Categories
Blog

The NBA/Clippers Investigation: Part 5 – Lessons for CCOs and Boards

The ultimate measure of a compliance program is whether it can constrain the people the organization believes it cannot afford to disappoint. Most compliance programs are designed for ordinary decisions made by ordinary employees. The real danger lies in extraordinary decisions involving people with unusual economic power. Today we conclude with lessons learned.

They may be founders, controlling owners, senior executives, rainmakers, celebrity endorsers, critical customers, or star performers. Their value to the organization can become a reason to bypass controls, reinterpret rules, or treat prohibited requests as business problems requiring creative solutions.

The investigation into the LA Clippers and Kawhi Leonard demonstrates what happens when that pressure enters the commercial ecosystem. The independent investigators’ report (Wachtell Report) concluded that Clippers leaders helped create outside-income opportunities for Leonard through companies doing business with the team, linked vendor business to endorsement arrangements, paid impermissible personal expenses, and failed to report prohibited demands.

The lessons reach well beyond professional sports. They reach into all businesses. Finally, they apply wherever commercial urgency can overwhelm governance.

Lesson One: Power Is a Compliance Risk Factor

Traditional risk assessments organize risk by geography, business unit, transaction type, or regulatory subject. They often overlook individual power.

Organizations should identify people whose economic importance, ownership position, revenue contribution, reputation, or personal relationship with leadership could weaken ordinary controls. This is not an accusation against those individuals. It is recognition that employees may respond differently when a request comes from someone perceived as indispensable.

The DOJ’s Evaluation of Corporate Compliance Programs asks whether risk management is proactive, whether resources follow risk, and whether senior leaders persist in their commitment to compliance when facing competing business objectives. A power-risk assessment helps answer those questions.

Lesson Two: Prior Misconduct Must Change the System

The Clippers had a prior circumvention violation. The NBA later investigated improper demands associated with Leonard’s 2019 free agency, established a reporting requirement, and trained the team’s senior leadership. Yet the Wachtell Report concluded that similar risks materialized again.

Training is not remediation unless the organization can demonstrate changed behavior. After an incident, compliance should identify the root cause, assign control owners, establish deadlines, test effectiveness, and report results to the board. The inquiry should continue until the organization can show it has materially reduced the opportunity for recurrence. DOJ expressly asks whether companies incorporate lessons from their own misconduct and from similar problems at peer organizations. The Organizational Sentencing Guidelines likewise make prior history relevant to risk assessment, program design, and organizational culpability.

Lesson Three: Compliance Must Have Independent Authority

The question is not whether the organization employs compliance professionals. It is whether those professionals can challenge a powerful executive, suspend a transaction, obtain complete information, and reach an independent board committee without management permission.

The DOJ evaluates whether compliance has adequate qualifications, seniority, stature, resources, autonomy, and direct board access. These are operational requirements, not organizational-chart preferences. A CCO who can advise but cannot stop or escalate is not empowered. A compliance committee dominated by the executives sponsoring the transaction is not independent. A board that receives only management-filtered information is not exercising informed oversight.

Lesson Four: Follow the Entire Commercial Relationship

The Clippers investigation involved sponsorships, consulting agreements, sustainability services, an owner’s investment, player endorsements, vendor payments, and personal expenses. Reviewing each transaction separately could obscure the common purpose. Compliance needs a consolidated view of the relationship. That requires common identifiers across procurement, contracts, accounts payable, expenses, conflict disclosures, gifts, sponsorships, and third-party systems.

The most useful question may be simple: What other business do we have with this person or entity? Make that question mandatory when a transaction involves a significant vendor, executive relationship, personal investment, public official, customer representative, agent, or other high-risk beneficiary.

Lesson Five: Test Economic Substance

According to the Wachtell Report, several endorsement arrangements had unusual economics, limited performance obligations, little public activation, and compressed negotiation timelines. Consulting agreements involved substantial advance payments. Separate agreements contained matching or closely connected amounts. The COSO Internal Control–Integrated Framework reminds organizations that controls support compliance and operational objectives, not simply accurate accounting. A payment can be correctly recorded and still serve an improper purpose.

Controls should test business rationale, market value, deliverables, proof of performance, payment timing, ultimate beneficiary, and connections to other transactions. Internal audit should be authorized to ask whether a contract makes commercial sense, not merely whether an authorized person signed it.

Lesson Six: Mandatory Reporting Requires a Closed Loop

The Wachtell Report found that Clippers leaders did not report improper solicitations made on Leonard’s behalf, despite a rule requiring reporting even if a request was rejected. A mandatory reporting policy needs more than a sentence in the code of conduct. It requires defined triggers, responsible owners, escalation deadlines, documentation, non-retaliation protection, and verification that the report reached the required recipient.

