Friday Roundup

A sign-off, no surprise, scrutiny alert, for the reading stack, spot-on, and the $10 million man.

Judge Leon Signs-Off On IBM Action

As highlighted in this prior post, in March 2011 the SEC announced an FCPA enforcement action against IBM concerning alleged conduct in South Korea and China.  The settlement terms contained a permanent injunction as to future FCPA violations and thus required judicial approval.  Similar to the Tyco FCPA enforcement action, the case sat on Judge Leon’s docket.  Last month, Judge Leon approved the Tyco settlement (see here) and yesterday Judge Leon approved the IBM settlement.

The common thread between the two enforcement actions would seem to be that both companies were repeat FCPA offenders.

Like Judge Leon’s final order in Tyco, the final order in IBM action states:

“[For a two year period IBM is required to submit annual reports] to the Commission and this Court describing its efforts to comply with the Foreign Corrupt Practices Act (“FCPA”), and to report to the Commission and this Court immediately upon learning it is reasonably likely that IBM has violated the FCPA in connection with either improper payments to foreign officials to obtain or retain business or any fraudulent books and records entries …””

For additional coverage of yesterday’s hearing, see here from Bloomberg.  The article quotes Judge Leon as follows.  IBM “has learned its lesson and is moving in the right direction to ensure this never happens again.” If there’s another violation over the next two years, “it won’t be a happy day.”

However, as noted in this previous post, IBM recently disclosed additional FCPA scrutiny.

No Surprise

This recent post highlighted the 9th Circuit’s restitution ruling in the Green FCPA enforcement action and was titled “Green Restitution Order Stands … For Now.”  As noted in the prior post, the decision practically invited the Greens to petition for an en banc hearing.

No surprise, the Greens did just that earlier this week – see here for the petition.

Scrutiny Alert

This February 2012 post detailed how Wynn Resorts $135 million donation to the University of Macau became the subject of an SEC inquiry.

Earlier this month, Wynn disclosed in an SEC filing as follows:

“On February 13, 2012, Wynn Resorts, Limited (the “Company”) filed a Report on Form 8-K disclosing that it had received a letter from the Salt Lake Regional Office (the “Office”) of the Securities and Exchange Commission (the “SEC”) advising the Company that the Office had commenced an informal inquiry with respect to certain matters, including a donation by Wynn Macau, Limited, an affiliate of the Company, to the University of Macau Development Foundation. On July 2, 2013, the Company received a letter from the Office stating that the investigation had been completed with the Office not intending to recommend any enforcement action against the Company by the SEC.”

According to this report:

“Speaking to The Associated Press from his boat on the Spanish island of Ibiza … CEO Steve Wynn said he never had any doubt federal investigators would clear the company.  ‘We were so sanguine that we never paid any attention to it; we had no exposure. It was a nonevent except for the damn newspapers.'”

For the Reading Stack

The always informative Gibson Dunn Mid-Year FCPA Update and Mid-Year DPA and NPA Update (through July 8th, approximately 30% of all DPAs/NPAs have been used to resolve FCPA enforcement actions).

Sound insight from Robertson Park and Timothy Peterson in this Inside Counsel column:

“Without putting too fine a spin on the matter, the discussion of the potential consequences faced by a company with potential anti-bribery exposure was fundamentally U.S.-centric. The dispositive question was often whether or not the potential misconduct was likely to fall under the umbrella of FCPA enforcement. Would U.S. authorities be interested in pursuing this matter? Would they find out about this matter? There were not many other concerns that mattered. Whether the site of the potential misconduct was in the European, Asian, South American or African sector, the substantial likelihood was that home authorities would have little interest in the matter, and even if they did it was likely an interest that would often frustrate and impede efforts by the Department of Justice or the Securities and Exchange Commission to investigate the matter. Cooperative enforcement was unlikely. This has changed. […]  For companies that learn of a potential international corruption issue, the impact of this emerging global enforcement market means that the headache associated with scoping an internal investigation is now a migraine with diverse and complex symptoms. Companies investigating potential bribery have always faced the question of how, if at all, they plan to disclose any subsequent findings to government authorities. Now, initial assessments of investigative plans in anti-bribery matters must consider a broader array of potentially interested enforcement authorities. Companies must design their anti-bribery investigations at the outset to consider not only the FCPA enforcement regime in the U.S., but also a newly energized U.K. anti-bribery law, along with a growing list of ant-bribery measures in almost all of the important jurisdictions with business growth opportunities.”

