Categories
Blog

The NBA/Clippers Investigation: Part 3 – Paper Compliance Is Not an Internal Control: Substance, Procurement, and the Audit Trail

The Clippers investigation shows why contracts, approvals, and carefully drafted emails cannot substitute for controls that test economic reality. In Part 3 of a five-part series, we explore why and how a transaction can have a contract, an approval, an invoice, and an email trail and still pose a serious compliance problem. Documentation proves that a process occurred. It does not prove that the process was legitimate.

That distinction sits at the center of the investigation into the LA Clippers and Kawhi Leonard. The independent investigators’ report (Wachtell Report) concluded that the Clippers initiated and facilitated endorsement arrangements between Leonard and four companies doing business with the team, induced those arrangements by offering business to the companies, paid impermissible personal expenses, and failed to meet improper demands made on Leonard’s behalf.

The alleged conduct crossed organizational boundaries. It touched business operations, basketball operations, procurement, sponsorships, consulting arrangements, accounts payable, expenses, legal review, and executive management. That makes this an internal controls case.

The Difference Between Evidence and Control

One of the report’s most important findings concerned introduction emails sent by Clippers President of Business Operations Gillian Zucker. The emails were written as if Boingo, Daktronics, Lockton, and later Aspiration had requested introductions to Leonard’s representatives. NBA rules permitted a narrow response when a commercial partner initiated such a request. They did not permit the team to create the opportunity for the player. The investigators concluded that the emails did not reflect the true sequence of events and, in Aspiration’s case, were created after deal development was already underway.

This is a classic paper-compliance problem. The communication used the language of the rule without satisfying its substance. A control cannot merely ask whether an introduction email contains the approved wording. It must test who initiated the contact, what discussions preceded the email, who proposed the economics, and whether team personnel remained involved afterward. Checklists confirm the form. Effective controls challenge reality.

Fragmented Transactions Hid a Common Purpose

The Wachtell Report described multiple agreements that could have appeared unrelated in separate systems. Vendors entered consulting or services agreements with the Clippers while also entering endorsement agreements with Leonard. Aspiration had sponsorship, sustainability, investment, forum, and player-endorsement relationships involving overlapping parties.

Investigators connected those transactions through timing, matching amounts, communications, and business leverage. Two companies reportedly received $10 million in consulting payments before entering endorsement agreements with Leonard. A third received a $2 million consulting payment one day after making its first payment to him.

The Forum agreement initially contemplated $7 million in annual business for Aspiration. That figure matched the annual cash component of Leonard’s endorsement agreement. Investigators further reported that the underlying carbon analysis did not generate the $28 million budget. Instead, the consultant said the Clippers supplied that budget.

The control failure was fragmentation. Procurement reviewed one agreement, marketing another, finance a payment, and business leaders the broader relationship. No control appears to have aggregated the transactions and asked whether one funded, induced, or conditioned another.

The DOJ’s Evaluation of Corporate Compliance Programs (ECCP) tells prosecutors to examine how misconduct was funded, including purchase orders and reimbursements (How was the misconduct in question funded (e.g., purchase orders, employee reimbursements, discounts, petty cash?); what controls could have prevented access to those funds (What controls failed?); whether vendor-selection procedures were followed (If vendors were involved in the misconduct, what was the process for vendor selection and did the vendor undergo that process?); and whether contract terms, payment terms, performance, and compensation were appropriate. Those are precisely the questions an organization should ask before enforcement authorities arrive.

Control Environment

The control environment begins with leadership and accountability. According to the report, the most senior business and basketball executives participated in or knew about key parts of the conduct. Investigators concluded that Ballmer failed to create conditions in which the organization followed rules it had previously violated. When senior leaders create the risk, lower-level approvals are unlikely to function as meaningful controls. Employees may view an executive request as authorization to proceed, even when the transaction presents obvious concerns.

Risk Assessment

The Clippers had a prior circumvention violation and were investigated over Leonard’s free-agency negotiations. The NBA had then provided specific training and imposed a mandatory reporting obligation. That history should have produced a targeted risk assessment covering player representatives, sponsor introductions, endorsement arrangements, personal expenses, vendor spend-back programs, and benefits flowing through third parties. Prior misconduct is not simply history. It is risk data.

