It’s that time of year when articles go from my “reading stack” to “just read stack.”
One such article was “Corporate Governance in an Era of Compliance” by Professor Sean Griffith and recently highlighted on the FCPA Blog.
There are several assertions in the article I agree with and indeed I, and others, have highlighted for several years such as: (i) “DPAs/NPAs … have a strong signaling effect on firms not party to the immediate settlement, pushing them to adopt compliance mechanisms similar to those upon their peers”; (ii) “it remains difficult to demonstrate the effectiveness of the compliance function;” (iii) government enforcement actions are often “foisted upon firms through an opaque settlement process, where the government has the whip hand, and the company accedes to its demands …”; (iv) “there is no serious judicial oversight of the [settlement] process” of government enforcement actions; (v) “prosecutors are larding firms with [compliance] cost for uncertain benefit” and that certain compliance mandates “merely amount to a wealth transfer from the firm to the third party [service provider].”
Yet, as described in this post, I have a fundamental disagreement with the thesis of the article. In addition, I propose a better solution (to those proposed in the article) to the problems highlighted in the article.
The main thesis of “Corporate Governance in an Era of Compliance” appears to be that the “impetus for compliance” comes from the government and that “government interventions in compliance come not through the traditional levers of state corporate or federal securities laws, but rather through prosecutions and regulatory enforcement actions.”
Stated differently, the “central argument” of the article is that the “contemporary compliance department is the product of a de facto government mandate that, although felt most strongly by firms in highly regulated industries, has become a market-wide concern.”
As further stated in the article:
“compliance cannot be explained by reference to traditional governance authorities, whether the board of directors, state corporate law, or federal securities law. Rather compliance is sui generis”
“compliance is made by government enforcers – prosecutors and regulatory enforcers – who promulgate de facto corporate governance standards despite possessing neither statutory nor regulatory authority to do so.”
As to the origins of compliance, the article asserts that it “has not been led by regulators or legislators enacting amendments to corporate or securities law – the government traditional inroads to corporate affairs” but “rather, compliance has been championed by the government’s enforcement agents.”
I have some fundamental disagreements regarding the salient assertions in the article.
Starting with state corporate law, the article mentions (as it surely must) a series of Delaware cases (Graham v. Allis Chalmers, In re Caremark and Stone v. Ritter).
However, the articles dismisses these judicial opinions as not being a proper source of compliance because they (along with corporate law in general) “provide[] no guidance as to adequacy” and that “as a result, state corporate law has not meaningfully contributed to the development of compliance.” To use the words in the article “whatever compliance may be, it is not the product of corporate law.”
My belief is that state corporate law (Delaware in particular) has meaningfully contributed to the development of compliance. The evolution has been as follows.
- Allis-Chalmer (1963) – Absent cause for suspicion, there is no duty upon the directors to install and operate a corporate system of espionage to ferret out wrongdoing which they have no reason to suspect it.
- Caremark (1996 Del. Trial Court Decision) – A director’s obligation includes a duty to attempt in good faith to assure that an adequate corporate information and reporting system exists and a failure to do so, in some circumstances, may give rise to director liability.
- Stone (2006 – Del. Supreme Court Decision) – Endorsing the Caremark standard and further articulating the necessary conditions for director oversight liability.
Just because, as recognized in the article, Stone v. Ritter (as did Caremark) establishes a high hurdle for director oversight liability does not mean that state corporate law has not meaningfully contributed to the development of compliance. (The standard articulated in Stone v. Ritter is it must be shown that directors utterly failed to implement any reporting or information system or control or having implemented such systems or controls, consciously failed to monitor or oversee its operations and further both situations require a showing that the directors knew that they were not discharging their fiduciary obligations)
Moreover, just because the Delaware decisions do not provide crystal clear guidance as to the necessary conditions for director oversight liability does not mean that state corporate law has not meaningfully contributed to the development of compliance. Indeed, the lack of crystal clear judicial guidance is true of most legal norms that derive from state common law. Think of the tort of negligence: who owes a duty to another? what is the relevant standard of care? what does causation mean? It depends is often the answer to these questions.
The article next turns to federal securities and states that “compliance cannot be understood as an outgrowth of securities regulation.”
Missing however from this section is any mention of the FCPA’s internal controls provisions (which are, after all, part of the securities laws).
