored in operation. Defence or state-owned-customer relationships may require enhanced review. Energy projects may use local consortiums or logistics providers. Civil programmes may involve long-term sales campaigns. Tailoring must increase explanatory precision, not create loopholes.

Business-unit leaders should receive dashboards showing active intermediaries, fees, public-official touchpoints, overdue diligence, service exceptions, rejected proposals, overrides and investigations. Aggregate spend alone is limited public evidence. A low-value engagement can be high-risk, and multiple small payments can avoid thresholds. Trends should be compared across regions and sponsors.

Performance incentives require board attention. Revenue targets, market-entry objectives and programme milestones can make an intermediary appear indispensable. Compensation should not reward leaders for contracts whose diligence or payment evidence is unresolved. Deferral and clawback arrangements should reflect compliance outcomes, subject to lawful and fair process.

Company governance and the 2017 response

Rolls-Royce’s 2017 resolution statement presented the company’s account of cooperation, financial terms, personnel action and programme change. Company statements are important for understanding governance commitments. Authority documents control the legal character, and later evidence is needed to assess whether the described controls operated.

The 2017 annual report described board and committee oversight, ethics and compliance resources, intermediary review and obligations under the resolutions. Statutory reporting creates accountability by requiring management and directors to describe principal risks and governance. It remains management reporting and should not be treated as independent transaction-level assurance.

Board committees need a meaningful view of third-party risk. Useful measures include engagements proposed, approved, rejected and terminated; due-diligence ageing; ownership gaps; public-official connections; percentage and success fees; payment holds; substantiated speak-up cases; repeat sponsors; and audit findings. A presentation limited to training completion and policy publication can show activity while hiding whether difficult transactions were stopped.

Internal audit should test the entire workflow from business case to payment and renewal. Samples should include high-risk approvals, low-risk approvals, rejected proposals, overrides and engagements just below thresholds. Reviewers should independently confirm ownership and services rather than inspect only the documents stored by the control owner. Findings should have named owners and due dates, with overdue items reported to the board.

Independent review and programme implementation

The 2018 annual report reported continued ethics and compliance work, board committee attention, training and independent review. An independent reviewer can assess design and implementation, identify gaps and verify whether recommendations are completed. Independence depends on access, mandate, expertise and the ability to report candidly to the board and authorities.

Recommendation closure should require evidence. A new procedure is not “implemented” merely because it was approved. The company should show deployment across relevant entities, system configuration, migrated intermediary data, trained users, tested access, sample decisions and corrected exceptions. A recommendation may be complete in project terms while the underlying control remains immature.

The strongest validation includes refusal. How often did the programme reject an intermediary, stop a payment, require a different fee or terminate a relationship? A system that approves every request may face uniformly excellent proposals, but it may also lack independence. Refusal data should be interpreted with context and not turned into a quota; otherwise staff may reject harmless cases to improve a metric.

Speak-up evidence also matters. Employees and third parties should have confidential channels, accessible languages and protection against retaliation. Case management should identify allegations involving senior leaders or control personnel and route them outside normal management. The board should see substantiation, ageing, corrective action and retaliation claims while protecting privacy and due process.

Completion of the UK DPA

The SFO’s details of compliance records performance and expiry of the UK agreement, including payment, cooperation and independent-review activity. It is the appropriate source for procedural completion. Completion means the requirements were met to the standard and process described; it does not repeal the agreed facts or prove recurrence impossible.

A completion record should therefore coexist with the historical case file. Employees need to understand why controls exist without assuming all current colleagues share past responsibility. Investors need to distinguish legal closure from residual risk. Regulators and auditors need evidence that records remain available after formal reporting ends.

Boards can prevent “programme decay” by assigning post-DPA ownership. Monitoring, audit and reporting should continue when authority deadlines disappear. Control budgets should not fall automatically because a DPA expires. High-risk markets, intermediary populations and commercial incentives can change, requiring new tests rather than maintenance of the exact historical programme.