Organizations should test the reporting control. Present leaders with realistic scenarios and ask what they would do, whom they would contact, and how quickly. If answers vary, the control is not operating reliably.

Lesson Seven: Red Flags Must Reach Someone Who Can Act

The Wachtell Report described unusual payment structures, internal concern about the Forum transaction, resistance from Aspiration executives, and explicit communications linking Clippers business to Leonard’s endorsement agreement. Red flags do not protect an organization merely because they exist in an email archive. They must reach a person with authority, independence, and responsibility to act.

Boards should identify mission-critical compliance risks and establish reporting systems that deliver meaningful information. The Delaware Supreme Court’s decision in Marchand v. Barnhill emphasizes the board’s obligation to make a good-faith effort to establish and monitor reporting systems for central compliance risks. That does not make every control failure a Caremark violation. It does mean that silence at the board level is not a defensible oversight model.

Lesson Eight: Investigation Conduct Is Compliance Conduct

Investigators assessed not only the underlying transactions but also witness credibility and cooperation. They distinguished between witnesses who accepted responsibility and those whose accounts conflicted with documents or changed over time.

Organizations should prepare for investigations before a crisis. Document preservation, witness instructions, privilege protocols, anti-retaliation protections, escalation duties, and cooperation standards should already be in place. Outside counsel should defend legitimate interests without impairing the organization’s ability to learn the truth. An investigation is not solely a litigation event. It tests culture and governance.

Lesson Nine: Accountability Must Reach Supervisors

The NBA’s penalties included a $30 million organizational fine, forfeiture of five first-round draft picks, individual suspensions, a payment by Leonard, a five-year restriction on Robertson, and a five-year compliance and monitoring program.

The sanctions reached individuals based on different forms of responsibility, including direct conduct, approval, supervision, and organizational leadership. Corporate consequence management should do the same. Employees who participate directly should be accountable, but so should managers who ignore red flags, approve unsupported exceptions, or fail to supervise. Enforce compliance consistently, regardless of commercial value or title.

Lesson Ten: The Board Must Oversee the Pressure Points

Boards do not need to approve every sponsorship, vendor agreement, or expense report. They do need visibility into the areas where incentives, power, and mission-critical compliance risks intersect.

The board should receive reporting on high-risk transactions, control overrides, related-party relationships, significant investigations, repeated policy violations, executive discipline, and remediation testing. It should meet privately with the CCO and internal audit leader and confirm both functions have the information and resources they need. Board oversight is not passive dashboard receipt. It is an informed challenge followed by documented action.

Practical Takeaways: A 90-Day Agenda

CCOs and risk leaders can translate these lessons into action:

  • Identify the organization’s most powerful internal and external stakeholders and assess where their requests could bypass controls.
  • Review prior investigations, violations, and audit findings to confirm that remediation was implemented and tested.
  • Map all relationships involving high-risk vendors, personal investments, sponsorships, consulting arrangements, and individual beneficiaries.
  • Establish independent review for transactions involving controlling owners, senior executives, or conflicts of interest.
  • Test procurement, payment, expense, and reporting controls using real transaction data.
  • Give compliance documented stop-work and escalation authority.
  • Define investigation cooperation and consequence-management standards before the next allegation.
  • Provide the board with targeted reporting on control overrides, repeat issues, and high-risk relationships.

The final lesson from the Clippers investigation is straightforward. Compliance fails when the organization treats the rule as an obstacle and the desired outcome as nonnegotiable. An effective program reverses that order. The rule defines the boundary, and the business must operate within it. The true measure of compliance is whether the organization can say no when yes would be more profitable, more convenient, or more popular. That is where governance becomes real.

Categories
Blog

The Clippers Investigation: Part 4 – Consequence Management at the Top

The Clippers penalties demonstrate that discipline is not the end of a compliance process. They are a public test of whether rules apply to powerful people. The Clippers investigation demonstrates why conflict controls must follow influence, economic benefit, and interconnected transactions, not merely financial ownership. In this Part 4 of a five-part series, we consider the consequences of cheating and not following the rules and regulations your organization agrees to comply with going forward. Every organization claims that no one is above the rules. Consequence management determines whether that statement is true.

