A Focus On SEC FCPA Individual Actions
Posts earlier this week (here and here) highlighted various facts and figures concerning DOJ FCPA individual prosecutions. This post focuses on SEC FCPA individual actions.
Like the DOJ, the SEC frequently speaks in lofty rhetoric concerning its focus on holding individuals accountable under the FCPA. For instance, in connection with the recent Garth Peterson enforcement action, Robert Khuzami (then Director of the SEC’s Division of Enforcement) stated (here) that the case “illustrates the SEC’s commitment to holding individuals accountable for FCPA violations.” Likewise, in connection with the 2011 SEC action against Paul Jennings, Cheryl Scarboro (then Chief of the SEC’s Foreign Corrupt Practices Act Unit) stated (here) that the SEC “will vigorously hold accountable” individuals for FCPA violations.
Since 2005, the SEC has charged 49 individuals with FCPA civil offenses. The breakdown is as follows.
- 2005 – 1 individual
- 2006 – 8 individuals
- 2007 – 7 individuals
- 2008 – 5 individuals
- 2009 – 5 individuals
- 2010 – 7 individuals
- 2011 – 12 individuals
- 2012 – 4 individuals
Similar to the prior DOJ figures, most of the individuals charged – 33 (or 67%) were charged since 2008. Thus, on one level the SEC is correct when it states that individual prosecutions are a focus at least as measured against the historical average given that between 1978 and 2004 the SEC charged 32 individuals with FCPA civil offenses.
Yet on another level, a more meaningful level given that there was much less overall enforcement of the FCPA between 1978 and 2004, the SEC’s statements (like the prior DOJ statements about its focus on individuals) represent hollow rhetoric as demonstrated by the below figures.
Of the 33 individuals charged with civil FCPA offenses by the SEC since 2008:
- 7 individuals were in the Siemens case;
- 4 individuals were in the Willbros Group case;
- 4 individuals were in the Alliance One case;
- 3 individuals were in the Maygar Telekom case; and
- 3 individuals were in the Noble Corp. case.
In other words, 64% of the individuals charged by the SEC with FCPA civil offenses since 2008 have been in just five cases.
Considering that there has been 57 corporate SEC FCPA enforcement actions since 2008, this is a rather remarkable statistic. Of the 57 corporate SEC FCPA enforcement actions, 45 (or 79%) have not (at least yet) resulted in any SEC charges against company employees. This figure is thus higher than the 74% figure (here) highlighted earlier this week regarding the DOJ. This is notable given that the SEC, as a civil law enforcement agency, has a lower burden of proof in an enforcement action.
Once again, like with the DOJ figures, one can ask the “but nobody was charged” question.
Yet, like with the DOJ figures and as highlighted in yesterday’s post (here), there is an equally plausible reason why so few individuals have been charged in connection with many corporate SEC FCPA enforcement actions. The reason has to do with the quality and legitimacy of the corporate enforcement action in the first place.
With the SEC, the issue is not so much NPAs or DPAs (the SEC has used such a vehicle just once to resolve an FCPA enforcement action – Tenaris 2011), but rather the SEC’s neither admit nor deny settlement policy. For more on this policy and its impact of SEC enforcement actions, see pgs. 946-955 of my article “The Facade of FCPA Enforcement.” In the article, I discuss the affidavit of Professor Joseph Grundfest (Standford Law School and former SEC Commissioner) in SEC v. Bank of America and how SEC enforcement actions “typically omit mention of valid defenses and of countervailing facts or mitigating circumstances that, if proven at trial, could cause the Commission to lose it case.” In the article, I also discuss the SEC’s frank admission in the Bank of America case that a settled SEC enforcement action “does not necessarily reflect the triumph of one party’s position over the other.” Individuals in an SEC FCPA enforcement, even if only a civil action, and even if allowed to settle on similar neither admit nor deny terms, have their personal reputation at stake and are thus more likely than corporate entities to challenge the SEC and force it satisfy its burden of proof at trial as to all FCPA elements.
In other words, and like in the DOJ context, perhaps the more appropriate question is not “but nobody was charged,” but rather – do SEC neither admit nor deny FCPA settlements represent provable FCPA violations.
