Compliance Defense Rebuttals Are Unpersuasive

In early 2012, I published “Revisiting an FCPA Compliance Defense.”  As far as I know, it is the most extensive article written specifically about an FCPA compliance defense, how an FCPA compliance defense is not a new or novel idea, and how an FCPA compliance defense can accomplish a host of policy objectives that can best advance the FCPA’s objective of reducing bribery.

While some (such as the Chamber of Commerce) are proposing a compliance defense as an affirmative defense, I am not proposing an affirmative defense.  Rather, and as detailed in the article, I have proposed that compliance is best incorporated into the FCPA as an element of a bribery offense, the absence of which the DOJ (or SEC) must establish to charge a substantive bribery offense.

Some have called this proposal unprecedented and radical.

This is simply not true.

For starters, such a proposal is consistent with the FCPA-like laws of several other peer nations which, like the U.S., are parties to the OECD Convention.  Just as importantly, the FCPA already has features that must be negated by the enforcement agencies to prove a violation of the FCPA’s anti-bribery provisions.  As detailed in this prior post, in SEC v. Jackson et. al, the court ruled, in an issue of first impression, that the government must bear the burden of negating the FCPA’s facilitation payment exception.

As evidenced from the November 2010 Senate FCPA hearing and the June 2011 House FCPA hearing, based on member comments, there appeared to be bipartisian support for an FCPA compliance defense.  As noted in the “Revisiting an FCPA Compliance Defense” article and here, a compliance defense is supported by a host of former U.S. attorney generals, and other former high-ranking DOJ officials including the former Chief of the DOJ’s FCPA Unit (here).

At every FCPA event I have attended over the past few years in which an informal straw poll or show of hands took place, an FCPA compliance defense enjoyed strong majority support.

Yet, there are those who remained unpersuaded that an FCPA compliance defense is wise.

In September, Thomas Fox (FCPA Compliance and Ethics Blog) published a roundtable of sorts on the merits of an FCPA compliance.  My former colleague at Foley & Lardner, David Simon, supported an FCPA compliance defense, while Fox and William Athanas (Waller Lansden Dortch & Davis) rejected an FCPA compliance defense.  Both Fox and Athanas rebutted the compliance defense as an affirmative defense, not a compliance defense as I have proposed.

Fox opined that a compliance defense “could seriously downgrade the effectiveness of anti-corruption programs” and the general thrust of his rebuttal was that a compliance defense would be “useless” because “corporations do not and will not go to trial in FCPA cases because it is not in their interest to do so.  So if a corporation will not go to trial, a compliance defense has as much use as a trial lawyer afraid of the courtroom, in other words it is useless.”  Fox stated that an FCPA compliance defense is “only useful if it is raised as an affirmative defense at trial” and rhetorically asked “do you want to be the first GC to got to trial … or do you want to settle and play it safe.”  In conclusion, Fox stated, “at the end of the day, the compliance defense will not help a company because no company will go to trial and face a fraud finding from a jury … it is always better to settle and obtain certainty than to risk everything.”

Athanas opined that a compliance defense “would actually cause harm to those companies who take seriously the FCPA’s obligations and endeavor to ensure compliance with its mandates, making it more difficult for them to operate in this enforcement environment.”  Like Fox, Athanas stated that a compliance defense is “unnecessary” because “the notion of enabling corporations to raise a defense at trials that will never occur is essentially meaningless.”

As noted in “Revisiting an FCPA Compliance Defense”:

“The present incentives [to adopt pro-active FCPA compliance policies and procedures] represent “baby carrots” [in that they merely lessen the impact of legal exposure] when what is needed to better incentivize more robust FCPA compliance are real “carrots” [that can reduce legal exposure].  An FCPA compliance defense is a real “carrot” that will better incentivize compliance across the business landscape. Organizations with existing FCPA compliance policies and procedures will be incentivized to make existing programs better. Likewise, organizations currently without stand-alone FCPA policies and procedures—and … statistics indicate there are many—will be incentivized to spend finite resources to implement FCPA compliance policies and procedures. By better incentivizing organizations to implement more robust FCPA policies and procedure, an FCPA compliance defense can reduce instances of improper conduct and thereby advance the FCPA’s objectives.”

