The A&E Network has a show, "The First 48," that I watch on occasion (see here). The show follows real-life homicide detectives from around the country during the "first 48 hours" of an investigation as they race against time to find the suspect.
Why is the "first 48 hours" so important? Because the chance of solving the case is apparently reduced by approximately 50% if the detectives do not get a lead in the "first 48 hours."
So what in the world does this have to do with FCPA training?
Just as the "first 48 hours" are critical to the success of a homicide investigation, the "first few minutes" are critical to the success of FCPA training.
During those critical "first few minutes" one needs to properly set the tone and engage participants on their level.
If one starts off an FCPA training session like this ... "today I will be talking about a U.S. law that makes it a crime to bribe foreign government officials to get business" - you just lost a good portion of your audience and, regardless of what you say during the rest of the training sesssion, your training session will not be as successful as it could have been.
Crime? Steve in the second row of the audience has a clean record and wouldn't hurt a fly. He coaches his son's soccer team and worships on the weekend. Joe is thinking to himself, "I have never committed a crime and I don't intend to - what does this FCPA training session have to do with me?"
Government? Melissa is in the first row of the audience. Her job function is internal audit and finance. She has absolutely no contact or communication with government officials and is thinking to herself "does this company even do business with foreign governments - what does this FCPA training session have to do with me?"
Business? Francisco, the logistics manager from outside the U.S., has been flown in for the FCPA training session. He is thinking "business - I'm not a sales and marketing guy, I just make sure our product gets into and out of the country and I occasionally help secure various licenses and permits for the company - what does this FCPA training session have to do with me?"
For reasons described in other postings on this blog, FCPA training is indeed relevant to the Steve, Melissa and Francisco's in a company.
To avoid having participants' minds wander during the "first few minutes" of FCPA training, it may be more effective to start off the training session along these lines.
"Today, I will be talking about a U.S. law that applies to all of you - regardless of whether you are in the sales and marketing department, the executive office suite, the finance and audit department, or the logistics department. This law can cover a wide range of payments the company makes, or could make, either directly or indirectly, in doing business or seeking business in foreign markets. Your understanding of this law and how it may relate to your specific job function will best ensure that the company remains compliant with this law and is able to achieve its business objectives."
Thursday, October 8, 2009
Tuesday, October 6, 2009
HP To Channel Partners - You MUST Complete FCPA Training
Engaging a foreign agent, representative, distributor or channel partner (collectively "channel partners") can greatly assist a company in increasing foreign sales. After all, these individuals or entities "know the landscape."
As readers of this blog well know, engaging a foreign channel partner can also be risky business under the FCPA.
In a previous post, I talked about certain minimum elements of an effective FCPA compliance program as typically set forth in DOJ non-prosecution or deferred prosecution agreements (see here).
One of those elements is the "promulgation of a compliance code, standards and procedures designed to reduce the prospect of violations of the FCPA" which "should apply to all directors, officers, and employees and, where necessary and approopriate, outside parties acting on behalf [of a company] in a foreign jurisdiction, including agents, consultants, representatives, distributors, teaming partners, and joint venture partners."
HP has apparently determined that it is necessary and appropriate for its global network of approximately 155,000 channel partners to complete HP's regulatory compliance training program or risk losing their partner status (see here).
A HP spokesperson confirmed that "HP is, in fact, working to have all of its global channel partners undergo training regarding government legal and regulatory compliance [including the FCPA] as part of establishing or renewing their Business Development Agreement" with HP.
As readers of this blog well know, engaging a foreign channel partner can also be risky business under the FCPA.
In a previous post, I talked about certain minimum elements of an effective FCPA compliance program as typically set forth in DOJ non-prosecution or deferred prosecution agreements (see here).
One of those elements is the "promulgation of a compliance code, standards and procedures designed to reduce the prospect of violations of the FCPA" which "should apply to all directors, officers, and employees and, where necessary and approopriate, outside parties acting on behalf [of a company] in a foreign jurisdiction, including agents, consultants, representatives, distributors, teaming partners, and joint venture partners."
HP has apparently determined that it is necessary and appropriate for its global network of approximately 155,000 channel partners to complete HP's regulatory compliance training program or risk losing their partner status (see here).
A HP spokesperson confirmed that "HP is, in fact, working to have all of its global channel partners undergo training regarding government legal and regulatory compliance [including the FCPA] as part of establishing or renewing their Business Development Agreement" with HP.
Friday, October 2, 2009
The FCPA As A Foreign Policy Stick
Michael Jacobson's piece (see here) about using the FCPA as perhaps a way to increase pressure on Iran has been discussed elsewhere (see here).
Below are some additional issues to consider.
The suggestion that the FCPA "gives the government extraterritorial reach over non-U.S. companies" and that "any foreign company listed on the U.S. stock exchange falls under FCPA jurisdiction" is not entirely accurate.
True, the FCPA's books and records and internal control provisions apply to non-U.S. companies which issue stock on a U.S. exchange, and true the books and records and internal control provisions contain no specific jurisdictional requirement. If a company is an issuer (including a foreign issuer) it must comply with the books and records and internal control provisions.
However, the jurisdictional reach of the anti-bribery provisions as to foreign companies is a different story.
The anti-bribery provisions were amended in 1998 to include an alternative "nationality" jurisdictional test for U.S. issuers and domestic concerns (see 78dd-1(g) and 78dd-2(i)).
As a result of these amendments, the original "use of the mails or any means or instrumentality of interstate commerce" nexus is no longer required and the reach of the anti-bribery provisions as to U.S. companies and U.S. citizens is indeed extraterritorial.
However, for a foreign issuer, the old "use of the mails or any means or instrumentality of interstate commerce" jurisdictional nexus is still applicable because the alternative jurisdictional test in 78dd-1(g) only applies to an "issuer organized under the laws of the U.S."
The other way in which a foreign company (other than an issuer) or foreign national can become subject to the FCPA anti-bribery provisions is through application of 78dd-3 (also added by the 1998 amendments). However, 78dd-3 has a "while in the territory of the U.S. [...] make use of the mails or any means or instrumentality of interstate commerce" jurisdictional requirement as well.
Big picture, for foreign companies (whether issuers or not) there is a U.S. jurisdictional requirement for the anti-bribery provisions to apply.
One sees this when looking at the Statoil enforcement action, which as Jacobson points out, is indeed the first time the U.S. held a foreign company accountable under the FCPA's criminal anti-bribery provisions - in the Statoil case for improper payments to Iranian officials to secure oil and gas rights in Iran.
However, the U.S. did not assert anti-bribery jurisdiction over Statoil merely on the basis of "its listing on the U.S. stock exchange."
Rather, Statoil was subject to the anti-bribery provisions because the improper payments were routed through a U.S. bank in New York, thus providing the U.S. the nexus needed to hold a foreign company accountable (see here for the criminal information describing the payments through the U.S. bank account and invoking the "means and instrumentality of interstate commerce" jurisdictional clause and here for the SEC cease and desist order finding violations of the anti-bribery provisions and finding that the improper payments were routed through a U.S. bank account in New York).
The point is, because of the U.S. nexus jurisdictional requirement of the anti-bribery provisions as to foreign companies, using the FCPA to hold foreign companies accountable in Iran is not as simple as Jacobson makes it seem.
Two "bigger picture" points as well.
First, I remain skeptical as to the suggestion that increased FCPA focus by U.S. enforcement authorities as to conduct in a particular country "could sufficiently deter many companies from doing business" in that particular country.
Those that adhere to this theory have, for instance, a "China issue" to address (i.e. it is common knowledge that U.S. enforcement authorities have announced several FCPA enforcement actions relating to conduct in China, yet such increased focus by the U.S. as to China business conduct has done little to deter companies from doing business in China).
Second, and more relevant to Jacobson's assertion that "even the suggestion of increased focus by the United States [...] could sufficiently deter many companies from doing business with Iran," is the following fact regarding Statoil in Iran.
In 2006 (as discussed above) Statoil paid $21 million in combined DOJ and SEC fines and penalties for improper payments that assisted the company in securing contracts for the South Pars field in Iran.
To my knowledge, the Statoil enforcement action is the only FCPA enforcement action concerning business conduct in Iran.
The Statoil case is thus the only "test case."
And it is a unique test case at that because both the DOJ and SEC material specifically refer to the South Pars field (often times DOJ/SEC material is silent as to specific projects), as does the company's annual reports filed with the SEC.
No doubt Jacobson is right when he says that the 2006 FCPA enforcement action had a "major impact" on Statoil. As Jacobson points out, "[s]ince then, Statoil has spent millions of dollars in building a more robust internal anti corruption compliance system and putting good governance procedures into place."
You know what else Statoil has done since the 2006 enforcement action?
It has continued to do business in Iran, including in the same South Pars fields that were the subject of the 2006 FCPA enforcement action.
