Categories
Blog

Impact of the Federal Sentencing Guidelines at 30

The Federal Sentencing Guidelines for Organizations (FSGO) by the US Sentencing Commission (USSC) turn 30 this year. For compliance officers, this was perhaps the most significant government release. It did not create the compliance profession, but it certainly put compliance professionals in the forefront of the design, creation and implementation of corporate compliance programs. The FSGO also laid out for the first time, the government’s expectations of what a well-designed compliance program should look like in practice. This led to a dramatic increase in compliance professionals. Earnie Broughton, writing in the ECI blog, said, “In many ways the promulgation of the guidelines was a defining moment in our collective journey in understanding and realizing the benefits of good corporate character.”

In 2021, the Bureau of Labor Statistics reported 291,000 compliance officers in the US. But more than driving the compliance profession and a concomitant increase in compliance professionals the FSGO has in many ways shaped the structure of the 21st century corporation and dramatically improved corporate governance. In these ways, it laid the environmental, social and governance (ESG) foundations. Last month the US Sentencing Commission (USSC) released a summary of the FSGO and how it helped drives these changes, “The Organizational Sentencing Guidelines: Thirty Years of Innovation(the History).

Regarding the FSGO themselves, they take a “carrot and stick” approach to the sentencing scheme that bases the fine range on the culpability of the organization. The guidelines instruct courts to determine culpability by considering six factors. The four aggravating factors, “that increase the ultimate punishment of an organization are: (i) the involvement in or tolerance of criminal activity; (ii) the prior history of the organization; (iii) the violation of an order; and (iv) the obstruction of justice.” The two mitigating factors are: “(i) the existence of an effective compliance and ethics program; and (ii) self-reporting, cooperation, or acceptance of responsibility.” Rather amazingly, the History reported that only 1.5% overall of all organizations sentenced “received the five-point culpability score reduction for disclosing the offense to appropriate authorities prior to a government investigation in addition to their  full cooperation and acceptance of responsibility.” Obviously, there is still room for improvement.

Rather unsurprisingly, the Department of Justice (DOJ) drew heavily on the FSGO for two key documents which laid out the foundations of an effective compliance program. The first was the 2012 FCPA Resource Guide (developed and released jointly with the Securities and Exchange Commission (SEC)) and its update, the 2021 FCPA Resource Guide, 2nd edition. The second was the Evaluation of Corporate Compliance Programs, initially released in 2019, and the 2020 Update to the Evaluation of Corporate Compliance Programs. The History noted that the Evaluation and its update, “was first developed in 2017 under the leadership of the DOJ’s first “corporate compliance expert”” and “provides greater clarity on some key issues prosecutors consider when assessing the adequacy of corporate compliance programs during charging and settlement decisions, by laying out “fundamental questions” that prosecutors should ask about compliance programs:

  • Is the corporation’s compliance program well designed. There were three key questions for consideration:
  • Is the program being applied earnestly and in good faith?
  • In other words, is the program being implemented effectively?
  • Does the corporation’s compliance program work in practice?

The Evaluation and its Update then proceed to describe “in detail the topics that prosecutors should consider when answering those questions.”Demonstrating its influence far beyond the DOJ, SEC and other government agencies, the Delaware court decision in Caremark demonstrates a key effect in the transformation of compliance programs, policies and procedures in the corporate world. The Caremark decision was a departure from prior Delaware case law which said that a board did not have to look for wrongdoing but only had to investigate if informed about it. That was from an old 1963 decision and the Court relied on the 1992 US Sentencing Guidelines to note how such views were no longer accepted. Board obligations had changed by 1996 with the following, “obligation to be reasonably informed concerning the corporation, without assuring themselves that information and reporting systems exist in the organization that are reasonably designed to provide to senior management and to the board itself timely, accurate information sufficient to allow management and the board, each within its scope, to reach informed judgments concerning both the corporation’s compliance with law and its business performance.”

Caremark considered the proposed settlement of a derivative suit seeking to impose personal liability on members of the board of directors. The History noted, “the court considered whether director liability could stem from unconsidered action by the board. After observing that “[t]he Guidelines offer powerful incentives for corporations today to have in place compliance programs to detect violations of law, promptly to report violations to appropriate public officials when discovered, and to take prompt, voluntary remedial efforts,” the court concluded that “[a]ny rational person attempting in good faith to meet an organizational governance responsibility would be bound to take into account [the organizational guidelines].”

This meant that a director has a good faith duty to see that the organization establishes adequate information and reporting systems. i.e., a compliance program. No doubt due to the significance of the Delaware courts, “following the Caremark decision, federal and state courts recognized the importance of compliance programs in the context of shareholder derivative suits.” Caremark  and its progeny are now the law of the land regarding corporate governance and compliance across most states in the US.

