Siemens And An FCPA Compliance Defense
The title of this post may induce a Gary Coleman moment – as in “whatcha talkin bout” (see here). No, I am not talking about that Siemens case – the 2008 FCPA enforcement action, the largest in FCPA history from a fine and penalty perspective, in which the DOJ and SEC alleged that Siemens engaged in a pattern of bribery “unprecedented in scale and geographic reach” and that for much of its operations around the world “bribery was nothing less than standard operating procedure.”
Should the FCPA be amended to include a compliance defense, such a defense would clearly be inapplicable to the 2008 Siemens matter given allegations that Siemens had, at one time, a “corporate culture in which bribery was tolerated and even rewarded at the highest levels of the company.” As detailed in my responses (here) to Senator Specter’s questions at the November 2010 FCPA hearing, according to the DOJ, “compliance, legal, internal, audit, and corporate finance departments were a significant focus of the investigation and were discovered to be areas of the company that played a significant role in the violations”
Since the 2008 FCPA enforcement action (and indeed even before the ink was dry on the settlement documents), Siemens has undergone a substantial compliance transformation. As noted in the DOJ’s sentencing memorandum (here), settlement of the matter contained, among other things, the following terms: “implementation of rigorous compliance enhancements, including periodic testing of same, with a recognition that Siemens has already implemented substantial compliance changes over the course of the investigation; and retention of an independent monitor, who will, over a four-year term, conduct a review of the compliance code, Siemens’ internal controls and related issues, and will prepare periodic reports on his reviews.”
A specific section of DOJ’s sentencing memorandum is titled “Remediation Efforts” and stated, in pertinent part, as follows. “Siemens also overhauled and greatly expanded its compliance organization, which now totals more than 500 full time compliance personnel worldwide. Control and accountability for all compliance matters is vested in a Chief Compliance Officer, who, in turn, reports directly to the General Counsel and the Chief Executive Officer. Siemens has also reorganized its Audit Department, which is headed by a newly appointed Chief Audit Officer who reports directly to Siemens’ Audit Committee. To ensure that auditing personnel throughout the company are competent, the Chief Audit Officer required that every member of his 450 person staff reapply for their jobs. Siemens also has enacted a series of new anti-corruption compliance policies, including a new anti-corruption handbook, sophisticated web-based tools for due diligence and compliance matters, a confidential communications channel for employees to report irregular business practices, and a corporate disciplinary committee to impose appropriate disciplinary measures for substantiated misconduct. Siemens has organized a working group devoted to fully implementing the new compliance initiatives, which consists of employees from Siemens’ Corporate Finance and Corporate Compliance departments, and professionals from PricewaterhouseCoopers (“PwC”). This working group developed a step-by-step guide on the new compliance program and improved financial controls known as the “Anti-Corruption Toolkit.” The Anti-Corruption Toolkit and its accompanying guide contain clear steps and timelier requirements of local management in the various Siemens entities to ensure full implementation of the global anti-corruption program and enhanced controls. Over 150 people, including 75 PwC professionals, provided support in implementing the Anti-Corruption Toolkit at 162 Siemens entities, and dedicated support teams spent six weeks on the ground at 56 of those entities deemed to be “higher risk,” assisting management in those locations with all aspects of the implementation. The total external cost to Siemens for the PwC remediation efforts has exceeded $150 million.”
Elsewhere, the DOJ sentencing memorandum, as to third parties, stated as follows. “Siemens also significantly enhanced its review and approval procedures for business consultants, in light of the past problems. The new state-of-the-art system requires any employee who wishes to engage a business consultant to enter detailed information into an interactive computer system, which assesses the risk of the engagement and directs the request to the appropriate supervisors for review and approval. Siemens has also increased corporate-level control over company funds and has centralized and reduced the number of company bank accounts and outgoing payments to third parties.”
In summary, the DOJ stated that “the reorganization and remediation efforts of Siemens have been extraordinary and have set a high standard for multi-national companies to follow.”