The notion that this “real carrot” as opposed to the present “baby carrot” will “seriously downgrade the effectiveness of anti-corruption programs” – in the words of Fox – or “actually cause harm” to companies – in the words of Athanas – are unpersuasive for the same reason it is unpersuasive to say that the greater incentive a parent provides a child to clean her room will result in fewer clean rooms or that the greater incentive a teacher provides a student to do well on an exam will result in worse exam scores.

The notion that an FCPA compliance defense is “useless” or “meaningless” because it could only be invoked at trial is a red herring because it does not address the merits of a compliance defense, but is rather a general comment as to the current state of government enforcement dynamics.  The implication is that reforming any law enforced by the DOJ or SEC is “usless” and “meaningless” because corporations are risk averse, and because of this risk aversion, legal elements that must be proven at trial will not matter.

On a related note, in opposing a compliance defense, Fox also raised the point that if a company under FCPA scrutiny raises “compliance defense” issues it might agitate a DOJ prosecutor and make the “DOJ even more aggressive in negotiations.”  If the FCPA were to be amended to include a compliance defense, and if company under FCPA scrutiny would in good faith raise this legal issue but risk agitating a DOJ prosecutor, gosh – we have more fundamental problems concerning our criminal justice system that just one statute – the FCPA – could possibly address.

More fundamentally, opposing an FCPA compliance defense for the reason that it is “useless” or “meaningless” because it could only be invoked at trial improperly views a compliance defense only through the narrow prism of hard enforcement, wholly ignoring the soft enforcement effect of an FCPA compliance defense.

As distinguished from “hard” enforcement of a law by enforcement agencies, “soft” enforcement generally refers to a law’s ability to facilitate self-policing and compliance to a greater degree than can be accomplished through “hard” enforcement alone.   In passing the FCPA, Congress anticipated that the “criminalization of foreign corporate bribery will to a significant extent act as a self-enforcing preventative mechanism.”  Likewise since the FCPA’s earliest days, the DOJ has recognized that the “most efficient means of implementing the FCPA is voluntary compliance by the American business community.”

This voluntary compliance can be better achieved by increasing the incentives to comply – a fundamental logic recently recognized by a host of SEC officials – see here, here and here.

My two-fold FCPA reform proposal (a compliance defense coupled with abolishing NPA and DPAs) – see here for a prior post – will result in the following enforcement landscape.

If a payment is made in violation of the FCPA’s anti-bribery provisions within a business organization, two issues will be relevant.

First, if the payment was made, authorized or condoned by a director or executive officer, the business organization will not be able to avail itself of an FCPA compliance defense.  Second, if the payment was made by any employee or agent in the absence of pre-existing FCPA compliance policies consistent with the best practices, the business organization will not be able to avail itself of an FCPA compliance defense.  In these scenarios involving corrupt directors or executive officers or business organizations without a commitment to FCPA compliance, the enforcement agencies will have two choices:  do not prosecute or prosecute the business organization for violating the FCPA.  This is a just and reasonable result and the third option of an NPA or DPA is not needed in such a scenario. As even the DOJ has acknowledged and empirical research has demonstrated, it is extremely unlikely that actual criminal prosecution of such a business organization will result in its demise.

Conversely, if the payment at issue is made by a non-executive employee or agent contrary to the business organization’s pre-existing FCPA compliance policies, the organization will be able to avail itself of an FCPA compliance.  Thus, as a matter of law, no FCPA prosecution of the organization will be able to proceed.  This too is a just and reasonable result and aligns FCPA enforcement with enforcement regimes in several other peer countries.

The above FCPA reforms will take courage, both by Congress in amending the FCPA and by the enforcement agencies in abolishing the resolution vehicles they created.  The reform proposals may indeed result in less hard FCPA enforcement actions as certain business organizations will be able to avail itself of the compliance defense and as enforcement agencies are once again mindful of their burdens of proof in prosecuting alleged FCPA violations.

However, more FCPA enforcement is not necessarily an inherent good and ought not be the singular goal of the FCPA.  The goal ought to be constructing an enforcement regime that best promotes compliance, reduces improper conduct, best advances the FCPA’s objective of reducing bribery, increases transparency and better aligns FCPA enforcement with rule of law principles.

The above FCPA reforms will accomplish these goals as well as increase public confidence in FCPA enforcement.  The proposals will also allow the enforcement agencies to better allocate limited prosecutorial resources to cases involving corrupt business organizations and the individuals who actually engage in the improper conduct.

