For years, DOJ officials have been talking about policy issues surrounding merger & acquisition activity and potential criminal conduct.
Earlier this week, Deputy Attorney General Lisa Monaco announced a “new safe harbor policy for voluntary self-disclosures made in connection with mergers and acquisitions.”
However, as highlighted below, substantively the policy is not really new, nor is it a safe harbor as companies who follow the policy and “receive the presumption of a declination” will still have to pay a disgorgement amount (which in the FCPA context can be millions and sometimes higher than other forms of resolution such as a non-prosecution or deferred prosecution agreement).
Before highlighting Monaco’s recent speech, set forth below is a sampling of speeches from DOJ officials over the past five years on the topic of policy issues surrounding merger & acquisition activity and potential criminal conduct.
As highlighted in this post, in 2018 Deputy Assistant Attorney General Matthew Miner stated that “one area where [the DOJ] would like to do better is with regard to mergers and acquisitions, particularly when such activity relates to high-risk industries and markets.”
Miner stated:
“Currently, the DoJ/SEC Resource Guide to the FCPA, which was released in 2012, provides some guidance on this. In particular, the Guide recognizes that in the past the Department and SEC have declined to take action where companies voluntarily disclosed and remediated, and cooperated with the government. The Guide also notes that “a successor company’s voluntary disclosure, appropriate due diligence, and implementation of an effective compliance program may also decrease the likelihood of an enforcement action regarding an acquired company’s post-acquisition conduct when pre-acquisition due diligence is not possible.” Furthermore, after laying out several M&A best practices, the Guide states that the “DOJ . . . will give meaningful credit to companies who undertake these actions, and, in appropriate circumstances, DOJ . . . may consequently decline to bring enforcement actions.”
Miner continued:
“While these policies are sound, I know from experience that “may” decline is a significant sticking point for corporate management when deciding whether and how to proceed with a potential merger or acquisition. There is a big difference between a theoretical outcome and one that is concrete and presumptively available. At the Department, we know that there are many benefits when law-abiding companies with robust compliance programs are the ones to enter high-risk markets or, in appropriate cases, take over otherwise problematic companies. Not only can the acquiring company help to uncover wrongdoing, but more importantly the acquiring company is in a position to right the ship by applying strong compliance practices to the acquired company.
We want to encourage this sort of activity. We certainly don’t want the specter of enforcement to be a risk factor that impedes such activity by good actors, and instead cedes the field to non-compliant companies. At bottom, it makes good economic sense and helps stamp out corruption when the Department adopts policies that foster greater corporate compliance.
When an acquiring company conducts robust due diligence that unearths wrongdoing, reports that conduct to the Department, and engages in remedial measures, including extending already robust compliance to the acquired company, it frees up resources for the Department that may have otherwise been expended investigating the acquired company. These resources can then be directed to other cases, not only in the FCPA context, but also to other areas such as opioid enforcement, human trafficking, and crimes impacting vulnerable victims, like children and the elderly.
For these reasons, I want to make clear that we intend to apply the principles contained in the FCPA Corporate Enforcement Policy to successor companies that uncover wrongdoing in connection with mergers and acquisitions and thereafter disclose that wrongdoing and provide cooperation, consistent with the terms of the Policy. We believe this approach provides companies and their advisors greater certainty when deciding whether to go forward with a foreign acquisition or merger, as well as in determining how to approach wrongdoing discovered subsequent to a deal. We are fully cognizant that in some instances an acquiring company has limited access to a target company’s data and records, perhaps even more so when the target company is in a high risk jurisdiction. In those instances, if an acquiring company unearths wrongdoing subsequent to the acquisition, we want to encourage its leadership to take the steps outlined in the FCPA Policy, and when they do, we want to reward them, accordingly for stepping up, being transparent, and reporting and remediating the problems they inherited.
[…]
This is not to say that wrongdoers will be getting a pass for corrupt behavior that occurred in the past in an acquired entity. Far from it. The Department continues to focus on individual accountability, and those responsible for past wrongdoing or the concealment of wrongdoing will continue to be investigated and prosecuted.”
Later in 2018, Miner stated:
“[T]his past July, I announced that going forward we will seek to apply the FCPA Corporate Enforcement Policy principles to mergers and acquisitions that uncover potential FCPA violations. We felt this clarification was needed because the Department’s guidance regarding mergers and acquisitions that was announced in the 2012 FCPA Guide and elsewhere was not updated or otherwise incorporated into the FCPA Corporate Enforcement Policy. The clarification was intended to be just that – a clarification that the new Policy also applied to misconduct detected through M&A activity and due diligence. Consistent with the goal of clarity and consistency, it is also why today I’m letting you know that we will also look to these principles in the context of mergers and acquisitions that uncover other types of potential wrongdoing, not just FCPA violations. The last situation we want to create is one where corporations and their attorneys uncover a problem and then face uncertainty as to what to do next. We are fully cognizant that in some instances an acquiring company has limited access to a target company’s data and records in pre-acquisition diligence. We also recognize that corporate deals often move quickly. In those instances, if an acquiring company unearths wrongdoing subsequent to the acquisition, we want to encourage its leadership to take the steps outlined in the FCPA Policy, and when they do, we want to reward them for stepping up, being transparent, and reporting and remediating the problems they inherited.”