All of these changes and much more point to the far- and wide-ranging impact of the FSGO.  “What began as an “experiment” to encourage legal compliance and foster more ethical business practices is now widely accepted as a success.” Moreover, “evidence suggests that compliance and ethics programs implemented using the guideline criteria produce positive effects on an organization’s behavior” and that the FSGO has had a significant impact on public and private sector actors.” Finally, the History concludes that the influence of FSGO “is now spreading around the globe, suggesting that the hallmarks of an effective compliance and ethics program have universal appeal.”

Categories
Everything Compliance - Shout Outs and Rants

Shout Outs and Rants from Episode 104

Welcome to theShout Outs and Rants from the Everything Compliance gang. In this episode, we have the quintet of Jonathan Marks, Jay Rosen, Tom Fox, Jonathan Armstrong, and Matt Kelly on a variety of shoutouts.

1. Jay Rosen shouts out to the firm Moxie, who is trying to create Oxygen from CO2 so that life can exist on Mars.

2. Matt Kelly shouts out to NASA engineers who scrubbed the space shuttle launch due to safety concerns.

3. Jonathan Marks shouts out the 30th anniversary of the US Sentencing Guidelines.

4. Tom Fox shouts out the American League-leading Houston Astros.

5. Jonathan Armstrong shouts out to the British television show “Have I Got News” for skewering Boris Johnson with his own words.

The members of Everything Compliance are:

•       Jay Rosen– Jay is Vice President, Business Development Corporate Monitoring at Affiliated Monitors. Rosen can be reached at JRosen@affiliatedmonitors.com

•       Karen Woody – One of the top academic experts on the SEC. Woody can be reached at kwoody@wlu.edu

•       Matt Kelly – Founder and CEO of Radical Compliance. Kelly can be reached at mkelly@radicalcompliance.com

•       Jonathan Armstrong –is our UK colleague who is an experienced data privacy/data protection lawyer with Cordery in London. Armstrong can be reached at jonathan.armstrong@corderycompliance.com

•       Jonathan Marks is Partner, Firm Practice Leader – Global Forensic, Compliance & Integrity Services at Baker Tilly. Marks can be reached at jonathan.marks@bakertilly.com

The host and producer of Everything Compliance is Tom Fox, the Voice of Compliance. He can be reached at tfox@tfoxlaw.com. Everything Compliance is a part of the Compliance Podcast Network.

Categories
Creativity and Compliance

Do We Really Have to do E&C Training?

Where does creativity fit into compliance? In more places than you think. Problem-solving, accountability, communication, and connection – all take creativity. Join Tom Fox and Ronnie Feldman on Creativity and Compliance, part of the award-winning Compliance Podcast Network. In this episode, Tom and Ronnie continue their short series of provocative statements on compliance training and communications, followed by a discussion. In this episode, Ronnie pitches today’s question to Tom on is ethics and compliance training is required? Highlights include:

·      Is E&C training required by law?

·      Why doesn’t E&C training work?

·      Why not spend your time doing things that help?

·      How E&C training can promote speak-up culture.

·      Why E&C training provides tools and resources.

·      How E&C training gets leadership involved.

Resources:

Ronnie Feldman (LinkedIn)
Learnings & Entertainments (LinkedIn)
Ronnie Feldman (Twitter)

Learnings & Entertainments (Website)

60-Second Communication & Awareness Shorts – A variety of short, customizable, quick-hitter “commercials” including songs & jingles, video shorts, newsletter graphics & Gifs, and more. Promote integrity, compliance, the Code, the helpline and the E&C team as helpful advisors and coaches.

Workplace Tonight Show! Micro-learning – a library of 1-10-minute training and communications wrapped in the style of a late-night variety show that explains corporate risk topics and why employees should care.

Custom Live & Digital Programing – We’ll develop programming that fits your culture and balances the seriousness of the subject matter with more engaging delivery.

Tales from the Hotline – check out some samples.

Categories
The Compliance Life

Joe Burke -To Dell and Into Compliance

The Compliance Life details the journey to and in the role of a Chief Compliance Officer. How does one come to sit in the CCO chair? What skills does a CCO need to navigate the compliance waters in any company successfully? What are some of the top challenges CCOs have faced, and how did they meet them? These questions and many others will be explored in this new podcast series. Over four episodes each month on The Compliance Life, I visit with one current or former CCO to explore their journey to the CCO chair. This month, my guest is Joe Burke, most recently the Chief Ethics & Compliance Officer and Employment Counsel, Quest Software Inc.

From Kentucky Fried Chicken in Louisville, Joe moved to Round Rock, TX, to work at Dell Inc. He began in Federal Government Sales, where he developed a compliance program for GSA and TAA work for  Dell Federal. He moved into compliance with the “big switch” from commercial legal to Chief Compliance Counsel. In this role, he was instrumental in building a new FCPA program using the Federal Sentencing Guidelines as a guideline.