More recently, as of May 2011, according to Siemens compliance: (i) approximately 600 employees work full time in a single compliance organization managed by a Chief Compliance Officer (of this number approximately 80 work at Siemens corporate headquarters with the rest deployed evenly around various sectors/divisions and regional companies); (ii) 300,000 employees world-wide have received compliance training, including 100,000 employees who received face-to-face multi-hour courses; (iii) all new compliance officers worldwide are required to take an intensive four-day course; (iv) approximately 5,500 top managers worldwide have compliance metrics as one aspect of their compensation; and (v) approximately 55 high-risk entities and approximately 105 business unit were required to implement over 100 compliance systems controls.
The 2008 judgement against Siemens (here) imposes a five year probation period during which Siemens shall not commit any further crimes and the additional probation term that Siemens is to comply with the compliance and ethics program set forth in its plea agreement.
In short, there is likely no other company in the world today that has devoted as many corporate resources, with the assistance of industry experts, to compliance than Siemens. On the flip side, there is likely no other company in the world today that faces as many negative consequences should its compliance efforts fail than Siemens.
Against this backdrop, over the summer media reports suggested “alleged corruption by three company managers working in Kuwait” who allegedly “made payments to high-ranking individuals” in Kuwait’s Energy and Water Ministry. (See here). According to the reports, German authorities began investigating the conduct after receiving information from Siemens itself.
In other words, notwithstanding 600 full time Siemens compliance personnel, an Anti-Corruption Toolkit designed by industry leaders, over 100 compliance systems controls in high-risk jurisdictions, someone in Siemens organization may have made payments in violation of its pre-existing compliance policies and procedures and in violation of the FCPA.
Presumably, Siemens – should it be prosecuted – would get credit for its committment to compliance and pre-existing policies and procedures pursuant to the DOJ’s Prosecution of Business Organizations. In addition, should Siemens be prosecuted it would presumably receive credit for the same under the advisory U.S. Sentencing Guidelines. As the enforcement agencies have frequently stated in connection with FCPA reform – we already take compliance into account!
However, are these “baby carrots” a sufficient return on Siemens compliance investment? Do these “baby carrots” sufficiently recognize Siemens committment to compliance? Or should Siemens compliance efforts be recognized as a matter of law as would be the case if the FCPA was amended to include a compliance defense?
Perhaps The Executives Are Just Being Realistic
It has turned out to be a statistics filled week on this site. If you like statistics, Deloitte’s recent “Anti-Corruption Practices Survey 2011” (here) serves up a buffet of delightful morsels.
Deloitte “surveyed 276 executives to assess how companies are managing their efforts to prevent corrupt practices in their operations around the world and ensure compliance with legislative requirements.” The Survey found that approximately 90% of executives said their company had an anti-corruption policy that covered a wide range of potentially corrupt activities.
Even so, the Survey seems to portray, as its most meaningful statistic, that “only 29% of the 276 executives … were very confident their company’s anti-corruption program would prevent and detect corrupt activities.” According to the Survey, “this low level of confidence indicates that many companies may need to evaluate and upgrade their anti-corruption efforts.”
Perhaps. Or perhaps the 29% figure indicates the stark reality that not even gold standard FCPA compliance policies and procedures can prevent or detect all problematic payments. In other words, perhaps the 71% of executives who were not very confident their company’s anti-corruption program would prevent and detect corrupt activities are just being realistic. As even Assistant Attorney General Lanny Breuer noted earlier this year before a compliance audience – “There will always be rogue employees who decide to take matters into their own hands. They are a fact of life.” (See here). Or as the U.K. Ministry of Justice stated in its Bribery Act guidance (see here) “no policies or procedures are capable of detecting and preventing all bribery.”
The Survey findings on corruption risks also caught my eye. Executives were asked to cite “significant” corruption risks. Use of third parties (not surprisingly) was the top concern and “customs clearance and importation of goods” and “entertainment related to government business/relations” were the 2nd and 3rd highest concerns respectively. These findings confirm my own observations from participating in executive roundtable forums during which I am always struck that business leaders are most worried about issues Congress did not even have on its radar when it passed the FCPA – yet are worrisome issues given the DOJ’s enforcement positions.