Six ways to improve in-house compliance training from Ryan McConnell and Gérard Sonnier.

The reality of facilitation payments from Matt Kelly.

“… Facilitation payments are a fact of life in global business. Nobody likes them, and no compliance officer wants to pay a bribe disguised as a facilitation payment. But when the transaction truly fits the definition of a facilitation payment—money paid to a government official, to speed up some job duty he would normally perform anyway—there shouldn’t be any ethical or legal crisis in paying it. After all, we have facilitation payments domestically in the United States. If you want a passport from the State Department, you pay $165 in fees. If you want an expedited passport, you pay an extra $60 fee and get your passport in half the usual time. That’s a facilitation payment, pure and simple. Other countries have all sorts of facilitation payments as well, say, to get a visa processed quickly or to clear goods through customs rather than let them rot on the docks. Urgent needs happen in business, and facilitation payments get you through them. That’s life.”

The language of corruption from the BBC.

Spot-On

Regardless of what you think of former New York Attorney General Eliot Spitzer, he is spot-on with his observation that the so-called Arthur Anderson effect (i.e. if a business organization is criminally charged it will go out of business) is “overrated.”  As noted in this Corporate Crime Reporter piece, in a new book titled “Protecting Capitalism Case by Case” Spitzer writes:

“Almost all entities have the capacity to regenerate — even if under a new name, with new ownership and new leadership — and forcing them to do so will have the deterrent effect we desire.”

“Most companies would have no trouble continuing in operation once charged. They might suffer reputational harm, perhaps lose contracts, have certain loans be declared to be in default, and lose some personnel and public support. But that would probably be the proper price to be paid in the context of the violations of the law they committed.”

As noted in previous posts, the Arthur Anderson effect was effectively debunked (see here) and even Denis McInerney (DOJ, Deputy Assistant Attorney General) recently acknowledged (see here) that there is a very small chance that a company would be put out of business as a result of actual DOJ criminal charges.

In his new book Spitzer also writes as follows concerning the SEC’s neither admit nor deny settlement policy.

“I hope that the new leadership at the Securities and Exchange Commission will mandate that an admission of guilt is a necessary part of future settlements in cases of this stature or magnitude. The law and justice require such an acknowledgement — or else nothing has been accomplished.”

Speaking of neither admit nor deny, part of the SEC’s talking points defense of this policy is that the SEC is not the only federal agency that makes use of such a settlement policy.

On this score, it is notable – as detailed in this Law360 article – that Bart Chilton, a top official at the U.S. Commodity Futures Trading Commission, “said the commission should rethink its policy of allowing defendants to settle claims without admitting or denying the allegations.”  According to the article, Chilton stated:

“I understand there are certain circumstances where we might not want to require [admissions], but I think we at the CFTC should change our modus operandi.  The default position should be that people who violate the law should admit wrongdoing.”

$10 Million Man

Continuing with neither admit nor deny, one of the defenders of this settlement policy was Robert Khuzami while he was at the SEC as the Director of Enforcement.   As noted in this Kirkland & Ellis release, Khuzami joined the firm as a partner in the global Government, Regulatory and Internal Investigations Practice Group.  According to this New York Times article, Khuzami’s new position “pays more than $5 million per year” and is guaranteed for two years.  In joining Kirkland, the New York Times stated that Khuzami “is following quintessential Washington script: an influential government insider becoming a paid advocate for industries he once policed.”

Khuzami and former Assistant Attorney General Lanny Breuer were the voice and face of the SEC and DOJ last November upon release of the FCPA Guidance.  As detailed in this prior post, Breuer is currently at Covington & Burling making approximately $4 million per year.

*****

A good weekend to all.

Compliance Fatigue?

Has this new era of FCPA enforcement resulted in compliance fatigue and its unintended negative consequence of numbing individuals to the FCPA?

