Lessons Learned From …

Imagine this post was titled “Lesson Learned from the NBA Playoffs.” I hope your reaction would be – well gosh, the NBA playoffs are merely in the second round. There are nearly two full months of basketball yet to be played.
Similarly if this post was titled “Lesson Learned from the 2016 Presidential Election,” again I hope your reaction would be – well gosh, sure there have been long, often brutal primary elections, but the general election is just beginning.
So why then do many (certainly not all) Foreign Corrupt Practices Act commentators publish articles, posts, etc. on purported lessons learned when: (i) they lack first hand information concerning the specific facts or circumstances at issue, but are merely relying on second-hand accounts often by non-lawyer journalists writing a story; and/or (ii) the specific issue has merely just begun, the situation remains fluid, and the end-result is unknown?
Fear-Based FCPA Marketing

As is his occasional style, Mike Volkov began this post on his Corruption Crime & Compliance blog with a rant:
“Akin to politics (to a smaller degree), there is a fair amount of disinformation, some call it bloviating, put out by the FCPA Paparazzi. Some of this disinformation is motivated by immature attempts to “market” legal services; other sources of disinformation carry a readily apparent bias, one way or the other, and usually are supported by self-citations to one’s own “scholarship” to prove their points.”
When ranting, one can at least be a bit more specific and perhaps provide supporting links so that readers can decide for themselves the veracity of the assertions.
In any event, it was a bit ironic that a few days after the above rant a post was published on Corruption Crime & Compliance titled “Doing Business in China Should be “Scary.“
Issues To Consider From The PTC Enforcement Action
This post went in-depth regarding this week’s $28 million Foreign Corrupt Practices Act enforcement action against PTC Inc. and related entities.
This post continues the analysis by highlighting various issues to consider.
Timeline
As highlighted in this previous post, the company first disclosed its FCPA scrutiny in August 2011. Thus, the timeline was approximately 4.5 years.
Pre and Post – Enforcement Action Professional Fees and Expenses
Unlike some issuers under FCPA scrutiny, PTC does not appear to have disclosed its pre-enforcement action professional fees and expenses over the past 4.5 years. If the company’s scrutiny followed a typical path, those pre-enforcement action professional fees and expenses likely were equal to or exceeded the $28 million settlement amount.
Given that PTC did not disclose its pre-enforcement action professional fees and expenses, it is unlikely that the company will disclose its post-enforcement action professional fees and expenses either. However, there will be plenty because, as a condition of settlement, the company is required to report to the DOJ for a three year term.
Let’s pause to consider whether this is truly necessary or simply another government required transfer of shareholder wealth to FCPA Inc. (see here, here and here for prior posts).
In the words of the DOJ:
“The [PTC Entities] engaged in extensive remedial measures, including a review and enhancement of the Companies’ and PTC Inc.’s compliance program, the establishment of a dedicated compliance team at the corporate level and at PTC China and enhanced policies for business partners, the termination of the business partners involved in the misconduct described in the Statement of Facts …, and the implementation of new customer travel policies and additional controls around expense reimbursement.”
In the words of the SEC:
“As part of its internal review and investigation, PTC undertook significant remedial measures including terminating the senior staff at PTC-China implicated in the FCPA violations. PTC also revised its pre-existing compliance program, updated and enhanced its financial accounting controls and its compliance protocols and policies worldwide, and implemented additional specific enhancements in China. These steps included: (1) reviewing and enhancing its anti-bribery policy, code of ethics, and gifts and entertainment policies to correct previous deficiencies; (2) establishing a dedicated compliance team, including a chief compliance officer and a new compliance director in China; (3) expanding its other compliance resources in China, including hiring a new vice president of finance for Asia and adding additional legal staff in China; (4) hiring a new management team in China, including a new China President; (5) enhancing its FCPA training for employees; (6) severing its relationships with the business partners that were implicated in the FCPA violations and discontinuing the use of COD partners or business referral partners generally; (7) implementing a comprehensive due diligence program for all other business partners that includes a risk-scoring system operated by a third party vendor and that includes FCPA training as part of the onboarding process; (8) obtaining quarterly anti-corruption certifications from sales staff; and (9) undertaking periodic compliance audits.”
