Categories
31 Days to More Effective Compliance Programs

Day 5 – The Board and Operationalizing Compliance

The most significant development for Boards and compliance continues to come from the Delaware courts, which have been expanding the civil law obligations of Boards through a series of court decisions involving the expansion of the Caremark Doctrine for the past several years. These developments began with the Marchand (Blue Bell Ice Cream) decision which required Boards to manage the risks their organizations face. Next was Clovis Oncology which required ongoing monitoring by the Board. Finally, the Boeing case stands for the continuing proposition that a Board cannot simply have the trappings of oversight, it must do the serious work required and have evidence of that work (Document, Document, and Document).


The decision in Boeing is yet a further expansion of the Caremark Doctrine, once again beginning with MarchandBoeing also states that a company must assess its risks and then manage them right up through the Board level. Finally, a Board must be aggressive in their approach and not passively take in what management has presented to them.
The DOJ has also made clear its thoughts on the role of the Board of Directors. The role of the Board is different than that of senior management. The 2020 Update and DOJ Antitrust Division’s 2019 Evaluation of Corporate Compliance Programs in Criminal Antitrust Investigations were even more explicit in announcing their expectation for robust Board oversight of a corporate compliance function.

Name any of the most recent corporate scandals; Wells Fargo, Theranos, Volkswagen, Boeing, FTX, etc., and there was no compliance expertise on the Board. It is now enshrined as a best practice for companies to have a seasoned compliance professional on the Board. I would also add that the DOJ may soon expect a Compliance Committee separate from the Audit Committee.
The DOJ continually speaks about the need for companies to operationalize their compliance programs. Businesses must work to integrate compliance into the DNA of their organization. Having a Board member with specific compliance expertise or heading a Compliance Committee can provide a level of oversight and commitment to achieving this goal. The DOJ enshrined this requirement in the FCPA Corporate Enforcement Policy. This means that when your company is evaluated by the DOJ, under the factors set out in the 2020 Update and FCPA Corporate Enforcement Policy, to retrospectively determine if your company had a best practices compliance program in place at the time of any violation, you need to have not only the structure of the Board-level Compliance Committee but also the specific subject matter expertise on the Board and on that committee.

This means that every Board of Directors needs a true compliance expert. Almost every Board has a former Chief Financial Officer, former head of Internal Audit, or persons with a similar background. Often, these are also the Audit Committee members of the Board. Such a background brings a level of sophistication, training, and SME that can help all companies with their financial reporting and other finance-based issues. So why is there no such SME at the Board level from the compliance profession?

Three key takeaways:

1. The 2020 Update required active Board of Director engagement and oversight around compliance.
2. Board communication on compliance is two-way, both inbound and outbound.
3. The Delaware courts have been expanding Board’s roles through the expansion of the Caremark Doctrine.

Categories
The ESG Report

Attributes of ESG Reporting with Doug Hileman

Tom Fox welcomes Doug Hileman to this episode of the ESG Report. Doug is the founder of Doug Hileman Consultancy and part of the Volkswagen Monitor Team. In this conversation, he and Tom talk about his experience in the environmental and compliance industries, highlighting the increasing complexity of the environment and legal landscape. He also discusses how corporate compliance officers can play an important role in ensuring that companies are compliant with their environmental and safety obligations.

The Evolution of Environmental Regulations 

Tom asks Doug how the environmental field has changed over the years. “I would say that it’s gotten a lot more complex,” Doug responds. Regulation in the past was about cleaning up and disposing of waste, whereas now regulation is borader, covering areas such as product design, biodiversity, and the circular economy. In addition, stakeholders are now imposing requirements: they no longer want to do business with companies that don’t comply with US and global regulations. 

 

The Compliance Professional in Corporate ESG

ESG is a great opportunity for compliance professionals. Compliance obligations are now widespread in the business world, so compliance professionals must learn what the requirements are of any organization that they’re working with. Once they learn the requirements, they can then take up a leadership role. “If they’re not at the table the way they think they should be at the table, then just pull up a chair and sit down,” Doug stresses. “Make your own case for why the compliance function has such an important role in ESG. It’s not about marketing; it’s compliance.”

