FCPA Compliance and Ethics Blog

August 21, 2015

Archie Bunker, Batgirl and the International Fight Against Corruption

Archie BunkerThis week saw the death of two notables from the television industry, Bud Yorkin and Yvonne Craig. According to his Obituary in the New York Times (NYT), Yorkin rose up the television industry ranks to eventually team with Norman Lear to produce one of the true “pioneering, provocative and singularly successful satirical series” in the history of television, All In The Family, introducing one of the most recognizable characters in all of TV – Archie Bunker. When I say he began at the bottom end of the business: it literally was that, as he began repairing TVs in New York City bars. All In The Family not only broke ground by discussing taboo subjects it also became “the first TV series to top the Nielsen ratings for five consecutive years.”

Yvonne Craig was known, according to her Obituary in the NYT, as the girl “who kept Gotham safe as Batgirl” whom she played in the 1960s TV series Batman. Craig was a classically trained ballerina who brought athleticism and “a scrappy girl-power element” to the series in its third and final season. However, I remember Craig as the green skinned slave girl in the “Whom The Gods Destroy” episode from the original Star Trek series. Her Obituary noted, “She performed a seductive, loose-limbed dance that seemed to nearly overwhelm William Shatner’s red-blooded Captain Kirk, while Leonard Nimoy’s Mr. Spock pronounced it “mildly interesting.””Batgirl

Interestingly both of these televisions stars inform today’s compliance issue. Yorkin for the way he and his partner Lear held up a mirror, through All In The Family, to address such issues as “racism, sexism, abortion, gay rights and the war in Vietnam, among other television taboos” and Craig, “who kept Gotham safe as Batgirl.” Of course I am referring to the devastating disaster that occurred last week in the Chinese city of Tianjin. A NYT article, entitled “Report Details Role of Political Connections in Tianjin Disaster”, reported that the death toll now stands at 114, with 674 injured and more than 17,000 homes damaged. An unknown number of persons are still missing.

Is anyone really surprised corruption was involved in the tragedy? Enforcement of anti-corruption laws, such as the Foreign Corrupt Practices Act (FCPA), the UK Bribery Act or even Chinese domestic anti-bribery laws, is not a game for corruption can kill. While most corruption leads to economic damage, there have been clear instances where corruption led to the loss of life. The 2013 massacre at the Narobi Westgate shopping mall was clearly a result of corruption in Kenya that allowed guns used in the attack to be illegally smuggled into the country through bribery.

Now it has been reported that corruption led to the disaster in Tianjin. The FCPA Blog, in a post entitled “Report: Tianjin warehouse owners used guanxi to land phony safety licenses”, wrote that “The owners of the warehouse in the port of Tianjin that exploded last week and killed more than 100 people obtained fraudulent safety licenses through their connections with fire and safety officials, China state media said.” The warehouse where the fire started and spread from was illegally holding certain lethal chemicals. The post also noted, “Ruihai International Logistics owned the warehouse. The main shareholders of the company are ex-Sinochem executive Yu Xuewei and Dong Shexuan, the son of a late police chief, VAO News reported.” The FCPA Blog went on to quote the VOA report for the following, “In an interview with the official Xinhua news agency, Dong and Yu admitted to using their connections, or guanxi, with local officials to obtain various fire safety, land, environmental and safety certifications.”

In addition to the illegally stored chemicals, it turns out there should not even have been a warehouse in that location in the first place. In another NYT article, entitled “Report Details Role of Political Connections in Tianjin Disaster”, Dan Levin reported the warehouse itself was not far enough back from the prescribed distance for residential housing. It seemed clear from the confession of the Mayor of Tianjin that he had been involved in the corruption when he stated, “I bear the unshirkable responsibility for this accident as head of the city.”

Another indicia of Chinese corruption had come into play as well. The executives of the company, which owned the warehouse and illegally stored chemicals, Ruihai, hid their ownership interest. The article reported they “had other people list their shares to avoid the appearance of a conflict of interest.”

In yet another NYT article, entitled “Fear of Toxic Air and Distrust of Government Follow Explosions in China” also by Dan Levin, it was noted “Later on Tuesday, China’s anticorruption agency announced on its website that Yang Dongliang, a former deputy mayor of Tianjin who became the head of the State Administration of Work Safety, was under investigation for “suspected violations of party discipline and the law,” a common euphemism for corruption. The Beijing Youth Daily reported, however, that Mr. Yang has been under investigation for a half-year, raising questions about why the case was announced now. Two other officials accused of taking bribes are also under investigation.”

The fallout from this tragedy continues. However, with such widespread corruption many Chinese feel they are not being told the truth and that their government is protecting corrupt officials. Levin said, “Public reflection on man-made tragedies is politically risky for the ruling Communist Party, according to David Bandurski, an editor of the China Media Project at the University of Hong Kong. “The party leadership is very aware that questions of responsibility in a disaster like this can very quickly move to fundamental issues of power and legitimacy,” he said, explaining that in an authoritarian system, “the buck stops with you.” Mr. Bandurski noted that censors had struggled to control the Tianjin narrative because some Chinese journalists had pushed ahead with their own reporting. “This is a very messy story, and for Chinese media, messy means opportunity,” he said.”

The Petrobras scandal in Brazil is bringing into question the government of President Dilma, it could forebode the same in China. Corruption in all its forms is no laughing matter and enforcing anti-corruption laws is no game. While prosecuting companies engaging in bribery and corruption through the hiring of sons and daughters of government officials to retain or garner new business may seem quite a long way from the Westgate Mall massacre or the massive loss of life in Tianjin; they are clearly on a unidimensional continuum.

Just as Archie Bunker put a light up to many of the social ills of his time, the more light you can shine on corruption, the more you can root it out of the shadows. But do not forget to send in Batgirl and those fighting for justice against corruption as well.TexasBarToday_TopTen_Badge_Large

This publication contains general information only and is based on the experiences and research of the author. The author is not, by means of this publication, rendering business, legal advice, or other professional advice or services. This publication is not a substitute for such legal advice or services, nor should it be used as a basis for any decision or action that may affect your business. Before making any decision or taking any action that may affect your business, you should consult a qualified legal advisor. The author, his affiliates, and related entities shall not be responsible for any loss sustained by any person or entity that relies on this publication. The Author gives his permission to link, post, distribute, or reference this article for any lawful purpose, provided attribution is made to the author. The author can be reached at tfox@tfoxlaw.com.

© Thomas R. Fox, 2015

August 20, 2015

BNY Mellon and Lessons Learned In Hiring Family Members – Part II

Lessons LearnedIn yesterday’s post I reviewed the Securities and Exchange Commission (SEC) Foreign Corrupt Practices Act (FCPA) enforcement action involving the Bank of New York Mellon Corporation (BNY Mellon) around its hiring of sons and nephews of foreign governmental officials to obtain or retain business from certain foreign Sovereign Wealth Funds. I discussed the underlying facts and penalties assessed against BNY Mellon as laid out in the SEC Cease and Desist Order (the “Order”). Today I want to provide some guidance on what this enforcement action may mean for companies going forward when hiring the sons and daughters or close family relatives of foreign government officials.

The first thing to remember is there is nothing in the FCPA which prohibits the hiring of a son, daughter or close family member of a foreign government official. What the FCPA does make illegal is an action where a company “or any officer, director, employee, or agent acting on behalf of such issuer, in order to obtain or retain business, from corruptly giving or authorizing the giving of, anything of value to any foreign official for the purposes of influencing the official or inducing the official to act in violation of his or her lawful duties, or to secure any improper advantage, or to induce a foreign official to use his influence with a foreign governmental instrumentality to influence any act or decision of such government or instrumentality.” [citation omitted]

The actions of BNY Mellon were clearly designed to not simply curry favor with the foreign governmental officials involved but also to either grow the business or help to retain what the company already had in place with the un-named foreign Sovereign Wealth Fund. At this point most companies have a written FCPA compliance program in place; consisting of policies and procedures. Note, this does not mean that the compliance program is effective because for a compliance program to be effective, a company must actually be doing compliance. Many FCPA enforcement actions occur because an exception was granted to a policy or procedure and either the reason for granting the exception was inappropriate or there was no documentation as to why the exception was granted. In the case of BNY Mellon, it was the latter.

BNY Mellon offered high value, high prestige summer internship programs for “undergraduates as well as a separate summer program for postgraduates actively pursuing a Master of Business Administration (MBA) or similar degree. Admission to the BNY Mellon postgraduate internship program was highly competitive and characterized by stringent hiring standards.” The main purpose of these internships was to give BNY Mellon an opportunity to evaluate the interns as potential permanent hires to the company. There was a designated track for nomination to the internship program and internal company evaluation prior to offering candidates an intern position. In other words, there were policies and procedures around the process but BNY Mellon did not follow them.