The FCPA has witnessed courageous moments before and a courageous moment is once again presented.

Friday Roundup

Another acknowledgment of the logic, whistleblower statistics, a guilty plea, and for the reading stack.  It’s all here in the Friday roundup.

Another Acknowledgment of the Logic

Previous posts here and here have highlighted recent speeches by top SEC officials in which they acknowledge the underlying logic supporting a compliance defense.  Deputy Attorney General James Cole did the same in this recent speech before a bank compliance officer crowd.

“At the Department of Justice, we know that compliance officers within financial institutions, and the lawyers, bankers, and others who work with them, are the first line of defense against abuse within these institutions.  Compliance officers are critical to protecting both a bank’s reputation and its bottom line.  They’re essential when it comes to preventing criminal activity – and if that effort is not entirely successful, detecting and reporting such conduct.  It is not an exaggeration to say that compliance is fundamental to protecting the security of our financial institutions and is essential to the integrity of our entire financial system. Despite, and in some ways because of, this crucial role, I know that working in compliance is often difficult.  Compliance is seldom thought of as a ‘money-maker’ for any bank, and it may be challenging to get sufficient resources and authority to do the job well.  To some, compliance may not seem to fit within the culture of a fast-moving, cutting-edge institution.  And at times, certain business units or managers may seem downright hostile toward the compliance function. We at the Department of Justice understand this reality.  And we appreciate that, despite these challenges, you and your colleagues are fully committed to helping protect the integrity of your institutions and our financial system.”

[…]

The notion that compliance must be firmly embedded in a corporation’s culture has been raised before, including at this conference, by many government officials.  You’ve heard a great deal about the importance of ‘tone at the top.’  Indeed, companies regularly argue during negotiations that they have taken various steps to set the right tone at the highest levels of their institutions.  But based on what we have seen, we cannot help but feel that the message is not getting through often enough or clearly enough. Despite years of admonitions by government officials that compliance must be an important part of a corporation’s culture, we continue to see significant violations of law at banks, inadequate compliance programs, and missed opportunities to prevent and detect crimes.”

In “Revisiting a Foreign Corrupt Practices Act Compliance Defense,” I argue, among other things, that a compliance defense will better incentivize corporate compliance and reduce improper conduct.  Compliance is a cost center within business organizations and expenditure of finite resources on FCPA compliance is an investment best sold if it can reduce legal exposure, not merely lessen the impact of legal exposure.

In short, an FCPA compliance defense will best allow compliance professionals in the FCPA context to – in the words of Cole – “get sufficient resources and authority to do the job well.”

Will the DOJ and SEC ever be capable of realizing that a compliance defense is a race to the top, not a race to the bottom?  (See here for the prior post).  Will the DOJ and SEC ever have the courage to realize that a compliance defense can best help the enforcement agencies accomplish its laudable goals? (See here for the prior post).

Whistleblower Statistics

The Dodd-Frank Act enacted in July 2010 contained whistleblower provisions applicable to all securities law violations including the Foreign Corrupt Practices Act.  In this prior post from July 2010, I predicted that the new whistleblower provisions would have a negligible impact on FCPA enforcement.  As noted in this prior post, my prediction was an outlier (so it seemed) compared to the flurry of law firm client alerts that predicted that the whistleblower provisions would have a significant impact on FCPA enforcement.  So anxious was FCPA Inc. for a marketing opportunity to sell its compliance services, some even called the generic whistleblower provision the FCPA’s “new” whistleblower provisions.

So far, there have not been any whistleblower awards in connection with FCPA enforcement actions.  Given that enforcement actions (from point of first disclosure to resolution) typically take between 2-4 years, it still may be too early to effectively analyze the impact of the whistleblower provisions on FCPA enforcement.

Whatever your view, I previously noted that the best part of the new whistleblower provisions were that its impact on FCPA enforcement can be monitored and analyzed because the SEC is required to submit annual reports to Congress.  Recently, the SEC released (here) its annual report for FY2013.

Of the 3,238 whisteblower tips received by the SEC in FY2013, 4.6% (149) related to the FCPA.  As noted in this similar post from last year, of the 3,001 whisteblower tips received by the SEC in FY2012, 3.8% (115) related to the FCPA.  In FY2011 (a partial reporting year)  3.9% of the 334 tips received by the SEC related to the FCPA.