[…]
At the Department, we know that there are many benefits when law-abiding companies with robust compliance programs are the ones to take over otherwise problematic companies. Not only can the acquiring company help to uncover wrongdoing, but more importantly, the acquiring company is in a position to right the ship by applying strong compliance practices to the acquired company. When an acquiring company conducts robust due diligence that unearths wrongdoing, reports that conduct to the Department, and engages in remedial measures, including extending already robust compliance to the acquired company, it frees up resources for the Department that may have otherwise been expended investigating the acquired company. Most importantly, it stops the misconduct.”
As highlighted here, later in 2018 Principal Deputy Assistant Attorney General John Cronan stated:
“I want to say a few words about compliance in the context of mergers and acquisitions. When we talk of top-to-bottom cultures of compliance, the Department fully recognizes that there are unique challenges that arise during mergers and acquisitions.
Let me start with stating the obvious. We recognize that considerable benefits flow from law-abiding companies with robust and effective compliance programs acquiring or merging with companies with inferior compliance programs. The acquiring or merging company can help uncover compliance shortcomings or employee misconduct, and then right the ship going forward after acquisition or merger. This, of course, is a good thing, and something we want to encourage. We also do not want concerns about future exposure to deter good actors from acquiring or merging with troubled companies, and as a result giving way to acquisition or merger by companies with weaker compliance.
That is why, as I mentioned before, we have announced that the FCPA Corporate Enforcement Policy applies to mergers and acquisitions, and that the Criminal Division would apply the principles of the Corporate Enforcement Policy to mergers and acquisitions outside the FCPA context.
We recognize that it would be a rare situation for an acquiring or merging company to conduct a full, worldwide pre-acquisition deep dive on the acquisition or merger target, but it makes sense to get an understanding of the target company’s risk profile and control systems. This permits the acquiring or merging company to identify what areas it needs to take a close look at, as well as any subsidiaries or divisions it wants to focus on reviewing.
It stands in a company’s interest to take a close look at those soft spots and, if misconduct is uncovered, to attempt to address the issue prior to merger or acquisition. This could entail disclosure of the issues, if appropriate given the posture of the merger or acquisition, or it could entail taking advantage of the Fraud Section’s FCPA Opinion Procedure. For those unfamiliar with the FCPA Opinion Procedure, issuers and domestic concerns can obtain an opinion from the Department of Justice as to whether certain specified, prospective conduct conforms with the Department’s present enforcement policy under the FCPA.
Why does that make sense? By taking such pre-merger or acquisition action – whether through self-disclosure or an FCPA Opinion – the companies entering into the merger or acquisition are able to receive more certainty going into the transaction and more accurately build that certainty into the transaction. The government may respond after a merger or acquisition in a manner that the companies did not anticipate and, as a result, the companies failed to appropriately price the transaction. Similarly, self-disclosure prior to an acquisition, or at the earlier possible point, permits companies to take full advantage of the significant benefits that are available to voluntarily disclosing companies. Furthermore, when two companies are involved in a transaction, the chance that a whistleblower will learn of the misconduct and report it only increases.
But we also realize that, in some circumstances, even the best pre-acquisition due diligence may not uncover problems until after a deal closes. And even an acquiring company with a strong culture of compliance may struggle to impose and imprint that culture on a newly-acquired business. But again, the Department endeavors to be clear-eyed about the importance of self-reporting and proactively addressing problems as they arise, whenever they come to light, even if it is after-the-fact. Our interest will be to zero in on the culpable individuals, and to focus on giving due credit to efforts to cooperate and remediate, not to punish a company for punishment’s sake.”
In 2019, Miner returned to the issue of merger and acquisition activity and acknowledged that the DOJ “realized that we hadn’t provided adequate guidance regarding how we would approach misconduct discovered as part of a merger or acquisition.” (See here for the prior post).
Miner stated:
“Aside from the questions counsel might face once misconduct was detected, we realized that uncertainty in this area could create a chilling effect, causing risk-averse companies with strong compliance cultures to shy away from acquisitions, especially in higher-risk markets. We amended our policies to make clear that the benefits of our voluntary self-disclosure policies would also be available to entities that uncover misconduct in an acquired entity and take appropriate action.
