What Southern Glazer’s compliance overhaul tells us about an effective anti-bribery programme

A company can have a code of conduct, compliance policies, training and a whistleblowing process and still have a serious compliance failure.

That is one of the more useful lessons from the US Department of Justice’s September 2026 settlement with Southern Glazer’s Wine & Spirits. The US alcohol distributor agreed to pay $12.5 million under a two-year non-prosecution agreement following an investigation into years of improper payments, gifts and benefits provided to employees of alcohol retailers.

The case is unusually instructive because the DOJ set out in considerable detail what Southern Glazer’s had subsequently done to strengthen its compliance programme, including major increases in compliance staffing and budget, changes to senior leadership, enhanced third-party controls, new auditing processes and a network of local compliance champions. Those reforms were among the factors the DOJ expressly considered in agreeing not to prosecute the company. 

As we’ve often said at VinciWorks, it is far easier, cheaper, and less of a headache to have a fully functioning compliance programme on your own terms, rather than it be imposed by a regulator with a massive fine on top. So what can we learn from this action?

What happened at Southern Glazer’s?

Southern Glazer’s is the largest wine and spirits distributor in the United States, employing more than 24,000 people and operating across 46 states and the District of Columbia. 

Federal prosecutors alleged that between at least 2016 and 2024 a group of employees participated in a scheme involving payments and benefits to grocery-chain alcohol buyers in return for increased purchases of particular brands. Five former Southern Glazer’s employees were indicted in March 2026. The allegations against those individuals remain allegations and they have not been convicted.

The methods allegedly used are familiar from many bribery cases. They included prepaid gift cards worth up to $1,000 each, luxury goods, golf trips, hotel stays and other benefits. Approved vendors were allegedly used to generate invoices that appeared to relate to legitimate marketing activity while actually funding gifts, travel and other expenditure.

Southern Glazer’s subsequently admitted and accepted responsibility in its non-prosecution agreement for conduct involving improper payments and benefits to its own employees and to employees of retail customers. The agreement records that some payments were facilitated through third-party vendors, supported by falsified invoices or sent directly by alcohol suppliers with the knowledge of certain Southern Glazer’s employees. 

The scale of the third-party issue is striking. One approved vendor was used to purchase millions of dollars of prepaid gift cards and arrange travel, while the associated funds frequently came from invoices that did not accurately describe what the money was being used for. The compliance weakness went far deeper than an absence of vendor onboarding.

Southern Glazer’s already had a compliance programme

Like most companies, Southern Glazer had compliance policies, a Code of Conduct, an employee handbook, trade-practice training and procedures for reporting, investigating and remediating misconduct. In 2019, Southern Glazer’s also responded to known trade-practice problems by telling third-party marketing companies that they could no longer handle incentives and gift cards. However despite appearances, failures still took place. 

Employees of alcohol suppliers were told around 2019 that Southern Glazer’s would no longer process sales incentives through certain third-party vendors. Employees nevertheless continued to receive funds outside approved processes, including in some cases directly from suppliers working with third parties.

There is an important compliance lesson here. A remedial action can be entirely sensible and still prove inadequate if the organisation does not test whether people have found another route around the control.

Blocking gift cards through Vendor A may achieve little if the same payment can be routed through Vendor B, made directly by a supplier or disguised under a different expense category. Remediation has to address the underlying risk and incentives, rather than simply close the channel through which the latest incident happened to occur.

The compliance overhaul

From 2023 onwards, Southern Glazer’s undertook a much wider restructuring of its compliance arrangements. The level of detail published by the DOJ provides a rare opportunity to see which changes prosecutors considered significant.

Governance was strengthened considerably. The general counsel was promoted to Executive Vice President and Chief Legal and Compliance Officer, reporting directly to the CEO. A new Senior Vice President of Compliance & Ethics was appointed, alongside a Vice President and Associate General Counsel for the West region. Legal and compliance responsibilities were also mapped across the company’s five business regions. 

That enhanced authority was supported with considerably greater resources. Compliance headcount increased by 85% between 2022 and 2024, while funding rose by more than 65%. The company also brought in external compliance specialists to advise on its programme. 

