Showing posts with label FCPA. Show all posts
Showing posts with label FCPA. Show all posts

16 March 2013

Legal Risk: Over-The-Horizon Digital Radar...

Operational Risk Management is a primary responsibility with an organizations General Counsel. Why?
"The definition includes Legal risk, which is the risk of loss resulting from failure to comply with laws as well as prudent ethical standards and contractual obligations. It also includes the exposure to litigation from all aspects of an institution’s activities."
So if you are a General Counsel or the Chief Legal Officer, your radar is consistently tuned to the "Over -The-Horizon" (OTH) risks that may impact your company, right?  The fact is that managing risk from the General Counsels office may be significantly different than what managing risk means from the CIOs office.

Loss events associated with peoples workplace behavior are many times treated differently than those events associated with a computer "intrusion" or a data breach, that was also caused by human behavior.  The law is a battleground that continues to keep an entire industry busy with offensive and defensive activities and the transfer of risks from one party to another.

What is the legal risk difference between the diversion of company funds to pay bribes in a foreign country and the theft of company trade secrets?  You see, the laws associated with these loss events have different statutes, penalties and legal risk:
On December 17, 2012, Germany-based insurance and asset management company Allianz SE paid more than $12.4 million to settle with the SEC over violations of the books and records and internal control provisions of the FCPA. The activity in question concerned improper payments to government officials in Indonesia. Following common FCPA procedure, Allianz did not deny or admit the SEC’s inquiry. The company disgorged $5.3 million in profits, paid a penalty of $5.3 million, with $1.8 million in prejudgment interest. 
The SEC stated that it uncovered 295 insurance contracts on government projects that were obtained or kept by improper payments totaling $650,626. The payments were made by Allianz’s Indonesian subsidiary. 
The conduct occurred from 2001 to 2008, at which time Allianz was considered an “issuer” under the FCPA because of its activity on the New York Stock Exchange. Even though it was not listed on the exchange, the presence of its bonds and shares on the market made it an issuer and subjecting it to the jurisdiction of the FCPA. The investigation was initiated internally using outside counsel after a whistleblower complaint in 2009.
On December 28, 2012, President Obama signed the Theft of Trade Secrets Clarification Act. S. 3642 (112th). The Clarification Act is a direct response to the Second Circuit’s decision in U.S. v. Aleynikov, 676 F.3d 71 (2nd Cir. 2012). (See details below.) In Aleynikov, the Second Circuit overturned a criminal conviction under the Economic Espionage Act 18 U.S.C. § 1831, et seq., after the court determined that the stolen source code was only used internally for a high-frequency trading system and was not “related to or included in a product that is produced for or placed in interstate or foreign commerce.” The Clarification Act expands Section 1832(a) to cover internal trade secrets “related to a product or service used in or intended for use in” commerce. In addition to the source code at issue in Aleynikov, this expansion could include internal processes of doing business or gathering information that may not qualify for traditional patent protection. More broadly, the quick reaction shows the importance that Congress attaches to this area of the law and puts individuals and companies on notice that increased indictments may occur down the line.
The ethics, compliance and legal components of Operational Risk Management comes down to "Achieving a Defensible Standard of Care" in your organization.  The risk exposures that face your organization will also occur from a more immediate impact, due to a loss of reputation and potential loss of market value.  On all fronts, the stakes remain high.

The modern day legal enterprise is still reactive and slow to respond to the changing environment around it.  The daily battle with legal risk is slow, compared with other risk management fronts within the institution.  The speed of response and the focus on preventive, preemptive or proactive actions is what sets apart the mental states of all of your security risk professionals.  Some people have seconds or minutes to decide and act, others have the luxury of days, months and years.

Unfortunately, for most the costs associated with legal risk are high, no matter who prevails in an incident or case. This fact alone, is why the introduction of a new generation of automated tools and the memory of computer-based evidence is so important.  Decision Advantage.  The law and the law industry is quickly playing catch up.  Practitioners from the technology and legal industry are now even more integrated, while the courts interpret the implications of their rulings on an accelerating mobile digital global society.

You and your team have a tremendous amount of new knowledge to gain, or your enterprise will be consumed by the volume of new Operational Risks unfolding before it.  How complex could this be?

The 1983 movie "WarGames" led to an anti-hacking law with felony penalties aimed at deterring intrusions into NORAD. Over time, it became broad and vague enough to ensnare the late Aaron Swartz.

22 April 2012

Workplace Trust: Integrity, Ethics & Legal Risk...


