Categories
This Week in FCPA

Episode 282 – The Naughty List Edition


With Jay on a holiday assignment, Tom is joined by Professor Karen Woody to look at some of the week’s top compliance and ethics stories this week in the Naughty List edition.
Stories

  1. JPMorgan tagged $200MM for failures in electronic record keeping. Tom in the FCPA Compliance and Ethics Blog. Matt Kelly in Radical Compliance. Tom and Matt in Compliance into the Weeds.  
  2. Nikola was fined $125MM for the former CEO’s imprudent tweets. Tom in the FCPA Compliance and Ethics Blog. Matt Kelly in Radical Compliance. Jaclyn Jaeger in Compliance Week(sub req’d).
  3. SOX 20 years later. Michael Peregrine looks back at the upcoming 20th anniversary of Sarbanes-Oxley in the Harvard Law School Forum on Corporate Governance
  4. France is updating its ABC regime. Frederick Davis in GAB.   
  5. Another Unaoil defendant appeals conviction based upon SFO misconduct. Dylan Tokar in WSJ Risk and Compliance Journal.
  6. What happened to FCPA Compliance in 2021? Dick Cassin explores in the FCPA Blog.  
  7. The story of internal controls and Netflix? Jonathan Marks in BakerTilly.  
  8. Vietnam imposes a 14-year sentence for wildlife trafficking. Jon Rusch in Dipping Through Geometries
  9. Lawyers and ESG. Lawrence Heim in PracticalESG
  10. Prioritizing your policy updates. David Banks in Risk and Compliance Matters.

Podcasts and Events

  1. Want some fun over the holidays? Join Tom and One Stone Creative co-founder Megan Dougherty to explore the full MCU. In Episode 1, Captain America. In Episode 2, Captain Marvel. Next week in Episode 3, Iron Man.  
  2. In December on The Compliance Life, I visited with Matt Silverman, Director of Trade Compliance at VIAVI. Matt is the first Trade Compliance Director I have hosted on TCL. In Part 1, Matt details his academic career and early professional life. In Part 2, Matt moves into trade compliance. In Part 3, Matt moves into the Director’s chair. 
  3. The Compliance Podcast Network welcomes Professor Karen Woody and her new podcast, Classroom Insider. In this unique pod, Karen interviews some of her students to tell them the history of insider trading. Check out Episode 1 on  Episode 2, the disclosure or abstain rule. In Episode 3 (premiering Dec. 31), they will take up narrowing the scope of the disclose or abstain rule. 
  4. The Shout Outs and Rants of Everything Compliance gets its own iTunes show. Everything Compliance has its first-year end review episode. 
  5. On Hidden Traffic, Gwen Hassan hosts Andrew Wallis, head of Unseen UK.

Tom Fox is the Voice of Compliance and can be reached at tfox@tfoxlaw.com. Karen Woody is a Professor of Law at Washington and Lee. She can be reached at kwoody@wlu.edu. 