 

The Board in Corporate ESG 

The board needs to be involved in the company ESG program. It needs to be an ‘all hands on deck’ initiative. This will make the entire company operations more competent. Doug remarks on the importance of internal auditing and how it impacts ESG. The board’s focus should be on how to be in line with ESG practices and requirements, Doug tells Tom. 

 

Resources

Doug Hileman | LinkedIn 

Doug Hileman Consultancy

Categories
FCPA Compliance Report

The EC Gang on the Monaco Doctrine

In this special 5 part podcast series, I am deeply diving into the Monaco Memo and analyzing it from various angles. In this episode of the FCPA Compliance Report, we have the Award-Winning Everything Compliance quartet of Jonathan Marks, Jonathan Armstrong, Karen Woody, and Tom Fox on the Monaco Memo.

1. Tom Fox looks at the Monaco Memo through the monitorship language and answers a listener’s questions about compliance programs under the Monaco Memo.

2. Karen Woody reviews the Monaco Memo, the self-disclosure angle, and investigatory considerations and ponders the role of defense counsel going forward.

3. Jonathan Marks also looks at investigatory issues under the Monaco Memo, the role of the Board of Directors, and the role of the forensic auditor under the Monaco Memo.

4. Jonathan Armstrong’s self-disclosure from a UK angle joins Karen Woody in questioning how defense counsel should move forward.

Resources

Tom 5-Part blog post series in the FCPA Compliance and Ethics Blog

1.     A Jolt for Compliance

2.     Timely Self-Disclosure

3.     Corporate Compliance Programs

4.     Monitors

5.     The Heat is On

Monaco Memo

Categories
Compliance Into the Weeds

Compliance into the Weeds: Mudge and Whistleblower Allegations Against Twitter

Compliance into the Weeds is the only weekly podcast that takes a deep dive into a compliance-related topic, literally going into the weeds to more fully explore a subject. In this episode, we explore the recently publicly released whistleblower allegations by Peiter Zatko, AKA “Mudge,” made against his former employer Twitter. Highlights include:

  • The allegations made by Mudge.
  • What possible enforcement actions and legal ramifications could develop?
  • What does this mean for the Twitter/Elon Musk litigation?
  • Where was the Board, and who was the Board?
  • Is there more to come?

Resources

Matt in Radical Compliance

Categories
Blog

A Caremark Retrospective: Part II – Holdings and Rationale

Today, I continue my exploration of two of the most significant cases regarding Boards of Directors and corporate compliance; the Caremark and Stone v. Ritter decisions. The former decision was released in 1996 and the latter, some ten years later in 2006. The original Caremark decision laid the foundation for the modern obligations of Boards of Directors in oversight of compliance in general and a company’s risk management profile in particular. Stone v. Ritter confirmed the ongoing vitality of the original Caremark decision. Yesterday, in Part 1, we reviewed the underlying facts of the Caremark decision. Today, in Part II, we consider the holdings and the legal reasoning. Perhaps the most interesting thing about both cases is that even though the Court in Caremark delineated the doctrine and in Stone v. Ritter confirmed it, both Courts ruled against the moving parties and for the defendant corporate Boards.

Caremark

In Caremark, the Court began by noting that director liability for a breach of the duty to exercise appropriate attention can come up in two distinct contexts. In the first, liability can occur from a board decision that results “in a loss because that decision was ill advised or “negligent””. In the second, board liability for a loss “may be said to arise from an unconsidered failure of the board to act in circumstances in which due attention would, arguably, have prevented the loss.”

However, any decision is tempered by the following, what “may not widely be understood by courts or commentators who are not often required to face such questions, is that compliance with a director’s duty of care can never appropriately be judicially determined by reference to the content of the board decision that leads to a corporate loss, apart from consideration of the good faith or rationality of the process employed.” In other words, if there is a process or protocol in place a board cannot be said to have violated its duty, even with “degrees of wrong extending through “stupid” to “egregious” or “irrational”.” To do so would abrogate the Business Judgment Rule.