Lessons should be embedded in ordinary approval systems. If the special DPA team holds all knowledge, its departure creates a control cliff. Business, finance, procurement, legal, compliance, technology and internal audit should each own durable parts of the evidence chain, with documented handoffs and common identifiers.

US completion and dismissal

The government’s motion to dismiss said the company had fulfilled the US DPA’s requirements, including the matters summarized in the filing, and requested dismissal. A government motion is a representation to the court and a procedural step. It is not itself the judicial disposition.

The court’s dismissal order dismissed the information with prejudice after the agreement term. “With prejudice” prevents refiling of that information as specified by the order; it is not an acquittal after trial and does not announce that every future intermediary control will succeed.

The distinction between corporate completion and effectiveness is essential. Authorities can reasonably conclude that contractual obligations were met based on reports, cooperation and certifications. Stakeholders may still ask whether controls detect new forms of third-party risk, operate across acquired entities and survive leadership change. Those are governance questions beyond the dismissal order’s procedural scope.

Closure metrics should separate obligations: money paid, reports delivered, recommendations completed, investigations supported, records retained and cases dismissed. Combining them into a single “100% complete” score obscures the different evidence and residual risks attached to each.

Evidence of durability after the resolutions

The 2020 annual report described post-resolution ethics, due diligence, training, speak-up and board indicators. Such reporting helps stakeholders track continuity. Completion percentages and activity counts, however, do not show whether training changed decisions or whether diligence detected concealed ownership.

Durability testing should use scenarios. One can introduce a proposed adviser with an undisclosed common owner, a bank account outside the contracting country and a commission unsupported by deliverables. The test asks whether systems connect the attributes, whether staff escalate, whether payment blocks work and whether senior commercial pressure can override the result without visibility.

Another scenario is a legitimate intermediary that changes ownership mid-contract. The programme should detect the change through contractual notification, screening refresh or payment verification; suspend affected activity; reassess connections and capability; and document reinstatement or termination. Periodic review dates alone may leave a long exposure window.

Data quality is part of compliance effectiveness. Third-party records need stable identifiers and common definitions across business units. Duplicate entries, free-text country names, missing owners and disconnected accounts undermine analytics. Access logs and change histories should show who changed risk ratings or approval conditions. Compliance technology should make responsibility visible, not convert judgment into an unexplained score.

The company’s current ethics and compliance description outlines present programme components such as third-party controls, training and speak-up. It is design evidence at the date accessed. Independent assurance requires transaction samples, control exceptions and outcomes. A current web page cannot prove how a historic payment was controlled or that every present engagement is effective.

A practical proof packet for every high-risk intermediary

The packet begins with the business request: programme, customer, geography, service, need, alternatives, expected value, duration and sponsor. It adds counterparty identity, beneficial owners, directors, employees, public-official links, bank account and tax status. Screening results should preserve underlying matches, review decisions and dates rather than only a final risk colour.

The contract layer contains the scope, deliverables, fee basis, audit rights, compliance promises, subcontracting restrictions, notification duties and termination rights. Any deviation from standard terms should name the approver and reason. Side letters, oral commitments and amendments belong in the same record.

The performance layer contains contemporaneous deliverables and independent confirmation by someone able to assess them. The payment layer contains the invoice, fee calculation, payee verification, tax handling, approval and settlement. The monitoring layer contains refreshes, red flags, investigations, training, certifications and renewal decisions.

The packet also records refusal and uncertainty. Missing ownership, unverified service, unexplained account changes and unresolved allegations should appear as open conditions that block payment or renewal. A dashboard that converts missing data to “low risk” because no adverse match was found reverses the burden of proof.

For public-sector or state-owned customers, the packet should map relevant decision-makers, procurement stages, permitted contacts and hospitality or gift restrictions. It should never assume that a state-owned enterprise has the same legal status in every jurisdiction. Local advice must be documented, and group minimum standards still apply.

