FCPA Enforcement Critic And Reform Advocate Selected As New DOJ Fraud Section Chief

Last week, the DOJ announced Andrew Weissmann has been selected as the Chief of the Criminal Division’s Fraud Section.

In recent years, Weissmann has been a vocal advocate of Foreign Corrupt Practices Act reform and more broadly, reforming corporate criminal liability principles.

In October 2010, Weissmann was the lead author of “Restoring Balance:  Proposed Amendments to the FCPA.”  Written on behalf of the U.S. Chamber Institute for Legal Reform, “Restoring Balance,” lead to a Senate FCPA reform hearing in November 2010, and thereafter, a House FCPA reform hearing in June 2011.

Here is what Weissmann wrote in “Restoring Balance”.

“In spite of this rise in enforcement and investigatory action, judicial oversight and rulings on the meaning of the provisions of the FCPA is still minimal. Commercial organizations are rarely positioned to litigate an FCPA enforcement action to its conclusion, and the risk of serious jail time for individual defendants has led most to seek favorable terms from the government rather than face the expense and uncertainty of a trial. Thus, the primary statutory interpretive function is still being performed almost exclusively by the DOJ Fraud Section and the SEC. Notably, these enforcement agencies have been increasingly aggressive in their reading of the law. The DOJ has expressed its approach primarily through its opinion releases, but also in its decisions as to what FCPA enforcement actions to pursue. Many commentators have expressed concern that the DOJ effectively serves as both prosecutor and judge in the FCPA context, because it both brings FCPA charges and effectively controls the disposition of the FCPA cases it initiates.”

Using phrases such as “how far the DOJ has pressed the limits of enforcement,” “DOJ’s aggressive pursuit” of companies as “indication of how far the DOJ is willing to expand the scope of FCPA enforcement,” and “the highly aggressive stance the DOJ is taking to expand the FCPA net beyond its borders,” Weissmann stated:

“The current FCPA enforcement environment has been costly to business. Businesses enmeshed in a fullblown FCPA investigation conducted by the U.S. government have and will continue to spend enormous sums on legal fees, forensic accounting, and other investigative costs before they are even confronted with a fine or penalty, which, as noted, can range into the tens or hundreds of millions. In fact, one noteworthy innovation in FCPA enforcement policy has been the effective outsourcing of investigations by the government to the private sector, by having companies suspected of FCPA violations shoulder the cost of uncovering such violations themselves through extensive internal investigations.

From the government’s standpoint, it is the best of both worlds. The costs of investigating FCPA violations are borne by the company and any resulting fines or penalties accrue entirely to the government. For businesses, this arrangement means having to expend significant sums on an investigation based solely on allegations of wrongdoing and, if violations are found, without any guarantee that the business will receive cooperation credit for conducting an investigation.”

Elsewhere in “Restoring Balance,” Weissmann wrote:

“[T]he FCPA should be modified to make clear what is and what is not a violation. The statute should take into account the realities that confront businesses that operate in countries with endemic corruption (e.g., Russia, which is consistently ranked by Transparency International as among the most corrupt in the world) or in countries where many companies are state-owned (e.g., China) and it therefore may not be immediately apparent whether an individual is considered a “foreign official” within the meaning of the act. As the U.S. government has not prohibited U.S. companies from engaging in business in such countries, a company that chooses to engage in such business faces unique hurdles. The FCPA should incentivize the company to establish compliance systems that will actively discourage and detect bribery, but should also permit companies that maintain such effective systems to avail themselves of an affirmative defense to charges of FCPA violations. This is so because in such countries even if companies have strong compliance systems in place, a third-party vendor or errant employee may be tempted to engage in acts that violate the business’s explicit anti-bribery policies. It is unfair to hold a business criminally liable for behavior that was neither sanctioned by or known to the business.

The imposition of criminal liability in such a situation does nothing to further the goals of the FCPA; it merely creates the illusion that the problem of bribery is being addressed, while the parties that actually engaged in bribery often continue on, undeterred and unpunished. The FCPA should instead encourage businesses to be vigilant and compliant. For this reason, and given the current state of enforcement, the FCPA is ripe for much needed clarification and reform through improvements to the existing statute. Such improvements, which are best suited for Congressional action, are aimed at providing more certainty to the business community when trying to comply with the FCPA, while promoting efficiency and enhancing public confidence in the integrity of the free market system as well as the underlying principles of our criminal justice system.”

Weissmann also testified, on behalf of the U.S. Chamber, at the November 2010 Senate hearing.  In his written testimony, Weissmann stated:

“The FCPA had been tailored to balance various competing interests, but that balance has been altered, at times, by aggressive application and interpretations of the statute by the government. Instead of serving the original intent of the statute, which was to punish companies that participate in foreign bribery, actions taken under more expansive interpretations of the statute may ultimately punish corporations whose connection to improper acts is attenuated at best and nonexistent at worst.

The result is that the FCPA, as it currently written and implemented, leaves corporations vulnerable to civil and criminal penalties for a wide variety of conduct that is in many cases beyond their control and sometimes even their knowledge. It also exposes businesses to predatory follow-on civil suits that often get filed in the wake of a FCPA enforcement action. In fact, there is reason to believe that the FCPA has made U.S. businesses less competitive than their foreign counterparts who do not have significant FCPA exposure.”

In concluding his written testimony, Weissmann stated:

“The recent dramatic increase in FCPA enforcement, coupled with the lack of judicial oversight, has created significant uncertainty among the American business community about the scope of the statute. In addition, some of the enforcement actions brought by the SEC and DOJ are not commensurate with the original goals of the FCPA, in that they fail to reach the true bad actors and instead assign criminal liability to corporate entities with attenuated or non-existent connections to potential FCPA violations.”