Yes, there will be in the future a whistleblower award made in the context of an FCPA enforcement action.  Yes, there will be much ink spilled on this occasion and wild predictions about this “new trend.”  Yet, I stand by my prediction – now 3.5 years old, that Dodd-Frank’s whistleblower provisions will have a negligible impact on FCPA enforcement.

“Foreign Official” Pleads Guilty

Earlier this week, the DOJ announced that Maria Gonzalez, the alleged “foreign official” at the center of the FCPA enforcement actions against individuals associated with broker-dealer Direct Access Partners LLC, pleaded guilty to “conspiring to violate the Travel Act and to commit money laundering, as well as substantive counts of these offenses.”  Gonzalez (V.P. of Finance / Executive Manager of Finance and Funds Administration at Bandes – an alleged state-run economic development bank in Venezuela) is to be sentenced on August 15, 2014.

As noted in the DOJ’s release:

“Previously, three former employees of the Broker-Dealer – Ernesto Lujan, Jose Alejandro Hurtado, and Tomas Alberto Clarke Bethancourt – each pleaded guilty in New York federal court to conspiring to violate the Foreign Corrupt Practices Act (FCPA), to violate the Travel Act and to commit money laundering, as well as substantive counts of these offenses, relating, among other things, to the scheme involving bribe payments to Gonzalez.  Sentencing for Lujan and Clarke is scheduled for Feb. 11, 2014, before U.S. District Judge Paul G. Gardephe.  Hurtado is scheduled for sentencing before U.S. District Judge Harold Baer Jr. on March 6, 2014.”

Reading Stack

An interesting read from a Vietnam media source regarding the notion that – just like in tango – it takes two in a bribery scheme and that many instances of bribery are the result of harassment by foreign officials and extortion-like demands.  When passing the FCPA in 1977, Congress fully recognized and understood this reality and that is why it did not seek to capture facilitation payments in the FCPA.  (See here for more reading).

*****

A good weekend to all.

Indeed, Trials Are Important … And Telling As Well

Three cheers for SEC Chair Mary Jo White’s recent speech titled “The Importance of Trials to the Law and Public Accountability.”

Under the heading, “why trials are important,” White stated that “simply put, [trials] put our system of justice […] on display for all to see.”  She stated as follows.

“The public airing of facts, literally in open court, creates accountability for both defendants and the government. How we resolve disputes and how we decide the guilt or innocence of an accused are the true measure of our democracy. Thomas Jefferson once said that he considered ‘trial by jury as the only anchor ever yet imagined by man, by which a government can be held to the principles of its constitution.'”

In the speech, White agreed that trials are the “‘crown jewel’ of our system of justice” and she focused on two “of the more important roles that trials play in our administration of justice:  how they foster development of the law, and perhaps even more importantly how they create public accountability for both defendants and the government through the public airing of charges and evidence.”

As to the former, White stated that “trials allow for more thoughtful and nuanced interpretations of the law in a way that settlements and summary judgments cannot.”

As to the later, White agreed with the following statement.  “The death of trials would … remove a source of disciplined information about matters of public significance. … It would mean the end of an irreplaceable public forum and would mean that more of the legal order would proceed behind closed doors.  And it would deprive us, as American citizens, of an important source of knowledge about ourselves and key issues of public concern.”

White talked about the “near-sacred nature of the courtroom,” how “litigants are required to meet their burden of proof, and where there is up-close-and-personal accountability for whatever the trial is about,”  how trials are where “victims and witnesses have the chance to tell their stories and where the public can hear the facts set forth in open court,” and how trials provide a place for “public closure on hotly disputed facts and legal issues.”

As White stated, “by the end of the trial, the full scope of the misconduct is laid before the fact-finder to decide guilt or innocence, liability or no liability.”

As to criminal trials, White, a former DOJ prosecutor, stated that the “scarcity of criminal trials means that the public does not often enough have this kind of public airing and adjudication that trials uniquely provide.”

Although White’s speech was general in nature, the topics addressed are relevant to Foreign Corrupt Practices Act enforcement and I completely agree with White, trials are indeed important.

In “The Facade of FCPA Enforcement,” under the heading “why the facade of FCPA enforcement matters,” I observed.