It has been noted:

“Rules and controls and training programs are essential in any organization, but at some point, the burdens imposed by intricate matrices of rules, complex reporting and approval processes, and seemingly never-ending training requirements become a net drag on the business.  […] The deleterious effects of too much compliance activity include much more than a drag on productivity. A system that is overly-controlled, that has passed its optimal point of compliance activities, will engender backlash and bewilderment from those who are being controlled. Managers and other employees will balk at a sclerotic network of rules and processes, and they won’t—and in many instances may not be able to—comply. Rules and signoffs will be overlooked, and training courses never taken. Such backlash can actually move a program backward down the benefits curve. And when an employee population sees the compliance program as overly burdensome and poorly aligned with business reality, they will undermine the credibility of the entire enterprise.”

At a recent compliance industry conference compliance officers expressed concerns “about too much compliance” across a wide variety of areas.  More to the point, a recent survey found that although “many companies have intensified their efforts to combat bribery and corruption, especially given the aggressive enforcement environment” many executives “must overcome a certain degree of institutional fatigue about anti-corruption compliance initiatives.”  The survey concluded:

“We found many boards felt increasingly swamped by risk management and control information. Combined with a growing sense of [bribery and corruption] compliance fatigue, this contributes towards a ‘tick the box’ approach to managing risk.”

Annual FCPA training, annual FCPA certifications, databases full of customers with government ownership, an automated process for this and that, periodic FCPA compliance reminders, FCPA compliance as an agenda item on each meeting, etc.  All of these are considered best practices, but the question is asked – is too much FCPA compliance actually a net negative?

Think of a typical television commercial for a new drug.  Thirty seconds of the commercial is devoted to describing the benefits of the drug.  However, because of regulatory requirements and the company’s potential legal liability associated with the drug, ninety seconds of the commercial is devoted to a laundry list of negative side effects associated with the drug.  At some point, viewers disengage from the message and the positive attributes of the drug (the reason for the commercial in the first place) are lost.

Applying this dynamic to FCPA compliance, is trying to anticipate and address every potential instance of FCPA risk through training slides and compliance modules diverting attention away from the big picture of FCPA compliance and numbing employees and others who operate on the company’s behalf to the underlying objectives of the company’s FCPA compliance policies and procedures?  In short, when it comes to FCPA compliance, is less more?

A compliance professional observed:

 “In response [to this new era of FCPA enforcement], companies have begun to provide more and more accessible (read: web-based) anti-corruption and related regulatory training programs.  Predictably, a panoply of vendors have surfaced offering state-of-the-art customizable online training modules, complete with scenarios, live actors, knowledge checks and certifications.  Online compliance training has now become a cottage industry serving a wide array of organizations faced with the daunting task of communicating a Western regulatory concept to tens of thousands of employees across multiple languages, cultures and jurisdictions – again, under the watchful eye of various enforcement bodies.  […] [Does] repeated online and other mass training over time actually have the unintended effect of desensitizing employees to, rather than making them more aware and cautious of, bribery and other corrupt activity.”

What do you think?  Is compliance fatigue real?

An FCPA Lawyer In Paris

Today’s post is a Q&A with Bryan Sillaman (Hughes Hubbard & Reed).  Sillaman is a member of the firm’s Anti-Corruption and Internal Investigations Practice Group and is currently working in the firm’s Paris office.  Prior to joining Hughes Hubbard, Sillaman was an attorney in the SEC Enforcement Division where he conducted several Foreign Corrupt Practices Act investigations.

Q:  What brought you to Paris and what is it like being an FCPA lawyer in Paris?

Hughes Hubbard has had an office in Paris for nearly 50 years, and has a long history representing French companies.  I was fortunate enough to be asked to come to Paris to assist one of our French clients with a global anti-corruption review.  At the time, it was unclear how long I would stay, but that was nearly four and a half years ago.  It has been fascinating and instructive to see how the FCPA and U.S. enforcement environment is perceived within Europe, and to also witness the development of other significant international anti-corruption initiatives, such as the passage of the U.K. Bribery Act, which got the attention of a lot of European companies.  The industry of compliance appears to be steadily growing in France, with one of the French universities creating a Masters in Law in Business Ethics (Master Droit & Ethique des Affairs).  While part of this seems to be in response to increased enforcement of European companies by the U.S., I also believe that the political climate in Europe generally, and France specifically, is becoming less tolerant of corruption – particularly at the governmental level – which has helped fuel the industry.