As reflected in this transcript, during the hearing Weissmann stated:

“One of the reasons it is important to have a clearer statute, particularly in the FCPA arena, is that corporations cannot typically take the risk of going to trial and, thus, there is a dearth of legal rulings on the provisions of the FCPA as it applies to organizations. Thus, the government’s interpretation can be the first and the last word on the scope of the statute as it applies to a company. The lack of judicial oversight, expansive government interpretation of the FCPA, and the increased enforcement that you heard about from [the DOJ witness] have led to considerable concern and uncertainty about how and when the FCPA applies to overseas business activities.”

During the hearing, Senator Arlen Specter asked: “overall, do you think that the act is fairly well balanced and fairly well enforced or too tough?”

Weissmann responded:

“I think there is no question that many of the cases that were brought up today, such as Siemens, fall far, far, far into the—that it is amply warranted for the application of the statute. The problem is that every company in America and many companies overseas worry about the statute daily. And so regardless of what the Department of Justice is doing, people think about the statute and could their conduct fall on one side of it versus the other and will they be subject to an investigation. So it is a difficult question to answer, because I have seen many prosecutions where you say, of course, that seems like a just result and should have been warranted, but there are many companies that are hurt by the ambiguities in the statute and what I think is the over-breadth of some of its provisions on a daily basis.”

Beyond the FCPA, Weissmann has also been a vocal advocate of reforming corporate criminal liability principles.

In “Rethinking Corporate Criminal Liability,” 82 IND. L.J. 411, 414 (2007), Weissmann challenged traditional notions of corporate criminal liability and argued that when the DOJ “seeks to charge a corporation as a defendant, the government should bear the burden of establishing as an additional element that the corporation failed to have reasonably effective policies and procedures to prevent the conduct.”

DOJ Enforcement Of The FCPA – Year In Review

This previous post highlighted facts and figures from SEC enforcement of the FCPA in 2014.

This post highlights facts and figures from DOJ FCPA enforcement in 2014.

(See here for a similar post from 2013, here for a similar post from 2012, here for a similar post from 2011, and here from 2010).

 

Settlement Amounts and Specifics

In 2014, the DOJ brought 7 corporate FCPA enforcement actions.  By comparision, in 2013 the DOJ brought 7 corporate enforcement action; in 2012 the DOJ brought 9 corporate FCPA enforcement actions; in 2011 the DOJ brought 11 corporate enforcement actions; and in 2010 the DOJ brought 17 corporate enforcement actions.  (Note:  these figures  use the “core” approach to FCPA statistics – see here for the prior post – an approach also endorsed by the DOJ – see here).

In the 7 corporate FCPA enforcement actions from 2014, the DOJ collected approximately $1.25 billion in criminal fines, an all-time record in terms of yearly FCPA settlement amounts. By way of comparison, in the 7 corporate FCPA enforcement actions from 2013, the DOJ collected approximately $420 million in criminal fines; in 2012, the DOJ collected approximately $142 million in criminal fines; in 2011, the DOJ collected approximately $355 million in criminal fines ($504 million including the $149 million forfeiture in the Jeffrey Tesler individual enforcement action); and in 2010, the DOJ collected approximately $870 million in criminal fines.

DOJ FCPA enforcement in 2014 ranged from $772 million in criminal fines (Alstom) to $14 million in criminal fines (Dallas Airmotive).  3 FCPA enforcement actions in 2014 were DOJ only (Alstom, Dallas Airmotive and Marubeni).

Of the approximate $1.25 billion the DOJ collected in 2014 corporate FCPA enforcement actions, $772 million (62%) was in one enforcement action (Alstom) and $981 million (78%) was in two enforcement actions (Alstom and Alcoa).

In 4 of 6 corporate FCPA enforcement actions where an analysis was possible, the DOJ agreed to a criminal fine below the minimum range suggested by the sentencing guidelines.  In these 4 actions, the average was approximately 29% below the minimum guidelines range and the distribution range was 9% below the minimum guidelines range (Avon) to 53% below the minimum guidelines range (Alcoa).  In 2 corporate FCPA enforcement actions in 2014 (Alstom and Marubeni), the company paid a criminal fine within the guidelines range.

[Note – why are only 6 of the 7 corporate enforcement actions included in the above analysis? 1 corporate enforcement action (Bio-Rad) was resolved via an NPA and the DOJ does not set forth a guidelines range in NPAs]

Corporate vs. Individual Prosecutions

How many corporate FCPA enforcement actions in 2014 involved related individual prosecutions of company employees by the DOJ (recognizing that such prosecutions may be forthcoming in the future)?  Of the 7 corporate DOJ enforcement actions in 2014, 1 (14%) has thus far resulted in related DOJ prosecutions of company employees. This action was the Alstom action (in which the DOJ alleged conduct concerning Indonesia, Saudi Arabia, Egypt, the Bahamas, and Taiwan) and the related individual prosecutions related only to the Indonesia conduct alleged by the DOJ.

The DOJ brought or announced 10 individual FCPA enforcement actions in 2014 in 3 core actions (5 individuals associated with DF Group in connection with Indian mining licenses, 2 individuals associated with Direct Access Partners and 3 individuals associated with PetroTiger).

Stay tuned for future posts specifically about DOJ and SEC individual FCPA enforcement actions.

NPAs / DPAs

What about non-prosecution and deferred prosecution agreements vs. old fashioned law enforcement (i.e. if a company committed a crime the DOJ charged it and if the company did not commit a crime the DOJ did not charge it)?  In 2014, 5 of the 7 (71%) corporate enforcement actions included an NPA or DPA.  Marubeni and Alcoa were plea agreements only. [Note, the Alstom enforcement action involved two plea agreements and two DPAs; the Avon enforcement action involved  a plea agreement and DPA; and the HP enforcement action involved a plea agreement, DPA and NPA].

