Either Enforce the FCPA or Don’t Enforce the FCPA
The DOJ and the SEC (the “Enforcement Agencies”) should either enforce the FCPA or not enforce the FCPA.
For instance, Team Inc. violated the FCPA, but in its August 2nd SEC filing (here) the company stated as follows regarding its previously disclosed FCPA issue. “In a letter to us dated July 12, 2011, the staff of the SEC informed us that it had completed its investigation and did not intend to recommend any enforcement action by the Commission or impose any fines or penalties against the Company. We have not received formal notification from the DOJ, however in July 2011, the staff of the DOJ informed us that it was likely that the staff would not recommend taking any further action or imposing any fines or penalties against the Company.”
How do we know that Team Inc. violated the FCPA? Because the company said it did. For instance, in this August 2010 SEC filing the company said as follows in reference to its previously disclosed internal review regarding its branch operation in Trinidad. “The report of the independent investigator was delivered to the Audit Committee in March 2010 and to the DOJ and SEC in May 2010. The investigation concluded that improper payments of limited size were made to employees of foreign government owned enterprises in Trinidad, but determined that the improper payments were not made, or authorized by, employees outside the one TMS Trinidad branch. The investigation of our other foreign operations did not result in any findings of significance and management has remediated or is undertaking remedial action on all matters identified in the investigation. Based upon the results of the investigation, we believe that the total of the improper payments to government owned enterprises over the past five years did not exceed $50,000. The total annual revenues from the impacted TMS Trinidad branch represent less than one percent of our annual consolidated revenues for all years presented. ” (emphasis added).
Accepting the Enforcement Agencies’ position that payments to government-owned enterprises fall under the FCPA, why didn’t the Enforcement Agencies bring an action? Sure Team Inc. did voluntarily disclose the conduct at issue and the results of its investigation, but that could also be said for nearly all corporate FCPA enforcement actions. Sure, Team Inc.’s “improper payments” appear to have been isolated, were relatively minor in scope, and were not (per the company) “made, or authorized by, employees outside the one TMS Trinidad branch.” But again, the same could also be said for a significant percentage of all corporate FCPA enforcement actions.
Using the Team Inc. standard, did Rockwell Automation deserve an FCPA enforcement action (see here for the prior post). Did Comverse (see here for the prior post) deserve an FCPA enforcement action?
If the FCPA contained a compliance defense (along the lines that a company would not be held vicariously liable for a violation of the FCPA’s anti-bribery provisions by its employees or agents, who were not an officer or director, if the company established procedures reasonably designed to prevent and detect FCPA violations by employees and agents) the end result in Team Inc. would have likely been the same and rightfully so.
But at least the result would have been grounded in law, not in the ad hoc, opaque, non-reviewable discretionary decisions of the Enforcement Agencies.
Compliance Certificates
In relation to the U.K. Bribery Act’s so-called adequate procedures defense, how does a company know whether it has adopted adequate procedures so that it can avail itself of the defense should its conduct come under scrutiny? It is a darn good question.
Last week, thebriberyact.com (see here) had a post regarding an adequate procedures certificate. The post profiled a recent speech by Richard Alderman (Director of the U.K. Serious Fraud Office) on the issue of a lawyer’s certificate for adequate procedures. As detailed in the post, Alderman stated as follows. “We know, for example, that some companies believe that all they need is a certificate from a firm of lawyers that they have adequate procedures. We hear about this. We hear as well that the company is not prepared to pay very much for this and expects a certificate of adequate procedures for its worldwide enterprise under say £25,000. This will not impress us very much. This does not mean that we expect companies to spend millions of pounds on this. What we do expect though is a proportionate approach by companies focussing on the key risks and on what they are doing in order to be able to combat those risks. This is what companies should be doing anyway. Indeed some companies have told us that this is a valuable exercise for them for all sorts of reasons that they should have carried out before. A company that does this but which finds problems will receive very sympathetic treatment at the SFO. A company that closes its mind to the issues while perhaps having some veneer of paper procedures will receive different treatment.”
One of the FCPA reform proposals under consideration – and a reform proposal I support (see here and here for prior posts) – is creation of a compliance defense. If enacted, the same issue will arise as under the U.K. Bribery Act – how does a company know whether it has adopted sufficient measures so that it can avail itself of the defense should its conduct come under scrutiny?
Is a compliance certificate the answer?
In Chile, the answer is yes. As detailed in this prior “Compliance Defense Around the World” post, Chile is one of several OECD Anti-Bribery Convention countries to incorporate compliance defense principles into its “FCPA-like” law.
Under Chilean law: in order for a legal person to be held responsible for a foreign bribery offence, the following “three cumulative requirements” must be satisfied: (1) the offence must be committed by a person acting as a representative, director or manager, a person exercising powers of administration or supervision, or a person under the “direction or supervision” of one of the aforementioned persons; (2) the offence must be committed for the direct and immediate benefit or interest of the legal entity. No offence is committed where the natural person commits the offence exclusively in his/her own interest or in the interest of a third party; and (3) the offence must have been made possible as a consequence of a failure of the legal entity to comply with its duties of management and supervision. An entity will have failed to comply with its duties if it violates the obligation to implement a model for the prevention of offences, or when having implemented the model, it was insufficient.”