Here is what the company's website says about its activity in Iran (see here).
"StatoilHydro is offshore development operator for phases 6, 7 & 8 of the South Pars gas and condensate field in the Iranian sector of the Persian Gulf. We have also engaged in onshore exploration and drilling activities."
More specifically, here is what Statoil's website says about South Pars (see here).
"Phases 6, 7 & 8 of South Pars – the world’s largest gas field – are being developed by StatoilHydro as operator under an agreement signed with its local partner Petropars and the National Iranian Oil Company (NIOC) in October 2002."
For those who enjoy reading SEC's filings, Statoil's Annual Report on Form 20-F (2008) (see here) indicates the company has invested $225 million in developing South Pars.
So, what does the only Iran "test case" show?
At least from public documents, it appears to show that enforcing the FCPA against a foreign company doing business in Iran does not even deter the subject of the enforcement action from continuing to do business in Iran.
Below are some additional issues to consider.
The suggestion that the FCPA "gives the government extraterritorial reach over non-U.S. companies" and that "any foreign company listed on the U.S. stock exchange falls under FCPA jurisdiction" is not entirely accurate.
True, the FCPA's books and records and internal control provisions apply to non-U.S. companies which issue stock on a U.S. exchange, and true the books and records and internal control provisions contain no specific jurisdictional requirement. If a company is an issuer (including a foreign issuer) it must comply with the books and records and internal control provisions.
However, the jurisdictional reach of the anti-bribery provisions as to foreign companies is a different story.
The anti-bribery provisions were amended in 1998 to include an alternative "nationality" jurisdictional test for U.S. issuers and domestic concerns (see 78dd-1(g) and 78dd-2(i)).
As a result of these amendments, the original "use of the mails or any means or instrumentality of interstate commerce" nexus is no longer required and the reach of the anti-bribery provisions as to U.S. companies and U.S. citizens is indeed extraterritorial.
However, for a foreign issuer, the old "use of the mails or any means or instrumentality of interstate commerce" jurisdictional nexus is still applicable because the alternative jurisdictional test in 78dd-1(g) only applies to an "issuer organized under the laws of the U.S."
The other way in which a foreign company (other than an issuer) or foreign national can become subject to the FCPA anti-bribery provisions is through application of 78dd-3 (also added by the 1998 amendments). However, 78dd-3 has a "while in the territory of the U.S. [...] make use of the mails or any means or instrumentality of interstate commerce" jurisdictional requirement as well.
Big picture, for foreign companies (whether issuers or not) there is a U.S. jurisdictional requirement for the anti-bribery provisions to apply.
One sees this when looking at the Statoil enforcement action, which as Jacobson points out, is indeed the first time the U.S. held a foreign company accountable under the FCPA's criminal anti-bribery provisions - in the Statoil case for improper payments to Iranian officials to secure oil and gas rights in Iran.
However, the U.S. did not assert anti-bribery jurisdiction over Statoil merely on the basis of "its listing on the U.S. stock exchange."
Rather, Statoil was subject to the anti-bribery provisions because the improper payments were routed through a U.S. bank in New York, thus providing the U.S. the nexus needed to hold a foreign company accountable (see here for the criminal information describing the payments through the U.S. bank account and invoking the "means and instrumentality of interstate commerce" jurisdictional clause and here for the SEC cease and desist order finding violations of the anti-bribery provisions and finding that the improper payments were routed through a U.S. bank account in New York).
The point is, because of the U.S. nexus jurisdictional requirement of the anti-bribery provisions as to foreign companies, using the FCPA to hold foreign companies accountable in Iran is not as simple as Jacobson makes it seem.
Two "bigger picture" points as well.
First, I remain skeptical as to the suggestion that increased FCPA focus by U.S. enforcement authorities as to conduct in a particular country "could sufficiently deter many companies from doing business" in that particular country.
Those that adhere to this theory have, for instance, a "China issue" to address (i.e. it is common knowledge that U.S. enforcement authorities have announced several FCPA enforcement actions relating to conduct in China, yet such increased focus by the U.S. as to China business conduct has done little to deter companies from doing business in China).
Second, and more relevant to Jacobson's assertion that "even the suggestion of increased focus by the United States [...] could sufficiently deter many companies from doing business with Iran," is the following fact regarding Statoil in Iran.
In 2006 (as discussed above) Statoil paid $21 million in combined DOJ and SEC fines and penalties for improper payments that assisted the company in securing contracts for the South Pars field in Iran.
To my knowledge, the Statoil enforcement action is the only FCPA enforcement action concerning business conduct in Iran.
The Statoil case is thus the only "test case."
And it is a unique test case at that because both the DOJ and SEC material specifically refer to the South Pars field (often times DOJ/SEC material is silent as to specific projects), as does the company's annual reports filed with the SEC.
No doubt Jacobson is right when he says that the 2006 FCPA enforcement action had a "major impact" on Statoil. As Jacobson points out, "[s]ince then, Statoil has spent millions of dollars in building a more robust internal anti corruption compliance system and putting good governance procedures into place."
You know what else Statoil has done since the 2006 enforcement action?
It has continued to do business in Iran, including in the same South Pars fields that were the subject of the 2006 FCPA enforcement action.
Here is what the company's website says about its activity in Iran (see here).
"StatoilHydro is offshore development operator for phases 6, 7 & 8 of the South Pars gas and condensate field in the Iranian sector of the Persian Gulf. We have also engaged in onshore exploration and drilling activities."
More specifically, here is what Statoil's website says about South Pars (see here).
"Phases 6, 7 & 8 of South Pars – the world’s largest gas field – are being developed by StatoilHydro as operator under an agreement signed with its local partner Petropars and the National Iranian Oil Company (NIOC) in October 2002."
For those who enjoy reading SEC's filings, Statoil's Annual Report on Form 20-F (2008) (see here) indicates the company has invested $225 million in developing South Pars.
So, what does the only Iran "test case" show?
At least from public documents, it appears to show that enforcing the FCPA against a foreign company doing business in Iran does not even deter the subject of the enforcement action from continuing to do business in Iran.
Thursday, October 1, 2009
"I Fully Expect That The Number of FCPA Prosecutions Will Continue To Rise"
Lanny Breuer delivered these words today before the National Association of Criminal Defense Lawyers.
Who is Lanny Breuer?
He is the Assistant Attorney General, Criminal Division.
When he speaks about the FCPA, one ought take notice.
Breuer's full remarks can be found here (FCPA remarks begin at pg. 5).
*****
We keep hearing about those 100+ FCPA investigations in the pipeline, but the government closed the books on its fiscal year yesterday with a relatively quite September.
The new fiscal year has ushered in change though as the DOJ unveiled a slick new website (check it out here). What logo will DOJ assign to the next FCPA release ... a calculator, a flying eagle, the scales of justice, a shield?
My bet is on the calculator ... for a FCPA books and records violation.
Who is Lanny Breuer?
He is the Assistant Attorney General, Criminal Division.
When he speaks about the FCPA, one ought take notice.
Breuer's full remarks can be found here (FCPA remarks begin at pg. 5).
*****
We keep hearing about those 100+ FCPA investigations in the pipeline, but the government closed the books on its fiscal year yesterday with a relatively quite September.
The new fiscal year has ushered in change though as the DOJ unveiled a slick new website (check it out here). What logo will DOJ assign to the next FCPA release ... a calculator, a flying eagle, the scales of justice, a shield?
My bet is on the calculator ... for a FCPA books and records violation.
"We Don't Want The Auditors Raising Any Questions on Iraq Business"
Yet another Iraqi Oil-For-Food enforcement action.
Yesterday, the DOJ and SEC announced resolution of an enforcement action against AGCO Corp. (a Georgia-based manufacturer and supplier of agricultural machinery and equipment) as well as AGCO Limited (AGCO's a wholly-owned subsidiary headquartered in the United Kingdom responsible for AGCO's business in Europe, Africa, and the Middle East)(see here, here, here, here, and here).
Big picture, AGCO acknowledged responsibility for improper payments made by its subsidiaries and agents to the former government of Iraq in order to obtain contracts with the Iraqi Ministry of Agriculture under the United Nations Oil-For-Food program.
DOJ filed a criminal information against AGCO Limited charging one count of conspiracy to commit wire fraud and to violate the FCPA's books and records provisions.
According to the DOJ, AGCO Limited paid approximately $550,000 to the former government of Iraq to secure three contracts. DOJ and AGCO entered into a three-year deferred prosecution agreement under which DOJ will defer prosecution upon, among other things, AGCO's payment of a $1.6 million penalty. According to the DOJ, the basis for the deferred prosecution agreement was, among other things, AGCO's cooperation in the DOJ's investigation, its implementation of remedial measures, and its settlement with the SEC (see below).