Against this backdrop, is it truly necessary for PTC to report to the government for three years regarding its “remediation efforts to date, their proposals reasonably designed to improve the Companies’ internal controls, policies, and procedures for ensuring compliance with the FCPA and other applicable anti-corruption laws, and the proposed scope of the subsequent reviews”?
One Core Enforcement Action
Certain FCPA Inc. participants have adopted creative counting methods when it comes to keeping FCPA enforcement statistics.
No doubt, some will count the PTC enforcement action as three separate enforcement actions (the DOJ component, the SEC component as to the company, and the SEC component as to the individual) even though each action was based on the same core conduct. Counting FCPA enforcement actions this way distorts FCPA enforcement statistics because this week’s action was one core action.
First Individual DPA by the SEC
The Yu Kai Yuan DPA, which the SEC termed the first DPA with an individual in an FCPA case, might be the most inconsequential legal document you will ever read.
Based on the same core conduct in the DOJ NPA and the SEC administrative order, the SEC alleged that Yuan (a Chinese citizen who resides in Shanghai and was last a sales executive for PTC entities in China in 2011) caused violations of the FCPA’s books and records and internal controls provisions.
The only specific allegation as to Yuan in the DPA is the first paragraph which merely identifies him. There is no other specific allegation regarding him including how he caused violations of the FCPA’s books and records and internal controls provisions.
Without admitting or denying the SEC’s allegations, Yuan agreed to refrain from violating the “federal and state securities law” and to “refrain from violating the applicable rules promulgated by any self-regulatory organization or professional licensing board.”
If what the SEC is seeking is more individual enforcement actions in connection with corporate FCPA actions, the Yuan DPA represents one way to juice the statistics.
Additional Sloppy or Incomplete Pleading
The recipients of the travel and entertainment alleged were employees of alleged Chinese state-owned entities.
That is all the DOJ and SEC state in the resolution documents.
Even though the two-factor control and function test set forth in Esquenazi is flawed (see pgs. 24-43 in this article for a detailed discussion of why), it would seem incumbent on the enforcement agencies to include allegations or findings relevant to this two-factor test as the business community (at least one intended audience of FCPA resolution documents) remains confused regarding the contours of the “foreign official” element.
Assumed Causation
Like many, many other FCPA enforcement actions, the PTC action assumes causation.
In other words, it is assumed that the only reason the Chinese SOEs purchased PTC products and services is because certain of the SOE employees engaged in non-business travel and received other things of value such as iPods, wine and clothing from PTC entities.
Such assumed causation, very much relevant to disgorgement issues, would seem to speculative at best.
Just Plain Silly
Speaking of assumed causation, some have asserted that the Yuan individual DPA by the SEC was “inspired in part by the Yates memo issued over at the Justice Department.”
My own two cents is that suggesting such a connection is just plain silly. The Yuan DPA signatures began in November 2015 and as stated by the SEC the DPA was the “result of significant cooperation [Yuan] provided during the SEC’s investigation” – an investigation which began in 2011.
Application of DD-3
One often overlooked reason for the general increase in FCPA enforcement in the modern era is that in 1998 the statute was expanded through the dd-3 portion of the FCPA which applies to, generally speaking, non-issuer foreign companies and foreign nationals, to the extent the “while in the territory of the U.S.” jurisdictional prong has been satisfied.
The DOJ’s NPA was against PTC China entities, not PTC Inc., and invoked dd-3. While not explicit in the resolution documents, the “while in territory of the U.S.” jurisdictional prong was presumably met given that certain PTC China employees accompanied the alleged Chinese “foreign officials” on their travels to the U.S.
