Courts Upholds FCPA Convictions Of Former ComEd Executives And Associates

As discussed in this prior post, in May 2023 a federal jury in Chicago found four former Commonwealth Edison (“ComEd”) executives and associates guilty on all counts charged, including conspiring to influence and reward the former Speaker of the Illinois House of Representatives in order to assist with the passage of legislation favorable to the electric utility company, in addition to multiple bribery and record falsification charges. (See here for the DOJ release).
Bribery of a state politician is not ordinarily the type of conduct that results in Foreign Corrupt Practices Act issues.
However, ComEd (a majority-owned indirect subsidiary of Exelon Corp) was an issuer (as was Exelon) and the FCPA has always been a law much broader than its name suggests because of the FCPA’s books and records and internal controls provisions.
Indeed, the most serious (from a sentencing and fine perspective) criminal charges the four individuals were found guilty of were record falsification in violation of the FCPA.
SEC Commissioners Criticize Recent Internal Controls Enforcement Theory

This post highlighted the SEC’s recent enforcement action against Charter Communications and how – in the non-FCPA, FCPA enforcement action – the SEC “pushed the internal controls envelope” in connection with the company’s stock buybacks.
In connection with the enforcement action, SEC Commissioners Hester Peirce (appointed by President Trump) and Mark Uyeda (appointed by President Biden) issued this blistering statement criticizing the SEC’s internal controls enforcement theory by stating that the SEC “does not have authority to tell companies how to run themselves – but [the SEC is] now routinely us[ing] the internal controls provisions to do just that.”
The statement reads in full:
The SEC Pushes The Internal Controls Envelope

To push the envelope means to surpass normal limits or attempt something viewed as radical or risky.
The FCPA’s enforcement agencies (the DOJ and SEC) have long pushed the envelope and enforcement agency officials may think – why not – a risk averse company is often going to cough up millions of dollars just to make us go away regardless of the underlying enforcement theory.
As highlighted in this post, the SEC recently charged SolarWinds with, among other things, FCPA internal controls violations (in a so-called non-FCPA, FCPA enforcement action) in connection with cybersecurity issues. The SEC filed a civil complaint and it appears – for now at least – that SolarWinds is contesting the enforcement action.
Not so with Charter Communications. Earlier this week, the company agreed to cough up $25 million in a non-FCPA, FCPA enforcement action in which the SEC found that the company violated the FCPA’s internal controls provisions in connection with stock buybacks.
A Most Interesting Internal Controls Theory Of Enforcement

Recently, the SEC filed a lengthy civil complaint against Austin, Texas-based software company SolarWinds Corporation and its chief information security officer, Timothy Brown, for fraud and internal control failures relating to allegedly known cybersecurity risks and vulnerabilities. (See here).
As stated in the SEC’s release:
“The complaint alleges that, from at least its October 2018 initial public offering through at least its December 2020 announcement that it was the target of a massive, nearly two-year long cyberattack, dubbed “SUNBURST,” SolarWinds and Brown defrauded investors by overstating SolarWinds’ cybersecurity practices and understating or failing to disclose known risks. In its filings with the SEC during this period, SolarWinds allegedly misled investors by disclosing only generic and hypothetical risks at a time when the company and Brown knew of specific deficiencies in SolarWinds’ cybersecurity practices as well as the increasingly elevated risks the company faced at the same time.”
“This Is Wrong” And “Callous” – CFTC Commissioner Unleashes On Enforcement Action Based On Record Keeping Issues During The Height Of Covid

This post has little to do with the Foreign Corrupt Practices Act specifically.
However, during the early months of Covid in Spring 2020, this post highlighted how the standard in the FCPA’s internal controls (and books and records) provisions is “reasonable” and that “reasonable” (a term used throughout the law) contemplates a variety of factors including the circumstances in which conduct occurs.
Given that FCPA scrutiny tends to last 4 years on average – and given that conduct giving rise to FCPA scrutiny tends to be up to 5-10 years old – this site has more than once “wondered” how FCPA internal control and/or books and records “deficiencies” will be viewed in future FCPA enforcement actions for the general time period March 2020 – 2021 (or perhaps even 2022).
If this recent Commodities Futures Trading Commission (CFTC) enforcement action against Goldman Sachs is any indication, the answer is the government may not care about the real-world conditions during that time period.