Operational Risk Management professionals wonder about the "Tone at the Top" and decisions at the latest Board of Directors meetings to ignore or investigate a whistleblowers claims of ethics or governance violations in the workplace.

The financial services companies have for years been the target of scrutiny for claims of fraud, mistreatment of consumers and violations of several U.S. federal regulations many under further examination by the SEC.  As time goes on in the evolution of maleficence you will find examples of wrong doing in other private sector areas, such as the Defense Industrial Base (DIB), Retail and Information Technology (IT).  Think about your own company and ask yourself how you treat and respond to the 800 number Ethics Line and those who staff the Internal Audit, Risk Management or Information Security departments.  Are these enablers or impediments to your future success?  Your answer may be a clue to the issue at hand.

The professionals in the Inspector Generals office, the Operational Risk Management department and the General Counsels office are also there for a good reason.  Think about them as the last "Thin Blue Line" between your company becoming a success or falling into a cultural abyss that will plague the institution for decades.  Steven Pearlstein explains from the Washington Post:

Steven Pearlstein: How could SAIC miss this? By , 
Last week in these pages, The Post ran a profile of John Jumper, the straight arrow former Air Force general who was brought in as chief executive of local contracting giant SAIC in the wake of an embarrassing overbilling scandal involving bribery, kickbacks, foreign shell corporations and a safe deposit box stuffed with $850,000 in cash. 
A year ago company officials were publicly denying that there were any problems at all with its contract to build a new timecard system for New York City, which by then was so late and so over budget that “CityTime” had become a frequent target for the New York tabloids and political embarrassment for Mayor Michael Bloomberg. 
It was just last June that SAIC executives and directors first informed shareholders that there might be a little $2.5 million overbilling problem with the contract and that federal prosecutors had brought criminal charges against six employees of an SAIC subcontractor. Shareholders had to read deep into Note 9 of that quarterly report to learn that there might be “a reasonable possibility of additional exposure to loss that is not currently estimable” that “could have a material adverse impact” on the company’s finances.


This episode by one DIB contractor, was not the first nor will it be the last.  One has to ask whether the advice these companies are getting from their outside counsel is always the right course of action.  The government and the internal risk management departments are going to be continuously deluged with new whistleblower claims.  Not just because new laws are in place to protect them and to provide them with the incentives to come forward.  It is because good people are sick and tired of having their organizations reputation tarnished and their respective ethical practices being jeopardized by a few bad cowboys or rogue actors.  Yet now, the Retail sector is being taught a serious lesson regarding a potential FCPA violation by Wal-Mart.  David Barstow at the NYT has this to report:

By  
Published: April 21, 2012  MEXICO CITY — 
In September 2005, a senior Wal-Mart lawyer received an alarming e-mail from a former executive at the company’s largest foreign subsidiary, Wal-Mart de Mexico. In the e-mail and follow-up conversations, the former executive described how Wal-Mart de Mexico had orchestrated a campaign of bribery to win market dominance. In its rush to build stores, he said, the company had paid bribes to obtain permits in virtually every corner of the country. 
The former executive gave names, dates and bribe amounts. He knew so much, he explained, because for years he had been the lawyer in charge of obtaining construction permits for Wal-Mart de Mexico. 
Wal-Mart dispatched investigators to Mexico City, and within days they unearthed evidence of widespread bribery. They found a paper trail of hundreds of suspect payments totaling more than $24 million. They also found documents showing that Wal-Mart de Mexico’s top executives not only knew about the payments, but had taken steps to conceal them from Wal-Mart’s headquarters in Bentonville, Ark. In a confidential report to his superiors, Wal-Mart’s lead investigator, a former F.B.I. special agent, summed up their initial findings this way: “There is reasonable suspicion to believe that Mexican and USA laws have been violated.”

Mitigation of Operational Risks in the workplace, such as fraud and corruption is different than it is outside the enterprise.  The difference is, that corporate executives do not always believe that their own employees would behave this way.  They could be naive to the reasons why fraud finds its way into the psyche of some of the organizations must trusted officers.  Corruption and the signs that an organization has lost its way from a place of cultural integrity and one that condones others to look the other way or for many to help perpetuate schemes of wrong doing, requires a massive organizational transformation.  A transformation that is lead by focused and talented Operational Risk professionals.