Hiring Process

The first Red Flag, which BNY Mellon seemingly ignored in this entire process, was that each of the candidates were recommended to the firm by foreign governmental officials who held control of business relations between Sovereign Wealth Funds and the bank. Their requests that their close family relations be hired by BNY Mellon was contra to the banks own process of selecting candidates for its internship program from a exclusive group of universities and colleges in the US and UK. The Order noted, “Successful applicants had to achieve a minimum grade point average, and had to advance through multiple rounds of interviews in addition to having relevant prior work experience and a demonstrated affinity for and interest in financial services work.”

None of these indicia were present in the hiring of the foreign governmental official’s relatives at issue. There was no evidence the candidates met any of BNY Mellon’s own internal criteria for consideration to the internship program. Indeed, as the Order stated, “as recent graduates not enrolled in any degree program, the Interns did not meet the basic entrance standard for a BNY Mellon postgraduate internship.” Finally, to top it off, all three were hired sight unseen and “BNY Mellon decided to hire the Interns before even meeting or interviewing them.” 

The Internships

But BNY Mellon’s violative conduct did not stop by simply hiring the three close family relatives for its internship program. The three persons got benefits far more than simply a regular internship program. BNY Mellon designed special “Bespoke” internship programs for the three interns. As requested by their fathers and uncle, the three interns received “customized work experiences” which “were not regular undergraduate or graduate summer internships at all, but customized one-of-a-kind training programs. The internships were valuable work experience, and the requesting officials derived significant personal value in being able to confer this benefit on their family members.”

The internships were abnormally long, lasting six months, which was twice the normal length. Additionally they were “rotational in nature, meaning that Interns A, B and C had the opportunity to work in a number of different BNY Mellon business units, enhancing the value of the work experience beyond that normally provided to BNY Mellon interns.”

The Costs

In addition to the exceptions granted in the hiring process and the internships themselves, BNY Mellon also paid out money and non-monetary benefits in a manner different to others in the internship program. The Order stated, “BNY Mellon determined, because Interns A and B had already graduated from college, that Interns A and B should be paid above the normal salary scale for BNY Mellon undergraduate interns but below the scale for postgraduate interns. Intern C was unpaid. BNY Mellon also coordinated obtaining visas for all three of the Interns so that they could travel from the Middle East to work in the countries in which they were placed. BNY Mellon paid the legal fees and filing costs related to the visas. As the BNY Mellon Asset Management employee responsible for arranging two of the three internships wrote in a contemporaneous e-mail, the internships constituted an “expensive favor” for the requesting foreign official.” Indeed the Order cited to an email from one BNY Mellon employee who wrote, “I am working on an expensive ‘favor’ for [Official X] – an internship for his son and cousin (don’t mention to him as this is not official).” Further, BNY Mellon knew the request and accommodation was unethical, if not illegal, as the same employee wrote in another email, ““[W]e have to be careful about this. This is more of a personal request . . . [Official X] doesn’t want

[the Middle Eastern Sovereign Wealth Fund] to know about it.” The same employee later directed his administrative assistant to refrain from sending email correspondence concerning Official X’s internship request “because it was a personal favor.”

Lessons Learned Going Forward

I must emphasize once again that there is nothing illegal around the hiring of a close family member of a foreign governmental official. It does however present a higher risk for indicia of bribery and corruption and violation of the FCPA. A higher FCPA risk means you need to evaluate that risk more closely and manage that risk accordingly.

The obvious starting point for any hiring of a close family member of a foreign governmental official is whether the candidate is qualified for the position. If they are not qualified it is ‘Full Stop’ at that point. In the case of BNY Mellon there was no evidence any of the candidates had the academic background, the academic credentials, leadership traits or intangible skills to meet the bank’s normal internship hiring criteria. As with any other anomaly granted in a company’s normal process, there must be a documented reason for the exception, review by appropriate authority of the exception and documentation as to why the exception was granted. None of these steps were present in the BNY Mellon matter. Put another way, if you are hiring a family member or close relative of a foreign government official for any reason other than merit, it had better be a darn good one and well-documented as to your decision-making calculus with appropriate senior management oversight.

But your risk management does not stop simply with the hiring process. If the foreign governmental official is the person who made the request for the hiring of the family member, this is a Red Flag not to be overlooked. Your analysis needs to be on the role of that foreign governmental official in awarding new business to your company or in retaining old business. If the foreign governmental official has direct or even strong indirect control over such business relation, this may present such a direct conflict of interest, this may be a risk that you cannot manage. A good rule of thumb here is whether there is full transparency in the hiring with the foreign government involved with your company. In the case of BNY Mellon, they did not want anyone in the Sovereign Wealth Fund to know BNY Mellon had hired the son or nephew. That is a clear sign transparency is lacking and someone, somewhere is engaging in unethical conduct, if not breaking the law.

Finally, if you do decide to move forward and hire the close family member, you need to assign that new hire to work not associated with the business relationship between your company and the foreign government involved. Just as in the lifecycle of third party management, managing the relationship after a contract is inked is in many ways the most critical element; the same is true in the employment relationship involving close family members of foreign government officials.

Ultimately, you need to have internal controls to ensure effective compliance going forward. You cannot have customer relationship managers making the calls on hiring which over-ride the Human Resources (HR) procedures. There must be not only HR review but also mechanisms to flag for compliance review such hires. Lastly, there needs to be sufficient senior management oversight because this is such a high-risk proposition.

I hope you have enjoyed and found this two-part series on the BNY Mellon FCPA enforcement action and the lessons learned from it useful. The SEC Order provides a clear road map to the Chief Compliance Officer (CCO), compliance practitioner, HR professional or anyone else who reads it on the steps you should take in the hiring of a close family member of a foreign government official with which you are doing business. It may take some additional effort than simply having your business unit employees make the call on who to award prestigious internships to in order to obtain or retain business but in the long run you will have a better run company for doing so. FCPA enforcement is not a game and by doing compliance will make your company a more accurtely operated  entity.

This publication contains general information only and is based on the experiences and research of the author. The author is not, by means of this publication, rendering business, legal advice, or other professional advice or services. This publication is not a substitute for such legal advice or services, nor should it be used as a basis for any decision or action that may affect your business. Before making any decision or taking any action that may affect your business, you should consult a qualified legal advisor. The author, his affiliates, and related entities shall not be responsible for any loss sustained by any person or entity that relies on this publication. The Author gives his permission to link, post, distribute, or reference this article for any lawful purpose, provided attribution is made to the author. The author can be reached at tfox@tfoxlaw.com.

© Thomas R. Fox, 2015

August 19, 2015

BNY Mellon Settles First Sons and Daughters (and Nephews) FCPA Hiring Matter – Part I

Prince and PrincessYesterday the Securities and Exchange Commission (SEC) announced a resolution with Bank of New York Mellon Corporation (BNY Mellon) for violations of the Foreign Corrupt Practices Act (FCPA). This was the first enforcement action around the now infamous Princesslings and Princelings investigations where US companies hired the sons and daughters of foreign government officials to curry favor and obtain or retain business.

While JPMorgan Chase has garnered the most attention around this issue, probably because of its notorious spreadsheet tracking of sons and daughters hires to develop business in China, there are multiple US companies under scrutiny for similar conduct. The FCPA Blog has reported that Credit Suisse, Goldman Sachs, Morgan Stanley, Citigroup, and UBS are all under investigation by the SEC for their hiring practices around the sons and daughters of foreign government officials. BNY Mellon has the honor of being the first company to reach resolution on this issue.

This is an important issue for many companies going forward and since this is the initial enforcement action on this issue, I am going to take a deep dive into the matter over the next couple of days. Today, I will discuss the facts of the case and tomorrow I will discuss not only the lessons to be learned from this FCPA enforcement action but also how the Chief Compliance Officer (CCO) or compliance practitioner can use those facts to graft a hiring program around the sons and daughters of foreign government officials which will not violate the FCPA.