By way of comparison, in 2013, 100% of corporate DOJ enforcement actions involved either an NPA or DPA; in 2012 100% of corporate DOJ enforcement actions involved either an NPA or a DPA;  in 2011 82% of corporate DOJ enforcement actions involved either an NPA or DPA; and in 2010 94% of corporate DOJ enforcement actions involved either an NPA or DPA.

Since 2010, 86% of corporate DOJ enforcement actions have involved either an NPA or DPA.

Voluntary Disclosures

Of the 7 corporate DOJ FCPA enforcement actions in 2014, 2 enforcement actions (29%) were the result of corporate voluntary disclosures (Avon and Bio-Rad),  3 enforcement actions (43%) were the result of previous foreign law enforcement investigations or related thereto (Alstom, Marubeni, and HP), 1 enforcement action was related to a previous FCPA enforcement action (Dallas Airmotive) and 1 enforcement action was the result of civil litigation (Alcoa).

By way of comparison, in 2013 57% of corporate FCPA enforcement actions were the result of corporate voluntary disclosures or the direct result of a related voluntary disclosure; in 2012, 78% of corporate FCPA enforcement actions were the result of corporate voluntary disclosures or casually related to previous corporate voluntary disclosures; in 2011, 73% of corporate FCPA enforcement actions were the result of corporate voluntary disclosures.

Monitors

Of the 7 corporate DOJ FCPA enforcement actions in 2014, 1 (14%) enforcement action (Avon) resulted in a corporate monitor. By way of comparison, of the 7 corporate DOJ FCPA enforcement actions in 2013, 4 enforcement actions (57%) involved a monitor; of the 9 corporate DOJ FCPA enforcement actions in 2012, 3 enforcement actions (33%) involved a monitor; of the 11 corporate DOJ FCPA enforcement actions in 2011, 1 enforcement action (9%) involved a corporate monitor; of the 17 corporate DOJ enforcement actions in 2010, 7 enforcement actions (41%) involved a corporate monitor.

This remainder of this post provides an overview of corporate DOJ FCPA enforcement in 2014.

Alstom and Related Entities (December 22nd).

See here and here for prior posts

Charges:  As to Alstom S.A., violation of the FCPA’s books and records and internal controls provisions.  As to Alstom Network Schweiz AG, conspiracy to violate the FCPA’s anti-bribery provisions.  As to Alstom Power Inc., conspiracy to violate the FCPA’s anti-bribery provisions.  As to Alstom Grid Inc., conspiracy to violate the FCPA’s anti-bribery provisions.

Resolution Vehicle:  As to Alstom and Alstom Network Schweiz, plea agreements.  As to Alstom Power and Alstom Grid, DPAs.

Guidelines Range:  As to Alstom $532.8 million to $1.065 billion

Penalty:  As to Alstom, $772 million (the other entities were not required to pay separate penalties).

Disclosure:  The enforcement action presumably originated from a prior 2011 Swiss enforcement action (see here and here).

Monitor:  No

Individuals Charged:  Yes (as to the Indonesia conduct – see here).

Avon Entities (December 17th)

See here and here for prior posts

Charges:  As to Avon China, conspiracy to violate the FCPA’s books and records provisions.  As to Avon Products, conspiracy to violate the FCPA’s books and records provisions and violation of the FCPA’s internal controls provisions.

Resolution Vehicle:  As to Avon China, a plea agreement; as to Avon Products a DPA.

Guidelines Range:  As to Avon China, $73.9 million to $147.9 million; as to Avon Products, $84.6 million to $169.1 million.

Penalty:  As to Avon China, $67.6 million; as to Avon Products $67.6 million but the Avon China penalty was deducted from this amount.

Disclosure:  Voluntary Disclosure.

Monitor:  Yes

Individuals Charged:  No

Dallas Airmotive (December 10th)

See here for the prior post

Charges:  Conspiracy to violate the FCPA’s anti-bribery provisions and violation of the FCPA’s anti-bribery provisions.

Resolution Vehicle:  DPA

Guidelines Range:  $17.5 million to $35 million

Penalty:  $14 million

Disclosure:  The enforcement action appears to be casually related to a prior enforcement action against BizJet International and certain of its executives

Monitor:  No

Individuals Charged:  No

Bio-Rad (November 3rd)

See here and here for prior posts

Charges:  Not applicable

Resolution Vehicle:  NPA

Guidelines Range:  Not set forth in the NPA

Penalty:  $14.4 million

Disclosure:  Voluntary Disclosure

Monitor:  No

Individuals Charged:  No

HP Related Entities (April 9th)

See here for the prior post

Charges:  As to HP Russia – (i) conspiracy to violate the FCPA’s anti-bribery provisions and books and records and internal controls provisions; (ii) one count of violating the FCPA’s anti-bribery provisions; (iii) one count of violating the FCPA’s internal controls provisions; and (iv) one count of violating the FCPA’s books and records provisions; As to HP Poland – violation of the FCPA’s books and records and internal controls provisions; As to HP Mexico – not applicable.

Resolution Vehicle:  As to HP Russia, a plea agreement; as to HP Poland a DPA; as to HP Mexico an NPA.

Guidelines Range:  As to HP Russia $87 million to $174 million; as to HP Poland $19.3 million to $38.6 million; as to HP Mexico not specified in the NPA.

Penalty:  As to HP Russia $58.8 million; as to HP Poland $15.5 million; as to HP Mexico $2.5 million.

Disclosure:  The enforcement action appears to have been the result of a previous German and Russian law enforcement investigation (see here for the prior post).

Monitor:  No

Individuals Charged:  No

Marubeni (March 19th)

See here for the prior post

Charges:  Conspiracy to violate the FCPA’s anti-bribery provisions and 7 substantive FCPA anti-bribery violations

Resolution Vehicle:  Criminal information resolved via a plea agreement

Guidelines Range:  $63.7 million to $127.4 million

Penalty:  $88 million

Disclosure:  Related to the April 2013 FCPA enforcement action against various current and former employees of Alstom

Monitor:  No

Individuals Charged:  No

Alcoa (January 9th)

See here for the prior post

Charges:  One count of violating the FCPA’s anti-bribery provisions.

