Showing posts with label Books and Records. Show all posts
Showing posts with label Books and Records. Show all posts

Wednesday, July 13, 2011

A Focus On The SEC

From an FCPA reform perspective, most of the recent scrutiny has been on the DOJ and its enforcement policies and positions.

Yet, the FCPA is also enforced by the SEC.

As a civil enforcement agency only, the SEC's stick is less sharp the DOJ's. Nevertheless, the SEC's FCPA enforcement positions on issues such as "foreign official" and "obtain or retain business" are seemingly identical to the DOJ's.

Moreover, certain of the SEC's enforcement theories as to the FCPA's books and records and internal control provisions are subject to controversy. As I highlighted in "The Facade of FCPA Enforcement" (here at pgs. 976-984), with increasing frequency, the SEC has charged FCPA books and records and internal control violations based on untested and dubious legal theories, as well as theories seemingly in direct conflict with the FCPA’s statutory provisions.

For instance, the SEC routinely charges parent companies with FCPA books and records and internal control violations based solely on the conduct of indirect subsidiaries or affiliates in the absence of any allegation that the parent company participated in, or had knowledge of, the conduct at issue - even though the FCPA specifically states that issuers that demonstrate good faith efforts to cause indirect subsidiaries and affiliates to devise and maintain effective internal controls “shall be conclusively presumed to have complied with” the FCPA’s applicable requirements.

The SEC's FCPA enforcement theories and policies are now being questioned. See here for the June 30th letter from Senator Mike Crapo (R-ID) to SEC Chairman Mary Schapiro.

The letter begins with Senator Crapo stating that "Congress and the agencies that enforce the FCPA must work together to ensure that the statute's goals are being met without perverting the risk and reward calculus U.S. firms face when considering overseas business opportunities that would support domestic job growth."

In the letter, Senator Crapo says he is "concerned by the recent Congressional testimony about the increased compliance costs for businesses operating in good faith to abide by the FCPA's strictures and the deterrence of U.S. firms' entry into, or expansion of, overseas operations."

Senator Crapo then asks Chairman Schapiro for answers to the following questions.

1. Should the FCPA be amended to provide an affirmative defense, which may be raised where violations resulted from the conduct of individual employees or agents who circumvented compliance measures that were reasonably designed to identify and prevent such violations?

2. Does the Commission believe that regulations or guidance explaning factors it considers when determining whether an entity's officers or employees are "foreign officials" would be helpful to U.S. firms? Would the Commission support legislation that more clearly defines the term "foreign official" under the FCPA?

3. What are the mechanisms by which the Commission could or does provide guidance on FCPA related matters?

4. Is it the Commission's policy to hold firms strictly liable for foreign subsidiaries' actions in violation of the FCPA?

5. Under what circumstances, if any, is it appropriate for both the Commission and the Department to seek the recovery of penalties from the same entity for the same conduct?

Prior to responding to Senator Crapo's letter, Chairman Schapiro and others at the SEC's FCPA Unit would be well served by reviewing a 1981 speech by then Chairman of the SEC - Harold Williams - on the FCPA's books and records and internal control provisions.

To best understand (and place in context) current SEC FCPA enforcement positions and policies, it is useful to understand past SEC FCPA enforcement positions and policies. Statements made by the SEC Chairman in 1981 bear little resemblence to the SEC's current enforcement of the FCPA's books and records and internal control provisions.

*****

The year was 1981, the event was the American Institute of Certified Public Accountants, and the speaker was Harold Williams, the Chairman of the SEC. Williams focused his remarks (here) “solely to one major auditing development of recent years: the accounting provisions of the Foreign Corrupt Practices Act of 1977.”

Williams began has remarks as follows. “When viewed from an abstract perspective, the Act’s accounting provisions seem merely to codify a basic and uncontroversial management principle: no enterprise of any size can operate successfully without maintaining effective controls over its transactions and the disposition of its assets. Perhaps in part because these provisions were considered truisms, the Act was passed without Congressional dissent. However, practical experience with new legislation – even a law thought to be noncontroversial – often will reveal unanticipated problems. Newly enacted standards, for example, may be subject to differing constructions or raise compliance difficulties and ambiguities unforeseen by their draftsmen. And, until these problems are resolved by an agency, the courts or the Congress, those who are subject to these laws are often faced, unfortunately, with some disquieting circumstances. The anxieties created by the Foreign Corrupt Practices Act – among men and women of utmost good faith – have been, in my experience without equal."

Williams noted that “such uncertainty can have a debilitating effect on the activities of those who seek to comply with the law. My sense is that, as a consequence, many businesses have been very cautious – sometimes overly so – in assuring at least technical compliance with the Act. And, therefore, business resources may have been diverted from more productive uses to overly-burdensome compliance systems which extend beyond the requirements of sound management or the policies embodied in the Act. The public, of course, is not well served by such reactions.”

Unlike many SEC speeches that contain the usual – this is only my personal opinion disclaimer – Williams specifically noted that he “conferred” with his “colleagues before presenting these remarks, and they have authorized me to advise you that these remarks constitute a statement of the Commission’s policy.”