As to the final element, the OECD report states as follows. “The final cumulative requirement for responsibility stresses that the offence must have been made possible as a consequence of the failure of the legal person to comply with its duties of administration and supervision. The entity will have failed to comply with its duties if it violated the obligation to implement a model for the prevention of offences, or when having implemented the model, the latter was insufficient. It shall be considered that the functions of direction and supervision have been met if, before the commission of the offense, the legal person had adopted and implemented organization, administration and supervision models, pursuant to the following article, to prevent such offenses as the one committed.”
The minimum features of a prevention system under the law are as follows: identify the different activities or processes of the entity, whether habitual or sporadic, in whose context the risk of commission of the offences emerges or increases; establish protocols, rules and procedures that permit persons involved in above-mentioned activities or processes to program and implement their tasks or functions in a manner that prevents the commission of the indicated offences; identify procedures for the administration and auditing that allow the entity to impede their use in the listed offences; establish internal administrative sanctions, as well as procedures for reporting or pursuing pecuniary responsibility against persons who violate the prevention system; introduce the above-mentioned duties, prohibitions and sanctions into the internal regulations of the legal person, and ensure that they are known by all persons bound to apply it (workers, employees, and service providers).
The OECD report states – as to the minimum requirements as follows. “It also aims to introduce a system of self-regulation by companies. Having a code of conduct on paper will not be sufficient to avoid responsibility. If prosecutors can prove that the code does not meet the minimum requirements of or that it is not implemented, the company can be responsible for the offence.” Under Chilean law, “the failure to comply with duties of management and supervision is an element of the offence rather than a defence. Therefore the burden of proof lies on prosecutors, i.e. it will be up to prosecutors to prove that the entity failed to comply with its duties of management and supervision.” The OECD report notes as follows. “This will require prosecutors to prove that the company failed in the design and/or implementation of the offense prevention model including why, in the circumstances, the prevention model was insufficient. This would appear to also require the prosecutor to establish that this failure made perpetration of the offence possible.”
Chilean law sets forth a detailed process by which legal persons are able to undergo a certification process on the existence and relevance of their organizational model. The OECD report states as follows. “Certification will confirm that the offence-prevention model complies with the minimum requirements [set forth above], taking into account the characteristics of the legal person. The certification is valid as long as the situation of the company does not change. Certification will be carried out by private institutions which have been authorised by public agencies to undertake this role. Two points should be noted. The first is that certification will not, by itself, avoid responsibility, since it will remain possible to convict a legal person if it can be proved that, notwithstanding the certification, the preventive model did not meet the minimum requirements [set forth above]; and/or that the model was not implemented. The second point to note is that, pursuant to [the Chilean law], private institutions carrying our certification will be carrying out public functions, which means that they will be criminally responsible in the event of a failure to act properly in the execution of those functions. The sole function of public agencies will be to authorise institutions to carry out these functions, and to keep record of certifications.”
What do you think? Is the Chilean certification process the answer? What are the pros and cons of such an approach? If anyone can direct me to Chilean counsel knowledgeable about this certification process or the “private institutions” authorized to issue such certifications, please send me an e-mail so that I can inquire and report back any findings.
If the FCPA were amended to include a compliance defense, would Chile’s certification approach work here in the U.S.?
For starters, it is useful to observe that the DOJ is already handing out compliance certificates in at least two respects – even if not formally called compliance certificates.
First, the FCPA’s Opinion Release Procedure results in the DOJ issuing – for all practical purposes – a compliance certificate in that the DOJ opines whether a proposed course of conduct, based on the requestor’s disclosed information and various representations, complies with the FCPA. Pursuant to the governing regulations (see here), “there shall be a rebuttable presumption that a requestor’s conduct, which is specified in a request, and for which the Attorney General has issued an opinion that such conduct is in conformity with the Department’s present enforcement policy, is in compliance with those provisions of the FCPA.”
Second, every NPA or DPA contains a clause stating that the DOJ will not bring an enforcement action if the company complies with the undertakings set forth in the agreement – including an appendix which sets forth various compliance obligations. (See here for the recent Armor Holdings NPA). As with the FCPA Release Procedure, the term compliance certificate is lacking, but in substance that is likewise the end result.
That the DOJ is already issuing “compliance certificates” makes the DOJ’s firm opposition to an FCPA compliance defense (see here for more) all the more curious – and all the more contradictory.
Friday Roundup
The Lindsey defendants argue that “repeated and intentional government misconduct” requires dismissal of their jury convictions, a nondescript Commerce Department statement regarding the July 22nd FCPA Business Roundtable, a World Bank service opportunity, there is now competing FCPA insurance products, Ethisphere launches its Anti-Corruption Resource Center, and the DOJ’s Travel Act opposition brief in Carson … its all here in the Friday Roundup.
Lindsey Supplemental Motion to Dismiss Based on Government Misconduct
A previous post (here) asked whether the Lindsey convictions were hanging by a thread and summarized the June 27th hearing on defendants’ prosecutorial misconduct motion during which Judge Matz made some rather damning comments concerning the DOJ’s first-ever corporate FCPA jury trial verdict. Earlier this week, Lindsey Manufacturing, Keith Lindsey and Steven Lee filed a “Supplemental Brief In Support of Motion to Dismiss the Indictment With Prejudice Due to Repeated and Intentional Government Misconduct” (see here and here in two parts).
