Categories
Blog

The Scoular DPA: Part 2 – A Journey Through Non-Disclosure

The Scoular Company Deferred Prosecution Agreement (DPA) presents a difficult but essential lesson for every Chief Compliance Officer and board: stopping misconduct is not the same as voluntarily disclosing it. This might seem as self-evident as anything in compliance, but it is a critical component of this case.

The Statement of Facts says that internal reports alleging improper business practices connected to the Mexican inspection fees arose in 2019. Scoular then changed its grain-shipment practices and terminated its direct engagement with the customs brokers involved. Those steps addressed the immediate conduct. They did not produce voluntary self-disclosure credit. That misstep cost Scoular Company millions, potentially leading to a full declination.

The DPA states that Scoular did not receive credit under the DOJ Corporate Enforcement and Voluntary Self-Disclosure Policy (VSP) because it did not “voluntarily and timely disclose” the conduct to the Fraud Section. That single sentence creates the central governance question in Blog Post Part 2: What must happen after a credible internal report reaches the company? An internal allegation starts an investigative clock. The company must preserve evidence, protect against retaliation, assess immediate risk, and establish enough facts to make responsible decisions. It also starts a disclosure clock.

The VSP encourages companies to report potential wrongdoing at the earliest possible time, even before an internal investigation is complete. To qualify as a voluntary self-disclosure, a report must be made in good faith to the appropriate DOJ component, concern misconduct not already known to the Department, occur without a preexisting disclosure obligation, precede an imminent threat of disclosure or government investigation, and be made within a reasonably prompt time after the company becomes aware of the misconduct.

The burden of demonstrating timeliness rests with the company. This does not mean a company must call the DOJ the moment an untested allegation enters the hotline. It does mean disclosure cannot wait until every interview, legal conclusion, and remediation project is complete. The investigation and disclosure analyses must proceed together.

The DPA Tells Us the Result, Not the Internal Debate

The agreement does not explain who received the 2019 reports, how the allegations were investigated, when senior management or the board learned of them, or why Scoular did not make a qualifying disclosure. It does not tell us whether the company made a deliberate decision not to report. What the DPA does establish is the outcome. Internal reports arose. The company changed its practices and terminated direct broker relationships. The company did not voluntarily and timely disclose the conduct to the Fraud Section and therefore received no voluntary disclosure credit.

That sequence is enough to demonstrate a control lesson. A company can remediate an operational problem and still leave the enforcement decision unresolved. The response requires four distinct workstreams:

  • Stopping the conduct prevents additional harm.
  • Investigating the conduct determines what happened and which controls failed.
  • Remediating the controls reduces recurrence risk.
  • Evaluating disclosure determines whether, when, where, and how the company should approach enforcement authorities. This fourth step is arguably the most important and must be reached with great speed, perhaps as little as two weeks after initial determination.

A Disclosure Needs a Decision Process

Disclosure decisions should not depend on one executive’s instinct or on the hope that remediation will close the matter. The company needs a defined escalation structure involving legal, compliance, internal audit, finance, and appropriate senior management. Depending on the seriousness of the facts, the audit committee or another independent board committee may need to oversee the decision.

For an FCPA matter involving customs brokers, repeated payments, government officials, inaccurate invoice descriptions, senior personnel, and multiple years of conduct, the disclosure analysis should address:

  • What credible facts are known now?
  • Is the misconduct continuing?
  • Which individuals and third parties may be involved?
  • Are the books and records inaccurate?
  • Is there evidence of management participation, approval, condonation, or willful ignorance?
  • Has a whistleblower, auditor, regulator, bank, business partner, or foreign authority already received the same information?
  • Is there an imminent threat that the DOJ will learn of the conduct?
  • What additional facts are necessary to make a disclosure decision?
  • When will the decision be revisited?
  • Who has authority to decide, and how will the reasoning be documented?

The objective is not to create a paper defense for a predetermined result. It is to establish a disciplined process that forces the company to confront timing, uncertainty, accountability, and enforcement exposure.

Disclosure Does Not Require a Finished Investigation

One reason companies may delay is the understandable fear of reporting facts that are incomplete or later prove wrong. The DOJ policy addresses that concern directly. It encourages early disclosure even when the company has not completed its internal investigation. The company can report the misconduct known at that stage, identify the limits of its current knowledge, preserve credibility by avoiding unsupported conclusions, and provide rolling updates as the investigation develops.