But most of all, even if you have these professionals on your team already, there are still some important ingredients to achieving your own "Defensible Standard of Care":

1.  If you think you have funded the risk management department in your enterprise adequately, you haven't.  Do not confuse your outside audit function with your internal risk management function. 
2.  If you don't understand how your 800 number ethics line works and the outsourced organization that runs this, then you need to do so immediately. 
3.  If you have a favorite outside counsel to help you with investigations, it might be time for a check up.  Even more importantly, it might be time to get your outside counsel firms and your outside audit firms invited to a meeting of the minds on corporate integrity. 
4.  If you find any indications that 1 through 3 have been ignored, pushed aside or been giving you a false sense of security, then you might consider making a career change.

Tech Inc., a rapidly growing software company operating in 45 countries, learns that the U.S. Department of Justice (DOJ) and the Securities and Exchange Commission (SEC) are investigating payments made by its subsidiaries in Brazil and China for possible violation of the Foreign Corrupt Practices Act (FCPA). Bob, the general counsel for Tech Inc., suspects that the source of the investigation is an employee who anonymously lodged a hotline complaint alleging that the company was 1) paying independent sales agents excessive commissions and 2) providing generous discounts and rebates to some of its channel customers and distributors. The complainant also said he believed the problem extended beyond Brazil and China based on discussions he had with other employees.

18 June 2011

FCPA Alert: Dodd-Frank vs. Powerball...

Board Directors are ever more tuned into the recent 2011 case settlements in Foreign Corrupt Practices Act (FCPA) violations. This is because Operational Risk Professionals are being much more proactive than years past on uncovering malfeasance in the supply chain operations of major global conglomerates:

Notable 2011 FCPA Settlements. 2010 was a record year for FCPA enforcement, and thus far 2011 has been no different. In the first half of 2011, 10 notable FCPA enforcement actions have settled, resulting in a total of about $490 million in penalties, disgorgement and prejudgment interest:

1. Tenaris agreed to pay a $3.5 million criminal penalty and $5.4 million in disgorgement and prejudgment interest.

2. Rockwell Automation agreed to pay disgorgement of $1.7 million, prejudgment interest of $590,000 and a civil penalty of $400,000.

3. Johnson & Johnson agreed to pay a $21.4 million criminal fine and $48.6 million in disgorgement and prejudgment interest, as well as about $7.9 million in related United Kingdom Serious Fraud Office recovery.

4. Comverse agreed to pay a $1.2 million criminal fine and $1.6 million in disgorgement and prejudgment interest.

5. Ball Corporation agreed to pay a $300,000 civil penalty.

6. Jeffrey Tesler, a key member of the TSKJ-Bonny Island joint venture accused of being part of a scheme to bribe Nigerian officials in exchange for contracts related to the construction of liquefied natural gas facilities, forfeited nearly $149 million, the largest FCPA-related forfeiture imposed on an individual to date.

7. JGC Corporation of Japan agreed to pay $218.8 million in criminal fines.

8. IBM agreed to pay a $2 million civil penalty, disgorgement of $5.3 million and $2.7 million in prejudgment interest.

9. Tyson Foods, Inc. agreed to pay a $4 million criminal penalty and $1.2 million in disgorgement and prejudgment interest.

10. Maxwell Technologies agreed to pay $8 million in criminal penalties, as well as $6.4 million to settle SEC civil charges.


Are any Board Directors out there amazed that companies such as IBM are still being impacted by the FCPA risk to the enterprise? Maybe more importantly, why is a Japanese company paying a criminal fine of over two hundred million dollars?

JGC CORPORATION is a Japan-based company mainly engaged in the engineering business. The Company operates in two business segments. The Integrated Engineering segment is engaged in the planning, design, procurement, construction and testing of equipment, appliances and facilities for petroleum, petroleum processing, petrochemistry, gas, liquefied natural gas (LNG), general chemistry, nuclear energy, metal smelting, biotechnology, food, pharmaceutical, logistics, information technology, environment protection and pollution prevention industries. This segment is also engaged in the provision of related inspection, maintenance and information processing services, as well as water and power generation business, among others. The Catalyst and Chemical segment is involved in the manufacture and sale of catalyst agents, functional materials, deodorants and enzymatic filters, electronic materials and high-performance ceramic products, as well as next-generation energy related products.

The Board of Directors of any transnational organization should be doing their homework on the reasons why JGC Corporation has employed an independent compliance consultant for the next two years and paid the $200M. fine. Remember, your supply chain and your business partners may be the reason why you are sitting around the Board Room table negotiating with the U.S. Department of Justice.

The larger question is, could this have been prevented? Is this a risk that can be mitigated within the corporate enterprise? Has the company done everything in it's capacity to put the right controls in place and the tools to keep the possibility of FCPA ever finding its way back to the Board Room Agenda? Do you know all of your joint venture partners are from the U.S. and all of the projects that they are working on together?