These provisions, which are among the most generic legal provisions one will ever find, require issuers to devise and maintain a system of internal accounting controls sufficient to provide reasonable assurances that transactions are properly authorized, recorded, and accounted for by the issuer.
In short, the internal controls provisions, the product of a legislative process, very much contributed to the development of compliance. As stated in a 1977 Senate Report:
“The establishment and maintenance of a system of internal controls and accurate books and records are fundamental responsibilities of management. The expected benefits to be derived from the conscientious discharge of these responsibilities are of basic importance to investors and the maintenance of the integrity of our capital market system.”
Although lacking meaningful mention of the FCPA’s internal controls provisions, “Corporate Governance in an Era of Compliance” does rightly acknowledge that “when the government acts through the SEC to regulate corporate governance, it acts subject to important institutional constraints, including the requirement that the Agency perform a persuasive cost-benefit analysis.” According to the article, “when the government intervenes in compliance, it does not act as a regulator and thus is not subject to the constraints of public comment and cost-benefit analysis.”
Here again however, the article fails to mention several pieces of SEC guidance relevant to the internal controls provisions that resulted from the regulatory requirements of the time.
For instance, in 1979 the SEC published rules concerning the internal controls provisions. In promulgating the rules, the SEC received numerous public comments. (See 44 Fed. Reg. 10, 968 (Feb. 23, 1979). In 1981, the SEC issued additional formal guidance concerning the FCPA’s books and records and internal control provisions. The guidance was in the form of a speech given by the SEC Chairman that was thereafter adopted as a formal statement of SEC policy. (See SEC Release No. 17500 (Jan. 29, 1981).
In short, and as highlighted above, state corporate law and securities regulation (both in terms of express statutory requirements and SEC rules and guidance) have meaningfully contributed to the development of compliance.
“Corporate Governance in an Era of Compliance” concludes by proposing two solutions to the problem of “compliance being made by government enforcers – prosecutors and regulatory enforcers – who promulgate de facto corporate governance standards despite possessing neither statutory nor regulatory authority to do so.”
The first – “end the government’s role as the architect of compliance, allowing firms to adopt compliance programs (or not) on the basis of efficiency concerns along while still holding them accountable for violations of substantive law.”
The second – “increase transparency of the compliance function on an ongoing basis through periodic disclosures in securities law filings.”
Regarding the first proposed solution, it must be noted that the FCPA’s internal controls provisions have long recognized (both in terms of statutory language and SEC guidance) that firms have the flexibility to adopt compliance programs (or not) on the basis of efficiency concerns. For instance, the 1981 SEC Guidance states:
“The Act does not mandate any particular kind of internal controls system. The test is whether a system, taken as a whole, reasonably meets the statute’s specified objectives. ‘Reasonableness,’ a familiar legal concept, depends on an evaluation of all the facts and circumstances.”
[…]
“Private sector decisions implementing these statutory objectives are business decisions. And, reasonable business decisions should be afforded deference. This means that the issuer need not always select the best or the most effective control measure. However, the one selected must be reasonable under all the circumstances.”
Likewise, in a 1999 SEC Staff Accounting Bulletin ( SEC Staff Accounting Bulletin: No. 99 – Materiality, 17 CFR Part 211 [Release No. SAB 99], Staff Accounting Bulletin No. 99 (Aug. 12, 1999)) the SEC stated:
“[Congress] adopted the prudent man qualification [in the FCPA’s books and records and internal control provisions] in order to clarify that the current standard does not connote an unrealistic degree of exactitude or precision. The concept of reasonableness of necessity contemplates the weighing of a number of relevant factors, including the costs of compliance.”
In the same Bulletin, the SEC also cited with approval various aspects of the above-mentioned 1981 formal statement of policy.
“As [the SEC] Chairman noted with respect to the internal control provisions of the FCPA, “thousands of dollars ordinarily should not be spent conserving hundreds. […] Because the judgment of [‘reasonableness’ under the accounting provisions] is not mechanical, the [SEC] staff will be inclined to defer to judgments that ‘allow a business, acting in good faith, to comply with the Act’s accounting provisions in an innovative and cost-effective way.”
In short, the first proposed solution in “Corporate Governance in an Era of Compliance” already captures the existing statutory and regulatory standard.