Highly factual, the brief begins as follows. “The investigation and prosecution of this case were permeated with instances of purposeful, prejudicial government misconduct. The government’s misconduct was patent and pervasive, designed to win the case, not do justice.” Counsel for Lindsey Manufacturing and Keith Lindsey, Jan Handzlik (Greenberg Traurig – here) stated as follows. “Considered individually or on a cumulative basis, the government’s conduct was extraordinarily damaging. We believe this unfair prejudice should result in a dismissal.”
The Lindsey case was profiled in a July 22nd Wall Street Journal article which detailed how “the Justice Department is grappling with a string of high-profile blunders that have prompted stinging rebukes from judges.” Interestingly, the WSJ did not profile the recent mistrial in the DOJ’s high-profile Africa Sting case (see here for the prior post).
As to the Africa Sting case, this recent post from the Blog of Legal Times detailed a hearing earlier this week in the case during which the DOJ said it “wants to retry the first four defendants before any of the other trials.”
Commerce Department Statement Regarding the July 22nd Business Roundtable
On July 22nd, the Commerce Department hosted, along with Assistant Attorney General Lanny Breuer and SEC Enforcement Director Robert Khuzami, a business roundtable on the Foreign Corrupt Practices Act. The statement (here) released yesterday by Cameron Kerry (Commerce Department General Counsel) stated as follows. “Over twenty company representatives from a wide range of business sectors, sizes, and geographic locations participated. Participants were recommended by business associations with an interest in this area. We engaged in an open and constructive dialogue and many participants noted that U.S. business and the government must work together to fight international bribery and corruption in order to uphold the rule of law and support human rights. We heard an array of concerns, complaints, and compliments about the statute, its enforcement and related guidance, and I was encouraged by the large turnout, the frank conversation, and the clear dedication of all participants to address the corrosive impact of corruption on international commerce.”
World Bank Sanctions Board Vacancies
The World Bank Sanctions Board is comprised of four external members and three internal (World Bank staff) members. The World Bank is inviting applications and nominations for the positions of two Sanctions Board members to be selected from among non-Bank staff. To learn more see here.
Additional FCPA Insurance Option
A prior post (here) noted that an insurance company (Chartis ) has begun offering Foreign Corrupt Practices Act insurance and how this development only confirmed that FCPA Inc. has become a full-fledged industry in and of itself. Recently, Marsh also launched (here) its own FCPA insurance product. As described in the company’s brochure, “FCPA Corporate Response” – “reimburses companies for investigation costs including legal, accounting, auditing, and consulting fees due to an FCPA claim;” “provides coverage for both the organization and individuals for FCPA investigations;” and “acts as primary insurance to a directors and officers (D&O) liability policy to immediately protect individual directors and officers.” The insurance also covers investigations under the U.K. Bribery Act as well.
Ethisphere Launches Anti-Corruption Resource Center
Earlier this week, Ethisphere (a leading international think-tank dedicated to the creation, advancement and sharing of best practices in business ethics, corporate social responsibility, anti-corruption and sustainability) launched its Anti-Corruption Resource Center – see here for the release. A mix of freely accessible and password protected information, the Anti-Corruption Resource Center contains, among other things, various article regarding FCPA and compliance topics, a schedule of upcoming FCPA conferences and events.
DOJ’s Travel Act Opposition Brief
A prior post (here) discussed certain of the Carson defendants motion to dismiss Travel Act charges based on alleged bribes to employees of private companies located in China and Russia. Among other things, defendants argued that the Travel Act has no foreign application.
Recently, the DOJ filed (here) its opposition brief. According to the DOJ, “[b]ecause the majority of defendants’ unlawful conduct was based in the United States, the statutes at issue [the Travel Act and California’s commercial bribery statute] reach defendants’ conduct without any resort to extraterritorial application.” As stated by the DOJ, “defendants S. Carson, R. Carson, Cosgrove, and Edmonds were all U.S. citizens and served as executives at CCI’s headquarters in Rancho Santa Margarita, California” and a “significant portion of the four defendants’ acts in furtherance of the conspiracy occurred either in the United States or through communications with individuals in the United States.” The DOJ further argued as follows. “Although the Court need not consider the question of whether the Travel Act applies extraterritorially, the plain language of the statute, the legislative history, and the case law all indicate that the Travel Act does apply extraterritorially.”
*****
A good weekend to all.
A Focus On The SEC
From an FCPA reform perspective, most of the recent scrutiny has been on the DOJ and its enforcement policies and positions.
Yet, the FCPA is also enforced by the SEC.
As a civil enforcement agency only, the SEC’s stick is less sharp the DOJ’s. Nevertheless, the SEC’s FCPA enforcement positions on issues such as “foreign official” and “obtain or retain business” are seemingly identical to the DOJ’s.
Moreover, certain of the SEC’s enforcement theories as to the FCPA’s books and records and internal control provisions are subject to controversy. As I highlighted in “The Facade of FCPA Enforcement” (here at pgs. 976-984), with increasing frequency, the SEC has charged FCPA books and records and internal control violations based on untested and dubious legal theories, as well as theories seemingly in direct conflict with the FCPA’s statutory provisions.
