Categories
Compliance Tip of the Day

Compliance Tip of the Day: Lessons on Root Cause Analysis from John Deere

Welcome to “Compliance Tip of the Day,” the podcast where we bring you daily insights and practical advice on navigating the ever-evolving landscape of compliance and regulatory requirements.

Whether you’re a seasoned compliance professional or just starting your journey, our aim is to provide you with bite-sized, actionable tips to help you stay on top of your compliance game.

Join us as we explore the latest industry trends, share best practices, and demystify complex compliance issues to keep your organization on the right side of the law.

Tune in daily for your dose of compliance wisdom, and let’s make compliance a little less daunting, one tip at a time.

Not only does the DOJ expect companies to perform a Root Cause Analysis during any investigation, but a RCA helps to identify systemic issues for remediation.

Categories
Compliance Tip of the Day

Compliance Tip of the Day: Lessons on Preventing Corrupt Payments from John Deere

Welcome to “Compliance Tip of the Day,” the podcast where we bring you daily insights and practical advice on navigating the ever-evolving landscape of compliance and regulatory requirements.

Whether you’re a seasoned compliance professional or just starting your journey, our aim is to provide you with bite-sized, actionable tips to help you stay on top of your compliance game.

Join us as we explore the latest industry trends, share best practices, and demystify complex compliance issues to keep your organization on the right side of the law.

Tune in daily for your dose of compliance wisdom, and let’s make compliance a little less daunting, one tip at a time.

The Deere enforcement action case offers valuable lessons on the importance of monitoring, oversight, and due diligence—especially when dealing with third-party agents.

Categories
Compliance Tip of the Day

Compliance Tip of the Day: Lessons on Post – Acquisition Integration and Investigation in M&A from John Deere

Welcome to “Compliance Tip of the Day,” the podcast where we bring you daily insights and practical advice on navigating the ever-evolving landscape of compliance and regulatory requirements.

Whether you’re a seasoned compliance professional or just starting your journey, our aim is to provide you with bite-sized, actionable tips to help you stay on top of your compliance game.

Join us as we explore the latest industry trends, share best practices, and demystify complex compliance issues to keep your organization on the right side of the law.

Tune in daily for your dose of compliance wisdom, and let’s make compliance a little less daunting, one tip at a time.

The rules for compliance programs on post-acquisition integration and investigation are set out in the DOJ M&A Safe Harbor Policy. Learn and implement them.

Categories
Compliance Tip of the Day

Compliance Tip of the Day: Lessons on Pre-Acquisition Due Diligence in M&A from John Deere

Welcome to “Compliance Tip of the Day,” the podcast where we bring you daily insights and practical advice on navigating the ever-evolving landscape of compliance and regulatory requirements.

Whether you’re a seasoned compliance professional or just starting your journey, our aim is to provide you with bite-sized, actionable tips to help you stay on top of your compliance game.

Join us as we explore the latest industry trends, share best practices, and demystify complex compliance issues to keep your organization on the right side of the law.

Tune in daily for your dose of compliance wisdom, and let’s make compliance a little less daunting, one tip at a time.

Inadequate pre-acquisition due diligence can put your company in serious legal, compliance, and reputational jeopardy.

Categories
Compliance Tip of the Day

Compliance Tip of the Day: Lessons on GTE from John Deere

Welcome to “Compliance Tip of the Day,” the podcast where we bring you daily insights and practical advice on navigating the ever-evolving landscape of compliance and regulatory requirements.

Whether you’re a seasoned compliance professional or just starting your journey, our aim is to provide you with bite-sized, actionable tips to help you stay on top of your compliance game.

Join us as we explore the latest industry trends, share best practices, and demystify complex compliance issues to keep your organization on the right side of the law.

Tune in daily for your dose of compliance wisdom, and let’s make compliance a little less daunting, one tip at a time.

The foundation of any effective whistleblower program is a clear, robust policy that is communicated effectively across the organization.