In its Press Release, the SEC noted, “The Securities and Exchange Commission today announced that BNY Mellon has agreed to pay $14.8 million to settle charges that it violated the Foreign Corrupt Practices Act (FCPA) by providing valuable student internships to family members of foreign government officials affiliated with a Middle Eastern sovereign wealth fund.” Andrew J. Ceresney, Director of the SEC Enforcement Division, was quoted in the Press Release as stating, “The FCPA prohibits companies from improperly influencing foreign officials with ‘anything of value,’ and therefore cash payments, gifts, internships, or anything else used in corrupt attempts to win business can expose companies to an SEC enforcement action. BNY Mellon deserved significant sanction for providing valuable student internships to family members of foreign officials to influence their actions.” Kara Brockmeyer, Chief of the SEC Enforcement Division’s FCPA Unit, said, “Financial services providers face unique corruption risks when seeking to win business in international markets, and we will continue to scrutinize industries that have not been vigilant about complying with the FCPA.”

The Cease and Desist Order (Order) entered found that BNY Mellon violated the anti-bribery and internal controls provisions of the Securities Exchange Act of 1934.  BNY Mellon, “Without admitting or denying the findings, the company agreed to pay $8.3 million in disgorgement, $1.5 million in prejudgment interest, and a $5 million penalty. The SEC considered the company’s remedial acts and its cooperation with the investigation when determining a settlement.”

The underlying facts and BNY Mellon’s conduct as laid out in the Order provide some clear guidance for the CCO or compliance practitioner regarding what will be a violation of the FCPA in terms of hiring sons, daughters and close family relatives going forward. It should be noted that two of the hires were sons of foreign governmental officials and one was a nephew. However, the first important lesson under this enforcement action is around the parties involved. Although not identified by country, the foreign governmental entity involved was a Middle Eastern Sovereign Wealth Fund. If there was any question as to whether foreign sovereign wealth funds were covered under the FCPA, that answer is now clear, they are covered. All corporate actions should be cloaked with this knowledge going forward.

The Order also specified how the hiring of the relatives led directly to BNY Mellon obtaining and retaining business. One foreign government official, (Official X), “made a personal and discreet request that BNY Mellon provide internships to two of his relatives: his son, Intern A, and nephew, Intern B. As a Middle Eastern Sovereign Wealth Fund department head, Official X had authority over allocations of new assets to existing managers such as the Boutique, and was viewed within BNY Mellon as a “key decision maker” at the Middle Eastern Sovereign Wealth Fund. Official X later persistently inquired of BNY Mellon employees concerning the status of his internship request, asking whether and when BNY Mellon would deliver the internships. At one point, Official X said to his primary contact at BNY Mellon that the request represented an “opportunity” for BNY Mellon, and that the official could secure internships for his family members from a competitor of BNY Mellon if it did not satisfy his personal request.”

There were clear statements by the BNY Mellon official involved that hiring this son and nephew were being done to obtain or retain business. As reported in the Order:

  • BNY Mellon was “not in a position to reject the request from a commercial point of view” even though it was a “personal request” from Official X. The employee stated: “by not allowing the internships to take place, we potentially jeopardize our mandate with [the Middle Eastern Sovereign Wealth Fund].”
  • Another employee was quoted as saying, ““I want more money for this. I expect more for this. . . . We’re doing [Official X] a favor.”
  • Yet another employee was quoted as saying, “I am working on an expensive ‘favor’ for [Official X] – an internship for his son and cousin (don’t mention to him as this is not official).”
  • Finally, to demonstrate the nefarious nature of the arrangement and lack of transparency in the entire process, this final BNY Mellon employee said, ““[W]e have to be careful about this. This is more of a personal request . . . [Official X] doesn’t want [the Middle Eastern Sovereign Wealth Fund] to know about it.” The same employee later directed his administrative assistant to refrain from sending email correspondence concerning Official X’s internship request “because it was a personal favor.”

The second foreign government official, (Official Y), “asked through a subordinate European Office employee that BNY Mellon provide an internship to the official’s son, Intern C. As a senior official at the European Office, Official Y had authority to make decisions directly impacting BNY Mellon’s business. Internal BNY Mellon documents reflected Official Y’s importance in this regard, stating that Official Y was “crucial to both retaining and gaining new business” for BNY Mellon. One or more European Office employees acting on Official Y’s behalf later inquired repeatedly about the status and details of the internship, including during discussions of the transfer of European Office assets to BNY Mellon. At the time of Official Y’s initial request, a number of recent client service issues had threatened to weaken the relationship between BNY Mellon and the European Office.”

When it came to hiring Official Y’s son there were some equally damning communications at BNY Mellon that were featured in the Order.

  • The BNY Mellon sovereign wealth fund relationship manager said, “that granting Official Y’s request was likely to “influence any future decisions taken within [the Middle Eastern Sovereign Wealth Fund].”
  • The same person also worried aloud that if BNY Mellon did not hire the son, it “might well lose market share to a competitor as a result.”
  • He went on to write ““Its [sic] silly things like this that help influence who ends up with more assets / retaining dominant position.”
  • Finally, he noted that to accede to Official Y’s request was the “only way” to increase business share.

Added to all of this was that none of the three individuals met the BNY Mellon requirements for its internship program; they met neither the academic or professional requirement to obtain an internship. BNY Mellon not only waived its own hiring requirements, it did not even go through the pretense of meeting with them or interviewing them. Finally, these three individuals were provided with “bespoke internships were rotational in nature, meaning that Interns A, B and C had the opportunity to work in a number of different BNY Mellon business units, enhancing the value of the work experience beyond that normally provided to BNY Mellon interns.”

The penalty was also interesting. As set out in the order BNY Mellon agreed to the following penalty amount: “disgorgement of $8,300,000, prejudgment interest of $1,500,000 and a civil money penalty in the amount of $5,000,000, for a total payment of $14,800,000.” The SEC noted the cooperation efforts of the bank in stating, “Respondent acknowledges that the Commission is not imposing a civil penalty in excess of $5,000,000 based upon its cooperation in a Commission investigation.” Further, BNY Mellon engaged in extensive remediation. The Order stated, “Prior to the investigation by the Commission of the Interns, BNY Mellon had begun a process of enhancing its anti-corruption compliance program including: making changes to the Anti-Corruption Policy to explicitly address the hiring of government officials’ relatives; requiring that every application for a full-time hire or an internship be routed through a centralized HR application process; enhancing its Code of Conduct to require that every year each employee certifies that he or she is not responsible for hiring through a non-centralized channel; and requiring as part of a centralized application process that each applicant indicate whether she or a close personal associate is or has recently been a government official, and, if so, additional review by BNY Mellon’s anti-corruption office is mandated.”

Tomorrow I will look at lessons learned for the CCO and compliance practitioner and how you can avoid the missteps of BNY Mellon in your hiring program going forward.

This publication contains general information only and is based on the experiences and research of the author. The author is not, by means of this publication, rendering business, legal advice, or other professional advice or services. This publication is not a substitute for such legal advice or services, nor should it be used as a basis for any decision or action that may affect your business. Before making any decision or taking any action that may affect your business, you should consult a qualified legal advisor. The author, his affiliates, and related entities shall not be responsible for any loss sustained by any person or entity that relies on this publication. The Author gives his permission to link, post, distribute, or reference this article for any lawful purpose, provided attribution is made to the author. The author can be reached at tfox@tfoxlaw.com.

© Thomas R. Fox, 2015

August 17, 2015

OIG Compliance Guidance for Health Care Governing Boards

Edward ThomasOn the front page of the Saturday New York Times (NYT) was an obituary for Edward Thomas, who joined the Houston Police Department (HPD) in 1948 and finally retired in 2011 at the age of 90. As reported in the article, entitled “Edward Thomas, Policing Pioneer Who Wore a Burden Stoically, Dies at 95”, when Thomas joined the HPD, “he could not report for work through the front door. He could not drive a squad car, eat in the department cafeteria or arrest a white suspect. Walking his beat, he was once disciplined for talking to a white meter maid.” The reason was that Thomas was the first African-America to don a uniform for the HPD. Yet through stoic service and professional leadership, Thomas became the longest serving Houston police officer and had the HPD Police headquarters renamed in his honor earlier this year.

I thought about how Thomas led the HPD to the modern era in the area of race relations in the context of a report, issued in April, by the Office of Inspector General (OIG), Department of Health and Human Resources, entitled “Practical Guidance for Health Care Governing Boards on Compliance Oversight” (the OIG Guidance). Through this paper, the OIG provided compliance practitioners and health care company Board of Directors its views on the proper role of a Board in overseeing a corporate compliance function.