The Caremark court went so far as to cite Learned Hand for the following, “They are the general advisors of the business and if they faithfully give such ability as they have to their charge, it would not be lawful to hold them liable. Must a director guarantee that his judgment is good? Can a shareholder call him to account for deficiencies that their votes assured him did not disqualify him for his office? While he may not have been the Cromwell for that Civil War, Andrews did not engage to play any such role.”

However, there is a second type of liability which boards can run afoul of under Caremark, and it is the one which seems to the liability under which most boards are found wanting in successful Caremark claims. It is when “director liability for inattention is theoretically possible entail  circumstances in which a loss eventuates not from a decision but, from unconsidered inaction.” This was a departure from prior Delaware case law which said that a board did not have to look for wrongdoing but only had to investigate if informed about it. That was from an old 1963 decision and the Court relied on the 1992 US Sentencing Guidelines to note how such views were no longer accepted. Board obligations had changed by 1996 with the following, “obligation to be reasonably informed concerning the corporation, without assuring themselves that information and reporting systems exist in the organization that are reasonably designed to provide to senior management and to the board itself timely, accurate information sufficient to allow management and the board, each within its scope, to reach informed judgments concerning both the corporation’s compliance with law and its business performance.”

Stone v. Ritter

This case involved money laundering and a bank’s failure to report suspicious activity which led to an employee running a Ponzi scheme. The bank in question was fined over $40 million. Once again, the plaintiffs were not successful in their claims. The Stone v. Ritter court approved the Caremark Doctrine and went on to further specify thatCaremark required a “lack of good faith as a “necessary condition to liability”.” It is because the Court was not focusing simply on the results but in the board’s overall conduct “of the fundamental duty of loyalty.” It follows that because a showing of bad faith conduct, “is essential to establish director oversight liability, the fiduciary duty violated by that conduct is the duty of loyalty.”

Interestingly, the Court added what it termed as “two additional doctrinal consequences.” First, although good faith is a “part of a “triad” of fiduciary duties that includes the duties of care and loyalty, the obligation to act in good faith does not establish an independent fiduciary duty that stands on the same footing as the duties of care and loyalty.” Violations of the duties of care and loyalty may result in direct liability, whereas a failure to act in good faith may do so, but it would only result in indirect liability. The second consequence is that the “duty of loyalty is not limited to cases involving a financial or other cognizable fiduciary conflict of interest. It also encompasses cases where the fiduciary fails to act in good faith. As the Court of Chancery aptly put it in Guttman, “[a] director cannot act loyally towards the corporation unless she acts in the good faith belief that her actions are in the corporation’s best interest.””

The Stone v. Ritter court ended by further refining the Caremark Doctrine to define the necessary conditions for director liability under Caremark. They are:

  1. Directors utterly failed to implement any reporting or information system or controls;
  2. If they have implemented such a system or controls, consciously failed to monitor or oversee its operations thus disabling themselves from being informed of risks or problems requiring their attention.

In either situation, imposition of liability requires a showing that the directors knew that they were not discharging their fiduciary obligations. Where directors fail to act in the face of a known duty to act, thereby demonstrating a conscious disregard for their responsibilities, they breach their duty of loyalty by failing to discharge that fiduciary obligation in good faith.

As usual, once I get started, I often cannot stop so in my next blog post (or two) I will consider how this has evolved.

Categories
Blog

A Caremark Retrospective: Part I – Background

It is often instructive to look back at old cases which have become so well known for a doctrine that the underlying facts are often forgotten. I did so recently in reading the original Caremark and Stone v. Ritterdecisions. The former decision was released in 1996 and the latter, some ten years later in 2006. They both made interesting reading and the underlying facts could well be drawn from the headlines of anti-corruption and anti-money laundering (AML) enforcement actions today. The original Caremark decision laid the foundation for the modern obligations of Boards of Directors in oversight of compliance in general and a company’s risk management profile in particular. Stone v. Ritter confirmed the ongoing vitality of the originalCaremark decision. Today, in Part 1, we review the underlying facts of the Caremark decision and in Part II, the legal reasoning.