For instance, the SEC routinely charges parent companies with FCPA books and records and internal control violations based solely on the conduct of indirect subsidiaries or affiliates in the absence of any allegation that the parent company participated in, or had knowledge of, the conduct at issue – even though the FCPA specifically states that issuers that demonstrate good faith efforts to cause indirect subsidiaries and affiliates to devise and maintain effective internal controls “shall be conclusively presumed to have complied with” the FCPA’s applicable requirements.
The SEC’s FCPA enforcement theories and policies are now being questioned. See here for the June 30th letter from Senator Mike Crapo (R-ID) to SEC Chairman Mary Schapiro.
The letter begins with Senator Crapo stating that “Congress and the agencies that enforce the FCPA must work together to ensure that the statute’s goals are being met without perverting the risk and reward calculus U.S. firms face when considering overseas business opportunities that would support domestic job growth.”
In the letter, Senator Crapo says he is “concerned by the recent Congressional testimony about the increased compliance costs for businesses operating in good faith to abide by the FCPA’s strictures and the deterrence of U.S. firms’ entry into, or expansion of, overseas operations.”
Senator Crapo then asks Chairman Schapiro for answers to the following questions.
1. Should the FCPA be amended to provide an affirmative defense, which may be raised where violations resulted from the conduct of individual employees or agents who circumvented compliance measures that were reasonably designed to identify and prevent such violations?
2. Does the Commission believe that regulations or guidance explaning factors it considers when determining whether an entity’s officers or employees are “foreign officials” would be helpful to U.S. firms? Would the Commission support legislation that more clearly defines the term “foreign official” under the FCPA?
3. What are the mechanisms by which the Commission could or does provide guidance on FCPA related matters?
4. Is it the Commission’s policy to hold firms strictly liable for foreign subsidiaries’ actions in violation of the FCPA?
5. Under what circumstances, if any, is it appropriate for both the Commission and the Department to seek the recovery of penalties from the same entity for the same conduct?
Prior to responding to Senator Crapo’s letter, Chairman Schapiro and others at the SEC’s FCPA Unit would be well served by reviewing a 1981 speech by then Chairman of the SEC – Harold Williams – on the FCPA’s books and records and internal control provisions.
To best understand (and place in context) current SEC FCPA enforcement positions and policies, it is useful to understand past SEC FCPA enforcement positions and policies. Statements made by the SEC Chairman in 1981 bear little resemblence to the SEC’s current enforcement of the FCPA’s books and records and internal control provisions.
*****
The year was 1981, the event was the American Institute of Certified Public Accountants, and the speaker was Harold Williams, the Chairman of the SEC. Williams focused his remarks (here) “solely to one major auditing development of recent years: the accounting provisions of the Foreign Corrupt Practices Act of 1977.”
Williams began has remarks as follows. “When viewed from an abstract perspective, the Act’s accounting provisions seem merely to codify a basic and uncontroversial management principle: no enterprise of any size can operate successfully without maintaining effective controls over its transactions and the disposition of its assets. Perhaps in part because these provisions were considered truisms, the Act was passed without Congressional dissent. However, practical experience with new legislation – even a law thought to be noncontroversial – often will reveal unanticipated problems. Newly enacted standards, for example, may be subject to differing constructions or raise compliance difficulties and ambiguities unforeseen by their draftsmen. And, until these problems are resolved by an agency, the courts or the Congress, those who are subject to these laws are often faced, unfortunately, with some disquieting circumstances. The anxieties created by the Foreign Corrupt Practices Act – among men and women of utmost good faith – have been, in my experience without equal.”
Williams noted that “such uncertainty can have a debilitating effect on the activities of those who seek to comply with the law. My sense is that, as a consequence, many businesses have been very cautious – sometimes overly so – in assuring at least technical compliance with the Act. And, therefore, business resources may have been diverted from more productive uses to overly-burdensome compliance systems which extend beyond the requirements of sound management or the policies embodied in the Act. The public, of course, is not well served by such reactions.”
Unlike many SEC speeches that contain the usual – this is only my personal opinion disclaimer – Williams specifically noted that he “conferred” with his “colleagues before presenting these remarks, and they have authorized me to advise you that these remarks constitute a statement of the Commission’s policy.”
As to the FCPA’s books and records provisions, Williams stated as follows. “This provision is intimately related to the requirement for a system of internal accounting controls, and we believe that records which are not relevant to accomplishing the objectives specified in the statute for the system of internal controls are not within the purview of the recordkeeping provision. […] nor could a company be enjoined for a falsification of which its management, broadly defined, was not aware and reasonably should not have known.”
As to the FCPA’s internal control provisions, Williams stated as follows. “The Act does not mandate any particular kind of internal controls system. The test is whether a system, taken as a whole, reasonably meets the statute’s specified objectives. ‘Reasonableness,’ a familiar legal concept, depends on an evaluation of all the facts and circumstances.”
Under the heading “deference” Williams stated as follows. “Private sector decisions implementing these statutory objectives are business decisions. And, reasonable business decisions should be afforded deference. This means that the issuer need not always select the best or the most effective control measure. However, the one selected must be reasonable under all the circumstances.”
Under the heading “state of mind” Williams stated as follows. “The accounting provisions principal objective is to reaching knowing or reckless conduct.”