As to the FCPA’s books and records provisions, Williams stated as follows. “This provision is intimately related to the requirement for a system of internal accounting controls, and we believe that records which are not relevant to accomplishing the objectives specified in the statute for the system of internal controls are not within the purview of the recordkeeping provision. […] nor could a company be enjoined for a falsification of which its management, broadly defined, was not aware and reasonably should not have known.”

As to the FCPA’s internal control provisions, Williams stated as follows. “The Act does not mandate any particular kind of internal controls system. The test is whether a system, taken as a whole, reasonably meets the statute’s specified objectives. ‘Reasonableness,’ a familiar legal concept, depends on an evaluation of all the facts and circumstances.”

Under the heading “deference” Williams stated as follows. “Private sector decisions implementing these statutory objectives are business decisions. And, reasonable business decisions should be afforded deference. This means that the issuer need not always select the best or the most effective control measure. However, the one selected must be reasonable under all the circumstances.”

Under the heading “state of mind” Williams stated as follows. “The accounting provisions principal objective is to reaching knowing or reckless conduct.”

As to the “purposes of the Act,” Williams provided a brief review of the “events which led to the [FCPA].” He stated as follows. “Clearly, Congress went further than determining whether the payments which gave the new law its name were ethically and commercially justifiable. It also chose to consider the corporate accounting and control deficiencies which had been breeding grounds for these practices. And, by doing so, it addressed the far more serious issues raised by these disclosures. […] These payments and falsifications were not only previously unknown to public investors and independent auditors, but many were also unknown to the payor’s board and, in numerous examples, even to its senior management. In some of these instances, internal controls existed, but they were shown to be ineffective or easily subverted. Unauthorized payments and related falsifications of corporate records seemed to evidence – indeed, were fostered by – a lack of adequate accounting records and controls. Consequently, in the legislation which ultimately emerged from Congress, prohibiting questionable payments and mandating control and recordkeeping were inexorably interconnected.”

Williams stated as follows. “The primary thrust of the Act’s accounting provisions, in short, was to require those public companies which lacked effective internal controls or tolerated unreliable recordkeeping to comply with the standards of their better managed peers. That is the context in which these provisions should be construed.”

Williams then addressed “four of the most important” interpretative questions concerning the then-young FCPA: “first, the degree of exactitude in recordkeeping mandated by the Act; second, the deference it affords business decisions concerning internal controls; third, whether a particular state of mind is necessary for a violation to exist; and finally, liability for compliance by subsidiaries.”

As to the “degree of exactitude” Williams stated as follows. “I turn first to the question of whether the Act’s text or purpose mandates that business records and controls conform to a standard of absolute exactitude or that a company’s control system meet some absolute ideal. The answer is ‘no.’ Both of the Act’s accounting provisions, it should be noted are modified by the key term ‘reasonable.’ […] In essence, therefore, the Act does provide a de minimus exemption, though not in absolute quantitative terms.”

Williams noted that Congress specifically declined to adopt a materiality test and stated that “internal accounting controls are not only concerned with misconduct that is material to investors, but also with a great deal of misconduct which is not.” He noted that while materiality is “appropriate as a threshold standard to determine the necessity for disclosure to investors, [it] is totally inadequate as a standard for an internal control system.”

Williams stated that “procedures designed only to uncover deficiencies in amounts material for financial statement purposes would be useless for internal control purposes” and noted that “systems which tolerated omissions or errors of many thousands or even millions of dollars would not represent, by any accepted standard, adequate records and controls.” Indeed, Williams noted that many of the “questionable payments that alarmed the public and caused Congress to act” […] were in most instance of far lesser magnitude than that which would constitute financial statement materiality.”

“Reasonableness, rather than materiality, is the appropriate test,” Williams stated. He noted as follows. "Reasonableness, as a standard, allows flexibility in responding to particular facts and circumstances. Inherent in this concept is a toleration of deviations from the absolute. One measure of the reasonableness of a system relates to whether the expected benefits from improving it would be significantly greater than the anticipated costs of doing so. Thousands of dollars ordinarily should not be spent conserving hundreds. Further, not every procedure which may be individually cost-justifiable need be implemented; the Act allows a range of reasonable judgments.”

As to the “specific recordkeeping requirement” in the FCPA, Williams stated as follows. “… [T]his provision is not an independent unrestrained mandate to the Commission to establish novel or unprecedented corporate recordkeeping standards; it is, rather, an integral part of Congress’ efforts to assure that the business community records transactions and assets in such a way as to maintain adequate control over them. And this leads to two important conclusions: First, the Act does not establish any absolute standard of exactitude for corporate records. And, second, records which are not related to internal or external audits or to the four internal control objectives set forth in the Act are not within the purview of the Act’s accounting provisions.”

As to “deference” with respect to “issuer liability for recordkeeping violations” Williams stated that the SEC “will look to the adequacy of the internal control system of the issuer, the involvement of top management in the violation, and the corrective actions taken once the violation was uncovered.”

In a sign of just how much FCPA enforcement has changed, Williams then stated as follows. “If a violation was committed by a low level employee, without the knowledge of top management, with an adequate system of internal control, and with appropriate corrective action taken by the issuer, we do not believe that any action against the company would be called for.”

Williams next turned to the “state of mind needed to violate the Act’s accounting provisions.” He reiterated that the “Act’s principal purpose is to reach knowing or reckless misconduct.”