For instance, the enacting Congress specifically excluded from the FCPA’s “foreign official” definition any employee of a foreign government “whose duties are essentially ministerial or clerical.” The relevant Senate Report states, in pertinent part, as follows. “The statute does not […] cover so-called ‘grease’ payments such as payments for expediting shipments through customs or placing a transatlantic telephone call, securing required permits, or obtaining adequate police protection, transactions which may involve even the proper performance of duties.” Similarly, the relevant House Report states, in pertinent part, as follows. “The language of the bill is deliberately cast in terms which differentiate between [corrupt payments] and facilitating payments, sometimes called ‘grease payments.’ […] For example, a gratuity paid to a customs official to speed the processing of a customs document would not be reached by this bill. Nor would it reach payments made to secure permits, licenses, or the expeditious performance of similar duties of an essentially ministerial or clerical nature which must of necessity be performed in any event. While payments made to assure or to speed the proper performance of a foreign official’s duties may be reprehensible in the United States, the committee recognizes that they are not necessarily so viewed elsewhere in the world and that it is not feasible for the United States to attempt unilaterally to eradicate all such payments. As a result, the committee has not attempted to reach such payments.”
Yet, as the Survey results suggest, executives are indeed significantly worried about such issues and compliance dollars are disproportionately spent on such issues.
Bribes, the reason Congress passed the FCPA in 1977, was identified as a “significant” risk by only 27% of Survey respondents.
Final statistic of note. On voluntary disclosure, the Survey states as follows.
“Executives were asked whether they thought that if an executive in their industry (not specifically in their own company) uncovered a significant violation of the company’s anti-corruption policy, they would report it to the SEC or the DOJ. Executives were divided on how they thought the typical executive in their industry would respond, with 36 percent saying it was very likely that an executive would report such a violation, 39 percent thinking it was somewhat likely, and 25 percent saying it was not likely. Only 27 percent saw significant benefits in self-reporting violations, while an additional 43 percent saw some benefits.”
*****
A good weekend to all.
Who Commits Fraud?
That is the question KPMG addresses in this recent report “Who Is The Typical Fraudster?” The study seeks to “identify patterns among individuals who have committed acts of fraud” and is based on research from “348 actual fraud investigations conducted by KPMG member firms in 69 countries.” Although not FCPA specific, the KPMG report identifies several fraud trends and indicators relevant to FCPA compliance.
The KPMG report notes that “typically, a fraudster is perceived as someone who is greedy and deceitful by nature,” however KPMG’s analysis found that “many fraudsters work within entities for several years without committing any fraud, before an influencing factor – financial worries, job dissatisfaction, aggressive targets, or simply an opportunity to commit fraud – tips the balance.”
According to the study, the “typical fraudster” is between the ages of 36 and 45, followed next by individuals between 46 and 55 years old. In terms of gender, men are the more likely perpetrators of detected fraud. According to KPMG, “the survey’s finding that men commit more fraud than women seems a reflection on the gender make-up of companies generally” and the “gender gap in fraud perpetration may reflect women’s under-representation in senior management positions and, as a consequence, fewer opportunities to commit fraud.”
In terms of job function, the KPMG report finds that people most often entrusted with a company’s sensitive information are able to override controls and thus are statistically more likely to become perpetrators. The report found that “most people involved in committing fraud work in the finance function” followed by those in the “chief executive’s / managing director’s office,” followed by those in “operations and sales.”
Other findings of note from the KPMG report include the following.
“One of the most significant findings of this survey is the very large increase in cases involving the exploitation of weak internal controls by fraudsters – up from 49 percent in 2007 to 74 percent in 2011. The difficult economic climate may be partially to blame. Tighter budgets are forcing some companies to cut costs in their control environments. Less robust controls, and fewer resources to monitor controls, allow for greater exploitation by fraudsters. Although necessary to preserve profits, such cost cutting should be balanced with effective risk management.”