Categories
Blog

Deere FCPA Enforcement Action: Lessons on Pre-Acquisition Due Diligence in M&A

We recently had a Foreign Corrupt Practices Act (FCPA) enforcement action that reminded me that everything old is new again in anti-corruption compliance. The Securities and Exchange Commission (SEC) FCPA enforcement action involving Deere has bribery schemes that were torn literally from the first decade of the 21st century as they involved gifts, travel, and entertainment. In other words, it was about a low set of hanging fruit that any compliance officer would see. Today, I continue a multipart look at the case and see what lessons the enforcement action can provide to the 2024 compliance professional.

John Deere, a global leader in agricultural machinery manufacturing, became the focus of an FCPA enforcement action due to its acquisition of a foreign entity with significant operations in countries with high corruption risks. The acquired company had little in the way of a formal compliance program and had been engaging in questionable business practices, including bribing foreign officials to secure contracts.

Post-acquisition, these corrupt practices continued for a period, undetected by Deere’s compliance team. When the issues finally surfaced, the result was a significant FCPA investigation, costly penalties, and a tarnished reputation.

The core issue in this case? Inadequate pre-acquisition due diligence.

One of the central themes from the Deere case is the critical need for rigorous pre-acquisition due diligence in M&A. As a compliance professional, it’s your role to ensure that your organization is not inheriting illegal practices or corruption risks when acquiring a new entity. The risks of overlooking this step can be immense—both in terms of regulatory enforcement and damage to your organization’s reputation.

Let’s examine the key lessons from the Deere case and explore how compliance professionals can apply them to their M&A strategies.

  1. Conduct a Thorough Corruption Risk Assessment

The Deere case underscores the importance of assessing a target company’s corruption risk profile. This means understanding the countries where the target operates and the inherent risks associated with those jurisdictions. Countries with a high Corruption Perceptions Index (CPI) score are more likely to expose your organization to FCPA risks.

Before any acquisition, a detailed analysis of the target’s business activities in these regions must be conducted. Ask yourself:

  • How much business is done with government entities?
  • Are third-party intermediaries involved in securing contracts?
  • What are the target company’s existing compliance policies?

In Deere’s case, the acquired company operated in high-risk jurisdictions without adequate controls. A robust pre-acquisition risk assessment could have flagged this issue, allowing Deere to either walk away from the deal or insist on corrective actions before proceeding.

  1. Evaluate the Target’s Compliance Program and Culture

Another key lesson from the Deere enforcement is the need to evaluate a company’s business operations, corporate culture, and compliance program—or lack thereof. A target company may have all the right words on paper, but those policies are meaningless if the culture does not support ethical business practices.

In the Deere case, the acquired company had minimal compliance structures. This should have raised immediate red flags for Deere’s compliance team, but the issue needed to be addressed or given more weight during the due diligence process.

As a compliance professional, you must:

  • Review existing policies and procedures to assess their adequacy.
  • Interview key personnel to understand how those policies are implemented and followed.
  • Examine the company’s culture to see if ethical business practices are truly embedded in day-to-day operations.

A proactive approach would have helped Deere spot these weaknesses before the acquisition, allowing them to implement a more effective compliance integration strategy.

  1. Look for Red Flags in the Target’s Financial and Operational Data

Financial data can often reveal hidden compliance risks. In the Deere case, irregularities in how contracts were won, especially in high-risk countries, should have raised concerns. Yet, these issues were only caught after the acquisition.

During pre-acquisition due diligence, compliance teams should partner with the finance and audit departments to:

  • Review contracts and agreements with a special focus on deals involving government entities or third parties.
  • Analyze payment patterns for signs of improper payments, such as unusually high commissions or payments to offshore accounts.
  • Investigate any prior audits or investigations related to compliance or financial irregularities.

These financial indicators are often the first signs of deeper corruption issues and should be fully explored before moving forward with any acquisition.

  1. Engage Third-Party Experts When Necessary

In many cases, particularly when acquiring companies in high-risk jurisdictions, it is wise to engage third-party experts to conduct a thorough FCPA-focused due diligence. These experts can bring an external perspective and often have access to local intelligence that may not be readily available to an internal compliance team.

Had Deere engaged such experts during its pre-acquisition process, they may have been able to identify the corrupt practices that eventually led to the FCPA enforcement action.