It is also interesting to analyze the 12 instances since 2008 where an SEC corporate FCPA enforcement action resulted in related charges against company employees. With the exception of Siemens, KBR/Halliburton and Magyar Telekom, the corporate SEC FCPA enforcement actions resulting in related charges against company employees occurred in what can only be described as relatively minor (at least from a settlement amount perspective) corporate enforcement actions. These actions are: Faro Technologies, Willbros Group, Nature’s Sunshine Products, United Industrial Corp., Pride Int’l., Noble Corp., Alliance One, Innospec, and Watts Water.
[Note – the above data was assembled using the “core” approach as well as the definition of an FCPA enforcement action described in this prior post]
DOJ Prosecution Of Individuals – Are Other Factors At Play?
Yesterday’s post (here) focused on DOJ FCPA individual prosecutions and highlighted the following facts and figures.
- Since 2008, the DOJ has charged 77 individuals with FCPA criminal offenses.
- 61% of the individuals charged by the DOJ with FCPA criminal offenses since 2008 have been in just four cases and 77% of the individuals charged by the DOJ since 2008 have been in just seven cases.
- There have been 53 corporate DOJ FCPA enforcement actions since 2008 and of the 53 corporate DOJ FCPA enforcement actions, 39 (or 74%) have not (at least yet) resulted in any DOJ charges against company employees.
These statistics should cause alarm, including at the DOJ as it has long recognized that a corporate-fine only enforcement program is not effective and does not adequately deter future FCPA violations. For instance, in 1986 John Keeney (Deputy Assistant Attorney General, Criminal Division, DOJ) submitted written responses in the context of Senate hearings concerning a bill to amend the FCPA. He stated as follows:
“If the risk of conduct in violation of the statute becomes merely monetary, the fine will simply become a cost of doing business, payable only upon being caught and in many instances, it will be only a fraction of the profit acquired from the corrupt activity. Absent the threat of incarceration, there may no longer be any compelling need to resist the urge to acquire business in any way possible.”
Likewise, in 2010 Hank Walther (Deputy Chief Fraud Section) stated that a corporate fine-only FCPA enforcement program allows companies to calculate FCPA settlements as the cost of doing business.
In my 2010 Senate FCPA testimony (here), I noted that the absence of individual FCPA charges in most corporate FCPA enforcement actions causes one to legitimately wonder whether the conduct giving rise to the corporate enforcement action was engaged in by ghosts. Others have rightly asked the “but nobody was charged” question, including perhaps most notably James Stewart in a New York Times column highlighted in this previous post.
However, as I stated in my Senate testimony, there is an equally plausible reason why no individuals have been charged in connection with many corporate FCPA enforcement actions. The reason has to do with the quality and legitimacy of the corporate enforcement action in the first place. Readers know well of the prevalence of non-prosecution and deferred prosecution agreements (NPA / DPA) in the FCPA context and how these agreements, not subject to any meaningful judicial scrutiny, are often agreed to by companies for reasons of ease and efficiency, and not necessarily because the conduct at issue violates the FCPA. For more on this dynamic, see my article “The Facade of FCPA Enforcement.” Individuals, on the other hand, face a deprivation of personal liberty, and are more likely to force the DOJ to satisfy its high burden of proof as to all FCPA elements.
In other words, perhaps the more appropriate question is not “but nobody was charged,” but rather do NPA and DPAs always represent provable FCPA violations.
I set out to test this with the following working hypothesis. Instances in which the DOJ brings actual criminal charges against a company or otherwise insists in the resolution context that the corporate entity pleads guilty to FCPA violations, represent a higher quality FCPA enforcement action (in the eyes of the DOJ) and is thus more likely to result in related FCPA criminal charges against company employees. Instances in which the DOJ resolves an FCPA enforcement action solely with an NPA or DPA, represent a lower quality FCPA enforcement action and is thus less likely to result in related FCPA criminal charges against company employees given that an individual is more likely to put the DOJ to its high burden of proof.
The below statistics provide a compelling datapoint concerning the quality and legitimacy of many corporate DOJ FCPA enforcement actions.