Categories
Blog

On the Naughty List – Urban Meyer

We conclude our pre-Christmas Naughty List review and today we have one person who is on the Very Naughty List. That person is now former Jacksonville Jaguars head coach Urban Meyer. The missteps, inanity and downright irresponsible actions taken by Meyer during his abortive less than one season with the Jags is not only one for the annals in National Football League (NFL) history but provides multiple lessons learned for the compliance professional.
Meyer was a very successful college coach winning national titles at two schools, Florida and Ohio State. But he was clearly out of his depth in the NFL, which of course is professional football and not college football. But the red flags were all there for any who cared enough to look. Clearly, they were ignored by the Jags owner, now to his shame and humiliation. It began almost immediately after Meyer’s hiring when he tried to retain a strength and conditioning coach who had been fired at Iowa for allegations of racial abuse.
Michael DiRocco reported, “In February, Meyer hired former Iowa strength coach Chris Doyle, who was accused of making racist remarks and belittling and bullying players while with the Hawkeyes. Doyle resigned a day later after the Jaguars were criticized for the hire by the Fritz Pollard Alliance.” Before the resignation, Meyer had claimed he had done his due diligence on Doyle with Meyer adding, he “did not consider the implications of hiring him.” Later in the summer, the NFL “fined the Jaguars $200,000 and Meyer $100,000 for excessive contact during a June 1 organized team activity. The team also must forfeit two OTAs during the first week of the 2022 offseason, meaning they will have only eight.”
Please note the season had not even started yet.
The Jags got off to an ignominious start losing to the pathetic Houston Texas and began the season 0-4. It was at this point, missteps turned into inanity. After losing to the Cincinnati Bengals to reach 0-4, Meyer did not travel back to Jacksonville with the team but went to Columbus OH to unwind, relax with friends and to visit with his grandchildren. Almost immediately, “a video began circulating on social media on Oct. 1 that showed a woman who was not Meyer’s wife dancing close to his lap at his Columbus restaurant. Meyer apologized in positional group meetings early in the week, then at a news conference and again in a team meeting later in the week. Khan also issued a public rebuke.”
As the losing wore on, Meyer’s true personality came out. Andrew Gastelum, reported that in November Meyer “was involved in multiple disputes with players and coaches over the last two weeks, including a heated argument with receiver Marvin Jones and that Jones was reportedly so angry with Meyer’s criticism of Jaguars receivers that he left the team facility. According to Pelissero, staff convinced the receiver to return only for him to get into a heated argument with Meyer at practice.” Moreover, “Meyer reportedly challenged assistants to defend their résumés individually during a staff meeting where he told his coaching staff that he was a winner and that they were losers.” Of added significance to this reporting was, according to Tom Pelissero, that the sources for this story came from the NFL office, not simply Jag players. Predictably, in an incredibly inane move, as reported by Jordan Dajani, Meyer denied both events ever happened.
Yet even Meyer was capable of achieving another low, moving to complete irresponsibility.
Enraged and wrongfully believing that the source of this latest escapade came from inside the Jags, he announced anyone that blew the whistle on him would be unceremoniously shown the door, as in immediately. Then last week, Ryan Glasspiegel, reported that former Jags kicker Josh Lambo accused of Meyer of kicking him at practice in August. Lambo said, “It certainly wasn’t as hard as he could’ve done it, but it certainly wasn’t a love tap. “Truthfully, I’d register it as a five (out of 10). Which in the workplace, I don’t care if it’s football or not, the boss can’t strike an employee. And for a second, I couldn’t believe it actually happened. Pardon my vulgarity, I said, ‘Don’t you ever f–king kick me again!’ And his response was, ‘I’m the head ball coach, I’ll kick you whenever the f–k I want.’”
Unsurprisingly Meyer denied this also ever happened. Yet this is where complete irresponsibility turns to the surreal. While Meyer was denying the event ever took place, he had his lawyers threatening the reporter who broke the story. But here is the surrealness, as the lawyers did not dispute that Meyer kicked Lambo, only how hard. So, Meyer’s lawyers admit there was an assault, it just was not serious.
Finally, even the Jags owner had enough and when the assault allegations broke, he fired Meyer that night. The owner, Shad Khan claimed that he had intended to fire Meyer after the latest loss on Sunday, but it took him several days to get his ducks in a row. Of course, while the owner was doing so, Meyer was still coaching the Jags. Me thinks something is rotten with that story.
What are the lessons for the compliance professional in all of this?
Let’s start with due diligence. Meyer was penalized in Columbus for his less-than-ethical behavior around an assistant coach accused of assaulting his wife. He somehow managed to lose or deleted multiple text message on the topic. He was suspended for three games by Ohio State for his conduct. All of this was in the public record and there for all to see. Think executive due diligence is not important? Think again (and while you are thinking about it call Candace Tal.)
Internal Controls. Yes, there are internal controls in football. One such control deals with player safety based upon amount of physical contact which can occur during offseason training camp (OTA). Meyer and the Jags were fined for having players engage in contact drills. In typical Meyer fashion, he had the Jags deny the team had done anything wrong as it was the players who simply could not contain themselves.
Discipline. Pro football has a Neanderthal governance structure (with the noted exception of the Green Bay Packers, who exist in a parallel socialist world). There is no public company, no Board overseeing the company. There is an owner and every significant employee reports directly to the owner. Clearly the owner, who did not do due diligence on Meyer’s character, was not going to discipline him. Although he belatedly claimed he was going to do so after the most recent loss, that seems like “Monday Morning Quaterbacking” to me. Do you really think that if any other Jag employee engaged in any of this behavior they would not have been sacked? Discipline must be delivered uniformly and fairly. That is called Institutional Fairness and is the responsibility of the Chief Compliance Officer (CCO). It is also a requirement of a compliance program. As was noted in the original FCPA Resource Guide, compliance has to apply from the “Board room to the shop floor.” Even in the recent Securities and Exchange Commission (SEC) enforcement action involving JPMorgan, the SEC required “an evaluation of who violated policies and why, what penalties were imposed, and whether penalties were handed out consistently across business lines and seniority levels.”
Perhaps now you might understand why Urban Meyer is on the Very Naughty List. But you can use the lessons learned to help keep your organization off the Naughty List in 2022 and beyond.