“Many frauds continue to be exposed by formal or informal whistleblowing mechanisms. In 2007, companies were alerted to fraud by whistleblowers in one-quarter of cases, with complaints coming from customers or suppliers accounting for a further 13 percent. In 2011, formal internal whistleblower reports accounted for 10 percent of detections while anonymous tip-offs were responsible for uncovering 14 percent of frauds. A further 8 percent of frauds were identified due to customer or supplier complaints while 6 percent came in response to issues raised by third parties, including banks, tax authorities, regulators, competitors, or investors. That one in seven frauds is now discovered by chance puts question marks over the effectiveness of controls and management review at detecting and preventing fraud. […] The upshot is that companies seem to depend increasingly on the good conscience of staff or third parties, on accidental discovery or, in a few cases, on confessions, to identify potential fraud.”
“The number of fraud cases preceded by a red flags rose to 56 percent of cases in 2011, from 45 percent in 2007. However, instances where action was taken following the initial red flag fell massively. Just 6 percent of initial red flags were acted on in the 2011 analysis, compared with almost one-quarter (24 percent) in 2007. Companies are failing to read and to act quickly on the warning signs. Ignored red flags are a license for perpetrators to carry on operating and a missed opportunity for the business to detect or prevent fraud and to reduce losses and associated costs.”
“Fraud now takes longer to detect – up from an average 2.9 years from inception to detection in 2007 to 3.4 years in the 2011 analysis.” “In Asia […] the duration of fraud prior to detection is longest – on average five years – with 16 percent of frauds going undetected for ten years or more. This is possibly because employees in Asia tend not to challenge their superiors or to rock the boat as much as in Western Europe or North America …”.
Compliance Certificates
In relation to the U.K. Bribery Act’s so-called adequate procedures defense, how does a company know whether it has adopted adequate procedures so that it can avail itself of the defense should its conduct come under scrutiny? It is a darn good question.
Last week, thebriberyact.com (see here) had a post regarding an adequate procedures certificate. The post profiled a recent speech by Richard Alderman (Director of the U.K. Serious Fraud Office) on the issue of a lawyer’s certificate for adequate procedures. As detailed in the post, Alderman stated as follows. “We know, for example, that some companies believe that all they need is a certificate from a firm of lawyers that they have adequate procedures. We hear about this. We hear as well that the company is not prepared to pay very much for this and expects a certificate of adequate procedures for its worldwide enterprise under say £25,000. This will not impress us very much. This does not mean that we expect companies to spend millions of pounds on this. What we do expect though is a proportionate approach by companies focussing on the key risks and on what they are doing in order to be able to combat those risks. This is what companies should be doing anyway. Indeed some companies have told us that this is a valuable exercise for them for all sorts of reasons that they should have carried out before. A company that does this but which finds problems will receive very sympathetic treatment at the SFO. A company that closes its mind to the issues while perhaps having some veneer of paper procedures will receive different treatment.”
One of the FCPA reform proposals under consideration – and a reform proposal I support (see here and here for prior posts) – is creation of a compliance defense. If enacted, the same issue will arise as under the U.K. Bribery Act – how does a company know whether it has adopted sufficient measures so that it can avail itself of the defense should its conduct come under scrutiny?
Is a compliance certificate the answer?
In Chile, the answer is yes. As detailed in this prior “Compliance Defense Around the World” post, Chile is one of several OECD Anti-Bribery Convention countries to incorporate compliance defense principles into its “FCPA-like” law.
Under Chilean law: in order for a legal person to be held responsible for a foreign bribery offence, the following “three cumulative requirements” must be satisfied: (1) the offence must be committed by a person acting as a representative, director or manager, a person exercising powers of administration or supervision, or a person under the “direction or supervision” of one of the aforementioned persons; (2) the offence must be committed for the direct and immediate benefit or interest of the legal entity. No offence is committed where the natural person commits the offence exclusively in his/her own interest or in the interest of a third party; and (3) the offence must have been made possible as a consequence of a failure of the legal entity to comply with its duties of management and supervision. An entity will have failed to comply with its duties if it violates the obligation to implement a model for the prevention of offences, or when having implemented the model, it was insufficient.”