Q:  How are European clients different from U.S. clients, perhaps in terms of voluntary disclosure, cooperation with enforcement agencies, etc.?

One thing to keep in mind when working with European companies is that, at least in certain countries, it was legal and in fact tax deductible to pay bribes until just over a decade ago.  In this sense, anti-corruption compliance is a newer issue for many companies, although it is one that is gaining increased focus and attention, particularly within multinational corporations.  It should also be remembered that for the first approximately twenty years of the FCPA’s existence, it was relatively rarely enforced.  Thus, while perhaps some European countries are lagging the U.S. in bringing their own enforcement proceedings, there does appear to be an increased focus on the issue within the corporate community.

For better or worse, European conceptions of topics such as voluntary disclosure, cooperation, and remediation have been largely shaped to date by U.S. enforcement jurisprudence and posture.  Therefore, in advising European companies on such issues, counsel naturally have differing philosophical viewpoints on the potential benefits and pitfalls of voluntary disclosure or cooperation.  Anecdotally, however, I think that the concept of voluntary disclosing issues to the government (and potentially being prosecuted in return) strikes many European companies as contrary to sound logic.  European clients also find fascinating the broad jurisdictional view taken by U.S. (and now U.K) regulators, as well as what until recent history is a new concept:  that of the independent corporate monitor.

There are also more nuanced issues that can have a profound impact on how to conduct a compliance review with European companies that may, at first blush, seem unusual to U.S. counsel.  For example, one of the initial differences that will likely become apparent is how European companies approach data privacy rights of employees and the handling or movement of potentially sensitive information.  Europe in general, and certain countries like France in particular, have much stronger personal privacy data rights than those we may be familiar with in the United States, and these rights extend into an individual’s workplace.  Counsel who are not wary of these issues and take them in consideration in structuring and conducting a review can face their own legal trouble.  In addition to bestowing legal rights on individuals, these data privacy concerns must also be taken into account culturally, in the sense that counsel should be prepared for greater resistance to activities such as the collection of emails and electronic data that may be necessary, but nonetheless intrusive, steps towards conducting an effective review.

Q: You have travelled extensively as part of your FCPA practice (Angola, Brazil, China, Indonesia, Malaysia, the Middle East, Nigeria, Thailand and Venezuela).  From these travels and experiences, what do you believe are the major root causes of FCPA violations?

Corruption is most certainly a two-way street.  When it comes to bribe payers, unfortunately many cases seem to boil down to greed and a myopic focus on winning at all costs that is ever-too-present in many industries.  For sure there are frequently claims that “everyone else is doing it,” but as we all learned when we were young, that doesn’t make it right.  In terms of bribe recipients, while I will not claim to have researched the issue as much as others have in this field, anecdotally one of the major themes in countries we often visit is the absence of a fair and livable wage for government functionaries.  In these cases, officials may feel as though there is no alternative but to seek payments from companies and their employees (who they may see living at a much higher standard) in order to earn a sufficient living.  With larger-scale corruption, I think the same mentality exists, but in a more perverse way – officials placed in charge of vast amounts of resources see companies and others making significant amounts of money off of those resources and see no alternative but to seek what they come to view as their rightful piece of the pie.

Q:  What do you know or realize now as it relates to the FCPA and FCPA compliance that you did not know or realize while at the SEC working on FCPA cases?