As an introduction, the OIG Guidance states that a Board must act in good faith around its obligations regarding compliance. This means that there must be both a corporation information and reporting system and that such reporting mechanisms provide appropriate information to a Board. It stated, “The existence of a corporate reporting system is a key compliance program element, which not only keeps the Board informed of the activities of the organization, but also enables an organization to evaluate and respond to issues of potentially illegal or otherwise inappropriate activity.” The OIG Guidance sets out four areas of Board oversight and review of a compliance function; “(1) roles of, and relationships between, the organization’s audit, compliance, and legal departments; (2) mechanism and process for issue-reporting within an organization; (3) approach to identifying regulatory risk; and (4) methods of encouraging enterprise-wide accountability for achievement of compliance goals and objectives.”

While noting that a corporate compliance function should promote the prevention, detection and remediation of compliance violations, the OIG Guidance goes on to state that an organization’s Chief Compliance Officer (CCO) “should neither be counsel for the provider, nor be subordinate in function or position to counsel or the legal department, in any manner.” Rather the Board must ensure the CCO and compliance function have resources to fulfill their assigned role within an organization and access to the Board. The Board should “evaluate and discuss how management works together to address risk, including the role of each in:

  1. identifying compliance risks,
  2. investigating compliance risks and avoiding duplication of effort,
  3. identifying and implementing appropriate corrective actions and decision-making, and
  4. communicating between the various functions throughout the process.”

A key component of Board oversight is through the flow of information. The OIG Guidance says, “The Board should set and enforce expectations for receiving particular types of compliance-related information from various members of management. The Board should receive regular reports regarding the organization’s risk mitigation and compliance efforts—separately and independently”. These reports can come to the Board via a variety of reporting mechanisms; regular Board meetings, special Executive Sessions where the Board meets with the CCO or compliance leadership outside of the presence of senior management and ad hoc communications from the CCO. All of these help create a “continuous expectation of open dialogue” which is paramount for proper Board oversight. Of course, if a serious compliance issue arises, it needs to be communicated directly, and in a timely manner, to the Board.

But in addition to setting the expectations for the flows of information, a Board must also set expectations for holding senior management accountable for areas such as compliance. This can be through the assessment of “individual, department, or facility-level performance or consistency in executing the compliance program” and using this information to payout or withhold discretionary based bonuses “based upon compliance and quality outcomes.” The OIG Guidance also notes, “Some companies have made participation in annual incentive programs contingent on satisfactorily meeting annual compliance goals. Others have instituted employee and executive compensation claw-back/recoupment provisions if compliance metrics are not met.” However the key component is that “Through a system of defined compliance goals and objectives against which performance may be measured and incentivized, organizations can effectively communicate the message that everyone is ultimately responsible for compliance.”

A Board also needs to have regular reports on the risks that any organization may face. This means keeping abreast of “relevant and emerging regulatory risks, the role and functioning of an organization’s compliance program in the face of those risks and the flow and elevation of reporting of potential issues and problems to senior management.” The OIG Guidance speaks to technological solutions when it says, “Some Boards use tools such as dashboards—containing key financial, operational and compliance indicators to assess risk, performance against budgets, strategic plans, policies and procedures, or other goals and objectives—in order to strike a balance between too much and too little information. For instance, Board quality committees can work with management to create the content of the dashboards with a goal of identifying and responding to risks and improving quality of care.”

Moreover, a Board should also mandate that the company’s compliance function have the proper tools in place to facilitate compliance reporting internally. It states, “Boards should also consider establishing a risk-based reporting system, in which those responsible for the compliance function provide reports to the Board when certain risk-based criteria are met. The Board should be assured that there are mechanisms in place to ensure timely reporting of suspected violations and to evaluate and implement remedial measures. These tools may also be used to track and identify trends in organizational performance against corrective action plans developed in response to compliance concerns.”

Ultimately a Board should drive home of the message of compliance as “a way of life” so that it permeates into the DNA of a health care organization. For if a Board can help drive compliance into the fabric of an organization, it will have done more than simply fulfill its legal obligations starting in the Caremark decision and going forward. The Board will have helped to make the entire organization more compliance-centric and when a Board can help to facilitate such a change in attitudes, it will have moved the organization several steps down the road of doing business in compliance with relevant laws and issues.

The OIG Guidance is an excellent review for not only compliance professionals and others in the health care industry but a good primer for Boards around their own duties under a best practices compliance program. The US Federal Sentencing Guidelines, the Ten Hallmarks of an Effective Compliance Program, the “OIG voluntary compliance program guidance documents, and OIG Corporate Integrity Agreements (CIAs) can be used as baseline assessment tools for Boards and management in determining what specific functions may be necessary to meet the requirements of an effective compliance program. The Guidelines “offer incentives to organizations to reduce and ultimately eliminate criminal conduct by providing a structural foundation from which an organization may self-police its own conduct through an effective compliance and ethics program.” The compliance program guidance documents were developed by OIG to encourage the development and use of internal controls to monitor adherence to applicable statutes, regulations, and program requirements.”

It is a document well worth your consideration.

This publication contains general information only and is based on the experiences and research of the author. The author is not, by means of this publication, rendering business, legal advice, or other professional advice or services. This publication is not a substitute for such legal advice or services, nor should it be used as a basis for any decision or action that may affect your business. Before making any decision or taking any action that may affect your business, you should consult a qualified legal advisor. The author, his affiliates, and related entities shall not be responsible for any loss sustained by any person or entity that relies on this publication. The Author gives his permission to link, post, distribute, or reference this article for any lawful purpose, provided attribution is made to the author. The author can be reached at tfox@tfoxlaw.com.

© Thomas R. Fox, 2015

August 13, 2015

Cymbeline – Doing Virtue and FCPA Compliance

CymbelineCommentators still level the hue and cry that it is somehow the fault of the Department of Justice (DOJ) and Securities and Exchange Commission (SEC) that companies continue to violate the Foreign Corrupt Practices Act (FCPA). Things would improve if only the DOJ and SEC would (1) prosecute companies more aggressively; (2) prosecute companies less aggressively; (3) make an example of ‘rogue’ employees who violate their corporate overseers pronouncements not to violate the law; (4) prosecute more corporate executives to ‘send a message’; (5) amend and clarify the FCPA because the concept of do not pay bribes is somehow too complicated for mere mortals to understand; (6) implement a compliance defense because apparently the DOJ does not consider that enough in any decision to prosecute; and/or (7) as The Donald desires, simply do away with the FCPA to restore the ability to pay a fair price for fair corruption.

I thought about all of these varied and contradictory reasons when considering one of Shakespeare’s most enigmatic plays, Cymbeline. In an article in the Wall Street Journal (WSJ) entitled “The Long, Painful Drama of Self-Knowledge”, Stephen Smith considered the character Posthumus who was thought of as virtuous yet, through the crush of the plot, has his virtuous image shattered. Smith poses the question of “Why is Posthumus such a poor leader of himself, and a danger to others?” He answers his own question by saying, “The play suggests that his lack of self-knowledge, along with the flattery of his culture, make him overconfident.” In other words, he was human.

I thought about this analysis in the context of the recent accounting and financial scandal that engulfed the Toshiba Corporation in Japan. For those who did not follow the news, Toshiba announced last month that it had overstated its profits from 2008-2014 by over $1 billion dollars. This was in the face of the company having been publicly recognized for its good governance standards and practices. In an article in the Financial Times (FT), entitled “Japan Inc left shaken by Toshiba scandal”, Kana Inagaki reported, “On paper, it had a structure that gave its external directors the authority to many top executives and an auditing committee to monitor the behaviour of the company’s leaders. It was lauded for its efforts. In 2013, the group was ranked ninth out of 120 publicly traded Japanese companies with good governance practices in a list compiled by the “Japan Corporate Governance Network.””

But it was all a sham as it turned out that chairman of the audit committee was in on the fraud in addition to a plethora of top executives. Kota Ezawa, an analyst at Citigroup was quoted in the piece that “Toshiba was lauded as the frontrunner in governance efforts but that was a misunderstanding. Its governance structure looked good but the execution was not.” Ezawa further stated, “We need to make sure that companies understand that having structures is not enough.” So even a company with $52bn in annual sales must have more than a paper program.

For those who want to point to some defect in the Japanese corporate character, reminding us of the Olympus scandal from 2011, where successive corporate executives covered up long running accounting fraud, Andrew Hill, also writing for the FT in an article entitled “The universal dangers shown by Toshiba’s failings”, says not to point that self-righteous finger quite so quickly. He reminds readers of WorldCom from earlier this century. Being from Houston, I would remind readers of Enron and its accounting fraud as well. Hill cites to the work of Professor Michael Jones to identify four main types of accounting fraud, (1) increasing income, (2) decreasing expenses, (3) increasing assets, and (4) decreasing liabilities. Hill further notes that one common failing in all of these examples is the failure of internal controls. A second key failing is the “Unwillingness to challenge authority, a trait attributed to employees at Toshiba and Olympus — and often given an “only in Japan” spin — is a recurring problem everywhere, from Royal Bank of Scotland under Fred Goodwin to Fifa under Sepp Blatter.”

