Categories
Blog

Executive Compliance Comp and Compliance: From Incentives to Clawbacks

There are two problems that every company must deal with at the intersection of executive compensation and compliance. The first is the presence of perverse incentives within organizations, where executives are often encouraged to take excessive risks because they personally profit from them. This misalignment of incentives can lead to unethical behavior and non-compliance, ultimately harming the organization and its stakeholders. The second is both the Securities and Exchange Commission (SEC) and Department of Justice (DOJ) mandates for executive clawbacks.

Incentives

To address this issue, companies need to tie positive incentives directly to senior executives. By holding them accountable for compliance failures, we can align their compensation with compliance objectives. This approach ensures that executives have a personal stake in maintaining ethical practices within the organization. What makes this approach unique is that it is a business response to a legal problem, rather than a government mandate. A business response is always a better way to go, as it allows organizations to take ownership of their compliance programs and tailor them to their specific needs.

Various proposals are discussed in the podcast to ensure senior executives are held personally accountable for compliance failures. One solution, suggested by William Dudley, former president of the Federal Reserve Bank of New York, is for senior management and material risk takers to forfeit their performance bond in the case of large fines. This not only disciplines individual behavior and decision-making but also incentivizes individuals to flag issues when problems arise.

Another approach, outlined in an article titled “Ties That Bind Codes of Conduct,” recommends automatic reduction of pay for officers, directors, and advisors for failures of corporate governance. Executives would agree to pay back a portion of their gross compensation for a set period before the beginning of any improprieties, regardless of their knowledge of misdeeds within the company.

While corporate leaders may not be enthusiastic about being held accountable, these proposals offer a business solution to a legal problem. Holding senior executives responsible for the conduct of others aligns with their obligations under Sarbanes-Oxley and ensures that they are not shielded from the consequences of non-compliance. Shareholders are also becoming less accepting of the argument that leaders should not be responsible for the actions of their employees.

Data from an article by Gretchen Morgenson titled “Ways to Put Your Boss’s Skin in the Game” further supports the need for accountability in executive compensation. The article explores how to make senior executives more responsible for corporate malfeasance, with implications that apply to compliance programs and compensation tied to compliance.  Creating accountability in executive compensation is a critical step towards promoting ethical business practices and compliance within organizations. By tying positive incentives to senior executives, we can ensure that they have a personal stake in maintaining compliance objectives. The proposals discussed in the podcast, such as forfeiting performance bonds and enforcing pay reductions for failures of corporate governance, offer practical solutions to address perverse incentives and drive ethical behavior.

Clawbacks

Clawbacks, often seen as a form of guarantee for businesses, play a vital role in addressing employee misconduct. These provisions, typically included in written contracts, serve as a deterrent and allow organizations to reclaim incentive or bonus funds from employees engaged in wrongful activities. It is important to note that clawbacks apply to compensation received as incentives or bonuses, rather than salary.

The SEC has provided guidance on constructing effective clawback provisions. In their final rule titled “Listing Standards for Recovery of Erroneously Awarded Compensation,” (the Rule) the SEC directs National Securities Exchanges and Associations to establish listing standards for issuers to develop and implement policies for recovering incentive-based compensation in the event of required accounting restatements.

The DOJ has also weighed in on subject of clawbacks, most recently in the 2023 Evaluation of Corporate Compliance Programs (ECCP), it stated “Are the terms of bonus and deferred compensation subject to cancellation or recoupment, to the extent available under applicable law, in the event that non-compliant or unethical behavior is exposed before or after the award was issued? Does the company have a policy for recouping compensation that has been paid, where there has been misconduct? Have there been specific examples of actions taken (e.g., promotions or awards denied, compensation recouped or deferred compensation cancelled) as a result of compliance and ethics considerations?

In summary, both the SEC and DOJ have now laid out the foundations for both incentives and consequence management.