Why no substantive FCPA anti-bribery charges in this case and other Iraqi Oil-For-Food cases (Novo Nordisk, Fiat, AB Volvo, etc.)? The anti-bribery provisions apply to payments to "foreign officials," not foreign governments. Thus, in this and the other cases, conspiracy to commit wire fraud and to violate the FCPA books and records provisions were charged.
Because AGCO is an issuer, the SEC also played a role in the enforcement action. The SEC filed a settled civil complaint charging AGCO with violating the FCPA's books and records and internal control provisions.
According to the SEC, certain AGCO subsidiaries made - through a Jordanian agent - approximately $5.9 million in kickback payments to Iraq in the form of "after-sales service fees" to secure contracts worth approximately $14 million. These payments were disguised or improperly recorded in the subsidiaries' books and records which were consolidated with AGCO's for SEC filing purposes. According to the SEC, "AGCO knew or was reckless in not knowing that kickbacks were paid in connection with its subsidiaries' transactions."
The SEC ordered AGCO to pay $18.3 million in combined disgorgement, interest, and penalties.
In a previous post (see here), it was noted that FCPA compliance is a task that not just company lawyers need to be concerned with, but rather a task that internal audit and finance should also be concerned with and actively involved in as well. It was noted that internal audit and finance personnel must be specifically trained to approach their specific job functions with "FCPA goggles" on.
Reading the SEC complaint against AGCO, it is clear that various AGCO personnel could have used a pair of "FCPA goggles" as the complaint is an indictment of the entire company's control function.
In para 23, the SEC charges, among other things, that:
the "accrual account [where the kickback payments were recorded] was created by AGCO Ltd.'s marketing staff with virtually no oversight from AGCO Ltd.s' finance department;"
"no one questioned the existence of the dual accounts;"
"no one questioned why the [accrual account] contained approximately ten percent of the contract value despite the fact that there was no contract in place requiring that such ten percent be paid to the ministry or anyone else;"
"when the finance department authorized payments from the [accrual account], it did not ask for or receive any proof of service to warrant the payments;" and
an employee cautioned the business manager for Iraq and his supervisor that "we don't want the auditors raising any questions on Iraq Business!"
Further, in para 25, the SEC charges, among other things, that:
"Sales and marketing personnel were able to enter into contracts without review from the legal or finance departments;"
"an accounting employee described the Finance Department employees as 'blind loaders' who input information into AGCO's books without any adequate oversight role;" and
"marketing personnel were able to create accrual accounts [...] without any oversight and caused accounts to be created and payments to be made without proper documentation."
In para. 26, the SEC charges, among other things, that:
"AGCO Ltd.'s structure at the time allocated inappropriate accounting and finance responsibilities to the marketing department;" and
"turnover in the marketing department [...] was high and employees were forced to shoulder a great deal of the accounting burden."
AGCO's management and legal department did not fare much better.
In para. 27, the SEC charges, among other things, that:
"AGCO did not conduct any due diligence on the [Jordanian] agent or require that the agent undergo FCPA training;" and
the "agent's contract with AGCO did not accurately explain the agent's services and payments, and lacked any FCPA language."
What would the results look like if your company or your client's company was "put under the internal controls microscope" in an FCPA enforcement action?
Yesterday, the DOJ and SEC announced resolution of an enforcement action against AGCO Corp. (a Georgia-based manufacturer and supplier of agricultural machinery and equipment) as well as AGCO Limited (AGCO's a wholly-owned subsidiary headquartered in the United Kingdom responsible for AGCO's business in Europe, Africa, and the Middle East)(see here, here, here, here, and here).
Big picture, AGCO acknowledged responsibility for improper payments made by its subsidiaries and agents to the former government of Iraq in order to obtain contracts with the Iraqi Ministry of Agriculture under the United Nations Oil-For-Food program.
DOJ filed a criminal information against AGCO Limited charging one count of conspiracy to commit wire fraud and to violate the FCPA's books and records provisions.
According to the DOJ, AGCO Limited paid approximately $550,000 to the former government of Iraq to secure three contracts. DOJ and AGCO entered into a three-year deferred prosecution agreement under which DOJ will defer prosecution upon, among other things, AGCO's payment of a $1.6 million penalty. According to the DOJ, the basis for the deferred prosecution agreement was, among other things, AGCO's cooperation in the DOJ's investigation, its implementation of remedial measures, and its settlement with the SEC (see below).
Why no substantive FCPA anti-bribery charges in this case and other Iraqi Oil-For-Food cases (Novo Nordisk, Fiat, AB Volvo, etc.)? The anti-bribery provisions apply to payments to "foreign officials," not foreign governments. Thus, in this and the other cases, conspiracy to commit wire fraud and to violate the FCPA books and records provisions were charged.
Because AGCO is an issuer, the SEC also played a role in the enforcement action. The SEC filed a settled civil complaint charging AGCO with violating the FCPA's books and records and internal control provisions.
According to the SEC, certain AGCO subsidiaries made - through a Jordanian agent - approximately $5.9 million in kickback payments to Iraq in the form of "after-sales service fees" to secure contracts worth approximately $14 million. These payments were disguised or improperly recorded in the subsidiaries' books and records which were consolidated with AGCO's for SEC filing purposes. According to the SEC, "AGCO knew or was reckless in not knowing that kickbacks were paid in connection with its subsidiaries' transactions."
The SEC ordered AGCO to pay $18.3 million in combined disgorgement, interest, and penalties.
In a previous post (see here), it was noted that FCPA compliance is a task that not just company lawyers need to be concerned with, but rather a task that internal audit and finance should also be concerned with and actively involved in as well. It was noted that internal audit and finance personnel must be specifically trained to approach their specific job functions with "FCPA goggles" on.
Reading the SEC complaint against AGCO, it is clear that various AGCO personnel could have used a pair of "FCPA goggles" as the complaint is an indictment of the entire company's control function.
In para 23, the SEC charges, among other things, that:
the "accrual account [where the kickback payments were recorded] was created by AGCO Ltd.'s marketing staff with virtually no oversight from AGCO Ltd.s' finance department;"
"no one questioned the existence of the dual accounts;"
"no one questioned why the [accrual account] contained approximately ten percent of the contract value despite the fact that there was no contract in place requiring that such ten percent be paid to the ministry or anyone else;"
"when the finance department authorized payments from the [accrual account], it did not ask for or receive any proof of service to warrant the payments;" and
an employee cautioned the business manager for Iraq and his supervisor that "we don't want the auditors raising any questions on Iraq Business!"
Further, in para 25, the SEC charges, among other things, that:
"Sales and marketing personnel were able to enter into contracts without review from the legal or finance departments;"
"an accounting employee described the Finance Department employees as 'blind loaders' who input information into AGCO's books without any adequate oversight role;" and
"marketing personnel were able to create accrual accounts [...] without any oversight and caused accounts to be created and payments to be made without proper documentation."
In para. 26, the SEC charges, among other things, that:
"AGCO Ltd.'s structure at the time allocated inappropriate accounting and finance responsibilities to the marketing department;" and
"turnover in the marketing department [...] was high and employees were forced to shoulder a great deal of the accounting burden."
AGCO's management and legal department did not fare much better.
In para. 27, the SEC charges, among other things, that:
"AGCO did not conduct any due diligence on the [Jordanian] agent or require that the agent undergo FCPA training;" and
the "agent's contract with AGCO did not accurately explain the agent's services and payments, and lacked any FCPA language."
What would the results look like if your company or your client's company was "put under the internal controls microscope" in an FCPA enforcement action?
Wednesday, September 30, 2009
North of the Border
We point the compass north in what has become "comparative law week" here at the blog and take a look at Canada's "FCPA-like" domestic statute - the Corruption of Foreign Public Officials Act ("CFPOA").
Saddle up, the Royal Canadian Mounted Police "have established a special unit dedicated to investigating international bribery and enforcing the CFPOA" according to a Canadian law firm which recently released a bulletin titled "Canada's Corruption of Foreign Public Officials Act: What You Need to Know and Why" (see here).
The bulletin is an informative read and "provides an introduction to the CFPOA, contrasts it with the anti-bribery provisions of the FCPA, and provides a brief update on recent developments in Canada."
According to the bulletin, an amendment to CFPOA was recently introduced to provide for extraterritorial jurisdiction much like 78dd-1(g) and 78dd-2(i) provide for U.S. issuers and domestic concerns.
The authors note that "[w]hile the CFPOA has been in force for a decade, it is only recently that it has been the subject of minimal enforcement efforts by Canadian authorities." However, the authors predict, "this is likely to change in the future."
Saddle up, the Royal Canadian Mounted Police "have established a special unit dedicated to investigating international bribery and enforcing the CFPOA" according to a Canadian law firm which recently released a bulletin titled "Canada's Corruption of Foreign Public Officials Act: What You Need to Know and Why" (see here).