In another sign of just how much FCPA enforcement has changed, William stated as follows. “… [D]epending on the circumstances, intentional circumventions of a company’s system of records and of accounting controls by a low-level employee would not always be considered violations of the Act by the issuer. No system of adequate records and controls – no matter how effectively devised or conscientiously applied – could be expected to prevent all mistaken and improper transactions and disposition of assets. Given human nature, regardless of the adequacy of the system, a bookkeeper may still erroneously post entries, an overzealous agent may make unauthorized payments, or an unscrupulous employee may falsify records for his own purposes. The Act recognizes each of these limitations. Neither its text and legislative history nor its purposes suggest that occasional, inadvertent errors were the kind of problem that Congress sought to remedy in passing the Act. No rational federal interest in punishing insignificant mistakes has been articulated. And, the Act’s accounting provisions do not require a company or its senior officials to be the guarantors of all conduct of company employees.”

In concluding this portion of his speech, Williams stated as follows. “The test of a company’s internal control system is not whether occasional failings can occur. Those will happen in the most ideally managed company. But, an adequate system of internal controls means that, when such breaches do arise, they will be isolated rather than systemic, and they will be subject to a reasonable likelihood of being uncovered in a timely manner and then remedied promptly. Barring, of course, the participation or complicity of senior company officials in the deed, when discovery and correction expeditiously follow, no failing in the company’s internal accounting system would have existed. To the contrary, routine discovery and correction would evidence its effectiveness.”

As to subsidiaries, Williams stated as follows. “Where the issuer controls more than 50 percent of the voting securities of the subsidiary, compliance is expected. So, too, would it be expected if there is between 20 percent and 50 percent ownership, subject to some demonstration by the issuer that this does not amount to control. If there is less than 20 percent ownership, we will shoulder the burden to affirmatively demonstrate control.”

As to the SEC’s enforcement policy, Williams concluded his remarks as follows. “The genius – and challenge – of [the FCPA’s accounting provisions] , it should be remembered, is their reliance on private sector decisionmaking – rather than specific federal edicts – to address an area of public concern. The Act’s eventual success or failure will, therefore, depend primarily upon business’s response. The Commission’s obligation, in turn, is to provide a regulatory environment in which the private sector can address these issues meaningfully and creatively. In this regard, we must encourage public companies to develop innovative records and control systems, to modify and improve them as circumstances change, and to correct recordkeeping errors when they occur without a chilling fear of penalty or inference that a violation of the Act is involved.”

Tuesday, January 12, 2010

Ready, Set, Go ...

The 2010 FCPA enforcement year has begun.

Yesterday, the SEC announced (here) resolution of an FCPA books and records and internal controls action against NATCO Group Inc. - a Houston based "worldwide leader in design, manufacture, and service" of oil and gas process equipment (see here).

The SEC complaint (here) alleges that TEST Automation & Controls, Inc., a wholly-owned subsidiary of NATCO Group, "created and accepted false documents while paying extorted immigration fines and obtaining immigration visas in the Republic of Kazakhstan." According to the complaint, "NATCO's system of internal accounting controls failed to ensure that TEST recorded the true purpose of the payments, and NATCO's consolidated books and records did not accurately reflect these payments."

According to the complaint, TEST maintained a branch office in Kazakhstan and in June 2005 it won a contract which required it to hire both expatriates and local Kazakh workers. Pursuant to Kazakh law, TEST needed to obtain immigration documentation before an expatriate worker could enter the country. Thereafter, Kazakh immigration authorities claimed that TEST's expatriate workers were working without proper documentation and the authorities threatened to fine, jail, or deport the workers if TEST did not pay cash fines.

According to the complaint, TEST employees believed the threats to be genuine and, after consulting with U.S. TEST management who authorized the payments, paid the officials approximately $45,0000 using their personal funds for which the employees were reimbursed by TEST.

The complaint alleges that when reimbursing the employees for these payments, TEST inaccurately described the money as: (i) being an advance on a bonus; and (ii) visa fines.

The complaint further alleges that TEST used consultants in Kazakhstan to assist in obtaining immigration documentation for its expatriate employees and that "one of these consultants did not have a license to perform visa services, but maintained close ties to an employee working at the Kazakh Ministry of Labor, the entity issuing the visas." According to the complaint, the consultant twice requested cash from TEST to help him obtain the visas and the complaint alleges that the consultant provided TEST with bogus invoices to support the payments.

Based on the above allegations, the SEC charged NATCO with FCPA books and records and internal control violations even though the complaint is completely silent as to any involvement or knowledge by NATCO in the conduct at issue. This action is thus the latest example of an issuer being strictly liable for a subsidiary's books and records violations (see here for a prior post).

Without admitting or denying the SEC's allegations, NATCO agreed to pay a $65,000 civil penalty. According to the SEC's findings in a related cease and desist order (here), during a routine internal audit review, NATCO discovered potential issues involving payments at TEST, conducted an internal investigation, and voluntarily disclosed the results to the SEC. The order also lists several other remedial measures NATCO implemented.

I've noted in prior posts that one of the effects of voluntary disclosure is that it sets into motion a whole series of events including, in many cases, a much broader review of the company's operations so that the company can answer the enforcement agencies' "where else may this have occurred" question.