Hill’s explanation of the how and why of these accounting scandals is as age old as the time of Cymbaline. He wrote, “The most important lesson from Toshiba is about the malign impact of top-down pressure to meet unrealistic targets. Toshiba’s ex-chief executive denies having given direct instructions to staff to inflate profits. But the investigating panel said he told executives to “use every possible measure to achieve profitability” and added that Toshiba’s corporate culture did “not allow employees to go against the will of their superiors”.”

The lessons that Hill finds in the Toshiba accounting scandal are equally applicable to FCPA compliance and enforcement. It is not the DOJ or SEC’s “fault” when companies do not comply with the FCPA. It is up to the companies to which the law applies to comply with it. Make no mistake; it is quite simple not to pay bribes. One only has to wake up and say “I am not paying a bribe today, no matter what the economic benefit is to me”. Yet for a company, it is not easy because you have to not only put the appropriate controls in place, but you have to do compliance by ensuring these controls are executed upon. That was the failing of Toshiba, it had the controls in place but it did not execute on them.

I think this speaks directly as to why FCPA violations continue to occur and be prosecuted. Hill ended his piece by noting, “When aggressive targets, irresistible management pressure and weak controls coincide, misconduct can spread quickly. Rival companies see the inflated numbers and strain to match them. To suggest such weaknesses are confined to one corporate or national culture is a first step into dangerous complacency.” As long as humans are involved with corporations and there are incentives in place for more and greater sales, you will always have the motivation to cut corners and pay bribes. That impulse can be brought on by a bump in salary, a nice bonus, a promotion or sometimes simply keeping your job. That is why a compliance program must be put in place and those controls must be effective.

In Cymbeline the protagonist Posthumus learns that one key component of virtue is prudence. Near the end of his article on Shakespeare’s play Smith writes, “In his story, we glimpse one goal of Shakespearean drama: to help forge just such a character – an integrated human person capable of leading himself and others to peace, with the help of virtue.” For FCPA compliance, as long as there are incentives in place to make money, there will be people who cut corners by paying bribes. Yet companies can temper this by putting an effective compliance program in place and actually doing compliance. Much like Posthumus learns in Cymbeline it is one’s actions which lead to being virtuous; for a company, it is doing compliance that leads to it being called ethical.

This publication contains general information only and is based on the experiences and research of the author. The author is not, by means of this publication, rendering business, legal advice, or other professional advice or services. This publication is not a substitute for such legal advice or services, nor should it be used as a basis for any decision or action that may affect your business. Before making any decision or taking any action that may affect your business, you should consult a qualified legal advisor. The author, his affiliates, and related entities shall not be responsible for any loss sustained by any person or entity that relies on this publication. The Author gives his permission to link, post, distribute, or reference this article for any lawful purpose, provided attribution is made to the author. The author can be reached at tfox@tfoxlaw.com.

© Thomas R. Fox, 2015

August 11, 2015

What Goes Downhill May Go Uphill in FCPA Compliance

Water Going Uphill 2Usually the question I am posed is how far down the chain must you go in your due diligence to ensure that your suppliers are in compliance with the Foreign Corrupt Practices Act (FCPA). I would pose that now, after the Petrobras scandal, a company may need to examine the flow in the other direction. I thought about this directional shift when I read an exhaustive report in the Sunday New York Times (NYT) on the Petrobras scandal, entitled “Brazil’s Great Oil Swindle, by David Segal. The article reviews the genesis of and details the ongoing nature of the Petrobras scandal.

While I have previously written about the other Brazilian companies that have been caught up in the scandal, such as Oderbrecht, Camargo Corrêa and UTC Engenharia, Segal’s article detailed a level of immersion in corruption that should concern every US Company subject to the FCPA and catch the eye of Department of Justice (DOJ) prosecutors handling FCPA cases. It appears that the companies that had direct contracts with Petrobras also colluded in the old-fashioned anti-trust sense, so that not only did they control all the subcontract work done on any Petrobras project but they would also demand bribes from the subcontractors which they then passed up the chain to Petrobras executives and eventually Brazilian politicians. If this scheme turns out to be true, it literally could explode potential FCPA exposure for any US Company doing business on any subcontract where Petrobras was the eventual beneficiary.

Segal reported, “according to prosecutors, these companies stopped competing and started to collaborate. They formed a cartel and decided, in advance, which of them would win a particular deal. A charade competition was orchestrated, and the anointed winner could charge vastly more than it would in a free market.” Further, “A document obtained by prosecutors laid out what it called the “rules of the game.” The trumped-up bidding process was labeled a “sports tournament”, with an assortment of rounds and a “trophy.” There was a no-sore-loser codicil, too: “The teams that participate in a round should honor the rules that have been agreed on, even when they are not the winner.”

But the corruption did not stop simply at these non-Petrobras entities. These companies would demand bribes from their subcontractors that they passed up the line to Petrobras. Segal wrote, “From 1 to 5 percent of the value of a given contract was diverted to those on the receiving end of the scheme, a group that included 50 politicians from six parties, according to prosecutors. Money from cartel members took a circuitous route to politicians’ pockets, passing through ghost corporations whose owners made bribes look like consulting fees.”

Think about all of this for a minute. What happens when everyone and every company associated with a National Oil Company (NOC) is in on the corruption? I thought about this question when I read an article in the Financial Times (FT) by Andres Schipani, entitled “We were terrorized by the drop in oil prices, where he discussed how the drop in world oil prices has negatively affected Venezuela more than any other top oil producing company. Part of the country’s trouble is the rampant corruption around its NOC PDVSA. Schipani quoted a former minster for the following, “The design of the political economy here only benefits the corrupt.” Moreover, the country is near the bottom of the Transparency International Corruption Perceptions Index (TI-CPI) coming in at 161st out of 175 countries listed.

Most Chief Compliance Officers (CCOs) and compliance practitioners had focused their third party risk management program around third parties, first on the sales side and then in the Supply Chain (SC). However now companies may well have to look at other relationships, particularly those where the company is a subcontractor involved in a country prone to corruption with a NOC or other key state owned enterprise. Last year the Wall Street Journal (WSJ) in an article entitled “Venezuelan Firm Is Probed In U.S.”, by José De Córdoba and Christopher M. Matthews, reported that a US company ProEnergy Services LLC (ProEnergy), a Missouri based engineering, procurement and construction company, sold turbines to Venezuelan company Derwick Associates de Venezuela SA (Derwick), who provided them to the Venezuelan national power company. The article reported that the DOJ’s “criminal fraud section are reviewing actions of Derwick and ProEnergy for possible violations of the Foreign Corrupt Practices Act”. Derwick was reported to have been “awarded hundreds of millions of dollars in contracts in little more than a year to build power plants in Venezuela, shortly before the country’s power grid began to sputter in 2009”. All of this with a commission rate paid by ProEnergy to Derwick of a reported 5%.

The Brazilian investigation poses far more dire consequences for any US Company that did business with the cartel of Brazilian companies that had locked up the Petrobras work. It means that you need to go back immediately and not only review the underlying due diligence which you did (probably none); then review the contracts with those entities; and, finally, cross-reference to see if there were any contract over-charges which were rebated back to the cartel members. If so, you may well have a serious problem on your hands as any unwarranted rebates, refunds, customer credits or anything else that could have been readily converted into cash to be used to fund a bribe.

This second part is one thing that challenges many compliance officers. The compliance function does not always have visibility into the transactions assigned to specific contracts or projects like your company might be engaged in for Petrobras in Brazil. However it also speaks to the need for transaction monitoring as not simply a cutting edge technique or even best practice but a required financial controls tool that is also applicable to compliance internal controls as well.

As Brazilian prosecutors expand ever outward from Petrobras, US companies subject to the FCPA and UK companies and others subject to the UK Bribery Act would do well to review everything around their Brazilian operations, contracts and dealings. The Petrobras scandal has shown two clear trends to-date. First is that we are far from the end of this scandal. Second, the prosecutors have been fearless so far in following the corruption trail wherever it may go. If they follow it to US companies, they could prosecute them on their own in Brazil for violation of domestic anti-bribery and anti-corruption laws or turn the evidence over to the DOJ. The thing to do now is to get out ahead of this all too certain waterfall.