Resolution Vehicle:  Criminal information against Alcoa World Alumina LLC resolved via a plea agreement.

Guidelines Range:  $446 million – $892 million.

Penalty:  $209 million (plus administrative forfeiture of $14 million)

Disclosure:  A 2008 civil lawsuit between Alba and Alcoa.

Monitor:  No

Individuals Charged:  No

Assistant Attorney General Caldwell’s Unconvincing Defense Of DPAs / NPAs

As noted in this Global Investigations Review article, at a recent event in Paris in connection with the release of the OECD’s Foreign Bribery Report, Assistant Attorney General Lisa Caldwell defended the DOJ’s frequent use of DPAs and NPAs to resolve Foreign Corrupt Practices Act enforcement actions.  As stated in the article:

“Caldwell defended the Department of Justice’s (DoJ) reliance on settlements in FCPA cases. “In the United States we are often able to achieve much more through a settlement – a negotiated settlement – than we could achieve following conviction at trial,” she said. “We are able to impose reforms, impose compliance controls, and impose all sorts of behavioural change that a court would never be able to impose following even a conviction at trial.” Since 2009 over 50 companies have settled with the DoJ for alleged FCPA violations. Caldwell told the audience in Paris: “Companies cannot be sent to jail, so all a court can do is say you will pay ‘x’. We can say: ‘you will also have a monitor and will do all sorts of other things for the next five years, and if you don’t do them for the next five years then you can still be prosecuted’.” “In the United States system at least it is a more powerful tool than actually going to trial,” she said.

Post-enforcement action compliance obligations typically last 2-3 years, not 5 as Caldwell suggested.  Regardless, Caldwell’s defense of DPAs and NPAs is just as unconvincing as former Assistant Attorney General Lanny Breuer’s defense of DPAs and DPAs in September 2012 (see here for the prior post).

For starters, the function of the DOJ’s criminal division, as stated on its website, is to “serve the public interest through the enforcement of criminal statutes.”  Whether the function of the DOJ is, in addition, to “impose reform, impose compliance controls, and all impose all sorts of behavioral changes” on a business organization is a point of much disagreement. (See, e.g., “Prosecutors in the Boardroom“).

Regardless of one’s thoughts on whether the DOJ’s criminal division ought to play the role of a quasi-regulator, the notion that the DOJ is powerless to effect corporate change through old-fashion law enforcement (that is enforcing the FCPA without use of NPAs and DPAs) is plainly false.

For instance, the Siemens enforcement action did not involve the use of an NPA or DPA.  Yet, it is clear from the plea agreement, sentencing memorandum, and judgment that the DOJ was able to obtain the reforms, compliance controls and behavioral changes it wanted.  More recently in 2014, the Alcoa enforcement action was resolved without an NPA or DPA.  The plea agreement and judgment in the case (see here and here) again demonstrate that the DOJ was again able to obtain the reform, compliance controls and behavioral changes it wanted.

To return to Caldwell’s words, perhaps NPAs and DPAs are indeed a more powerful tool in FCPA enforcement actions than actually going to trial, but then again the DOJ is 0-2 in FCPA history when put to its ultimate burden of proof by a business organization in an FCPA enforcement action.

Just because the DOJ may have difficulty proving FCPA violations against business organizations and just because the DOJ is troubled – with good reason – by traditional notions of corporate criminal liability, does not mean the DOJ needs to continue to champion the alternate universe of NPAs and DPAs it has created.

*****

To read a different perspective on Caldwell’s recent remarks, see here from Tom Fox at the FCPA Compliance and Ethics Blog.

Recent DOJ Speeches

Previous posts here and here highlighted recent speeches by top Department of Justice officials on topics relevant to the Foreign Corrupt Practices Act.

This post highlights additional recent speeches by Assistant Attorney General for the Criminal Division Leslie Caldwell on October 1st and by Principal Deputy Assistant Attorney General for the Criminal Division Marshall Miller on October 7th.  The speeches are near carbon-copies of each other, but both are excerpted below in one space for ease of reference.  Moreover, Caldwell’s speech further expounds on cooperation issues previously articulated in Miller’s September 17th speech.

Before excerpting the speeches, it is worth noting that the DOJ officials (as prior DOJ officials have in the past) made several important acknowledgments relevant to the difficulties of FCPA compliance and in support of the policy rationales for an FCPA compliance defense.  (See here for the article “Revisiting a Foreign Corrupt Practices Act Compliance Defense”).  In pertinent part, the DOJ officials stated:

“While the Justice Department is often the last line of defense against fraud and corruption, all of you [compliance professionals] are the first.  Criminal prosecutions can and do deter future bad behavior, but they most often serve as an after-the-fact sanction for misconduct.  Your collective work is designed to ensure corporate compliance and ethical practices from the outset.”

“[W]e recognize that even with proper support of a compliance program by management, perfect compliance in this increasingly global economy is incredibly difficult.  Compliance departments are asked to monitor business units that are spread about the globe.”

“Every company hires human beings who, when they are in a tough and maybe unfamiliar situation with no clear guidance about what is expected, will sometimes choose the wrong path.  And that becomes even harder when they are operating in countries with business cultures very different from their own.”

“Corporations do not act, but for the actions of individuals.  In all but a few cases, an individual or group of individuals is responsible for the corporation’s criminal conduct.”

“Compliance must be incentivized.”

“Although increasingly rare in this day and age – more than a decade after the passage of the Sarbanes Oxley Act – we are still encountering prominent companies with no real compliance programs. Hard to believe, but true.”

“[E]ven companies with strong compliance programs can and do detect and report criminal misconduct by employees.”