Categories
Innovation in Compliance

Not Your Father’s Monitor-Part 3: Cristina Revelo on E&C Assessment and Internal Controls

In October, Deputy Attorney General (DAG) Lisa O. Monaco gave a Keynote Address at ABA’s 36th National Institute on White Collar Crime (Monaco Speech). Monaco’s remarks should be studied by every compliance professional as they portend a very large change in the way the DOJ will utilize monitors going forward.

Over this podcast series, sponsored by AMI we will consider why DAG Monaco’s remarks herald a new era for monitorships. We will consider Monaco’s remarks from a variety of perspectives. Bethany Hengsbach will consider this change in monitorships from the white-collar enforcement and defense perspective. Mikhail Reider Gordon will look at global aspects of the new DOJ monitor’s focus. Cristina Revelo will discuss how E&C assessments help drive More compliant companies. Jesse Caplan brings his views on the twin topics of antitrust and healthcare compliance. We will conclude our series with AMI founder Vin DiCianni who will look at where monitors monitorships are going in 2022 and beyond. In this Episode 3, Cristina Revelo brings her internal control expertise to analyze for E&C assessments, particularly with monitors and monitorships.

Highlights of this podcast include:

  1. Monitoring skills will be in demand as we see the rise of proactive monitorships / assessments
  2. Compliance and ethical culture are important considerations to review.
  3. E&C Assessments help companies get ahead of what is coming, mitigate risk, ensure compliance and address any gaps that might exist before a regulator comes knocking on their door.

Resources

Cristina Revelo

Affiliated Monitors Inc.

Categories
Compliance Into the Weeds

Ransomware Attacks and Internal Controls


Compliance into the Weeds is the only weekly podcast which takes a deep dive into a compliance related topic, literally going into the weeds to more fully explore a subject. Today, Matt and Tom take a deep dive into the difference between a privacy breach and a ransomware attack.
Some of the issues we consider are:

  • Why are privacy breaches different from ransomware attacks?
  • What is an authenticated v. unauthenticated cyber-attack?
  • Why would the SEC get involved?
  • What are the internal controls need to prevent and detect a ransomware attack? How will they be audited?
  • How can a material weakness in internal controls around ransomware lead to a financial restatement?
  • What will the SEC look at from an enforcement angle?

Resources
Matt in Radical Compliance

Categories
Blog

Not Your Father’s Monitor – Cristina Revelo, Using Assessments to Drive Compliance

In October, Deputy Attorney General (DAG) Lisa O. Monaco gave a Keynote Address at ABA’s 36th National Institute on White Collar Crime (Monaco Speech). Her remarks reframed a discussion about the uses of, reasons for and perceptions on independent monitors and monitorships. I asked Affiliated Monitors Inc. (AMI) founder Vin DiCianni for his thoughts around the remarks on monitors. He said, “For Affiliated Monitors this refreshed approach by DAG Monaco highlights the seriousness which businesses must place on the investment in their programs and in addressing what has for some been a negative experience with a monitor. For those who might be the subject of a monitorship, DAG Monaco recognized that the negativity that has sometimes surrounded monitorships as being punitive, should be seen in a different light bringing value, pointing a way forward and as a solution which has had great success in resolving matters.”
Monaco’s remarks should be studied by every compliance professional as they portend a very large change in the way the Department of Justice (DOJ) will utilize monitors going forward. Over this podcast series, sponsored by AMI, we will consider why DAG Monaco’s remarks herald a new era for monitorships. We will consider Monaco’s remarks from a variety of perspectives. Bethany Hengsbach will consider this change in monitorships from the white-collar enforcement and defense perspective. Mikhail Reider-Gordon will look at global aspects of the new DOJ monitor’s focus. Jesse Caplan brings his views on the twin topics of antitrust and healthcare compliance. We will conclude the series with Vin DiCianni who will look at where monitorships are going in 2022 and beyond. In Part 3, Cristina Revelo, Deputy Director, Corporate Monitoring and Compliance Services at AMI, discusses how ethics and compliance (E&C) assessments help drive more compliant companies.
Revelo has a different professional background than many compliance professionals, having earned both her Master of Science and Bachelor of Science in Accountancy. We began by exploring why a proactive monitorship can be such a valuable tool in a best practices compliance program. With this an independent monitor can help companies review their ethics and compliance programs. AMI’s vast experience in monitorships under different regulators and requirements gives them insights into what the regulators are looking for in this type of project. With this knowledge from prior monitorships AMI can facilitate a very practical assessment. It can highlight to a company what are some gaps within, for example, their anti-corruption program, ethics program, internal controls, or for their entire E&C program.
This type of approach allows AMI to provide recommendations based on what we think the regulars might be looking for. Revelo noted, “These are great because it helps companies get ahead of potential regulators coming, knocking on their door.” It also allows a company to demonstrate they have been proactively working on their E&C program and that they are seeking to close those gaps and enhance their programs.
We then turned to Revelo’s academic and professional background which gives a different perspective from a legally trained compliance professional. As more individuals with different backgrounds, especially with the auditing and forensic background, Revelo feels it really does help in these proactive assessments because she’s looking to “follow the gaps, follow the issues,  use the five whys, digging a little bit deeper as opposed to potentially just checking that there is a law and that we have complied with the law.” A forensic type will inevitably dig a little bit deeper to understand a company’s internal controls, how they implement their controls, whether those internal controls are manual or automated, where there could be a failure, essentially to walk through the entire process.
Revelo emphasized, “conducting a walkthrough of your entire internal controls process, sitting with different individuals, having interviews, really understanding, whoever is implementing that process. This allows you to really pick apart and identify the different failures that could come up throughout the different controls in the process.” It is really looking at things through a different lens. From there you can move to enhance or remediate as needed. These are the types of skills and analysis an accountant or forensic auditor could bring to a proactive E&C assessment.
Turning to a more commercial reason for proactive assessments, Revelo concluded with an observation about culture. In the ever-increasing race for talent acquisition and talent retention, culture has become one of the most critical factors for millennials as they make up most of the workforce now and will be above 50% of the workforce in a few years. Millennials want to have pride in a place they work, they want to be happy, and money is not the driving factors in their equation. Revelo noted, “they want to work for companies that are ethical, that are socially responsible, that are behind the right things that they care about.” As these areas fall directly within the area of E&C, Revelo said, “I think it’s really important for companies in order to attract the right talent and retain that talent because sometimes also you see millennials moving jobs very often. Those employees a company might want to retain are going to care about what you are behind, how ethical you are, how you treat your employees, and all of this has to do with a company culture and the ethical culture.”
Affiliated Monitors
Cristina Revelo