As to the final element, the OECD report states as follows. “The final cumulative requirement for responsibility stresses that the offence must have been made possible as a consequence of the failure of the legal person to comply with its duties of administration and supervision. The entity will have failed to comply with its duties if it violated the obligation to implement a model for the prevention of offences, or when having implemented the model, the latter was insufficient. It shall be considered that the functions of direction and supervision have been met if, before the commission of the offense, the legal person had adopted and implemented organization, administration and supervision models, pursuant to the following article, to prevent such offenses as the one committed.”
The minimum features of a prevention system under the law are as follows: identify the different activities or processes of the entity, whether habitual or sporadic, in whose context the risk of commission of the offences emerges or increases; establish protocols, rules and procedures that permit persons involved in above-mentioned activities or processes to program and implement their tasks or functions in a manner that prevents the commission of the indicated offences; identify procedures for the administration and auditing that allow the entity to impede their use in the listed offences; establish internal administrative sanctions, as well as procedures for reporting or pursuing pecuniary responsibility against persons who violate the prevention system; introduce the above-mentioned duties, prohibitions and sanctions into the internal regulations of the legal person, and ensure that they are known by all persons bound to apply it (workers, employees, and service providers).
The OECD report states – as to the minimum requirements as follows. “It also aims to introduce a system of self-regulation by companies. Having a code of conduct on paper will not be sufficient to avoid responsibility. If prosecutors can prove that the code does not meet the minimum requirements of or that it is not implemented, the company can be responsible for the offence.” Under Chilean law, “the failure to comply with duties of management and supervision is an element of the offence rather than a defence. Therefore the burden of proof lies on prosecutors, i.e. it will be up to prosecutors to prove that the entity failed to comply with its duties of management and supervision.” The OECD report notes as follows. “This will require prosecutors to prove that the company failed in the design and/or implementation of the offense prevention model including why, in the circumstances, the prevention model was insufficient. This would appear to also require the prosecutor to establish that this failure made perpetration of the offence possible.”
Chilean law sets forth a detailed process by which legal persons are able to undergo a certification process on the existence and relevance of their organizational model. The OECD report states as follows. “Certification will confirm that the offence-prevention model complies with the minimum requirements [set forth above], taking into account the characteristics of the legal person. The certification is valid as long as the situation of the company does not change. Certification will be carried out by private institutions which have been authorised by public agencies to undertake this role. Two points should be noted. The first is that certification will not, by itself, avoid responsibility, since it will remain possible to convict a legal person if it can be proved that, notwithstanding the certification, the preventive model did not meet the minimum requirements [set forth above]; and/or that the model was not implemented. The second point to note is that, pursuant to [the Chilean law], private institutions carrying our certification will be carrying out public functions, which means that they will be criminally responsible in the event of a failure to act properly in the execution of those functions. The sole function of public agencies will be to authorise institutions to carry out these functions, and to keep record of certifications.”
What do you think? Is the Chilean certification process the answer? What are the pros and cons of such an approach? If anyone can direct me to Chilean counsel knowledgeable about this certification process or the “private institutions” authorized to issue such certifications, please send me an e-mail so that I can inquire and report back any findings.
If the FCPA were amended to include a compliance defense, would Chile’s certification approach work here in the U.S.?
For starters, it is useful to observe that the DOJ is already handing out compliance certificates in at least two respects – even if not formally called compliance certificates.
First, the FCPA’s Opinion Release Procedure results in the DOJ issuing – for all practical purposes – a compliance certificate in that the DOJ opines whether a proposed course of conduct, based on the requestor’s disclosed information and various representations, complies with the FCPA. Pursuant to the governing regulations (see here), “there shall be a rebuttable presumption that a requestor’s conduct, which is specified in a request, and for which the Attorney General has issued an opinion that such conduct is in conformity with the Department’s present enforcement policy, is in compliance with those provisions of the FCPA.”