Perhaps it was more a function that I was at the SEC very early in my career, but I did not realize until traveling extensively assisting clients in this area the importance that companies place on practical guidance when it comes to anti-corruption compliance.  It is one thing to recite to a client the FCPA’s statutory language, but quite another to provide helpful guidance on ways in which companies can operate in a legal and compliant way in very difficult locations and business environments.  I and my colleagues operate from the premise that most people want to do the right thing, they just need the training and guidance to do so.  I think this thirst for practical guidance is one of the reasons that DOJ/SEC Resource Guide to the U.S. Foreign Corrupt Practices Act has been well received within this community, and I applaud both agencies for the significant efforts that went into making it approachable and practical.  Certainly, there remain very difficult questions, some of which do not have a clear answer.  For example, when and to what extent is it appropriate to take personnel action against an employee?  There may not be a black-and-white answer to this question, and in Europe, where labor laws tend to heavily favor employees, implementing appropriate employee sanctions can be quite difficult.  Having been fortunate enough to have helped companies navigate through some of these issues, I acknowledge that I lacked a full appreciation earlier in my career for the time and energy that companies and their compliance personnel devote to implementing, in a practical way, the anti-corruption legal standards and guidance that govern their activity.

What Is A Board’s Responsibility For Compliance?

A guest post today from Thomas Fox who runs the FCPA Compliance and Ethics Blog.

*****

“The nightmare of every corporate director is to wake up to find out that the company of the Board he or she sits on is on the front page of the New York Times (NYT) for alleged illegal conduct. This nightmare came true for the Directors of Wal-Mart when the New York Times, in an article entitled “Vast Mexico Bribery Case Hushed Up by Wal-Mart After Top-Level Struggle”, alleged that Wal-Mart’s Mexican subsidiary had engaged in bribery of Mexican governmental officials and that the corporate headquarters in Bentonville, Arkansas, had covered up any investigations into these allegations.

Recently the NYT reported that shareholders were asking questions of the Wal-Mart Board regarding its response these allegations. In a story, entitled “More Dissent in a Store Over Wal-Mart Bribery Scandal”, Stephanie Clifford reported Wal-Mart shareholders are still asking questions of the Board regarding its role in the ongoing scandal. Some of these questions include “whether the company is holding current and former executives financially responsible for breaching company policies” and concerns about the company’s supply chain vendors. This shareholder dissatisfaction led several groups of large shareholders to indicate that they would vote against the company’s current Board of Directors at its annual shareholder meeting.

Clifford quoted from a report by Institutional Shareholder Services (ISS), a proxy advising firm, which said that investors have also complained about “being in the dark about the nature and extent of the alleged violations (and knowledge of them within the company)” and the company’s “timetable for completion of its investigation and disclosure of its results.”  There were also questions raised about the remediation efforts of Wal-Mart. The ISS report went on to add that “Shareholders should vote against these directors to send a clear message to the board that such poor oversight does not come without repercussions.”

The publicity and costs to Wal-Mart have been well documented.  On his FCPA Professor website, Professor Koehler has consistently stated that he views this scandal as largely a failure of corporate governance. In a post entitled, “Wal-Mart One Year Later” he said, “corporate governance, or lack thereof, is what made the NY Times April 2012 remarkable.  This is the reason why Wal-Mart generated all the buzz it did a year ago this week and I’ve consistently held the view that the Wal-Mart story is a corporate governance sandwich with the FCPA as a mere condiment.” I thought about Professor Koehler’s observations on this failure in light of Clifford’s article and wondered what the Board’s legal obligations might be.

I.                   Some Case Law

As to the specific role of ‘Best Practices’ in the area of general compliance and ethics, one can look to Delaware corporate law for guidance. The case of In Re Caremark International Inc. Derivative Litigation 698 A.2d 959 (Del.1996) was the first case to hold that a Board’s obligation “includes a duty to attempt in good faith to assure that a corporate information and reporting system, which the board concludes is adequate, exists, and that failure to do so under some circumstances may, in theory at least, render a director liable for losses caused by non-compliance with applicable legal standards.” The Corporate Compliance Blog, in a post entitled “Caremark 101”, said that the Caremark case “addressed the board’s duty to oversee a corporation’s legal compliance efforts. As part of its duty to monitor, the Board must make good faith efforts to ensure that a corporation has adequate reporting and information systems. The opinion described this claim as “possibly the most difficult theory in corporation law upon which a plaintiff might hope to win a judgment,” with liability attaching only for “a sustained or systematic failure to exercise oversight” or “[a]n utter failure to attempt to ensure a reporting and information system.”