Underlying Facts

In Caremark, the decision involved a company which provided patient care and managed care services and a substantial part of the revenues generated by the company was derived through third party payments, insurers, and Medicare and Medicaid reimbursement programs. Medicare and Medicaid payments were governed under the Anti-Referral Payments Law (“ARPL”) which prohibited health care providers (HCPs) from paying any form of remuneration (i.e., kickbacks) to physicians to induce them to refer Medicare or Medicaid patients to Caremark products or services.

To try and get around this prescription, Caremark entered various contracts for services (e.g., consultation agreements and research grants) with physicians at least some of whom prescribed or recommended services or products that Caremark provided to Medicare recipients and other patients. Moreover, Caremark had a decentralized governance and operational structure which allowed wide latitude to the business units to enter into such agreements without corporate or any centralized compliance or legal oversight. The results were about what you would expect.

Multiple federal investigations found that from the mid-1980s until the early 1990s, Caremark paid out millions to doctors in forms disguised to evade ARPL liability. Caremark claimed that its payments for consultation, teaching, research grants and other similar evasions did not violate the law. Further, it relied on an audit by Price Waterhouse (PwC) which concluded that there were no material weaknesses in Caremark’s control structure.

In 1993, Caremark formally changed its compliance manual to prohibit such payments, announced this change internally and put on training for this new set of policies. However, there were no attendant controls, monitoring or follow up noted. Indeed, it is not clear if much if anything changed at Caremark, given the decentralized nature of its business model.

Criminal and Civil Charges

In August 1994, Caremark was hit with a 47-page indictment alleging criminal violations of ARPL, specifically including making payments to induce physicians to refer patients to Caremark services and products. The indictment alleged that payments were “in the guise of research grants and others were consulting agreements.” Moreover, the Indictment went on to allege that such payments were made where no consulting services or research performed. (Very 2022 FCPA-ish) One doctor was alleged to have direct payments from Caremark for staff and offices expenses. Multiple shareholder suits were filed against the Board in Delaware and another federal Indictment was handled in Ohio. In addition to the claims in Ohio, new allegations of over billing and inappropriate referral payments made in Georgia and “reported that federal investigators were expanding their inquiry to look at Caremark’s referral practices in Michigan as well as allegations of fraudulent billing of insurers.” Rather amazingly, the company management, when reporting the Indictment to the Board of Directors, maintained the company had done nothing wrong.

Settlements

Of course, the Caremark senior management was not correct, and Caremark was required to pay millions to resolve enforcement actions. An agreement, with the Department of Justice (DOJ), Office of Inspector General (OIG), US Veterans Administration, US Federal Employee Health Benefits Program, federal Civilian Health and Medical Program of the Uniformed Services, and related state agencies in all fifty states and the District of Columbia required a Caremark subsidiary to enter a guilty plea to two counts of mail fraud, and required Caremark to pay $29 million in criminal fines, $129.9 million relating to civil claims concerning payment practices, $3.5 million for alleged violations of the Controlled Substances Act, and $2 million, in the form of a donation, to a grant program set up by the Ryan White Comprehensive AIDS Resources Emergency Act. Caremark also agreed to enter into a compliance agreement with the Department of Health and Human Services (HHS).

In addition to all these entities, Caremark was also sued by several private insurance company payors (“Private Payors”), who alleged that Caremark was liable for damages to them for allegedly improper business practices related to those at issue in the OIG investigation. As a result of negotiations with the Private Payors the Caremark Board of Directors approved a $98.5 million settlement agreement with the Private Payors in 1996.

In addition to the financial penalties, Caremark finally agreed to institute a full compliance program. It created the position of Chief Compliance Officer (CCO) and created a Board level Compliance and Ethics Committee who, with the assistance of outside counsel, was tasked with reviewing existing contracts and advanced approval of any new contract forms.