On this issue, the SEC order states that NATCO "expanded its investigation to examine TEST's other worldwide operations, including Nigeria, Angola, and China, geographic locations with historic FCPA concerns." However, the SEC order notes that "NATCO's expanded internal investigation of TEST uncovered no wrongdoing."

According to the complaint, at all times relevant to the complaint, NATCO's stock was listed on the NYSE, but in November 2009 NATCO became a subsidiary of Cameron International Corporation (here) (an NYSE listed company) and NATCO's NYSE listing ended.

The NATCO enforcement action is "as garden variety" of an FCPA enforcement action as perhaps one will find. Not only does moving product into and out of a country expose a company to FCPA risk, but so too does moving employees into and out of a country.

The NATCO civil penalty also demonstrates that in certain cases, the smallest "cost" of an alleged FCPA violation are the fines or penalties, figures which are so dwarfed by investigative, remedial and resolution costs.

Wednesday, January 6, 2010

Team of Plenty

Voluntary disclosure (i.e. picking up the phone and calling the DOJ and/or SEC (if applicable) to schedule a meeting, during which a company's lawyers disclose conduct that could potentially implicate the FCPA, even though the enforcement agencies, in many cases, would never find out about the conduct) is a tough issue.

In a November 2009 speech to an FCPA audience (see here), Assistant Attorney General Lanny Breuer acknowledged that the decision of whether to make a voluntary disclosure is "sometimes a difficult question" [...] a question I grappled with as a defense lawyer."

The Gibson Dunn Year End FCPA Report (the subject of yesterday's post see here) has this to say about voluntary disclosure:

"To be sure, a company that voluntary discloses a potential FCPA violation to DOJ and the SEC will be better situated than one that otherwise finds itself across the table from the government having not disclosed the conduct."

[...]

"On the other hand, there is substantial debate about just how "tangible" the benefits of voluntary disclosure truly are."

[...]

"Although some corporate defendants that self-reported misconduct have certainly received relatively lenient treatment, it is not clear that voluntary disclosure was the reason for any particular settlement term."

[...]

"Although it is certain that companies do receive some benefit for self-reporting FCPA violations, the real question is whether the company considering a voluntary disclosure is better off for having made the disclosure, which is not necessary one-and-the-same. Because voluntary disclosure makes the government aware of alleged improper conduct that it otherwise may have never discovered on its own, the likelihood of the government uncovering the misconduct through other means, such as a whistleblower, foreign government investigation, tip from a competitor or business partner, or industry-wide investigation, is a critical factor in determining whether to make a voluntary disclosure."

[...]

"Given the multitude of factors to consider when making a voluntary disclosure decision, it is often challenging to make such a significant decision with any degree of confidence that a particular course of action is the right one. This task is made even more difficult by the uncertainty of obtaining any particular benefits for disclosing."

As raised in a prior post (see here), a company's decision in deciding whether or not to voluntarily disclose conduct to the enforcement agencies that could potentially implicate the FCPA is made even more difficult given the potential conflict of interest FCPA counsel has in advising the company as to the important disclosure issue - particularly where the disclosure only involves a potential FCPA violation?

I raised this lurking "elephant in the room" question in connection with Dyncorp International's recent disclosure of potential FCPA issues.

One could raise the same question in connection with Team Inc.

In August 2009, Team (a Texas-based provider of specialty industrial services) disclosed (here) that an internal investigation conducted by FCPA counsel "found evidence suggesting that payments, which may violate the Foreign Corrupt Practices Act (FCPA), were made to employees of foreign government owned enterprises."

The release further noted that "[b]ased upon the evidence obtained to date, we believe that the total of these improper payments over the past five years did not exceed $50,000. The total annual revenues from the impacted Trinidad branch represent approximately one-half of one percent of our annual consolidated revenues. We have voluntary disclosed information relating to the initial allegations, the investigation and the initial findings to the U.S. Department of Justice and to the Securities and Exchange Commission, and we will cooperate with the DOJ and SEC in connection with their review of this matter."

In the prior post, I noted that a voluntary disclosure often sets into motion a series of events and the next thing the company knows it is paying for a team of lawyers (accompanied by forensic accountants and other specialists) even though the voluntary disclosure that got the whole process started involved conduct that may not actually violate the FCPA.

Fast forward to yesterday as Team disclosed (here) as follows:

"As previously reported, the Audit Committee is conducting an independent investigation regarding possible violations of the Foreign Corrupt Practices Act (“FCPA”) in cooperation with the U.S. Department of Justice and the Securities and Exchange Commission. While the investigation is ongoing, management continues to believe that any possible violations of the FCPA are limited in size and scope. The investigation is now expected to be completed during the first calendar quarter of 2010. The total professional costs associated with the investigation are now projected to be about $3.0 million."

A $3 million dollar internal investigation concerning non-material payments made by a branch office that represents less than one-half of one percent of the company's annual consolidated revenues?

Wow!

Double-wow because the payments may not even violate the FCPA because they were made to "employees of foreign government owned enterprises" (see here for several prior posts on the enforcement agenices untested and unchallenged interpretation of the "foreign official" element)!

Others have scratched their heads about this as well (see here and here).

Of course, the FCPA does not contain a de minimis exception and of course the FCPA contains books and records and internal control provisions applicable to issuers like Team. Thus, even if the payments were not material in terms of the company's overall financial condition, there still could be FCPA books and records and internal control exposure if they were misrecorded in the company's books and records or made in the absence of any internal controls.