Since NPAs and DPAs were first introduced to the FCPA context in December 2004 (see here), there have been 69 corporate DOJ FCPA enforcement actions.
-
12 of these corporate enforcement actions were the result of a criminal indictment or resulted in a guilty plea by the corporate entity to FCPA violations. 10 of these corporate enforcement actions – 83% – resulted in related criminal charges of company employees.
-
46 of these corporate enforcement actions were resolved solely with an NPA or DPA. In only 3 instances – 6.5% – were there related criminal charges of company employees.
-
A third type of corporate FCPA enforcement action is what I will call a hybrid action in which the resolution includes a guilty plea by some entity in the corporate family – usually the relevant foreign subsidiary – and an NPA or DPA against the parent company. Since the advent of NPAs and DPAs in the FCPA context, there have been 11 such corporate enforcement actions. In 3 of these actions – 27% – there were related criminal charges of company employees. This percentage is what one might expect compared to the two types of corporate FCPA enforcement actions discussed above, although it is interesting to note the following regarding these three instances. The DOJ ended up dismissing the charges against Si Chan Wooh (Schnitzer Steel), John O’Shea (ABB) was not found not guilty, and Bobby Elkin (Alliance One) received a probation sentence after the sentencing judge questioned many aspects of the enforcement action (see here for the prior post).
If the above statistics do not cause you to question the quality and legitimacy of many corporate FCPA enforcement actions, no empirical data ever will. For those who believe NPAs and DPAs always represent provable FCPA violations, the ball is now in your court to offer credible explanations for following datapoints.
If a corporate DOJ FCPA enforcement action is the result of a criminal indictment or resulted in a guilty plea by the corporate entity to FCPA violations, there is a 83% chance that related criminal charges will be brought against a company employee. If a corporate DOJ FCPA enforcement action is resolved solely with an NPA or DPA, there is a 6.5% chance that criminal charges will be brought against a company employee.
[Note – the above data was assembled using the “core” approach as well as the definition of an FCPA enforcement action described in this prior post]
A Focus On DOJ FCPA Individual Prosecutions
This post updates various facts and figures first published in September 2011 (see here, here) concerning the DOJ’s prosecution of individuals for FCPA offenses.
Since 2005, the DOJ has charged 93 individuals with FCPA criminal offenses. The breakdown is as follows.
- 2005 – 3 individuals
- 2006 – 6 individuals
- 2007 – 7 individuals
- 2008 – 14 individuals
- 2009 – 18 individuals
- 2010 – 33 individuals (including 22 in the Africa Sting case)
- 2011 – 10 individuals
- 2012 – 2 individuals
An analysis of the numbers reveals some interesting points.
Most of the individuals – 77 (or 83%) were charged since 2008. Thus, on one level the DOJ is correct when it states that individual prosecutions are a “cornerstone” of its FCPA enforcement strategy and that it has been “vigorous about holding individuals accountable” – at least as measured against the historical average given that between 1978 and 2004, the DOJ charged 53 individuals with FCPA criminal offenses.
Yet on another level, a more meaningful level given that there was much less overall enforcement of the FCPA between 1978 and 2004, the DOJ’s statements about its focus on individuals represents hollow rhetoric as demonstrated by the below figures.
Of the 77 individuals criminally charged with FCPA offenses by the DOJ since 2008:
- 22 individuals were in the Africa Sting case;
- 9 individuals (minus the “foreign officials” charged) were in the Haiti Teleco case;
- 8 individuals were in the Control Components case;
- 8 individuals were in the Siemens case;
- 4 individuals were in the Lindsey Manufacturing case;
- 4 individuals were in the LatinNode / Hondutel case; and
- 4 individuals were in the Nexus Technologies case.
In other words, 61% of the individuals charged by the DOJ with FCPA criminal offenses since 2008 have been in just four cases and 77% of the individuals charged by the DOJ since 2008 have been in just seven cases.
Considering that there has been 53 corporate DOJ FCPA enforcement actions since 2008, this is a rather remarkable statistic. Of the 53 corporate DOJ FCPA enforcement actions, 39 (or 74%) have not (at least yet) resulted in any DOJ charges against company employees.