“While the Justice Department is often the last line of defense against fraud and corruption, all of you who work in compliance are the first. Criminal prosecutions can and do deter future bad behavior, but your work can prevent that conduct before it happens.”

For additional writing and videos on many of the same points discussed in the DOJ speeches see:

Assistant Attorney General Caldwell’s October 1st Speech

“While the Justice Department is often the last line of defense against fraud and corruption, all of you are the first. Criminal prosecutions can and do deter future bad behavior, but they most often serve as an after-the fact sanction for misconduct.

Your collective work is designed to ensure corporate compliance and ethical practices from the outset. The importance of your work cannot be overstated: it serves to protect the integrity of our public markets, the country’s financial systems, our intellectual property, the retirement accounts of our hardworking citizens, and our taxpayer dollars used to fund healthcare programs and government and military contracts.

A very large part of the mission of the Criminal Division is fighting major corporate fraud and corruption. Our Fraud Section employs approximately 100 prosecutors who are experienced in investigating health care fraud, defense procurement fraud, securities and financial fraud, and violations of the Foreign Corrupt Practices Act.

Our Asset Forfeiture and Money Laundering Section investigates and prosecutes international money laundering and violations of U.S. sanctions laws, and it recovers the proceeds of foreign official corruption by kleptocrats.

Unfortunately, in our fraud, corruption, money laundering, and sanctions cases, we have seen too many failures of corporate compliance.

In this day and age – more than a decade after the Sarbanes-Oxley Act – we come across very few companies that do not have any compliance program. In fact, we have seen a marked improvement in compliance programs over the years. In years past, it was not uncommon to see companies with only rudimentary compliance programs.

That situation is illustrated by a case resolved just last year, involving Weatherford International, a Swiss oil services company that trades on the New York Stock Exchange. Three subsidiaries of Weatherford International pleaded guilty to violating the anti-bribery provisions of the Foreign Corrupt Practices Act and export controls violations.

Before 2008, the company had little more than a weak paper compliance program. The subsidiaries admitted that the company did not have a dedicated compliance officer or compliance personnel, did not conduct anti-corruption training, and did not have an effective system for investigating employee reporting of ethics and compliance violations. Weatherford companies paid $252 million in penalties and fines.

It is increasingly rare that we encounter circumstances in which a company has such a feeble compliance program. And I doubt that anyone in this audience works for a company like that, or you probably would not be here.

More often, we encounter companies with compliance programs that are strong on paper, but much weaker in practice.”

[…]

“Now, we recognize that even with proper support of a compliance program by management, perfect compliance in this increasingly global economy is incredibly difficult. Compliance departments are asked to monitor business units that are spread about the globe.

More than the geographic divide, however, there often are cultural divides from country-to-country that you must bridge.”

[…]

“There is no doubt that monitoring compliance on a global scale is a difficult, but difficulty cannot be used as an excuse to turn a blind eye to problematic business practices. Compliance programs must be put into place and—more importantly—communicated repeatedly and enforced properly throughout the entire organization.

The emphasis on compliance must be heard not only in the executive suites at headquarters, but wherever the company operates around the globe.

When considering criminal action against a company, one factor that the Justice Department evaluates is the company’s compliance program.

Under the department’s internal guidance, the Principles of Federal Prosecution of Business Organizations, prosecutors must consider “the existence and effectiveness of the corporation’s pre-existing compliance program.”

As all of you know, the United States Sentencing Guidelines also expressly include a company’s corporate compliance program as a factor in corporate sentencing in criminal cases.

There is, of course, no “off the rack” compliance program that can be installed at every company. Effective compliance programs must be tailored to the unique needs and risks faced by each company.

But there are hallmarks of good compliance programs. The department includes many of these in our non-prosecution agreements and deferred prosecution agreements, and I’d like to discuss them with you.

1. High-level commitment. A company must ensure that its directors and senior management provide strong, explicit, and visible commitment to its corporate compliance policy. Stated differently, and again, “tone from the top.”

This means that the importance of compliance should be communicated from the very top of the company. I once heard of a large company whose prominent CEO refused to put his signature on a company-wide communication announcing the company’s new compliance program.

When asked why not, he replied: “Because we don’t hire those kinds of people.” Well, he could not have been more wrong. Every company hires “those kinds of people.”

Every company hires human beings who, when they are in a tough and maybe unfamiliar situation with no clear guidance about what is expected, will sometimes choose the wrong path. And that becomes even harder when they are operating in countries with business cultures very different from our own.

2. Written Policies. A company should have a clearly articulated and visible corporate compliance policy memorialized in a written compliance code. Again, employees need to know what to do–or not do–when faced with a tough judgment call involving business ethics. Companies need to make that as easy as possible for their employees.

3. Periodic Risk-Based Review. A company should periodically evaluate these compliance codes on the basis of a risk assessment addressing the individual circumstances of the company. Companies change over time through natural growth, mergers, and acquisitions.

Compliance policies should be live organisms that also change and grow with the company. You are only as strong as your weakest flank.

I once represented a company that had an A+ compliance program. But then they acquired a Chinese subsidiary and for several years failed to communicate to their new—and then not-so new–Chinese employees the need for FCPA compliance.

The predictable result: the Chinese employees continued doing business in the way that was familiar to them. And the US parent found itself in deep violation of the FCPA.

4. Proper Oversight and Independence. A company should assign responsibility to senior executives for the implementation and oversight of the compliance program.

Those executives should have the authority to report directly to independent monitoring bodies, including internal audit and the Board of Directors, and should have autonomy from management. Compliance programs needed to be funded; they need to have resources.

And they need to have teeth and respect within the company. For years, Wall Street banks housed their compliance programs across the Hudson River, in New Jersey. They were out of sight, out of mind. They were underpaid. And nobody paid much attention to them.

Compliance programs need to have an appropriate stature within the company, or compliance will be the last thing on the mind of an employee tempted to engage in wrongdoing.

