The Foreign Corrupt Practices Act has always been a law much broader than its name suggests.
Sure, the FCPA contains anti-bribery provisions which concern foreign bribery.
Sure, the FCPA’s books and records and internal controls provisions can be implicated in foreign bribery schemes.
However, the fact remains that most FCPA enforcement actions (that is enforcement actions that charge or find violations of the FCPA’s books and records and internal controls provisions) have nothing to do with foreign bribery. For lack of a better term, these enforcement actions have longed been called non-FCPA, FCPA enforcement actions on this site.
This 2023 post highlighted the SEC’s enforcement action against Austin, Texas-based software company SolarWinds Corporation and its chief information security officer, Timothy Brown, for fraud and internal control failures relating to allegedly known cybersecurity risks and vulnerabilities.
The SEC’s complaint, filed in the Southern District of New York, alleged that SolarWinds and Brown violated the antifraud provisions of the Securities Act of 1933 and of the Securities Exchange Act of 1934; SolarWinds violated reporting and internal controls provisions of the Exchange Act; and Brown aided and abetted the company’s violations.
The prior post called the SEC’s internal controls theory of enforcement “most interesting” because the FCPA’s internal controls provisions concern accounting controls.
Given the FCPA’s statutory language – as well as legislative history – it is not surprising that today the court dismissed the SEC’s internal controls claims.
This opinion by Judge Paul Engelmayer states in pertinent part:
“The SEC next brings claims against Solar Winds under Section 13(b )(2)(B) of the Exchange Act for failure to devise and maintain appropriate “internal accounting controls.”
[…]
The AC [Amended Complaint] alleges that SolarWinds’ cybersecurity deficiencies are actionable under Section 13(b)(2)(B)(iii) because(1) the company’s source code, databases, and products were its most vital assets, but (2) as a result of its poor access controls, weak internal password policies, and VPN security gaps, the company failed to limit access to these “only in accordance with management’s general or specific authorization,” enabling access by external attackers. AC 320-24. Solar Winds counters that although the Section 13(b )(2)(B) term gives the SEC authority to regulate an issuer’s “system of internal accounting controls,” that term, as a matter of statutory construction, cannot reasonably be interpreted to cover a company’s cybersecurity controls such as its password and VPN protocols. SolarWinds is clearly correct.
“As with any question of statutory interpretation, [the Court] begin[s] with the text of the statute to determine whether the language at issue has a plain and unambiguous meaning.” Louis Vuitton Malletier S.A. v. LY USA, Inc., 676 F.3d 83, 108 (2d Cir. 2012) (citations omitted). A statute’s “plain meaning can best be understood by looking to the statutory scheme as a whole and placing the particular provision within the context of that statute.” Saks v. Franklin Covey Co., 316 F.3d 337,345 (2d Cir. 2003). In general, the Court “need proceed no further than the statute’s text and context in the broader statutory scheme.” United States v. Epskamp, 832 F.3d 154, 162 (2d Cir. 2016) (internal quotation marks omitted). But extrinsic materials may “have a role in statutory interpretation … to the extent they shed a reliable light on the enacting Legislature’s understanding of otherwise ambiguous terms.” Exxon Mobil Corp. v. Allapattah Servs., Inc., 545 U.S. 546, 568 (2005).
The text of Section 13(b )(2)(B)(iii) requires that public companies “devise and maintain a system of internal accounting controls sufficient to provide reasonable assurances that … access to assets is permitted only in accordance with management’s general or specific authorization.” The provision thus applies only to a company’s “system of internal accounting controls.” For the SEC’s claim to survive dismissal, that provision must be construed to cover an issuer’s cybersecurity controls.
As a matter of statutory construction, that reading is not tenable. In various respects, the text of the statute strongly supports that the term “system of internal accounting controls” instead refers to a company’s financial accounting. The term “accounting” is widely defined in this manner-for example, as “the system of recording and summarizing business and financial transactions and analyzing, verifying, and reporting the results.” Accounting, Merriam-Webster Dictionary, https://www.merriam-webster.com/dictionary/accounting (emphasis added). The SEC has not identified any dictionary definition favoring its construction. And the surrounding terms that Congress used in Section 13(b)(2)(B)-which refer, inter alia, to “transactions,” “preparation of financial statements,” “generally accepted accounting principles,” and “books and records”-are uniformly consistent with financial accounting. See Yates v. United States, 574 U.S. 528 (2015) (“[W]e rely on the principle of noscitur a sociis-a word is known by the company it keeps-to ‘avoid ascribing to one word a meaning so broad that it is inconsistent with its accompanying words, thus giving unintended breadth to the Acts of Congress.”‘ (quoting Gustafson v. Alloyd Co., 513 U.S. 561, 575 (1995)); United States v. Williams, 553 U.S. 285,294 (2008) (“a word is given more precise content by the neighboring words with which it is associated”). The text thus defeats the SEC’s attempt to apply this provision to cybersecurity controls. And there is no evidence of any other sort that Congress intended its reference to “a system of internal accounting controls” to reach cybersecurity controls. That is no surprise. The statute was enacted in 1977-long before cybersecurity became a relevant concept in business or society.