JGC’s agreement to pay the fine brings to $1.5 billion the total penalties in a case against a joint venture known as TSKJ that included Houston-based Kellogg Brown & Root LLC, Paris- basedTechnip SA (TEC) and Dutch engineering firm Snamprogetti Netherlands BV, according to a Justice Department statement.

The joint venture’s prosecution represents one of the biggest foreign bribery cases undertaken by the Justice Department since it stepped up pursuit of such cases starting in 2008 when Munich-based Siemens, Germany’s largest engineering company, paid $1.6 billion to settle U.S. and German probes.

“Each of the four companies in the TSKJ joint venture, the former chairman of the U.S. joint venture partner, and several other individuals have now been held accountable for a massive conspiracy to bribe Nigerian government officials to obtain lucrative construction contracts,” Deputy Assistant Attorney General Mythili Raman said in the statement.


What is the cost of a FCPA investigation beyond the fine? Imagine for a moment the number of e-mail messages that have to be acquired, preserved and examined. Add up the billable hours for subject matter experts to review the remaining mountain of data to determine the final relevancy of a communication with the matter and the people associated with the project. As an example, what was the magnitude of the Siemens case?

According to court records, it was a vast undertaking spanning 34 countries, with private investigators conducting more than 1,750 interviews and gathering more than 100 million documents. They reviewed approximately 14 million of those documents and gave the Justice Department and the SEC a small subset, about 24,000, according to a Siemens tally.


So what is one of the answers or solutions to finding the "Red Flags" and to self-disclose the issue to the proper authorities early and often? First off, you need to develop your corporate "Human Intelligence" (HUMINT) capability, around your Corporate Intelligence Unit (CIU). Developing and building an awareness factor in a pervasive manner is one way to do this. In order to get your HUMINT working for you, the people on the front lines and in the middle of the corporate hierarchy need to understand and internalize these "Red Flags". If the monthly or quarterly bulletin from the CEO, discussing the integrity factor of the company supply chain partners raises the issue of ethical behavior around a particular scenario, this will educate and increase awareness with those people in the enterprise who comprise this HUMINT network.

Sticks and carrots or other methods for awarding compliance is so 1980's and 1990's. Wake up! In order to bring your global enterprise into the next decade of the 2000's, you have to start using the methods, processes and tools your deal makers use to run their business (SAP, Siebel CRM, Oracle). When was the last time the CEO visited the deal makers pipeline meeting to review and discuss the joint ventures or pending projects that the business developers are forecasting to close in the next quarter? This is the perfect time for the CEO to ask them to fire any partner, agent, consultant, contractor or vendor that does not meet the foundation for the companies "Corporate Integrity Standards." Does your CEO even know what Social CRM is all about?

And how quickly the lessons that should have been learned, are soon forgotten. Not any more. Under the Dodd-Frank Wall Street Reform and Consumer Protection Act, employees, partners and other persons who provide original information on an FCPA violation by a public company can receive between 10% and 30% of the resulting fines as a "Whistleblower" bounty.

We wonder whether the odds of winning the next "Powerball" Lottery in the U.S. might be more difficult than getting 20% of a $200 million dollar fine. Global corporations should be preparing their internal processes for Ethics and Integrity Management now. This Operational Risk will soon be more apparent as employees understand the odds of "Winning".

18 September 2010

China Syndrome: FCPA & Rating Agencies...

A modern day "Operational Risk China Syndrome" is making the Board of Directors nervous these days. The new syndrome otherwise called the Foreign Corrupt Practices Act (FCPA) has been the buzz at rating agencies for months. Are you sure about your ability to withstand the scrutiny of a FCPA litmus test? Board Member Magazine explains:

On June 2nd, Fitch Ratings agency announced that Foreign Corrupt Practices Act violations could result in ratings downgrades. That’s one more reason boards should educate themselves on FCPA and how their companies are monitoring FCPA-related risks. It appears, though, that many boards do not feel comfortable with their companies’ compliance programs. In a soon-to-be released survey from KPMG’s Audit Committee Institute, only 27 percent of U.S. audit committee members said they were satisfied that their company had an effective process to manage Foreign Corrupt Practices Act risks, and other risks associated with doing business in Brazil, Russia, India, China and other emerging markets. 35 percent of respondents were only somewhat satisfied, and 9 percent said process improvements were needed in conducting such business, which may include sourcing, outsourcing, manufacturing, or sales and distribution channels.