In the case of Stone v. Ritter 911 A.2d 362, 370 (Del. 2006), the Supreme Court of Delaware expanded on the Caremark decision by establishing two important principles. First, the Court held that the Caremark standard is the appropriate standard for director duties with respect to corporate compliance issues. Second, the Court found that there is no duty of good faith that forms a basis, independent of the duties of care and loyalty, for director liability. Rather, Stone v. Ritter holds that the question of director liability turns on whether there is a “sustained or systematic failure of the board to exercise oversight – such as an utter failure to attempt to assure a reasonable information and reporting system exists.”

Andrew J. Demetriou and Jessica T. Olmon, writing in the ABA Health Esource blog, said that “This standard aims to protect shareholders by ensuring that corporations will adopt reasonable programs to deter, detect and address violations of law and corporate policy, while absolving the Board from liability for corporate conduct so long as it has exercised reasonable responsibility with respect to the adoption and maintenance of a compliance and reporting system. Although the standard protects the Board, consistent with most jurisprudence under the business judgment rule, it also requires that the Board follow through to address problems of which it has notice and this may include adopting modifications to its compliance program to address emerging risks.”

Lastly, I recently heard Jeff Kaplan discuss the oversight obligations of the Board regarding the compliance function. In addition to the above cases, he discussed the case of Louisiana Municipal Police Employees’ Retirement System et al. v. David Pyott, et al., 2012 WL 2087205 (Del. Ch. June 11, 2012) (rev’d on other grounds, No. 380, 2012, 2013 WL 1364695 (Del. Apr. 4, 2013), which was a shareholder action that went forward against a Board based upon a claim that the Board knew of compliance risk based on the company’s business plan. The Delaware Court pointed out the possibility that “the appearance of formal compliance cloaked the reality of noncompliance, and directors who understood the difference between legal off-label sales and illegal off-label marketing continued to approve and oversee business plans that depended on illegal activity.” Kaplan believes that this case more generally, supports the need for risk-based oversight by a Board.

II.                FCPA Guidance and US Sentencing Guidelines

A Board’s duty under the Foreign Corrupt Practices Act (FCPA) is well-known. In the Department of Justice / Securities and Exchange Commission FCPA Guidance, under the Ten Hallmarks of an Effective Compliance Program, there are two specific references to the obligations of a Board.

The first in Hallmark No. 1, entitled “Commitment from Senior Management and a Clearly Articulated Policy Against Corruption”, states “within a business organization, compliance begins with the board of directors and senior executives setting the proper tone for the rest of the company.”

The second is found under Hallmark No. 3 entitled “Oversight, Autonomy and Resources”, where it discusses that the Chief Compliance Officer (CCO) should have “direct access to an organization’s governing authority, such as the board of directors and committees of the board of directors (e.g., the audit committee).”

Further, under the US Sentencing Guidelines, the Board must exercise reasonable oversight on the effectiveness of a company’s compliance program. The DOJ’s Prosecution Standards posed the following queries: (1) Do the Directors exercise independent review of a company’s compliance program? and (2) Are Directors provided information sufficient to enable the exercise of independent judgment?

Board failure to head this warning can lead to serious consequences. David Stuart, a senior attorney with Cravath, Swaine & Moore LLP, noted that FCPA compliance issues can lead to personal liability for directors, as both the SEC and DOJ have been “very vocal about their interest in identifying the highest-level individuals within the organization who are responsible for the tone, culture, or weak internal controls that may contribute to, or at least fail to prevent, bribery and corruption”. He added that based upon the SEC’s enforcement action against two senior executives at Nature’s Sunshine Products, “under certain circumstances, I could see the SEC invoking the same provisions against audit committee members—for instance, for failing to oversee implementation of a compliance program to mitigate risk of bribery”. It would not be a far next step for the SEC to invoke the same provisions against audit committee members who do not actively exercise oversight of an ongoing compliance program.

There is one other issue regarding the Board and risk management, including FCPA risk management, which should be noted. It appears that the SEC desires Boards to take a more active role in overseeing the management of risk within a company. The SEC has promulgated Regulation SK 407 under which each company must make a disclosure regarding the Board’s role in risk oversight which “may enable investors to better evaluate whether the board is exercising appropriate oversight of risk.” If this disclosure is not made, it could be a securities law violation and subject the company, which fails to make it, to fines, penalties or profit disgorgement.

