Compliance Certificates
In relation to the U.K. Bribery Act’s so-called adequate procedures defense, how does a company know whether it has adopted adequate procedures so that it can avail itself of the defense should its conduct come under scrutiny? It is a darn good question.
Last week, thebriberyact.com (see here) had a post regarding an adequate procedures certificate. The post profiled a recent speech by Richard Alderman (Director of the U.K. Serious Fraud Office) on the issue of a lawyer’s certificate for adequate procedures. As detailed in the post, Alderman stated as follows. “We know, for example, that some companies believe that all they need is a certificate from a firm of lawyers that they have adequate procedures. We hear about this. We hear as well that the company is not prepared to pay very much for this and expects a certificate of adequate procedures for its worldwide enterprise under say £25,000. This will not impress us very much. This does not mean that we expect companies to spend millions of pounds on this. What we do expect though is a proportionate approach by companies focussing on the key risks and on what they are doing in order to be able to combat those risks. This is what companies should be doing anyway. Indeed some companies have told us that this is a valuable exercise for them for all sorts of reasons that they should have carried out before. A company that does this but which finds problems will receive very sympathetic treatment at the SFO. A company that closes its mind to the issues while perhaps having some veneer of paper procedures will receive different treatment.”
One of the FCPA reform proposals under consideration – and a reform proposal I support (see here and here for prior posts) – is creation of a compliance defense. If enacted, the same issue will arise as under the U.K. Bribery Act – how does a company know whether it has adopted sufficient measures so that it can avail itself of the defense should its conduct come under scrutiny?
Is a compliance certificate the answer?
In Chile, the answer is yes. As detailed in this prior “Compliance Defense Around the World” post, Chile is one of several OECD Anti-Bribery Convention countries to incorporate compliance defense principles into its “FCPA-like” law.
Under Chilean law: in order for a legal person to be held responsible for a foreign bribery offence, the following “three cumulative requirements” must be satisfied: (1) the offence must be committed by a person acting as a representative, director or manager, a person exercising powers of administration or supervision, or a person under the “direction or supervision” of one of the aforementioned persons; (2) the offence must be committed for the direct and immediate benefit or interest of the legal entity. No offence is committed where the natural person commits the offence exclusively in his/her own interest or in the interest of a third party; and (3) the offence must have been made possible as a consequence of a failure of the legal entity to comply with its duties of management and supervision. An entity will have failed to comply with its duties if it violates the obligation to implement a model for the prevention of offences, or when having implemented the model, it was insufficient.”
As to the final element, the OECD report states as follows. “The final cumulative requirement for responsibility stresses that the offence must have been made possible as a consequence of the failure of the legal person to comply with its duties of administration and supervision. The entity will have failed to comply with its duties if it violated the obligation to implement a model for the prevention of offences, or when having implemented the model, the latter was insufficient. It shall be considered that the functions of direction and supervision have been met if, before the commission of the offense, the legal person had adopted and implemented organization, administration and supervision models, pursuant to the following article, to prevent such offenses as the one committed.”
The minimum features of a prevention system under the law are as follows: identify the different activities or processes of the entity, whether habitual or sporadic, in whose context the risk of commission of the offences emerges or increases; establish protocols, rules and procedures that permit persons involved in above-mentioned activities or processes to program and implement their tasks or functions in a manner that prevents the commission of the indicated offences; identify procedures for the administration and auditing that allow the entity to impede their use in the listed offences; establish internal administrative sanctions, as well as procedures for reporting or pursuing pecuniary responsibility against persons who violate the prevention system; introduce the above-mentioned duties, prohibitions and sanctions into the internal regulations of the legal person, and ensure that they are known by all persons bound to apply it (workers, employees, and service providers).
The OECD report states – as to the minimum requirements as follows. “It also aims to introduce a system of self-regulation by companies. Having a code of conduct on paper will not be sufficient to avoid responsibility. If prosecutors can prove that the code does not meet the minimum requirements of or that it is not implemented, the company can be responsible for the offence.” Under Chilean law, “the failure to comply with duties of management and supervision is an element of the offence rather than a defence. Therefore the burden of proof lies on prosecutors, i.e. it will be up to prosecutors to prove that the entity failed to comply with its duties of management and supervision.” The OECD report notes as follows. “This will require prosecutors to prove that the company failed in the design and/or implementation of the offense prevention model including why, in the circumstances, the prevention model was insufficient. This would appear to also require the prosecutor to establish that this failure made perpetration of the offence possible.”
Chilean law sets forth a detailed process by which legal persons are able to undergo a certification process on the existence and relevance of their organizational model. The OECD report states as follows. “Certification will confirm that the offence-prevention model complies with the minimum requirements [set forth above], taking into account the characteristics of the legal person. The certification is valid as long as the situation of the company does not change. Certification will be carried out by private institutions which have been authorised by public agencies to undertake this role. Two points should be noted. The first is that certification will not, by itself, avoid responsibility, since it will remain possible to convict a legal person if it can be proved that, notwithstanding the certification, the preventive model did not meet the minimum requirements [set forth above]; and/or that the model was not implemented. The second point to note is that, pursuant to [the Chilean law], private institutions carrying our certification will be carrying out public functions, which means that they will be criminally responsible in the event of a failure to act properly in the execution of those functions. The sole function of public agencies will be to authorise institutions to carry out these functions, and to keep record of certifications.”
