This prior post highlighted the Foreign Corrupt Practices Act enforcement action against McKinsey and Company Africa (Pty) Ltd (“MCKINSEY AFRICA”), a wholly owned and wholly controlled subsidiary of McKinsey & Company (an international consulting firm) concerning bribery schemes in South Africa.
This prior post highlighted how the matter was yet another FCPA enforcement action related to South Africa’s Broad-Based Black Economic Empowerment Program.
This post highlights additional issues to consider.
Timeline
McKinsey’s business practices in South Africa were the subject of scrutiny since at least mid-2018. (See here for a New York Times article).
From start to finish, the company’s FCPA scrutiny appears to have lasted approximately six years.
I’ve said it many times, and will continue saying it until the cows come home: if the DOJ/SEC want their FCPA enforcement programs to be viewed as more credible and more effective, the enforcement agencies must resolve instances of FCPA scrutiny much quicker.
This is particularly true in the McKinsey matter given the following language from the DOJ about the company’s cooperation:
“Such cooperation included: (i) immediately and proactively cooperating from the inception of the DOJ’s investigation; (ii) making numerous factual presentations to the DOJ over the course of their investigation, derived from information obtained through the Company’s internal investigation; (iii) collecting, reviewing, and producing voluminous records, including those located abroad, in response to requests from the DOJ; (iv) promptly reporting the discovery of document-deletion efforts by the McKinsey partner involved in the conduct found during its internal investigation, taking additional investigative steps to uncover information and evidence regarding those efforts, and producing such information and evidence to the DOJ; (v) reporting, in real time, newly discovered information and documents which allowed the DOJ to preserve and obtain evidence as part of their independent investigation; (vi) tracing complex internal accounting money-flows and currency exchange-information in response to requests from the DOJ; (vii) preserving, collecting and producing to the DOJ documents located abroad, and engaging a third-party forensics consultant to analyze key electronic devices and providing to the DOJ the results of that analysis; (viii) collecting and producing to the DOJ personal email and bank account information of the McKinsey partner involved in the conduct relevant to the DOJ’s investigation; (ix) engaging with the DOJ in response to a deconflicting request to preserve the integrity of the DOJ’s investigation; and (x) making Company officers and employees available for interviews.”
Gaining Access to Confidential Information
As discussed in this prior post, in several Foreign Corrupt Practices Act enforcement actions, the end result of things of value being offered or provided to alleged “foreign officials” is the company gaining access to confidential documents in the government’s possession.
Add the McKinsey enforcement action to this long list.
As alleged by the DOJ:
“In furtherance of the scheme, MCKINSEY AFRICA, together with co-conspirators, among other things: (a) obtained sensitive confidential and non-public information from Transnet and Eskom through CC 1 [a South African national and businessperson who worked in South Africa], CC 2 [a South African national and businessperson who worked in South Africa at Company 1 and Company 2] and others, regarding the award of consulting contracts; and (b) submitted proposals for multimillion-dollar consulting contracts to Transnet and Eskom on behalf of MCKINSEY AFRICA and partner firms, Company 1, and Company 2, knowing that a portion of the proposed consulting fees from the contracts would be used to pay bribes to Foreign Official 1 and Foreign Official 2.”
What Should Happen?
What should happen when a single individual at a company orchestrates a bribery scheme and takes various active steps to avoid detection by the company.
As alleged by the DOJ
“To avoid detection, Sagar [a former senior partner of McKinsey working in South Africa who separately pled guilty to conspiracy to violate the FCPA’s anti-bribery provisions] and CC 1 conducted meetings at coffee shops, restaurants, and other locations in and around Johannesburg, South Africa, instead of meeting at MCKINSEY AFRICA or Transnet offices. Sagar and CC 1 also limited their use of written communications over the course of the scheme, and when they did correspond via email, they often used private personal email addresses rather than Sagar’s McKinsey email address.”
We know what DID happen, but the question posed is what SHOULD happen?
What Should The Financial Consequences Be?
Separate from the issue of legal liability is the question of what should the financial consequences be.
According to the DOJ, “McKinsey and MCKINSEY AFRICA earned profits of approximately $85,000,000 as a result of the bribery scheme.” The DPA contained an advisory Sentencing Guidelines fine range of $180 million – $360 million and states that the appropriate criminal penalty is $122.85 million (Total Criminal Penalty). Pursuant to the DPA, McKinsey agreed to pay a monetary penalty of $61.425 million as the DOJ agreed to credit toward the Total Criminal Penalty the amount paid by McKinsey to authorities in South Africa from violations of South African law related to the same conduct.
It is interesting to note though that the DPA also states that McKinsey “voluntarily repay[ed], in 2018 and 2021, all revenues the Company and McKinsey received from potentially tainted contracts to the SOEs in South Africa from which it received contracts as a result of the criminal scheme.”