Compliance 2.0 – A (Mostly) Meaningless Buzzword
This recent article in the Journal of Judgment and Decision Making titled “On the Reception and Detection of Pseudo-Profound Bullshit” caught my eye. The article focuses “on pseudo-profound bullshit, which consists of seemingly impressive assertions that are presented as true and meaningful but are actually vacuous.”
Perhaps you’ve noticed the emergence of the term “compliance 2.0” in the Foreign Corrupt Practices Act space and beyond?
You can read a three part series on Compliance 2.0 (here, here, and here) on the FCPA Blog.
You can read a five part series on Compliance 2.0 (here, here, here, here, here) on Corruption Crime and Compliance.
Panels at conferences are titled “Compliance 2.0: How to Build and Implement a Strong Compliance Program for FCPA” and other areas.
You can read the above links and decide for yourself whether those promoting Compliance 2.0 as some kind of secret sauce have a point or are mostly speaking in vague generalities and thus gobbledygook.
My own two cents is that Compliance 2.0, as used in the FCPA space, is mostly a meaningless buzzword.
Using the word “no” FCPA issue is a bit strong because, after all, a broken clock is right twice a day (pardon the buzzword / cliche).
However, few if any FCPA issues are going to be “nipped in the bud” (pardon the buzzword / cliche) based on the following purported components of Compliance 2.0: the reporting relationship between a board of directors and chief compliance officer or general counsel; a CEO or other executive officer’s “tone at the top” (another mostly meaningless buzzword in the FCPA space); or consideration of other stakeholders.
Rather, FCPA issues arise – and can thus best be mitigated and managed – by understanding how real people, operating in foreign countries with real business conditions, interact with real foreign officials.
The narrative roadmap for many FCPA issues is as follows.
- Barriers, distortions and conditions create bureaucracy
- Bureaucracy creates points of contact with foreign officials
- Points of contact with foreign officials create discretion
- Discretion creates the opportunity for a foreign official to misuse their position by making bribe demands.
Instead of complicating the compliance playbook with a mostly meaningless buzzword, business organizations should keep it simple and focus on blocking and tackling type issues (pardon the buzzword / cliche) such as the following questions relevant to conducting an FCPA risk assessment:
- In which countries does the company do business? As to each country, what is the country’s reputation for corruption?
- Who are the company’s customers or potential customers in each country? Is the customer a government (whether federal, state, or local) department, agency or instrumentality? Does a government department, agency, or instrumentality, or individual associated with such units, have an ownership or equity interest in the customer?
- How does the company do business and/or interact with customers or potential customers in the country? Does the company use third parties in the foreign countries?
- How does the company’s product enter and exit the country? Does the company use the services of a customs broker or freight forwarder?
- What licenses, permits, or certifications does the company need to do business in the country? As to each license, permit or certification, how does the company obtain such approvals?
- Is the company subject to other unique forms of government regulation in the country? What other points of contact does the company have with foreign government in the country (such as tax and immigration authorities)?
Understanding the answers to the above questions and incorporating them into an FCPA compliance program are leaps and bounds more important than “tone at the top” and the specifics of the reporting relationship between a chief compliance officer and the board of directors.
Moreover, Compliance 2.0, like most buzzwords, can be counter-productive because they create a false sense of results by inferring that adherence to the buzzword will show results. Indeed, a recent survey by the Institute of Leadership & Management suggests that a meaningful percent of employees consider management jargon as pointless and often irritating.
In short, decide for yourself whether Compliance 2.0 is a useful concept or mostly a meaningless buzzword.
And when you are done with that, turn your attention to Compliance 3.0 (see here).
Ten Things That Will Likely Happen In 2016
I’ve never been much for predictions when it comes to the Foreign Corrupt Practices Act and related topics.
After all, FCPA enforcement is often unpredictable largely on account of the enforcement agencies having a tremendous amount discretion (some would say too much), coupled with the fact that much FCPA enforcement takes place around conference room tables in Washington D.C. in the absence or practical absence of outside scrutiny.