SEC: The SEC Rule encompasses a wide range of scenarios. Companies are required to claw back incentive compensation erroneously received by current or former executives during the three-year period preceding the required restatement date. The definition of “received” is broad, considering incentive compensation earned even if not yet paid. The recoverable amount may differ from what executives would have received based on the required restatement. The SEC rule prohibits companies from obtaining indemnity insurance to protect executives from clawbacks. This step ensures that executives are held personally accountable for their actions and fosters a culture of compliance within organizations.

DOJ: In the ECCP has emphasized the significance of clawbacks in compliance programs. The ECCP directs companies to develop and apply compensation and clawback policies, shifting the burden of financial penalties away from innocent shareholders. The clear intent to prevent companies from shielding employees involved in illegal and unethical conduct. The DOJ will consider whether a company has incentivized compliance by designing compensation systems that defer or escrow certain compensation tied to conduct consistent with company values and policies. Enforcement of a contract provisions that permit the company to recoup previously awarded compensation if the recipient of such compensation is found to have engaged in or to be otherwise responsible for corporate wrongdoing is now a critical metric that prosecutors will consider. Finally, prosecutors may consider whether provisions for recoupment or reduction of compensation due to compliance violations or misconduct are maintained and enforced in accordance with company policy and applicable laws.

 Practical Steps

To create a robust compliance program that promotes ethical behavior and compliance, companies should consider the following practical advice:

  1. Documented Policies and Procedures: It is crucial for companies to document and reflect clawback policies and procedures in their compensation agreements. This documentation showcases a commitment to compliance and serves as a deterrent for potential misconduct.
  1. Clear Disciplinary Procedures: Companies should have appropriate and clear disciplinary procedures in place when enforcing a compliance program. Publicizing disciplinary actions internally and under local law can have a deterrent effect on employees, emphasizing the consequences of engaging in unlawful or unethical behavior.
  1. Personal Accountability: The DOJ and SEC prioritize holding individuals accountable for misconduct. Prosecutors evaluate whether a corporation’s compensation agreements incorporate clawback provisions that enable penalties to be levied against employees, executives, or directors involved in criminal conduct.

 Conclusion

Clawback provisions have become a crucial element in compliance programs, promoting ethical behavior and ensuring accountability within organizations. The SEC Rule, along with the DOJ’s emphasis on clawbacks from the Monaco Memo to the ECCP, highlights the significance of these provisions in the business world. By implementing well-documented clawback policies, companies can create a culture of compliance that rewards ethical behavior and protects innocent shareholders. Both initiatives prioritize ethical practices and compliance to build a better business environment for all stakeholders.

Categories
Daily Compliance News

Daily Compliance News: August 17, 2023 – The Importing Monkeys Edition

Welcome to the Daily Compliance News. Each day, Tom Fox, the Voice of Compliance brings to you compliance-related stories to start your day. Sit back, enjoy a cup of morning coffee, and listen in to the Daily Compliance News. All, from the Compliance Podcast Network. Each day we consider four stories from the business world, compliance, ethics, risk management, leadership, or general interest for the compliance professional

  • Inotiv facing FCPA issues around importing monkeys for research. (WSJ)
  • Chile President shuffles Cabinet around corruption scandal. (Bloomberg)
  • Beware SEC overreach in crypto. (FT)
  • BNSF tries to settle massive data privacy claim. (Reuters)
Categories
Daily Compliance News

Daily Compliance News: August 16, 2023 – The Protective Order Edition

Welcome to the Daily Compliance News. Each day, Tom Fox, the Voice of Compliance brings to you compliance-related stories to start your day. Sit back, enjoy a cup of morning coffee, and listen in to the Daily Compliance News. All, from the Compliance Podcast Network. Each day we consider four stories from the business world, compliance, ethics, risk management, leadership, or general interest for the compliance professional.

