The U.K. Financial Conduct Authority And Its Focus On Adequate Procedures To Prevent Bribery

Today’s post is from Robert Amaee (Covington & Burling), the United Kingdom Expert for FCPA Professor.

In the post, Amaee notes that while the U.K. Bribery Act does not have formal books and records and internal controls provisions like the FCPA, the U.K. Financial Conduct Authority (which regulates firms in the U.K. that provide financial products and services to U.K. and overseas customers and is the U.K. listing authority) has brought several recent enforcement actions against regulated entities on grounds similar to typical FCPA books and records and internal controls actions.

*****

The recent enforcement action taken by the U.K. Financial Conduct Authority (“FCA”) against JLT Specialty Limited (“JLTSL”) is the latest example of the regulator’s drive to penalize companies in the financial sector for failures in their anti-corruption policies and procedures, even in the absence of any evidence of bribery.  There is every indication that the FCA will continue to use its regulatory powers to bring enforcement actions against companies that it deems not to have adequate anti-corruption controls.  In the words of Tracy McDermott, the FCA’s Director of enforcement and financial crime:

“[b]ribery and corruption from overseas payments is an issue we expect all firms to do everything they can to tackle. Firms cannot be complacent about their controls – when we take enforcement action we expect the industry to sit up and take notice.”

This article outlines the FCA’s role in combating financial crime and discusses some pertinent aspects of the JLTSL case as well as previous cases against Willis Limited (“Willis”), and Aon Limited (“Aon”).

The remit and track record of the Securities and Exchange Commission (“SEC”) in enforcing the internal control and accounting provisions of the Foreign Corrupt Practices Act 1977 is well known to readers of FCPA Professor.  Companies that are US issuers have an obligation to keep accurate books, records and accounts, and to devise and maintain sufficient internal accounting controls to ensure such accuracy.  In the UK, the Bribery Act 2010, does not contain equivalent internal control or accounting provisions.

In the case of a company that is suspected of failing to prevent bribery, the Serious Fraud Office (“SFO”) — the lead agency tasked with enforcing the Bribery Act — must assess the adequacy of the company’s procedures (i.e., whether the company has a defence) before deciding to bring Bribery Act charges (see Sec. 7 of the Bribery Act).   In the absence of evidence of bribery, however, the SFO cannot simply take enforcement action under the Bribery Act against a company for failures in its anti-corruption procedures.  In respect of a suspected failure to keep adequate accounting records, UK Prosecutors have in the past resorted to bringing action under the provisions of the Companies Acts of 1985 and 2006.  In 2010, for example, the SFO relied on section 221 of the Companies Act 1985 (now replaced, in substantially the same form, by the sections 386 and 387 of the Companies Act 2006) to sanction BAE for a failure to keep adequate accounting records in relation to payments made to a third party intermediary.

The FCA

The FCA, which took over the majority of the responsibilities of the Financial Services Authority (“FSA”) in April 2013, however, has a statutory objective under the Financial Services & Markets Act 2000 (as amended by the Financial Services Act 2012) to protect and enhance the integrity of the UK financial system.  This market integrity objective includes tackling the risk that the financial sector companies that it regulates may be used for a purpose connected with financial crime, including fraud, money laundering, and bribery and corruption.  In its July 2013 publication, The FCA’s Approach to Advancing its Objectives, the FCA states: “we will take action against firms found to be using corrupt practices, or failing to prevent bribes being paid to win business.”

To achieve this objective, the FCA has imposed, via the FCA Handbook, a number of financial crime requirements on the financial sector companies that it regulates. The key requirements are set out in Principles 1 (integrity), 2 (skill, care and diligence), 3 (management and control) and 11 (relations with regulators) of the FCA’s Principles for Businesses (“PRIN”); and Chapters 3 and 6 of the FCA’s Senior Management Arrangements, Systems and Controls sourcebook (“SYSC”).

In addition, the FCA’s recently published Thematic Review TR13/9 (October 2013) (here) on Anti-Money Laundering and Anti-Bribery and Corruption Systems and Controls, based on an assessment of 22 companies, sets out a case-based analysis of good and bad practice examples for businesses dealing with the risks of bribery and corruption. The October 2013 review followed previous thematic reviews of anti-corruption controls in commercial insurance broking (2010), in investment banking (2012), and AML and sanctions controls in trade finance (2013). The foregoing, together with the FCA’s Financial Crime: A Guide for Firms (here), provide companies with a clear indication of the FCA’s expectations in relation to the implementation and monitoring of anti-corruption systems and controls.

The recent JLTSL enforcement action followed the FCA findings of a breach of Principle 3 of PRIN.  Principle 3 provides that “A firm must take reasonable care to organise and control its affairs responsibly and effectively, with adequate risk management systems.”  This includes implementing checks and controls designed to prevent bribery and corruption overseas.   For a breach of Principle 3 to be established, there is no need for the FCA to show that suspicious payments were made or that an act of bribery has taken place.  In both the Aon and Willis cases investigations did show that suspicious payments were in fact made, while in the JLTSL case there was no evidence of suspicious payments having been made.

JLT Speciality Limited

On December 19, 2013 JLTSL, a wholly owned subsidiary of JLT Group (the largest European broker quoted on the London Stock Exchange), was fined £1,876,000 in respect of breaches of Principle 3 of PRIN.  The FCA found that JLTSL had failed to carry out effective due diligence before entering into relationships with, and making payments to overseas introducers.  The FCA found that the overseas introducers had been paid in excess of £11.7 million, representing some 57% of the total amount received by JLTSL from the business that had been introduced by the overseas introducers.  There was no evidence of bribery or any improper intent on the part of JLTSL, but the FCA concluded that the failings gave rise to an unacceptable risk that the payments made to the overseas introducers could have been used to pay bribes “to persons connected with the insured clients and/or public officials.”