The bulletin is an informative read and "provides an introduction to the CFPOA, contrasts it with the anti-bribery provisions of the FCPA, and provides a brief update on recent developments in Canada."
According to the bulletin, an amendment to CFPOA was recently introduced to provide for extraterritorial jurisdiction much like 78dd-1(g) and 78dd-2(i) provide for U.S. issuers and domestic concerns.
The authors note that "[w]hile the CFPOA has been in force for a decade, it is only recently that it has been the subject of minimal enforcement efforts by Canadian authorities." However, the authors predict, "this is likely to change in the future."
Tuesday, September 29, 2009
An Update From Across the Pond
The U.S. is not the only country with an "FCPA-like" domestic statute. The United Kingdom has a similar law (actually a mix of several different statutes on the books for nearly one-hundred years - however, in March 2009, a new bill - the "Bribery Bill" was introduced in Parliament and is currently being debated).
As discussed in a July post (see here), the U.K.'s Serious Fraud Office ("SFO") (an enforcement agency similar to the U.S. DOJ) announced "the first prosecution brought in the U.K. against a company for overseas corruption."
The company - Mabey & Johnson Ltd. ("M&J") - a U.K. company that designs and manufacturers steel bridges used in more than 115 countries worldwide.
Last week, the SFO issued a press release announcing the details of M&J's £6.6 million sentence (see here).
The SFO also released two "prosecution opening statements" relating to (a) the company's conduct in Jamaica and Ghana; and (b) the company's breach of United Nations Oil for Food Regulations (see here and here).
To state the obvious, one enforcement action does not constitute a practice.
Subject to that qualification, I offer some comments about the SFO's released documents compared to what the DOJ and SEC typically release in an FCPA enforcement action (where indeed a common practice has developed).
Naming Names
Unlike a typical DOJ deferred prosecution, non-prosecution agreement or plea or SEC complaint, the SFO documents name names. Specifically identified in the documents are numerous "public officials" in Jamaica, Ghana, Angola, Madagascar, Mozambique, and Bangladesh (see pages 11, 25, 28, 32, 33, 35, and 38) alleged to have received improper payments from M&J (or its agents) to help secure company business.
The SFO documents also specifically identify the agents and their companies which were used by M&J to make certain of the improper payments (see pages 12, 22, 28, 32, 35, 37).
Is there value to "naming names," does it "punish" the foreign or public official recipient of the improper payment (given that the FCPA only punishes the bribe payor not the bribe recipient)? Does naming the agent effectively blacklist the individual/company and thus serve a useful public function for other companies doing business in that particular market?
All interesting questions to ponder. There is also an interesting historical FCPA angle as well. Many, including the Ford administration, were opposed to the FCPA as it now exists, opting instead for a disclosure approach on the theory, to use the famous Justice Brandeis quote that "sunshine is the best disinfectant."
Back to the SFO documents.
As referenced above, the applicable term used in the SFO documents is "public official" not "foreign official" as used in the FCPA. Do these terms means the same thing? All of the "public officials" identified in the SFO documents are government Ministers or Ambassadors (what I'll call core government officials).
There is no exception though, an exception relevant to the current debate over the FCPA's "foreign official" term and whether it should include employees of state-owned or state-controlled companies.
The Angolan "public officials" appear to be Directors of Empresa Nacional des Pontes, an "Angolan State owned entity."
Joint Venture Partners
Under the FCPA, conventional wisdom seems to hold that joint venture partners will be liable for improper payments made by other joint venture partners, particularly when the joint venture partners share revenues and profits of contracts secured through improper payments and particularly when the joint venture's board includes individuals from both companies. (see here for a discussion of this issue in connection with the recent Halliburton/KBR enforcement action).
Not so in the M&J matter.
The SFO documents reference a joint venture relationship between M&J and Kier International Ltd. ("Kier") in order to facilitate both the construction and engineering aspects of "Jamaica 1" (the contract allegedly secured through the bribe payments).
According to the SFO documents, M&J and Kier agreed that "overall revenue and profits from the JV with respect of Jamaica I would be divided 57% and 43% respectively." The documents further state that under the terms of the JV "a sponsor would have primary responsibility for representing the JV" and that "Kier was nominated to act as the sponsor." Further the documents indicate that "the supervisory board" of the JV comprised both M&J and Kier executives.
However, the documents evidence that the "SFO has investigated the relationship between Kier and M&J in respect of this contract" and "all the evidence currently available to the SFO" indicates that "there is no evidence that Kier [was] privy to these corrupt practices."
Will JV partners in the cross-hairs of a future FCPA enforcement action be citing to the SFO's decision as to Kier in the M&J enforcement action to argue that there is no basis for FCPA liability (whether anti-bribery or books and records of internal controls)? Perhaps so.
Cooperation
Despite these apparent differences between the M&J enforcement action and a "typical" FCPA enforcement action, there are some similarities and it is clear that the SFO is following DOJ's lead when it comes to "rewarding" voluntary disclosure (see pages 40-41 "the SFO have sought where appropriate to have regard to the model for corporate regulation adopted by the Department of Justice in the United States of America under the Foreign Corrupt Practices Act 1977.").
The SFO's stance in the M&J matter, in which it noted that M&J's internal investigation and subsequent voluntary disclosure were "meriting specific commendation" (see pg. 7) is consistent with the approach the SFO set forth in July when it released a memo titled "Approach of the Serious Fraud Office to Dealing with Overseas Corruption" (see here).
Individuals
Finally, much like the DOJ, the SFO appears interested in charging individuals (not just corporations) for participating in improper payments. The SFO specifically noted that "a number of individuals are the subjects of investigation with regard to the corrupt business practices of M&J" (see pg. 5) and it explained that it did not "name certain directors, executives and employees of M&J at this stage because they may face trial in English Courts."
Again, to restate the obvious, one enforcement action does not constitute a practice. Yet when doing a comparative analysis of the FCPA with other FCPA-like statutes one has got to start "somewhere" and that "somewhere" now exists with release of the specific facts of the U.K.'s first prosecution against a company for overseas corruption."
As discussed in a July post (see here), the U.K.'s Serious Fraud Office ("SFO") (an enforcement agency similar to the U.S. DOJ) announced "the first prosecution brought in the U.K. against a company for overseas corruption."
The company - Mabey & Johnson Ltd. ("M&J") - a U.K. company that designs and manufacturers steel bridges used in more than 115 countries worldwide.
Last week, the SFO issued a press release announcing the details of M&J's £6.6 million sentence (see here).
The SFO also released two "prosecution opening statements" relating to (a) the company's conduct in Jamaica and Ghana; and (b) the company's breach of United Nations Oil for Food Regulations (see here and here).
To state the obvious, one enforcement action does not constitute a practice.
Subject to that qualification, I offer some comments about the SFO's released documents compared to what the DOJ and SEC typically release in an FCPA enforcement action (where indeed a common practice has developed).
Naming Names
Unlike a typical DOJ deferred prosecution, non-prosecution agreement or plea or SEC complaint, the SFO documents name names. Specifically identified in the documents are numerous "public officials" in Jamaica, Ghana, Angola, Madagascar, Mozambique, and Bangladesh (see pages 11, 25, 28, 32, 33, 35, and 38) alleged to have received improper payments from M&J (or its agents) to help secure company business.
The SFO documents also specifically identify the agents and their companies which were used by M&J to make certain of the improper payments (see pages 12, 22, 28, 32, 35, 37).
Is there value to "naming names," does it "punish" the foreign or public official recipient of the improper payment (given that the FCPA only punishes the bribe payor not the bribe recipient)? Does naming the agent effectively blacklist the individual/company and thus serve a useful public function for other companies doing business in that particular market?
All interesting questions to ponder. There is also an interesting historical FCPA angle as well. Many, including the Ford administration, were opposed to the FCPA as it now exists, opting instead for a disclosure approach on the theory, to use the famous Justice Brandeis quote that "sunshine is the best disinfectant."
Back to the SFO documents.
As referenced above, the applicable term used in the SFO documents is "public official" not "foreign official" as used in the FCPA. Do these terms means the same thing? All of the "public officials" identified in the SFO documents are government Ministers or Ambassadors (what I'll call core government officials).
There is no exception though, an exception relevant to the current debate over the FCPA's "foreign official" term and whether it should include employees of state-owned or state-controlled companies.
The Angolan "public officials" appear to be Directors of Empresa Nacional des Pontes, an "Angolan State owned entity."
Joint Venture Partners
Under the FCPA, conventional wisdom seems to hold that joint venture partners will be liable for improper payments made by other joint venture partners, particularly when the joint venture partners share revenues and profits of contracts secured through improper payments and particularly when the joint venture's board includes individuals from both companies. (see here for a discussion of this issue in connection with the recent Halliburton/KBR enforcement action).
Not so in the M&J matter.