Join us for our next piece where we consider the court holdings and rationales in Caremark and Stone v. Ritter.

Categories
Blog

The CCO and Board Refreshment

Boards of Directors are coming under increased legal and regulatory scrutiny. Courts in Delaware, from the Delaware Court of Chancery to the Delaware Supreme Court, have continued to refine and expand the Caremark Doctrine. Boards are on notice they must actively engage in compliance and risk management oversight. One of the continuing challenges for boards in this era of increasing responsibility is getting the right persons on boards. I was therefore interested in a recent MIT Sloan Management Review article, entitled Meet the New Board — Same as the Old Board, where authors Cynthia E. Clark and Jill A. Brown posit that many companies are just going through the motions of recruiting more diverse board members. Moreover, they advocate the time is now to get serious about board refreshment.

In addition to these new legal requirements, other stakeholders are pushing for public companies to refresh their boards to achieve greater diversity. Shareholders have been leading the way at least a dozen public company boards since mid-2020, “accusing them of failing to broaden out with greater diversity.” Institutional investors and investment managers such as BlackRock, Inc. have voted “against more than 1,800 directors at close to 1,000 companies for insufficient action to increase board diversity.” The proxy advisory firm Institutional Shareholder Services Inc. “now recommends withholding votes from, or voting against, directors with nominating or governance roles on boards that don’t have at least one non-White director and at least one woman.” Finally, the Nasdaq Exchange, with the approval of the Securities and Exchange Commission (SEC), “will soon require listed companies to have at least two demographically diverse directors (or explain why they don’t).”

Yet board refreshment and diversity is not simply something driven by regulators or changes in the law. The authors believe, “diverse boards representing a broader range of experience may be better able to quickly navigate volatile business environments and unexpected disruptions, such as a global pandemic.” They cite to “recent data from BoardReady, a nonprofit group that promotes corporate diversity, found a positive correlation between the diversity of S&P 500 boards and revenue growth during the pandemic.” So, if the law, regulators, stakeholders and the market all believe in board refreshment, why is not this effort moving forward with greater speed and urgency?

The authors found two key reasons why many companies still struggle to appoint directors who are women, people of color, or members of other underrepresented groups. (1) They found “that corporations go through the motions of refreshment but ultimately accomplish little, replacing an outgoing director with someone similar rather than with a person who has a different professional background, identity, or perspective.” (2) Perhaps not too surprisingly, they also “found that the independence of the board’s nominating committee is often compromised by substantial CEO influence over the process, perpetuating a tendency to select directors who reflect the opinions, and often the identity, of senior management.” When these factors converge, board independence and effectiveness in overseeing management of the company is compromised, which can negatively impact corporate performance.

The authors developed four actions which they believe can allow a company to turn around these areas in board refreshment. How can boards avoid these pitfalls and achieve meaningful refreshment? Leaders who want to change the culture of the board should take the following actions.

Diversity of identity and thought

Obviously, there are certain easily verifiable and achievable standard boards can articulate around diversity, including gender, race, and other such attributes. They can then evaluate nominees against that definition and for diversity of through as well. As the Compliance Evangelist, it would surprise you that I believe more former Chief Compliance Officers (CCOs) and compliance professionals should be nominated to boards. The same is true in other areas of risk management, cyber, export controls and trade sanction and even supply chain. The authors state, “Boards should also encourage nominees to talk about what type of diversity they believe they would bring to the board.” Documenting these actions will serve companies well, as multiple stakeholders are increasingly demanding public disclosure of this documented  information.

Refresh frequently

It is clear that a long-standing board is not the best system to have in place as members gradually lose effectiveness and long “tenures tend to compromise the true nature of director independence.” This leads the authors to suggest boards “set earlier mandatory retirements and shorter term limits.” Some investors oppose the re-election of directors who have served on a board for more than nine years, while others may limit service to seven years. Interestingly, the authors note, “in industries where business models and operational contexts change fast, tenures might need to be even shorter.” Rotation of members and a staggered hiring tenure can also be used.