It is worth noting that the FCA brought this action against JLTSL in spite of the fact that it found that JLTSL had (i) implemented policies and procedures aimed at countering the risk of bribery and corruption, including an Employee handbook and a Group Anti-Bribery and Corruption Policy which prohibited JLTSL employees from engaging in any form of bribery, an Operating Procedure Manual which contained more detailed procedures that employees had to follow in order to establish relationships with overseas introducers, and a 7 Alarm Bells policy to assess the bribery and corruption risk associated with entering into a relationship with an overseas introducer; and (ii) engaged an external adviser to review its systems and controls to assess compliance with the provisions of the Bribery Act 2010, concluding that the due diligence procedures in relation to introducer/facilitator relationships appeared comprehensive and broadly in line with the Act.

The FCA took the position that there was a failure to conduct adequate due diligence, and the external advisor had not conducted aholistic” review of JLTSL’s systems and controls.  JLTSL also was found to have failed to adequately assess bribery and corruption risks, only carrying out a risk assessment at the start of each relationship not every time that overseas introducer introduced a new piece of business.  JLTSL also failed to adequately implement its own anti-bribery and corruption policies, which resulted in the risk of JLTSL entering into higher risk relationships with overseas introducers without senior management oversight and approval.

Specifically, JLTSL failed to assess whether or not there were any connections between the overseas introducers and the clients or any public officials.  Although both the OPM and the Alarm Bells highlighted the importance of carrying out due diligence, there was a lack of practical guidance “to employees in order to establish whether the Overseas Introducer was connected to the client it was introducing.”  On reviewing 17 of JLTSL’s relationships with overseas introducers, the FCA found that in the majority of cases in which the overseas introducer was a company, JLTSL had failed to screen one or more directors or beneficial owners.  In one example, a major shareholder of the overseas introducer was known to JLTSL to be a Nigerian public official. The FCA concluded that as a Nigerian public official it was entirely possible even probable that the shareholder of the overseas introducer would have connections to West African public officials.

Willis Limited

On July 21, 2011 the insurance broker Willis was fined £6,895,000 for failings in its anti-corruption systems and controls (breaches were for Principle 3 of PRIN and Rule 3.2.6 R of the SYSC) which “contributed to a weak control environment surrounding the making of payments to Overseas Third Parties.”

The FSA found that overseas third parties had received commissions of approximately £27 million, representing some 45% of the brokerage earned by Willis from the business that had been introduced by the overseas third parties.  The FSA’s findings were supported by Willis’ own internal investigation which identified a number of suspicious payments made to overseas third parties, two of which formed the subject of suspicious activity reports that Willis submitted to the Serious Organised Crime Agency (“SOCA”) (now replaced by the National Crime Agency (“NCA”)).

The FSA did not find any evidence to suggest that Willis’s conduct was either deliberate or reckless.  It acknowledged that Willis had introduced improved anti-corruption policies and guidance in 2008, reviewed how its new policies were operating in practice and further revised its guidance in 2009.  The FSA, however, formed the view that Willis had failed to ensure its policies were adequately implemented, that failures by staff to adhere to the new policies were identified in a timely manner, or that the Board was provided with sufficient relevant management information regarding the performance of the new policies.

Specifically, the FSA concluded, inter alia, that Willis had (i) failed to ensure that it had established and recorded an adequate commercial rationale for using overseas third parties; (ii) failed to provide formal training or adequate guidance for staff who only recorded brief descriptions of the reason for making commission payments; and (iii) conducted inadequate due diligence on overseas third parties to establish, for example, any connections with the insured, insurer or public officials.

Aon Limited

On January 6, 2009 Aon was fined £5,250,000 for failing to “take reasonable care to organise and control its affairs responsibly and effectively, with adequate risk management systems” (breach of Principle 3 of PRIN).  In particular, the FSA highlighted Aon’s failure to establish and maintain effective systems and controls for countering the risks of bribery and corruption associated with its use of overseas Third parties in high risk jurisdictions.

As in the Willis case, the FSA found that the failings led to a weak control environment that gave rise to an unacceptable risk that Aon could become involved in potentially corrupt payments to win or retain business. The FSA highlighted 66 suspicious payments totalling in excess of US$7 million that were paid to nine overseas third parties.  Aon’s own internal investigation identified a number of suspicious payments that it later reported to SOCA.

The FSA concluded, inter alia, that (i) procedures lacked adequate levels of due diligence either before commencing relationships with overseas third parties or before payments were made; (ii) Aon failed to monitor its relationships with overseas third parties in respect of specific bribery risks; (iii) Aon did not provide its staff with sufficient training and guidance on bribery and corruption matters; and (iv) Aon failed to ensure that the committees it appointed to oversee bribery and corruption risks received relevant management information or routinely assessed whether bribery and corruption risks were managed effectively.  Aon also failed to implement effective internal systems and controls to mitigate those risks.  Margaret Cole, FSA director of enforcement at the time, described the case as sending a clear message that it is completely unacceptable for firms to conduct business overseas without having in place appropriate anti-bribery and corruption systems and controls”.

Adequate Procedures

The FSA’s 2009 action against Aon marked the start of period of concerted effort by the regulator to take action against companies deemed to have inadequate policies and controls, in particular in respect of the risks associated with making payments to overseas third parties.  The Aon action was followed in 2011 by the FSA’s action against Willis for failings in its anti- corruption policies and controls.  In bringing its recent action against JLTSL, the FCA has clearly signalled its intention to continue the focus on companies’ internal anti-corruption control environment. In addition, a number of separate enforcement actions have confirmed that the FCA remains focused on ensuring companies also maintain adequate anti-money laundering policies and controls.  See here, here, here and here.

It is clear, in particular from the JLTSL case, that the FCA will not be impressed by the volume of policies and controls that have been drafted or the fact that an external vendor has given the anti-corruption program the all clear.  The FCA is focused on the effectiveness of the policies and controls and how they have been implemented, and how they are being monitored in practice.  There is little doubt that when the SFO starts to bring enforcement actions against companies under the failure to prevent bribery offence contained in section 7 of the Bribery Act, its assessment of the adequacy of a company’s policies and controls will similarly focus on their real life implementation, and not on the elegance of the prose, or the sign off of external vendors.