The SFO documents reference a joint venture relationship between M&J and Kier International Ltd. ("Kier") in order to facilitate both the construction and engineering aspects of "Jamaica 1" (the contract allegedly secured through the bribe payments).
According to the SFO documents, M&J and Kier agreed that "overall revenue and profits from the JV with respect of Jamaica I would be divided 57% and 43% respectively." The documents further state that under the terms of the JV "a sponsor would have primary responsibility for representing the JV" and that "Kier was nominated to act as the sponsor." Further the documents indicate that "the supervisory board" of the JV comprised both M&J and Kier executives.
However, the documents evidence that the "SFO has investigated the relationship between Kier and M&J in respect of this contract" and "all the evidence currently available to the SFO" indicates that "there is no evidence that Kier [was] privy to these corrupt practices."
Will JV partners in the cross-hairs of a future FCPA enforcement action be citing to the SFO's decision as to Kier in the M&J enforcement action to argue that there is no basis for FCPA liability (whether anti-bribery or books and records of internal controls)? Perhaps so.
Cooperation
Despite these apparent differences between the M&J enforcement action and a "typical" FCPA enforcement action, there are some similarities and it is clear that the SFO is following DOJ's lead when it comes to "rewarding" voluntary disclosure (see pages 40-41 "the SFO have sought where appropriate to have regard to the model for corporate regulation adopted by the Department of Justice in the United States of America under the Foreign Corrupt Practices Act 1977.").
The SFO's stance in the M&J matter, in which it noted that M&J's internal investigation and subsequent voluntary disclosure were "meriting specific commendation" (see pg. 7) is consistent with the approach the SFO set forth in July when it released a memo titled "Approach of the Serious Fraud Office to Dealing with Overseas Corruption" (see here).
Individuals
Finally, much like the DOJ, the SFO appears interested in charging individuals (not just corporations) for participating in improper payments. The SFO specifically noted that "a number of individuals are the subjects of investigation with regard to the corrupt business practices of M&J" (see pg. 5) and it explained that it did not "name certain directors, executives and employees of M&J at this stage because they may face trial in English Courts."
Again, to restate the obvious, one enforcement action does not constitute a practice. Yet when doing a comparative analysis of the FCPA with other FCPA-like statutes one has got to start "somewhere" and that "somewhere" now exists with release of the specific facts of the U.K.'s first prosecution against a company for overseas corruption."
Labels:
Angola,
Bangladesh,
Ghana,
Iraq,
Jamaica,
Mabey Johnson,
Madagascar,
Mozambique,
Serious Fraud Office,
United Kingdom
Saturday, September 26, 2009
Welcome to the Club
Initial Public Offerings (IPO's) were back in the news this week. Leading the way was Shanda Games Ltd. By raising $1.04 billion, Shanda's IPO was the largest since April 2008.
Shanda is a Beijing, China based online computer game company and its listing is the latest example of a foreign issuer (frequently a Chinese company) electing to trade its shares (or a portion of its shares) on a U.S. Exchange.
By becoming an "issuer" Shanda becomes subject to the FCPA.
Presumably, Shanda had experienced securities counsel advising it on its listing and the consequences that flow from such a listing. If not, and if you are listening, welcome to the club Shanda.
Your potential FCPA exposure is not just limited to the books and records and internal control provisions. The FCPA's anti-bribery provisions also apply to you.
Don't take my word for it, listen to the Department of Justice.
In 2006, the Department of Justice announced an FCPA enforcement action against Statoil ASA, a Norwegian company, for making improper payments to Iranian foreign officials - the first time DOJ brought criminal FCPA charges against a non-U.S. company. (See here for the deferred prosecution agreement).
The U.S. prosecuting a Norwegian company for making improper payments to Iranian foreign officials ... how did that happen?
Statoil had shares traded on a U.S. exchange and was thus an "issuer" subject to the FCPA.
In announcing the settlement, the DOJ had this to say - “Although Statoil is a foreign issuer, the Foreign Corrupt Practices Act applies to foreign and domestic public companies alike, where the company’s stock trades on American exchanges" (see here).
And this - “This prosecution demonstrates the Justice Department’s commitment vigorously to enforce the FCPA against all international businesses whose conduct falls within its scope.”
The Statoil FCPA enforcement action is certainly not the only FCPA enforcement action against a foreign issuer. In fact, the largest FCPA enforcement action ever was settled in December 2008 involving Siemens AG, a German company (see here and here).
Despite these, and other, enforcement actions, there is still a common misperception that the FCPA is "the law that applies to only U.S. companies."
With the IPO market showing signs of life again, with foreign companies (like Shanda) increasingly turning to U.S. capital markets, and with many of these companies doing business in FCPA high-risk countries, the number of FCPA enforcement actions against foreign issuers is likely to increase.
Shanda is a Beijing, China based online computer game company and its listing is the latest example of a foreign issuer (frequently a Chinese company) electing to trade its shares (or a portion of its shares) on a U.S. Exchange.
By becoming an "issuer" Shanda becomes subject to the FCPA.
Presumably, Shanda had experienced securities counsel advising it on its listing and the consequences that flow from such a listing. If not, and if you are listening, welcome to the club Shanda.
Your potential FCPA exposure is not just limited to the books and records and internal control provisions. The FCPA's anti-bribery provisions also apply to you.
Don't take my word for it, listen to the Department of Justice.
In 2006, the Department of Justice announced an FCPA enforcement action against Statoil ASA, a Norwegian company, for making improper payments to Iranian foreign officials - the first time DOJ brought criminal FCPA charges against a non-U.S. company. (See here for the deferred prosecution agreement).
The U.S. prosecuting a Norwegian company for making improper payments to Iranian foreign officials ... how did that happen?
Statoil had shares traded on a U.S. exchange and was thus an "issuer" subject to the FCPA.
In announcing the settlement, the DOJ had this to say - “Although Statoil is a foreign issuer, the Foreign Corrupt Practices Act applies to foreign and domestic public companies alike, where the company’s stock trades on American exchanges" (see here).
And this - “This prosecution demonstrates the Justice Department’s commitment vigorously to enforce the FCPA against all international businesses whose conduct falls within its scope.”
The Statoil FCPA enforcement action is certainly not the only FCPA enforcement action against a foreign issuer. In fact, the largest FCPA enforcement action ever was settled in December 2008 involving Siemens AG, a German company (see here and here).
Despite these, and other, enforcement actions, there is still a common misperception that the FCPA is "the law that applies to only U.S. companies."
With the IPO market showing signs of life again, with foreign companies (like Shanda) increasingly turning to U.S. capital markets, and with many of these companies doing business in FCPA high-risk countries, the number of FCPA enforcement actions against foreign issuers is likely to increase.
Wednesday, September 23, 2009
If H.R. 2152 Were to Be Enacted ...
There is little in terms of substantive FCPA case law. Yet this much is clear - there is no private right of action under the FCPA - enforcement of the law is in the hands of the DOJ and the SEC (as to issuers).
However, Representative Ed Perlmutter (D-CO) would like to change that (at least a bit). In April, 2009, Perlumutter introduced H.R. 2152 - the Foreign Business Bribery Prohibition Act of 2009 (see here).
Big picture, under the proposed law, any "foreign concern" (defined to mean any person other than an issuer, domestic concern or U.S. person) that violates the FCPA's anti-bribery provisions would be liable to any issuer, domestic concern or U.S. person for damages caused by the FCPA violation. Under the proposed law, a plaintiff would need to prove that: (i) the "foreign concern" violated the FCPA's anti-bribery provisions; and (ii) the violation prevented the plaintiff from obtaining or retaining business and assisted the foreign concern in obtaining or retaining business.
In other words, if a U.S. company can prove that it lost business because a "foreign concern" gained that same business by violating the FCPA, the U.S. company could bring a lawsuit seeking damages. Under the proposed law, the damages would be the higher of the total amount of the contract or agreement that the "foreign concern" gained in obtaining or retaining the business or the total amount of the contract or agreement that the plaintiff failed to gain. To sweeten the pot, the proposed law requires treble damages along with attorneys fees and costs.
Certainly, lots to think about here.
But alas, with two foreign wars, government bailouts and debates about financial regulation, and now, the health care debate, H.R. 2152 remains buried in Congress. The last reported activity is from June 12, 2009 when the bill was reported to the House Subcommittee on Crime, Terrorism, and Homeland Security.
It's been a few months since I thought about H.R. 2152.
But I was reminded of the law and its potential application last night while reading an interesting front-page article in the New York Times titled "China Spreads Aid in Africa, With a Catch for Recipients" (see here).
The article talks about business activity by Chinese companies around the globe, and how, according to quoted sources, Chinese companies may be securing contracts through improper payments, kickbacks and the like.
A good portion of the article is about Nuctech Company Ltd. (a Beijing-based scanner company) and its questionable activity in Namibia. The article quotes the Vice President of Nuctech's "American rival, Rapiscan Systems."