Categories
Blog

Internal Controls Week: Part 5-Assessing Internal Controls in International Operations

How should you assess your internal controls regime for international operations? It is incumbent that you need to review as much information as you can to understand the financial and operational structure of an entity and how it is integrated with the corporate headquarters, or the U.S. business unit’s financial and operation structure, if the foreign operation is part of a U.S. business unit.
You could begin with the TI-CPI to garner a sense of the reputation of the country in which your business unit is located, as well as the CPI for all other countries in which the location either markets business or has current customers. Another area for inquiry or review is the scope of your foreign operations. This means you will need to consider your sales model, whether employee based or primarily using third party representatives. You will also need to consider if such third-party representatives are coming into a commercial relationship with your company through your supply chain.
Other areas of inquiry should include whether your company’s finance and accounting staff produce financial statements that are integrated into the parent’s financial statements; whether your international business locations utilize a local bank account for local sales receipts as well as funds transfers from the U.S. and whether the account has local check signers and whether dual signatures are required on the checks. You may also want to consider the extent to which disbursements are made in the local currency and, of course, is there a local petty cash fund.
As with many other areas around internal controls, it is important to consider the local DOA and whether it is consistent with your corporate DOA. Some of the considerations regarding the local DOA should extend to which corporate or U.S. business unit approvals are required for transactions initiated locally, such as: 1) approval of vendor invoices, 2) disbursements of funds, including wire transfers; 3) execution of facilities leases; 4) execution of contracts with agents; and 5) approval of pricing and credit terms to customers and distributors. You should also review whether the local DOA provides appropriate SODs at the local business unit level.
You should consider how sales of product are conducted. For example, is an inventory maintained at the local operation for shipment to customers; are products drop shipped from U.S. directly to the customers of the local operation or are they drop shipped to distributors for delivery to the ultimate customer?
Hopefully you are already doing the above, but you should review what is being done to determine if employees or local contractors who are local nationals have gone through your due diligence process so that they have been properly vetted to determine whether they are government officials in any capacity or are relatives of government officials. Along the lines of a more formal FCPA analysis you should review to see if there has been any investigation of alleged fraud, including FCPA violations, at the location and, if so, what were the results of the investigation? Around customers, you should review with whom each international location does business to determine the extent to which its current customers are local government entities as well as the extent to which the location is pursuing sales activities for other local government entities.
If there has not been a sufficient assessment of controls, the compliance professional must then decide how to best determine whether the local controls are sufficient to satisfy the requirement of the FCPA and accurately reflect all transactions and prevent concealment of improper transactions. Some of these considerations would be an inadequate SODs because the separation of responsibility for physical custody of an asset from the related record keeping is a critical control. In practice, this means that persons who can authorize purchase orders should not be capable of processing accounts payable transactions. Further, the employee who prepares the deposit should not post the receipts to the customer accounts.
You should look to see if there is inappropriate access to assets. If there are, internal controls should be created to provide safeguards for physical objects such as inventory and cash, restricted information, critical forms and update applications. This means that an employee who only needs to view computer information should be restricted to “read and file scan” access and should not be granted “write and create” access. Moreover, controls should prevent the unauthorized removal of resale inventory and movable fixed assets from the premises.
It is not necessary to prove a that a bribe has been paid to have an enforcement action against a company for violation of the internal controls provisions of the FCPA. That was the situation in the SEC 2018 FCPA enforcement action involving Kinross Gold Corporation. It was this lack of effective internal controls, not the payment of a bribe, which was the basis for the civil enforcement action. This means that you should look to make certain the situation is not one of form over substance, where controls can appear to be well designed but still lack substance, as is often the case with required approvals.
Such a situation could arise in several different scenarios. The first is where an account manager’s signature attests to the accuracy of the payroll voucher information, but if the account manager does not have assurance that the supporting time records are accurate, the approval process lacks substance. Other examples are where a supervisor who approves expense reports but routinely does not look at the supporting documentation; a country manager provides a true control as an approver; or where the country manager or the local finance manager has ability to conceal the true nature of transactions without detection by anyone else.
Another important area involves sales and compensation for a foreign business unit. On the sales side of the equation, you review the three-year historical sales for the location and the budgeted sales for the upcoming year. This can give insight into the relative pressure on employees to grow the business and, accordingly, the possibility of an employee seeing a bribe as a good way to grow the business. The inquiries can lead to questions about compensation such as: What is the sales incentive compensation plan for local sales personnel? For the country manager? Such an inquiry gives insight into the possibility of personal benefit which might result from someone paying a bribe to win a contract which results in a large sales incentive compensation to the employee.
These reviews, questions, inquiries and analyses are designed to locate the pressure points involved in any company’s sales processes. This is because pressure is a key element of occupational fraud and the risk of fraud, including corruption, increases as the pressure increases. Since corruption is viewed as a subset of fraud, it might be a good time to review the “fraud triangle,” which lays out breeding ground for fraud in the corruption context:

  • Pressure which has financial implications, whether it be personal financial needs that are unmet or pressure to reach sales goals;
  • Rationalization. A fraud perpetrator always rationalizes that he/she is not a criminal and when committing fraud for personal benefit, the perpetrator intends to repay the money; when committing fraud for company benefit, the perpetrator rationalizes that the company really wants to meet its goals and that the perpetrator’s actions are in furtherance of the company’s goals; and
  • Opportunity. The perpetrator must be in a situation where the internal controls do not prevent the fraud and its necessary concealment
Categories
Blog

Internal Controls Week: Part 4 – Internal Controls in International Operations

Today, I want to consider some of the issues around internal controls outside the U.S. and why your company’s internal controls might require changes for different countries across the globe. However, this provides an opportunity to further operationalize your compliance program through internal controls more narrowly tailored to mirror your business practices.
Every CCO should consider entity-wide internal controls for a company. Under the FCPA accounting provisions, issuers can be held liable for the conduct of their foreign subsidiaries, even though the improper conduct occurred outside of the U.S. The scope of liability is based on the issuer’s incorporation of the subsidiary’s financial statements in its own records and SEC filings. So, as with the use of third-party distributors to sell product, FCPA enforcement looks past the structure of the transaction and makes enforcement decisions based upon the substance.
While a CCO should expect (or at least hope) that internal controls at locations outside the U.S. are of the same effectiveness as internal controls within U.S. business units and at the U.S. corporate office; unfortunately, that might not always be the case. It is often the case that corporate level internal controls are stronger than those in foreign business units. There may well be several reasons for this. First, the CFO may be paying closer attention to the corporate level internal controls, with the idea that the corporate level internal controls are the final “filter” to detect issues. This follows partly from the focus in most companies on the controls over financial reporting, which does not include all controls needed for compliance. A second reason is that many companies were built through acquisitions, resulting in many business units (both in and outside the U.S.) having completely different accounting, ERP and internal control systems than the corporate office. There is often a tendency to leave acquired companies in the state in which they were acquired, rather than trying to integrate their controls and conform them to those of current business units. After all, the reason for the acquisition was the profitability of the acquired company and nobody wants to be accused of negatively impacting profitability.
A third situation may exist at locations outside the U.S. with what began simply as a sales office and then expanded its scope of operations to become a business unit with its own accounting and data processing functions. Unfortunately, it is not often the situation where there was a master plan for internal controls as the location’s scope grew. Processes are usually added and designed by the local personnel which, in practice, means the country manager has total control over financial affairs and is not truly accountable to the corporate office. This can be particularly true as long as a country business unit’s profits continue. In such situations, there will rarely be any focus on effective preventive internal controls for compliance risk.
Where should a CCO begin in any of the above scenarios? The first step is to determine the extent of centralization or decentralization of relevant processes or, put another way, to what extent are relevant processes performed at the corporate offices? In some companies it is common, for example, to have all vendor invoices paid from the corporate office, whereas in others the corporate accounting function only aggregates information received from business unit accounting departments. This translates into a varying analysis of risk regarding locations outside the U.S., depending on the degree of accounting decentralization. A good starting point is to determine the extent to which the financial statements of non-U.S. business units are reviewed and analyzed by the corporate accounting function. This will give good insight into whether the corporate accounting function provides an element of internal control or merely serves as a data aggregator.
The second step for the CCO is to determine the possible universe of risks and to assess the risks to result in a priority of how attention will be focused. One useful approach advocated is performing a location risk assessment, whose purpose is to capture in one place each location outside the U.S. where your company conducts business and to assess the compliance risks posed by the nature of operations at each location. Once the risks at each location have been properly categorized, you can then prioritize your approach to dealing with the risks.