  • Binance files for Protective Order against SEC. (Decrypt)
  • Compliant filed over required religious liberty training. (Reuters)
  • Federal corruption investigation heating up in Ohio. (Ohio Capital Journal)
  • SEC Whistleblower Program growing pains. (WSJ)
Categories
Compliance Into the Weeds

Compliance into the Weeds: Messaging App Enforcement and Internal Controls

The award-winning, Compliance into the Weeds is the only weekly podcast that takes a deep dive into a compliance-related topic, literally going into the weeds to explore a subject more. Looking for some hard-hitting insights on sanctions compliance? Look no further than Compliance into the Weeds! In this episode, Tom and Matt consider the recent SEC and CFTC enforcement actions around messaging app non-compliance.

Join Tom and Matt as they take a deep dive into the enforcement actions and then consider how such claims would impact non-regulated industries. Regulated industries, particularly broker-dealer firms like Wells Fargo and Morgan Stanley, are facing enforcement actions and hefty fines for their employees’ use of messaging apps like WhatsApp and Snapchat that allow record preservation to be disabled. The involvement of senior managers in these misconducts has prompted the SEC to require an independent compliance consultant in settlements.

The conversation between Tom and Matt emphasizes the importance of messaging policies and procedures in regulated industries and the need for stricter compliance measures. They also discuss the complexities and potential consequences of record-keeping obligations and the regulatory concerns over the use of messaging apps. The conversation briefly touches on the future of AI chatbots in customer service, with differing perspectives on their ethical implications. Overall, the conversation highlights the significance of messaging policies, enforcement, and compliance in regulated industries.

Key Highlights

·      Enforcement Actions Against Regulated Industries

·      Enforcement actions and messaging policies

·      Record-keeping obligations for broker dealers and other industries

·      Regulatory concerns over the use of messaging apps

·      Internal Controls and non-regulated industries

 Resources

Matt 

LinkedIn

Blog Post in Radical Compliance

No Smoke and No Fire: The Rise of Internal Controls Absent Anti-Bribery Violations in FCPA Enforcement by Karen Woody in Cardoza Law Review

Tom 

Instagram

Facebook

YouTube

Twitter

LinkedIn

Categories
31 Days to More Effective Compliance Programs

One Month to a More Effective Compliance Program: Day 9 – Clawbacks

In this podcast series, host Tom Fox explores the growing emphasis on clawback provisions in compliance programs and employee compensation.

Tom Fox delves into the crucial topic of clawback provisions in compliance programs and employee compensation. In light of the Department of Justice (DOJ) and Securities and Exchange Commission (SEC) prioritizing individual accountability for misconduct, clawbacks have become essential in promoting ethical behavior and ensuring compliance. So, let’s dive in and explore the significance of clawbacks in today’s evolving compliance landscape.

Understanding Clawbacks and Incentive-Based Compensation:

Clawbacks, as discussed in the podcast, are provisions that enable organizations to reclaim incentive or bonus funds from employees engaged in misconduct. They serve as a powerful deterrent and hold individuals accountable for their actions. Previously, clawbacks were not seen as necessary, but the DOJ now mandates their inclusion in compensation agreements.

The DOJ’s Focus on Ethical Business Practices:

The DOJ, in its pursuit of punishing officers and employees who fail to conduct business ethically, has made clawbacks a part of best practices compliance programs. To evaluate a company’s compliance program, the DOJ and SEC consider whether the organization has appropriate disciplinary procedures in place. Publicizing disciplinary actions internally and under local law can have a deterrent effect, emphasizing the importance of transparent consequences for misconduct.

The Role of Clawbacks in Compliance Programs:

Having clawback provisions is now seen as a crucial aspect of a good corporate compliance culture. It promotes compliant behavior and demonstrates a company’s commitment to its compliance program. The DOJ investigates whether corporations have included clawback provisions in their compensation agreements and taken steps to execute on such agreements. This highlights the significance of documenting and reflecting these policies and procedures in a company’s own compensation practices.