That approach requires discipline. The initial disclosure should distinguish facts from allegations, describe preservation and remediation steps, and explain the investigative plan. Later presentations should attribute facts to specific sources and identify individuals regardless of seniority.

Waiting for certainty can eliminate the benefit the company hoped to secure. A whistleblower may contact the government, a third party may cooperate, or the payment may surface in another investigation. Once the DOJ already knows or disclosure is imminent, the analysis changes. The business lesson is straightforward. Uncertainty calls for a staged disclosure strategy, not an indefinite pause.

Cooperation Still Mattered

Scoular Company lost the disclosure benefit, but the DPA demonstrates that the company could still earn meaningful credit. The DOJ credited Scoular with conducting an internal investigation, making detailed factual presentations, identifying individuals involved, producing and organizing requested materials, securing counsel for current employees, and providing all relevant facts known to it.

Voluntary self-disclosure, cooperation, and remediation are separate pillars. A company that misses the first can still create value through the other two. The DPA also notes “certain deficiencies in the early part of the investigation.” It does not identify those deficiencies, and they should not be guessed. Their inclusion nevertheless sends a message: cooperation is judged across the life of the investigation, not merely by the quality of the final presentation.

The current DOJ policy makes the standard explicit. A company starts at zero cooperation credit and earns credit through specific actions: scope, quality, impact, and timing matter. A failure to cooperate fully at the earliest opportunity may reduce the credit available later. For CCOs and boards, the lesson is that recovery remains possible, but delay has a price.

Remediation Changed How the Business Operated

Scoular also received credit for substantial remediation. The company increased compliance engagement with the business, used external compliance maturity and anti-corruption risk assessments, restructured the compliance function, and incorporated senior leadership oversight. It eliminated customs brokers associated with reinspection fees, strengthened risk-based review and monitoring with software tools, revised policies, enhanced third-party screening and approvals, added anti-corruption and audit-right provisions to contracts, improved financial controls for high-risk transactions, and delivered general and targeted training.

These measures went beyond terminating vendors. They addressed governance, third-party management, payment controls, monitoring, technology, policies, and training. That breadth matters because remediation must be tied to root cause. If the misconduct was enabled by commercial pressure, broker dependence, misleading invoices, weak transaction validation, and fragmented data, another annual training course will not solve the problem.

The Economic Difference Was Significant

Scoular entered into a three-year DPA and agreed to pay a $9,769,521 criminal penalty and $414,351 in forfeiture. The DPA states that the penalty reflected a 25 percent reduction from the applicable low-end amount. A footnote explains that the statutory alternative-fine cap, based on twice the approximately $6.513 million gross gain, constrained the otherwise higher Guidelines minimum.

The DPA does not say what disposition Scoular would have received after a qualifying disclosure. It would be improper to rewrite the resolution with hypothetical facts.

The current department-wide CEP nevertheless shows why the distinction matters. A company that voluntarily self-discloses, fully cooperates, timely remediates, and has no disqualifying aggravating circumstances is placed on a declination path. A good-faith self-report that narrowly misses the policy’s technical requirements can still lead to an NPA, a term shorter than three years, no monitor, and a reduction of 50 to 75 percent from the low end. Companies outside those paths remain subject to prosecutorial discretion, with a reduction capped at 50 percent.

Scoular received a DPA, a three-year term, and a 25 percent reduction. The numbers turn disclosure governance into a business issue. The decision affects resolution form, penalty exposure, duration, oversight, reputation, management time, and the company’s ability to move beyond the misconduct.

Questions for CCOs

CCOs should ask:

  • Does every credible allegation involving government payments trigger a documented disclosure analysis?
  • Who owns the disclosure clock while the investigation proceeds?
  • Can legal and compliance make an early report without waiting for a completed investigation?
  • Are facts, assumptions, open questions, and decision deadlines documented separately?
  • Have we tested the process through a tabletop exercise involving a whistleblower, a third party, and an imminent government inquiry?

The Scoular DPA does not establish why the company missed voluntary disclosure credit. It does establish that internal reporting, operational remediation, and voluntary disclosure are not interchangeable. When a credible allegation arrives, the company must stop the conduct, investigate the facts, remediate the controls, and make a timely, documented disclosure decision. Doing three of those four things can still leave substantial value on the table.

Join us tomorrow for Part 3, where we will examine how a robust internal control system paired with a robust data analytics overview can help a company avoid a Scoular Company-type series of failures.