In A Way, It Is Like Gambling

Last week Penn National Gaming Inc. Chairman Peter Carlino spoke at the Baron Investment Conference in New York.  This article by CNBC’s Lawrence Delevingne states:

“The U.S. government is too restrictive in trying to prevent its companies from corruption abroad and it’s hurting business expansion in Asia and elsewhere, according to Carlino. ‘There’s a little bit of overzealousness in this,’ Carlino said during a speech at the Baron Conference. ‘Those are limitations that American companies face that others don’t.’  Carlino said he wants to get into the lucrative Asian casino market—Las Vegas Sands already has a large presence in Macau, for example—but hasn’t been able to out of fear of violating U.S. rules.  […] ‘There’s a problem for U.S. businesses, frankly. We had an interesting opportunity in a country that I won’t name; we were hampered in a major way by the American Foreign Corrupt Practices Act,’ he said.  […]  Carlino said Penn looked at expanding into the Asian country via an existing company but one of the line items of the business was to pay off the border guards.  ‘It seems OK to me, frankly. If that’s the game, we’ll play it,’ Carlino said to chuckles from the mostly retiree Baron fund-shareholder audience. ‘There are problems for American companies trying to do business.’  ‘If it’s there, we’re looking at it. Problem is, the pickings are slim,’ he said of countries like Burma, India and Sri Lanka. ‘So finding the right opportunity, although we look and I trust we will, is tough,’ Carlino added.”

There are two ways to view Carlino’s comments.

The first is that Carlino meant that the FCPA – the law passed by Congress – is hurting U.S. business abroad.  If so, well that is a correct policy decision that Congress knew and accepted when it passed the FCPA in 1977.  For instance, as highlighted in “The Story of the Foreign Corrupt Practices Act,” during a Congressional hearing Representative John Moss stated:

“To think that no loss of business would occur in every instance would be unrealistic. Can we allow this to occur? Yes, if that is the small price we must pay to return morality to corporate practice. Yes, if that is the small price we pay to show that U.S. firms compete in terms of price, quality, and service and not in terms of the size of a bribe. Real competition works. The vast majority of American companies have operated successfully in foreign countries without the need to resort to bribery.”

Likewise, Treasury Secretary Michael Blumenthal stated:

 “To the very, very small extent a particular company may lose a particular contract because it refuses to engage in this practice, I would be willing to say, all right, we will be at a slight competitive disadvantage and we will all sleep the better for it.”

The second way to view Carlino’s comments is that he conflated FCPA enforcement with the actual FCPA – as Donald Trump also did as highlighted in this prior post.  In other words, Carlino confused FCPA enforcement with the FCPA.

Simply put, there is often a difference between FCPA enforcement and the FCPA.

For instance, Congress specifically exempted facilitation payments from the FCPA’s anti-bribery provisions.  However, it is an open question whether the facilitating payments exception has any real meaning or whether the enforcement agencies have essentially repealed this exception through its enforcement theories.  For instance, the SEC’s former Assistant Director of Enforcement has called the FCPA’s facilitating payment exception “illusory” and stated:

“The drafters of the FCPA recognized that such demands for ‘grease payments’ are a reality in many countries, and accordingly made clear that certain payments made to expedite the approval of permits or licenses, or to prompt the expeditious performance of similar low-level ministerial duties, fell outside the ambit of the statute’s anti-bribery provisions. Yet that exception for ‘facilitating payments’ […] is becoming harder and harder to rely on. […]  The DOJ and SEC have pressed a narrow view of the exception in recent years … […] Of course, the fact that the FCPA’s twin enforcement agencies have treated certain payments as prohibited despite their possible categorization as facilitating payments does not mean a federal court would agree. But because the vast majority of enforcement actions are resolved through DPAs and NPAs, and other settlement devices, these cases never make it to trial. As a result, the DOJ and the SEC’s narrow interpretation of the facilitating payments exception is making that exception ever more illusory, regardless of whether the federal courts – or Congress – would agree.”

Similarly, the FCPA’s books and records and internal controls provisions are qualified by the term “reasonable” and the only substantive judicial decision on these provisions (see here for the prior post) stated:

“The definition of accounting controls does comprehend reasonable, but not absolute, assurances that the objectives expressed in it will be accomplished by the system. The concept of ‘reasonable assurances’ contained in [internal control provisions] recognizes that the costs of internal controls should not exceed the benefits expected to be derived. It does not appear that either the SEC or Congress, which adopted the SEC’s recommendations, intended that the statute should require that each affected issuer install a fail-safe accounting control system at all costs. It appears that Congress was fully cognizant of the cost-effective considerations which confront companies as they consider the institution of accounting controls and of the subjective elements which may lead reasonable individuals to arrive at different conclusions. Congress has demanded only that judgment be exercised in applying the standard of reasonableness. […] It is also true that the internal accounting controls provisions contemplate the financial principle of proportionality—what is material to a small company is not necessarily material to a large company.”

SEC guidance on the FCPA’s books and records and internal controls provisions stand for the following propositions:

  • not all books and records are within the purview of the provisions;
  • issuers should not face liability when its management was not aware and reasonably should not have known of the conduct at issue;
  • the principal objective of the provisions is to reach knowing or reckless conduct;
  • thousands of dollars ordinarily should not be spent conserving hundreds;
  • the provisions are not an independent unrestrained mandate to establish novel or unprecedented corporate recordkeeping standards;
  • if conduct was engaged in by a low-level employee, without the knowledge of top management, and with appropriate corrective action taken, an enforcement action against the issuer is not warranted; and
  • the provisions do not require a company or its senior officials to be guarantors of all conduct of company employees.

Nevertheless, the enforcement agencies frequently bring FCPA enforcement actions against issuers without any allegation or suggestion that the conduct at issue was known or approved by top management (see here for example).  In this new era of FCPA enforcement, the position of the enforcement agencies appear to be that indeed corporate officers are guarantors of all conduct of company employees and that fail-safe accounting and internal controls measures are indeed the standard (see here for example).

Against this backdrop, seeking to do business in challenging foreign markets through employees or agents may indeed be- based on the current enforcement theories – in a way like gambling.

If this is what Carlino meant, perhaps he has a point.  The Congress that enacted the FCPA in 1977 and the Congress that amended the FCPA in 1988 certainly appeared to empathize.