The test does not come when a junior employee commits an obvious policy violation. It comes when the conduct involves a founder, controlling owner, senior executive, star performer, or other person viewed as essential to the business. The investigation into the LA Clippers and Kawhi Leonard presents that test in unusually clear terms. The independent investigators’ report of the Clippers’ NBA salary cap circumvention (Wachtell Report) attributed primary responsibility to Clippers owner Steve Ballmer, President of Business Operations Gillian Zucker, and President of Basketball Operations Lawrence Frank. It also found violations by Leonard through the conduct of his uncle and then-business manager, Dennis Robertson (Uncle Dennis).

The NBA responded with organizational, financial, individual, competitive, and monitoring consequences. For compliance professionals, the case provides a framework for considering who should be held accountable, for what conduct, and through what mechanism.

From Punishment to Consequence Management

Punishment looks backward. It asks what sanction should follow a violation. Consequence management is broader. It identifies misconduct, investigates responsibility, calibrates discipline, addresses supervisory failures, remediates control weaknesses, and communicates the organization’s expectations. All of this brings me to one of my favorite compliance phrases: consequence management.

The DOJ’s Evaluation of Corporate Compliance Programs (ECCP) introduces consequence management procedures as procedures to identify, investigate, discipline, and remediate violations of law, regulation, or policy. It goes on to state that every organization must enforce them consistently across the organization and ensure the procedures are commensurate with the violations. It concludes: Prosecutors should also assess the extent to which the company’s communications convey to its employees that unethical conduct will not be tolerated and will bring swift consequences, regardless of the employee’s position or title. 

Consequence Calibration

The report provides several categories for assessing responsibility.

  1. Direct participation. Investigators concluded that Zucker initiated, facilitated, and induced endorsement agreements involving Leonard and four Clippers business partners. They found that Ballmer knowingly sought to help Leonard obtain outside income and approved the Forum agreement after learning that Aspiration had tied it to Leonard’s endorsement arrangement. Frank conveyed Robertson’s demands and approved impermissible personal expenses.
  2. Supervisory responsibility. The report concluded that Ballmer failed to supervise the organization’s most senior business executive and failed to create conditions supporting compliance with the circumvention rules.
  3. Reporting responsibility. Investigators found that Ballmer, Zucker, and Frank did not report Robertson’s improper demands, despite an NBA rule requiring those reports even when the solicitation was rejected.
  4. Personal or represented conduct. The report concluded that Leonard, through Robertson, pressured the team to help obtain outside income and failed to reimburse certain personal expenses. Robertson allegedly made the demands and applied the pressure.

A defensible consequence decision should map each individual to the conduct, knowledge, authority, benefit, supervisory obligation, and missed opportunity to intervene. Titles alone should neither establish nor eliminate responsibility.

Credibility and Cooperation Matter

The report did something particularly useful for compliance officers: it distinguished among witness behavior. Investigators wrote that Zucker made statements inconsistent with contemporaneous documents and other witnesses, professed limited recollection on significant issues, placed responsibility on subordinates, and provided inconsistent versions of events.

By contrast, they reported that Frank discussed his conduct openly, recalled important details, accepted responsibility for subordinates, and remained generally consistent across interviews. The investigators stated that cooperation and credibility, or their absence, should factor into determining consequences.

Cooperation does not erase underlying conduct. It should, however, affect how consequences are calibrated. An employee who preserves documents, provides candid information, accepts responsibility, and assists remediation presents a different risk from one who misleads investigators or shifts blame.

The organization should define cooperation before an investigation begins. Employees should understand that cooperation requires truthful, complete, and timely responses; preserving relevant information; correcting prior inaccuracies; and no retaliation or interference. It does not require surrendering legitimate legal rights.

Prior Misconduct Changes the Analysis

The Clippers had previously been penalized for a salary-cap circumvention violation involving an endorsement opportunity. The NBA had also investigated demands made during Leonard’s 2019 free agency and provided specific training to Clippers leaders.

Prior history matters because it changes what the organization and its leaders reasonably should have done. A first incident may reveal an unrecognized risk. A repeated incident following investigation, rule clarification, and training raises questions about culture, supervision, remediation, and willingness to comply.

The Sentencing Guidelines identify prior organizational history as relevant to culpability and direct organizations to consider similar misconduct when designing an effective program. DOJ likewise asks whether policies, training, controls, and risk assessments incorporate lessons from prior incidents.

Remediation that ends with training is incomplete. The organization must test whether behavior, decision rights, escalation pathways, and controls changed.