As to the “purposes of the Act,” Williams provided a brief review of the “events which led to the [FCPA].” He stated as follows. “Clearly, Congress went further than determining whether the payments which gave the new law its name were ethically and commercially justifiable. It also chose to consider the corporate accounting and control deficiencies which had been breeding grounds for these practices. And, by doing so, it addressed the far more serious issues raised by these disclosures. […] These payments and falsifications were not only previously unknown to public investors and independent auditors, but many were also unknown to the payor’s board and, in numerous examples, even to its senior management. In some of these instances, internal controls existed, but they were shown to be ineffective or easily subverted. Unauthorized payments and related falsifications of corporate records seemed to evidence – indeed, were fostered by – a lack of adequate accounting records and controls. Consequently, in the legislation which ultimately emerged from Congress, prohibiting questionable payments and mandating control and recordkeeping were inexorably interconnected.”
Williams stated as follows. “The primary thrust of the Act’s accounting provisions, in short, was to require those public companies which lacked effective internal controls or tolerated unreliable recordkeeping to comply with the standards of their better managed peers. That is the context in which these provisions should be construed.”
Williams then addressed “four of the most important” interpretative questions concerning the then-young FCPA: “first, the degree of exactitude in recordkeeping mandated by the Act; second, the deference it affords business decisions concerning internal controls; third, whether a particular state of mind is necessary for a violation to exist; and finally, liability for compliance by subsidiaries.”
As to the “degree of exactitude” Williams stated as follows. “I turn first to the question of whether the Act’s text or purpose mandates that business records and controls conform to a standard of absolute exactitude or that a company’s control system meet some absolute ideal. The answer is ‘no.’ Both of the Act’s accounting provisions, it should be noted are modified by the key term ‘reasonable.’ […] In essence, therefore, the Act does provide a de minimus exemption, though not in absolute quantitative terms.”
Williams noted that Congress specifically declined to adopt a materiality test and stated that “internal accounting controls are not only concerned with misconduct that is material to investors, but also with a great deal of misconduct which is not.” He noted that while materiality is “appropriate as a threshold standard to determine the necessity for disclosure to investors, [it] is totally inadequate as a standard for an internal control system.”
Williams stated that “procedures designed only to uncover deficiencies in amounts material for financial statement purposes would be useless for internal control purposes” and noted that “systems which tolerated omissions or errors of many thousands or even millions of dollars would not represent, by any accepted standard, adequate records and controls.” Indeed, Williams noted that many of the “questionable payments that alarmed the public and caused Congress to act” […] were in most instance of far lesser magnitude than that which would constitute financial statement materiality.”
“Reasonableness, rather than materiality, is the appropriate test,” Williams stated. He noted as follows. “Reasonableness, as a standard, allows flexibility in responding to particular facts and circumstances. Inherent in this concept is a toleration of deviations from the absolute. One measure of the reasonableness of a system relates to whether the expected benefits from improving it would be significantly greater than the anticipated costs of doing so. Thousands of dollars ordinarily should not be spent conserving hundreds. Further, not every procedure which may be individually cost-justifiable need be implemented; the Act allows a range of reasonable judgments.”
As to the “specific recordkeeping requirement” in the FCPA, Williams stated as follows. “… [T]his provision is not an independent unrestrained mandate to the Commission to establish novel or unprecedented corporate recordkeeping standards; it is, rather, an integral part of Congress’ efforts to assure that the business community records transactions and assets in such a way as to maintain adequate control over them. And this leads to two important conclusions: First, the Act does not establish any absolute standard of exactitude for corporate records. And, second, records which are not related to internal or external audits or to the four internal control objectives set forth in the Act are not within the purview of the Act’s accounting provisions.”
As to “deference” with respect to “issuer liability for recordkeeping violations” Williams stated that the SEC “will look to the adequacy of the internal control system of the issuer, the involvement of top management in the violation, and the corrective actions taken once the violation was uncovered.”
In a sign of just how much FCPA enforcement has changed, Williams then stated as follows. “If a violation was committed by a low level employee, without the knowledge of top management, with an adequate system of internal control, and with appropriate corrective action taken by the issuer, we do not believe that any action against the company would be called for.”
Williams next turned to the “state of mind needed to violate the Act’s accounting provisions.” He reiterated that the “Act’s principal purpose is to reach knowing or reckless misconduct.”
In another sign of just how much FCPA enforcement has changed, William stated as follows. “… [D]epending on the circumstances, intentional circumventions of a company’s system of records and of accounting controls by a low-level employee would not always be considered violations of the Act by the issuer. No system of adequate records and controls – no matter how effectively devised or conscientiously applied – could be expected to prevent all mistaken and improper transactions and disposition of assets. Given human nature, regardless of the adequacy of the system, a bookkeeper may still erroneously post entries, an overzealous agent may make unauthorized payments, or an unscrupulous employee may falsify records for his own purposes. The Act recognizes each of these limitations. Neither its text and legislative history nor its purposes suggest that occasional, inadvertent errors were the kind of problem that Congress sought to remedy in passing the Act. No rational federal interest in punishing insignificant mistakes has been articulated. And, the Act’s accounting provisions do not require a company or its senior officials to be the guarantors of all conduct of company employees.”