I trust you are now thinking about the potential application of H.R. 2152 as well?
Let's go through the elements - "foreign concern" check, potential violation of the FCPA check, a domestic concern damaged by the "foreign concern's" violation check.
Before FCPA lawyers start dusting off their copy of the rules of civil procedure and daydreaming about H.R. 2152's promise of treble damages and attorney fees, H.R. 2152 needs to at least get "out of committee."
In any event, for those in favor of H.R. 2152, the article would seem to present a poster-child of sorts.
However, Representative Ed Perlmutter (D-CO) would like to change that (at least a bit). In April, 2009, Perlumutter introduced H.R. 2152 - the Foreign Business Bribery Prohibition Act of 2009 (see here).
Big picture, under the proposed law, any "foreign concern" (defined to mean any person other than an issuer, domestic concern or U.S. person) that violates the FCPA's anti-bribery provisions would be liable to any issuer, domestic concern or U.S. person for damages caused by the FCPA violation. Under the proposed law, a plaintiff would need to prove that: (i) the "foreign concern" violated the FCPA's anti-bribery provisions; and (ii) the violation prevented the plaintiff from obtaining or retaining business and assisted the foreign concern in obtaining or retaining business.
In other words, if a U.S. company can prove that it lost business because a "foreign concern" gained that same business by violating the FCPA, the U.S. company could bring a lawsuit seeking damages. Under the proposed law, the damages would be the higher of the total amount of the contract or agreement that the "foreign concern" gained in obtaining or retaining the business or the total amount of the contract or agreement that the plaintiff failed to gain. To sweeten the pot, the proposed law requires treble damages along with attorneys fees and costs.
Certainly, lots to think about here.
But alas, with two foreign wars, government bailouts and debates about financial regulation, and now, the health care debate, H.R. 2152 remains buried in Congress. The last reported activity is from June 12, 2009 when the bill was reported to the House Subcommittee on Crime, Terrorism, and Homeland Security.
It's been a few months since I thought about H.R. 2152.
But I was reminded of the law and its potential application last night while reading an interesting front-page article in the New York Times titled "China Spreads Aid in Africa, With a Catch for Recipients" (see here).
The article talks about business activity by Chinese companies around the globe, and how, according to quoted sources, Chinese companies may be securing contracts through improper payments, kickbacks and the like.
A good portion of the article is about Nuctech Company Ltd. (a Beijing-based scanner company) and its questionable activity in Namibia. The article quotes the Vice President of Nuctech's "American rival, Rapiscan Systems."
I trust you are now thinking about the potential application of H.R. 2152 as well?
Let's go through the elements - "foreign concern" check, potential violation of the FCPA check, a domestic concern damaged by the "foreign concern's" violation check.
Before FCPA lawyers start dusting off their copy of the rules of civil procedure and daydreaming about H.R. 2152's promise of treble damages and attorney fees, H.R. 2152 needs to at least get "out of committee."
In any event, for those in favor of H.R. 2152, the article would seem to present a poster-child of sorts.
Monday, September 21, 2009
Understanding China FCPA Risk
Many thanks to Dan Harris over at China Law Blog for inviting "me over" to share my thoughts on China FCPA risk. My post can be found here.
Labels:
China,
Compliance,
Control Components Inc.,
Foreign Official,
Lucent
Books and Records and Internal Controls Compliance ... The Importance of FCPA Goggles
A reader recently commented that most companies know "what to do" when it comes to FCPA anti-bribery compliance training, but that when it comes to FCPA books and records and internal controls compliance training most people "scratch their heads."
Below, I offer some thoughts on books and records and internal controls compliance training, but by no means does this cover the entire landscape.
I think the reader is correct in that most companies do in fact focus compliance efforts (if they have pro-active compliance efforts - see here) on the FCPA's anti-bribery provisions. The FCPA's other prong - the books and records and internal control provisions are usually mentioned (if at all) in passing.
An explanation for why likely has to do with the statute itself.
The anti-bribery provisions have specific elements tied to things we can all generally understand such as - things of value, foreign official, and obtain or retain business - and companies can easily tailor compliance training to those elements, or it is probably more accurate to say, DOJ and SEC's interpretations of those elements.
In contrast, the FCPA's book and records and internal control provisions are rather generic and have key terms such as "reasonable detail," "accurately and fairly," "sufficient," "reasonable assurances, and "general or specific authorization."
Tailoring compliance training to such general concepts can be difficult. Moreover, the books and records, and internal control provisions apply to issuers in ALL instances, not just those instances in which the company is doing business or seeking business abroad. Thus, it may be more difficult to frame books and records and internal control issues to training, because the provisions apply to everything an issuer does.
Against this backdrop, what works best I think is to view FCPA compliance as not just a task that company lawyers and selected key positions from an anti-bribery perspective (i.e. sales, marketing, business development) need to be concerned with, but rather a task that internal audit and finance should also be concerned with and actively involved in as well.
This means that internal audit and finance personnel must be specifically trained to approach their specific job functions not only in a traditional way, but also with "FCPA goggles" on.
It is clear from recent FCPA enforcement actions that the SEC expects much more from non-legal personnel when it comes to FCPA compliance, including the ability to spot FCPA issues and display a high degree of (I'll call it) intellectual curiosity as to certain issues.
For instance, in the 2007 York matter, the SEC alleged in its civil complaint (see here at para 51) that (i) "York International's management had the ability to review or cause internal audit to review [the problematic contracts] and, had this been done, it would have been immediately apparant that the consultancy agreements were a sham; and (ii) it was "clear that local finance personnel did not provide an independent internal control function, but rather acquiesced in questionable practices and documentation without critical review."
Again, because the FCPA's books and records and internal control provisions are rather generic, I think a "best practice" (not only for issuers, but for any company) is to specifically train internal audit and finance personnel to view their job with "FCPA goggles" on.
This means that internal audit and finance personnel should:
(1) Understand the broad interpretations given to the anything of value, foreign official, and obtain or retain business elements of anti-bribery violation so that they clearly understand that conduct other than a "suitcase full of cash to a government official to get a government contract" is problematic. For instance,
excessive travel and marketing expenses, payment of scholarships, etc. can be things of value. Internal audit and finance personnel also need to understand that employees of state-owned or state-controlled companies are considered "foreign officials" by DOJ/SEC (even if that interpretation has not been tested or challenged). This means that things a company does to "wine and dine" its purely private customers can become problematic when state-owned or state-controlled customers receive the same treatment. In terms of state-owned or state-controlled customers, it is also a good idea for a company to maintain a roster of such entities so that heightened review will be triggered when any corporate personnel deals with such customers or prospective customers. Internal audit and finance personnel also need to understand that payments which result in a company securing a foreign license, permit, or certification can satisfy the "obtain or retain business" element of an anti-bribery violation on the theory that such payments help the company, in the general sense, obtain or retain business.
(2) Pay particular attention to employee reimbursement requests and think about FCPA issues in connection with these requests. For instance, if a specific sales and marketing employee is the designated "wine and dine" person, is there any heightened scrutiny of that individuals reimbursement requests?
(3) Be aware of the FCPA's third-party payment provisions and be able to spot (and follow-up on) the following issues relevant to engaging and supervising a foreign agent or representative: payments made to personal (rather than company) bank accounts; payments to off-shore bank accounts; payments which could be made in one lump sum but are split up to avoid detection; and payments made to an account in a country different than where the service provider is located. When utilizing third parties, commission payments are obviously a big FCPA risk. Thus, internal audit and finance personnel need to ask what steps the company has taken to assure itself that the commission payments are reasonable. Moreover, such personnel should specifically look for evidence that the third party actually provided legitimate value-added services before payment was made by the company.
(4) Figure out who within the company, the relevant business unit, etc. has the authority to authorize large payments and make sure those authorizations are scrutinized. Because of title, prestige and in some countries - gender - certain individuals are subjected to less oversight and scrutiny when it comes to authorizing payments. If any such trends or patterns emerge within a company as to this issue, internal audit and finance personnel must be diligent in understanding why.
(5)Pay particular attention to the following accounts (all of which, per recent FCPA enforcement actions, were used to conceal improper payments) - "additional assessments," "extra costs," "extraordinary expenses," "urgent processing," "urgent dispatch," "customs processing," "importation advances," . These accounts, and all other accounts described in a vague or ambiguous manner, should be subject to heightened scrutiny by internal audit and finance personnel.
Back to the original issue raised by the reader as to how best to offer FCPA books and records, and internal controls compliance training. Again, because the books and records and internal control provisions are so generic, I think the "best practice" is to couple such training with anti-bribery training and to make sure that internal audit and finance personnel have the FCPA tools necessary to properly execute their jobs.