From the Delaware cases, I believe that a Board must not only have a corporate compliance program in place but actively oversee that function. Further, if a company’s business plan includes a high-risk proposition, there should be additional oversight. In other words, there is an affirmative duty to ask the tough questions. The specific obligations set out regarding the FCPA drive home these general legal obligations down to the specific level of the statute.

The Wal-Mart case has driven home the need for focused Board of Directors oversight of a company’s compliance program.  But it is more than simply having a compliance program in place. The Board must exercise appropriate oversight of the compliance program and indeed the compliance function. The Board needs to ask the hard questions and be fully informed of the company’s overall compliance strategy going forward. If the Wal-Mart Board had fulfilled its legal obligations regarding compliance, the company might not have found itself on the front page of the New York Times.”

Can We Bring Quality FCPA Compliance and Investigative Services to the Underserved Middle Market?

Today’s post is from David Simon (Foley & Lardner).

*****

Professor Koehler (my former colleague at Foley & Lardner) has been critical of “FCPA Inc.” and, in particular, the astronomical costs associated with certain FCPA investigations and compliance measures.  My friends in the C-Suite of FCPA Inc. have responded defensively – reacting at least in part to a perception that these criticisms suggest a corner-cutting approach to important work that must be done properly.

As an FCPA lawyer with a foot in both camps, let me try to find some common ground.

I share Mike’s concerns.  While I understand that each case is different and that it is often necessary for investigating counsel to respond to outside forces that drive up costs, some of the eye-popping numbers can’t help but make one question the FCPA investigation/compliance value proposition.

This dynamic is especially troubling because, I fear, it drives the perception among many smaller and mid-sized companies that anti-bribery compliance is simply out of reach financially.  A recent survey of global corruption compliance in the middle market conducted by McGladrey confirms that this segment of the market is underserved.  That is dangerous and bad for all the interested parties – including the DOJ and SEC.  It simply isn’t good public policy for sound FCPA compliance advice and investigative resources to be available only to the Exxon Mobils of the world.

That said, the quality of the work should not be compromised by maintaining some focus on the value proposition.  Corner-cutting is not appropriate (and is almost never in the company’s long-term interests).  But aren’t there ways to manage costs and still produce quality work?  The answer is clearly yes.  And while the options for delivering more for less are myriad, let me propose three fairly modest concepts, which, if implemented, would help bring quality FCPA representation to many more companies that really need it:

1.         Give Strong but Practical Compliance Advice

We can start by heeding the counsel of the SEC and DOJ in last year’s Resource Guide:

  •  “DOJ and SEC have no formulaic requirements regarding compliance programs.  Rather, they employ a common-sense and pragmatic approach to evaluating compliance programs.”
  • “[T]here is no one-size-fits all program. . . . Indeed, small-and medium-sized enterprises likely will have different compliance programs from large multi-national corporations, a fact DOJ and SEC take into account when evaluating companies’ compliance programs.”

In other words, take it seriously, but be practical.  And take a risk-based approach to FCPA compliance.

In a world where FCPA compliance was the company’s number one focus (above and beyond making and selling stuff), a company would conduct “Full Monty” due diligence on all of its distributors (maybe even its customers).  It would employ a rigorous system for reviewing all gifts, meals and entertainment expenses in excess of $25.  (After all, $25 is a lot of money to a customs official in Borneo . . .)  It would conduct annual compliance audits of the books and records of all of its third-party intermediaries.

But really, does that approach make sense for most of our clients?  While there may be companies that have a risk profile that justifies these procedures, for many – indeed, the vast majority –  such an approach is simply impractical.  Let’s not make the perfect the enemy of the good.

To lawyers and compliance professionals:  Be practical. Be willing to sign-off on compliance procedures that are effective but tailored to the actual risk posed.  Don’t be afraid to divert from “best practices” when best practices are not risk justified.  Take a stand.  But be prepared to defend your decisions.

And to the enforcement agencies.  Be true to your word.  “[D]o not hold companies to a standard of perfection.” Accept common sense compliance judgments, even when things ultimately go wrong.