In recent years, the DOJ has consistently stated that prosecution of individuals is a “cornerstone” of its FCPA enforcement strategy. For instance, in a November 2012 speech (see here for the prior post), Assistant Attorney General Lanny Breuer stated as follows. “If you look at the FCPA over the past 4 years, you’ll see we really have been vigorous about holding individuals accountable.”
Yet, the above numbers paint a different picture, a very different picture – at least in certain enforcement actions. What type of enforcement actions?
A very interesting and significant picture emerges when analyzing DOJ individual prosecution data based on whether the corporate entity employing or otherwise involved with the individual charged was a public or private entity.
Of the 77 individuals charged by the DOJ with FCPA criminal offenses since 2008, 54 of the individuals (70%) were employees or otherwise affiliated with private business entities. This is a striking statistic given that 42 of the 53 corporate DOJ FCPA enforcement actions since 2008 (79%) were against publicly traded corporations.
In the 11 private entity DOJ FCPA enforcement actions since 2008, individuals were charged in connection with 6 of those cases (55%). In contrast, in the 42 public entity DOJ FCPA enforcement actions since 2008, individuals were charged in connection with 8 of those cases (19%). In short, and based on the data, a private entity DOJ FCPA enforcement is approximately three times more likely to have a related DOJ FCPA criminal prosecution of an individual than a public entity DOJ FCPA enforcement action.
[Notes – the above data was assembled using the “core” approach – see this prior post for an explanation. The term “public entity” is not limited to “issuers” under the FCPA, but rather a public entity regardless of which market it shares trade on. Thus, for instance, JGC Corp. of Japan and Bridgestone are both public entities even though its shares are not traded on a U.S. exchange.]
Keeping FCPA Enforcement Statistics In Perspective
The below chart provides a summary of corporate FCPA enforcement data (DOJ and SEC combined) for the years 2007-2012, as well as notable circumstances that significantly skewed enforcement data statistics for a particular year. (The below data was assembled using the “core” approach – see this prior post for an explanation).
Corporate FCPA Enforcement Actions (2007-2012)
|
Year
|
Enforcement Actions
|
Settlement Amounts
|
Of Note
|
|
2007
|
15
|
$149 million
|
Six enforcement actions involved Iraq Oil for Food conduct and these enforcement actions comprised 40% of all enforcement actions and approximately 50% of the $149 million amount. |
|
2008
|
10
|
$885 million
|
The $800 million Siemens enforcement action comprised approximately 90% of the $885 million amount. |
|
2009
|
11
|
$645 million
|
The $579 million KBR / Halliburton Bonny Island, Nigeria enforcement action comprised approximately 90% of the $645 million amount. |
|
2010
|
21
|
$1.4 billion
|
Six enforcement actions, all resolved on the same day, centered on various oil and gas companies use Panalpina in Nigeria. Panalpina also resolved an enforcement action on the same day.Two enforcement actions (Technip and Eni / Snamprogetti) involved Bonny Island conduct. In other words, there were 14 unique corporate enforcement actions in 2010. Of further note, the two Bonny Island enforcement actions, Technip($338 million) and Eni/Snamprogetti ($365 million) comprised approximately 50% of the $1.4 billion amount. |
|
2011
|
16
|
$503 million
|
The $219 million JGC Corp. Bonny Island, Nigeria enforcement action comprised approximately 44% of the $503 million amount |
|
2012
|
12
|
$260 million
|
None that significantly skewed the statistics. |
| TOTAL: 85 | TOTAL: $3.9 billion |
As demonstrated by the above chart, 2010 was the apex of FCPA enforcement, both in terms of the number of enforcement actions and settlement amounts. FCPA enforcement in 2012 was less than in 2011, and FCPA enforcement in 2011 was less than in 2010.
Industry participants have offered various reasons for the decrease in FCPA enforcement in 2012 – all speculative and not empirically based.
What is not speculative and what is empirically based is an analysis of how just a few unique historical events had a significant impact on FCPA enforcement data between 2007 and 2011 and how these events place 2012 FCPA enforcement data in a proper context.