A Focus On World-Wide Coin

The SEC’s administrative order (here) in the December 2012 Allianz enforcement action cited SEC v. World-Wide Coin Investments, 567 F.Supp. 724 (N.D. Ga. 1983) for the following proposition.  “[The FCPA’s books and records provisions do] not require that the amounts involved be “material,” nor is it necessary to prove “scienter” under its provisions.  […]  Similarly, there is no scienter requirement for establishing a violation of [the FCPA’s internal controls provisions].

These citations are not inaccurate, but nor do they tell the whole story of World-Wide Coin’s holding.

So what does World-Wide Coin really say about the FCPA’s books and records and internal control provisions?

For starters, World-Wide Coin, amazingly  given the generic nature of the FCPA books and records and internal controls provisions, appears to be the only judicial decision that directly addresses the substance of these provisions.  [If anyone is familiar with another such case, please let me know].  Yes, there are hundreds of cases if you run a search that include passing reference to the FCPA’s books and records and internal control provisions, but the decisions are generally void of substantive analysis.

The pertinent holding of World-Wide Coin, in the words of Judge Robert Vining, is as follows.

“The definition of accounting controls does comprehend reasonable, but not absolute, assurances that the objectives expressed in it will be accomplished by the system. The concept of “reasonable assurances” contained in [internal control provisions] recognizes that the costs of internal controls should not exceed the benefits expected to be derived. It does not appear that either the SEC or Congress, which adopted the SEC’s recommendations, intended that the statute should require that each affected issuer install a fail-safe accounting control system at all costs. It appears that Congress was fully cognizant of the cost-effective considerations which confront companies as they consider the institution of accounting controls and of the subjective elements which may lead reasonable individuals to arrive at different conclusions. Congress has demanded only that judgment be exercised in applying the standard of reasonableness. […] It is also true that the internal accounting controls provisions contemplate the financial principle of proportionality—what is material to a small company is not necessarily material to a large company.”

That remainder of this post summarizes the facts and holding of World-Wide Coin.

Factually, World-Wide Coin was an egregious case and the FCPA issues addressed were not very difficult for Judge Vining in ruling on the SEC’s request for a permanent injunction.  The case involved a wide-ranging securities fraud action involving World-Wide Coin, a business engaged primarily in the wholesale and retail sale of rare coins, precious metals, gold and silver coins, and bullion.  Its stock was registered with the SEC and listed on the Boston Stock Exchange.  Joseph Hale was the company’s controlling shareholder, chairman of the board, chief executive officer and president and Floyd Seibert was a member of the board and served as the company’s one-man audit committee.

In the words of Judge Vining:

“The deterioration of World-Wide’s internal controls and accounting procedures constituted the primary thrust of the SEC’s complaint.  The SEC contended that the combination of late filings, lack of internal controls, transactions unsupported by adequate documentation, and a total disregard for proper accounting procedures resulted in the precarious position of the company.  […] The company’s accounting books were virtually ignored.  General ledgers and general journals were not kept, and the checks written on World-Wide’s five checking accounts were not reconciled.”

Judge Vining described a bookkeeper hired by the company as follows.  “[She] was not a high school graduate; her only experience for this position consisted of five months of vocational school training and seven years of bookkeeping for a privately held lumber company.”

Judge Vinings findings of fact also highlights how the accounting firm Kanes, Benator & Co., retained by the company as an independent auditor, wrote a letter to the company “expressing grave concern over certain accounting procedures and lack of internal controls that [it] considered to be detrimental to the company. […] This letter [notified] World-Wide of its deficiencies in its internal accounting controls …”  Yet, “even with this official notice that improvements were needed, Hale and Seibert did nothing to remedy the situation, and the criticisms of [it] were virtually ignored.”

With respect to a 10K report, the individuals “prepared it themselves without the assistance of counsel and it contained” numerous misrepresentations.  “The company’s problems increased […] mostly resulting from its chaotic bookkeeping practices and total disregard for an adequate internal control system.”   The decision goes into great detail concerning the “problems that occurred at the company with respect to internal controls and accounting procedures” such as “(1) inventory problems, (2) problems with separation of duties and the lack of documentation of transactions, and (3) problems with the books, records, and accounting procedures of the company.”

As to the defendants’ position, the decision states as follows.

“With respect to the SEC’s allegations of violations of the [FCPA], the defendants presented a cost/benefit argument, contending that a company the size of World-Wide should not be subjected to overly burdensome internal controls systems requirements, and accounting procedures, since compliance with such requirements would, as a practical matter, put small companies such as World-Wide out of business.”

Judge Vining called the FCPA’s provisions on accounting controls “short and deceptively straight-forward.”   He stated as follows.

“The only express congressional requirement for accuracy is the phrase ‘in reasonable detail.’  Although [the books and records provisions] expects management to see that the corporation’s recordkeeping system is adequate and effectively implemented, how the issuer goes about this task is up to management; the FCPA provides no guidance, and this court cannot issue any kind of advisory opinion.  Just as the degree of error is not relevant to an issuer’s responsibility for any inaccuracies, the motivations of those who erred are not relevant.  There are no words in [the books and record provisions] indicating that Congress intended to impose a scienter requirement …”.

Judge Vining continued as follows.

“Like the recordkeeping provisions of the Act, the internal controls provision is not limited to material transactions or to those above a specific dollar amount.  While this requirement is supportive of accuracy and reliability in the auditor’s review and financial disclosure process, this provision should not be analyzed solely from that point of view.  The internal controls requirement is primarily designed to give statutory content to an aspect of management stewardship responsibility, that of providing shareholders with reasonable assurances that the business is adequately controlled.”

“Internal accounting control is, generally speaking, only one aspect of a company’s total control system; in order to maintain accountability for the disposition of its assets, a business must attempt to make it difficult for its assets to be misappropriated. The internal accounting controls element of a company’s control system is that which is specifically designed to provide reasonable, cost-effective safeguards against the unauthorized use or disposition of company assets and reasonable assurances that financial records and accounts are sufficiently reliable for purposes of external reporting.  […] Internal accounting controls must be distinguished from the accounting system typically found in a company. Accounting systems process transactions and recognize, calculate, classify, post, summarize, and report transactions. Internal controls safeguard assets and assure the reliability of financial records, one of their main jobs being to prevent and detect errors and irregularities that arise in the accounting systems of the company. Internal accounting controls are basic indicators of the reliability of the financial statements and the accounting system and records from which financial statements are prepared.”