What do you think? Is the Chilean certification process the answer? What are the pros and cons of such an approach? If anyone can direct me to Chilean counsel knowledgeable about this certification process or the “private institutions” authorized to issue such certifications, please send me an e-mail so that I can inquire and report back any findings.
If the FCPA were amended to include a compliance defense, would Chile’s certification approach work here in the U.S.?
For starters, it is useful to observe that the DOJ is already handing out compliance certificates in at least two respects – even if not formally called compliance certificates.
First, the FCPA’s Opinion Release Procedure results in the DOJ issuing – for all practical purposes – a compliance certificate in that the DOJ opines whether a proposed course of conduct, based on the requestor’s disclosed information and various representations, complies with the FCPA. Pursuant to the governing regulations (see here), “there shall be a rebuttable presumption that a requestor’s conduct, which is specified in a request, and for which the Attorney General has issued an opinion that such conduct is in conformity with the Department’s present enforcement policy, is in compliance with those provisions of the FCPA.”
Second, every NPA or DPA contains a clause stating that the DOJ will not bring an enforcement action if the company complies with the undertakings set forth in the agreement – including an appendix which sets forth various compliance obligations. (See here for the recent Armor Holdings NPA). As with the FCPA Release Procedure, the term compliance certificate is lacking, but in substance that is likewise the end result.
That the DOJ is already issuing “compliance certificates” makes the DOJ’s firm opposition to an FCPA compliance defense (see here for more) all the more curious – and all the more contradictory.
The FCPA’s “Illusory” Facilitating Payments Exception
Facilitating payments. The FCPA is clear, as was Congress when it passed the FCPA. Such payments are excepted from the FCPA’s anti-bribery provisions.
Yet why do so many FCPA enforcement actions concern payments to low-level foreign officials to secure permits, licenses and the like?
In the words of former SEC FCPA enforcement attorney Richard Grime (see here) it is because “the DOJ and the SEC’s narrow interpretation of the facilitating payments exception is making that exception ever more illusory, regardless of whether the federal courts – or Congress – would agree.”
In this piece, Grime and co-author Sara Zbed (here) discuss the FCPA’s facilitating payment exception, how “recent enforcement actions have diminished the availability of the exception,” and why the exception has been “further eroded by the recently-enacted U.K. Bribery Act, which lacks any comparable exception and applies broadly to individuals and companies as long as they carry on some business in the United Kingdom.”
Excerpts from the article appear below.
*****
“The drafters of the Foreign Corrupt Practices Act (“FCPA”) recognized that such demands for “grease payments” are a reality in many countries, and accordingly made clear that certain payments made to expedite the approval of permits or licenses, or to prompt the expeditious performance of similar low-level ministerial duties, fell outside the ambit of the statute’s anti bribery provisions. Yet that exception for “facilitating payments” – enacted during the FCPA’s 1988 amendments – is becoming harder and harder to rely on.”
“By excluding facilitating payments from the FCPA’s ambit, Congress acknowledged that such payments – while considered reprehensible within the United States – are “not necessarily [considered reprehensible] elsewhere in the world” and, for that reason, that “it is not feasible for the United States to attempt unilaterally to eradicate all such payments.””
“The FCPA contains no indication of whether permitted facilitating payments are required to be below a certain dollar amount; nor does the statute provide any additional guidance about where a facilitating payment ends and a corrupt payment begins. Federal courts have not squarely confronted the issue, either. To the contrary, only a small handful of decisions even mention the facilitating payments exception, and those that do provide little clarity about the exception’s outer limits.”
“… [T]he Department of Justice (“DOJ”) and the Securities and Exchange Commission (“SEC”) have pressed a narrow view of the exception in recent years, and businesses and other defendants, reluctant to test the law’s boundaries at trial, have settled their cases instead.”
“The DOJ and the SEC have stepped into the void created by this absence of relevant case law, and their recent enforcement actions have diminished the availability of the exception in two principal ways. First, the business purpose requirement of the FCPA is being expanded to cover all manner of circumstances regardless whether there is a clear connection between the payment to the foreign official and obtaining or retaining business. For example, payments to obtain tax refunds, expedite inspections, and procure inspections from government officials are being charged as violations of the anti-bribery provisions without any explanation of why those payments satisfied the business purpose requirement of the law. Second, both the SEC and DOJ have charged violations of the accounting provisions for facilitation payments that are not recorded accurately.”
“Of course, the fact that the FCPA’s twin enforcement agencies have treated certain payments as prohibited despite their possible categorization as facilitating payments does not mean a federal court would agree. But because the vast majority of enforcement actions are resolved through deferred prosecution agreements, non-prosecution agreements, and other settlement devices, these cases never make it to trial. As a result, the DOJ and the SEC’s narrow interpretation of the facilitating payments exception is making that exception ever more illusory, regardless of whether the federal courts – or Congress – would agree.”
Grime and Zbed then shift gears and talk about the FCPA’s facilitating payment exception in light of the U.K. Bribery Act, a law that went live on July 1st.
“Whatever force the facilitating payments exception retains in this environment has been further eroded by the recently-enacted U.K. Bribery Act, which lacks any comparable exception and applies broadly to individuals and companies as long as they carry on some business in the United Kingdom.”