Categories
Blog

The Updated CEP: Is Real Credit Finally Here?

Matthew R. Galeotti, Head of the Criminal Division at the U.S. Department of Justice (DOJ), recently delivered a speech at SIFMA’s Anti-Money Laundering and Financial Crimes Conference. Contemporaneously, the DOJ issued a Memo (the Galeotti Memo) entitled Focus, Fairness, and Efficiency in the Fight Against White-Collar Crime. I have explored both in previous blog posts. Today, I want to review the Corporate Enforcement and Voluntary Self-Disclosure Policy (CEP) updates. It provides a roadmap for how companies can earn leniency when they self-report wrongdoing. And in an increasingly unforgiving regulatory landscape, that roadmap is worth its weight in gold.

Under the CEP, a company that voluntarily self-discloses, fully cooperates, and timely remediates can qualify for a declination of prosecution, provided there are no aggravating circumstances. This is the reaffirmation of a multi-year DOJ effort to garner more self-disclosures. It gives compliance professionals something real to bring to the C-suite: if we invest in robust compliance and proactively address issues, we can avoid criminal prosecution altogether.

What if aggravating factors exist, such as senior-level involvement or prior misconduct? If the company cooperates and remediates in good faith, the policy still provides for reduced penalties, non-prosecution agreements, and shorter resolution terms. In other words, the DOJ offers a “near miss” safety net for companies that fall short of full eligibility but act responsibly.

The takeaway is clear: Compliance is not just a cost center but a value driver. The CEP recognizes that companies should be rewarded for coming forward, cooperating, and fixing problems. That means compliance professionals must build systems that detect misconduct early, encourage internal reporting, and enable swift action. When a crisis hits, your response will not just shape your company’s future; it may be the difference between a decline and a prosecution.

Voluntary Self-Disclosure

The DOJ’s Criminal Division strongly encourages companies to voluntarily self-disclose potential misconduct as early as possible, even before completing an internal investigation. To qualify under the CEP, a disclosure must meet several key criteria: it must be made to the Criminal Division (or in good faith to another DOJ component involved in the resolution), concern previously unknown misconduct, not be required by any existing legal obligation, and occur before any imminent threat of disclosure or government investigation arises. Additionally, the disclosure must be made within a “reasonably prompt” timeframe, with the company bearing the burden of proving timeliness.

The DOJ proposes a limited exception for the new Corporate Whistleblower Awards Pilot Program. Suppose a whistleblower reports misconduct internally and to the DOJ. In that case, a company may still qualify for the presumption of declination, but only if it self-discloses to the DOJ within 120 days of the internal report and meets all other voluntary disclosure conditions.

This guidance underscores the urgency and importance of real-time reporting mechanisms, strong internal controls, and rapid compliance response protocols. Timely self-disclosure is not just encouraged; it is now a strategic imperative in mitigating enforcement risk.

What is Full Cooperation?

To earn full cooperation credit under the CEP, a company must go beyond the general requirements of the Principles of Federal Prosecution of Business Organizations (Justice Manual 9-28.000) and meet six key obligations:

  1. Disclosure of All Relevant Facts: A company must share all non-privileged, relevant facts it knows, including facts about individuals responsible for the misconduct, regardless of their rank, whether internal or external to the company.
  2. Timely and Specific Information Sharing: This includes facts obtained through any internal investigation, updates during that investigation, and specific attributions of facts to sources. The company must also clearly identify all involved parties.
  3. Proactive Cooperation: Companies must voluntarily disclose relevant facts, even if prosecutors do not specifically request them. They are also expected to alert the DOJ to any avenues of obtaining evidence not in the company’s possession but known to them.
  4. Preservation and Disclosure of Documents: Relevant documents, including overseas ones, must be preserved, collected, and produced. Companies must detail such documents’ origin, custodians, and locations; facilitate third-party productions; and provide necessary translations. The company must prove the restriction if foreign law prevents disclosure and suggest viable alternatives.
  5. De-confliction: Companies must avoid actions that might interfere with DOJ investigations. If requested, they must delay certain investigative steps, such as employee interviews, for a narrowly tailored period to protect DOJ priorities.
  6. Availability of Individuals for Interviews: Subject to constitutional protections, companies must make current and former employees (including those overseas) available for DOJ interviews and facilitate third-party interviews where possible.