The NBA’s Consequence Framework

The NBA’s official action included multiple forms of individual accountability. The box score of individual consequences reads as follows:

Person Relationship Consequence
Steve Ballmer Owner: LA Clippers Fine and one-year ban
Gillian Zucker Clippers President of Business Operations One-year unpaid suspension
Lawrence Frank Clippers President of Basketball Operations 6-month Unpaid Suspension
Kawhi Leonard Clipper Player $700K fine
Uncle Dennis Leonard Representative 5-Year Ban from NBA

These measures address different risks. For corporate compliance programs, the equivalent toolkit may include termination, suspension, bonus reduction, clawbacks where legally available, promotion restrictions, written warnings, removal of approval authority, enhanced supervision, vendor termination, and mandatory remediation. Consequences need not be identical, but the process must be consistent. Consistency means applying the same decision factors to similarly situated people. It does not mean imposing the same outcome regardless of role, intent, cooperation, history, or responsibility.

Practical Takeaways

CCOs, human resources leaders, and boards should consider the following:

  • Adopt written consequence-management procedures before a significant investigation occurs.
  • Use a consistent decision matrix covering conduct, intent, seniority, authority, benefit, cooperation, prior history, and supervisory responsibility.
  • Separate factual findings from disciplinary decisions, and ensure decision-makers understand the evidentiary record.
  • Document why similarly situated individuals received similar or different outcomes.
  • Apply financial consequences where permitted and align future compensation with compliance performance.
  • Communicate substantiated outcomes internally with enough detail to reinforce expectations while respecting legal and privacy constraints.
  • Track disciplinary data by level, function, geography, and type of misconduct to identify inconsistency.
  • Require independent board oversight when senior management is implicated.

Consequence management is where culture becomes measurable. If the organization protects its most powerful people, employees will understand that performance outranks integrity. If it applies a fair, independent, and proportionate process, employees will understand that compliance is part of how the business operates.

In our final blog post, we will bring the series together and develop a practical framework for CCOs, boards, and risk leaders seeking to build a compliance program that can say no to the star.

Categories
Blog

The NBA/Clippers Investigation: Part 3 – Paper Compliance Is Not an Internal Control: Substance, Procurement, and the Audit Trail

The Clippers investigation shows why contracts, approvals, and carefully drafted emails cannot substitute for controls that test economic reality. In Part 3 of a five-part series, we explore why and how a transaction can have a contract, an approval, an invoice, and an email trail and still pose a serious compliance problem. Documentation proves that a process occurred. It does not prove that the process was legitimate.

That distinction sits at the center of the investigation into the LA Clippers and Kawhi Leonard. The independent investigators’ report (Wachtell Report) concluded that the Clippers initiated and facilitated endorsement arrangements between Leonard and four companies doing business with the team, induced those arrangements by offering business to the companies, paid impermissible personal expenses, and failed to meet improper demands made on Leonard’s behalf.

The alleged conduct crossed organizational boundaries. It touched business operations, basketball operations, procurement, sponsorships, consulting arrangements, accounts payable, expenses, legal review, and executive management. That makes this an internal controls case.

The Difference Between Evidence and Control

One of the report’s most important findings concerned introduction emails sent by Clippers President of Business Operations Gillian Zucker. The emails were written as if Boingo, Daktronics, Lockton, and later Aspiration had requested introductions to Leonard’s representatives. NBA rules permitted a narrow response when a commercial partner initiated such a request. They did not permit the team to create the opportunity for the player. The investigators concluded that the emails did not reflect the true sequence of events and, in Aspiration’s case, were created after deal development was already underway.

This is a classic paper-compliance problem. The communication used the language of the rule without satisfying its substance. A control cannot merely ask whether an introduction email contains the approved wording. It must test who initiated the contact, what discussions preceded the email, who proposed the economics, and whether team personnel remained involved afterward. Checklists confirm the form. Effective controls challenge reality.

Fragmented Transactions Hid a Common Purpose

The Wachtell Report described multiple agreements that could have appeared unrelated in separate systems. Vendors entered consulting or services agreements with the Clippers while also entering endorsement agreements with Leonard. Aspiration had sponsorship, sustainability, investment, forum, and player-endorsement relationships involving overlapping parties.

Investigators connected those transactions through timing, matching amounts, communications, and business leverage. Two companies reportedly received $10 million in consulting payments before entering endorsement agreements with Leonard. A third received a $2 million consulting payment one day after making its first payment to him.

The Forum agreement initially contemplated $7 million in annual business for Aspiration. That figure matched the annual cash component of Leonard’s endorsement agreement. Investigators further reported that the underlying carbon analysis did not generate the $28 million budget. Instead, the consultant said the Clippers supplied that budget.

The control failure was fragmentation. Procurement reviewed one agreement, marketing another, finance a payment, and business leaders the broader relationship. No control appears to have aggregated the transactions and asked whether one funded, induced, or conditioned another.