In concluding this portion of his speech, Williams stated as follows. “The test of a company’s internal control system is not whether occasional failings can occur. Those will happen in the most ideally managed company. But, an adequate system of internal controls means that, when such breaches do arise, they will be isolated rather than systemic, and they will be subject to a reasonable likelihood of being uncovered in a timely manner and then remedied promptly. Barring, of course, the participation or complicity of senior company officials in the deed, when discovery and correction expeditiously follow, no failing in the company’s internal accounting system would have existed. To the contrary, routine discovery and correction would evidence its effectiveness.”
As to subsidiaries, Williams stated as follows. “Where the issuer controls more than 50 percent of the voting securities of the subsidiary, compliance is expected. So, too, would it be expected if there is between 20 percent and 50 percent ownership, subject to some demonstration by the issuer that this does not amount to control. If there is less than 20 percent ownership, we will shoulder the burden to affirmatively demonstrate control.”
As to the SEC’s enforcement policy, Williams concluded his remarks as follows. “The genius – and challenge – of [the FCPA’s accounting provisions] , it should be remembered, is their reliance on private sector decisionmaking – rather than specific federal edicts – to address an area of public concern. The Act’s eventual success or failure will, therefore, depend primarily upon business’s response. The Commission’s obligation, in turn, is to provide a regulatory environment in which the private sector can address these issues meaningfully and creatively. In this regard, we must encourage public companies to develop innovative records and control systems, to modify and improve them as circumstances change, and to correct recordkeeping errors when they occur without a chilling fear of penalty or inference that a violation of the Act is involved.”
The Compliance Defense Around The World
As highlighted in this prior post, numerous FCPA reform bills in the 1980’s included a specific defense which stated a company would not be held vicariously liable for a violation of the FCPA’s anti-bribery provisions by its employees or agents, who were not an officer or director, if the company established procedures reasonably designed to prevent and detect FCPA violations by employees and agents. An FCPA reform bill containing such a provision did pass the U.S. House, but was not enacted into law.
Amending the FCPA to include a compliance defense is one of the U.S. Chamber’s FCPA reform proposals (see here). In November 2010, Andrew Weissman, on behalf of the Chamber, testified in favor of a compliance defense (and other reform proposals) during the Senate’s FCPA hearing (see here for the prior post) and during the House hearing earlier this month (see here for the prior post), former Attorney General Michael Mukasey, on behalf of the Chamber, also testified in favor of a compliance defense (and other reform proposals).
During the House hearing, there appeared to be bi-partisan support for consideration of an FCPA compliance defense.
Even so, Greg Andres, testifying on behalf of the DOJ, stated that a potential FCPA compliance defense was “novel and risky” and that the “time is not right to consider it.”
Public debate on a potential compliance defense has thus far focused, from a comparative standpoint, on the United Kingdom and Italy.
The purpose of this post is to further inform the public debate on a potential compliance defense by highlighting various compliance-like defenses around the world in other countries that are signatories (like the U.S.) to the OECD Anti-Bribery Convention.
This post is further to my work in progress – Revisiting an FCPA Compliance Defense – and represents hours of research analyzing 38 OECD Country Reports.
The post provides an overview of compliance-like defenses in the following OECD Convention signatory countries: Australia, Chile, Germany, Hungary, Italy, Japan, Korea, Poland, Portugal, Sweden, and Switzerland. [The U.K. Bribery Act, set to go live on July 1st, also contains a compliance-like defense in Section 7].
A first reaction might be – only 12 of the 38 OECD member countries have a compliance-like defense.
However, this number must be viewed against the backdrop of the following dynamics: (i) in many OECD Convention signatory countries, the concept of legal person criminal liability (as opposed to natural person criminal liability) is non-existent; and (ii) in many OECD Convention signatory countries that do have legal person criminal liability, such legal person liability can only result from the actions of high-level executive personnel or other so-called “controlling minds” of the legal person.
Obviously if a foreign country does not provide for legal person liability, there is no need for a compliance defense, and the rationale for a compliance defense is less compelling if legal exposure can result only from the conduct of high-level executive personnel or other “controlling minds.”
When properly viewed against these dynamics, a compliance-like defense (whether specifically part of a foreign country’s “FCPA-like” law or otherwise generally part of a foreign country’s legal principles) is far from a “novel” idea, but rather common among OECD Anti-Bribery Convention signatory countries that – like the U.S. – have legal person criminal liability that can attach based on the conduct of non-executive officers or other “controlling minds.”
[The below information is based strictly on OECD country reports and is subject to the qualification that in many instances the most recent information concerning a particular country may be several years old. If anyone has more recent information concerning any particular country, how the compliance defense in a particular country has worked in practice, or any other relevant information, please leave a comment on this site or contact me at mjkoehle@butler.edu]
*****
Australia
Australian law implementing the OECD Convention entered into force on December 18, 1999.
Thereafter, a section of the Criminal Code on corporate criminal liability came into full force establishing an organizational model for the liability of legal persons. “Bodies corporate” are liable for offences committed by “an employee, agent or officer of a body corporate acting within the actual or apparent scope of his or her employment, or within his or her actual or apparent authority” where the body corporate “expressly, tacitly, or impliedly authorised or permitted the commission of the offence”.