This publication contains general information only and is based on the experiences and research of the author. The author is not, by means of this publication, rendering business, legal advice, or other professional advice or services. This publication is not a substitute for such legal advice or services, nor should it be used as a basis for any decision or action that may affect your business. Before making any decision or taking any action that may affect your business, you should consult a qualified legal advisor. The author, his affiliates, and related entities shall not be responsible for any loss sustained by any person or entity that relies on this publication. The Author gives his permission to link, post, distribute, or reference this article for any lawful purpose, provided attribution is made to the author. The author can be reached at tfox@tfoxlaw.com.

© Thomas R. Fox, 2015

August 7, 2015

Social Media Week Part V – Tools and Apps for the Compliance Practitioner

Social Media 5-IconsTo conclude this week’s posts, I wanted to list some of the more prevalent social media tools, explain what they are and how you might use them in a compliance program. (As usual I got carried away so this series will conclude on Monday of next week.) You need to remember that your compliance customer base are your employees. The younger the work force, the more tech savvy they will be and the more adapted to communicating through social media. According to Social Media Examiner’s 2015 Social Media Marketing Industry Report, the top two social networks for marketing are Facebook and LinkedIn. The three social media tools that hold the top spot for social media planning are LinkedIn, YouTube and Twitter. Marketers report that video streaming is becoming increasingly important tools for markets and that is currently encompassed in Meerkat and Periscope. Finally, I would add that Pinterest is another hot social media app.

Facebook

If you do not know what Facebook is at this point, you may have just transported down from a Borg Cube or perhaps you are a Vulcan looking for First Contact. This is the world’s most ubiquitous social media tool. It combines both personal and business applications. For the compliance practitioner, think about the business uses of Facebook. You can open a Facebook page for your compliance function and share an unlimited amount of information. Equally importantly, you can be responsive when employees comment on your posts, it allows you to interact with them and demonstrate that compliance is listening and responsive. The more regularly you post, the more opportunity you have for connecting with your employee base and building trust.

YouTube 

Much like Facebook, YouTube is one of the most ubiquitous social media tools around. It allows you to upload video and audio recordings for unlimited play. For the compliance practitioner, why not consider creating a YouTube channel for your company’s compliance program. You can put together full training on specific issues or you can create short videos. For an example of short videos, you can check out the training videos I have on my website Advanced Compliance Solutions. If there is any information that you wish to put into a visual format, YouTube is one of the best solutions available to you.

LinkedIn

LinkedIn is almost as ubiquitous as Facebook and YouTube. As with Facebook, you can set up a business site or even a private compliance group for your organization. Your employees are the best place to start adding followers, as they are not only your target audience but they are also your biggest advocates. You can encourage employees to add their compliance profile to their personal profiles. By doing so, they automatically become followers and can like, comment on, and share your company updates to help expand your viral reach. As with Facebook, LinkedIn provides you a platform to communicate with your employee base. It has a chat function that can be used to solicit feedback and comments going forward. You can also tie in with or ‘link to’ other groups and people that can facilitate not only creating but also expanding your culture of compliance.

Twitter

Earlier this week, I wrote about how you can use Twitter to capture information from the marketplace of ideas. However Twitter can also be used for communicating with your employee base. Tweets are publicly visible by default, but senders can restrict message delivery to just their followers. Users can tweet via the Twitter website, compatible external applications or by Short Message Service (SMS) available in certain countries. Retweeting is when users forward a tweet via Twitter. Both tweets and retweets can be tracked to see which ones are most popular. Finally, through the use of hashtags (#) users can group posts to Twitter together by topic.

I believe that Twitter is one of the most powerful tools (and completely underused tools) that is available to the compliance function. If employees follow their company’s name through a hashtag, they can see what trending topics other employees are discussing. Compliance practitioners can help lead that internal discussion through the same technique. Moreover, if the Chief Compliance Officer (CCO) or compliance function regularly monitors Twitter they can keep abreast of any communications and those can be used as a backup communication channel, in case the company hotline or other reporting system is not immediately available or even convenient.

Meerkat and Periscope

Two of the newest and perhaps coolest tools a CCO or compliance practitioner can utilize in the realm of social media are Meerkat and Periscope. Both tools allow you to tell a compliance story in real time, throughout your organization and beyond through the capture and broadcast of video, live through your smartphone. They are both live streaming apps that enable you to create a video and open the portal to anyone who wants to use it. Anybody in your Twitter community can click on that link and watch whatever you’re showing on your phone. The big piece is the mobile aspect. It is as simple as a basic tweet and hitting the “stream” button.

This is one of the more exciting new social media tools I see for the compliance practitioner. You could start a compliance campaign along the lines a campaign that the company Hootsuite initiated called “Follow the Sun” using Periscope. They decided to let their employees showcase what they called #HootsuiteLife. They gave access to different people in every company office around the globe. Throughout the day, it would “Follow the Sun,” and people in different offices would log into the Hootsuite account and walk around and show off their culture, interviewing their friends, etc. They talk about the importance of culture and now they are proving it. The number of inbound applications drastically increased after people got that sneak peek into their company. You could do the same for your worldwide compliance team.

You can live stream video training around the globe. Moreover, if you use either of these tools in conjunction with internal podcasting or other messaging you can create those all important “Compliance Reminders” which were so prominently mentioned in the Morgan Stanley Foreign Corrupt Practices Act (FCPA) Declination. The videos that you create with both of these tools can be saved and stored so a record of what you have created can be documented going forward.

Pinterest

According to Pinterest for Dummies, this tool is an online bulletin board, a visual take on the social bookmarking site, where the content shared is driven entirely by visuals. In fact, you cannot share something on Pinterest unless an image is involved. When you share something on Pinterest, each bookmark is called a pin. When you share someone else’s pin, it’s called a repin. Your group pins together by topic onto various boards, aka pinboards, in your profile. Each board mimics a real-life pinboard. You can share images you find online, or you can directly upload images. Using the “Pin It” button, you can share directly in your browser from any web page. You can also share your pins on Twitter and Facebook.

Although a relatively new social media tool, I find it to be one of the more interesting ones for use by the compliance function as it compliments many of the other tools I discussed above. You can set up your compliance account for your organization and pin items, lists, or other visual information that can be viewed and used by employees. In addition to the enumerated items, you can pin such things as a link, a website, graphics or other forms of information. If you think of it as an online bulletin board, you can consider all of the compliance information that you can post for your customer base and the interactions they can have back with you.

All of these tools can help you as CCO or a compliance practitioner to engage with your customer base. On Monday, I will conclude with some final thoughts on why the compliance function should use social media tools available to them.

Once again please remember that I am compiling a list of questions that you would like to be explored or answered on the use of social media in your compliance program. So if you have any questions email them to me, at tfox@tfoxlaw.com, and I will answer them within the next couple of weeks in my next Mailbag Episode on my podcast, the FCPA Compliance and Ethics Report.

 

This publication contains general information only and is based on the experiences and research of the author. The author is not, by means of this publication, rendering business, legal advice, or other professional advice or services. This publication is not a substitute for such legal advice or services, nor should it be used as a basis for any decision or action that may affect your business. Before making any decision or taking any action that may affect your business, you should consult a qualified legal advisor. The author, his affiliates, and related entities shall not be responsible for any loss sustained by any person or entity that relies on this publication. The Author gives his permission to link, post, distribute, or reference this article for any lawful purpose, provided attribution is made to the author. The author can be reached at tfox@tfoxlaw.com.

 

© Thomas R. Fox, 2015

August 4, 2015

Social Media Week Part II – Sharing in the Compliance Function

Social Media 2I continue my exploration of the use of social media as a tool of doing compliance by looking at some concepts around the sharing of information. In a recent podcast on Social Media Examiner, entitled “Sharing: The Art and Science of Social Sharing”, podcast host Michael Stelzner interviewed Bryan Kramer, a social strategist and author of the book “Shareology: How Sharing is Powering the Human Economy”. Kramer talked about several concepts that I found particularly useful for a Chief Compliance Officer (CCO) or compliance practitioner to think through when considering the use of a social media strategy in a best practices anti-corruption compliance program, under the Foreign Corrupt Practices Act (FCPA), UK Bribery Act or some other compliance regime.

Kramer’s book Shareology is a study of how, what, where, when and why people and brands share. For this book, Kramer conducted more than 250 interviews with executives, marketers and social media people, as well as professors of linguistics, psychology, sociology and so on, with the question “why people share” in mind.