The events, as suggested by the above chart, are the following: (i) publication in 2005 of the so-called Volcker Report on the United Nations Iraq Oil for Food Program which served as a ready-made list of enforcement actions; (ii) in 2003 Georges Krammer, a former top official at Technip, shared information with French investigators concerning a $6 billion dollar project at Bonny Island, Nigeria; and (iii) several oil and gas companies utilized the services of Panalpina.
As indicated in the below charts, these unique historical events had a significant impact on FCPA enforcement data between 2007 and 2011.
Corporate FCPA Enforcement Actions Based on Iraq Oil For Food Conduct (2007-2011)
|
Enforcement Actions
|
Total Enforcement Action Percentage
|
Settlement Amounts
|
Total Settlement Amount Percentage
|
|
14
|
19%
|
$267 million
|
7%
|
Corporate Bonny Island, Nigeria FCPA Enforcement Actions (2007-2011)
|
Enforcement Actions
|
Total Enforcement Action Percentage
|
Settlement Amounts
|
Total Settlement Amount Percentage
|
|
4
|
5%
|
$1.5 billion
|
41%
|
Corporate Panalpina Related FCPA Enforcement Actions (2007-2011)
|
Enforcement Actions
|
Total Enforcement Action Percentage
|
Settlement Amounts
|
Total Settlement Amount Percentage
|
|
8
|
11%
|
$262 million
|
7%
|
As demonstrated by the above charts, the combined effect of just three unique historical events – Iraq Oil for Food, Bonny Island conduct, and use of Panalpina – had a significant impact on FCPA enforcement data between 2007 and 2011. These events served as the foundation for 35% of all corporate enforcement actions between 2007-2011 and resulted in 55% of the settlement amounts in corporate enforcement actions between 2007-2011.
Adding just the 2008 Siemens enforcement action to the settlement amount calculation, results in just four unique historical events accounting for 77% of settlement amounts in corporate enforcement actions between 2007-2011.
While the January 2012 FCPA enforcement action against Marubeni did involve Bonny Island conduct, the unique events identified above have run their course. Recognizing these events and how they impacted FCPA enforcement data is important to understanding why FCPA enforcement has declined in recent years.
Even though FCPA enforcement has declined in recent years, unique events giving rise to FCPA enforcement actions have remained relatively constant between 2007 and 2012. In 2007, corporate FCPA enforcement actions were the result of 15 unique events. In 2008, corporate FCPA enforcement actions were the result of 10 unique events. In 2009, corporate FCPA enforcement actions were the result of 11 unique events. In 2010, corporate FCPA enforcement actions were the result of 14 unique events. In 2011, corporate FCPA enforcement actions were the result of 16 unique events. In 2012, corporate FCPA enforcement actions were the result of 12 unique events.
What Is An FCPA Enforcement Action?
Posts later this week will be devoted to 2012 FCPA enforcement statistics. Many of the statistics were calculated based on the number of corporate FCPA enforcement actions in 2012.
But what is a Foreign Corrupt Practices Act enforcement action? Let’s start the New Year off with this basic question.
It is a difficult question and an important question given the increase in FCPA Inc. statistical information and the growing interest in empirical FCPA-related research.
How one answers the question is materially significant as it determines the denominator in almost every FCPA computation. How one answers the question impacts everything from “how many FCPA enforcement actions are there,” to “what country is the site of the most FCPA enforcement actions,” to “what percentage of FCPA enforcement are resolved via non-prosecution or deferred prosecution agreements,” to “what percentage of FCPA enforcement actions involve related individual enforcement actions,” to “what is the average fine/penalty amount in an FCPA enforcement action” and many, many other issues.
How one answers the question may depend on one’s objective and motivation – for instance, is an FCPA Inc. participate marketing its FCPA services in which case more FCPA enforcement actions may be a good thing? It is not just for-profit industry participants who seemingly have an objective and motivation in categorizing FCPA enforcement actions a certain way. For instance, the DOJ and SEC would seem to have an incentive to liberally count more FCPA enforcement actions than conservatively to perhaps achieve a deterrent effect. Likewise, the DOJ and SEC would seem to have the same incentive knowing that its enforcement record will be judged by civil society monitoring organizations. For instance, did you know that Transparency International’s 2012 Progress Report shows (see here at Table A) that the U.S. (since 1999 – the year the OECD Convention entered into force in the U.S.), has brought 275 “total [FCPA] cases.” One can only achieve a number like that with creative counting methods.