Among the factors that determine the internal accounting control environment of a company are its organizational structure, including the competence of personnel, the degree and manner of delegation and responsibility, the quality of internal budgets and financial reports, and the checks and balances that separate incompatible activities. The efficiency of the internal control system of a company cannot be evaluated without considering the company’s organizational structure, the caliber of its employees, the strength of its audit committee, the effectiveness of its internal audit operation, and a host of other factors which, while not part of the internal control system itself, have an impact on the function of the system.”

“Although not specifically delineated in the Act itself, the following directives can be inferred from the internal controls provisions: (1) Every company should have reliable personnel, which may require that some be bonded, and all should be supervised. (2) Account functions should be segregated and procedures designed to prevent errors or irregularities. The major functions of recordkeeping, custodianship, authorization, and operation should be performed by different people to avoid the temptation for abuse of these incompatible functions. (3) Reasonable assurances should be maintained that transactions are executed as authorized. (4) Transactions should be properly recorded in the firm’s accounting records to facilitate control, which would also require standardized procedures for making accounting entries. Exceptional entries should be investigated regularly. (5) Access to assets of the company should be limited to authorized personnel. (6) At reasonable intervals, there should be a comparison of the accounting records with the actual inventory of assets, which would usually involve the physical taking of inventory, the counting of cash, and the reconciliation of accounting records with the actual physical assets. Frequency of these comparisons will usually depend on the cost of the process and upon the materiality of the assets involved.”

Judge Vining then stated as follows.

“The main problem with the internal accounting controls provision of the FCPA is that there are no specific standards by which to evaluate the sufficiency of controls; any evaluation is inevitably a highly subjective process in which knowledgable individuals can arrive at totally different conclusions. Any ruling by a court with respect to the applicability of both the accounting provisions and the internal accounting control provisions should be strictly limited to the facts of each case.”

Judge Vining then summarized the defendants’ arguments as follows.

“The defendants in the instant case contend that the SEC has misconstrued the provisions of the FCPA relating to a knowledge requirement, contending that the SEC must show scienter. The defendants further state that the SEC does not allege a knowing attempt to circumvent for an improper purpose an internal control system required by law and that the complaint ignores all considerations of the costs and benefits of internal accounting controls and seeks to require World-Wide to maintain a system of controls that would destroy the company.”

Judge Vining then stated as follows.

“The definition of accounting controls does comprehend reasonable, but not absolute, assurances that the objectives expressed in it will be accomplished by the system. The concept of “reasonable assurances” contained in section 13(b)(2)(B) recognizes that the costs of internal controls should not exceed the benefits expected to be derived. It does not appear that either the SEC or Congress, which adopted the SEC’s recommendations, intended that the statute should require that each affected issuer install a fail-safe accounting control system at all costs. It appears that Congress was fully cognizant of the cost-effective considerations which confront companies as they consider the institution of accounting controls and of the subjective elements which may lead reasonable individuals to arrive at different conclusions. Congress has demanded only that judgment be exercised in applying the standard of reasonableness. The size of the business, diversity of operations, degree of centralization of financial and operating management, amount of contact by top management with day-to-day operations, and numerous other circumstances are factors which management must consider in establishing and maintaining an internal accounting controls system. However, an issuer would probably not be successful in arguing a cost-benefit defense in circumstances where the management, despite warnings by its auditors or significant weaknesses of its accounting control system, had decided, after a cost benefit analysis, not to strengthen them, and then the internal accounting controls proved to be so inadequate that the company was virtually destroyed.  It is also true that the internal accounting controls provisions contemplate the financial principle or proportionality—what is material to a small company is not necessarily material to a large company.”

Judge Vining concluded his decision as follows.

“This court has already declined to adopt the defense offered by the defendants that the accounting controls provisions of the FCPA require a scienter requirement. The remainder of World-Wide’s defense appears to be that such a small operation should not be required to maintain an elaborate and sophisticated internal control system, since the costs of implementing and maintaining it would financially destroy the company. It is true that a cost/benefit analysis is particularly relevant here, but it remains undisputed that it was the lack of any control over the inventory and inadequate accounting procedures that primarily contributed to World-Wide’s demise. No organization, no matter how small, should ignore the provisions of the FCPA completely, as World-Wide did. Furthermore, common sense dictates the need for such internal controls and procedures in a business with an inventory as liquid as coins, medals, and bullion.”

“The evidence in this case reveals that World-Wide, aided and abetted by Hale and Seibert, violated the provisions of section 13(b)(2)(B) of the FCPA.  As set forth in the factual background portion of this order, the internal recordkeeping and accounting controls of World-Wide has been sheer chaos since Hale took over control of the company. For example, there has been no procedure implemented with respect to writing checks: employees have had access to presigned checks; source documents were not required to be prepared when a check was drawn; employees have not been required to obtain approval before writing a check; and, even when a check was drawn to cash, supporting documentation was usually not prepared to explain the purpose for which the check was drawn. In addition to extremely lax security measures such as leaving the vault unguarded, there has been no separation of duties in the areas of purchase and sales transactions, and valuation procedures for ending inventory. Furthermore, no promissory notes or other supporting documentation has been prepared to evidence purported loans to World-Wide by Hale or by his affiliate companies.”

“Since Hale obtained control of World-Wide, employees have not been required to write source documents relating to the purchase and sale of coins, bullion, or other inventory. Because of this total lack of an audit trail with respect to these transactions and the disposition of World-Wide’s assets, it has been virtually impossible to determine if an item has been sold at a profit or at a loss. Furthermore, there are more than $1,700,000 worth of checks drawn to Hale or to Hale’s affiliates, or to cash, for which no adequate source documentation exists. Furthermore, Hale and Seibert knew that the medallions that were sold to World-Wide by Hale in 1979 were overvalued and unmarketable. Even so, they allowed the incorrect value of the medallions to be entered on the books of World-Wide. They also knew that the company’s books and records were neither accurate nor complete. Pursuant to their directives, source documents were not prepared with respect to the transfer of funds; additionally, no audit trail was maintained for the acquisition and disposition of inventory. Furthermore, it appears that there were numerous false and misleading statements and omissions in the company’s numerous reports to the SEC, many of which were filed late or not at all.”