“If the increasing skepticism with which the FCPA’s enforcement agencies view facilitating payments gives pause to companies that permit such payments, so too should the recently enacted Bribery Act – a United Kingdom law that does not permit facilitating payments and whose broad territorial sweep may render the FCPA’s exception even more illusory.”
“The risk associated with permitting facilitating payments are particularly great for companies that do some business in the U.K., because the Bribery Act prohibits such payments and has a broad jurisdictional scope.”
*****
As to the FCPA’s facilitating payment exception, I previously observed here that some find facilitating payments to be corrupt payments under a different name. However, Congress did not agree, and the fact remains that the FCPA contains an express exception for facilitating payments. The enforcement agencies are obligated to enforce the statute that Congress passed, not a statute they wish they had. If Congress wants to remove the facilitating payment exception from the FCPA, let Congress do that, not the enforcement agencies through its charging decisions.
News Corp And The FCPA
On July 7th the U.K. Guardian reported (here) that “up to five [U.K. police] officers were paid between them a total of at least £100,000 in cash from the News of the World.” The next day, Dominic Rushe and Jill Treanor of the U.K. Guardian made the link (see here) between these payments and the Foreign Corrupt Practices Act.
What followed over the next 10 days was the most intense worldwide media coverage of the FCPA in its nearly 35 year history.
Last Wednesday, in a development seldom – if ever – seen in the FCPA context, Senator Barbara Boxer (D-CA) and John Rockefeller (D-WV) wrote Attorney General Eric Holder and SEC Chairman Mary Schapiro (see here) requesting “that the U.S. Department of Justice and the Securities and Exchange Commission investigate whether News Corporation, a U.S.-based corporation, has violated United States law – specifically the Foreign Corrupt Practices Act of 1977.” Separately, Senator Frank Lautenberg (D-NJ) wrote Holder and Schapiro (see here). Senator Lautenberg stated as follows. “The limited information already reported in this case raises serious questions about the legality of the conduct of News Corporation and its subsidiaries under the FCPA. Further investigation may reveal that current reports only scratch the surface of the problem at News Corporation. Accordingly, I am requesting that DOJ and the SEC examine these circumstances and determine whether U.S. laws have been violated.”
Public interest groups (see here for one example) also began demanding an FCPA inquiry into the News of the World scandal.
Soon thereafter, it was reported that the FBI (an agency that investigates allegations of criminal violations of the FCPA under the supervision of the Fraud Section of the DOJ Criminal Division) opened an investigation of News Corp. Among others, Congressmen John Conyers “applaud[ed] Attorney General Eric Holder’s announcement that the Justice Department has opened a formal investigation into allegations that News Corp. may have violated both federal wiretapping statutes and the Foreign Corrupt Practices Act.” (See here).
The News Corp. scandal is wide in scope potentially implicating several laws both here in the U.S. and the U.K. This post focuses on News Corp.’s potential FCPA exposure.
Can the FCPA apply to News Corp. even if the improper conduct took place outside of the U.S.?
Yes. News Corp. is a U.S. company and as such the FCPA has extraterritorial application meaning it can face FCPA liability even if the conduct at issue takes places entirely outside of the U.S. Indeed, in most FCPA enforcement actions the conduct at issue takes place outside of the U.S. Further, it is very common in FCPA enforcement actions for parent companies to be held legally responsible for the acts of subsidiary employees on the theory that such employees acted as “agents” of the parent company and that the parent company ultimately derived the financial benefit from the improper conduct at issue.
Indeed, even News Corp.’s FCPA policies and procedures (here) states as follows. “The Foreign Corrupt Practices Act (FCPA) is a U.S. law that forbids bribery of foreign (meaning non-U.S.) government officials, whether elected or appointed, even if the bribe takes place outside the United States. Because News Corporation is a U.S. corporation, the FCPA may apply to all Company employees everywhere in the world, regardless of their nationality or where they reside or do business.”
Why do the London police payments implicate the FCPA’s anti-bribery provisions?
As a general matter, the FCPA’s anti-bribery provisions prohibit the payment of money or anything of value to a “foreign official” to “obtain or retain business.” London police officers are “foreign officials” under the FCPA. For instance, in this 2006 FCPA enforcement action the DOJ asserted that an Iraqi police officer was a “foreign official” under the FCPA.
As to “obtain or retain business,” for most of its history FCPA enforcement actions focused on payments to “foreign officials” to “obtain or retain business” with a foreign government. However, during the past decade, the DOJ has brought numerous FCPA enforcement actions premised on payments to customs officials, tax officials, immigration officials and the like where the payments have nothing to do with “obtaining or retaining business” with a foreign government. Rather, the payments were alleged to have assisted the payor in “obtaining or retaining” business in the general sense.
The leading court decision on this issue is U.S. v. Kay. 359 F.3d 738, 740 (5th Cir. 2004). As further explained in this piece (pages 917-921), in Kay, a U.S. circuit court (one step below the U.S. Supreme Court) concluded that payments to a “foreign official” to lower taxes and custom duties in a foreign country can provide an unfair advantage to the payer over competitors and thereby assist the payer in obtaining and retaining business. The court concluded that there was “little difference” between these type of payments and traditional FCPA violations in which a company makes payments to a “foreign official” to influence or induce the official to award a government contract. Even so, the court stated that not all such payments to a “foreign official” outside the context of directly securing a foreign government contract violate the FCPA; it merely held that such payments “could” violate the FCPA. The court recognized that “there are bound to be circumstances” in which a custom or tax reduction merely increases the profitability of an existing profitable company and thus, presumably, does not assist the payer in obtaining or retaining business.