These standards ensure that cooperation is meaningful, timely, and valuable to the DOJ’s efforts, rewarding companies that truly support investigations with favorable outcomes under the CEP.

Timely and Appropriate Remediation

Under the CEP, timely and appropriate remediation is a non-negotiable component of earning cooperation credit and potentially avoiding prosecution. And for compliance professionals, it is a clarion call to action. First, the company must conduct a root cause analysis, a genuine examination of what went wrong, why, and how to prevent it from happening again. It’s not about blaming a few bad apples but addressing systemic issues that allowed the misconduct to take root. Did a cultural blind spot develop in a high-risk market? Was there a breakdown in oversight or a failure to escalate red flags? The DOJ expects thoughtful answers and corrective action.

Second, the company must demonstrate an effective compliance and ethics program tailored to its risk profile, business model, and resources. That means more than having policies on the books. DOJ evaluators are looking at leadership’s commitment, compliance’s access to the board, compensation tied to ethical performance, and real-time testing of program effectiveness. Box-checking won’t cut it.

Third, accountability is key. Companies must appropriately discipline wrongdoers, including those who failed in their supervisory duties, and ensure they retain and safeguard business records, including communications on personal devices and ephemeral apps.

Finally, remediation includes showing that the company understands the seriousness of the misconduct and is proactively reducing future risk. This is about culture, not cosmetics.

In short, remediation is proof of your values in action. It is the difference between performative compliance and real commitment. Suppose you’re building a credible compliance program in today’s enforcement environment. In that case, remediation must be embedded in your DNA because the DOJ is watching, and your organization’s future may depend on how you respond.

Providing Cooperation Credit

Finally, there is the cooperation credit. Hopefully, we have finally moved past the Kenneth Polite formulation of super, double-secret, undefined “we know it when we see it” cooperation. Cooperation credit here will be earned through demonstrable, high-quality, timely actions. Cooperation is assessed on a sliding scale based on how extensively and effectively a company supports the government’s investigation. Once a company meets the minimum threshold for cooperation, prosecutors evaluate factors such as scope, quantity, quality, timing, and the overall impact of the cooperation provided.

Importantly, cooperation credit starts at zero and increases only with meaningful contributions, and there is no presumption of full credit. The DOJ now distinguishes between cooperation levels by varying the starting point within the U.S. Sentencing Guidelines fine range, and the percentage of fine reduction awarded. Companies that delay cooperation may significantly reduce their potential credit.

Waiver of attorney-client privilege or work product protections is not required to receive cooperation credit. If a company claims its financial condition limits its ability to cooperate, it must provide supporting documentation. The DOJ will carefully evaluate any such claims. Ultimately, the message is clear: to earn meaningful credit, cooperation must be real, proactive, and sustained. But at least it is now defined and not “We know it when we see it.”

Resources:

CRM White Collar Enforcement Plan

Revised CEP

CRM Monitor Memo

Categories
FCPA Survival Guide

FCPA Survival Guide: Step 3 – Extensive Remediation

How can you survive an FCPA enforcement action? In this special podcast series, Tom Fox and Nick Gallo lay out the Top 10 things you can do to reduce your overall fine and penalty, perhaps down to a full declination. All of the actions you can take come from recent DOJ prosecutions under the FCPA and speeches from DOJ representatives. This podcast, sponsored by Ethico, is the companion series to the book The FCPA Survival Guide: Surviving and Thriving a Foreign Corrupt Practices Act Enforcement Action. Today, we discuss the DOJ requirement for extensive remediation.

Tom Fox and Nick Gallo are back to look at the importance of extensive remediation in compliance, particularly in the context of the FCPA enforcement actions. They highlight three enforcement actions – ABB, Albemarle, and SAP – to demonstrate how companies have implemented effective remediation strategies. ABB’s approach included a comprehensive data analytics program and cultural changes led by Chief Integrity Officer Natalia Shehadeh. The DOJ’s recognition of data analytics in the Albemarle and SAP cases signals a shift from cutting-edge practices to standard expectations in compliance. The episode also delves into the transformation of business models as a form of remediation, with Albemarle and SAP making significant changes to their sales strategies to manage risks better and ensure direct customer relationships. Through these discussions, Tom and Nick emphasize that extraordinary remediation is about authentic efforts to improve compliance and reduce risk, not just fulfilling minimal requirements.