“Individually, the acts of these defendants do not appear so egregious as to warrant the full panoply of relief requested by the SEC nor to impose complete liability under the FCPA. However, the court cannot ignore the all-pervasive effect of the combined failure to act, failure to keep accurate records, failure to maintain any type of inventory control, material omissions and misrepresentations, and other activities which caused World-Wide to decrease from a company of 40 employees and assets over $2,000,000 to a company of only three employees and assets of less than $500,000. It is evident that World-Wide, Hale, and Seibert violated all provisions contained in section 13(b)(2)(A) and (B) and the SEC’s rules promulgated thereunder.”

Friday Roundup

The SEC files an amended complaint, Judge Leon strikes again, a provocative press release, a focus on lobbying and for the reading stack.  It’s all here in the Friday roundup.

SEC Files Amended Complaint in Jackson / Ruehlen Matter

As highlighted in this prior post, this past December Judge Keith Ellison (S.D. Tex.) issued a lengthy 61 page decision (here) in SEC v. Mark Jackson and James Ruehlen.  In short, Judge Ellison granted Defendants’ motion to dismiss the SEC’s claims that seek monetary damages while denying the motion to dismiss as to claims seeking injunctive relief.  Even though Judge Ellison granted the motion as to SEC monetary damage claims, the dismissal was without prejudice meaning that the SEC was allowed to file an amended complaint.  As explained in the prior post, Judge Ellison’s decision was based on statute of limitations grounds (specifically that the SEC failed to plead any facts to support an inference that it acted diligently in bringing the complaint) as well as the SEC’s failure to adequately plead discretionary functions relevant to the FCPA’s facilitation payments exception.

Last week, the SEC filed its amended complaint (here).  The most noticeable difference in the amended complaint, based on my brief review of the 58 page document, appears to be several allegations regarding Nigerian law, including the Customs & Excise Management Act.

Judge Leon Strikes Again

This prior post generally discussed Judge Richard Leon’s rejection of the SEC v. IBM FCPA settlement, a case that still lingers on the docket.

As noted in this Main Justice story and this Wall Street Journal story, Judge Leon has struck again.  According to the reports, yesterday Judge Leon conducted a scheduled hearing in SEC – Tyco FCPA case in chambers, much to the dismay of media assembled in open court.

As noted in this prior post, in September 2012, the DOJ and SEC announced an FCPA enforcement against Tyco International Ltd. and a subsidiary company.  Total fines and penalties in the enforcement action were approximately $26.8 million (approximately $13.7 million in the DOJ enforcement action and approximately $13.1 million in the SEC enforcement action).  As noted in this SEC release, Tyco consented to a final judgment that orders the company to pay approximately $10.5 million in disgorgement and approximately $2.6 million in prejudgment interest.  Tyco also agreed to be permanently enjoined from violating the FCPA.

Although both the IBM and Tyco enforcement actions involve the SEC’s neither admit nor deny settlement language, this would not seem to be the key thread between these two enforcement actions that is drawing the ire of Judge Leon.  Rather as explained in this post summarizing the IBM enforcement action and this post highlighting various notable features of the Tyco action, both companies are repeat FCPA violators.  In resolving the “original” FCPA enforcement actions – IBM in 2000 and Tyco in 2006 – both companies agreed to permanent injunctions prohibiting future FCPA violations.

This prior post titled “Meaningless Settlement Language” detailed Judge Jed Rakoff’s discussion of so-called “obey the law” injunctions in SEC v. Citigroup and this prior guest post discussed an Eleventh Circuit decision last year vacating a SEC “obey the law” injunction.

A Provocative Press Release

The law firm Bienert, Miller & Katzman (“BMK”) represented Paul Cosgrove (a former executive of Control Components Inc.) in the so-called Carson enforcement actions.  The Carson action involved a notable “foreign official” challenge and as highlighted in previous posts here, here, and here, after Judge Selna issued a pro-defendant jury instruction, the DOJ soon thereafter offered the remaining defendants (Stuart Carson, Hong Carson, David Edmonds, and Cosgrove) plea agreements which the defendants accepted.  As to those plea agreements, I ended each post by saying – the conclusions are yours to reach.  In Fall 2012, the defendants were sentenced as follows:  S. Carson (four months in prison), H. Carson (three years probation), Edmonds (four months in prison) and Cosgrove (15 months of home detention).  See this prior post regarding Carson sentencing issues.

In a January 17th press release (here), BMK stated as follows.

“BMK and counsel for three other defendants … conducted a worldwide investigation and developed evidence suggesting the government’s evidence was incomplete, the court documents indicate.  Ultimately,  most companies bought CCI valves because they were the best in the world (not because of bribes); most of the supposed “public officials” denied receiving any bribes; and, in most cases, the alleged improper payments were never actually made, according to court records.

Further, through an aggressive litigation and motion strategy, counsel were able to obtain jury instructions that highlighted the government’s heavy burden of proof at trial.  For example, the trial court agreed with defense counsel that the government was obligated to prove defendants’ knew they were dealing with “foreign officials,” something that would have been extremely difficult for the government to prove.  The supposed bribery recipients worked for companies that appeared to operate like private companies in the United States, making it very unlikely that the defendants realized they were dealing with “government officials.”

BMK and other defense counsel  raised several other issues that brought the government’s ability to obtain a conviction, or defend an appeal, into serious doubt.  These motions called into question whether the alleged bribe recipients were even “public officials” as intended by the FCPA; whether the Travel Act even applied to the case; and, whether defendants were entitled to millions of pages of documents that had been withheld from them by CCI, their former employer.  Each of these issues likely would have been decided for the first time on an appeal in this case.”