Despite Kay’s equivocal holding, there has been a significant increase in FCPA enforcement actions since the decision concerning payments to “foreign officials” that better position the payor to “obtain or retain business” in the general sense. (See for instance the “CustomsGate” category under the Search page of this site).
Thus, payments to London police officers that allowed News of the World to obtain non-public information to write sensational news stories – and thus sell more newspapers – would seem to fit the type of FCPA enforcement common post-Kay. Given that News Corp. is a media company and its product is information, such payments are similar to an oil and gas company making payments to a “foreign official” to obtain non-public information concerning the location of oil and gas deposits.
What about the FCPA’s books and records and internal control provisions?
In addition to its anti-bribery provisions, the FCPA also contains books and records and internal control provisions applicable to U.S. listed companies such as News Corp. The books and records provision requires that “issuers” (the statutory term for U.S. listed companies) “make and keep books, records, and accounts, which, in reasonable detail, accurately and fairly reflect the transactions and dispositions of the assets of the issuer.” The internal controls provision require that “issuers” “devise and maintain a system of internal accounting controls sufficient to provide reasonable assurances that:” among other things, “transactions are executed in accordance with management’s general or specific authorization;” “access to assets is permitted only in accordance with management’s general or specific authorization;” and “transactions are recorded as necessary to permit a preparation of financial statements in conformity with generally accepted accounting principles … and to maintain accountability for assets.”
These provisions, despite being part of the FCPA, are generic in scope. Thus, if other payments part of News Corp.’s wide-ranging scandal – such as “hush” settlement payments to phone hacking victims are misrecorded on the company’s books and records, such entries would provide the basis for independent FCPA books and records violations – even if such conduct does not directly implicate the FCPA’s anti-bribery provisions. As to the London police payments, such payments, if not recorded accurately on the company’s books and records, would of course also give rise to an independent FCPA books and records violation. Both the DOJ and the SEC (which also has FCPA jurisdiction over U.S. listed companies) frequently hold parent companies liable for the books and records violations of subsidiaries on the theory that subsidiary books and records are consolidated with the parent company’s books and records for purposes of financial reporting.
As to the FCPA’s internal control provisions, the enforcement agencies often take the rather simplistic position that because the payments were made or because corporate expenses were not accurately recorded, the company did not have effective internal controls.
If News Corp. faces FCPA liability does that mean that executive officers will as well?
Not necessarily. Under U.S. legal principles, a corporate entity such as News Corp. can face legal liability based on the conduct of any employee or agent to the extent the employee or agent was acting within the scope of their authority and the conduct was intended to benefit, at least in part, the organization. Many FCPA enforcement actions against corporate entities result from the improper conduct of low to mid-ranking employees in the absence of any allegation that executive officers or board members knew about the conduct at issue or participated in the conduct at issue. Thus, just because News Corp. may face FCPA liability under these principles does not necessarily mean that executive officers will as well.
As to individuals (whether high-ranking executives or otherwise) there needs to be some evidence of culpable conduct – which in the FCPA criminal context – often means participating in the improper conduct, authorizing the improper conduct, or knowing of the improper conduct but failing to put a stop to it.
Will U.S. authorities defer to British authorities in investigating the London police payments?
Some have suggested that U.S. authorities are unlikely to bring an enforcement action because the U.K. has strong anti-corruption laws and is capable of handling this matter domestically. I disagree. The U.K. Bribery Act went live on July 1st, but it only covers conduct that occurs after that date. Prior to the Bribery Act, the U.K. had a hodgepodge of antiquated bribery and corruption statutes. However, the problem with those statutes is they required a “controlling mind” of the corporate to be involved in the conduct at issue in order to prosecute the entity. The weakness of these pre-Bribery Act laws was clearly evident in the U.K. BAE enforcement action from 2010. As the Serious Fraud Office stated in court papers “a serious evidential difficulty had been identified in respect of potential corruption charges, namely the difficulty of proving the involvement of a ‘controlling mind’ in the offending.” Thus, if there is no evidence of “controlling minds” being involved in the London police payments, pre-Bribery Act laws will be insufficient to bring bribery charges as occurred in the BAE matter. This evidentiary difficulty is one of the reasons the U.K. passed the Bribery Act.
U.S. enforcement agencies have a good relationship with their U.K. counterparts and cooperation between the agencies is likely to occur, but there is little reason to believe that the U.S. will stand down and not bring an enforcement action if that is what the evidence warrants. In fact, there have been several FCPA enforcement actions concerning U.K. business entities, based on conduct occurring in the U.K.,and/or involving U.K. citizens. See here for the 2010 FCPA enforcement action relating to Innospec, here for the FCPA enforcement action concerning employees of Pacific Consolidated Industries and here for the FCPA enforcement action against U.K. citizen Jeffrey Tesler.
What is likely to happen next?
There are multiple reasons why News Corp. will cooperate, if it is not already, in the DOJ’s FCPA investigation. The DOJ has substantial discretion (some would argue too much) in resolving corporate criminal matters. Under the DOJ’s Principles of Prosecution of Business Organizations (see here), one of the factors DOJ will consider in deciding how to resolve any potential action is the company’s cooperation. Cooperation in the FCPA context often means conducting an internal, independent review of the conduct at issue and sharing the results, witness statements, key documents, etc. with the enforcement agencies on a near real-time basis. Cooperation is also a mitigating factor under the advisory U.S. Sentencing Guidelines which provide a monetary penalty range for all FCPA criminal actions.
