Quotable

“What is an internal accounting controls violation? Anything that the SEC staff thinks—and three out of five Commissioners agree—is a righteous case and to which a public company is willing to settle.”
A good read here from Walker Newell (Woodruff Sawyer and former Senior Counsel in the SEC’s Division of Enforcement in San Francisco) titled “Uncooked Books: Avoiding SEC Accounting Scrutiny.” The article discusses recent trends in the SEC’s accounting enforcement activities.
As stated in the article:
“Hey, Look, There’s A Hoof Cleaner!” – SEC Commissioners Again Criticize Recent Internal Controls Enforcement Theory

Yesterday’s post highlighted the SEC’s enforcement action against R.R. Donnelley & Sons Company (RRD) and how – in the non-FCPA, FCPA enforcement action – the SEC “pushed the internal controls envelope” in connection with a cybersecurity breach at the company. In prior recent enforcement actions against SolarWinds and Charter Communications, the SEC also “pushed the internal controls envelope.” (See here and here).
In connection with the Charter Communications matter, SEC Commissioners Hester Peirce (appointed by President Trump) and Mark Uyeda (appointed by President Biden) issued a blistering statement criticizing the SEC’s internal controls enforcement theory by stating that the SEC “does not have authority to tell companies how to run themselves – but [the SEC is] now routinely us[ing] the internal controls provisions to do just that.”
In connection with the RRD matter, Commissions Peirce and Uyeda once again criticized the SEC’s internal controls theory of enforcement and stated that the SEC “stretch[ed] the law to punish a company that was the victim of a cyberattack” and “distort[ed] a statutory provision.”
The SEC Continues To Push The Internal Controls Envelope

To push the envelope means to surpass normal limits or attempt something viewed as radical or risky.
The FCPA’s enforcement agencies (the DOJ and SEC) have long pushed the envelope and enforcement agency officials may think – why not – a risk averse company is often going to cough up millions of dollars just to make us go away regardless of the underlying enforcement theory.
As highlighted in this prior post, in November 2023, Charter Communications agreed to cough up $25 million in a non-FCPA, FCPA enforcement action in which the SEC found that the company violated the FCPA’s internal controls provisions in connection with stock buybacks.
“[The SEC’s] Theory Of Internal Accounting Controls Violations Amounts To A Wholesale Rewriting Of The Law”

This previous post highlighted the SEC’s “non-FCPA, FCPA enforcement action” (that is an enforcement action that charges violations of the FCPA’s books and records and/or internal controls provisions yet has nothing to do with foreign bribery) against SolarWinds Corporation and various individuals based on, among other things, control failures related to allegedly known cybersecurity risks and vulnerabilities.
The post was one of just several in recent years to highlight the SEC’s unhinged theory of enforcement regarding the FCPA’s internal controls provisions (see here, here, here, here, here, here, here, here and here for instance).
Unlike most issuers which roll over and play dead when the SEC has an expansive legal theory, the defendants are mounting a defense – and this is good from the perspective of case law development of the FCPA’s internal controls provisions.
Issues To Consider From The SAP Enforcement Action

This previous post highlighted the recent FCPA enforcement action against SAP based on conduct in South Africa, Indonesia, Malawi, Kenya, Tanzania, Ghana, and Azerbaijan.
This post highlights additional issues to consider.
Timeline
As highlighted in this previous post, in mid-2017 SAP disclosed that it was under FCPA scrutiny concerning its business practices in South Africa.