Issues To Consider From The SAP Enforcement Action

January 25, 2024

This previous post highlighted the recent FCPA enforcement action against SAP based on conduct in South Africa, Indonesia, Malawi, Kenya, Tanzania, Ghana, and Azerbaijan.

This post highlights additional issues to consider.

Timeline

As highlighted in this previous post, in mid-2017 SAP disclosed that it was under FCPA scrutiny concerning its business practices in South Africa.

Thus, from start to finish, SAP’s FCPA scrutiny lasted an unconscionable 6.5 years.

I’ve said it many times, and will continue saying it until the cows come home: if the DOJ/SEC want their FCPA enforcement programs to be viewed as more credible and more effective, the enforcement agencies must resolve instances of FCPA scrutiny much quicker.

This is particularly true in the SAP matter given the following language from the DOJ:

“The Company’s cooperation included, among other things, (i) immediately beginning to cooperate after South African investigative reports made public allegations of the South Africa-related misconduct in 2017 and providing regular, prompt, and detailed updates to the Fraud Section and the Office regarding factual information obtained through its own internal investigation, which allowed the government to preserve and obtain evidence as part of its independent investigation; (ii) producing relevant documents and other information to the Fraud Section and the Office from multiple foreign countries expeditiously, while navigating foreign data privacy and related laws; (iii) at the request of the Fraud Section and the Office, voluntarily making Company officers and employees available for interviews; (iv) taking significant affirmative steps to. facilitate interviews while addressing witness security concerns; (v) raising and resolving potential deconfliction issues between the Company’s internal investigation and the investigation being conducted by the Fraud Section and the Office; (vi) promptly collecting, analyzing, and organizing voluminous information, including complex financial information, at the request of the Fraud Section and the Office; (vii) translating voluminous foreign language documents to facilitate and expedite review by the Fraud Section and the Office; and (viii) imaging the phones of relevant custodians at the beginning of the Company’s internal investigation, thus preserving relevant and highly probative business communications sent on mobile messaging applications.”

Likewise, the SEC stated:

“SAP cooperated in the Commission’s investigation by identifying and timely producing key documents identified in the course of its own internal investigation, providing the facts developed in its internal investigation, and making current or former employees available to the Commission staff.”

Voluntary Disclosure Or Not?

In 2017, SAP issued a press release which stated that it “had initiated its voluntary disclosure” to the DOJ and SEC concerning its South Africa business “on July 13, 2017.”

In its recent administrative order, the SEC stated that the “Commission considered SAP’s self-reporting of certain conduct.”

However, the DOJ resolution documents state: “the Company did not receive voluntary disclosure credit … because it did not voluntarily and timely disclose to the Fraud Section and the Office the conduct …”.

So, what is it? A voluntary disclosure or not?

Third Party Issues

The SAP enforcement action contains a laundry list of third party deficiencies (in the eyes of the DOJ/SEC) including the following:

“SAP conducted only limited due diligence of Intermediary 2 during its onboarding in 2015. Subsequent review by SAP in 2017 revealed that Intermediary 2 had no financial statements (audited or unaudited), had not filed any returns for employee tax purposes, and found no signs of activity at Intermediary 2’s claimed business address.”

“SA Intermediary 1 is a South African tech company, known for various corrupt business activities, and is controlled by a South African-based family. According to the terms of the deal, SA Intermediary 1 was to receive a 10% commission for the deal and was to perform certain deliverables. In reality, it did not perform any actual work for SAP. There is no record of SA Intermediary 1 ever being present at meetings with Transnet, nor does SA Intermediary 1 appear to have a credible IT background or experience.”

“SAP South Africa and its employees knew about the red flags relating to SA Intermediary 2’s ownership. The former director of SA Intermediary 2 admitted that the entity had “no expertise” or skills to provide meaningful services on the Transnet deal and also said he had no knowledge of SA Intermediary 2 providing any services. During an SAP-initiated audit of SA Intermediary 2, the third party failed to provide evidence of any services performed.”

“In November 2016, SAP South Africa closed a deal with Eskom, a state-owned entity and the largest producer of electricity in South Africa, to renew software licenses for approximately $28.58 million. Internally, SAP South Africa set aside several million dollars from this renewal fee to pay SA Intermediary 3, a purported IT consultant on the Eskom project. SA Intermediary 3, however, never performed any services. Instead, SAP South Africa’s Managing Director instructed SAP South Africa employees to perform the consulting work in SA Intermediary 3’s stead and still paid the entity a total of $1.6 million. Notably, officials at Eskom approved these payments despite SA Intermediary 3’s absence on the project. SAP also retained SA Intermediary 2 to perform vague services on Eskom contracts dated March, 2016 and November 2016 that, as a 3D printing company, SA Intermediary 2 was unqualified to perform. Regardless, SAP South Africa paid SA Intermediary 2 a total of $5.18 million in consulting fees.”

