Kroll’s recent 2022 Anti-Bribery and Corruption Benchmarking Report caught my eye (and not just because it contains beautiful photography of slot canyons and Moab, Utah area attractions such as Delicate Arch – from different vantage points – and Corona Arch).
According to the report:
“In February 2022, Kroll analyzed data from 100 U.S. and Canadian compliance professionals, the vast majority of whom projected confidence in their firms’ ability to meet challenges posed by new or tightened regulations.
In the U.S. and Canada, 70% of survey respondents ranked their companies’ ABC programs as effective, including 45% that ranked them as very effective. Over 60% attributed their confidence in the programs to the results of internal audits and the absence of bribery or corruption incidents identified to date. Respondents also overwhelmingly maintained that their organizations are meaningfully committed to a culture of integrity (74%), that senior management within the organization supports the compliance function (75%) and signals that compliance and accountability are important (75%), that new business initiatives receive appropriate risk assessment (72%) and that performance goals and incentives do not conflict with compliance processes (74%).”
The report then contains the following graphic:

The above information and data is interesting.
What does effective even mean?
Are there any actual laws or regulations that require anti-bribery and corruption (or any) compliance programs to be effective?
The FCPA’s internal controls provisions surely do not require effectiveness.
Rather, the provisions generally require issuers to “devise and maintain a system of internal accounting controls sufficient to provide reasonable assurances that” certain limited financial objectives are met.
The FCPA then defines “reasonable assurances” and “reasonable detail” to “mean such level of detail and degree of assurance as would satisfy prudent officials in the conduct of their own affairs.”
This is surely a different standard than effective.
How different is an open question as the FCPA’s internal controls provisions lack specific standards.
The leading case on the meaning of the internal controls provisions is SEC v. Worldwide Coin in which the court stated:
“The main problem with the internal accounting controls provision of the FCPA is that there are no specific standards by which to evaluate the sufficiency of controls; any evaluation is inevitably a highly subjective process in which knowledgable individuals can arrive at totally different conclusions. Any ruling by a court with respect to the applicability of both the accounting provisions and the internal accounting control provisions should be strictly limited to the facts of each case.”
The meaning of effective aside, I found the “reasons” for the survey responses on effectiveness interesting.
If a unit within a business organization (such as internal audit) says that another unit within a business organization (such as compliance) is effective, does that make it so?
If you pay a third party to review a program (subject to what standards is an open question) and they conclude it is effective, does that make it so? Do recall that Unaoil was Trace International “certified” and that several companies that have won awards for being among the World’s Most Ethical Companies – at the same general time – have resolved FCPA enforcement actions or have been under FCPA scrutiny.
If compliance personnel receives a compliment or “commendation” about their company’s compliance program does that make it effective? Jane (at company A) says to Bob (at company B), “Bob, I saw/heard about your compliance program – you are doing some great things.” Does that make Company B’s compliance program effective?
What does “budget support” or “broad support” even mean? Just because a company devotes money to an issue does that mean that the company is effectively dealing with the issue?
And then there is the “no bribery or corruption incidents [have] been identified to date” reason for effectiveness. However, given the broad FCPA interpretations of the FCPA’s modern era can that really be true? Moreover, if a compliance program was “effective” would it not flag inadequate due diligence or monitoring of a third party (a frequent allegation or finding in FCPA enforcement actions) or some corporate hospitality involving the broad category of individuals the DOJ/SEC consider to be “foreign officials”?
As the SEC’s Chairman stated in perhaps the SEC’s most extensive FCPA guidance ever:
“The test of a company’s internal control system is not whether occasional failings can occur. Those will happen in the most ideally managed company. But, an adequate system of internal controls means that, when such breaches do arise, they will be isolated rather than systemic, and they will be subject to a reasonable likelihood of being uncovered in a timely manner and then remedied promptly. Barring, of course, the participation or complicity of senior company officials in the deed, when discovery and correction expeditiously follow, no failing in the company’s internal accounting system would have existed. To the contrary, routine discovery and correction would evidence its effectiveness.” (emphasis added).