Internal audit and finance personnel clearly have an FCPA compliance role to play, and the SEC is clearly expecting them to play that role. However, internal audit and finance personnel can only raise FCPA issues if they first know what FCPA issues to look for. Providing internal audit and finance personnel with a good pair of "FCPA goggles" is a good way to achieve books and records, and internal controls compliance.
Below, I offer some thoughts on books and records and internal controls compliance training, but by no means does this cover the entire landscape.
I think the reader is correct in that most companies do in fact focus compliance efforts (if they have pro-active compliance efforts - see here) on the FCPA's anti-bribery provisions. The FCPA's other prong - the books and records and internal control provisions are usually mentioned (if at all) in passing.
An explanation for why likely has to do with the statute itself.
The anti-bribery provisions have specific elements tied to things we can all generally understand such as - things of value, foreign official, and obtain or retain business - and companies can easily tailor compliance training to those elements, or it is probably more accurate to say, DOJ and SEC's interpretations of those elements.
In contrast, the FCPA's book and records and internal control provisions are rather generic and have key terms such as "reasonable detail," "accurately and fairly," "sufficient," "reasonable assurances, and "general or specific authorization."
Tailoring compliance training to such general concepts can be difficult. Moreover, the books and records, and internal control provisions apply to issuers in ALL instances, not just those instances in which the company is doing business or seeking business abroad. Thus, it may be more difficult to frame books and records and internal control issues to training, because the provisions apply to everything an issuer does.
Against this backdrop, what works best I think is to view FCPA compliance as not just a task that company lawyers and selected key positions from an anti-bribery perspective (i.e. sales, marketing, business development) need to be concerned with, but rather a task that internal audit and finance should also be concerned with and actively involved in as well.
This means that internal audit and finance personnel must be specifically trained to approach their specific job functions not only in a traditional way, but also with "FCPA goggles" on.
It is clear from recent FCPA enforcement actions that the SEC expects much more from non-legal personnel when it comes to FCPA compliance, including the ability to spot FCPA issues and display a high degree of (I'll call it) intellectual curiosity as to certain issues.
For instance, in the 2007 York matter, the SEC alleged in its civil complaint (see here at para 51) that (i) "York International's management had the ability to review or cause internal audit to review [the problematic contracts] and, had this been done, it would have been immediately apparant that the consultancy agreements were a sham; and (ii) it was "clear that local finance personnel did not provide an independent internal control function, but rather acquiesced in questionable practices and documentation without critical review."
Again, because the FCPA's books and records and internal control provisions are rather generic, I think a "best practice" (not only for issuers, but for any company) is to specifically train internal audit and finance personnel to view their job with "FCPA goggles" on.
This means that internal audit and finance personnel should:
(1) Understand the broad interpretations given to the anything of value, foreign official, and obtain or retain business elements of anti-bribery violation so that they clearly understand that conduct other than a "suitcase full of cash to a government official to get a government contract" is problematic. For instance,
excessive travel and marketing expenses, payment of scholarships, etc. can be things of value. Internal audit and finance personnel also need to understand that employees of state-owned or state-controlled companies are considered "foreign officials" by DOJ/SEC (even if that interpretation has not been tested or challenged). This means that things a company does to "wine and dine" its purely private customers can become problematic when state-owned or state-controlled customers receive the same treatment. In terms of state-owned or state-controlled customers, it is also a good idea for a company to maintain a roster of such entities so that heightened review will be triggered when any corporate personnel deals with such customers or prospective customers. Internal audit and finance personnel also need to understand that payments which result in a company securing a foreign license, permit, or certification can satisfy the "obtain or retain business" element of an anti-bribery violation on the theory that such payments help the company, in the general sense, obtain or retain business.
(2) Pay particular attention to employee reimbursement requests and think about FCPA issues in connection with these requests. For instance, if a specific sales and marketing employee is the designated "wine and dine" person, is there any heightened scrutiny of that individuals reimbursement requests?
(3) Be aware of the FCPA's third-party payment provisions and be able to spot (and follow-up on) the following issues relevant to engaging and supervising a foreign agent or representative: payments made to personal (rather than company) bank accounts; payments to off-shore bank accounts; payments which could be made in one lump sum but are split up to avoid detection; and payments made to an account in a country different than where the service provider is located. When utilizing third parties, commission payments are obviously a big FCPA risk. Thus, internal audit and finance personnel need to ask what steps the company has taken to assure itself that the commission payments are reasonable. Moreover, such personnel should specifically look for evidence that the third party actually provided legitimate value-added services before payment was made by the company.
(4) Figure out who within the company, the relevant business unit, etc. has the authority to authorize large payments and make sure those authorizations are scrutinized. Because of title, prestige and in some countries - gender - certain individuals are subjected to less oversight and scrutiny when it comes to authorizing payments. If any such trends or patterns emerge within a company as to this issue, internal audit and finance personnel must be diligent in understanding why.
(5)Pay particular attention to the following accounts (all of which, per recent FCPA enforcement actions, were used to conceal improper payments) - "additional assessments," "extra costs," "extraordinary expenses," "urgent processing," "urgent dispatch," "customs processing," "importation advances," . These accounts, and all other accounts described in a vague or ambiguous manner, should be subject to heightened scrutiny by internal audit and finance personnel.
Back to the original issue raised by the reader as to how best to offer FCPA books and records, and internal controls compliance training. Again, because the books and records and internal control provisions are so generic, I think the "best practice" is to couple such training with anti-bribery training and to make sure that internal audit and finance personnel have the FCPA tools necessary to properly execute their jobs.
Internal audit and finance personnel clearly have an FCPA compliance role to play, and the SEC is clearly expecting them to play that role. However, internal audit and finance personnel can only raise FCPA issues if they first know what FCPA issues to look for. Providing internal audit and finance personnel with a good pair of "FCPA goggles" is a good way to achieve books and records, and internal controls compliance.
Thursday, September 17, 2009
The Enforcement Officials Speak
Over at the wrageblog (see here), Alexandra Wrage, President of Trace International Inc., a leading non-profit membership association focused on anti-bribery compliance, has a good summary post of comments made by Mark Mendelsohn (DOJ's top FCPA prosecutor) and others at a recent FCPA conference.
Given that the enforcement agencies' untested and unchallenged interpretation of the "foreign official" element is one of my favorite FCPA issues, I was happy to see that Mendelsohn, in response to a question, apparently acknowledged that there can be difficult assessments of who qualifies as a "foreign official" under the FCPA.
Looks like FCPA trials are over for the year, but I'm guessing that there will be forthcoming appeals from the three FCPA verdicts reached this summer.
Given that the enforcement agencies' untested and unchallenged interpretation of the "foreign official" element is one of my favorite FCPA issues, I was happy to see that Mendelsohn, in response to a question, apparently acknowledged that there can be difficult assessments of who qualifies as a "foreign official" under the FCPA.
Looks like FCPA trials are over for the year, but I'm guessing that there will be forthcoming appeals from the three FCPA verdicts reached this summer.
Monday, September 14, 2009
The Results Are In ...
A couple of survey/poll results that may be of interest to FCPA followers.
The first survey is courtesy of Deloitte which obtained over 1,000 on-line survey responses from business professionals in various industries in connection with a recent webcast titled "Global Anticorruption: Risks and Strategies for Today's Global Enterprise."
Results of interest:
Only 31% of respondents indicated that their company had in place a "comprehensive FCPA compliance program." When asked why some companies might not have a comprehensive FCPA compliance program, 23% of respondents cited an "unawareness of the severity and consequences of FCPA violations." Clearly more people need to read this blog (and others) and follow FCPA news!
Only 32% of respondents indicated that their company addresses FCPA risks "proactively."
Respondents are most nervous about FCPA issues arising from: foreign subsidiaries (35%), agent/consultant relationships (28%) and joint venture/strategic alliances (18%).
And finally, 40% of respondents either said "no" or "don't know" to the question of whether the increased FCPA enforcement activity will deter future FCPA violations. You have to wonder what goes through the minds of Mark Mendelsohn and others at DOJ when they read a response like that?
The second survey (see here to download) was sponsored by Integrity Interactive Corporation and Compliance Week. The survey (which covers a wide range of compliance and ethics topics - not just the FCPA) collected approximately 230 responses from executives at global public companies and large private entities. Pgs. 38-39 of the survey contain FCPA data and indicate that executives are most concerned about payments to third parties, followed by inappropriate gifts and entertainment, direct bribes, company-financed "business trips" and unlawful political or charitable contributions.
The first survey is courtesy of Deloitte which obtained over 1,000 on-line survey responses from business professionals in various industries in connection with a recent webcast titled "Global Anticorruption: Risks and Strategies for Today's Global Enterprise."