But then again, the FCPA books and records and internal control provisions would be implicated if a Team employee took his Cousin Randy to the company's corporate suite for the ballgame but recorded the costs as "marketing expenses" on his reimbursement request causing the company to misrecord the payment. Yet, no one would suggest disclosing this potential FCPA violation!

Monday, December 28, 2009

A Look Back (and Forward)

This week marks not only the end of a year, but also a decade.

So let’s take a look back at FCPA enforcement circa 2000.

In 2000, the FCPA was indeed “on the books” (the statute was enacted in 1977), yet there was little in terms of FCPA news or enforcement actions.

A "U.S. newspapers and wires" search for the FCPA in the 2000 picks up 64 “hits” and among the more noteworthy stories from that year were the following:

(1) BellSouth corporation disclosed that the SEC launched a probe into whether one of its Latin American subsidiaries violated the FCPA and the company also disclosed that its outside counsel had already investigated the conduct and found that no violations had occurred; and

(2) BF Goodrich Company announced that it was using a web-enabled training system to educate its employees about work-related legal issues including the FCPA.

One could even attend a few FCPA training sessions in 2000 as the search picked up programs sponsored by both the City of New York Bar and the Washington DC Bar.

There was even one FCPA enforcement action in 2000!

In December 2000, the SEC announced (here) the filing of a settled cease-and-desist proceeding against International Business Machines Corporation (“IBM”).

According to the SEC order (here), IBM violated the books and records provisions of the FCPA based on the conduct of its indirect, wholly-owned subsidiary, IBM-Argentina, S.A. The conduct involved “presumed illicit payments to foreign officials” in connection with a “$250 million systems integration contract” between Banco de la Nacion Argentina (“BNA”) (an apparent “government-owned commercial bank in Argentina) and IBM-Argentina.

The SEC order finds that, in connection with the contract, IBM-Argentina’s Former Senior Management (without the knowledge or approval of any IBM employee in the U.S.) caused IBM-Argentina to enter into a subcontract with an Argentine corporation (“CCR”) and that “money paid to CCR by IBM-Argentina in connection with the subcontract was apparently subsequently paid by CCR to certain BNA officials.”

According to the Order, IBM-Argentina paid CCR approximately $22 million under the subcontract and “at least $4.5 million was transferred to several BNA directors by CCR.”

According to the Order, the former Senior Management “overrode IBM procurement and contracting procedures, and hid the details of the subcontract from the technical and financial review personnel assigned to the Contract.” The Order finds that IBM-Argentina “recorded the payments to CCR in its books and records as third-party subcontractor expenses” and that IBM-Argentina’s financial results were incorporated into IBM’s financial results filed with the Commission.

Based on the above conduct, the SEC concluded that “IBM violated [the FCPA’s books and records provisions] by failing to ensure that IBM-Argentina maintained books and records which accurately reflected IBM-Argentina’s transactions and dispositions of assets with respect to the Subcontract.” IBM consented to a cease and desist order and consented to entry of a judgment ordering it to pay a $300,000 penalty.

A Washington Post article about the IBM action notes that it "is the SEC's first in three years involving overseas bribery."

In 2000, there were no DOJ FCPA prosecutions (against corporations or individuals).

The first DOJ corporate FCPA prosecution of this decade did not occur until 2002.

In that action (here) Syncor Taiwan, Inc. (a wholly-owned, indirect subsidiary of Syncor International Corporation) pleaded guilty to a one-count criminal information charging violations of the FCPA. According to the DOJ release, "[t]he company admitted making improper payments [approximately $344,110] to physicians employed by hospitals owned by the legal authorities in Taiwan for the purpose of obtaining and retaining business from those hospitals and in connection with the purchase and sale of unit dosages of certain radiopharmaceuticals."

The release further notes that the company "made payments [approximately $113,000] to physicians employed by hospitals owned by the legal authorities in Taiwan in exchange for their referrals of patients to medial imaging centers owned and operated by the defendant."

Based on this conduct, the release notes that the company agreed to a $2 million criminal fine - "the maximum criminal fine for a corporation under the FCPA" (as noted in the release). The release also notes that "Syncor International has consented to the entry of a judgment requiring it to pay a $500,000 civil penalty, the largest penalty ever obtained by the SEC in an FCPA case.".

From this retrospective, two issues jump out.

First, as demonstrated by the IBM action, the notion that an issuer may be strictly liable for a subsidiary's (even if indirect) violations of the FCPA books and records is nothing new. (See here for a prior post on this issue).

Second, as demonstrated by the Syncor action, DOJ's interpretation of the "foreign official" element to include non-government employees employed by state-owned or state-controlled entities stretches back to earlier this decade. (See here for prior posts on this issue).

This retrospective also highlights just how significantly FCPA enforcement has changed this decade.

For starters, the same "U.S. newspapers and wires" search for the FCPA (year to date) picks up nearly 700 "hits" (a ten-fold increase from ten years ago). In addition, if one wanted to, one could attend (it seems) an FCPA seminar, training session, bar event, etc. every week in a different state.

Further, I bet my Jack LaLanne Power Juicer received this holiday season that if the IBM enforcement action were to have recently occurred, the SEC would have also charged FCPA internal control violations as well as sought a significant disgorgement penalty given that the alleged improper payments in that matter helped secure a $250 million contract.