As to the second proposed solution, the article suggests”increas[ing] transparency of the compliance function on an ongoing basis through periodic disclosures in securities law filings” and then suggests a long list of “mandatory compliance disclosures” such as “how compliance is organized,” “whether and how compliance is involved in strategic business decisions,” “how escalation and reporting structures work, and whether and to what degree compliance influence executive compensation.”
Regarding this proposed solution, it must be recognized that it would only cover issuers (a relatively small section of the total number of business organizations subject to corporate governance standards). Moreover, it is a curious suggestion given that other portions of the article argued that it is “difficult to demonstrate the effectiveness of the compliance function.” In other words, what is disclosure of the above-suggested vague topics really going to accomplish other than raising the compliance costs for companies subject to the proposed “mandatory compliance disclosures”?
Regarding the second proposed solution, the article asserts that federal securities law, “which forces public companies to disclose a vast amount of information, does not mandate any compliance disclosures.”
That is not exactly true.
For instance, in 2003, the SEC issued a final rule implementing Section 406 of the Sarbanes Oxley Act of 2002 (the “Sarbanes-Oxley Act”), which directed the Commission to devise and promulgate requirements for the disclosure of “codes of ethics” by public companies. The final rule defines a “code of ethics” as “written standards that are reasonably designed to deter wrongdoing and to promote,” among other things, “[c]ompliance with applicable governmental laws, rules and regulations.” The Commission’s final rule requires public companies to disclose their codes of ethics to the public by either (i) filing them as an exhibit to an annual report (on Form 10-K), or (ii) posting them on the company’s website. The final rule also requires that certain types of changes to a company’s code of ethics must be disclosed within four business days of the change where the company elects to disclose its code of ethics on its website.
In short, the two solutions proposed in “Corporate Governance in an Era of Compliance” are not the best solutions to the problem of “compliance being made by government enforcers – prosecutors and regulatory enforcers – who promulgate de facto corporate governance standards despite possessing neither statutory nor regulatory authority to do so.”
A third solution will be much more effective and it is basic.
If a business organization does not want post-enforcement action compliance obligations imposed upon it, assert factual and legal defenses to the enforcement action theories and force the DOJ and/or SEC to prove their case subject to applicable burdens of proof.
To state the obvious, if the DOJ or SEC does not prevail, there will be no post-enforcement action compliance obligations.
For example, Lindsey Manufacturing was not subject to any post-enforcement action compliance obligations. Rather, it mounted a defense, forced the DOJ to prove its FCPA case, and ultimately prevailed.
Likewise, Cobalt was not subject to any post-enforcement action compliance obligations. Rather, when hit with an SEC Wells Notice, it mounted a defense, forced the SEC to prove its FCPA case, and ultimately prevailed.
Outside the FCPA context, Vascular Solutions was not subject to any post-enforcement action compliance obligations. Rather, it mounted a defense, forced the DOJ to prove its case, and prevailed.
MetLife is not going to be subject to onerous compliance requirements the government sought to impose on its for being a “systemically important” non-bank financial institution under the Dodd-Frank Wall Street Reform and Consumer Protection Act. Rather, it mounted a defense, forced the government to prove its case, and prevailed.
Most recently, FedEx was not subject to any post-enforcement action compliance obligations. Rather, it mounted a defense, forced the DOJ to prove its case, and recently prevailed.
In short, the legal and regulatory environment that business organizations find themselves in (including the post-enforcement action compliance obligations imposed on settling companies that “Corporate Governance in an Era of Compliance” rightly notes then often serve as signaling devices to non-parties) are largely the result of excessive risk aversion and the lack of spine business leaders have in standing up to the government.
Stated differently, business organizations and their counsel are part of the problem. As to the later, stop to ponder who is the greatest beneficiary of post-enforcement action compliance obligations and reporting requirements?
Some might be inclined to respond to this best solution as being impractical because of the collateral consequences of challenging the government. However, in case you haven’t heard the “Arthur Anderson effect” has been debunked as a myth and the government itself has acknowledged that there is a very small chance that a company would be put out of business as a result of actual DOJ criminal charges. As highlighted in this recent post, the “Arthur Anderson effect” should be dead after the FedEx enforcement action.