“As a matter of general jurisprudence, it is troubling when any area of law largely develops outside of the judicial process. The judicial process facilitates the thoughtful presentation of opposing views, mitigating facts and circumstances, and potential defenses in an adversarial proceeding culminating in an impartial decision-maker weighing the facts and applying the law in rendering a decision in a transparent manner. These fundamental hallmarks are largely missing in FCPA enforcement. Rather, the enforcement agencies, occupying positions of advocate, judge, and rule-maker, induce settlement through the “carrots” and “sticks” they possess even though many of the enforcement theories leading to these resolutions are untested and dubious, and in some case in direct conflict with the FCPA’s statutory provisions. The end result is resolution vehicles that do not facilitate the thoughtful presentation of opposing views, mitigating facts and circumstances, potential defenses, or testing of legal theories. Yet, these resolution vehicles largely define the FCPA. When the parameters of any law develop through such an opaque process, public confidence in that law, as well as the rule of law, suffers.”

The irony of course is that – notwithstanding White’s sensible statements – the SEC has never been put to its burden of proof in a corporate FCPA enforcement.  The reasons are largely due to SEC enforcement policies that pre-date White’s tenure at the SEC, but policies that she continues to champion – namely the SEC’s neither admit nor deny settlement policy (notwithstanding its recent tweak) and the SEC’s more recent use of non-prosecution and deferred prosecution agreements.

As to the later, when the SEC announced its intention to use NPAs and DPAs, I called the development (see here for the prior post) a blow to those who prefer government law enforcement agencies to enforce a law in an open, transparent matter and in the context of an adversary proceeding … in other words the very same things White championed in her recent speech.

The further irony of course from White’s recent speech is that when the SEC has been put to its burden of proof in individual FCPA enforcement actions, the SEC has an overall losing record.  (See this prior post detailing the instances).

The importance of trials and the issues addressed in White’s speech are of course also relevant to the DOJ’s overall losing record when put to its burden of proof in FCPA enforcement actions.  (See here for “What Percentage of DOJ FCPA Losses Is Acceptable?”).  And of course White’s comments about “behind closed doors” and how trials “allow for more thoughtful and nuanced interpretations of the law in a way that settlements” cannot is even more important to the DOJ’s enforcement of the FCPA given its prevalent use of NPAs and DPAs.

As I’ve offered a number of times in the FCPA context, success in enforcing a law, whether in the corporate context or individual context, is best measured by instances in which an enforcement agency is actually put to its burden of proof in an adversarial proceeding.

Thanks to White’s recent speech, we have been reminded of that.

*****

Much like this prior post in which a high-ranking SEC official acknowledged the underlying logic supporting a compliance defense, White did the same thing in this October speech before a broker-dealer compliance audience.  In pertinent part, White stated:

“Your work is extremely important to us as well as to investors because you are positioned to prevent infractions from happening in the first place, rather than coming to our attention only after harm has been done.”  […] “[W]e rely on you.  We rely on you because as much as we strive to be everywhere we can be, our resources are limited and always stretched.”

Elsewhere, White stated that a question the SEC often asks is whether compliance professionals are “empowered by your firms to do what you need to do?”  […]  “We want to encourage companies to give you the recognition that you deserve, the resources that you need and the authority that your role demands, so you can succeed and, as a result, our markets are safe and can succeed.”  […]  “[W]e seek to promote the role of compliance and ensure that the firms recognize and acknowledge the importance we place on your role.”

For why these statements acknowledge the underlying logic supporting a compliance defense, see “Revisiting a Foreign Corrupt Practices Act Compliance Defense.”

SEC Enforcement Official Acknowledges The Underlying Logic Supporting A Compliance Defense

There is an underlying logic to a Foreign Corrupt Practices Act compliance defense.

In “Revisiting a Foreign Corrupt Practices Act Compliance Defense,” I argued, among other things, that a compliance defense will better incentivize corporate compliance and reduce improper conduct.  Compliance is a cost center within business organizations and expenditure of finite resources on FCPA compliance is an investment best sold if it can reduce legal exposure, not merely lessen the impact of legal exposure.

In a recent speech before the Society of Corporate Compliance and Ethics, Stephen Cohen (SEC Associate Director of Enforcement) rightly acknowledged the underlying logic supporting a compliance defense.