Here, the ECCP asked some direct questions, including, “Were there prior opportunities to detect the misconduct in question, such as audit reports identifying relevant control failures or allegations, complaints, or investigations?” Additionally, it notes that critical factors in evaluating any program include whether the program is adequately designed to maximize effectiveness in preventing and detecting employee wrongdoing and whether corporate management enforces the program or tacitly encourages or permits employees to engage in misconduct.

Control Activities

The Wachtell Report suggests potential gaps in segregation of duties, conflict review, procurement approval, contract benchmarking, expense reimbursement, and related-transaction analysis. High-risk transactions should require independent approval outside the requesting executive’s chain of command. Controls should compare compensation with deliverables, confirm actual performance, flag advance payments, and identify common counterparties across procurement and non-procurement systems.

Information and Communication

The organization reportedly had information that should have triggered escalation: demands for $10 million in annual off-court income, unusual endorsement economics, concerns from Aspiration executives, internal descriptions of a Forum deal as “shady,” and explicit threats connecting the Forum and Leonard agreements. Indeed, Uncle Dennis’s presence alone was enough of a red flag based on his prior conduct. The issue was not the absence of information. It was the failure to move that information to a function with the independence and authority to act.

Monitoring

Hundreds of personal expenses were reportedly paid without the required deduction or reimbursement. Multiple vendors signed unusual endorsement arrangements, with minimal public activation or performance. These were recurring patterns, not one-time exceptions. Monitoring should identify patterns across time. If a control repeatedly approves exceptions without examining their cumulative effect, it is not monitoring risk. It is normalizing it.

Designing Controls for Substance

An effective control architecture should include three layers. Preventive controls should require documented business rationale, competitive sourcing, conflict disclosures, independent approval, clear deliverables, market benchmarking, and legal and compliance review before committing funds.

Detective controls should compare related transactions, test payment timing, examine overrides, confirm performance, and monitor expense exceptions. They should search for patterns across legal entities and business functions. Responsive controls should define who receives red flags, when compliance can stop payment, when issues reach the audit committee, and how remediation is tracked to completion. The most important design principle is independence. The DOJ asks whether compliance has adequate authority, stature, resources, and direct access to the board. (Where within the company is the compliance function housed (e.g., within the legal department, under a business function, or as an independent function reporting to the CEO and/or board?)

If executives can bypass or overrule the control function without documented challenge, the program is not empowered.

Practical Takeaways

Compliance, audit, and risk leaders should take the following actions:

  • Inventory all systems containing vendor, contract, payment, expense, sponsorship, and conflict information.
  • Build monitoring systems that identify common parties and beneficiaries across those systems.
  • Require proof of services and measurable deliverables before releasing significant payments.
  • Review advance payments, matching amounts, compressed timelines, and executive overrides as elevated-risk indicators.
  • Treat prior violations and mandatory reporting duties as subjects for recurring control testing.
  • Give internal audit authority to examine commercial substance, not merely procedural completion.
  • Report control failures involving senior management directly to an independent board committee.

The Clippers salary cap circumvention demonstrates that an audit trail can document a failure as easily as it documents compliance. The question is whether the organization has controls that can interpret what the records mean.

In tomorrow’s blog post, we will turn from detection to accountability and examine how cooperation, credibility, seniority, prior misconduct, and supervisory failure should shape consequence management.

Categories
Blog

The 2024 ECCP: Complying with the 2024 ECCP on Whistleblowers

The Department of Justice (DOJ), in its 2024 Update, has explicitly directed companies to ensure they have robust processes in place to identify, manage, and mitigate emerging risks related to new technologies, including AI. As compliance professionals, we are responsible for safeguarding the integrity of our organizations and fostering a culture where ethical behavior is the norm, not the exception. The 2024 Update to the Evaluation of Corporate Compliance Programs provides us with critical insights into how we can enhance the effectiveness of our compliance programs, particularly regarding reporting mechanisms and whistleblower protection. These elements are the bedrock of a robust compliance culture, and the update offers a clear roadmap for their implementation and improvement.

The DOJ posed two sets of queries for compliance professionals. They are found in Section I, entitled “Is the Corporation’s Compliance Program Well Designed?” A prosecutor could ask a company or compliance professional going through an investigation in the following series of questions.

Effectiveness of the Reporting Mechanism

  • Does the company have an anonymous reporting mechanism, and if not, why not?
  • How is the reporting mechanism publicized to the company’s employees and other third parties? Has it been used?
  • Does the company test whether employees know the hotline and feel comfortable using it?
  • Does the company encourage and incentivize reporting of potential misconduct or violations of company policy? Conversely, does it use practices that tend to chill such reporting?
  • How does the company assess employees’ willingness to report? How has the company assessed the seriousness of the allegations it received?
  • Has the compliance function had full access to reporting and investigative information?

