Walmart, Like Prior Issuers, Gets Whistled For Decentralized Compliance

July 22, 2019

Generally speaking, the FCPA’s internal controls provisions require issuers to “devise and maintain a system of internal accounting controls sufficient to provide reasonable assurances” that certain limited financial objectives are met. The FCPA then defines “reasonable assurances” to mean “such level of detail and degree of assurance as would satisfy prudent officials in the conduct of their own affairs.”

The main problem with these provisions is there is no specific standards by which to judge compliance. Indeed, as highlighted in this prior post, in SEC v. Worldwide Coin (believed to be the only judicial decision to substantively construe the FCPA’s books and records and internal controls provisions) the judge stated:  “The main problem with the internal accounting controls provision of the FCPA is that there are no specific standards by which to evaluate the sufficiency of controls; any evaluation is inevitably a highly subjective process in which knowledgable individuals can arrive at totally different conclusions.”

Nevertheless, it is clear that the FCPA enforcement agencies have come to the conclusion that decentralized compliance (whatever that may mean) is an internal control deficiency and as highlighted below in the recent Walmart enforcement action the company became the latest issuer to be whistled by the government for having decentralized compliance.

As stated by the DOJ in the Walmart NPA:

“On or about April 6, 2009, Walmart International announced the creation of a Walmart International Compliance Office that revised the existing anti-corruption standard. The concept for the new standard was “Freedom within a Framework.” Instead of taking a centralized approach to ensuring that sufficient anti-corruption related internal accounting controls were implemented throughout Walmart’s foreign subsidiaries, the new anti-corruption standard allowed individual markets to design and implement their own program as long as it met certain global standards.”

As stated by the SEC in the Walmart administrative order:

“In or around April 2009, Walmart informed its foreign subsidiaries that it would soon promulgate anti-corruption standards that would be more flexible and easier and quicker to implement. Instead of taking a centralized approach, each country would be required to devise its own program based on the standards. On or around June 11, 2009, Walmart circulated to the 10 subsidiaries a one-page document entitled Global Anti-Corruption Standards that: 1) summarized the FCPA; 2) acknowledged that in certain instances Walmart may provide gifts, meals, travel, and entertainment to government officials; 3) noted that the standards applied to TPIs; and 4) provided contact information for the Company’s global ethics office. The markets were instructed to design and implement risk-based internal accounting controls, procedures, and training to ensure the standards were met.”

Walmart was certainly not the first issuer to be whistled by the FCPA enforcement agencies for decentralized compliance.

For instance, in the 2013 Stryker enforcement action, the SEC found:

“Stryker’s foreign subsidiaries were organized in a decentralized, country-based structure, wherein a manager of a particular country’s operations had primary responsibility for all business within a given country. During the relevant period, each of Stryker’s foreign subsidiaries operated pursuant to individual policies and directives implemented by country or regional management. Stryker had corporate policies addressing anti-corruption, but these policies were inadequate and insufficiently implemented on the regional and country level.”

Likewise, in the 2013 ADM enforcement action, the SEC alleged:

“ADM’s anti-corruption policies and procedures relating to [a foreign affiliate] were decentralized and did not prevent improper payments by [foreign affiliate] to third-party vendors in the Ukraine or ensure that these transactions were properly recorded by [foreign affiliate]. In this respect, ADM failed to implement sufficient anti-bribery compliance policies and procedures, including oversight of third-party vendor transactions, to prevent these payments at [foreign affiliates].”

Likewise, in the 2014 Bio-Rad enforcement action the DOJ stated:

“Bio-Rad decentralized its compliance program such that its international offices were responsible for ensuring adequate compliance with its business ethics policy and code of conduct […] Bio-Rad did not take sufficient steps to monitor its international offices.”

In the 2017 Orthofix International enforcement action, the SEC found:

“[Parent company’s] reporting structure and relationship with its subsidiaries was decentralized … complicating parent oversight, compliance monitoring, and communication with U.S. executives. [Parent company] lacked adequate training, policies, processes, and corporate culture that would have allowed employees at its subsidiaries to raise compliance concerns to the parent level.”

FCPA Institute – Zoom (November 10-12)

Elevate your FCPA knowledge and practical skills. Nine hours of integrated and cohesive instruction led by Professor Koehler (an FCPA expert with teaching experience). Learn more, spend less. Professional credential available.

Learn More and Register