Limit CEO involvement

Given the negative impact of a Chief Executive Officer (CEO) in the process of selection, it is not too surprising the authors posit “the CEO should not have a vote in the hiring decision, implied or otherwise.” To enhance this position, they also write, “We think boards could normalize the use of executive sessions and reduce any stigma associated with them by holding them more frequently, including when evaluating director candidates.” They noted the “New York Stock Exchange (NYSE) requires executive sessions once a year and Nasdaq at least twice a year, although neither specifies that the sessions be used in the nominee search and hiring process.”

Changing culture

Every CCO and compliance professional who has dealt with a board understands refreshment and corporate culture are tied together. The very act of refreshing an old, stagnant board with new people and ideas changes the culture of a board. That change permeates down into an organization. It is almost axiomatic that “A group of directors with similar experiences, opinions, skills, and identities will naturally tend toward consensus much too often.”

A CCO should work to get directors “to think about and freely discuss the existing board culture, including their own behavior and whether it needs to change.” You could also encourage a board to hire “a consultant to help diagnose and possibly change your board culture.” Finally, work to  “Encourage board members to voice their opinions, especially when they challenge the consensus.” As with most things in life, if you do what you did, you get what you got. The same is true for boards. If you replace one old white guy who was an executive in your industry with another old white guy who also is from the same industry, you have not refreshed your board member, you have simply replaced one for another. In this time of near constant change, boards need to be able to respond quickly and nimbly. That is going to take new blood into your Board of Directors.

And do not forget the ‘G’ in ESG.

Categories
FCPA Compliance Report

Ty Francis on Assessing Corporate Culture: A Practical Guide to Improving Board Oversight

In this episode of the FCPA Compliance Report, I am joined by Ty Francis, Chief Advisory Officer at LRN. We dive deeply into a recently released LNR/Tapestry Networks Report on Assessing Corporate Culture: A Practical Guide to Improving Board Oversight. Some of the highlights include:

  1. The genesis of this report.
  2. How does the Report serve as a roadmap to a clearer picture of the company’s ethical culture?
  3. How can the Report help determine how to improve culture throughout the enterprise?
  4. Who should a Board collaborate with, and how?
  5. How does the work LRN conducts help organizations foster more effective collaborative cultures?
  6. How do you prioritize culture on the board agenda?
  7. What is the challenge to the board’s culture?
  8. How does a Board measure and monitor?
  9. How does a Board articulate the desired culture?
  10.  How can a Board establish clear communication?

Resources

Ty Francis on LinkedIn

LRN

Assessing Corporate Culture: A Practical Guide to Improving Board Oversight

Tapestry Networks

Categories
Sunday Book Review

August 14, 2022 the Culture edition

In today’s edition of Sunday Book Review:

The Advantage: Why Organizational Health Trumps Everything Else in Business by Patrick Lencioni

Culture by Design: How to Build a High-Performing Culture, Even in the New Remote Work Environment by David J. Friedman

The Culture Code: The Secrets of Highly Successful Groups by Daniel Coyle

Organizational Culture and Leadership by Edgar H. Schein with Peter Schein

Winning Behavior: What the Smartest, Most Successful Companies Do Differently by Terry R. Bacon and David G. Pugh

Resource

5 Top Books on Corporate Culture

Categories
The Woody Report

Caremark Claims, Part 2

Welcome to The Woody Report, where Washington & Lee School of Law Associate Professor Karen Woody and host Tom Fox discuss issues on white collar crime, compliance issues, international corruption, securities and accounting fraud, and internal corporate investigations. From current events to topical issues to academic research and thought leadership, Karen Woody helps lead the discussion of these issues on the new and exciting podcast. Today in Part 2, Tom and Karen look at cases in the wake of Marchand, including Clovis Oncology, Boeing and Cardinal Health.

Resources

Karen Woody on LinkedIn

Karen Woody at Washington & Lee, School of Law