How long is this FCPA gray cloud likely to hang over News Corp?
Likely for a few years. It is typical for an FCPA enforcement inquiry to begin based on a certain set of limited and discrete facts – here the London police payments. However, before the enforcement agencies (DOJ or SEC) will agree to resolve an FCPA matter, it is typical for the agencies to ask the “where else” question. In other words, the question will be – if News Corp. employees (broadly speaking) made the London police payments, did other News Corp. employees around the world make similar payments to “foreign officials” to “obtain or retain business.” To answer this question, and because News Corp. is likely in cooperation mode and because the company has an incentive to learn this information itself, News Corp. will likely conduct a targeted world-wide review of its operations. Such a review takes time and often costs tens of millions of dollars in professional fees and expenses. Because of these dynamics, it is typical for FCPA scrutiny – from the point of investigation to the point of enforcement action – to last between 2-4 years.
The U.K. Bribery Act Goes Live
At the time of this post, the U.K. Bribery Act has been live for about ten hours, yet there has not been an enforcement action. Given that the Act is not retrospective and applies only to bribes paid after July 1st, this is hardly surprising, but I hope you appreciate the Friday humor.
U.K. corporates and others subject to the Bribery Act are doing business around the world, including in high-risk jurisdictions, and a healthy dose of corporate hospitality is no doubt occurring at Wimbledon. In other words, the world has not changed.
Today, of course, is the day the U.K. Bribery Act finally goes live.
As explained is this U.K. Ministry of Justice circular, “the Bribery Act replaces the offences at common law and under the Public Bodies Corrupt Practices Act 1889, the Prevention of Corruption Act 1906 and the Prevention of Corruption Act 1916 (known collectively as the Prevention of Corruption Acts 1889 to 1916) with a new consolidated scheme of bribery offences.”
The FCPA-like provision of the Bribery Act is Section 6 described in the circular as follows. “Section 6 is designed to deal with the corruption of decision making in publicly funded business transactions through the personal enrichment of foreign public officials by those seeking business opportunities. The offence is committed where a person offers, promises or gives a financial or other advantage to a foreign public official with the intention of influencing the official in the performance of his or her official functions. There must also be an intention to obtain or retain business or a business advantage on the part of the perpetrator. However, the offence is not committed where the official is permitted or required by the applicable written law to be influenced by the advantage.”
As to corporate liability, the circular states as follows. “The Bribery Act includes a new form of corporate criminal liability where there is a failure to prevent bribery perpetrated on behalf of a “relevant commercial organisation” (Section 7). This new corporate liability for bribery […] does not in any way change the existing common law principle governing the liability of corporate bodies for criminal offences that require the prosecution to prove a fault element or ‘mens rea’ in addition to a conduct element. This common law principle, sometimes referred to as the “identification principle”, will therefore continue to operate so that where there is evidence to prove that a person who is properly regarded as representing the “directing mind” of the body in question possessed the necessary fault element required for the offence charged the corporate body may be proceeded against.”
As to the Section 7 offense, the circular states as follows. “The offence at section 7 of the Act creates a new form of corporate criminal liability. The offence applies only to a “relevant commercial organisation” as defined at section 7(5) and focuses on a failure by such an organisation to prevent a person “associated with” it from committing a section 1 or 6 bribery offence in order to obtain or retain business or an advantage in the conduct of business for that organisation. It creates direct rather than vicarious liability and its commission does not amount to the commission of a substantive bribery offence under section 1 or 6. A commercial organisation will have a full defence if it can show that despite a particular case of bribery it nevertheless had adequate procedures in place designed to prevent persons associated with it from bribing.”
As Michael Volkov (here) nicely stated – “The longest pre-game show in history is drawing to a close. The new world will shortly be upon us. Will the UK Bribery Act be a game-changer or will it fizzle out like Y2K? Everyone has their predictions; everyone has their focus and emphasis.”
Here is my two cents.
As with any new law, there is likely to be a learning phase for both the enforcement agencies and those subject to the law. That was certainly the case in the U.S. in the years following passage of the FCPA in 1977. Thus, it very well may be the case that there are no enforcement actions for some time (recognizing that it often takes a few years from beginning of an inquiry to resolution of an action). Thus the greatest immediate impact of the Bribery Act is sure to be the compliance ethic it inspires. I expect that the enforcement actions that may develop over time to focus on egregious instances of corporate conduct on which no reasonable minds would disagree. I do not get the sense, based on public comments of the Ministry of Justice and the Serious Fraud Office, that the envelope will be pushed too far in the early years of the Bribery Act.
*****
See here for the text of Richard Alderman’s (Director of the U.K. Serious Fraud Office) recent speech on the Bribery Act.
In a signature departure from U.S. enforcement policy concerning merger and aquisition issues, Alderman stated as follows. “I know that there are many occasions when an acquiring company takes over a target company and discovers either before or after the event that there are serious problems about corrupt activities in the target company. My view is that when an ethical acquiring company identifies these issues, then it is in everyone’s interest that that acquiring company gets on and sorts out the problems that it has inherited. I have difficulty in seeing that any SFO investigation at the corporate level would be justified although I would have to consider carefully the position of any individuals.” (As highlighted in this recent post, several FCPA enforcement actions have been based on successor liability theories).