Engaging external resources is an investment in mitigating future risks. While it may increase upfront costs, the long-term savings in avoiding penalties, legal costs, and reputational damage far outweigh the initial expense.

  1. Ensure Post-Acquisition Integration is Swift and Effective

Even if certain risks are identified during the pre-acquisition phase, the true test comes during post-acquisition integration. In the Deere case, there was a failure to implement effective compliance controls post-acquisition quickly, allowing the corrupt practices to continue unchecked for a period.

Compliance professionals must ensure that:

  • Compliance policies are integrated quickly into the acquired entity’s operations.
  • Training is provided to the acquired company’s employees on FCPA and anti-corruption best practices.
  • Ongoing monitoring ensures that any potential risks identified during due diligence are mitigated.

The Deere FCPA enforcement action is a cautionary tale for all compliance professionals engaged in M&A activity. Pre-acquisition due diligence is not just a box-ticking exercise but a critical function that can help prevent serious legal and financial consequences for your organization. By conducting thorough corruption risk assessments, evaluating compliance programs and culture, scrutinizing financial data, engaging third-party experts when necessary, and ensuring effective post-acquisition integration, compliance professionals can help their organizations navigate the complexities of M&A in today’s global business environment.

The lessons from Deere reminds us that robust due diligence is the first line of defense in preventing FCPA violations and safeguarding a company’s reputation. Do not wait until after the acquisition to address these issues, as it may be too late.

Categories
Compliance Tip of the Day

Compliance Tip of the Day: Everything Old is New Again: The John Deere FCPA Enforcement Action

Welcome to “Compliance Tip of the Day,” the podcast where we bring you daily insights and practical advice on navigating the ever-evolving landscape of compliance and regulatory requirements.

Whether you’re a seasoned compliance professional or just starting your journey, our aim is to provide you with bite-sized, actionable tips to help you stay on top of your compliance game.

Join us as we explore the latest industry trends, share best practices, and demystify complex compliance issues to keep your organization on the right side of the law.

Tune in daily for your dose of compliance wisdom, and let’s make compliance a little less daunting, one tip at a time.

Today we review the basics of the John Deere enforcement action and why it is so instructive for compliance professionals.

 

Categories
Blog

The John Deere’s FCPA Case: A Throwback to Compliance Fundamentals

In corporate compliance, some very basic compliance lessons are destined to be repeated. This was clear from the recently announced Securities and Exchange Commission (SEC) Foreign Corruption Practices Act enforcement action involving Deere (John Deere herein). The $9.9 million settlement between John Deere and the SEC involved FCPA violations at its Wirtgen Group subsidiary. It offers a stark reminder that even the most established companies can stumble over basic compliance principles. For those in the compliance community, this case highlights the importance of robust integration post-acquisition and serves as a throwback to classic FCPA pitfalls that should have been avoided.

The John Deere Case: A Synopsis

According to the SEC Press Release announcing the resolution, “From at least late 2017 through 2020, Wirtgen Thailand employees bribed Thai government officials with the Royal Thai Air Force, the Department of Highways, and the Department of Rural Roads to win multiple government contracts and also bribed employees of a private company to win sales to that company. The order finds that the bribes included cash payments, massage parlor visits, and international travel for government officials and private company employees. According to the SEC’s order, Wirtgen Thailand made approximately $4.3 million in profits” from these bribes. The improper payments were inaccurately recorded as legitimate expenses in Deere’s books and records.

The settlement resulted in John Deere paying $9.9 million in penalties and disgorgements. While the case details could easily be mistaken for a compliance nightmare from the early 2000s, it happened just last year, making it a timely cautionary tale for compliance professionals today.

The Importance of Post-Acquisition Integration

One of the most glaring issues in this case was John Deere’s failure to integrate Wirtgen’s operations into its compliance program swiftly. This lapse is a textbook example of the risks arising when companies fail to prioritize compliance during and after mergers and acquisitions. The SEC’s settlement order emphasized this point, making it clear that Deere’s delay in extending its compliance framework to Wirtgen created an environment where bribery and corruption could thrive unchecked.