In his speech, Cohen “fully appreciated” that the compliance professionals in the room “are on the front lines in the battle to persuade companies to invest” in compliance programs.  (emphasis added).  Elsewhere, Cohen stated:  “So, as you go back to your companies to advocate for more resources and stature, tell your management that they will get much more credit from regulators by demonstrating that misconduct is an outlier in a highly ethical and compliance-driven culture rather than a remedial step after investors suffered losses.”  (emphasis added).

As highlighted in “Revisiting an FCPA Compliance Defense,” at present, the incentives organizations have to adopt FCPA compliance policies and procedures are solely to lessen the impact of legal exposure.  These present incentives thus represent “baby carrots,” when what is needed to better incentivize more robust FCPA compliance are real “carrots.”  An FCPA compliance defense is a real “carrot” that will better incentivize compliance across the business landscape.  Organizations with existing FCPA compliance policies and procedures will be incentivized to make existing programs better.  Likewise, organizations currently without stand-alone FCPA policies and procedures—and statistics indicate there are many—will be incentivized to spend finite resources to implement FCPA compliance policies and procedures.

In short, an FCPA compliance defense will best allow compliance professionals in the FCPA context to – in the words of Cohen – win “the battle to persuade companies to invest” in compliance programs and to “advocate for more resources and stature.”

A few other issues from Cohen’s recent speech.

It contains a curious reference to the Ralph Lauren enforcement action.  As to the general topic that “isolated conduct combined with good compliance and internal controls make it less likely that [the SEC] will bring an action at all,” Cohen stated that a “great example for compliance professionals is the recent non-prosecution agreement with Ralph Lauren.”

This is a curious reference given that the DOJ (as highlighted in this prior post) specifically stated that “[Ralph Lauren – RLC] did not have an anti-corruption program and did not provide any anti-corruption training or oversight with respect to [the relevant subsidiary].”  Likewise, the SEC specifically stated that “RLC’s policies, procedures and training related to anticorruption and the Foreign Corrupt Practices Act (“FCPA”) compliance in place at that time of the misconduct warranted further strengthening to ensure effective compliance with the related laws.”

Yes, both the SEC and DOJ did commend RLC on its compliance remediation, but this goes to the following point Cohen made in his speech.  He stated.

“I  am surprised how infrequently companies try to persuade us at the front end of an investigation that they have a robust compliance culture and record of ethical conduct.  Invariably, the discussion about a company’s compliance program takes place during settlement negotiations in the context of the substantial remediation that the company has undertaken since violations occurred.”

Aside from the above issues, Cohen’s speech did contain a useful section titled “Warning Signs” of value – in the FCPA context and otherwise – to the compliance practitioner.  This section, stated in full, as follows.

“Warning Signs

Where we find fraud, there are often early warning signs that may have suggested a corporate compliance culture that is not meeting appropriate standards.

Pushing the envelope. 

Risk-taking in the area of legal and ethical obligations invariably leads to bad outcomes.  Any company or person prepared to come close to the line when it comes to legal and ethical standards is already on dangerous ground.

Tolerating close-to-the-line behavior sends a terrible message throughout an organization that pushing the envelope is acceptable.

Technical Compliance. 

Be on the lookout for people who are overly technical in their approach to issues of ethics and professional responsibility. Pay particular attention to those who may disparage or diminish the importance of respect for the law and protecting the organization from reputational harm.

Be Skeptical. 

Be skeptical of explanations that don’t add up regardless of who provides them.  If someone explains something to you in a way that you don’t understand, don’t accept it.

In many ways, one of the important lessons of the financial crisis is that highly sophisticated models that can explain away risk but defy common sense shouldn’t be trusted.  We often see people come in and testify that they failed to follow up on their hunches until after it was too late.

Lack of Empowerment. 

Another warning sign is an organization that limits the access of legal and compliance personnel to senior leadership of the company.

These leaders need to hear candidly and regularly from those on the front lines of compliance efforts.  Compliance professionals are not hallway monitors.  Companies that empower these professionals to act as trusted advisors are more likely to stay out of harm’s way.”

Yes As To A Certain Type Of Compliance Defense

Today’s post is from Marcia Narine (St. Thomas University School of Law).