The answer came down to one thing: connection. He found that “People all have the desire to reach out and connect with other people, whether it’s through sharing content and having someone reply back or by sharing other people’s content and helping them out.” From this research, Kramer identified six types of people who share:

  • Altruist: Someone who shares something specific about one topic all the time.
  • Careerist: Someone who wants to become a thought leader in their own industry, so they can see their career grow.
  • Hipster: Someone who likes to try things for the first time and share it faster than everyone else.
  • Boomerang: Someone who asks a question so they can receive a comment only to reply.
  • Connector: Someone who likes to connect one or more persons to each other.
  • Selective: This is the observer.

I find all of these categories to be relevant to a CCO or compliance practitioner in considering the use of social media in their compliance program. All of these can describe not only the reasons to use social media but they can also help you to identify who in your organization might be inclined to use social media and how it can facilitate your compliance program going forward.

The Altruist, Hipster and Careerist speak to how a CCO or compliance practitioner can be seen in getting out the message of compliance throughout your organization. Whichever category you might fall into, it is still about the message or content going forward. I find nothing negative in being seen as one or the other if your message is useful. Even if you are my age, there is nothing wrong with incorporating a little Hipster into your communication skills. As my daughter often reminds me, Dad you are so uncool that you are retro, but that is cool too. Applying that maxim to your compliance regime, if you can communicate in a manner your workforce sees as interesting or even hip, it may well help facilitation incorporation of that message into their corporate DNA.

I found the Boomerang, Connector and Selective categories as good ways to think about how your customer base in compliance (i.e. your employees) might well use social media tools to communicate with the compliance function. The use of social media is certainly a two-way street and you, as the compliance practitioner, need to be ready to accept those communications back to you. Indeed some comments by your customer base could be the most important interactions that you have with employees as their comments or questions could lead you to uncovering issues which may have arisen before they become Code of Conduct or FCPA violations. More importantly, it could allow you to introduce a proscriptive solution which moves your program beyond even the prevent phase.

Kramer also has some insights about the substance of your social media message. Adapting his insights to the compliance field, I found a key message to be that the problem is that companies do not write the way they speak, and don’t speak the language of their employee base. In many ways, compliance is a brand and Kramer believes that “brands and the people representing those brands need to change their language. If they focus on the title and the quality of the content, among other things, it’ll resonate more with their audience.” He also advocates using the social media tools and apps available to you. He specifically mentions Meerkat and Periscope, Snapchat, memes and/or videos to raise the value of the content. He was quoted as saying, “If you have a blog and there are no visuals, you might as well shut it down.”

It would seem the thesis of Kramer’s work is that sharing is a primary method to communicate and connect. In any far-flung international corporation this is always a challenge, particularly for discipline which can be viewed as home office overhead at best; the Land of No populated by Dr. No at worst. Kramer says that you should work to hone your message through social media. Part of this is based on experimenting on what message to send and how to send it. Yet another aspect was based upon the Wave (of all things) where he discussed its development and coming to fruition in the early 1980s. It took some time for it to become popular but once it was communicated to enough disparate communications, it took off, literally. Kramer noted, “It’s the same thing with social media. On social media, we think something will go viral because the art is beautiful or the science is full of deep analytics, but at the end of the day it really takes time to build the community.”

This means that you will need to work to hone your message but also continue to plug away to send that message out. I think the Morgan Stanley Declination will always be instructional as one of the stated reasons the Department of Justice (DOJ) did not prosecute the company as they sent out 35 compliance reminders to its workforce, over 7 years. Social media can be used in the same cost effective way, to not only get the message of compliance out but also to receive information and communications back from your customer base, the company employees.

Once again please remember that I am compiling a list of questions that you would like to be explored or answered on the use of social media in your compliance program. So if you have any questions email them to me, at tfox@tfoxlaw.com, and I will answer them within the next couple of weeks in my next Mailbag Episode on my podcast, The FCPA Compliance and Ethics Report.

This publication contains general information only and is based on the experiences and research of the author. The author is not, by means of this publication, rendering business, legal advice, or other professional advice or services. This publication is not a substitute for such legal advice or services, nor should it be used as a basis for any decision or action that may affect your business. Before making any decision or taking any action that may affect your business, you should consult a qualified legal advisor. The author, his affiliates, and related entities shall not be responsible for any loss sustained by any person or entity that relies on this publication. The Author gives his permission to link, post, distribute, or reference this article for any lawful purpose, provided attribution is made to the author. The author can be reached at tfox@tfoxlaw.com.

© Thomas R. Fox, 2015

July 21, 2015

Hemingway and Trust and Respect for Compliance Leadership

HemingwayOn this day in 1899, Ernest Hemingway was born. To me, he was the greatest Man of Letters the US has produced. Probably like most of you all, I was introduced to Hemingway in high school through The Son Also Rises. It remains my favorite of his works but I have enjoyed many more of his novels, short stories and non-fiction work. I particularly enjoyed his Nick Adams short stories as I found them crisply written and with a conciseness of language that is not often found today, or perhaps in any other time. Hemingway was awarded the Pulitzer Prize in 1953 and the Nobel Prize for Literature in 1954. He died via suicide in 1962.

I thought about Hemingway and his writing style when reading the most recent Corner Office column by Adam Bryant in the New York Times (NYT), entitled “To Work Here, Win the ‘Nice’ Vote”, where he profiled Peter Miller, the Chief Executive Officer (CEO) of Optinose, a pharmaceutical company. Miller has some interesting leadership concepts that are applicable to the position of Chief Compliance Officer (CCO) 2.0 and how a CCO 2.0 could use influence to lead, not only in the compliance function but also across an organization.

Miller talked about one thing you rarely hear in the corporate world, which is to be nice. He garnered this concept because as a “young sales manager at Procter & Gamble. I had five salespeople working for me, and one of the guys was 55 and another guy was 48. They were really successful salespeople, so I realized that I couldn’t teach these guys anything about selling. Since I couldn’t teach them anything, I tried to cultivate trust and respect by working really hard at figuring out how I could help them in a meaningful way.”

Yet this apparent inability to lead in precisely the area he was tasked in leading led Miller to formulate “a very important core value of mine, which is that you can and should try to create friends at your company.” But more than simply becoming friends, Miller came to the understanding that underlying the friendship “is this concept of trust and respect. When you get that as a team, that’s when great things happen. And that comes from creating a culture of openness, of authenticity, of being willing to have fearless conversations. It’s about being yourself, not being afraid to say what’s on your mind.”

As a CCO, you need to be able to have that type of conversation with those both up and down your chain of command. Certainly it is always beneficial to have type of relationship with your team that allows the full flow of communication. Miller said, “Think about how people are with their best friends. You want them to succeed. And sometimes that means having really hard conversations. If that’s what’s motivating you — and you’re really trying to help everybody around you in a company as if they were great friends of yours — that’s really powerful.”

I was interested in using some of Miller’s insights in the managing up role for any CCO. You have to be able to have some very frank conversations with your CEO and Board members about your compliance program and any issues that may arise under it. As CCO if you “cultivate trust and respect by working really hard at figuring out how I could help them in a meaningful way” as Miller used with his more senior sales team members, it should certainly help you going forward when you have to manage up your chain.

I also thought about this somewhat enlightened approach as contrasted with another style that I read about in a recent On Work column by Lucy Kellaway in the Financial Times (FT) entitled, “Wrong skillset excuse masks coup at the top of Barclays, where she discussed the recent termination of Antony Jenkins from Barclays Bank. The newly installed chairman of the company’s Board, John McFarlane, who simultaneously promoted himself to CEO, Jenkins former position, fired Jenkins. The reason Jenkins was fired; he no longer had the right “set of skills” for the organization. Chairman McFarlane explained to Kellaway that there were four skills going forward which (apparently) were lacking in Jenkins: “a) strategic vision; b) charisma; c) the ability to put plans in place that deliver shareholder value; and d) ability to ensure results were delivered.” Ironically, Kellaway noted that lawyers for Kleiner Perkins had said that Ellen Pao “was an employee who never had a skillset.”

Kellaway noted the obvious when she wrote “To invoke skillsets in hiring is not only ugly, but dangerous. Find the right person to run a very big bank is very hard, and having a list of skills that you are matching an applicant against is not necessarily the best way of going about it.” More ominously, she noted that the head of such bank would have to be able to reign in the traders and investment banker types who brought Barclays its unwanted regulatory scrutiny. More critically from the compliance perspective, I think it says much more about Chairman McFarlane that he did not say anything about a new CEO running the business ethically, in compliance or in any other manner which could help to prevent Barclays from another very large fine or penalty from the regulators.