Moreover, the $2 million "maximum criminal fine for a corporation under the FCPA" (as noted in the Syncor DOJ release) seems laughable when viewed in the context of the $450 million Siemens criminal fine (Dec. 2008) or the $402 million Kellogg Brown & Root criminal fine (Feb. 2009). Also laughable is the $500,000 "largest penalty ever obtained by the SEC in an FCPA case" (as noted in the Syncor release) when viewed in the context of the $350 million Siemens penalty or the $177 million KBR/Halliburton penalty.

Has the conduct become more egregious during this decade or have enforcement theories and strategies simply changed? I doubt it is the former.

Why have enforcement theories and strategies changed? One of the best, candid explanations I've heard recently is that FCPA enforcement for the government "is lucrative." (See here).

One of the great legal "head-scratchers" of this decade is how DOJ and SEC's enforcement of the FCPA against business entities has taken place almost entirely outside of the normal judicial process due to the fact that corporate FCPA prosecutions are resolved through non-prosecution or deferred prosecution agreements, settled through SEC cease and desist orders, or otherwise resolved informally. The end result is that in many cases, the FCPA means what DOJ and SEC says it means.

My hope for the New Year and decade is that many of the untested and unchallenged legal theories which are now common in FCPA enforcement will actually be subject to judicial scrutiny and interpretation.

Sunday, November 29, 2009

If the SEC Was An Issuer ...

The FCPA’s books and records and internal control provisions require issuers (i.e. publicly-traded companies) to: (i) “make and keep books, records, and accounts, which, in reasonable detail, accurately and fairly reflect the transactions and dispositions of the assets of the issuer;” and (ii) devise and maintain a system of internal accounting controls sufficient to provide reasonable assurances that (among other things) transactions are executed in accordance with management’s general or specific authorization, transactions are recorded as necessary to maintain accountability of assets, and access to assets is permitted only in accordance with management’s general or specific authorization.

The SEC enforces these provisions against issuers.

Often times, the SEC enforces these provisions against issuers aggressively (see here and here).

It seems to not matter to SEC enforcement officials whether the improper recording in the company’s books or records occurred at a far flung, fifth-tier subsidiary by a rogue employee or whether the issuer actually had knowledge that a far flung subsidiary was engaged in improper conduct.

The SEC’s position is that if the far-flung subsidiary’s financial results are consolidated with the parent company issuer’s financial results for purpose of financial reporting, then the subsidiary’s violation is the issuer’s violation.

Further, it seems to not matter to SEC enforcement officials whether the violation resulted from a rogue employee acting contrary to clearly articulated and well communicated company policies and procedures prohibiting the improper conduct because, after all, if the company’s internal controls were effective, rogue employees would not exist or, if they do exist, proper controls would be put in place to monitor their behavior before it occurred.

Every so often, it is fun to spend a few moments in “hypothetical land.”

The issue in “hypothetical land” today is - if the SEC was an issuer.

If the SEC was an issuer, it would have some serious FCPA books and records and internal control issues to deal with as a result of the Government Accountability Office’s ("GAO's") recent “Financial Audit – Securities and Exchange Commission’s Financial Statements for Fiscal Years 2009 and 2008” (see here).

As detailed in the audit, the GAO “identified six significant deficiencies that collectively represent a material weakness in SEC’s internal control over financial reporting.” In short, the GAO concluded that “SEC’s internal control over financial reporting was not effective as of September 30, 2009.”

Most notably, the GAO found material weaknesses that have: (i) “resulted in unsupported entries and errors in the general ledger"; (ii) “ineffective financial reporting controls and general ledger system reporting limitations"; and (iii) “ineffective processes and related documentation concerning budgetary transactions.” (p. 5).

Among other specifics, in terms of the general ledger system and the supporting processes the SEC uses to prepare its financial statements, the GAO found that:

“unauthorized personnel can view, manipulate, or destroy data” (p. 64);

SEC controls to compensate for the general ledger limitations “are cumbersome and largely detective nature, increasing the risk that errors or fraud that could result in a misstatement to the financial statements would not be prevented” (p. 65);

in connection with deposit account activity, the SEC's processes are “labor-intensive” and that “it does not have dedicated resources assigned to address this issue” (p. 69); and

"obligations […] were not always recorded timely and were not always supported by documentation evidencing the obligation as having been approved by an authorized individual” (p. 70).

Under the FCPA, not only is it important for issuers to have effective internal controls, but issuers must also monitor those internal controls to make sure that they are effective.

The GAO was critical of the SEC on this score as well.

The report notes:

“We also identified weaknesses in SEC’s monitoring process which indicate a lack of effective oversight of controls. Management’s monitoring of controls should include whether the controls are operating as intended and include an assessing of the design and operation of controls on a timely basis and taking necessary corrective actions. As discussed previously, we found that SEC’s monitoring procedures did not address all identified risks. Further, SEC’s management oversight was not sufficient given the frequency and sensitivity of the control activity, and monitoring procedures were not always completed in accordance with SEC’s stated testing plan.” (p. 71-72).

According to the GAO – “[b]ecause of inherent limitations, [the SEC's] internal control[s] may not prevent or detect and correct misstatements due to error or fraud, losses, or noncompliance.” (p. 8).