Nevertheless, set forth below are ten things that will likely happen in 2016 (presented in a slightly jocular, yet equally serious manner) based on my experience in following FCPA enforcement (and the flow of FCPA information) as close as anyone for the past six years.
*****
- Sometime during the year there will be a lull in FCPA enforcement, yet one minor, inconsequential enforcement action will be announced (probably in the early spring) and everyone will write about it as well as the purported new trends and compliance messages from the enforcement action. Why? Because it happens all the time as FCPA Inc. is an active group of writers that frequently make mountains out of mole hills by using recent enforcement action as a “hook” to market their practices and compliance services. In 2015, it was the late February enforcement action against Goodyear that generated a substantial amount of commentary. I fielded more media calls about this inconsequential action than any other FCPA enforcement action in recent memory. During one call, the reporter asked for my reaction, I looked outside my window and it was raining, and I said “well it’s raining out, it’s really no big deal.” The reporter said, “that may be true, but to others this is a thunderstorm.” Precisely my point.
- On more than one occasion in 2016, the media contingent of FCPA Inc. is likely to publish an article or post that is false, misleading, embellished, breathless, or taken completely out of context. Why? Because it happens all the time (see here for a collection of examples) and is the end result of non-lawyer journalist and/or FCPA Inc. participants with financial motives serving as the gatekeepers of much information.
- The most active month for SEC enforcement will likely be September. Why? Because September is the end of the SEC’s fiscal year and historical statistics demonstrate that September tends to be a very active month for FCPA enforcement.
- Speaking of September, there will likely be some “major” DOJ/SEC policy speech. Why? Because it happens almost every September as the enforcement agencies seemingly seek to reassert their authority and re-articulate their message after the summer hiatus. In connection with this “major” policy speech (which in reality will likely not be “major” at all) the aforementioned media contingent of FCPA Inc. will likely churn out articles and client alerts (most of which will simply regurgitate the policy position as if the policy announcement – much of it old news to those informed – of a political actor represented a big deal).
- In months leading up to November a certain for-profit conference firm will, in a truly disgraceful practice, likely market DOJ / SEC FCPA enforcement attorneys who will speak at their event as if the enforcement attorneys are a commodity they own and can profit from. Why? Because it happens every year. The speech delivered by the public officials at the private event will generate much FCPA Inc. media coverage, but sophisticated observers will have already heard the speech. Why? Because it will likely be basically the speech delivered last year at the event (See here and here).
- In November, the SEC will release its annual whistleblower statistics and alleged FCPA violations will likely be a very minor component of the overall tips the SEC receives. Why? Because, despite numerous early predictions that the whistleblower provisions would transform FCPA enforcement, alleged FCPA violations have consistently comprised less than 5% of the SEC’s overall tips.
- Marketing the holidays seems to occur sooner and sooner each year, thus this next development will likely take place in November, but perhaps even as early as October or September. FCPA Inc. participants will churn out client alerts and publications warning of the FCPA risks of the holidays and gift giving. Why? Because it happens every year and is convenient hook to try to sell compliance services.
- Back to SEC FCPA enforcement. The SEC will likely not have to prove any of its FCPA enforcement theories to anyone other than itself. Why? Because in the FCPA’s 38 year history, the SEC has never gone to trial in an FCPA matter (corporate or individual) and in the rare instances when it has been put to its ultimate burden of proof, the SEC has never prevailed. (See here).
- Like September, December will also likely be an active month for FCPA enforcement. Why? Because even though December 2015 was a clear outlier, December is the end of the calendar year and historical statistics demonstrate that December tends to be a very active month for FCPA enforcement.
- A high-ranking FCPA enforcement attorney will likely leave either the DOJ or SEC for a lucrative, guaranteed multi-million dollar position at a law firm and then almost immediately begin writing client alerts and other publications criticizing recent FCPA enforcement theories. Why? Because it happens all the time and in 2016 or early 2017 there is likely to be substantial turnover at the DOJ and SEC given the change in executive administration.