The SEC’s Final Rule on Clawbacks:

The SEC’s final rule, titled “Listing Standards for Recovery of Erroneously Awarded Compensation,” directs issuers to establish policies for recovering incentive-based compensation in the event of required accounting restatements. This rule applies to both Big R and Little R restatements and provides guidance in the anti-corruption world. Companies are now required to claw back incentive compensation erroneously received by current or former executives during the three-year period preceding the required restatement date.

Ensuring Compliance with Clawbacks:

It is essential for companies to construct well-documented clawback programs that align with the SEC’s guidance. The recoverable amount may differ from what executives would have received based on the required restatement, emphasizing the need for clarity and transparency in compensation agreements. Additionally, the SEC’s final rule prohibits companies from obtaining indemnity insurance to protect executives from clawbacks, further reinforcing the importance of accountability.

Conclusion:

As we’ve explored in this episode, clawbacks play a vital role in promoting ethical behavior and compliance within organizations. The DOJ’s emphasis on individual accountability and the SEC’s final rule on clawbacks demonstrate the evolving landscape of compliance. By implementing well-documented clawback provisions, companies can deter misconduct, hold individuals accountable, and showcase their commitment to ethical practices. Remember, incorporating clawbacks into your compliance program is not just a regulatory requirement but a practical step towards fostering a culture of integrity and responsibility.

 Three key takeaways:

1. The DOJ now mandates clawbacks in a compliance program.

2. The SEC has passed a clawback rule apart from the Monaco Memo.

3. Your clawback program should be well-documented.

For more information, check out The Compliance Handbook, 4th edition, available on LexisNexis.com.

Categories
Daily Compliance News

Daily Compliance News: August 9, 2023 – The $555MM Edition

Welcome to the Daily Compliance News. Each day, Tom Fox, the Voice of Compliance brings to you compliance-related stories to start your day. Sit back, enjoy a cup of morning coffee, and listen in to the Daily Compliance News. All, from the Compliance Podcast Network. Each day we consider four stories from the business world, compliance, ethics, risk management, leadership, or general interest for the compliance professional.

  • Federal judge says we need world ABC court. (WaPo)
  • Zoom and AI training. (BBC)
  • Judge order SW Airline lawyers to take religious training. (Reuters)
  • More messaging app non-compliance fines. (WSJ)
Categories
Daily Compliance News

Daily Compliance News: August 8, 2023 – The Shocked, Just Shocked Edition

Welcome to the Daily Compliance News. Each day, Tom Fox, the Voice of Compliance brings to you compliance-related stories to start your day. Sit back, enjoy a cup of morning coffee, and listen in to the Daily Compliance News. All, from the Compliance Podcast Network. Each day we consider four stories from the business world, compliance, ethics, risk management, leadership, or general interest for the compliance professional.

·       Largest Altice shareholder ‘shocked’ about corruption allegations. (Broadband)

·       Zoom order employees back to the office.  (NYT)

·       Former CISA head blasts new SEC disclosure rules. (FT)

·       Siemens under ABC investigation in Austria.  (Reuters)

Categories
Daily Compliance News

Daily Compliance News: August 7, 2023 – The Face, The Music Edition

Welcome to the Daily Compliance News. Each day, Tom Fox, the Voice of Compliance brings to you compliance-related stories to start your day. Sit back, enjoy a cup of morning coffee, and listen in to the Daily Compliance News. All, from the Compliance Podcast Network. Each day we consider four stories from the business world, compliance, ethics, risk management, leadership, or general interest for the compliance professional.

  • Albemarle makes FCPA settlement reserve. (WSJ)
  • Catching pandemic fraudsters. (NYT)
  • Wells, SocGen to settle messaging app violations. (WSJ)
  • Ex-Allianz manager to face $7bn criminal fraud claim. (Reuters)
Categories
Daily Compliance News

Daily Compliance News for August 4, 2023 – The Follow Your Passion Edition

Welcome to the Daily Compliance News. Each day, Tom Fox, the Voice of Compliance brings to you compliance-related stories to start your day. Sit back, enjoy a cup of morning coffee, and listen in to the Daily Compliance News. All, from the Compliance Podcast Network. Each day we consider four stories from the business world, compliance, ethics, risk management, leadership, or general interest for the compliance professional.