In this post, my goal is to improve the quality and reliability of FCPA statistics and related information. Pursuant to this goal, I discuss various ways, using real enforcement actions, to answer the difficult question of what is an FCPA enforcement action. I then conclude the post with suggested criteria for what is an FCPA enforcement action.
The “Core” Approach
I have long kept my corporate FCPA enforcement statistics by using what I’ve termed the “core” approach. The core approaches focuses on corporate conduct at issue regardless of whether the conduct at issue involves a DOJ or SEC enforcement action or both (as is frequently the case), regardless of whether the corporate enforcement action involves a parent company, a subsidiary or both (as is frequency the case), and regardless of whether the DOJ and/or SEC bring any related individual enforcement actions (as is occasionally the case).
To demonstrate the core approach and its impact on the quality and reliability of FCPA enforcement statistics, consider the Siemens enforcement action. In 2008, the DOJ and SEC brought related corporate enforcement actions. The DOJ component included an action against Siemens AG and separate enforcement actions against Siemens Argentina, Siemens Bangladesh, and Siemens Venezuela. The SEC component included an action against Siemens AG. In 2011, the DOJ brought a related enforcement action against 8 individuals and the SEC brought a related enforcement action against 7 individuals. All of the enforcement actions were based, in whole or in part, on the same core set of corporate conduct.
Does the above paragraph describe 1 “core” enforcement action or 20 different enforcement actions? You can see how just using the Siemens example, the denominator in any calculation will be significantly impacted by the answer. In my mind, the above paragraph describes 1 “core” enforcement action, but many others (perhaps because of the objectives and motivations discussed above) categorize Siemens as 20 enforcement actions – a highly misleading data point in my opinion. For instance, and assuming that the Siemens corporate enforcement actions comprise the entire universe of corporate FCPA enforcement actions, using a non-core approach, the average fine/penalty amount would be $160 million with a median fine and penalty amount of $500,000. However, using the core approach, the Siemens corporate enforcement action resulted in $800 million in fine and penalty amounts.
Take the Africa Sting case as another example. In January 2010, the DOJ announced a manufactured enforcement action against 22 individuals. All individuals were alleged to have engaged in the same “core” conduct. Is the Africa Sting enforcement action 1 “core” enforcement action or 22 different enforcement actions? If you have seen many of the charts and graphs published by FCPA Inc. and have noticed the spike in FCPA enforcement actions in 2010, you know that many in the industry count the Africa Sting case as 22 actions. Again, how you answer this question will significantly impact the denominator in any calculation. For instance, if the Africa Sting enforcement actions are counted as 22 different enforcement actions, Gabon is all of a sudden the site of the most FCPA enforcement activity in recent years – a highly misleading data point.
In short, depending on one’s methodology and using just the Siemens enforcement action and the Africa Sting enforcement action, these instances were either 2 enforcement actions or 42 enforcement actions.
High quality and reliable FCPA enforcement statistics, reflecting what is really occurring and without distorting reality, are best achieved by using the “core” approach and categorizing the Siemens enforcement action and the Africa Sting enforcement action as 2 enforcement actions, not 42 enforcement actions.
Non Prosecution and Deferred Prosecution Agreements
For most of the FCPA’s history, the DOJ did one of two things when resolving an instance of FCPA scrutiny. One option was that a corporate entity was actually charged (whether via a criminal indictment or more often via a criminal information) with an FCPA offense and the entity pleaded guilty via a plea agreement or mounted a legal defense (something that has only happened twice in FCPA history in the corporate context). The other option was that the DOJ did not charge or prosecute the corporate entity and there was no enforcement action.
However, in 2004, non-prosecution and deferred prosecution agreements were introduced to FCPA enforcement.
Should NPAs (in which criminal charges are not filed against a company) or DPAs (in which criminal charges are technically filed but not actually prosecuted) count as FCPA enforcement actions?