A control-ownership matrix for the full payment path

Sales or programme management owns the initial proposition. It identifies the opportunity, customer process, need for an intermediary and commercial assumptions. Its evidence should make the relationship understandable to a reviewer with no background in the account. A statement that the intermediary is customary or personally trusted is not evidence. The sponsor must disclose how the candidate was found, any employee or customer recommendation, known connections, anticipated contacts and the consequences if the engagement is refused.

Procurement owns the contractual sourcing process without pretending that ordinary price competition resolves integrity risk. It checks whether alternative providers were considered, whether specifications were tailored to a preferred party, and whether amendments change the risk originally approved. Procurement should be able to see compliance conditions and prevent a purchase order from bypassing them. Emergency procedures need defined duration, senior approval and retrospective review rather than becoming an informal path for relationship-driven work.

Compliance owns independent diligence standards, risk assessment and challenge. It should have access to ownership databases, screening tools, case records and local expertise. Its reviewer must be sufficiently independent of the commercial hierarchy to refuse or escalate. Compliance should document what it verified, what remains represented by the third party and what conditions apply. A risk score without its component evidence is not auditable.

Legal owns the enforceability and clarity of the contract, local-law analysis and response to investigations. It should ensure that the scope and payment terms match the approved business case and that audit, information, termination and subcontractor provisions are usable. Legal advice may rely on stated facts; those assumptions must be visible to the sponsor and approvers. An opinion cannot cure false ownership or nonexistent services.

Finance owns accounting classification, invoice checks, fee calculation, tax treatment and ledger integrity. It should understand whether a commission is capitalized, expensed, accrued or contingent, and whether recognition matches actual performance. Finance should challenge invoices that repeat contract language without describing work and entries that move costs between programmes or entities. Month-end urgency must not reduce evidence requirements.

Treasury and accounts payable own beneficiary verification and execution. They confirm that the payee matches the approved entity and bank account, sanctions checks remain current and required approvals are active. System controls should prevent an employee from changing master data and releasing the resulting payment. A callback to contact details supplied in the change request is not independent confirmation; verification should use previously controlled information.

Technology owns workflow integrity, access, interfaces and logs. Approval status should pass directly from the due-diligence system to procurement and payment platforms. Manual copying invites error and manipulation. Privileged changes need segregation, immutable history and alerts. Data retention must support investigation while complying with privacy and localization law. Analytics should identify linked owners, addresses, accounts and sponsors across business units.

Internal audit owns independent testing, not operation. It reviews whether each function performed its role and whether the end-to-end chain proves the transaction. Audit should select samples using risk indicators and random coverage, confirm information externally where appropriate, and report systemic themes rather than isolated paperwork gaps. It should also test the reliability of management dashboards before the board relies on them.

The executive committee owns resources and consequences. It decides whether commercial leaders are rewarded for compliant, cash-generating business or only for contract awards. It resolves disputes when a business claims that a control threatens a strategic opportunity. Any override should state the evidence, decision-maker, expiry and monitoring, and should reach the board committee for high-risk cases. Some conditions should be non-overridable, including an unidentified payee or prohibited payment.

The board owns assurance that the matrix operates. Directors do not redo diligence, but they should ask which control failed, which detected the problem, how quickly it escalated and whether incentives contributed. They should see both gross populations and unresolved exceptions. A committee cannot assess exposure from percentages alone when the number and value of intermediary relationships are changing.

Measurement, investigation and remediation discipline

Measurement begins with stable populations. The company should know how many intermediaries are active, inactive, proposed, rejected and suspended; which business units sponsor them; and what payments and customer programmes they touch. Duplicate or dormant records distort denominators. A global master should retain historical states so management cannot make risk disappear by closing and recreating an account.

Due-diligence metrics should distinguish completeness from judgment. Percentage of files with ownership data, percentage independently verified, screening alerts reviewed, enhanced diligence completed and overdue refreshes are separate measures. Combining them into one score can allow a strong training metric to compensate for missing payee identity. Hard gates should remain visible and non-compensating.