Key Highlights and Issues

  • Exploring ABB’s Compliance Remediation Strategy
  • Beyond Checking the Box: A Deep Dive into Compliance Remediation Mindset
  • The Power of Data Analytics in Compliance Remediation
  • Transforming Business Models for Better Compliance Remediation

Resources:

Nick Gallo on LinkedIn

Ethico

The FCPA Survival Guide: Surviving and Thriving a Foreign Corrupt Practices Act Enforcement Action

Tom

Instagram

Facebook

YouTube

Twitter

LinkedIn

Categories
FCPA Survival Guide

FCPA Survival Guide: Step 2 – Extraordinary Cooperation

How can you survive an FCPA enforcement action? In this special podcast series, Tom Fox and Nick Gallo outline the Top 10 things you can do to reduce your overall fine and penalty, perhaps down to a full declination. All of the actions you can take come from recent DOJ prosecutions under the FCPA and speeches from DOJ representatives. This podcast, sponsored by Ethico, is the companion series to the book The FCPA Survival Guide: Surviving and Thriving a Foreign Corrupt Practices Act Enforcement Action. Today, we discuss the DOJ requirement of extraordinary cooperation.

This episode highlights the definitions of full cooperation and extraordinary cooperation from a law enforcement perspective, emphasizing the advice from Kenneth Polite and Deputy Attorney General Lisa Monaco on acting ‘swiftly and without delay.’ They explore strategies for accelerating investigations without compromising quality, including leveraging technology, ensuring a well-defined process, and engaging the right people. They emphasize the DOJ’s demand for immediacy, consistency, and impact in investigations, linking efficient, real-time processes with the broader goal of compliance and remediation. The discussion also touches on managing messaging apps and the significance of preparation and proactive processes to meet the Department of Justice’s expectations effectively.

Key Highlights and Issues:

  • Defining Extraordinary Cooperation and Its Challenges
  • The Importance of Real-Time Systems in Investigations
  • Strategies for Efficient and Effective Investigations
  • Leveraging Technology, Process, and People for Speed
  • The DOJ’s Expectations: Immediacy, Consistency, and Impact
  • The Process Nature of Compliance and Investigation

 Resources:

Nick Gallo on LinkedIn

Ethico

The FCPA Survival Guide: Surviving and Thriving a Foreign Corrupt Practices Act Enforcement Action

Tom

Instagram

Facebook

YouTube

Twitter

LinkedIn

Categories
Blog

Ten Top Lessons from Recent FCPA Settlements – Lesson No. 10, Getting to Self-Disclosure: Speak Up, Triage and Internal Investigation

Over this series, I have reviewed the messages communicated by the Department of Justice (DOJ) and Securities and Exchange Commission (SEC) from three key Foreign Corrupt Practices Act (FCPA) enforcement actions regarding their priorities in investigations, what they want to see in remediations, and what they consider best practices compliance programs. These enforcement actions warrant a close study of the lessons learned. They should guide not simply your actions should you find yourself in an investigation but also how you should think about priorities. One thing is abundantly clear: It all begins with self-disclosure.

The three FCPA enforcement actions we have reviewed are ABB from December 2022, Albemarle from November 2023, and SAP from January 2024. I added a fourth, the Gunvor S.A. enforcement action, as a discussion point, as it was released while I was writing this series. I have also cited several speeches by DOJ officials, including those from Deputy Attorney General Lisa Monaco and Assistant Attorney General Kenneth Polite. They pointed out a clear path for the company, which finds itself in an investigation, using extensive remediation to avoid monitoring. They provided insight for the compliance professional into what the DOJ expects in a best practices compliance program on an ongoing basis.

Late last week, there were two speeches at the ABA White Collar Conference: one by DAG Lisa Monaco and a second by Acting Assistant Attorney General Nicole M. Argentieri, which re-emphasized the points I have articulated. Today, I want to use their speeches to add another factor to my Top Ten Lessons List: a Speak Up Culture, effective triage, and quick, efficient, and accurate internal investigation when information is brought forward.