Unsurprisingly, the few courts that have construed the term “internal accounting controls” as used in Section 13(b )(2)(B)(iii) have consistently construed it to address financial accounting. In SEC v. World-Wide Coin Investments, Ltd., 567 F. Supp. 724 (N.D. Ga. 1983), Judge Robert L. Vining defined “internal accounting controls” as those controls that “safeguard assets and assure the reliability of financial records, one of their main jobs being to prevent and detect errors and irregularities that arise in the accounting systems of the company. Internal accounting controls are basic indicators of the reliability of the financial statements and the accounting system and records from which financial statements are prepared.” Id. at 750.”
A footnote states:
“The SEC contends that World-Wide Coin Investments adopted a broader conception of “internal accounting controls.” That is wrong. The company there was engaged in the sale of rare coins, precious metals, gold and silver coins, and bullion. In finding a violation of Section 13(b)(2)(B), the court noted that the “internal recordkeeping and accounting controls” at the company had been in “sheer chaos.” World-Wide Coin Invs., 567 F. Supp. at 752. It did not have a “procedure implemented with respect to writing checks,” it did not employ a “separation of duties in the areas of purchase and sales transactions, and valuation procedures for ending inventory,” and employees were not “required to write source documents relating to the purchase and sale of coins, bullion, or other inventory.” Id. These deficiencies quintessentially relate to financial matters. The SEC seizes on the court’s passing observation that the company had “extremely lax security measures such as leaving the vault [ of its rare coins and other inventory] unguarded.” Id. But that observation was not the heart of its analysis. In any event, because the company bought and sold rare coins, the physical security of its rare coin collection directly affected its inventory controls and its ability to financially audit “transactions and the disposition of World-Wide’s assets.” Id. The same cannot be said of SolarWinds’ cybersecurity measures.”
See here for a prior post about World-Wide Coin.
The opinion continues:
“In McConville v. SEC, 465 F.3d 780 (7th Cir. 2006), as amended on denial of reh ‘g and reh ‘gen bane, (Jan. 17, 2007), the Seventh Circuit gave examples of internal accounting controls as including: “manual or automated review of records to check for completeness, accuracy and authenticity; a method to record transactions completely and accurately; and reconciliation of accounting entries to detect errors.” Id at 790 (citing In re Albert Glenn Yesner, CPA, Initial Decision, Exchange Act Release No. 184, 2001 WL 587989, at *33 (May 22, 2001); Montgomery’s Auditing 9-2 (John Wiley & Sons, Inc. 12th ed. 1998)). And in a public administrative cease and desist proceeding brought by the SEC, Administrative Law Judge (“ALJ”) Robert G. Mahony, interpreted internal accounting controls as:
the policies and procedures adopted within an organization that operate as a means of promoting operational efficiency, reliability in financial reporting, and encouraging adherence to managerial policies, applicable laws, and regulations. Internal accounting controls are one element of a control system implemented to safeguard assets and promote reliable financial records. They provide reasonable assurance that transactions are authorized and recorded as necessary to permit the preparation of financial statements in conformity with GAAP, or other applicable criteria, as well as limiting access to records and providing for periodic review to test for inconsistencies. In re Albert Glenn Yesner, CPA, Initial Decision, Exchange Act Release No. 184, 2001 WL 587989, at *33 (May 22, 2001) (internal citations omitted).
In light of the above, the statutory requirement that a public issuer “devise and maintain a system of internal accounting controls” is properly read to require that issuer to accurately report, record, and reconcile financial transactions and events. A cybersecurity control does not naturally fit within this term, as a failure to detect a cybersecurity deficiency (e.g., poorly chosen passwords) cannot reasonably be termed an accounting problem. Cybersecurity controls are undeniably vitally important, and their failures can have systemically damaging consequences. But these controls cannot fairly be said to be in place to “prevent and detect errors and irregularities that arise in the accounting systems of the company.” World-Wide Coin Ins., 567 F. Supp. at 750.
The SEC counters by arguing that SEC v. Cavco Industries Inc., No. 21 Civ. 01507 (PHX) (SRB), 2022 WL 1491279, at *4 (D. Ariz. Jan. 25, 2022), embraced its reading of the statutory term. The court there found that Cavco’s failure to follow its insider trading policy constituted an “internal accounting control” failure. Id. at *3-4. But its decision little avails the SEC here. Cavco had internal policies “to control corporate investing (‘Investment Policy’) and prevent insider trading (‘Insider Trading Policy’)” that required the company to invest its surplus cash assets in low-risk cash equivalents. Id. at *I. The company’s CEO created an end-run around the process that ordinarily required the CEO to obtain pre-approval for its investment of surplus cash from the CFO and the board of directors, and thereby invested funds in a publicly traded company without review or approval by the CFO or board. Id. at *1-2. The SEC’s claim under Section 13(b )(2)(B) was that the company had “insufficient checks for how investments outside the [Investment and Iusider Trading policies] would be identified and reported and for how improper investments would be prevented.” Id. at *3. Unlike the allegedly deficient cybersecurity controls in this case, the internal policies and controls in Cavco directly related to ensuring the integrity of the company’s financial transactions. The decision cannot responsibly be read as supporting the SEC’s argument here that Section 13(b)(2)(B) reaches cybersecurity controls.