[Full disclosure – I was an engaged expert in the Carson cases, filed a “foreign official” declaration in connection with the motion to dismiss, and was disclosed as a testifying expert for the trial]

Lobbying

In my double-standard series (here), I have highlighted various aspects of lobbying here in the U.S.  The beginning of the recent opinion in U.S. v. Ring (D.C. Circuit) is an interesting read.  In pertinent part, it states as follows (internal citations omitted).

“Lobbying has been integral to the American political system since its very inception.  […] As some have put it more cynically, lobbyists have besieged the U.S. government for as long as it has had lobbies.” […]  By 2008, the year Ring was indicted, corporations, unions, and other organizations employed more than 14,000 registered Washington lobbyists and spent more than $3 billion lobbying Congress and federal agencies. […] 

The interaction between lobbyists and public officials produces important benefits for our representative form of government. Lobbyists serve as a line of communication between citizens and their representatives, safeguard minority interests, and help ensure that elected officials have the information necessary to evaluate proposed legislation. Indeed, Senator Robert Byrd once suggested that Congress “could not adequately consider [its] workload without them.” […]

In order to more effectively communicate their clients’ policy goals, lobbyists often seek to cultivate personal relationships with public officials. This involves not only making campaign contributions, but sometimes also hosting events or providing gifts of value such as drinks, meals, and tickets to sporting events and concerts. Such practices have a long and storied history of use—and misuse. During the very First Congress, Pennsylvania Senator William Maclay complained that “New York merchants employed ‘treats, dinners, attentions’ to delay passage of a tariff bill.” […] Sixty years later, lobbyists working to pass a bill that would benefit munitions magnate Samuel Colt “stage[d] lavish entertainments for wavering senators.” […] Then, in the 1870s, congressmen came to rely on railroad lobbyists for free travel. […]. Indeed, one railroad tycoon complained that he was “averag[ing] six letters per day from Senators and Members of Congress asking for passes over the road.”

Reading Stack

Some dandy articles/essays to pass along regarding the FCPA books and records provisions, victim issues and criminal procedure.

FCPA Books and Records Provisions

Michael Schachter (Willkie Farr & Gallagher and a former Assistant United States Attorney in the Southern District of New York, where he focused on criminal prosecution of securities fraud and was a member of the Securities and Commodities Fraud Task Force) recently authored an article concerning the FCPA’s books and records provisions.  Titled “Defending an FCPA Books and Records Violation” and published in the New York Law Journal, the article begins as follows.

“In recent years, the books and records provisions of the [FCPA] have taken on new life, as both the [DOJ and SEC] have announced their intention to bring more charges, especially against individuals, for violation of this section of the FCPA.  A review of recent enforcement actions reveals that the Justice Department and the SEC consider the books and records requirement violated whenever corrupt payments are made to a foreign official and recorded in a corporation’s books as anything other than a ‘bribe,’ including, but not limited to, such things as commissions, social payments, or after sales service fees.  This article proposes that the books and records provision is, in fact, narrower than the Justice Department and the SEC interpretations suggest, and argues that both agencies may be using the provision to punish behavior falling outside the FCPA’s reach.”

Spot on.  See prior posts here and here.  See here for a word cloud of the FCPA’s books and records and internal control provisions.

Corporate Employer’s As Victims

The title of Professor Peter Henning’s recent White Collar Crime Watch post in the New York Times DealBook was “How Can Companies Sue Defendants in Insider Trading Cases?”  The post concerned the Mandatory Victims Restitution Act and Professor Henning writes that it “has been interpreted to allow companies that incur costs in cooperating with the government to seek repayment of their expenses from defendants” and the “statute requires a court to order the reimbursement to victims of ‘other expenses incurred during participation in the investigation or prosecution of the offense.'”

The parallels to a company incurring expenses in connection with FCPA investigations based on employee conduct is obvious.

Yet, Professor Henning writes as follows.

“[T]he crucial word in the Mandatory Victims Restitution Act is “incurred,” and there isn’t a consensus among federal courts over what expenses are covered.  Companies want it to include all costs related to any part of the case, including dealing with the S.E.C. even though it can only pursue a civil enforcement case. Defendants take a much narrower view, arguing that mandatory restitution covers only expenses arising as direct result of the criminal prosecution by the Justice Department.

Ham Sandwich Nation

Glenn Reynolds (University of Tennessee College of Law) recently published an essay titled “Ham Sandwich Nation: Due Process When Everything is a Crime” (see here to download).  The essay does not mention the FCPA, yet it is very much applicable to the FCPA.  In just the past year, approximately 25 individuals criminally indicted by the DOJ have put the DOJ to its burden of proof and ultimately prevailed.  Ham Sandwich Nation would also seem applicable given the extensive use of NPAs and DPAs in the FCPA context.  The thesis of the essay is spot on.  Reynolds write as follows.

“Though people suspected of a crime have extensive due process rights in dealing with the police, and people charged with a crime have even more extensive due process rights in courts, the actual decision whether or not to charge a person with a crime is almost completely unconstrained.  Yet, because of overcharging and plea bargains, that decision is probably the single most important event in the chain of criminal procedure.”

Year In Review

The Year in Review version of Debevoise & Plimpton’s always informative and comprehensive FCPA Update is here.   Among the many topics discussed in the FCPA Update is the notion that many FCPA enforcement actions are based on very old conduct and the following observation.  “Targets of enforcement actions also run the risk that regulators – whether consciously or not – apply current expectations of appropriate compliance measures and effective internal controls mechanisms when evaluating the adequacy of procedures that existed at times when less rigorous standards may have commonly been considered acceptable.”  For my similar previous observation, see this prior post.

*****

A good weekend to all.

The Dilution Of FCPA Enforcement Has Reached A New Level With The SEC’s Enforcement Action Against Oracle

Yesterday,the SEC announced (here) a Foreign Corrupt Practices Act books and records and internal controls enforcement action against Oracle Corporation.

With the enforcement action, the dilution of FCPA enforcement has reached a new level.   The only allegations against Oracle itself is that it failed to audit distributor margins against end user prices and that it failed to audit third party payments made by distributors.  It is common for large multi-national companies to have hundreds, if not thousands, of distributors.  Because of this, audits Oracle was held liable for not conducting are not practical or cost-effective absent red flags suggesting improper conduct. The SEC did not allege any such red flag issues.  In fact, the SEC alleges that Oracle’s Indian subsidiary “concealed” and kept “secret” the conduct from Oracle.  Congress did not intend for the FCPA’s books and records and internal control provisions to be a strict liability statute.  The SEC used to recognize this.  However, it no longer does as once again demonstrated by the Oracle action.