Commitment to Whistleblower Protection and Anti-Retaliation

  • Does the company have an anti-retaliation policy?
  • Does the company train employees on internal and external anti-retaliation policies and whistleblower protection laws?
  • To the extent that the company disciplines employees involved in misconduct, are employees who reported internally treated differently than others involved in misconduct who did not?
  • Does the company train employees on internal reporting systems, external whistleblower programs, and regulatory regimes?

As compliance professionals, we are charged with safeguarding the integrity of our organizations and fostering a culture where ethical behavior is the norm, not the exception. The 2024 Update to the Evaluation of Corporate Compliance Programs provides us with critical insights into how we can enhance the effectiveness of our compliance programs, particularly regarding reporting mechanisms and whistleblower protection. These elements are the bedrock of a robust compliance culture, and the update offers a clear roadmap for their implementation and improvement.

The Importance of an Anonymous Reporting Mechanism

One key takeaway from the 2024 Update is the emphasis on having an anonymous reporting mechanism. This tool is essential for any compliance program as it provides employees and third parties with a safe and confidential way to report potential misconduct or violations of company policy.

The update explicitly asks whether your company has such a mechanism and, if not, why not. The absence of an anonymous reporting system should be a red flag for any compliance professional. In today’s regulatory environment, where transparency and accountability are paramount, the lack of such a mechanism can severely undermine the credibility of your compliance program.

If your organization does not have an anonymous reporting mechanism, now is the time to implement one. The benefits are clear: it encourages more reports, provides a sense of security to the reporter, and demonstrates the company’s commitment to addressing unethical behavior. However, merely having a mechanism is not enough.

The lesson here is that the existence of an anonymous reporting mechanism is not just a best practice—it’s a necessity. If your company lacks such a system, it’s time to reconsider seriously. The key takeaway is ensuring your company has an anonymous reporting mechanism. This tool is crucial for empowering employees and third parties to report misconduct without fear of exposure. The absence of this mechanism signals a significant gap in your compliance program, which could undermine trust and deter reporting.

How Is the Reporting Mechanism Publicized?

Another critical aspect highlighted in the update is how well the reporting mechanism is publicized within the company and to third parties. A reporting mechanism that isn’t well-known or accessible might as well not exist. The compliance team is responsible for ensuring employees know and understand how to use this tool. This can be achieved through regular training sessions, clear communication channels, and visible reminders throughout the workplace.

It is not simply about making employees aware but also making them comfortable with using the mechanism. This involves creating a workplace culture where reporting misconduct is seen as a positive action, not something that will lead to negative repercussions.

The key lesson for every compliance professional is that a reporting mechanism is only as effective as its visibility and accessibility. If employees and third parties aren’t aware of it, it will not be used. However, it would be best if you publicized your reporting mechanism widely. Regularly communicate its existence, purpose, and how to use it. Training sessions, internal communications, and visible reminders throughout the organization are essential to ensure everyone knows how to report concerns.

Testing Employee Awareness and Comfort

The 2024 Update introduces a crucial question: Has the company tested whether employees know the hotline and feel comfortable using it? This goes beyond just tracking the number of reports received. It requires proactive steps such as surveys, focus groups, or even role-playing scenarios to gauge the effectiveness of your reporting system.

Understanding employees’ perceptions and addressing any concerns they may have is vital. For instance, if employees hesitate to use the hotline due to fear of retaliation or believing nothing will change, these issues must be addressed head-on. Ensuring that the reporting mechanism is perceived as a trusted and effective tool is key to its success.

The bottom line is that awareness is one thing; comfort in using the reporting system is another. Employees must feel secure using the mechanism without fear of retaliation or inaction. As a compliance professional, you must regularly test and measure employee awareness and comfort. Use surveys, focus groups, and feedback sessions to gauge whether employees know about the reporting channels and feel safe using them. Address any concerns or misconceptions that may prevent employees from reporting misconduct.

Encouraging and Incentivizing Reporting

The update also challenges companies to reflect on whether they encourage and incentivize reporting of potential misconduct or violations. This is a nuanced area, as it involves balancing encouragement without creating a system that can be abused.