Categories
Blog

Internal Controls in Compliance: Part 3-Key Compliance Internal Controls

There are four significant controls that I would suggest the compliance practitioner implement initially. They are: 1) DOA; 2) maintenance of the vendor master file; 3) contracts with third parties; and 4) movement of cash/currency.
Your DOA should reflect the impact of compliance risk including both transactions and geographic location so that a higher level of approval for matters involving third parties, for fund transfers and invoice payments to countries outside the U.S. would be required inside your company. While it is quite often true that a DOA is prepared without much thought given to compliance risks, once a DOA is prepared it is not used again until it is time to update for personnel changes. Moreover, it is often not available, not kept current, and/or does not define authority in a way even the approvers could understand it. Therefore, it is incumbent that the DOA be integrated into a company’s accounts payable processing system in a manner that ensures all high-risk vendor invoices receive the proper visibility. To achieve this, you should identify the vendors within the vendor master file so payments are flagged for the appropriate approval beforethey are paid. If a DOA is properly prepared and enforced, it can be a powerful preventive tool for compliance.
The vendor master file can be one of the most powerful preventative control tools largely because payments to fictitious vendors are one of the most common occupational frauds. The vendor master file should be structured so that each vendor can be identified not only by risk level but also by the date on which the vetting was completed and the vendor received final approval. There should be electronic controls in place to block payments to any vendor for which vetting has not been approved. Next manual controls are needed over the submission, approval, and input of changes to the vendor master file. These controls include verification that all vendors have been approved before their information (and the vendor approval date) is input into the vendor master. Finally, manual controls are also needed when “one time” vendors are requested, when a vendor name and/or vendor payment information changes are submitted.
Near and dear to my heart as a lawyer are contracts with third parties. These can be a very effective internal control which works to prevent nefarious conduct rather than simply as a detect control. I would caution that for contracts to provide effective internal controls, relevant terms of those contracts, including for instance the commission rate, reimbursement of business expenses, use of subagents, etc., should be made available to those who process and approve vendor invoices. If there are nonconforming service descriptions or commission rates present in a contract, the terms must be approved not only by the original approver but also by the person so delegated in the DOA. Unfortunately, contracts are not typically integrated into the internal control system. They are left off to the side on their own, usually gathering dust in the legal department file room.
The Hewlett-Packard (HP) FCPA enforcement action was an excellent example of the lack of internal control over the disbursements of funds and movement of currency because you had the country manager delivering bags of cash to a Polish government official to obtain or retain business. All situations where funds can be sent outside the U.S., including such methods accounts payable computer checks, manual checks, wire transfers, replenishment of petty cash, loans or advances, should all be reviewed from the compliance risk standpoint. This means you need to identify the ways in which a country manager or a sales manager could cause funds to be transferred to their control and to conceal the true nature of the use of the funds within the accounting system.
To prevent these types of activities internal controls, need to be in place. This means all wire transfers outside the U.S. should have defined approvals in the DOA, and the persons who execute the wire transfers should be required to evidence agreement of the approvals to the DOA and wire transfer requests going out of the U.S. should always require dual approvals. Lastly, wire transfer requests going outside the U.S. should be required to include a description of proper business purpose.
The bottom line is that internal controls are just good financial controls. The internal controls that detail requirements for third party representatives in the compliance context will help to detect fraud, which could well lead to bribery and corruption.