In reading the Oracle action, I was reminded of a 1981 speech by Harold Williams (Chairman of the SEC) regarding the FCPA books and records and internal control provisions.  See here for the prior post.  Williams stated that the provisions are not “independent unrestrained mandate[s] to the Commission to establish novel or unprecedented corporate recordkeeping standards.”  Williams further stated as follows.  “Depending on the circumstances, intentional circumventions of a company’s system of records and of accounting controls by a low-level employee would not always be considered violations of the Act by the issuer. No system of adequate records and controls – no matter how effectively devised or conscientiously applied – could be expected to prevent all mistaken and improper transactions and disposition of assets. Given human nature, regardless of the adequacy of the system, a bookkeeper may still erroneously post entries, an overzealous agent may make unauthorized payments, or an unscrupulous employee may falsify records for his own purposes. The Act recognizes each of these limitations. Neither its text and legislative history nor its purposes suggest that occasional, inadvertent errors were the kind of problem that Congress sought to remedy in passing the Act. No rational federal interest in punishing insignificant mistakes has been articulated. And, the Act’s accounting provisions do not require a company or its senior officials to be the guarantors of all conduct of company employees.”

Back to the SEC’s enforcement action against Oracle.

The SEC complaint (here) states in summary fashion as follows.

“This matter involves violations of the books and records and internal controls provisions of the FCPA by Oracle Corporation.  From 2005 to 2007, certain employees of Oracle’s Indian subsidiary Oracle India Private Limited (“Oracle India”) secretly ‘parked’ a portion of the proceeds from certain sales to the Indian government and put the money to unauthorized use, creating the potential for bribery or embezzlement.  These Oracle India employes structured more than a dozen transactions so that a total of around $2.2 million was held by the Company’s distributors and kept off Oracle India’s corporate books.  The Oracle India employes would then direct its distributor to disburse payments out of the unauthorized side funds to purported local ‘vendors.’  Several of the ‘vendors’ were merely storefronts that did not provide any services.  Oracle failed to accurately record these side funds on the Company’s books and records, and failed to implement or maintain a system of effective internal accounting controls to prevent improper side funds in violation of the FCPA, which requires public companies to keep books and records that accurately reflect their operations.”

Specifically, the SEC complaint states as follows.

“On approximately 14 occasions related to 8 different government contracts between 2005 and 2007, certain Oracle India employees created extra margins between the end user and distributor price and directed the distributors to hold the extra margin in side funds. Oracle India’s employees made these margins large enough to ensure a side fund existed to pay third parties. At the direction of the Oracle India employees, the distributor then made payments out of the side funds to third parties, purportedly for marketing and development expenses. Some of the recipients of these payments were not on Oracle’s approved local vendor list; indeed, some of the third parties did not exist and were merely storefronts.  Because the Oracle India employees concealed the existence of the side fund, Oracle did not properly account for these side funds. These funds constituted prepaid marketing expenses incurred by Oracle India and should have been recorded as an asset and rolled up to Oracle’s corporate books and records. These marketing expenses should then have been reflected in the income statement once they were used. Instead, the parked funds were not reflected on Oracle India’s books and were not properly recorded as prepaid marketing expenses. This incorrect accounting in turn affected Oracle’s books and records.  Between 2005 and 2007, government customers paid Oracle India’s distributors at least $6.7 million on these sales, with Oracle receiving approximately $4.5 million in revenue, resulting in about $2.2 million in funds improperly ‘parked’ with the Company’s distributors.”

The SEC further alleged as follows.

“Oracle lacked the proper controls to prevent its employees at Oracle India from creating and misusing the parked funds.  For example, Oracle knew distributor discounts created a margin of cash from which distributors received payments for their services.  Before 2009, however, the company failed to audit and compare the distributor’s margin against the end user price to ensure excess margins were not being built into the pricing structure.  In addition, although Oracle maintained corporate policies requiring approvals for payment of marketing expenses, Oracle failed to seek transparency in or audit third party payments made by distributors on Oracle India’s behalf.  This control would have enabled Oracle to check that payments wer made to appropriate recipients.”

Based on the above conduct, the SEC charged Oracle with FCPA books and records and internal controls violations.

In the SEC’s release, Marc Fagel (Director of the SEC’s San Francisco Regional Office) stated as follows.  “Through its subsidiary’s use of secret cash cushions, Oracle exposed itself to the risk that these hidden funds would be put to illegal use.  It is important for U.S. companies to proactively establish policies and procedures to minimize the potential for payments to foreign officials or other unauthorized uses of company funds.”  As noted in the release, without admitting or denying the SEC’s allegations, Oracle consented to the entry of a final judgment ordering the company to pay a $2 million penalty and permanently enjoining it from future books and records and internal control violations.  The release further states as follows.  “The settlement takes into account Oracle’s voluntary disclosure of the conduct in India and its cooperation with the SEC’s investigation, as well as remedial measures taken by the company, including firing the employees involved in the misconduct and making significant enhancements to its FCPA compliance program.”

It is typical for the DOJ and SEC to announce FCPA enforcement actions on the same day.  Thus, the absence of a parallel DOJ enforcement action as to the alleged conduct at issue suggests that there will be no DOJ enforcement action, a good result given the SEC’s allegations and for the reasons stated above.

However, it may be premature to conclude that Oracle’s FCPA scrutiny is over.  As noted in this prior post, in September 2011, the Wall Street Journal reported that the DOJ was investigating “whether Oracle employees or agents acting on the company’s behalf made improper payments in Africa in order to land sales of database and applications software.”

*****

The SEC’s enforcement action against Oracle  is not the first time distributor margin payments have served as the basis of an FCPA enforcement action.  See here for the 2005 enforcement action against InVison, specifically the Thailand allegations.  However, in that action the SEC alleged that the company was aware of the “high probability” that the margin was being used for improper purposes.