DAG Monaco could not have been clearer when she said, “When a business discovers that its employees broke the law, the company is far better off reporting the violation than waiting for DOJ to discover it. Now, when the DOJ does discover the violation, the company can still reduce its exposure by proactively cooperating in our investigation. But I want to be clear: no matter how good a company’s cooperation, a resolution will always be more favourable with voluntary self-disclosure.” [emphasis supplied]

DAG Monaco noted that the DOJ has structured its “Voluntary Self Disclosure (VSD) programs to encourage companies to take responsibility for misconduct within their organizations. And we’ve conditioned benefits on the company’s willingness to step up and own up — requiring it to disgorge profits, upgrade compliance systems, and cooperate in investigations of culpable employees…We want to empower them to make the business case for investing in compliance. And when they do, they can point to our policies. Early reports on this work are promising. We directed all components and U.S. Attorneys to implement self-disclosure programs.”

The benefits of the VSD come from this self-disclosure. The DOJ’s announcement that it was launching a whistleblower program for payments to people who come forward with information about criminal activity emphasised this idea even more. While the SEC, CFTC, IRS, and other agencies have whistleblower reward programs, this is a powerful message from the DOJ that if your company has an issue, it is far better to self-disclose than investigate, remediate, and hope the DOJ (or any other agency) never finds out about the matter. Put another way, Argentieri spoke about “the benefits that await those that voluntarily disclose misconduct.”

All of this means you must be able to intake, evaluate, and investigate the information.

Culture of Speak Up

Your organization must have an effective and efficient means of allowing employees to raise their hands and speak up. That speak-up can be through an anonymous hotline, by going into their supervisor’s office to report something, or by coming to the compliance function. Or it could be another avenue of reporting. The point is that every company must be ready, willing, and able to hear and act on internal reports of wrongdoing.

Triage

Given the number of ways that information about violations or potential violations can be communicated to government regulators, having a robust triage system is a critical way to separate the wheat from the chaff and bring the correct number of resources to bear on a compliance problem. One important area is determining whether to bring in outside counsel to head up an investigation and the resources you may want or need to commit to a problem. You need to “kick the tyres” of any allegations or information so that you know the circumstances in front of you before you make decisions. You can achieve this through a robust triage process.

Internal Investigations

You can decide whether or not to investigate by consulting with other groups, such as the Compliance Committee of the Board of Directors or the Legal Department. The head of the business unit in which the claim arose may also be notified that an allegation has been made and that the Compliance Department will be handling the matter on a go-forward basis. Using a detailed written procedure, you can ensure complete transparency on all parties’ rights and obligations once an allegation is made. This gives compliance the flexibility and responsibility to deal with such matters, from which it can best assess and decide how to manage them.

We concluded this series where we began with the need for or benefits of self-disclosure. The benefits laid out by the DOJ are clear, tangible, and direct. If you self-disclose, provide extraordinary cooperation, extensively remediate, and disgorge any ill-gotten gains through profit disgorgement, there will be a presumption of declination. Even if you do not meet the self-disclosure threshold, you can still garner significant discounts under the DOJ’s Corporate Enforcement Policy through extraordinary cooperation and extensive remediation.

Categories
Blog

Ten Top Lessons from Recent FCPA Settlements – Lesson No. 3, Extensive Remediation

Over the past 15 months, the Department of Justice (DOJ) and Securities and Exchange Commission (SEC) have made clear, through three Foreign Corrupt Practices Act (FCPA) enforcement actions and speeches, their priorities in investigations, remediations, and best practices compliance programs. Every compliance professional should study these enforcement actions closely for the lessons learned and direct communications from the DOJ. They should guide not simply your actions should you find yourself in an investigation but also how you should think about priorities.

The three FCPA enforcement actions are ABB from December 2022, Albemarle from November 2023, and SAP from January 2024. Taken together, they point out a clear path for the company that finds itself in an investigation, using extensive remediation to avoid monitoring and provide insight for the compliance professional into what the DOJ expects in a best practices compliance program on an ongoing basis.

Over a series of blog posts, I will lay out what I believe are the Top Ten lessons from these enforcement actions for compliance professionals who find themselves in an enforcement action. Today, we continue with Number 3, Extensive Remediation. The DOJ expects extensive remediation, well documented with data analytics to support everything you have done. Each of the companies engaged in extensive remediation.

ABB

The plea agreement said that ABB “took a lot of corrective action,” such as hiring experienced compliance staff and, after figuring out what caused the behavior described in the Statement of Facts, putting a lot more money into testing and monitoring compliance across the whole company; putting in place targeted training programs and extra case-study sessions on-site; and continuing to test and monitor to see how things are going. This final point was expanded on in the SEC Order, which reported that all employees involved in the misconduct were terminated.