Categories
Blog

Internal Controls in Compliance: Part 2-Rigor In Your Internal Controls

New York Times columnist David Brooks’ thoughts on building and maintaining order inform the discussion on rigor in your internal controls. In internal controls, I believe it is incumbent to consider not only the most obvious risk areas for your internal controls but also the universe of potential transactions within the operations of a company. There is a clear need for rigor in your internal controls protocols and adherence to that rigor can increase operationalization around the internal controls a company should consider including gifts, travel and entertainment expenses.
One area that companies need to be mindful of is corporate checks and wire transfers, in response to falsified supporting documentation, such as check requests, purchase orders, or vendor invoices. The Delegation of Authority (DOA) is a critical internal control. For example, a wire transfer of $X between company bank accounts in the US might require approval by the Finance Manager at the initiating location and one officer. However, a wire transfer of $X to the company’s bank account in Nigeria, could require approval by the Finance Manager, a knowledgeable person in the compliance function, and one officer. The key is that the DOA should specify who must give the final approval for such an expense.
Petty cash disbursements in locations outside the US have unique control issues. Some petty cash funds outside the US have small balances but substantial throughput of transactions. Your DOA should address replenishment of petty cash funds in countries outside the US, as well as approval of expense reports for employees who work outside the US, including those who travel from the US to work outside the US
Another area for concern is travel, the reason for this being that a company’s corporate travel department and independent travel agencies can buy tickets, hotel rooms, etc., for non-employees. Internal controls might be needed to ensure policies are enforced when travel for non-employees can be purchased through a corporate travel department or through independent travel agencies. As was demonstrated with the GlaxoSmithKline plc (GSK) bribery and corruption criminal conviction in China, a company must not discount the risk related to abuse of power internally and collusion with independent travel agencies. You should implement procedures to ensure compliance with your company policies regarding payment of travel and related expenses for third parties, for not only visits to manufacturing or job sites but also any compliance restrictions that might be in place.
An area for fraud, corruption and corporate abuse has long been P-Cards. If your company uses P-Cards, assume this to be a very high-risk area, not just for bribery and corruption but also for fraud risk generally. Banks have made a great selling job to corporations for the use of P-Cards to help to facilitate “cash management” but, more often than not, they can simply be a streamlined way to allow embezzlement and misbehavior to go undetected. Here a control objective should be put in place along the lines of a written policy and procedure defining the acceptable and unacceptable use of company P-Cards, required forms, required approvals, documentation and review requirements.
If the pre-approval process and strong controls over expense reports prevent misbehavior, employees who wish to misbehave will seek other ways to do it where controls are not so strong. This means you should use your risk assessment process to help prioritize where controls are most needed. If your company prohibits gifts and any travel other than for the submitting employee from being included in the expense report, you should consider requiring instead a check request form be used, which would be subject to stringent controls. In such cases a checklist should be completed and attached to the request which includes questions and disclosures designed to flush out exactly what was provided in the way of a business class airline, pocket money, event tickets, side trips, leisure activities, spouses or other relatives who might be traveling and why the travel had business purpose. Such an internal control would allow for a more streamlined processing of expense reports and still elevates the items to the appropriate level of review and requires appropriate documentation.
One question I am often asked is why does a company need internal controls in place regarding gifts because in many companies internal audits of these expense reports are common? It is important to keep in mind that, with respect to gifts, travel and entertainment, internal audits most often constitute, at best, a detect control, which only gives comfort for some historical period and is not necessarily representative of the controls in place to prevent future violations. So, it will be a false sense of security if a compliance officer relies on the internal audit of expense reports to be the control needed over violation of gift policies.
Brooks said, “Building and maintaining order…requires toughness of mind and rigid discipline to properly serve your own work.” By having the rigor to institute and enforce the types of internal controls identified, you can go a long way towards detecting and, more importantly, preventing a Foreign Corrupt Practices Act (FCPA) violation from occurring.

Categories
Blog

Internal Controls in Compliance: Part 1-What are Internal Controls?