5. Training and Guidance. A company should implement mechanisms designed to ensure that its compliance code is effectively communicated to all directors, officers, employees. This means repeated communication, frequent and effective training, and an ability to provide guidance when issues arise.

And as I said before, employees should see that the importance of compliance is being communicated from the top—whether the CEO, the Board, the General Counsel, or some other very highly respected senior-level figure within the company.

6. Internal Reporting. A company should have an effective system for confidential, internal reporting of compliance violations. I know that many companies have multiple mechanisms, which is good.

7. Investigation. A company should establish an effective process with sufficient resources for responding to, investigating, and documenting allegations of violations. What this means on the ground will depend on the company. A sophisticated multi-national corporation obviously will be expected to have more resources devoted to compliance than a small regional company.

8. Enforcement and Discipline. A company should implement mechanisms designed to enforce its compliance code, including appropriately incentivizing compliance and disciplining violations.

And the response to a violation must be even-handed. Too often, we see situations where low level employees who may have implemented the bad conduct are fired, but their boss, who saw what they were doing and did nothing—and maybe even the directed the conduct—is left in place.

This should not happen. Not only from a department perspective, but from a business perspective. Leaving in place senior managers who sanction bad behavior sends a very wrong message about the company’s true commitment to compliance and ethics.

People watch what people do much more carefully than what they say. When it comes to compliance, you must both say and do.

9. Third-Party Relationships. A company should institute compliance requirements pertaining to the oversight of all agents and business partners.

I cannot emphasize strongly enough the need to sensitize third parties, like vendors, agents, and consultants, to the importance of not compliance.

And these partners need to understand that the company really expects its partners to be compliant. This often means more than just including a boilerplate paragraph in a contract in which the partner promises to comply with the law and company policies. It means warning, and even terminating, relationships with partners who fail to behave in a compliant manner.

10. Monitoring and Testing. A company should conduct periodic reviews and testing of its compliance code to improve its effectiveness in preventing and detecting violations. Kick the tires regularly. As I said, compliance programs must evolve with changes in the law, business practices, technology and culture.

As I said, there is no “one-size fits all” compliance program. But these are guideposts that we consider important to the success of a strong program.

And as important as the compliance program itself is implementation. When we investigate a case, we look at the messages about compliance that are given to employees.

More than just reading the paper program or the code of conduct, we look at what employees are told in their day-to-day work.

We are looking at e-mails, chats, and recorded phone calls. We are talking to witnesses about the messages they received from their supervisors and management – did they receive messages about compliance, or about making money at all costs.

And we examine the incentives that a company provides to encourage compliant behavior – or not. If a company is actually encouraging compliance, if its values are to be ethical and within the law, then that message must be conveyed to employees in a meaningful way. Otherwise, the Department of Justice will not view the compliance program as credible.

And sometimes, effective implementation of a compliance program means standing apart from the other companies in your industry. We have seen significant misconduct taking place throughout an industry.

But the excuse that “everyone else is doing it” didnd’t work in grade school, and it sure won’t work when federal agents come knocking at your door.”

[…]

“Effective compliance programs must be embedded in a company’s culture. And they need to be applied even in the face of misconduct by other companies in the same industry, even if that might mean a short-term competitive disadvantage.

A company’s executives can choose to rise above the rest — or race to the bottom. I am telling you that the Criminal Division will hold responsible companies and individuals that knowingly violate the law, no matter if the excuse is that “everyone” was doing it.

Now what should you do when your robust compliance program fails? Or, when it works, allowing you to discover criminal misconduct? I encourage you to conduct a thorough investigation and to disclose potentially criminal misconduct to the Justice Department.

When criminal misconduct is discovered, a critical factor in the department’s prosecutorial decision making is the extent and nature of the company’s cooperation.

The department’s Principles of Federal Prosecution of Business Organizations provides that prosecutors should consider “the corporation’s timely and voluntary disclosure of wrongdoing and its willingness to cooperate in the investigation of its agents.”

Now let me flesh out the often discussed, but sometimes poorly understood, concept of cooperation.

Most companies now understand the benefits of voluntarily disclosing the misconduct before we come asking, and the benefits of conducting an internal investigation and providing facts about the misconduct to the government.

But companies all too often tout what they view as strong cooperation, while ignoring that prosecutors specifically consider “the company’s willingness to cooperate in the investigation of its agents.”

Corporations do not act, but for the actions of individuals. In all but a few cases, an individual or group of individuals is responsible for the corporation’s criminal conduct. The prosecution of culpable individuals – including corporate executives – for their criminal wrongdoing continues to be a high priority for the department.

For a company to receive full cooperation credit following a self-report, it must root out the misconduct and identify the individuals responsible, even if they are senior executives.

We are not asking that you become surrogate FBI agents or prosecutors, or that you use law enforcement tactics like body wires. And we do not need to hear you say that executive A violated a particular criminal law. All we are saying is that we expect you to provide us with facts. We will take it from there.

But a company that interviews its employees in an effort to whitewash the facts or spread the company’s narrative spin risks receiving any cooperation credit.

Additionally, for a company to receive full cooperation credit, the company must provide relevant documents and evidence, and should do so in a timely fashion.

We find that global companies are increasingly hasty to invoke foreign data privacy laws to avoid providing evidence to the department. While we recognize that some of these laws pose real challenges to data access and transfer, many do not.

As a result, we are looking closely – with an ever more skeptical eye – to ensure that these claims are honest and not obstructionist. A company that reads foreign data protection laws expansively, to restrict its disclosure of documents, when it could be read more narrowly, is in dangerous territory if it wants to receive full cooperation credit.

Although the department welcomes and encourages corporate cooperation, we do not rely upon it. We conduct our own robust investigations – often alongside that of the company – to build our own criminal cases and to pressure-test corporate claims of cooperation.