The SEC next argues that it needs authority to regulate cybersecurity controls under Section 13(b )(2)(B) because such adequate controls are necessary “to provide reasonable assurances that … access to assets is permitted only in accordance with management’s general or specific authorization.” 15 U.S.C. § 78m(b)(2)(B)(iii). It notes that deficient cybersecurity controls can expose a company’s core assets to damage or destruction, reducing their value. But that argument does not engage with the critical word that delimits the statute’s reach: “a system of internal accounting controls.” Id. § 78m(b)(2)(B). By its terms, Section 13(b)(2)(B) does not govern every internal system a public company uses to guard against unauthorized access to its assets, but only those qualifying as “internal accounting” controls. The SEC’s rationale, under which the statute must be construed to broadly cover all systems public companies use to safeguard their valuable assets, would have sweeping ramifications. It could empower the agency to regulate background checks used in hiring nighttime security guards, the selection of padlocks for storage sheds, safety measures at water parks on whose reliability the asset of customer goodwill depended, and the lengths and configurations of passwords required to access company computers. That construction-and those outcomes-cannot be squared with the statutory text. See, e.g., United States v. Dauray, 215 F. 3d 257,264 (2d Cir. 2000) (“A statute should be interpreted in a way that avoids absurd results.”). Congress does not “hide elephants in mouseholes,” Cyan, Inc. v. Beaver Cnty. Emps. Ret. Fund, 583 U.S. 416,431 (2018), and the SEC does not recite any basis to conclude that Congress, in enacting Section 13(b )(2)(B), intended to confer such power upon the SEC.
The history and purpose of the statute confirm that cybersecurity controls are outside the scope of Section 13(b)(2)(B). Sections 13(b)(2)(A) and 13(b)(2)(B) were enacted as part of the 1977 Foreign Corrupt Practices Act (“FCP A”), amending the 1934 Securities Exchange Act, In re Yesner, 2001 WL 587989, at *33, and together are referred to as the “accounting provisions,” Foreign Corrupt Practices Act of 1977, Statement of Policy, 21 SEC Docket 1466, 1468 (Jan. 29, 1981). The FCPA was passed in response to “a pattern of questionable payments to foreign government officers by prominent American corporations.” Id. The accounting provisions were enacted “to assure books and records accurately and fairly reflected transactions and the disposition of assets, to protect the integrity of the independent audit, and to promote reliability and completeness of financial information that is disseminated to investors.” In re Yesner, CPA, 2001 WL 587989, at *31. And with regard to Section 13(b)(2)(B) in particular, Congress’s explicit purpose, as codified in the text, was to “provide reasonable assurances that, among other things, transactions are recorded as necessary to permit the preparation of financial statements in conformity with generally accepted accounting principles or any other applicable criteria.” S. Rep. No. 95-114 at 7 (1977) (emphasis added). Indeed, Congress recognized that because “the accounting profession has defined the objectives of a system of accounting control, the definition of the objectives contained in this subparagraph is taken from the authoritative accounting literature.” Id. (citing American Institute of Certified Public Accountants, Statement on Auditing Standards No. I, 320.28 (1973)) (emphasis added).
To that end, these provisions require public companies, in addition to filing with the SEC annual and quarterly reports containing detailed financial information, to put in place systems to ensure that the information reported is accurate and complete. Section 13(b)(2)(A) regulates financial recordkeeping. It requires public companies to “make and keep books, records, and accounts, which, in reasonable detail, accurately and fairly reflect the transactions and dispositions of [their] assets.” And Section 13(b)(2)(B), at issue here, requires issuers to “devise and maintain a system of internal accounting controls sufficient to provide reasonable assurances” that assets are safeguarded from unauthorized use, that corporate transactions conform to managerial authorizations, and that records are accurate. As evinced by the broader statutory scheme, the internal accounting controls identified in Section 13(b )(2)(B) thus are intended to provide extra assurance of the accuracy and completeness of the financial information on which the issuer’s annual and quarterly reports rely.
To state the obvious, cybersecurity controls are not-and could not have been expected to be-part of the apparatus necessary to the production of accurate such reports. The Court therefore dismisses the AC’s internal accounting control claim against SolarWinds for failure to state a claim. (In light of this dismissal, the Court also dismisses the aiding and abetting claim against Brown).”