What specifically are internal controls in a compliance program? Internal controls are not only the foundation of a company but are also the foundation of any effective anti-corruption compliance program. The starting point is the FCPA itself, which states the following:
Section 13(b)(2)(B) of the Exchange Act (15 U.S.C. § 78m(b)(2)(B)), commonly called the “internal controls” provision, requires issuers to devise and maintain a system of internal accounting controls sufficient to provide reasonable assurances that—
(i) transactions are executed in accordance with management’s general or specific authorization;
(ii) transactions are recorded as necessary (I) to permit preparation of financial statements in conformity with generally accepted accounting principles or any other criteria applicable to such statements, and (II) to maintain accountability for assets;
(iii) access to assets is permitted only in accordance with management’s general or specific authorization; and
(iv) the recorded accountability for assets is compared with the existing assets at reasonable intervals and appropriate action is taken with respect to any
differences ….
The DOJ and SEC, in the  FCPA Resource Guide, 2nd edition, stated:
Internal controls over financial reporting are the processes used by compa­nies to provide reasonable assurances regarding the reliabil­ity of financial reporting and the preparation of financial statements. They include various components, such as: a control environment that covers the tone set by the organi­zation regarding integrity and ethics; risk assessments; con­trol activities that cover policies and procedures designed to ensure that management directives are carried out (e.g., approvals, authorizations, reconciliations, and segregation of duties); information and communication; and monitoring.
…the design of a company’s internal controls must take into account the operational realities and risks attendant to the company’s business, such as: the nature of its products or services; how the products or services get to market; the nature of its work force; the degree of regulation; the extent of its government interaction; and the degree to which it has operations in countries with a high risk of corruption.
Perhaps the best definition I have ever heard came from Jonathan Marks, Partner at Baker Tilly, who defined an internal control as
Internal controls expert Joe Howell, former Executive Vice President (EVP) at Workiva, Inc., has said that internal controls are systematic measures, such as reviews, checks and balances, methods and procedures, instituted by an organization that performs several different functions. These functions include allowing a company to conduct its business in an orderly and efficient manner; to safeguard its assets and resources, to detect and deter errors, fraud, and theft; to assist an organization ensuring the accuracy and completeness of its accounting data; to enable a business to produce reliable and timely financial and management information; and to help an entity to ensure there is adherence to its policies and plans by its employees, applicable third parties and others. Howell adds that internal controls are entity wide; that is, they are not just limited to the accountants and auditors. Howell also notes that for compliance purposes, controls are those measures specifically to provide reasonable assurance any assets or resources of a company cannot be used to pay a bribe. This definition includes diversion of company assets, such as by unauthorized sales discounts or receivables write-offs as well as the distribution of assets.
The COSO, in its 2013 publication entitled “Internal Controls – Integrated Framework”, defined internal controls as “a process, effected by an entity’s board of directors, management, and other personnel, designed to provide reasonable assurance regarding the achievement of objectives relating to operations, reporting, and compliance.” More specifically, internal controls are, according to COSO:

  • Geared to the achievement of objectives in one or more categories – operations, reporting, and compliance
  • A process consisting of ongoing tasks and activities – a means to an end, not an end in itself
  • Effected by people – not merely about policy and procedure manuals, systems, and forms, but about people and the actions they take at every level of an organization to affect internal control
  • Able to provide reasonable assurance – but not absolute assurance, to an entity’s senior management and board of directors
  • Adaptable to the entity structure – flexible in application for the entire entity or for a particular subsidiary, division, operating unit, or business process

The Integrated Framework goes on to note, “This definition is intentionally broad. It captures important concepts that are fundamental to how organizations design, implement, and conduct internal control, providing a basis for application across organizations that operate in different entity structures, industries, and geographic regions.”
Why are internal controls important in your compliance program? Two FCPA enforcement actions demonstrate the reason. The first came in late 2013 when the DOJ obtained a criminal plea from Weatherford International. There were three areas where Weatherford failed to institute appropriate internal controls. First, around third parties and business transactions, limits of authority and documentation requirements. Second, on effectively evaluating business transactions, including acquisitions and JVs, for corruption risks and to investigate those risks when detected. Finally, in the area of gifts, travel and entertainment expenses, they were not adequately vetted to ensure that they were reasonable, bona fide, and properly documented.
The second case involved the SEC 2017 FCPA enforcement action with Halliburton. In this matter, Halliburton’s internal controls were circumvented and over-ridden which led to a FCPA violation without evidence of a bribe being paid. It was a civil FCPA enforcement action. It demonstrated that internal controls must be shown to be effect under the FCPA and without such a showing there can be a large financial penalty paid by a violator.
The whole concept of internal controls is that companies need to focus on where the risks are, whether they be compliance risks or other, and they need to allocate their limited resources to putting controls in place that address those risks, and in the compliance world, of course, your two big risks are the assets or resources of a company. Not just cash but inventory, fixed assets etc., being used to pay a bribe, and then the second big element would be diversion of company assets, such as unauthorized sales discounts or receivables and write offs, which are used to pay a bribe.
As an exercise, I suggest that you map your existing internal controls to the Ten Hallmarks of an Effective Compliance Program or some other well-known anti-corruption regime to see where control gaps may exist. This will help you to determine whether adequate compliance internal controls are present. From there you can move to see if they are working in practice or “functioning.” Internal controls will only become more important in FCPA enforcement. In this chapter, you will learn how to get ahead of the curve.