Pursuant to the Criminal Code, authorisation or permission by the body corporate may be established in the following ways: (1) the board of directors intentionally, knowingly or recklessly carried out the conduct, or expressly, tacitly or impliedly authorised or permitted it to occur; (2) a high managerial agent intentionally, knowingly or recklessly carried out the conduct, or expressly, tacitly or impliedly authorised or permitted it to occur; (3) a corporate culture existed that directed, encouraged, tolerated or led to the offence; or (4) the body corporate failed to create and maintain a corporate culture that required compliance with the relevant provision.
However, under the Criminal Code, “if a high managerial agent is directly or indirectly involved in the conduct, no offence is committed where the body corporate proves that it “exercised due diligence to prevent the conduct, or the authorisation or permission.”
Chile
Chilean law implementing the OECD Convention entered into force on October 8, 2002.
In December 2009, a separate Chilean law entered into force establishing criminal responsibility of legal persons for a limited list of offences including bribery of foreign public officials.
In order for a legal person to be held responsible for a foreign bribery offence, the following “three cumulative requirements” must be satisfied: (1) the offence must be committed by a person acting as a representative, director or manager, a person exercising powers of administration or supervision, or a person under the “direction or supervision” of one of the aforementioned persons; (2) the offence must be committed for the direct and immediate benefit or interest of the legal entity. No offence is committed where the natural person commits the offence exclusively in his/her own interest or in the interest of a third party; and (3) the offence must have been made possible as a consequence of a failure of the legal entity to comply with its duties of management and supervision. An entity will have failed to comply with its duties if it violates the obligation to implement a model for the prevention of offences, or when having implemented the model, it was insufficient.”
As to the final element, the OECD report states as follows. “The final cumulative requirement for responsibility stresses that the offence must have been made possible as a consequence of the failure of the legal person to comply with its duties of administration and supervision. The entity will have failed to comply with its duties if it violated the obligation to implement a model for the prevention of offences, or when having implemented the model, the latter was insufficient. It shall be considered that the functions of direction and supervision have been met if, before the commission of the offense, the legal person had adopted and implemented organization, administration and supervision models, pursuant to the following article, to prevent such offenses as the one committed.”
The minimum features of a prevention system under the law are as follows: identify the different activities or processes of the entity, whether habitual or sporadic, in whose context the risk of commission of the offences emerges or increases; establish protocols, rules and procedures that permit persons involved in above-mentioned activities or processes to program and implement their tasks or functions in a manner that prevents the commission of the indicated offences; identify procedures for the administration and auditing that allow the entity to impede their use in the listed offences; establish internal administrative sanctions, as well as procedures for reporting or pursuing pecuniary responsibility against persons who violate the prevention system; introduce the above-mentioned duties, prohibitions and sanctions into the internal regulations of the legal person, and ensure that they are known by all persons bound to apply it (workers, employees, and service providers).
The OECD report states – as to the minimum requirements as follows. “It also aims to introduce a system of self-regulation by companies. Having a code of conduct on paper will not be sufficient to avoid responsibility. If prosecutors can prove that the code does not meet the minimum requirements of or that it is not implemented, the company can be responsible for the offence.”
Under Chilean law, “the failure to comply with duties of management and supervision is an element of the offence rather than a defence. Therefore the burden of proof lies on prosecutors, i.e. it will be up to prosecutors to prove that the entity failed to comply with its duties of management and supervision.”
The OECD report notes as follows. “This will require prosecutors to prove that the company failed in the design and/or implementation of the offense prevention model including why, in the circumstances, the prevention model was insufficient. This would appear to also require the prosecutor to establish that this failure made perpetration of the offence possible.”
As noted in the OECD report, the Chilean “standard of liability is inspired from the Italian system of liability of legal persons” (discussed below).
Germany
German law implementing the OECD Convention entered into force on February 15, 1999.
German law establishes the liability of legal persons, including liability for the foreign bribery offence, under an administrative (i.e. non-criminal form) act.
Pursuant to the administrative act, “the liability of legal persons is triggered where any “responsible person” (which includes a broad range of senior managerial stakeholders and not only an authorised representative or manager), acting for the management of the entity commits i) a criminal offence including bribery; or ii) an administrative offence including a violation of supervisory duties which either violates duties of the legal entity, or by which the legal entity gained or was supposed to gain a “profit”.”
As noted in the OECD report, “in other words, Germany enables corporations to be imputed with offences i) by senior managers, and, somewhat indirectly, ii) with offences by lower level personnel which result from a failure by a senior corporate figure to faithfully discharge his/her duties of supervision.”
The OECD report states that the “standards for a violation of supervisory duties include consideration of factors such as whether the company has in place a monitoring system or in-house regulations for employees.”
Hungary
Hungarian law implementing the OECD Convention entered into force on March 1, 1999.
In 2004, a separate law was enacted specifying the individuals whose actions can trigger the liability of the legal person.
The OECD report states as follows. “The specific persons and additional conditions for liability are defined as follows: (i) the bribery is committed by one of the members or officers [of the legal entity] entitled to manage or represent it, or a supervisory board member and/or their representatives acting within the legal scope of activity of the legal person ; (ii) the bribery is committed by one of the members of the legal entity or an employee acting within the legal scope of activity of the legal person provided the bribery could have been prevented by the chief executive fulfilling his supervisory or control obligations; and (iii) the bribery is committed by a third party individual, provided that the legal entity’s member or officer entitled to manage or represent the it had knowledge of the facts.”