We want companies to invest in robust and effective compliance programs in advance of misconduct, as well as in a prompt remedial response to any misconduct that is discovered. But one can imagine a general counsel, chief compliance officer, or even a consultant being questioned about the concrete value of such investments, especially if the perspective is that Department will second-guess the adequacy of any program that allowed misconduct to occur. One can imagine questions akin to, “aren’t we going to have make these investments again, so why do them now?” “Doesn’t this just increase our chances of finding a problem – what’s the point of doing more than the minimum?” Or, “Isn’t the government just going to require a monitor, regardless of what we do in response to this mess?” It is for this reason that we have sought to be transparent about our approach to compliance programs, developing guidance for Criminal Division attorneys to use that not only sets forth questions that can be used to probe a program’s adequacy, but also the underlying rationale for such questions – explaining what we’re seeking to get at and how compliance program adequacy factors into our decision-making. We have also set forth guidance to make clear when the appointment of a monitor is appropriate – and not – pointing to the maturity of a compliance program as one of the key criteria.”
Without really mentioning or acknowledging DOJ’s prior statements on the issue, Monaco announced the DOJ’s “latest effort to promote voluntary self-disclosure” – a so-called “new Mergers & Acquisitions Safe Harbor policy.”
Monaco stated:
“In a world where companies are on the front line in responding to geopolitical risks – we are mindful of the danger of unintended consequences. The last thing the Department wants to do is discourage companies with effective compliance programs from lawfully acquiring companies with ineffective compliance programs and a history of misconduct. Instead, we want to incentivize the acquiring company to timely disclose misconduct uncovered during the M&A process.
Now, in 2008, the FCPA Unit published an opinion requested by the energy company Halliburton, in which the Department said it did not intend to take enforcement action against Halliburton for misconduct it self-disclosed and remediated post-acquisition within a certain timeframe. That opinion applied only to that transaction, however, and did not have broader application.
Since then, some parts of the Department have addressed M&A transactions as part of their Voluntary Self Disclosure policies, though they differ from each other in approach. So today, for the first time, we are announcing a Department-wide Safe Harbor Policy for voluntary self-disclosures made in the context of the mergers and acquisition process. Going forward, acquiring companies that promptly and voluntarily disclose criminal misconduct within the Safe Harbor period, and that cooperate with the ensuing investigation, and engage in requisite, timely and appropriate remediation, restitution, and disgorgement – they will receive the presumption of a declination.
To ensure consistency, I am instructing that this Safe Harbor policy be applied Department-wide. Each part of the Department will tailor its application of this policy to fit their specific enforcement regime, and will consider how this policy will be implemented in practice.
To ensure predictability, we are setting clear timelines. As a baseline matter, to qualify for the Safe Harbor, companies must disclose misconduct discovered at the acquired entity within six months from the date of closing. That applies whether the misconduct was discovered pre- or post-acquisition.
Companies will then have a baseline of one year from the date of closing to fully remediate the misconduct. Both of these baselines are subject to a reasonableness analysis because we recognize deals differ and not every transaction is the same. So, depending on the specific facts, circumstances, and complexity of a particular transaction, those deadlines could be extended by Department prosecutors. And of course, companies that detect misconduct threatening national security or involving ongoing or imminent harm can’t wait for a deadline to self-disclose.
For transparency, we are making clear that aggravating factors will be treated differently in the M&A context. The presence of aggravating factors at the acquired company will not impact in any way the acquiring company’s ability to receive a declination. Now, one question we have heard is how the Department will treat the acquired entity when an acquirer voluntarily self-discloses under the Safe Harbor Policy. Unless aggravating factors exist at the acquired company, that entity can also qualify for applicable VSD benefits, including potentially a declination.
Finally, misconduct disclosed under the Safe Harbor Policy will not affect any recidivist analysis at the time of disclosure or in the future. Put another way, any misconduct disclosed under the Safe Harbor Policy will not be factored into future recidivist analysis for the acquiring company.
Of course, this policy will only apply to criminal conduct discovered in bona fide, arms-length M&A transactions. The Safe Harbor does not apply to misconduct that was otherwise required to be disclosed or already public or known to the Department. Nor will anything in this policy impact civil merger enforcement.
So, for those advising boards and deal teams – here are the takeaways. We are placing an enhanced premium on timely compliance-related due diligence and integration. Compliance must have a prominent seat at the deal table if an acquiring company wishes to effectively de-risk a transaction.
By contrast, if your company does not perform effective due diligence or self-disclose misconduct at an acquired entity, it will be subject to full successor liability for that misconduct under the law. Our goal is simple: good companies – those that invest in strong compliance programs – will not be penalized for lawfully acquiring companies when they do their due diligence and discover and self-disclose misconduct.
And we are doubling down on clarity and predictability. Through careful due diligence and timely post-acquisition integration – alongside self-disclosure, remediation, disgorgement, and cooperation where warranted – acquiring companies can protect shareholders, promote compliance, and advance the goal of fighting corporate crime.”

FCPA Institute – Zoom (November 10-12)
Elevate your FCPA knowledge and practical skills. Nine hours of integrated and cohesive instruction led by Professor Koehler (an FCPA expert with teaching experience). Learn more, spend less. Professional credential available.