Because of the above identified deficiencies, if the SEC was an issuer - would: (i) the SEC's main DC office be strictly liable for branch office deficiencies; (ii) the SEC disgorge all of its "profits" connected (no matter how remotely) to the improper recording or the deficient internal controls; and (iii) would high-level SEC officials be accountable under "control person" theories for the books and records and internal control violations?

As readers of this blog know, all of the above "theories" are straight from recent SEC enforcement actions against issuers.

So next time an FCPA practitioner and his/her corporate client representative are seated across the table from an SEC enforcement official who asks, "how could this payment have not been recorded properly in subsidiary X's books and records, how could the issuer not put in place effective internal controls, how could those controls not be monitored and assessed, etc. etc." the most candid response just might be "I don't know, you tell me - such issues happen at the SEC as well."

One more thing, when enforcing the FCPA's books and records and internal control provisions against issuers, the SEC insists on remedial measures and wants to see evidence of those remedial measures being put into place "yesterday." An issuer comment, such as "this takes time," would likely fall on deaf ears.

Yet, here is what SEC Chairman Mary Schapiro had to say about the GAO report and its findings of various deficiencies: “some deficiencies are likely to be resolved during the first half of FY 2010, while others – which have been the result of long-term and growing constraints affecting our information technology and human resources – will take longer to fully resolve.” (p. 29). This statement was also repeated by Kristine Chadwick, SEC CFO and Associate Executive Director (p. 33).

Alas, time to come back to reality, the SEC is not an issuer, but a couple minutes in "hypothetical land" does provide some useful perspectives as to the SEC's enforcement of the FCPA's books and records and internal control provisions.

Monday, September 21, 2009

Books and Records and Internal Controls Compliance ... The Importance of FCPA Goggles

A reader recently commented that most companies know "what to do" when it comes to FCPA anti-bribery compliance training, but that when it comes to FCPA books and records and internal controls compliance training most people "scratch their heads."

Below, I offer some thoughts on books and records and internal controls compliance training, but by no means does this cover the entire landscape.

I think the reader is correct in that most companies do in fact focus compliance efforts (if they have pro-active compliance efforts - see here) on the FCPA's anti-bribery provisions. The FCPA's other prong - the books and records and internal control provisions are usually mentioned (if at all) in passing.

An explanation for why likely has to do with the statute itself.

The anti-bribery provisions have specific elements tied to things we can all generally understand such as - things of value, foreign official, and obtain or retain business - and companies can easily tailor compliance training to those elements, or it is probably more accurate to say, DOJ and SEC's interpretations of those elements.

In contrast, the FCPA's book and records and internal control provisions are rather generic and have key terms such as "reasonable detail," "accurately and fairly," "sufficient," "reasonable assurances, and "general or specific authorization."

Tailoring compliance training to such general concepts can be difficult. Moreover, the books and records, and internal control provisions apply to issuers in ALL instances, not just those instances in which the company is doing business or seeking business abroad. Thus, it may be more difficult to frame books and records and internal control issues to training, because the provisions apply to everything an issuer does.

Against this backdrop, what works best I think is to view FCPA compliance as not just a task that company lawyers and selected key positions from an anti-bribery perspective (i.e. sales, marketing, business development) need to be concerned with, but rather a task that internal audit and finance should also be concerned with and actively involved in as well.

This means that internal audit and finance personnel must be specifically trained to approach their specific job functions not only in a traditional way, but also with "FCPA goggles" on.

It is clear from recent FCPA enforcement actions that the SEC expects much more from non-legal personnel when it comes to FCPA compliance, including the ability to spot FCPA issues and display a high degree of (I'll call it) intellectual curiosity as to certain issues.

For instance, in the 2007 York matter, the SEC alleged in its civil complaint (see here at para 51) that (i) "York International's management had the ability to review or cause internal audit to review [the problematic contracts] and, had this been done, it would have been immediately apparant that the consultancy agreements were a sham; and (ii) it was "clear that local finance personnel did not provide an independent internal control function, but rather acquiesced in questionable practices and documentation without critical review."

Again, because the FCPA's books and records and internal control provisions are rather generic, I think a "best practice" (not only for issuers, but for any company) is to specifically train internal audit and finance personnel to view their job with "FCPA goggles" on.

This means that internal audit and finance personnel should:

(1) Understand the broad interpretations given to the anything of value, foreign official, and obtain or retain business elements of anti-bribery violation so that they clearly understand that conduct other than a "suitcase full of cash to a government official to get a government contract" is problematic. For instance,
excessive travel and marketing expenses, payment of scholarships, etc. can be things of value. Internal audit and finance personnel also need to understand that employees of state-owned or state-controlled companies are considered "foreign officials" by DOJ/SEC (even if that interpretation has not been tested or challenged). This means that things a company does to "wine and dine" its purely private customers can become problematic when state-owned or state-controlled customers receive the same treatment. In terms of state-owned or state-controlled customers, it is also a good idea for a company to maintain a roster of such entities so that heightened review will be triggered when any corporate personnel deals with such customers or prospective customers. Internal audit and finance personnel also need to understand that payments which result in a company securing a foreign license, permit, or certification can satisfy the "obtain or retain business" element of an anti-bribery violation on the theory that such payments help the company, in the general sense, obtain or retain business.