At this point, there are not many specific components of the ABB remediation available, but we do know that ABB was given credit for hiring “experienced compliance personnel,” starting with the hiring of Natalia Shehadeh, SVP and Chief Integrity Officer, and then allowing Shehadeh to hire a dream team of compliance professionals to work with her.

Albemarle

The NPA cited several remedial actions by the company that helped Albemarle obtain a superior result regarding the discounted fine and penalty. These steps were taken during the pendency of the DOJ investigation so that when the parties were ready to resolve the matter, Albemarle had built out an effective compliance program and had tested it. The NPA provided that Albemarle engage in the following remedial efforts:

  • Strengthening its anti-corruption compliance program by investing in compliance resources, expanding its compliance function with experienced and qualified personnel, and taking steps to embed compliance and ethical values at all levels of its business organization;
  • Transformed its business model and risk management process to reduce corruption risk in its operation and to embed compliance in the business, including implementing a go-to-market strategy that resulted in eliminating the use of sales agents throughout the Company, terminating hundreds of other third-party sales representatives, such as distributors and resellers, and shifting to a direct sales business model;
  • Provided extensive training to its sales team, restructuring compensation and incentives so that compensation is no longer tied to sales amounts;
  • Used data analytics to monitor and measure the compliance program’s effectiveness and
  • We are engaged in continuous testing, monitoring, and improving all aspects of its compliance program, beginning immediately after identifying misconduct.

SAP

SAP also did an excellent job in its remedial efforts, whether SAP realized that, as a recidivist in dire straits, it was after the publicity in South Africa around corruption or some other reason that the company made major steps to create an effective, operationalized compliance program that met the requirements of the Hallmarks of an Effective Compliance Program as laid out in the 2020 FCPA Resource Guide, 2nd edition.

The remedial actions by SAP can be grouped as follows:

  1. Root Cause, Risk Assessment, and Gap Analysis. After doing a gap analysis of internal controls and fixing any problems found, the company did a root cause analysis of the behavior in question and fixed the issues it found. It then did a full risk assessment, focusing on high-risk areas and controls around payment processes, and used the results to improve its compliance risk assessment process.
  2. Enhancement of Compliance. Here, the company significantly increased the budget, resources, and expertise devoted to compliance; restructured its Offices of Ethics and Compliance to ensure adequate stature, independence, autonomy, and access to executive leadership; enhanced its code of conduct and policies and procedures regarding gifts, hospitality, and the use of third parties; enhanced its reporting, investigations and consequence management processes;
  3. Change in sales models. On the external sales side, SAP eliminated its third-party sales commission model globally, prohibited all sales commissions for public sector contracts in high-risk markets, and enhanced compliance monitoring and audit programs, including creating a well-resourced team devoted to audits of third-party partners and suppliers. On the internal side, SAP adjusted internal compensation incentives to align with compliance objectives and reduce corruption risk.
  4. Data Analytics. Here, SAP expanded its data analytics capabilities to cover over 150 countries, including all high-risk countries globally, and comprehensively used data analytics in its risk assessments.

Each of these entities worked quite diligently to rebuild their compliance programs from the ground up. Whatever the faults of their prior compliance programs, each company was quite diligent in revamping their compliance regimes. While each company builds out a program based on its own risk, there is quite a bit of guidance you can draw from if your company finds itself in this position.

Categories
Blog

The SAP FCPA Enforcement Action-Part 5: Lessons Learned

We conclude our series on the initial Foreign Corrupt Practices Act (FCPA) enforcement action. It involved the German software giant SAP. While the conduct which led to the enforcement action occurred for a lengthy period of time and was literally worldwide in scope, the response by SAP is to be both noted and commended. The hard and impressive work that SAP did during the pendency of the investigation and enforcement action led to a very favorable result for the company in the reduced amount of its assessed fine and penalty as well as the fact that no monitor was mandated by the Department of Justice (DOJ) or Securities and Exchange Commission (SEC). Today, in our final post, we review key lessons learned from the SAP enforcement action.

Remediation

SAP did an excellent job in its remedial efforts. Whether SAP realized as a recidivist of the dire straits it was in after the publicity in South Africa around is corruption or some other reason, the company made major steps to create an effective, operationalized compliance program which met the requirement of the Hallmarks of an Effective Compliance Program as laid out in the 2020 FCPA Resource Guide, 2nd edition.

The remedial actions by SAP can be grouped as follows.