*****
In this speech, Alderman stated the following regarding the “foreign public official” term in the Bribery Act.
“Who then is a foreign public official? This is the subject of litigation at the moment in the US and I am following this with interest. The test I use is one that was set out by the OECD in the commentary on the OECD Convention. What we look at is whether or not the foreign State is in a position to influence the foreign company. We therefore look at the relationship between the company and the State to see whether effectively this commercial organisation is being run by the State. This can lead us into some tricky areas. We have received questions about banking officials in countries where the State has a very major interest in the Bank and exercises that interest very actively. Are those officials foreign public officials? Our view is that in those circumstances the individual is likely to be a foreign public official. On the other hand if the State has a major interest but does not control the operations of the Bank, then I think we could have a different situation.”
*****
Keeping with today’s U.K. theme, earlier this week Bloomberg reported (here) that the SFO is assisting the SEC “on inquiries involving financial institutions and whether bribes were paid in transactions with sovereign wealth funds.”
As previously reported by the Wall Street Journal (see here) the SEC is “examining whether Goldman Sachs Group Inc. and other financial firms might have violated bribery laws in dealings with Libya’s sovereign wealth fund.” The SFO’s inquiry appears to be related to HSBC Holdings Plc’s interactions with Libya’s sovereign wealth fund.
Other financial services firms that have reportedly received letters of inquiry from the SEC include Bank of America, Morgan Stanley, and Citigroup.
*****
A good holiday weekend to all.
The Compliance Defense Around The World
As highlighted in this prior post, numerous FCPA reform bills in the 1980’s included a specific defense which stated a company would not be held vicariously liable for a violation of the FCPA’s anti-bribery provisions by its employees or agents, who were not an officer or director, if the company established procedures reasonably designed to prevent and detect FCPA violations by employees and agents. An FCPA reform bill containing such a provision did pass the U.S. House, but was not enacted into law.
Amending the FCPA to include a compliance defense is one of the U.S. Chamber’s FCPA reform proposals (see here). In November 2010, Andrew Weissman, on behalf of the Chamber, testified in favor of a compliance defense (and other reform proposals) during the Senate’s FCPA hearing (see here for the prior post) and during the House hearing earlier this month (see here for the prior post), former Attorney General Michael Mukasey, on behalf of the Chamber, also testified in favor of a compliance defense (and other reform proposals).
During the House hearing, there appeared to be bi-partisan support for consideration of an FCPA compliance defense.
Even so, Greg Andres, testifying on behalf of the DOJ, stated that a potential FCPA compliance defense was “novel and risky” and that the “time is not right to consider it.”
Public debate on a potential compliance defense has thus far focused, from a comparative standpoint, on the United Kingdom and Italy.
The purpose of this post is to further inform the public debate on a potential compliance defense by highlighting various compliance-like defenses around the world in other countries that are signatories (like the U.S.) to the OECD Anti-Bribery Convention.
This post is further to my work in progress – Revisiting an FCPA Compliance Defense – and represents hours of research analyzing 38 OECD Country Reports.
The post provides an overview of compliance-like defenses in the following OECD Convention signatory countries: Australia, Chile, Germany, Hungary, Italy, Japan, Korea, Poland, Portugal, Sweden, and Switzerland. [The U.K. Bribery Act, set to go live on July 1st, also contains a compliance-like defense in Section 7].
A first reaction might be – only 12 of the 38 OECD member countries have a compliance-like defense.
However, this number must be viewed against the backdrop of the following dynamics: (i) in many OECD Convention signatory countries, the concept of legal person criminal liability (as opposed to natural person criminal liability) is non-existent; and (ii) in many OECD Convention signatory countries that do have legal person criminal liability, such legal person liability can only result from the actions of high-level executive personnel or other so-called “controlling minds” of the legal person.
Obviously if a foreign country does not provide for legal person liability, there is no need for a compliance defense, and the rationale for a compliance defense is less compelling if legal exposure can result only from the conduct of high-level executive personnel or other “controlling minds.”
When properly viewed against these dynamics, a compliance-like defense (whether specifically part of a foreign country’s “FCPA-like” law or otherwise generally part of a foreign country’s legal principles) is far from a “novel” idea, but rather common among OECD Anti-Bribery Convention signatory countries that – like the U.S. – have legal person criminal liability that can attach based on the conduct of non-executive officers or other “controlling minds.”
[The below information is based strictly on OECD country reports and is subject to the qualification that in many instances the most recent information concerning a particular country may be several years old. If anyone has more recent information concerning any particular country, how the compliance defense in a particular country has worked in practice, or any other relevant information, please leave a comment on this site or contact me at mjkoehle@butler.edu]
*****
Australia
Australian law implementing the OECD Convention entered into force on December 18, 1999.
Thereafter, a section of the Criminal Code on corporate criminal liability came into full force establishing an organizational model for the liability of legal persons. “Bodies corporate” are liable for offences committed by “an employee, agent or officer of a body corporate acting within the actual or apparent scope of his or her employment, or within his or her actual or apparent authority” where the body corporate “expressly, tacitly, or impliedly authorised or permitted the commission of the offence”.