(2) Pay particular attention to employee reimbursement requests and think about FCPA issues in connection with these requests. For instance, if a specific sales and marketing employee is the designated "wine and dine" person, is there any heightened scrutiny of that individuals reimbursement requests?

(3) Be aware of the FCPA's third-party payment provisions and be able to spot (and follow-up on) the following issues relevant to engaging and supervising a foreign agent or representative: payments made to personal (rather than company) bank accounts; payments to off-shore bank accounts; payments which could be made in one lump sum but are split up to avoid detection; and payments made to an account in a country different than where the service provider is located. When utilizing third parties, commission payments are obviously a big FCPA risk. Thus, internal audit and finance personnel need to ask what steps the company has taken to assure itself that the commission payments are reasonable. Moreover, such personnel should specifically look for evidence that the third party actually provided legitimate value-added services before payment was made by the company.


(4) Figure out who within the company, the relevant business unit, etc. has the authority to authorize large payments and make sure those authorizations are scrutinized. Because of title, prestige and in some countries - gender - certain individuals are subjected to less oversight and scrutiny when it comes to authorizing payments. If any such trends or patterns emerge within a company as to this issue, internal audit and finance personnel must be diligent in understanding why.

(5)Pay particular attention to the following accounts (all of which, per recent FCPA enforcement actions, were used to conceal improper payments) - "additional assessments," "extra costs," "extraordinary expenses," "urgent processing," "urgent dispatch," "customs processing," "importation advances," . These accounts, and all other accounts described in a vague or ambiguous manner, should be subject to heightened scrutiny by internal audit and finance personnel.

Back to the original issue raised by the reader as to how best to offer FCPA books and records, and internal controls compliance training. Again, because the books and records and internal control provisions are so generic, I think the "best practice" is to couple such training with anti-bribery training and to make sure that internal audit and finance personnel have the FCPA tools necessary to properly execute their jobs.

Internal audit and finance personnel clearly have an FCPA compliance role to play, and the SEC is clearly expecting them to play that role. However, internal audit and finance personnel can only raise FCPA issues if they first know what FCPA issues to look for. Providing internal audit and finance personnel with a good pair of "FCPA goggles" is a good way to achieve books and records, and internal controls compliance.

Tuesday, August 4, 2009

FCPA Aches and "Payne"s

Helmerich & Payne Inc. ("H&P") is an international drilling contractor headquartered in Tulsa. It has land and offshore operations in South America. To operate in that region, H&P must import and export equipment and materials. According to the DOJ and SEC, therein lies the problem.

H&P recently settled a DOJ and SEC FCPA enforcement action based on the conduct of two wholly-owned second tier subsidiaries, Helmerich & Payne (Argentina) Drilling Company ("H&P Argentina") and Helmerich & Payne de Venezuela, C.A. ("H&P Venezuela").

Pursuant to a two-year DOJ non-prosecution agreement, H&P acknowledged responsibility for the conduct of H&P Argentina and H&P Venezuela in making various improper payments to officials of the Argentine and Venezuelan customs services. According to a DOJ release (see here), the payments "were made in order to import and export goods that were not within regulations, to import good that could not lawfully be imported, and to evade higher duties and taxes on the goods." Pursuant to the agreement, H&P will pay a $1 million penalty.

In a parallel action, H&P agreed to an SEC settlement under which it agreed to pay approximately $375,000. The SEC cease-and-desist order ("Order") (see here) finds that: (i) "H&P Argentina paid Argentine customs officials approximately $166,000 to permit the importation and exportation of equipment and materials without required certifications, to expedite the importation of equipment and materials, and to allow the importation of materials that could not imported under Argentine law; and (ii) "H&P Venezuela paid Venezuelan customs officials approximately 19,673 either to permit the importation and exportation of equipment and materials that were not in compliance with Venezuelan importation and exportation regulations or to secure a partial inspection, rather than a full inspection, of the goods being imported."

According to the Order, the payments were "falsely, or at least misleadingly" described as "additional assessments," "extra costs," "extraordinary expenses," "urgent processing," "urgent dispatch," or "customs processing." The SEC found that as a result of the payments, H&P avoided approximately $320,000 in expenses it would have otherwise incurred had it properly imported and exported the equipment and materials. The subsidiaries' financial results were included in H&P's filings with the SEC and, based on the above conduct, the SEC found that H&P violated the FCPA books and records and internal control provisions.

The Order is silent as to H&P's knowledge of or involvement in the above described payments.

No doubt H&P received an SEC cease and desist order (the least harsh SEC sanction) and a DOJ non-prosecution agreement because of its conduct upon learning of the payments. As described in the Order, during an FCPA training session, an employee voluntarily disclosed some potentially problematic payments, through a customs broker, in Argentina to customs officials. Thereafter, H&P hired FCPA counsel, conducted an internal investigation, and voluntarily reported the conduct at issue to the government.

According to H&P's Form 8-K filed on July 30, 2009 (see here), "[t]here are no criminal charges involved in the settlements and disciplinary action has been taken by the company with respect to certain employees involved in the matter, including in some cases, termination of employment." The 8-K also notes that both settlements "recognize the company's voluntary disclosure, cooperation with both agencies, and its proactive remedial efforts."