Resources

Joe Burke LinkedIn Profile

Categories
Blog

Glencore Resolution: Part IV – The Resolution

Last week, the Attorney General and a host of other Department of Justice (DOJ) officials announced the settlement of a massive Foreign Corrupt Practices Act (FCPA) and market manipulation case against Glencore plc (Glencore). Over this blog series, I have been reviewing the matter and mining it for lessons learned for the compliance community. Today, in Part IV, we take a dive into the settlement itself.
According to the DOJ Press Release, Glencore pled guilty to one count of conspiracy to violate the FCPA, agreed to a criminal fine of $428,521,173, and acknowledged criminal forfeiture liability in the amount of $272,185,792. Glencore also had charges brought against it by the UK Serious Fraud Office (SFO) and reached separate parallel resolutions with the Brazilian Ministério Público Federal (MPF). The DOJ agreed to credit the company over $256 million in payments that it makes to the CFTC, to the Court in the UK as well as to authorities in Switzerland, in the event that the company reaches a resolution with Swiss authorities within one year.
In a Market Manipulation case, separate and apart from the FCPA enforcement action, Glencore admitted to a muti-year scheme to manipulate fuel oil prices at two of the busiest commercial shipping ports in the United States. Under the terms of the Commodities Future Trading Commission (CFTC) resolution, the company will pay a criminal fine of $341,221,682 and criminal forfeiture of $144,417,203. Under the terms of the Plea Agreement, the DOJ will credit over $242 million in payments that the company makes to the CFTC.
In other words, there was some serious misconduct going on here, for multiple years, in multiple countries with multiple schemes. Yet Glencore received a reduction of 15% based upon the FCPA Corporate Enforcement Policy and a 2-point reduction in the overall penalty calculation under the US Sentencing Guidelines. Both of these discounts led to a not-insignificant reduction from the overall penalty assessed.
First let us take up the areas that did not avail itself of under the FCPA Corporate Enforcement Policy. Glencore did not receive voluntary disclosure credit because it failed to self-disclose its legal violations to the DOJ. Although Glencore received partial cooperation credit, it did not receive full credit because it did not always “demonstrate a full commitment” to cooperation, was slow in providing documents and other evidence and was slow in its remediation. Additionally, it did not timely and appropriately remediate with respect to disciplining certain employees involved in the misconduct.
Moreover, Glencore did not have adequate internal controls in place at the time of the underlying incidents took place. Since that time, Glencore has taken remedial measures, certain of the compliance enhancements are new and have not been fully implemented or tested to demonstrate that they would prevent and detect similar misconduct in the future, mandating the imposition of an independent compliance monitor for a term of three years.
Even with these failures, Glencore received a substantial reduction of what it could have been required to pay. Based upon the calculations in the Plea Agreement, I estimate the total discount was in the range of $100 million.
Glencore agreed to continue to cooperate with the DOJ in ongoing investigations and prosecutions relating to the underlying misconduct, to modify its compliance program where necessary. The DOJ cited several additional factors crediting Glencore’s compliance remediation efforts, including (a) Glencore’s implementation of a centralized compliance function, hiring of a Chief Compliance Officer (CCO), and significantly increasing the compliance staff; (b) enhancing its business partner management, reducing the number of third-party representatives, adopting payment controls and post-engagement monitoring controls; and (c) investing in increased compliance headcount and data analytics.
Glencore itself, in a Press Release issued the day of the announced settlements, touted new additions to its compliance program. The company said that it has “bolstered its compliance structures and controls through a comprehensive programme built around risk assessment, policies, procedures, standards and guidelines based on international best practice, associated training and awareness initiatives as well as monitoring systems.” These initiatives included:

  • Strengthening the Group’s Code of Conduct and launching a comprehensive global awareness and training campaign designed to embed Glencore’s Values throughout its business, set expectations and ensure accountability for all employees;
  • Establishing a centralized, independent and empowered compliance function and, in 2020, appointing a new dedicated Head of Compliance;
  • Making a significant investment in compliance systems and resources, as well as experienced personnel;
  • Significantly enhancing and expanding the Group’s ethics and compliance training programs;
  • Instituting a comprehensive business partner management programme, including significantly reducing the Company’s use of third-party business generating intermediaries and employing end-to-end controls to oversee their engagement;
  • Implementing extensive monitoring and testing mechanisms, including through the use of data analytics, to assess whether our controls are entrenched and effective across the Group and ensure continuous improvement; and
  • Engaging leading external advisors to review Glencore’s systems and verify that controls are working as intended.

It appears quite a bit of work went into not simply cleaning up Glencore but in improving its overall culture. Of course, there is quite a bit of work do and that will no doubt turn in large part on the effectiveness of the monitor. More on that and final thoughts in our next post.