Accountability followed. Some vice presidents and managers were removed for policy violations, other employees were disciplined and senior leadership in California and the West region was replaced. At the same time, the CEO and senior management increased compliance and ethics messaging, while the company introduced a revised set of corporate values. 

Southern Glazer’s also tried to embed compliance closer to the business. It established compliance champions in each state to promote awareness and provide local support. For a large organisation operating across different markets and regulatory environments, this is significant. Central compliance can set standards and oversee risks, while local representatives can help identify how those risks actually present themselves in individual business units. 

Controls over transactions were also strengthened. The company introduced a Trade Practice Compliance Audit Program and an “iShop” platform covering marketing and promotional expenditure, alongside additional mandatory ethics and compliance training. 

Third-party management received particularly substantial attention. Vendors became subject to enhanced due diligence and documentation requirements, contractual compliance and audit standards and audit rights. Vendors also had to be approved before payments could be issued, and some vendors were removed as a result of the new requirements. 

What does an effective compliance programme actually look like?

A good programme begins with the risks generated by the business itself. In this case, suppliers, marketing funds, promotional expenditure, retailers, gifts, entertainment and third-party vendors were central to the commercial model and therefore central to the compliance risk. The settlement requires periodic risk assessments that take account of factors such as the company’s geography, sectors of operation and level of regulatory oversight, with policies reviewed at least annually. 

This is a useful reminder for organisations relying on generic anti-bribery policies. Effective risk assessment should tell a business where bribery could realistically occur, how payments could be disguised, who has the ability to approve them and which transactions deserve additional scrutiny.

Additional resources are also important. An 85% increase in headcount and a 65% increase in budget do not automatically produce effective compliance. They do demonstrate that Southern Glazer’s treated the programme as something requiring meaningful capacity rather than simply assigning responsibility to an overstretched legal or compliance team. The DOJ guidance specifically asks whether compliance is sufficiently resourced and empowered.

The same applies to seniority. Southern Glazer’s placed compliance responsibility with an executive reporting to the CEO and created additional senior roles. Under the compliance agreement, responsible senior executives must have sufficient autonomy, authority and resources, as well as access to internal audit or appropriate board or executive bodies. 

Follow the money, not just the policy

The case also shows why financial controls should form part of anti-bribery compliance. The alleged conduct was hidden through invoices, supplier marketing funds, bill-backs, expenses and approved vendors. Those are accounting processes as much as conventional compliance issues.

Southern Glazer’s reforms therefore went into the mechanics of expenditure. Its programme now includes independent auditing of bill-backs, accounts payable and employee reimbursement systems, alongside enhanced vendor controls and monitoring of marketing expenditure. 

For compliance teams, that means working closely with finance, procurement and internal audit. A gifts and hospitality policy may prohibit improper expenditure, yet the more valuable question is whether the organisation can identify payments that do not make commercial sense, invoices that disguise their real purpose, repeat payments through unusual vendors or expenses being deliberately split or rerouted.

Technology can help, particularly where organisations have large transaction volumes. It still needs to be aimed at the risks revealed by the risk assessment rather than simply producing more compliance data.

Third-party due diligence cannot end at onboarding

Some of the alleged conduct involved vendors that had already been approved. The problem was what happened once those vendors were inside the organisation’s payment infrastructure. A mature third-party programme therefore needs controls throughout the relationship. Due diligence before appointment remains important, alongside clear contractual expectations, periodic review, monitoring of actual transactions, audit rights and a credible process for suspending or terminating relationships when concerns arise.

This approach closely reflects the DOJ’s wider compliance expectations. Prosecutors are instructed to consider whether businesses manage third-party risk throughout the lifespan of the relationship and what they do when warning signs emerge.

Southern Glazer’s new controls went further still by making vendor approval a prerequisite to payment. That connects third-party compliance directly to accounts payable, rather than leaving due diligence in a separate compliance database that business processes can bypass.

Are your anti-bribery procedures good enough? Join our webinar on 11 November 2026

Be the first to know about releases and industry news and insights.

By filling in this form you agree to share your information with VinciWorks. We take privacy seriously, click here to read our privacy notice.