Companies claiming to cooperate while conducting lackluster investigations with little results should not be surprised when they do not get credit for their supposed efforts. And they should not be surprised when they face the consequences of our own investigations.

The benefits of corporate cooperation are clear. We often explicitly describe the benefits when we reach resolutions with companies. As just one example, earlier this year, the department announced Alcoa World Alumina’s guilty plea to FCPA charges stemming from its payment of millions of dollars in bribes to officials of the Kingdom of Bahrain.

As part of the plea, Alcoa paid $223 million in criminal fines and forfeiture. The department publicly commended Alcoa for its cooperation, which included conducting an extensive internal investigation, making proffers to the government, voluntarily making current and former employees available for interviews, and providing relevant documents to the department.

Alcoa’s cooperation was mentioned specifically as a factor that lowered the size of the criminal fine. In fact, absent cooperation, Alcoa could have faced a fine of more than $1 billion. Many people, however, want concrete examples of cases where we decided not to pursue charges at all in light of a company’s cooperation. The department is not typically in a position to disclose these declinations, and indeed many companies do not want the world to know that they were under department scrutiny.”

[…]

“The Criminal Division is more committed than ever to investigating corporate fraud and corruption. We will investigate regardless whether a company choses to cooperate.

But for a company to receive credit for its compliance program, it must have demonstrated effectiveness, with messages about compliance that come from the top and echo throughout the corporate hallways.

And for a company to receive full cooperation credit, it must uncover the misconduct, identify the responsible individuals, and fully disclose the facts to the department.”

Deputy Attorney General Miller’s October 7th Speech

“I suspect that everybody in this room is familiar with the Principles of Federal Prosecution of Business Organizations, or the Filip factors, upon which we base our corporate charging and resolution decisions. One of those factors expressly directs us to consider “the existence and effectiveness of the corporation’s pre-existing compliance program” in deciding whether to charge a corporation with a crime.

In fact, one is hard-pressed to find a corporate resolution with the Justice Department that does not contain a prominent reference – positive or negative – to the corporation’s compliance program. The existence of an effective compliance program can make all the difference when a corporation is in the Justice Department’s sights.

Today, I would like to highlight a few primary strengths and weaknesses that we have observed in corporate compliance programs of late. As an overarching theme, the failure to expand compliance programs to meet the needs of growing corporations – particularly global corporations – drives many of the compliance problems we have seen. On the flip side, compliance programs that have widespread prophylactic and training mechanisms – as well as procedures designed to uncover wrongdoing and expose individuals responsible for criminal behavior – are the most effective.

A corporation’s ability to use compliance to uncover misconduct and, just as importantly, identify wrongdoers is central to the Justice Department’s evaluation of a compliance program.

As you know, there is no off-the-rack, one-size-fits-all compliance program. Companies must tailor compliance programs to manage their unique risks. There are, however, characteristics that should be present in each program.

In 2012, the Justice Department and the SEC published the Foreign Corrupt Practices Act, or FCPA, Resource Guide, which contains an entire section entitled, “Hallmarks of Effective Compliance Programs.” While the hallmarks in the FCPA Guide are focused on anti-corruption compliance programs, the principles identified apply universally.

Now, I’m not going to go through all the hallmarks with you today – but I will make a couple of overarching points. First, the Justice Department’s hallmarks are designed to encourage a ‘culture of compliance,’ which begins – but doesn’t end – with ‘a tone from the top,’ and extends to actions throughout a company’s ranks.

So hallmark # 1 is high-level commitment. When employees truly understand that a company’s leadership is committed to compliance – even when it runs up against profits – only then does a company truly have a successful compliance program. The quickest way to check on that commitment is to take a look at corporate structure. If you see compliance executives sitting in true positions of authority at a corporation, reporting directly to independent monitoring bodies, like internal audit committees or boards of directors, you likely are looking at a strong compliance program. Compliance programs also need to be resourced; they need to have teeth and respect. By contrast, for years, Wall Street banks housed their compliance programs across the Hudson River, in New Jersey. They were out of sight, out of mind. Compliance programs need to have appropriate stature within corporations.

Another key hallmark is whether the program grows with the company. Any good compliance program needs to be periodically evaluated, using risk assessment models aimed at the individual circumstances of the company. As companies change over time, so must compliance policies.

A strong compliance program must also involve enforcement and discipline. It is human nature to pay more attention to what people do than to what they say. Compliance must be incentivized; violations disciplined. And the response must be even-handed. Too often we see low-level employees who implemented bad conduct fired, but bosses, who did nothing to stop the conduct – and may even have directed it – left in place without sanction.

Although increasingly rare in this day and age – more than a decade after the passage of the Sarbanes Oxley Act – we are still encountering prominent companies with no real compliance programs. Hard to believe, but true.

Just last year, three subsidiaries of Weatherford International, a Swiss oil services company listed on the New York Stock Exchange, pleaded guilty to FCPA and export control violations. Over a period of many years, Weatherford subsidiaries in Africa, the Middle East, and Iraq paid bribes to foreign officials in exchange for lucrative contracts and inside information about competitors. Some of Weatherford’s international subsidiaries also illegally exported oil and gas drilling equipment to countries under United States sanctions – countries like Cuba, Iran, Sudan, and Syria.

But more important to this audience than Weatherford’s conduct itself may be the admissions it made regarding the state of its compliance programs. Weatherford admitted that prior to 2008, the company did not have a dedicated compliance officer or compliance personnel, did not conduct anti-corruption training, and did not have an effective system for investigating employee reporting of ethics and compliance violations.

The most glaring failures occurred in its overseas offices and subsidiaries. Let me give you a revealing example: Despite its global presence, Weatherford did not even bother to translate its compliance policy into languages other than English. Think about that for a second. Weatherford had subsidiaries and operations in more than 100 countries across the globe. It operated in the high-risk environment that is the oil extraction industry. And yet Weatherford didn’t even bother to make its compliance program intelligible to many of its employees – in languages they could understand.