As your Business Development teams fan out across the globe to satisfy the appetite of the Chinese economy for critical infrastructure, establish a sound and effective awareness, training and audit program. What are the ramifications of putting unprepared personnel on the ground to do business in the Chinese Markets?

American companies or individuals who enter joint ventures with foreign partners, as well as those who hire foreign agents or distributors in China, must be extremely cautious of the vicarious liability that they may face as a result of a third party's violation of the principles set forth in the FCPA. According to the Justice Department, an American company will be subject to liability under the FCPA if it makes payments to an intermediary third party with the knowledge that such payments will go to a foreign official for corrupt purposes. Conscious disregard is enough to satisfy the requirement; if the American company is aware of a "high probability" that such payments will occur, the knowledge requirement will be satisfied. More importantly, a joint venture partner, agent, or distributor will be considered an intermediary third party for purposes of the FCPA. Therefore, any violation of FCPA standards by one of those parties could result in the American company being vicariously liable under the FCPA.

In order for the Board of Directors to have peace of mind on the emerging markets business opportunities first a substantial compliance framework needs to be established. Next, the implementation of predictive analytics software to manage the complexity of companies, people and relationships as you do business in any of these countries. This includes the subscription to several databases that include the constantly changing landscape of specially designated nationals (SDN) and politically exposed persons (PEP). World check explains:

During the period 2005 to 2007 alone, more than 310 elections and by-elections took place around the world – that’s an average of nearly 10 elections per month. (Source: ElectionGuide.org). This means that your existing clients may be elected to public office, and hence become PEPs, without your business knowing it. It may be that you only apply your due diligence processes to new customers and so miss a whole category of individuals that do not meet your corporate risk appetite. As such, routine and ongoing PEP risk screening is not only considered best practice, but is also a legal requirement.
In practice, full compliance with PEP legislation has not come without major operational challenges. In the post-9/11 era, the proliferation of regulatory compliance laws, combined with the need to screen hundreds of thousands of users and accounts on a routine basis, has created a substantial administrative burden for businesses subject to PEP legislation.

The sheer magnitude of the due diligence challenge has subsequently led to the adoption of a risk-based approach to regulatory compliance, but nevertheless Enhanced Due Diligence and ongoing risk management is still required for PEPs. Broadly speaking, the risk-based approach entails the identification of risks that exceed your business’ stated risk appetite (including the need for regulatory compliance), and then matching individuals and entities against these heightened risks during the preliminary stages of due diligence. Should a person fall into one or more of the specified heightened risk categories, additional due diligence is then required.

As your company establishes it new China-based strategy for partnerships, joint ventures or actually putting employees in country the operational risks become exponential. Remember, a sound and prudent risk framework includes a 4D approach:

  • Deter
  • Detect
  • Defend
  • Document

With these established and operating on a global basis the Board of Directors will be sleeping more soundly. Or perhaps not...learn more.

24 April 2010

FCPA: OPS Risk in Pharma & Small Business...

If you are a large U.S. based pharmaceutical company the odds are that over a third of your annual sales are overseas. Selling drugs in the EU, Asia and South America into the health care systems is a tremendous pipeline for Eli Lilly, Pfizer and others who find these markets hungry for their products. What kind of Operational Risks might exist for these firms and should be on "Red Alert" status with the General Counsel?

The DOJ is currently pursuing 120-130 FCPA investigations, and now it has set its sights on enforcement in the pharmaceutical industry where on an annual basis “close to $100 billion dollars, or roughly one-third, of total sales … [are] generated outside of the United States.” The DOJ’s new focus stems in part from the fact that many foreign health systems are regulated, operated and financed by government entities, and competition is intense, which creates more opportunities to “pay off foreign officials for the sake of profit,” and a perceived need for greater supervision from law enforcement.

The head of the Criminal Division of the United States Department of Justice (DOJ), Assistant Attorney General Lanny A. Breuer has indicated their interest in looking at this industry with increased scrutiny. So if you are a General Counsel at one of the companies in the cross-hairs of the government what are you doing about it?

First, you have to call together the right people and create your own internal FCPA Task Force within the enterprise. The General Counsels Office has the lead on bringing together four to six people from Sales & Marketing, Finance, Information Technology, and Internal Audit. This team will have the autonomy, funding and jurisdiction to work specifically on the vulnerabilities that exist on a global basis.

Second, you have to understand the culture, governments and the "Ground Truth" in each country you are selling your pharmaceuticals in, to map the processes and the people associated with the heath care systems, hospitals or the military that are the actual consumers of the medicines and drugs.