The short answer is that if NPAs and DPAs were not counted, there would be very, very few corporate FCPA enforcement actions. In recent years, these resolution vehicles have been used in approximately 70%-100% of corporate FCPA enforcement actions in any given year.
Enforcement Actions That Do Not Include Anti-Bribery Charges or Findings
Should an FCPA enforcement action be only those that involve anti-bribery charges or findings (as in the case of non-prosecution agreements and SEC administrative orders)?
In many instances, the enforcement agencies (DOJ or SEC) allege conduct that would seem to implicate the FCPA’s anti-bribery provisions. However, because the resolution occurs in the context of a negotiated settlement, because the enforcement agencies say they seek to reward voluntary disclosures and cooperation, and because FCPA anti-bribery charges or findings could have potential negative collateral consequences for the company, the enforcement agencies are are often content in resolving the action without actual FCPA anti-bribery charges. For instance, Siemens and Daimler were never charged with FCPA anti-bribery violations.
Stated differently, should FCPA books and records and internal control charges only (whether criminal or civil) count as an FCPA enforcement action? Statistically, this is a very important question given the number of Iraqi Oil for Food Cases – actions that, for the most part, did not involve FCPA anti-bribery charges or findings because the kickback payments were made to a foreign government not a “foreign official.” (See note 115 of the FCPA Guidance for the DOJ/SEC’s similar explanation).
Most people will say “yes,” enforcement actions involving FCPA books and records and internal controls charges or findings do represent FCPA enforcement actions. However, in order to be consistent and intellectually honest, would not all FCPA books and records and internal control charges or findings have to be considered an FCPA enforcement action? Recall that the FCPA books and records and internal control provisions are completely generic and can apply in purely domestic cases that have nothing to do with bribery and corruption. (See here for a prior post for what I’ve called “non-FCPA, FCPA enforcement actions”). As to these numerous non-FCPA, FCPA enforcement actions (according to one estimate, see here – figure 3, since 1977 there have been approximately 1,000 such actions), not even the SEC includes such actions on its FCPA website.
Enforcement Actions That Do Not Include Any FCPA Charges
As you likely know, FCPA Inc. (as well as the DOJ) classify the BAE enforcement action as an FCPA enforcement and it is included in many FCPA top-ten lists (see here for example).
But why?
BAE was not charged with any FCPA offenses (the conventional wisdom is because of the negative collateral consequences such charges could have resulted in for the defense contractor) even though the alleged facts in the DOJ enforcement action would seem to implicate the FCPA’s anti-bribery provisions.
If enforcement actions that do not result in any FCPA charges or findings are included, to be consistent and intellectually honest, would not all enforcement actions that allege facts that would seem to implicate the FCPA have to be considered an FCPA enforcement action? For instance, the recent DOJ enforcement action against APEGO Group and its executives (see here for the prior post) alleged foreign bribery and corruption but did not result in any FCPA charges. Same thing with the DOJ’s prosecution of R. Allen Stanford (see here for indictment).
What is the reasoned rationale for including the BAE enforcement action as an FCPA enforcement action, but not these other enforcement actions?
Now that we are all dizzy thinking about the seemingly easy question of what is an FCPA enforcement action, let’s return to the original question. What is an FCPA enforcement action?
In an effort to improve the quality and reliability of FCPA statistics and related information, I offer the following criteria for what is an FCPA enforcement action.
(1) An FCPA enforcement action is an instance in which an enforcement agency (whether DOJ or SEC) charges or finds that the FCPA (whether its anti-bribery, books and records, or internal controls provisions) has been violated.
(2) As to FCPA books and records or internal control charges or findings, such actions are only FCPA enforcement actions to the extent categorized as such by either the DOJ or SEC on its FCPA websites.
(3) As to each instance of conduct meeting the above criteria, the “core” approach is to be used in quantifying the number of FCPA enforcement actions.
(4) If an instance of conduct does not meet the above criteria for any reasons (such as an instance of an enforcement action that does not include FCPA charges or findings), the person or organization including such an instance in FCPA enforcement statistics should, in a transparent way, explain the rationale for including such an instance as an FCPA enforcement action.
High quality and reliable FCPA enforcement statistics, reflecting what is really occurring and without distorting reality, are best achieved by following the above criteria.