Pursuant to the Criminal Code, authorisation or permission by the body corporate may be established in the following ways: (1) the board of directors intentionally, knowingly or recklessly carried out the conduct, or expressly, tacitly or impliedly authorised or permitted it to occur; (2) a high managerial agent intentionally, knowingly or recklessly carried out the conduct, or expressly, tacitly or impliedly authorised or permitted it to occur; (3) a corporate culture existed that directed, encouraged, tolerated or led to the offence; or (4) the body corporate failed to create and maintain a corporate culture that required compliance with the relevant provision.
However, under the Criminal Code, “if a high managerial agent is directly or indirectly involved in the conduct, no offence is committed where the body corporate proves that it “exercised due diligence to prevent the conduct, or the authorisation or permission.”
Chile
Chilean law implementing the OECD Convention entered into force on October 8, 2002.
In December 2009, a separate Chilean law entered into force establishing criminal responsibility of legal persons for a limited list of offences including bribery of foreign public officials.
In order for a legal person to be held responsible for a foreign bribery offence, the following “three cumulative requirements” must be satisfied: (1) the offence must be committed by a person acting as a representative, director or manager, a person exercising powers of administration or supervision, or a person under the “direction or supervision” of one of the aforementioned persons; (2) the offence must be committed for the direct and immediate benefit or interest of the legal entity. No offence is committed where the natural person commits the offence exclusively in his/her own interest or in the interest of a third party; and (3) the offence must have been made possible as a consequence of a failure of the legal entity to comply with its duties of management and supervision. An entity will have failed to comply with its duties if it violates the obligation to implement a model for the prevention of offences, or when having implemented the model, it was insufficient.”
As to the final element, the OECD report states as follows. “The final cumulative requirement for responsibility stresses that the offence must have been made possible as a consequence of the failure of the legal person to comply with its duties of administration and supervision. The entity will have failed to comply with its duties if it violated the obligation to implement a model for the prevention of offences, or when having implemented the model, the latter was insufficient. It shall be considered that the functions of direction and supervision have been met if, before the commission of the offense, the legal person had adopted and implemented organization, administration and supervision models, pursuant to the following article, to prevent such offenses as the one committed.”
The minimum features of a prevention system under the law are as follows: identify the different activities or processes of the entity, whether habitual or sporadic, in whose context the risk of commission of the offences emerges or increases; establish protocols, rules and procedures that permit persons involved in above-mentioned activities or processes to program and implement their tasks or functions in a manner that prevents the commission of the indicated offences; identify procedures for the administration and auditing that allow the entity to impede their use in the listed offences; establish internal administrative sanctions, as well as procedures for reporting or pursuing pecuniary responsibility against persons who violate the prevention system; introduce the above-mentioned duties, prohibitions and sanctions into the internal regulations of the legal person, and ensure that they are known by all persons bound to apply it (workers, employees, and service providers).
The OECD report states – as to the minimum requirements as follows. “It also aims to introduce a system of self-regulation by companies. Having a code of conduct on paper will not be sufficient to avoid responsibility. If prosecutors can prove that the code does not meet the minimum requirements of or that it is not implemented, the company can be responsible for the offence.”
Under Chilean law, “the failure to comply with duties of management and supervision is an element of the offence rather than a defence. Therefore the burden of proof lies on prosecutors, i.e. it will be up to prosecutors to prove that the entity failed to comply with its duties of management and supervision.”
The OECD report notes as follows. “This will require prosecutors to prove that the company failed in the design and/or implementation of the offense prevention model including why, in the circumstances, the prevention model was insufficient. This would appear to also require the prosecutor to establish that this failure made perpetration of the offence possible.”
As noted in the OECD report, the Chilean “standard of liability is inspired from the Italian system of liability of legal persons” (discussed below).
Germany
German law implementing the OECD Convention entered into force on February 15, 1999.
German law establishes the liability of legal persons, including liability for the foreign bribery offence, under an administrative (i.e. non-criminal form) act.
Pursuant to the administrative act, “the liability of legal persons is triggered where any “responsible person” (which includes a broad range of senior managerial stakeholders and not only an authorised representative or manager), acting for the management of the entity commits i) a criminal offence including bribery; or ii) an administrative offence including a violation of supervisory duties which either violates duties of the legal entity, or by which the legal entity gained or was supposed to gain a “profit”.”
As noted in the OECD report, “in other words, Germany enables corporations to be imputed with offences i) by senior managers, and, somewhat indirectly, ii) with offences by lower level personnel which result from a failure by a senior corporate figure to faithfully discharge his/her duties of supervision.”
The OECD report states that the “standards for a violation of supervisory duties include consideration of factors such as whether the company has in place a monitoring system or in-house regulations for employees.”
Hungary
Hungarian law implementing the OECD Convention entered into force on March 1, 1999.
In 2004, a separate law was enacted specifying the individuals whose actions can trigger the liability of the legal person.
The OECD report states as follows. “The specific persons and additional conditions for liability are defined as follows: (i) the bribery is committed by one of the members or officers [of the legal entity] entitled to manage or represent it, or a supervisory board member and/or their representatives acting within the legal scope of activity of the legal person ; (ii) the bribery is committed by one of the members of the legal entity or an employee acting within the legal scope of activity of the legal person provided the bribery could have been prevented by the chief executive fulfilling his supervisory or control obligations; and (iii) the bribery is committed by a third party individual, provided that the legal entity’s member or officer entitled to manage or represent the it had knowledge of the facts.”