Second, every NPA or DPA contains a clause stating that the DOJ will not bring an enforcement action if the company complies with the undertakings set forth in the agreement – including an appendix which sets forth various compliance obligations. (See here for the recent Armor Holdings NPA). As with the FCPA Release Procedure, the term compliance certificate is lacking, but in substance that is likewise the end result.
That the DOJ is already issuing “compliance certificates” makes the DOJ’s firm opposition to an FCPA compliance defense (see here for more) all the more curious – and all the more contradictory.
The Demand Side Of Bribery
This new era of FCPA enforcement has resulted in many things, including an increase in quality legal scholarship devoted to the FCPA and related topics.
Case in point, Joseph Yockey’s recently released scholarship “Solicitation, Extortion, and the FCPA” (see here for the download). Yockey (here – Associate Professor at the University of Iowa College of Law) provides the following abstract.
“The U.S. Foreign Corrupt Practices Act (FCPA) prohibits firms from paying bribes to foreign officials to obtain or retain business. It is one of the most significant and feared statutes for companies operating abroad. FCPA enforcement has never been higher and nine-figure monetary penalties are not uncommon. This makes the implementation of robust FCPA compliance programs of paramount importance. Unfortunately, regardless of whether they have compliance measures in place, many firms report that they face bribe requests and extortionate threats from foreign public officials on a daily basis. The implications of these demand-side pressures have gone largely unexplored in the FCPA context. This Article helps fill that gap. First, I describe the nature and frequency of bribe solicitation and extortion to illustrate the scope of the problem and the costs it imposes on firms and other market participants. I then argue that current FCPA enforcement policy in cases of solicitation and extortion raises several unique corporate governance and compliance challenges, and ultimately poses a risk of overdeterrence. Though these concerns can be partially addressed through enhanced statutory guidance, I conclude by urging regulators to shift some of their focus from bribe-paying firms in order to directly target bribe-seeking public officials. Confronting the market for bribe demands in this way will help reduce corruption in general while also allowing employees and agents to spend less time worrying about how to respond to bribe requests and more time on legitimate, value-enhancing transactions.”
Yockey’s article also nicely touches upon other topics as the below excerpts demonstrate.
“As regulators continue to push the boundaries of statutory interpretation firms, find it difficult to predict ex ante whether conduct that appears permissible under the FCPA‟s terms will later expose them to sanction (or the threat of sanction). Left unchecked, this hinders efforts to design monitoring programs that will prevent illegal payments without also deterring employees from pursuing legitimate transactions or engaging in socially desirable risk-taking.”
“Several factors explain the recent resurgence in FCPA enforcement. […] A more cynical explanation for the government‟s focus on the FCPA is based on the “revolving door” between government and private sector employment. The rise in FCPA enforcement has produced a cottage industry of FCPA experts, including lawyers, accountants, and consultants at prestigious firms, which DOJ and SEC personnel often join after leaving their federal jobs for considerably higher compensation.”
“Another factor adding to the compliance challenges faced by firms concerns the way in which the DOJ and SEC have recently interpreted and applied several of the FCPA’s key provisions. Regulators have become more expansive in their interpretation of the FCPA anti-bribery provisions and considerably narrower in their assessment of the statute’s exceptions and defenses. Much of the trouble in this regard comes because the government’s authority under the FCPA is not as broad as the recent resurgence in enforcement activity might suggest.”
“Whether there is truly an unfair balance of power between regulators and corporate defendants [given the prevalence in which FCPA enforcement actions are resolved via non-prosecution or deferred prosecution agreements] is outside the scope of this paper. What appears undeniable, however, is that an absence of judicial review on key aspects of the FCPA makes it considerably more difficult for firms to design compliance programs that efficiently separate lawful but aggressive competitive activity from conduct that clearly violates the statute.”