*****

First, I would like to thank Mike Koehler for the opportunity to add to the debate about an affirmative defense for a corporate compliance program. Although I am now an academic, I write from the perspective as a former compliance officer and deputy general counsel, and as a current consultant to a boutique law firm that advises multinationals, startups and suppliers grappling with the Foreign Corrupt Practices Act on a daily basis. I vote “yes” for the defense, but not for compliance programs that would currently be considered “effective” under the Federal Sentencing Guidelines.

I believe that the current system provides a disincentive for optimal investment in compliance. It is no surprise to me that only 30-40% of SEC cases and less than 50% of DOJ cases come from voluntary disclosures, as was reported by the FCPA Professor here last week. Why voluntarily disclose wrongdoing by a rogue employee when doing the right thing may still subject your firm to fines, penalties, shareholder derivative suits, possible debarment, and potential loss of licenses?

As I wrote here, the burden for corporations attempting to avoid deferred or nonprosecution agreements altogether should be high. I would require the prosecutor to rebut the affirmative defense posed by the firm, which would provide evidence that:

(1)      it has implemented a state of the art program approved and overseen by the board or a designated board committee, which receives comprehensive updates at least twice yearly on the program from the compliance officer;

(2)      elevated the compliance officer to report directly to the board or a designated committee and make the officer terminable only by the board (a suggestion rejected in the 2010 amendments to the Guidelines and which could eliminate potential conflicts when the general counsel does not want to disclose to the government but the compliance officer does);

(3)      clearly communicated the corporation’s intent to comply with the law and appropriate penalties for prohibited acts to employees, suppliers, agents, and partners;

(4)      has developed and provided position-specific training on legal and ethical obligations for employees and board members annually (at a minimum), which is revised as the law changes;

(5)      meets or exceeds industry standards and norms related to compliance and ethics;

(6)      provides the appropriate training and policies to agents, joint venture partners and others who can subject it to liability, requires them by contract to comply, receives annual compliance certifications, and audits their compliance with the same rigor as they audit their own processes;

(7)      has consistently applied anti-retaliation policies for whistleblowers, including terminating those who engage in retaliation;

(8)      is not a habitual recidivist, meaning that the company may have had rogue employees in the past but has endeavored to learn from the compliance failure rather than continuing the same conduct;

(9)      has voluntarily reported wrongdoing to authorities when appropriate;

(10)   is periodically audited and benchmarked by an independent third party that does not provide any other consulting or professional services to it or have any actual or perceived conflicts of interest (such as providing legal advice or external auditing for Sarbanes-Oxley or other purposes) and/or is pre-certified by the appropriate US government agency; and

(11)   has made modifications if necessary to the compliance program based upon the results of the audit.

The external compliance audit or pre-certification process should benchmark the company compared to peer companies and the general corporate population, reviewing, at a minimum, the following factors:

(1)     The corporate culture and tone at the top and throughout the organization. The higher up the level of the wrongdoer, the higher the burden for the company.

(2)     Incentive programs and compensation plans at all levels of the organization that encourage legal, ethical behavior. Companies that have financial incentives in place that either encourage unlawful or unethical behavior through goals that are impossible to reach or that fail to penalize bad conduct would fail this critical prong, which would disqualify them from using the defense.

(3)     Promotional practices and whether compliance and ethical behavior are considered prior to such decisions.

(4)     Adequacy, timeliness and comprehensiveness of training initiatives and the level of employee engagement and understanding of their compliance responsibilities (both position-specific and general).

(5)     The effectiveness of the anti-retaliation programs.

(6)     The effectiveness and usage rate of the anonymous reporting mechanisms.

(7)     The process by which complaints are investigated, including an audit of a random sampling of investigations for thoroughness.

(8)     The adequacy of the resources for the compliance function including continuing external education, appropriate salary and sufficient personnel commensurate with the size of the organization and the nature of the risks for that organization and that industry and

(9)     The level of board engagement and understanding of the compliance priorities of the company based upon the risks related to its business, geography, employee base and incentive structures.

My criteria –which make more sense after reading the longer article– incorporate research about behavioral economics, executive compensation, and best practices from around the world, and would likely disqualify Wal-Mart Mexico and a number of high profile companies that are alleged to have engaged in bribery.  It would also add a tool to the arsenal of beleaguered compliance officers who need ammunition every year around budget time. Most important, this defense would level the playing field between corporations and prosecutors, would provide the proper incentives for companies to prevent, detect and disclose criminal activity, and would allow both the private and public sector to allocate their resources more productively.