According to the OECD report, the relevant law does not provide any guidance as to the necessary degree of supervision to avoid liability for bribery.
Italy
Italian law implementing the OECD Convention entered into force on October 26, 2000.
Under Italian law, “criminal liability cannot be attributed to legal persons” however, “administrative liability may be attributed to legal persons for certain criminal offences (including foreign bribery) committed by a natural person.
The relevant administrative decree provides a “defence of organisational models” to a body which makes reasonable efforts to prevent the commission of an offence.
The OECD report states as follows. “… [A] body is not liable for offences committed by persons in senior positions if it proves the following. First, before the offence was committed, the body’s management had adopted and effectively implemented an appropriate organisational and management model to prevent offences of the kind that has occurred. Second, the body had set up an autonomous organ to supervise, enforce and update the model. Third, this autonomous organ had sufficiently supervised the operation of the model. Fourth, the perpetrator committed the offence by fraudulently evading the operation of the model.” The defence of organisation models operates as a full defence which completely exculpates a legal person.
The relevant administrative decree stipulates the essential elements of an acceptable organisational model described in the OECD report as follows. “First, the model must identify activities which may give rise to offences. Second, the model must define procedures through which the body makes and implements decisions relating to the offences to be prevented. It must also prescribe procedures for managing financial resources to prevent offences from being committed. Third, the model must oblige the internal organ responsible for supervision and enforcement to provide information to the body. Finally, the model must include a disciplinary system for non-compliance.”
Japan
Japanese law implementing the OECD Convention entered into force on February 15, 1999 .
“Under Japanese law, criminal responsibility of a legal person is based on the principle that the company did not exercise due care in the supervision, selection, etc. of an officer or employee to prevent the culpable act.
The burden rests on the legal person to prove that due care was exercised. Where a legal person raises the defence, a person must be identified as having exercised due care, etc., and the court must determine whether it was exercised properly having regard to the nature of the legal person and the circumstances of the case.”
Korea
Korean law implementing the OECD Convention entered into force on February 15, 1999.
Korean law establishes the criminal responsibility of legal persons for the bribery of a foreign public official, however, a legal person is exempt from liability where it has paid “due attention” or exercised “proper supervision” to prevent the offence.
The statute itself does not provide information about what constitutes “due attention” or “proper supervision.” A representative of the Supreme Public Prosecutor’s Office informed the OECD that “the exemption is triggered when a director or ‘superior person’ exercises due attention.” The Explanatory Manual published by the Ministry of Justice states that “it is difficult to standardize the extent of attention or supervision in deciding whether a legal person can be exempted from criminal punishment.” The Explanatory Manual further states that whether the exemption applies depends upon “general circumstances such as the motive and background that led to the bribery, intervention of exclusive members of the legal person, whether it was informed earlier, and how much effort was usually made by the corporation to prevent bribery, etc.” and that companies involved in international business must prevent violations of the law by all employees and executives of the company “through sufficient necessary management”.
Poland
Polish law implementing the OECD Convention entered into force on February 4, 2001.
Polish law provides “a noncriminal form of responsibility for collective entities.” Among the requirements for liability is the offence was committed “in the effect of at least absence of due diligence in electing the natural person [committing the act] or of at least the absence of due supervision over this person by an authority or a representative of the collective entity.”
According to the relevant Polish legislative history, “the perpetration of a prohibited act by a natural person will trigger liability of the
collective entity where the act occurred as a result of negligence on the part of the authority or representative of the collective entity.”
Portugal
Portuguese law implementing the OECD Convention entered into force on June 9, 2001.
Under Portuguese law relevant to corruption in international business transactions, legal persons can be liable for conduct committed “on their behalf and in the collective interest by natural persons occupying a leadership position within the legal person structure” or by “whoever acts under the authority” of such natural persons.
However, “[t]he liability of legal persons and equivalent entities is excluded when the actor has acted against the orders or express instructions of the person responsible.”
Sweden
Swedish law implementing the OECD Convention entered into force on July 1, 1999.
Under Swedish Law, only natural persons can commit crimes. However, pursuant to the Swedish Penal Code, a “kind of quasi-criminal liability is applied to an ‘entrepreneur’ (a general term meaning “any natural or legal person that professionally runs a business of an economic nature) for a ‘crime committed in the exercise of business activities.’”
However, one requirement under the Penal Code is that “the entrepreneur has not done what could reasonable be required of him for prevention of the crime.”
Switzerland
Swiss law implementing the OECD Convention entered into force on May 1, 2000.
Article 100quater of the Swiss Criminal Code requires “defective organisation as a condition for corporate criminal liability.”
In order to incur criminal liability, “the enterprise must not have taken all reasonable and necessary organisational measures to prevent the individual from committing the offence.”
Under Swiss law, the burden is on the prosecutor to furnish proof of defective organization and according to Swiss authorities contacted by the OECD “steps should be taken to assess whether employees have been sufficiently informed, supervised and controlled” and “the fact that an enterprise is organised in compliance with international management standards will not be sufficient to rule out all liability on its part; it will be one element to take into consideration among others …”. In the view of Swiss authorities, “ shifting the burden of proof in criminal cases would contravene Article 6 of the European Convention on Human Rights.”