According to the OECD report, the relevant law does not provide any guidance as to the necessary degree of supervision to avoid liability for bribery.
Italy
Italian law implementing the OECD Convention entered into force on October 26, 2000.
Under Italian law, “criminal liability cannot be attributed to legal persons” however, “administrative liability may be attributed to legal persons for certain criminal offences (including foreign bribery) committed by a natural person.
The relevant administrative decree provides a “defence of organisational models” to a body which makes reasonable efforts to prevent the commission of an offence.
The OECD report states as follows. “… [A] body is not liable for offences committed by persons in senior positions if it proves the following. First, before the offence was committed, the body’s management had adopted and effectively implemented an appropriate organisational and management model to prevent offences of the kind that has occurred. Second, the body had set up an autonomous organ to supervise, enforce and update the model. Third, this autonomous organ had sufficiently supervised the operation of the model. Fourth, the perpetrator committed the offence by fraudulently evading the operation of the model.” The defence of organisation models operates as a full defence which completely exculpates a legal person.
The relevant administrative decree stipulates the essential elements of an acceptable organisational model described in the OECD report as follows. “First, the model must identify activities which may give rise to offences. Second, the model must define procedures through which the body makes and implements decisions relating to the offences to be prevented. It must also prescribe procedures for managing financial resources to prevent offences from being committed. Third, the model must oblige the internal organ responsible for supervision and enforcement to provide information to the body. Finally, the model must include a disciplinary system for non-compliance.”
Japan
Japanese law implementing the OECD Convention entered into force on February 15, 1999 .
“Under Japanese law, criminal responsibility of a legal person is based on the principle that the company did not exercise due care in the supervision, selection, etc. of an officer or employee to prevent the culpable act.
The burden rests on the legal person to prove that due care was exercised. Where a legal person raises the defence, a person must be identified as having exercised due care, etc., and the court must determine whether it was exercised properly having regard to the nature of the legal person and the circumstances of the case.”
Korea
Korean law implementing the OECD Convention entered into force on February 15, 1999.
Korean law establishes the criminal responsibility of legal persons for the bribery of a foreign public official, however, a legal person is exempt from liability where it has paid “due attention” or exercised “proper supervision” to prevent the offence.
The statute itself does not provide information about what constitutes “due attention” or “proper supervision.” A representative of the Supreme Public Prosecutor’s Office informed the OECD that “the exemption is triggered when a director or ‘superior person’ exercises due attention.” The Explanatory Manual published by the Ministry of Justice states that “it is difficult to standardize the extent of attention or supervision in deciding whether a legal person can be exempted from criminal punishment.” The Explanatory Manual further states that whether the exemption applies depends upon “general circumstances such as the motive and background that led to the bribery, intervention of exclusive members of the legal person, whether it was informed earlier, and how much effort was usually made by the corporation to prevent bribery, etc.” and that companies involved in international business must prevent violations of the law by all employees and executives of the company “through sufficient necessary management”.
Poland
Polish law implementing the OECD Convention entered into force on February 4, 2001.
Polish law provides “a noncriminal form of responsibility for collective entities.” Among the requirements for liability is the offence was committed “in the effect of at least absence of due diligence in electing the natural person [committing the act] or of at least the absence of due supervision over this person by an authority or a representative of the collective entity.”
According to the relevant Polish legislative history, “the perpetration of a prohibited act by a natural person will trigger liability of the
collective entity where the act occurred as a result of negligence on the part of the authority or representative of the collective entity.”
Portugal
Portuguese law implementing the OECD Convention entered into force on June 9, 2001.
Under Portuguese law relevant to corruption in international business transactions, legal persons can be liable for conduct committed “on their behalf and in the collective interest by natural persons occupying a leadership position within the legal person structure” or by “whoever acts under the authority” of such natural persons.
However, “[t]he liability of legal persons and equivalent entities is excluded when the actor has acted against the orders or express instructions of the person responsible.”
Sweden
Swedish law implementing the OECD Convention entered into force on July 1, 1999.
Under Swedish Law, only natural persons can commit crimes. However, pursuant to the Swedish Penal Code, a “kind of quasi-criminal liability is applied to an ‘entrepreneur’ (a general term meaning “any natural or legal person that professionally runs a business of an economic nature) for a ‘crime committed in the exercise of business activities.’”
However, one requirement under the Penal Code is that “the entrepreneur has not done what could reasonable be required of him for prevention of the crime.”
Switzerland
Swiss law implementing the OECD Convention entered into force on May 1, 2000.
Article 100quater of the Swiss Criminal Code requires “defective organisation as a condition for corporate criminal liability.”
In order to incur criminal liability, “the enterprise must not have taken all reasonable and necessary organisational measures to prevent the individual from committing the offence.”
Under Swiss law, the burden is on the prosecutor to furnish proof of defective organization and according to Swiss authorities contacted by the OECD “steps should be taken to assess whether employees have been sufficiently informed, supervised and controlled” and “the fact that an enterprise is organised in compliance with international management standards will not be sufficient to rule out all liability on its part; it will be one element to take into consideration among others …”. In the view of Swiss authorities, “ shifting the burden of proof in criminal cases would contravene Article 6 of the European Convention on Human Rights.”