Results of interest:
Only 31% of respondents indicated that their company had in place a "comprehensive FCPA compliance program." When asked why some companies might not have a comprehensive FCPA compliance program, 23% of respondents cited an "unawareness of the severity and consequences of FCPA violations." Clearly more people need to read this blog (and others) and follow FCPA news!
Only 32% of respondents indicated that their company addresses FCPA risks "proactively."
Respondents are most nervous about FCPA issues arising from: foreign subsidiaries (35%), agent/consultant relationships (28%) and joint venture/strategic alliances (18%).
And finally, 40% of respondents either said "no" or "don't know" to the question of whether the increased FCPA enforcement activity will deter future FCPA violations. You have to wonder what goes through the minds of Mark Mendelsohn and others at DOJ when they read a response like that?
The second survey (see here to download) was sponsored by Integrity Interactive Corporation and Compliance Week. The survey (which covers a wide range of compliance and ethics topics - not just the FCPA) collected approximately 230 responses from executives at global public companies and large private entities. Pgs. 38-39 of the survey contain FCPA data and indicate that executives are most concerned about payments to third parties, followed by inappropriate gifts and entertainment, direct bribes, company-financed "business trips" and unlawful political or charitable contributions.
Verdict In ... Green's Found Guilty
The third FCPA trial of the summer has concluded and Gerald and Patricia Green (two Los Angeles area film executives) have been found guilty by a federal jury of conspiracy to violate the FCPA, substantive FCPA violations, and other charges (see here for the DOJ New Release).
According to the DOJ release, evidence introduced at trial showed that "beginning in 2002 and continuing into 2007, the Greens conspired with others to bribe the former governor of the [Tourism Authority of Thailand] in order to get lucrative film festival contracts as well as other TAT contracts." According to the release, the evidence also established that the Green's attempted to disguise the bribe payments by labeling them "sale commissions" and by making the payments "for the benefit of the former governor through the foreign bank accounts of intermediaries, including bank accounts in the name of the former governor's daughter and friend."
Reacting to the verdict, Assistant Attorney General Breuer stated that the DOJ "will not waiver in its fight against corruption, whether perpetrated within our borders or abroad" and that the FCPA "is a powerful tool that the [DOJ] will continue to use in an effort to stop individuals like the Greens who seek to further their own business interests through bribes paid to foreign officials."
The Greens are to be sentenced in December and the conspiracy and FCPA charges each carry a maximum penalty of five years in prison.
As mentioned, the Green trial was the third FCPA trial of the summer.
The other two were the Bourke matter (see here) and the Jefferson matter (see here).
Leading up to these trials, the FCPA bar and the enforcement officials themselves, predicted that one result of these trials would be greater clarity of some of the FCPA's murky elements.
While the verdicts were, on balance, pro-DOJ verdicts, the verdicts reached in these trials were not exactly uniform.
Bourke was convicted of conspiracy to violate the FCPA (the case did not proceed to trial on a substantive FCPA violation).
Jefferson was also convicted of conspiracy (although it is not entirely clear if the jury found him guilty of conspiracy to violate the FCPA). However, Jefferson was found not guilty on the substantive FCPA charge (the charge predicated on the "cash in the freezer" allegations).
Have these trials provided any greater clarity as to various FCPA elements as widely predicted?
I think it is far to say that as a result of the Bourke verdict (even though it was not a substantive FCPA trial), the FCPA's knowledge standard has never been broader, and can be satisfied even when an investor, like Bourke, does not actually pay a bribe, but is merely aware that others may be making bribe payments in a widely viewed corrupt country for the potential benefit of an entity in which he is an investor (see here and here).
Beyond this, I'm not sure that any further clarity as to substantive FCPA elements has resulted from these trials, but I would be interested to hear what others have to say.
Will these trials and the largely pro-DOJ verdicts send a "proceed with caution" message to any individual or corporation faced with an FCPA enforcement action and stiffle legitimate defense theories based on the FCPA's elements?
I expect so, yet that is indeed unfortunate as a significant portion of FCPA enforcements are based largely on DOJ/SEC's untested and unchallenged interpretations of the law.
According to the DOJ release, evidence introduced at trial showed that "beginning in 2002 and continuing into 2007, the Greens conspired with others to bribe the former governor of the [Tourism Authority of Thailand] in order to get lucrative film festival contracts as well as other TAT contracts." According to the release, the evidence also established that the Green's attempted to disguise the bribe payments by labeling them "sale commissions" and by making the payments "for the benefit of the former governor through the foreign bank accounts of intermediaries, including bank accounts in the name of the former governor's daughter and friend."
Reacting to the verdict, Assistant Attorney General Breuer stated that the DOJ "will not waiver in its fight against corruption, whether perpetrated within our borders or abroad" and that the FCPA "is a powerful tool that the [DOJ] will continue to use in an effort to stop individuals like the Greens who seek to further their own business interests through bribes paid to foreign officials."
The Greens are to be sentenced in December and the conspiracy and FCPA charges each carry a maximum penalty of five years in prison.
As mentioned, the Green trial was the third FCPA trial of the summer.
The other two were the Bourke matter (see here) and the Jefferson matter (see here).
Leading up to these trials, the FCPA bar and the enforcement officials themselves, predicted that one result of these trials would be greater clarity of some of the FCPA's murky elements.
While the verdicts were, on balance, pro-DOJ verdicts, the verdicts reached in these trials were not exactly uniform.
Bourke was convicted of conspiracy to violate the FCPA (the case did not proceed to trial on a substantive FCPA violation).
Jefferson was also convicted of conspiracy (although it is not entirely clear if the jury found him guilty of conspiracy to violate the FCPA). However, Jefferson was found not guilty on the substantive FCPA charge (the charge predicated on the "cash in the freezer" allegations).
Have these trials provided any greater clarity as to various FCPA elements as widely predicted?
I think it is far to say that as a result of the Bourke verdict (even though it was not a substantive FCPA trial), the FCPA's knowledge standard has never been broader, and can be satisfied even when an investor, like Bourke, does not actually pay a bribe, but is merely aware that others may be making bribe payments in a widely viewed corrupt country for the potential benefit of an entity in which he is an investor (see here and here).
Beyond this, I'm not sure that any further clarity as to substantive FCPA elements has resulted from these trials, but I would be interested to hear what others have to say.
Will these trials and the largely pro-DOJ verdicts send a "proceed with caution" message to any individual or corporation faced with an FCPA enforcement action and stiffle legitimate defense theories based on the FCPA's elements?
I expect so, yet that is indeed unfortunate as a significant portion of FCPA enforcements are based largely on DOJ/SEC's untested and unchallenged interpretations of the law.
Thursday, September 10, 2009
"Foreign Officials" in Puerto Rico?
While reading the DOJ release today regarding the guilty plea of Dr. Candido Negron Mella (see here), I was reminded of a conversation I had a few years back with a former law firm colleague during which we scratched our heads wondering if a Puerto Rico government official could be a "foreign official" under the FCPA. Because the statute defines "foreign official" as being an "officer or employee of a foreign government ..." we surmised that the answer was no, but agreed that the question was nevertheless an interesting issue to ponder.
The Mella enforcement action would seem to bear all the hallmarks of an FCPA enforcement action. As set forth in the release, Mella pleaded guilty to conspiracy to violate the Federal Election Campaign Act for "his participation in a corruption scheme involving the 2000 Resident Commissioner campaign of a former governor of Puerto Rico." The release notes that "Mella was a partner in a company that had a professional relationship with a large Medicaid dental provider in the United States that was interested in obtaining a direct dental agreement with the Commonwealth of Puerto Rico." According to the release, "[i]n order to assist that provider in obtaining a contract in Puerto Rico" Mella agreed to raise contributions for the campaign and he admitted that he hoped that contributing to the campaign "would enable him to obtain access to the government of Puerto Rico to promote his business interests."
All the hallmarks of an FCPA enforcement action that is ... except a foreign official. At least that is my conclusion from reading the Mella enforcement action and the lack of FCPA charges.
I ponder no more.
The Mella enforcement action would seem to bear all the hallmarks of an FCPA enforcement action. As set forth in the release, Mella pleaded guilty to conspiracy to violate the Federal Election Campaign Act for "his participation in a corruption scheme involving the 2000 Resident Commissioner campaign of a former governor of Puerto Rico." The release notes that "Mella was a partner in a company that had a professional relationship with a large Medicaid dental provider in the United States that was interested in obtaining a direct dental agreement with the Commonwealth of Puerto Rico." According to the release, "[i]n order to assist that provider in obtaining a contract in Puerto Rico" Mella agreed to raise contributions for the campaign and he admitted that he hoped that contributing to the campaign "would enable him to obtain access to the government of Puerto Rico to promote his business interests."
All the hallmarks of an FCPA enforcement action that is ... except a foreign official. At least that is my conclusion from reading the Mella enforcement action and the lack of FCPA charges.
I ponder no more.
Subscribe to:
Posts (Atom)