Payment metrics should track gross and net amounts, currency, fee basis, beneficiary jurisdiction, account changes, manual releases, holds and rejected instructions. Commission concentration by sponsor, intermediary, customer and programme can reveal dependency. Analysts should examine payments just below thresholds and activity clustered around reporting periods. A pattern is a trigger for explanation, not proof of misconduct.

Service-evidence metrics need qualitative sampling. Counting uploaded files encourages low-value documentation. Reviewers should assess whether work product is contemporaneous, specific, useful, consistent with the intermediary’s capacity and independently acknowledged by the business. Sampling results should record failure types: no deliverable, generic deliverable, unsupported time, duplicate content, mismatch with invoice or inability to confirm receipt.

Investigation metrics should protect fairness. Cases can be classified by allegation, seniority, country, source, substantiation, time to preserve evidence, time to decide and corrective action. A faster closure rate is not always better if complex cases are prematurely narrowed. Boards need ageing and reasons for delay, while privacy controls limit unnecessary distribution of names and sensitive details.

Remediation should address cause, not only the failed file. If a payment passed because an account change was accepted by email, correcting the bank record is limited public evidence. The company should modify the workflow, segregate access, test the block, search for similar changes and train affected staff. Cause categories should distinguish deliberate override, ambiguous policy, poor system design, missing data, limited public evidence capacity and ineffective supervision.

Discipline should be consistent across hierarchy and business performance. Consequences can include coaching, warning, compensation adjustment, reassignment or termination, subject to law and fair process. The company should compare outcomes for similar conduct and document reasons for differences. Strong revenue results should not reduce consequences; good-faith escalation and cooperation should not be punished.

Remediation validation belongs to an independent function. The control owner supplies evidence, but internal audit, an independent reviewer or another qualified party tests design and a sample of operation. A closure memo should state the population, test period, exceptions and residual risk. “Implemented” should mean more than a policy was issued or a system field added.

The board should receive a post-resolution trend that spans several years. It can show whether intermediary count and spend changed, whether ownership verification improved, whether payment holds occur, whether repeat findings declined and whether speak-up remains trusted. Changes in business mix should be explained so a lower number is not automatically read as improvement. A mature programme may surface more issues because detection has become stronger.

Public reporting must balance transparency, privilege, privacy and investigative integrity. Stakeholders benefit from concrete control categories and governance ownership, but disclosure should not identify uncharged individuals or compromise active cases. Amounts and legal status require definitions. A report should state whether a measure describes programme activity, management testing, internal audit, independent review or authority conclusion.

Finally, effectiveness is contextual. A programme can pass historical DPA requirements and still face new risks from acquisitions, digital sales channels, sanctions changes, remote work or different partner structures. Periodic risk assessment should translate those changes into revised tests. The goal is not permanent confidence in a fixed programme; it is an institution capable of detecting when its assumptions no longer hold.

Conclusion

Rolls-Royce’s coordinated resolutions transformed third-party relationships from a local sales practice into a test of group accountability. The core control question is whether a company can prove, before payment, that an intermediary is transparent, capable, necessary, fairly compensated and performing real services—and that the customer or public decision remains uncorrupted.

The legal record must remain segmented. The UK DPA, statement of facts and judicial judgment form one conditional corporate resolution. The US information, DPA, completion motion and dismissal order form another. Brazil was a separate authority track. Individual pleas establish only those defendants’ admissions; indictments remain allegations. Corporate completion does not become an acquittal or an indefinite certificate of effectiveness.

Durable repair joins ownership, service and payment evidence under a common identifier. It gives compliance independent challenge while leaving commercial truth with the business sponsor. It tests rejected cases and overrides as well as approvals. It protects speak-up, preserves records across borders and reports unresolved exceptions to the board before revenue pressure determines the result.

Global compliance succeeds when a reviewer can reconstruct why the intermediary was engaged, what was delivered, how the fee was set, who approved it and where the money went. Without that proof, policies and dashboards can create the appearance of control. With it, third parties can support legitimate international business without becoming an opaque channel through which accountability disappears.