·       Altice France suspends director. (Bloomberg)

·       The biggest attorney/client privilege case in years.  (FT)

·       SEC tells some Wall Street brokers to get their AML controls in order. (WSJ)

·       Following your passion.  (NYT)

Categories
Blog

SEC Formalizes New Rules on Cyber Breach Disclosures

The SEC has recently voted on new rules that will require companies to disclose material cybersecurity incidents within four days and to make disclosures about their broad cybersecurity risks in their annual report. Tom Fox and Matt Kelly discussed this issue on a recent edition of Compliance into the Weeds. Matt blogged about it on Radical Compliance.

This new set of rules represents a major shift from the past, when companies may have been asked by law enforcement not to disclose an attack until they were done tracking the attackers. The SEC has tried to balance the need for transparency with the need for law enforcement to use the information, and companies can go to the Justice Department to get permission to keep a breach private.

The SEC had originally proposed these rules nearly 18 months ago, in March of 2022. After considering public feedback, the SEC voted on the rules two weeks ago, at the end of July. Companies now have to disclose material cybersecurity incidents within four days of deciding that the incident is material. They must also make disclosures about their broad cybersecurity risks and how they manage those risks in their annual report. This includes disclosing the impact of the breach, such as the financial consequences and any qualitative effects.

The SEC has also proposed a rule that would require companies to disclose the cyber expertise of their board directors. However, this was changed due to public feedback that most of cyber risk management is done at the management level. The two Republican commissioners objected to the rule, saying it was too extensive and unnecessary, and arguing that the SEC was trying to dictate how companies should run their cybersecurity functions. The US Chamber or other groups may try to litigate over the rule, but for now, companies must disclose or discuss the processes for assessing, identifying, and managing material risks from cybersecurity threats.

The Head of the SEC Enforcement Division recently gave a speech about disclosing cybersecurity incidents and what his division looks at for bad practices that might lead to an enforcement action. The SEC Enforcement Director zeroed in on the misleading disclosure and said companies cannot engage in such conduct. He gave examples of companies who have suffered enforcement actions long before any of the new rules were adopted. First American Title Insurance and Pearson both gave misleading disclosures to investors about the nature of the breaches they suffered. First American thought the breach was not material and announced it was not a big deal, but their IT team later realized it was a big deal. Pearson suffered an extensive breach and disclosed to investors that there may have been some exposure of confidential data, when they already knew there was no ‘may’ involved. Companies need to disclose the severity of the incident and the reality of what actually happened.

To ensure compliance with the new rules, companies need to have proper policies for handling cybersecurity incidents that are useful and relevant to their company. Companies cannot simply copy language from a regulation and paste it into their policy manual and declare victory. They need to be clear and relevant to their employees about how to find red flags and how to respond to them.

We took a deep dive into the policy choice of transparency over use of information by law enforcement. Companies can go to the Justice Department and get permission from the Attorney General to keep a breach private if it is a threat to national security or public safety. Companies can then take that permission back to the SEC and tell the SEC the company will not disclose the breach for 30 days. Companies can then go back to the Attorney General’s office for another 30-day extension to keep the breach private. The SEC has tried to cut the baby in half by creating a process to keep some breaches private, but they have made clear they do not want corporate or lawyer-led gamesmanship around these disclosures and want a solid informational disclosure.

As this new rule is sure to have a major impact on how companies handle cybersecurity incidents in the future, it is important for companies to be aware of the new rules and the potential consequences of not complying. Companies need to have proper policies in place to ensure compliance, and they need to be sure to provide accurate and timely disclosures about any material cybersecurity incidents.