Further To The SEC’s Inconsistent Approach To Enforcing The FCPA’s Books And Records And Internal Controls Provisions

As highlighted in previous posts on this subject (here, here and here), a basic rule of law principle is consistency.
In other words, the same legal violation ought to be sanctioned in the same way. When the same legal violation is sanctioned in materially different ways, trust and confidence in law enforcement is diminished.
However, there sure does seem to be a lack of consistency between how the SEC resolves Foreign Corrupt Practices Act books and records and internal controls violations.
SEC Co-Director Of Enforcement Peikin On International Cooperation

Recently Steven Peikin (Co-Director of the SEC’s Enforcement Division) delivered this speech in which he talked about international cooperation and how it is “critical to the SEC’s civil law enforcement success” including the Foreign Corrupt Practices Act space.
In addition, Peikin stated that “vigorous enforcement of the FCPA remains a high priority for the SEC.”
Does The SEC Really Even Need A Specific FCPA Unit?

In fiscal year 2010, the Securities and Exchange Commission created a specialized unit (one of only five in its enforcement division “dedicated to particular highly specialized and complex areas of securities law“) devoted to enforcing the FCPA.
The question arises however: does the SEC really even need a specific FCPA unit?
The below post highlights how, based on the SEC’s own enforcement statistics, FCPA enforcement actions comprise a minuscule percentage of its overall enforcement actions as well as other quantitative and qualitative factors relevant to the question posed.
FCPA Flash Podcast – A Conversation With Thomas Gorman Regarding The SEC’s Recent Internal Controls Report Of Investigation

The FCPA Flash podcast provides in an audio format the same fresh, candid, and informed commentary about the Foreign Corrupt Practices Act and related topics as readers have come to expect from written posts on FCPA Professor.
This FCPA Flash episode is a conversation with Thomas Gorman (Dorsey & Whitney, former Senior Counsel in the SEC’s Division of Enforcement, and founder and editor of the informative SEC Actions blog). In the episode, Gorman discusses the SEC’s recent report of investigation relevant to the FCPA’s internal controls provisions, whether certain emerging FCPA issues should have been addressed through a report of investigation as opposed to an enforcement action, and common SEC internal controls enforcement theories including the “prevent and detect” standard not even found in the FCPA.
Obvious Parallels To Certain FCPA Enforcement Actions In The SEC’s Recent Report Of Investigation

I’ve long believed that in certain instances, the SEC should use its Section 21(a) report of investigation powers to address emerging Foreign Corrupt Practices Act issues rather than bring an actual enforcement action.
Recently the SEC did just that in this report “regarding certain cyber-related frauds perpetrated against public companies and related internal accounting controls requirements.”
As highlighted below, in the report the SEC cites FCPA legislative history, prior SEC FCPA guidance, and otherwise takes positions in the report that seemingly undermine its internal controls enforcement theories in many traditional FCPA enforcement actions involving alleged foreign bribery.