This raises critical questions for compliance professionals: How quickly can we realistically integrate an acquired company into our compliance program? What resources are needed to ensure this integration happens efficiently? The answers to these questions are theoretical; they have real-world implications for preventing violations and avoiding costly enforcement actions.

The Role of Internal Controls and Red Flags

The SEC’s order also highlighted several internal control failures and red flags Deere’s compliance team should have caught regarding gifts, travel, and entertainment (GTE). Expense reports with round numbers, lack of detail in expense documentation, and including non-existent employees to justify expenses are all classic indicators of fraud and bribery. Yet, these obvious signs were missed—or worse, ignored. What makes all of this even more egregious is that the rules around gifts, travel, and entertainment for clients have long been known, since at least 2007 when the Department of Justice (DOJ) issued Opinion Releases 07-01 and 07-02, which detailed the DOJ’s expectations for GTE going forward.

This oversight suggests a deeper issue: a lack of robust internal audit and compliance mechanisms within Deere at the time. It is a stark reminder that strong internal controls are not just a regulatory requirement but essential tools for detecting and preventing unethical behavior. The lesson for compliance officers is to continually assess and strengthen these controls, ensuring they can identify red flags before they escalate into full-blown violations.

The Perennial Importance of Pre-Acquisition Due Diligence

Another critical aspect of this case is the apparent need for thorough pre-acquisition due diligence. The SEC’s order does not mention evidence of John Deere conducting such due diligence before acquiring Wirtgen, raising serious concerns about the company’s risk assessment process. In high-risk markets like Thailand, where corruption is pervasive, skipping or skimping due diligence can be costly.

Compliance professionals should take this as a reminder to prioritize comprehensive due diligence in any acquisition, especially when the target operates in regions of corruption risks. This includes reviewing the target’s compliance program and understanding its business practices, key relationships, and potential vulnerabilities. As Deere’s case demonstrates, failure to do so can expose a company to significant legal and financial liabilities.

Positive Steps and Root Cause Analysis

While the case against John Deere is filled with the company’s missteps, the company’s response post-settlement also offers some positive lessons. John Deere has enhanced its internal audit and compliance programs, including launching an in-house compliance podcast and a bi-monthly compliance newsletter. These initiatives reflect an effort to improve the company’s tone at the top and engage employees in ongoing compliance education.

Moreover, Deere’s commitment to conducting a root cause analysis is particularly noteworthy. We saw this set out by the DOJ in its enforcement action involving SAP earlier this year. Understanding the root causes of compliance failures is crucial for preventing future violations. In this case, the root cause seems to stem from a failure to integrate Wirtgen into John Deere’s compliance framework rather than from deficiencies in accounting or transparency. This distinction highlights the need for companies to identify compliance gaps and address the underlying issues that allow those gaps to exist in the first place.

For compliance professionals, the takeaway is clear: a robust root cause analysis is a vital component of any remediation effort. Whether conducted by the compliance team, internal audit, or an external party, this analysis should be thorough and inform subsequent risk assessments and program improvements.

Learning from the Past

In many ways, the John Deere case feels like a throwback to the early days of FCPA enforcement, when companies were still learning the ropes of anti-bribery compliance. The violations at Wirtgen Thailand are reminiscent of the kind of misconduct that the DOJ and SEC have warned against for over a decade, with the GTE issues mandated nearly 15 years ago. Yet, here we are in 2024, still grappling with the same basic issues.

The John Deere enforcement action serves as a sobering reminder that the fundamentals of compliance—strong internal controls, thorough due diligence, timely post-acquisition integration, and ongoing risk assessment—are as relevant today as they were 20 years ago. The challenge for compliance professionals is ensuring that these fundamentals are understood and deeply embedded in the company’s culture and operations.

Ultimately, the John Deere case is a call to action for the compliance community. It reminds us that even large, sophisticated companies can falter if they lose sight of the basics. It prompts us to revisit those basics in our organizations, ensuring that we are not just keeping up with the latest trends in compliance but also mastering the fundamentals that will protect our companies from tomorrow’s risks.