Anything of Value

If you are looking to add to your “anything of value” list, the SAP enforcement action included the following things of value: handbags, keychains, a luxury watch, novelties, gifts, meals, golf outings, and other items.

Justified or Not?

In the resolution documents, the government mentions (and thus seemingly endorses) the following remedial measure by SAP:

“(iii) eliminating its third-party sales commission model globally, and prohibiting all sales commissions for public sector contracts in high-risk markets.”

A large technology company eliminating its third-party sales commission model globally?

Justified or not? Practical or not? Sustainable or not?

Interesting Quote

In the DOJ press release, U.S. Attorney Jessica Aber for the Eastern District of Virginia stated:

“SAP has accepted responsibility for corrupt practices that hurt honest businesses engaging in global commerce. We will continue to vigorously prosecute bribery cases to protect domestic companies that follow the law while participating in the international marketplace.” (emphasis added).

So … the reason the U.S. brought an enforcement action against a German company for its interactions with officials in South Africa, Indonesia, Malawi, Kenya, Tanzania, Ghana, and Azerbaijan was to protect U.S. companies?

That is interesting.

Damned If You Don’t, Damned If You Do 

Per the SEC:

“During the relevant time frame, SAP’s internal policies and procedures for working with third parties required employees to conduct due diligence to assess risk and ensure: (1) That a third party had no relations (as a family member) to the SAP customer or a potential customer, and (2) that the third party was not a government official, government employee, political party official or candidate, or officer or employee of any public international organization or an immediate family member of any of these. In addition, with respect to BDPs, all sales commission contracts had to be in writing and clearly define the services to be provided and the related business and payment terms. SAP subsidiaries and employees were required to use a model agreement that included standard commission rates and to follow a standardized internal approval process, which required the involvement and approval of the local legal department or compliance officer, the subsidiary’s local managing director, and its local chief financial officer. In cases where a BDP agreement required non-standard terms, regional management had to provide additional approvals. The policy documents explicitly state that they were put into place to ensure that no relationship with a third party would be used to inappropriately influence a business decision or pay bribes to government officials.”

You can bet the farm that if SAP did not have these internal policies and procedures, that the SEC would have found SAP’s internal controls deficient.

Yet, SAP did have these internal policies and procedures.

Even so, in the words of the SEC:

“SAP’s wholly-owned subsidiaries—SAP South Africa, SAP Africa, SAP Indonesia and SAP Azerbaijan—repeatedly violated these internal policies to engage in bribery schemes with the help of third party intermediaries from at least December 2014, to obtain or retain business. Because the payments were made by third parties acting outside of SAP’s own systems, SAP lacks sufficient records to determine with specificity the full scope of the bribe schemes.”

Thus, a company is damned if they don’t and damned if they do when certain actors act “outside of [a company’s] own systems.”

In the words of the SEC, under the heading ““SAP Had Inaccurate Books and Records and Insufficient Accounting Controls to Detect or Prevent Bribery,”:

“The bribe payments made by SAP South Africa, SAP Africa, SAP Indonesia, and SAP Azerbaijan were inaccurately recorded as legitimate commission or other expenses in SAP’s books and records. SAP lacked the internal accounting controls sufficient to detect or prevent such payments. Specifically, SAP lacked adequate due diligence and vetting to properly assess risk and approve payments to the third parties it worked with in these jurisdictions.

SAP did not adequately address the high risk of bribery and corruption in South Africa, Greater Africa, Indonesia, and Azerbaijan and did not implement sufficient internal accounting controls to address those risks. The company failed to implement sufficient payment approval controls to ensure that services were actually rendered, or expenses were actually incurred, before issuing payments to third parties. Although SAP had a corporate anti-corruption policy in place during the relevant time period, SAP had insufficient formal monitoring, or internal controls in place, to ensure that SAP South Africa, SAP Africa, SAP Indonesia, or SAP Azerbaijan were adhering to the relevant policies.

Lastly, SAP lacked entity level controls over SAP South Africa, SAP Africa, SAP Indonesia, and SAP Azerbaijan because of the lack of oversight over personnel in those jurisdictions.”

Also, keep in mind that the SEC’s professed “detect or prevent” standard is nowhere to be found in the FCPA.

Elevate Your FCPA Research

There are several subject matter tags in this post. However, only subscribers to FCPA Professor’s premium search feature can see and use them in research. Efficient and cost-effective FCPA research is just a click away.

Elevate Your Research