One effective approach is to incorporate positive reinforcement into the reporting process. This could be recognition programs for employees who demonstrate ethical behavior, including those who report concerns. Additionally, communicating the outcomes of investigations (while maintaining confidentiality) can reinforce the idea that reporting leads to tangible results and positive organizational changes.

Conversely, the update warns against practices that might chill reporting. These can include overly aggressive investigations, a lack of confidentiality, or a corporate culture that implicitly discourages speaking up. Compliance professionals must be vigilant in identifying and eliminating these barriers. Ensuring that employees feel safe and supported when they report misconduct is non-negotiable.

It is incumbent to note that practices that discourage or chill reporting are counterproductive and can erode trust in the compliance program. Compliance professionals must identify and eliminate practices that may deter reporting. This includes ensuring confidentiality, avoiding overly aggressive investigations, and addressing any cultural factors that may implicitly discourage speaking up. Building a culture where reporting is seen as a positive and valued action is crucial.

Assessing and Acting on Reports

Once a report is made, how the company handles it speaks volumes about its commitment to compliance. The update emphasizes the importance of assessing the seriousness of the allegations and ensuring that the compliance function has full access to reporting and investigative information.

This means every report deserves to be taken seriously, regardless of how minor it may seem. The compliance department must ensure that investigations are thorough, impartial, and conducted with the utmost confidentiality. This helps resolve the issue at hand and builds trust in the system, encouraging more employees to come forward in the future.

Other key components are both transparency and communication. While maintaining confidentiality, it is crucial to keep the reporter informed about the status of their report. This can significantly impact their perception of the process and the company’s commitment to addressing misconduct.

A compliance professional must realize that how reports are handled reflects the company’s commitment to compliance and ethics. Further, every corporate compliance program must ensure thorough and impartial investigations. Every report deserves serious attention, regardless of its perceived severity. The compliance team should have full access to reporting and investigative information, and the process should be transparent. Keeping the reporter informed while maintaining confidentiality builds trust and encourages future reporting.

Commitment to Whistleblower Protection and Anti-Retaliation

One of the update’s most critical aspects is its focus on whistleblower protection and anti-retaliation. A robust compliance program is complete with strong measures to protect those who come forward. The 2024 ECCP asks whether the company has an anti-retaliation policy in place. This is a fundamental requirement. Without such a policy, employees will be reluctant to report misconduct, fearing repercussions. However, having a policy is just the first step.

Training ensures employees know internal anti-retaliation policies and external whistleblower protection laws. This training should be regular, comprehensive, and tailored to different levels of the organization. Employees must understand that retaliation is against company policy and illegal under various regulatory regimes.

The 2024 ECCP also asks whether employees who report misconduct are treated differently than those who do not. This question is crucial as it touches on the fairness and integrity of your compliance program. It is essential that reporters are not penalized for their actions and that the company consistently demonstrates its commitment to protecting whistleblowers. Protecting whistleblowers is fundamental to maintaining an effective compliance program. Without strong anti-retaliation measures, your program’s credibility is at risk. Every corporate compliance function must implement and enforce a robust anti-retaliation policy.

Compliance must regularly train employees on internal policies and external whistleblower protection laws. This will ensure that whistleblowers are not treated unfairly and that there is a clear, consistent approach to handling reports. This protection not only encourages reporting but also supports a culture of integrity.

However, simply being aware of the reporting mechanism is not enough. Employees also need to be trained in the broader regulatory environment. Compliance functions must not conduct regular training on internal reporting systems and external whistleblower programs. Make sure that employees understand not only how to report but also the legal protections available to them. This comprehensive approach helps reinforce the importance of compliance and the company’s commitment to ethical behavior.

The 2024 Update to the Evaluation of Corporate Compliance Programs is a critical reminder that compliance is not just about having policies in place but about creating a culture of ethics and integrity. For in-house compliance professionals, the lessons are clear: prioritize anonymous reporting mechanisms, ensure robust whistleblower protections, and foster a culture where employees feel safe and encouraged to speak up. Doing so protects our organizations and builds a workplace where ethical behavior is the norm, not the exception.

The 2024 Update to the Evaluation of Corporate Compliance Programs underscores the importance of a well-structured, well-publicized, and well-enforced compliance program. For compliance professionals, the key takeaways are clear: ensure your reporting mechanisms are robust and accessible, foster a safe and supportive environment for reporting, and protect those who come forward. By focusing on these areas, you can build a culture of integrity that meets regulatory expectations and creates a workplace where ethical behavior is the standard.