The DOJ’s Evaluation of Corporate Compliance Programs (ECCP) tells prosecutors to examine how misconduct was funded, including purchase orders and reimbursements (How was the misconduct in question funded (e.g., purchase orders, employee reimbursements, discounts, petty cash?); what controls could have prevented access to those funds (What controls failed?); whether vendor-selection procedures were followed (If vendors were involved in the misconduct, what was the process for vendor selection and did the vendor undergo that process?); and whether contract terms, payment terms, performance, and compensation were appropriate. Those are precisely the questions an organization should ask before enforcement authorities arrive.

Control Environment

The control environment begins with leadership and accountability. According to the report, the most senior business and basketball executives participated in or knew about key parts of the conduct. Investigators concluded that Ballmer failed to create conditions in which the organization followed rules it had previously violated. When senior leaders create the risk, lower-level approvals are unlikely to function as meaningful controls. Employees may view an executive request as authorization to proceed, even when the transaction presents obvious concerns.

Risk Assessment

The Clippers had a prior circumvention violation and were investigated over Leonard’s free-agency negotiations. The NBA had then provided specific training and imposed a mandatory reporting obligation. That history should have produced a targeted risk assessment covering player representatives, sponsor introductions, endorsement arrangements, personal expenses, vendor spend-back programs, and benefits flowing through third parties. Prior misconduct is not simply history. It is risk data.

Here, the ECCP asked some direct questions, including, “Were there prior opportunities to detect the misconduct in question, such as audit reports identifying relevant control failures or allegations, complaints, or investigations?” Additionally, it notes that critical factors in evaluating any program include whether the program is adequately designed to maximize effectiveness in preventing and detecting employee wrongdoing and whether corporate management enforces the program or tacitly encourages or permits employees to engage in misconduct.

Control Activities

The Wachtell Report suggests potential gaps in segregation of duties, conflict review, procurement approval, contract benchmarking, expense reimbursement, and related-transaction analysis. High-risk transactions should require independent approval outside the requesting executive’s chain of command. Controls should compare compensation with deliverables, confirm actual performance, flag advance payments, and identify common counterparties across procurement and non-procurement systems.

Information and Communication

The organization reportedly had information that should have triggered escalation: demands for $10 million in annual off-court income, unusual endorsement economics, concerns from Aspiration executives, internal descriptions of a Forum deal as “shady,” and explicit threats connecting the Forum and Leonard agreements. Indeed, Uncle Dennis’s presence alone was enough of a red flag based on his prior conduct. The issue was not the absence of information. It was the failure to move that information to a function with the independence and authority to act.

Monitoring

Hundreds of personal expenses were reportedly paid without the required deduction or reimbursement. Multiple vendors signed unusual endorsement arrangements, with minimal public activation or performance. These were recurring patterns, not one-time exceptions. Monitoring should identify patterns across time. If a control repeatedly approves exceptions without examining their cumulative effect, it is not monitoring risk. It is normalizing it.

Designing Controls for Substance

An effective control architecture should include three layers. Preventive controls should require documented business rationale, competitive sourcing, conflict disclosures, independent approval, clear deliverables, market benchmarking, and legal and compliance review before committing funds.

Detective controls should compare related transactions, test payment timing, examine overrides, confirm performance, and monitor expense exceptions. They should search for patterns across legal entities and business functions. Responsive controls should define who receives red flags, when compliance can stop payment, when issues reach the audit committee, and how remediation is tracked to completion. The most important design principle is independence. The DOJ asks whether compliance has adequate authority, stature, resources, and direct access to the board. (Where within the company is the compliance function housed (e.g., within the legal department, under a business function, or as an independent function reporting to the CEO and/or board?)

If executives can bypass or overrule the control function without documented challenge, the program is not empowered.

Practical Takeaways

Compliance, audit, and risk leaders should take the following actions:

  • Inventory all systems containing vendor, contract, payment, expense, sponsorship, and conflict information.
  • Build monitoring systems that identify common parties and beneficiaries across those systems.
  • Require proof of services and measurable deliverables before releasing significant payments.
  • Review advance payments, matching amounts, compressed timelines, and executive overrides as elevated-risk indicators.
  • Treat prior violations and mandatory reporting duties as subjects for recurring control testing.
  • Give internal audit authority to examine commercial substance, not merely procedural completion.
  • Report control failures involving senior management directly to an independent board committee.

The Clippers salary cap circumvention demonstrates that an audit trail can document a failure as easily as it documents compliance. The question is whether the organization has controls that can interpret what the records mean.

In tomorrow’s blog post, we will turn from detection to accountability and examine how cooperation, credibility, seniority, prior misconduct, and supervisory failure should shape consequence management.