And there’s more. Though in 2004 it began circulating an ethics questionnaire asking if employees were aware of payments to foreign officials, Weatherford had no process to investigate affirmative responses. Indeed, Weatherford did not conduct any follow-up investigation in response to allegations of corruption.

Put simply, Weatherford’s compliance policy was a program in name only. It wasn’t worth the paper it was written on. Had Weatherford employed even a basic compliance program, it may not have found itself paying over $252 million in penalties and fines.

Just last year, three subsidiaries of Weatherford International, a Swiss oil services company listed on the New York Stock Exchange, pleaded guilty to FCPA and export control violations. Over a period of many years, Weatherford subsidiaries in Africa, the Middle East, and Iraq paid bribes to foreign officials in exchange for lucrative contracts and inside information about competitors. Some of Weatherford’s international subsidiaries also illegally exported oil and gas drilling equipment to countries under United States sanctions – countries like Cuba, Iran, Sudan, and Syria.

But more important to this audience than Weatherford’s conduct itself may be the admissions it made regarding the state of its compliance programs. Weatherford admitted that prior to 2008, the company did not have a dedicated compliance officer or compliance personnel, did not conduct anti-corruption training, and did not have an effective system for investigating employee reporting of ethics and compliance violations.

The most glaring failures occurred in its overseas offices and subsidiaries. Let me give you a revealing example: Despite its global presence, Weatherford did not even bother to translate its compliance policy into languages other than English. Think about that for a second. Weatherford had subsidiaries and operations in more than 100 countries across the globe. It operated in the high-risk environment that is the oil extraction industry. And yet Weatherford didn’t even bother to make its compliance program intelligible to many of its employees – in languages they could understand.

And there’s more. Though in 2004 it began circulating an ethics questionnaire asking if employees were aware of payments to foreign officials, Weatherford had no process to investigate affirmative responses. Indeed, Weatherford did not conduct any follow-up investigation in response to allegations of corruption.

Put simply, Weatherford’s compliance policy was a program in name only. It wasn’t worth the paper it was written on. Had Weatherford employed even a basic compliance program, it may not have found itself paying over $252 million in penalties and fines.”

[…]

While the Justice Department is often the last line of defense against fraud and corruption, all of you who work in compliance are the first. Criminal prosecutions can and do deter future bad behavior, but your work can prevent that conduct before it happens.”

DOJ’s Empty Rhetoric On Individual FCPA Prosecutions Continues

This previous post highlighted the empty rhetoric of a former DOJ Criminal Division Chief regarding individual FCPA prosecutions.

A change in leadership at the DOJ Criminal Division has not brought about a change in the rhetoric.

As noted in this Reuters FCPA article, current Chief of the Criminal Division Leslie Caldwell stated:

“Certainly…there has been an increased emphasis on, let’s get some individuals.”

“It’s very important for us to hold accountable individuals who engage in criminal misconduct in white-collar (cases), as we do in every other kind of crime.”

Once again, the rhetoric is empty.

Sure the DOJ can point to a few core actions in which the DOJ has “clustered” multiple defendants into one action to achieve notable individual prosecution numbers.  The April 2014 action against six individuals allegedly involved in a conspiracy to obtain Indian mining licenses is a good example as was the “clustering phenomenon” in the enforcement action against five individuals associated with Direct Access Partners.   As highlighted in this previous post (with statistics calculated through the end of 2013), 53% of the individuals charged by the DOJ with FCPA criminal offenses since 2008 have been in just four cases and 75% of the individuals charged by the DOJ since 2008 have been in just nine cases.

In the vast majority of corporate FCPA enforcement actions (based presumably on the conduct of real individuals not ghosts as I indicated in my 2010 Senate FCPA testimony), the talk of individual prosecutions is nothing more than empty rhetoric.  Indeed, as highlighted in this previous post (with statistics calculated through the end of 2013) since 2008 approximately 75% of corporate FCPA enforcement have not (at least yet) resulted in any DOJ charges against company employees.

Consider the below chart with the 20 most recent corporate FCPA enforcement actions.  Only one has resulted (at least yet) in any DOJ charges against company employees.

Corporate Action

Related Prosecution of Company Employees

 

HP

No

Marubeni

No

Alcoa

No

ADM

No

Bilfinger

No

Weatherford

No

Diebold

No

Total

No

Ralph Lauren

No

Parker Drilling

No

Tyco

No

Pfizer

No

Nordam Group

No

Orthofix

No

Data Systems & Solutions

No

Biomet

No

BizJet / Lufthansa

Yes

Smith & Nephew

No

Marubeni

No

Magyar / Deutsche Telekom

No

The DOJ has long recognized that an FCPA enforcement program based solely on corporate fines is not effective and does not adequately deter future FCPA violations. For instance, in 1986 the DOJ Deputy Assistant Attorney General stated:

“If the risk of conduct in violation of the [FCPA] becomes merely monetary, the fine will simply become a cost of doing business, payable only upon being caught and in many instances, it will be only a fraction of the profit acquired from the corrupt activity. Absent the threat of incarceration, there may no longer be any compelling need to resist the urge to acquire business in any way possible.”

In 2010, the DOJ Deputy Chief of the Fraud Section likewise stated that a corporate fine-only FCPA enforcement program allows companies to calculate FCPA settlements as the cost of doing business.   In this new era, the DOJ has consistently stated that prosecution of individuals is a “cornerstone” of its FCPA enforcement strategy and in a 2012 speech the Assistant Attorney General stated: “If you look at the FCPA over the past 4 years, you’ll see we really have been vigorous about holding individuals accountable.” Add Caldwell’s recent statements to this long line of empty rhetoric.

Despite the rhetoric, the actual statistics demonstrate that FCPA enforcement is largely corporate enforcement only.