2.         Appropriately Scope FCPA and Bribery Investigations

When a company discovers conduct that may violate the FCPA or company policies, an investigation is necessary.  It never makes sense for a company to ignore such a discovery.  You are simply not serious about compliance if you do not take steps to understand what happened, why, how, and to respond appropriately.  The enforcement agencies are entirely justified in requiring this and in taking companies to account for failing to investigate and respond to indications of wrongdoing.

The problem for many companies is that they hear the words “FCPA investigation” and think millions of dollars – or tens of millions, or hundreds of millions – in costs and fees.  Too often, this leads companies to make the bad decision to forgo an investigation altogether.

But just as there is no “one-size-fits-all” FCPA compliance program, there is no “one-size-fits-all” FCPA investigation.  Proportionality and reasonableness are key.

The main driver of investigation cost is scope.  FCPA investigations that spin out of control usually do so because the scope is never clearly defined at the outset or because of significant scope-creep during the investigation.  Think about our country’s history with Independent Counsel investigations.  Without a clear, narrowly defined mandate, investigations can go on interminably.  Investigators investigate.  There is always some new lead to pursue, another witness to interview, another document to request and review.

The investigation scope needs to be reasonable and appropriately calibrated to the issues under investigation.  Scope must be clearly defined, and the investigator must keep the scope front of mind.  Discipline is key.

This is not to say that the scope should never change once defined.  Often, new significant facts are discovered and new issues identified.  Many times, these developments warrant a modification to the scope.  But those decisions should be approached thoughtfully and intentionally.  Scope modification is not the same thing as scope-creep.

Appropriately scoped investigations cost less.  Companies with limited legal and compliance resources can access quality investigative services and can fulfill the agencies’ directive that “companies should have in place an efficient, reliable, and properly funded process for investigating the allegation and documenting the company’s response.”

To the SEC and DOJ:  To make this work, you need to apply these same common-sense principles to your assessment of company investigations.  Be reasonable.  To outside auditors assessing the company’s response:  Ditto.

3.         Disaggregation of Services in FCPA and Bribery Investigations

One final modest idea to manage the cost of FCPA investigations:  Consider disaggregating services.

It is not necessary to have high-priced lawyers conduct every aspect of every investigation.  In the health care industry, they refer to “working at the top of your license.”  In other words, to enhance the efficiency of the provision of care, each professional should be put to his or her highest and best use.  Move the work down the chain of training and expertise where appropriate.  Application of the same concept in FCPA investigations can have the same pro-efficiency effect.

As a preliminary matter, it isn’t necessary for a company to hire outside counsel to conduct every FCPA investigation.  There are certainly some situations where the exclusive deployment of inside investigative resources is appropriate.

Even when outside counsel properly leads the investigation, the lead investigator should consider non-traditional deployment of resources so that everyone on the team is being put to his or her highest and best use.  A couple of examples:

Consider enlisting internal company resources to accomplish some investigative tasks.  Under the right circumstances, company IT personnel can help gather and process data for the investigation; internal audit or finance resources can help with the analysis of the books and records; and in-house counsel can perform certain investigative tasks.  Independence and perceptions of independence must be taken into consideration in every case, of course.  In some investigations, it won’t be appropriate to involve company personnel.  But in some, it will be entirely reasonable and appropriate.  And where it is, there will be substantial cost savings.

In addition, investigative counsel should consider outsourcing or alternative-sourcing aspects of the investigation.  Document review is an obvious example.  Consider using data review software to cull the relevant documents that warrant review.  (It is noteworthy that DOJ recently approved the use of this approach in the AB InBev/Grupo Modelo merger review.  If it works in antitrust, why not FCPA investigations?)  This can save hundreds of hours of lawyer and staff time.  It also often makes sense to outsource document review.  There are a number of firms that conduct quality document review at a much lower cost than using attorneys (even contract attorneys.)  I personally have used Novus Law, a document-related discovery firm, to handle all of the document review, management and analysis on a couple of document-heavy FCPA investigations.  They do an outstanding job (no quality compromises) at a fraction of the cost.

These are just a few ideas for changing the way we provide compliance and investigative services to give better access to these critical services to more companies.  How we do this is less important than that we do it.