  1. Root Cause, Risk Assessment and Gap Analysis. Here the company conducted a root cause analysis of the underlying conduct then remediating those root causes, conducted a gap analysis of internal controls, remediating those found lacking; and then performed a comprehensive risk assessment focusing on high-risk areas and controls around payment processes, using the information obtained to enhance its compliance risk assessment process;
  2. Enhancement of Compliance. Here the company significantly increasing the budget, resources, and expertise devoted to compliance; restructuring its Offices of Ethics and Compliance to ensure adequate stature, independence, autonomy, and access to executive leadership; enhanced its code of conduct and policies and procedures regarding gifts, hospitality, and the use of third parties; enhanced its reporting, investigations and consequence management processes;
  3. Change in sales models. On the external sales side, SAP eliminated its third-party sales commission model globally, and prohibiting all sales commissions for public sector contracts in high-risk markets and enhanced compliance monitoring and audit programs, including the creation of a well-resourced team devoted to audits of third-party partners and suppliers. On the internal side, SAP adjusted internal compensation incentives to align with compliance objectives and reduce corruption risk;
  4. Data Analytics. Here SAP expanded its data analytics capabilities to cover over 150 countries, including all high-risk countries globally; and comprehensively used data analytics in its risk assessments.

Data Analytics

The references to data analytics and data driven compliance warrant additional consideration. SAP not only did incorporate data analytics into its third-party program but also expanded its data analytics capabilities to cover over 150 countries, including all high-risk countries globally. The SEC Order also noted that SAP had implemented data analytics to identify and review high- risk transactions and third-party controls. The SAP DPA follows the Albemarle FCPA settlement by noting that data analytics is now used by SAP to measure the compliance program’s effectiveness. This language follows a long line of DOJ pronouncements, starting with the 2020 Update to the Evaluation of Corporate Compliance Programs, about the corporate compliance functions access to all company data; this is the second time it has been called out in a FCPA settlement agreement in this manner. Additionally, it appears that by using data analytics, SAP was able to satisfy the DOJ requirement for implementing controls and then effectively testing them throughout the pendency of the DOJ investigation; thereby avoiding a monitor.

Holdbacks

Next was the holdback actions engaged in by SAP. The DPA noted, SAP withheld bonuses totaling $109,141 during the course of its internal investigation from employees who engaged in suspected wrongdoing in connection with the conduct under investigation, or who both (a) had supervisory authority over the employee(s) or business area engaged in the misconduct and (b) knew of, or were willfully blind to, the misconduct, and further engaged in substantial litigation to defend its withholding from those employees, which qualified SAP for an additional fine reduction in the amount of the withheld bonuses under the DOJ’s Compensation Incentives and Clawbacks Pilot Program.

Self-Disclosure

While this factor was not present in the SAP enforcement action, the message sent by the DOJ could not be clearer on not simply the expectation of the DOJ for self-disclosure but also the very clear and demonstrable benefits of self-disclosure. Under the Corporate Enforcement Policy, SAP’s failure to self-disclose cost it an opportunity of at least 50% and up to a 75% reduction off the low end of the U.S. Sentencing Guidelines fine range. Its actions as a criminal recidivist, resulted in it not receiving a reduction of at least 50% and up to 75% from the low end of the U.S.S.G. fine range but rather at 40% from above the low end. SAP’s failure to self-disclose cost it an estimated $20 million under the Sentencing Guidelines. It’s failure to self-disclose and recidivism cost it a potential $94.5 million in discounts under the Corporate Enforcement Policy. The DOJ’s message could not be any clearer.

Extensive Cooperation

There were also lessons to be garnered from SAP’s cooperation with the DOJ. While there was no mention of the super duper, extra-credit giving extensive remediation which Kenneth Polite discussed last year; when SAP began to cooperate, it moved to extensively cooperate. The DPA noted SAP “immediately beginning to cooperate after South African investigative reports made public allegations of the South Africa-related misconduct in 2017 and providing regular, prompt, and detailed updates to the Fraud Section and the Office regarding factual information obtained through its own internal investigation, which allowed the government to preserve and obtain evidence as part of its independent investigation…” Most interestingly, the DPA reported that SAP imaged “the phones of relevant custodians at the beginning of the Company’s internal investigation, thus preserving relevant and highly probative business communications sent on mobile messaging applications.” This is clear instruction around messaging apps in FCPA enforcement actions.

Resources

SEC Order

DOJ DPA