McFarlane’s dictum is one that will certainly be noted by regulators on both sides of the Atlantic going forward. After the disastrous run by former Barclays’ head Bob Diamond, the bank was moving in the direction of regulatory compliance while securing the profits demanded by shareholders. However, McFarlane’s sacking of Jenkins could well derail the bank’s focus on ethics and compliance and engender the former attitude which led to the bank’s fine in the LIBOR scandal.

Unlike Peter Miller at Optinose, it does not appear that Chairman McFarlane appreciates the trust and respect style of leadership. I fear things may well turn out badly for Barclay’s yet again with the newly found emphasis on profits, profits and profits.TexasBarToday_TopTen_Badge_Large

This publication contains general information only and is based on the experiences and research of the author. The author is not, by means of this publication, rendering business, legal advice, or other professional advice or services. This publication is not a substitute for such legal advice or services, nor should it be used as a basis for any decision or action that may affect your business. Before making any decision or taking any action that may affect your business, you should consult a qualified legal advisor. The author, his affiliates, and related entities shall not be responsible for any loss sustained by any person or entity that relies on this publication. The Author gives his permission to link, post, distribute, or reference this article for any lawful purpose, provided attribution is made to the author. The author can be reached at tfox@tfoxlaw.com.

© Thomas R. Fox, 2015

July 17, 2015

Great Structures Week V – The Tacoma Narrow Bridge Failure and Preventing Failure in Your Compliance Program

Tacoma Narrows BridgeI conclude my Great Structures Week with a focus on structural engineering failures: suspension bridges and the challenges of wind in their construction and maintenance. I am drawing these posts from The Great Courses offering, entitled “Understanding the World’s Greatest Structures: Science and Innovation from Antiquity to Modernity”, taught by Professor Stephen Ressler. In his chapter on suspension bridges he notes that the “Tacoma Narrows Bridge was the third longest span in the world when it opened to the world, this month of July in 1940.” Yet it collapsed only four months later, in one of the most famous visual images of a bridge’s collapsing. This is due to the “inherent flexibility of cable as a structural form”. A bridge can move in longitudinal vibration, that is up and down and in torsion, where it twists from side-to-side.

Most people recognize unstiffened suspension bridges as old as man and engineering itself. It was not until the 1820s that serious study was brought to bear on the issue of wind-related collapse of suspension bridges. The initial solution was to simply use more weight to reinforce the span. However, while that solution did bring some stability, it reinforced damage as the structure became a textbook example of Newton’s Second Law of Motion, which states that the acceleration of an object is dependent upon two variables – the net force acting upon the object and the mass of the object; meaning that once a heavy weight is in motion, it is more resistant to deceleration.

Yet it was scientific methodology that led to the disaster with the Tacoma Narrows Bridge. An engineer named Leon Moisseiff had developed a theory that long spanned suspension bridges were heavy enough that they did not require stiffening trusses because “their mass stabilized them against wind-induced vibrations.” However this theory failed to take into account how air flows around a bridge and the “dynamic response of the structural system.” Ressler concludes this section by stating, “this case has become a classic symbol of the dangers of arrogance born of overconfidence in science-based design methods, and belt-and-suspenders engineering has made a bit of a comeback.”

I thought about the catastrophic failure of the Tacoma Narrows Bridge in the context of one of the greatest risks in Foreign Corrupt Practices Act (FCPA) compliance; that being third parties. Many non-compliance corporate employees assume that if a third party passes due diligence muster; they are in the clear. After all, you cannot stop a third party from making a bribe or other corrupt payment. Fortunately the Department of Justice (DOJ) does not take such a myopic view as many business types. Under the FCPA, a company is responsible for the actions of its third party representatives.

The real work around your third party compliance program begins after the contract is signed and it is in the management of the third party relationship. While the FCPA Guidance itself only provides that “companies should undertake some form of ongoing monitoring of third-party relationships”. Diana Lutz, writing in the White Paper by The Steele Foundation entitled “Global anti-corruption and anti-bribery program best practices”, said, “As an additional means of prevention and detection of wrongdoing, an experienced compliance and audit team must be actively engaged in home office and field activities to ensure that financial controls and policy provisions are routinely complied with and that remedial measures for violations or gaps are tracked, implemented and rechecked.”

Carol Switzer, writing in the Compliance Week magazine, set out a five-step process for managing corruption risks, which I have adapted for third parties.

  1. Screen – Monitor third party records against trusted data sources for red flags.
  2. Identify – Establish helplines and other open channels for reporting of issues and asking compliance related questions by third parties.
  3. Investigate – Use appropriately qualified investigative teams to obtain and assess information about suspected violations.
  4. Analyze – Evaluate data to determine “concerns and potential problems” by using data analytics, tools and reporting.
  5. Audit – Finally, your company should have regular internal audit reviews and inspections of the third party’s anti-corruption program; including testing and assessment of internal controls to determine if enhancement or modification is necessary.

Additionally there several different functions in a company that play a role in the ongoing monitoring of the third party. While there is overlap, I believe that each role fulfills a critical function in any best practices compliance program. 

Relationship Manager

There should be a Relationship Manager for every third party which your company does business. The Relationship Manager should be a business unit employee who is responsible for monitoring, maintaining and continuously evaluating the relationship between your company and the third party.

Compliance Professional

Just as a company needs a subject matter expert (SME) in anti-bribery compliance to be able to work with the business folks and answer the usual questions that come up in the day-to-day routine of doing business internationally, third parties also need such access. A third party may not be large enough to have its own compliance staff so I advocate a company providing such a dedicated resource to third parties. This role can also include anti-corruption training for the third party, either through onsite or remote mechanisms. The compliance practitioner should work closely with the relationship manager to provide advice, training and communications to the third party. 

Oversight Committee

A company can have an Oversight Committee review documents relating to the full panoply of a third party’s relationship with the company. It can be a formal structure or some other type of group but the key is to have the senior management put a ‘second set of eyes’ on any third parties who might represent a company in the sales side. In addition to the basic concept of process validation of your management of third parties, as third parties are recognized as the highest risk in FCPA or Bribery Act compliance, this is a manner to deliver additional management of that risk.

After the commercial relationship has begun the Oversight Committee should monitor the third party relationship on no less than an annual basis. This annual audit should include a review of remedial due diligence investigations and evaluation of any new or supplement risk associated with any negative information discovered from a review of financial audit reports on the third party. The Oversight Committee should review any reports of any material breach of contract including any breach of the requirements of the Company Code of Ethics and Compliance. In addition to the above remedial review, the Oversight Committee should review all payments requested by the third party to assure such payment is within the company guidelines and is warranted by the contractual relationship with the third party. Lastly, the Oversight Committee should review any request to provide the third party any type of non-monetary compensation and, as appropriate, approve such requests.

Audit

A key tool in managing the relationship with a third party post-contract is auditing the relationship. I hope that you will have secured audit rights, as that is an important clause in any compliance terms and conditions. Your audit should be a systematic, independent and documented process for obtaining evidence and evaluating it objectively to determine the extent to which your compliance terms and conditions are followed.

Perhaps now you will understand why I say that managing the relationship of your third party’s is where the real work of your FCPA compliance program comes to the fore. It also demonstrates a key difference in having a paper compliance program and doing compliance. Having a paper compliance program is simple but doing compliance is not always easy; you have to work at it to maintain an effective program.

I hope that you have enjoyed this week’s offering based around some of the world’s greatest structures, their engineering concepts and innovations and how they all related to a best practices compliance program. I am a huge fan of The Great Courses offerings and if you are interested in learning in a great many areas it is one of the best resources available to you. For a more detailed discussion of how you can develop and implement a best practices anti-corruption compliance program, I hope you will check my book Doing Compliance: Design, Create, and Implement an Effective Anti-Corruption Compliance Program, which is available through Compliance Week. You can review the book and obtain a copy by clicking here.

For a dramatic video of the collapse of the Tacoma Narrows Bridge on YouTube, click here.

This publication contains general information only and is based on the experiences and research of the author. The author is not, by means of this publication, rendering business, legal advice, or other professional advice or services. This publication is not a substitute for such legal advice or services, nor should it be used as a basis for any decision or action that may affect your business. Before making any decision or taking any action that may affect your business, you should consult a qualified legal advisor. The author, his affiliates, and related entities shall not be responsible for any loss sustained by any person or entity that relies on this publication. The Author gives his permission to link, post, distribute, or reference this article for any lawful purpose, provided attribution is made to the author. The author can be reached at tfox@tfoxlaw.com.

© Thomas R. Fox, 2015

Next Page »

Blog at WordPress.com.