Finally, you have to educate your work force on the fact that pharmacists, doctors, lab technicians and other health care consultants may indeed be officials of the government of that country based upon who they work for. Why is this important?

The FCPA has a broad definition under the law that pertains to the foreign officials. In some countries it's entirely possible that if the medical institutions are owned by the government that almost everyone who works in these facilities could be considered under the FCPA. So what is the task force going to do to ensure that the company does not violate the law?

Beyond the focus on compliance and education of employees, there is much work to be done in the collection, analysis and actions within the enterprise of relevant information. Predictive analysis of data that is coming from the CRM, ERP and other open sources can provide the task force with the "Corporate Intelligence" and "Red Flag" warning to prevent a violation of the law. The ability of the company to utilize data collection and predictive analytics to not only head off any DOJ investigation also can be effective in providing voluntary disclosure to government.

Wait a minute. You mean, tell the government that we have identified a violation of the law and bring the wrath of the law and the possible impact on our corporate reputation? Yes and this is why.

Under Federal Sentencing Guidelines, those organizations that do a rigorous internal investigation and share the results with the government can avoid such sanctions as the mandate for a costly independent compliance monitor. Deferred prosecutions are not unheard of and the government can in some cases help you save money in terms of getting fines on the lower end of the sentencing guidelines.

The General Counsel's "Corporate Intelligence Unit" that is focused on the analytics of relevant data, combined with the education, awareness and compliance processes will be well on there way to keeping the legal risk and Operational Risk events associated with the Foreign Corrupt Practices Act (FCPA) from impacting their global pharmaceutical enterprises. And just when you think that the DOJ is only looking at the Fortune 500, then think again:

More focus on small and mid-sized companies: As part of their increased FCPA-related efforts, the DOJ and SEC are expected to look more at small and mid-sized firms which do business overseas. The majority of such companies have a small established compliance program, or none at all, yet some may conduct billions of dollars in foreign transactions.

Companies that are not household names have long believed that they were under law enforcement’s radar. Smaller firms have also thought that the DOJ would not expend the resources to investigate their overseas sales. That comfortable illusion no longer exists.

If you are a small disadvantaged supplier to a large Defense Industrial Base (DIB) company working on a sub-contract, then you too should be standing up your FCPA Task Force now:

On January 18, 2010 twenty-two business executives were arrested and over 100 FBI agents conducted related searches. These actions were based on sealed federal indictments handed down by a grand jury several weeks earlier, which in turn stemmed from a two-and-a-half year undercover operation. The indictments claimed that the defendants believed that they were involved in a scheme to acquire a US$15 million defense contract to outfit the presidential guard of an unnamed country. They allegedly agreed to pay a 20 percent bribe to a sales agent, supposedly representing the defense minister but really an undercover FBI officer. This was the first large-scale use of undercover law enforcement techniques to investigate Foreign Corrupt Practices Act (FCPA) violations.

29 October 2009

Legal Risk: The Art of Compliance...

Risk Management is on the mind's of Corporate Directors and in some interesting places according to a recent poll by PWC and Corporate Board Member Magazine:

How has your personal risk as a director changed in the past 12 months?

Increased 69%
No change 30%
Decreased 1%

Some risks are tough to name...

What keeps you up at night?

Unknown risks 59%

...while others are identifiable.

Do you think regulators are more likely to investigate your company?

Yes 71%

Do you think there'll be an increase in shareholder suits?

Yes 65%

If 71% of the directors surveyed think that regulators are more likely to investigate the company where does that feeling come from? Is it the fact that the SEC and others such as the FTC, OCC and others are gearing up to facilitate greater oversight than in past years? Is it the lack of internal focus on creating a systemic Risk Management Framework? Could it be the amount of toxic assets that are still on the balance sheet? The answer is yes, yes, and yes.

So what can Directors do to make sure that management and the company are ready when the "Feds" come to town? The answer may well lie in the ability to show a history and evidence of doing the right thing and doing it with extreme diligence.

For good or bad—okay, mainly for bad, most respondents agree—the government as boardroom-player-cum-active-investor will be around for a foreseeable spell.

Regulation will rise...

Do you think there will be a big increase in regulation?

Yes 91%
No 2%

Of that 91%, 54% “strongly agree” with the premise that there’ll be more regulation, 37% “agree.”

...and spread.

Do you think other companies will have to adopt rules that the government has imposed on those receiving financial help?

Yes 54%
No 20%

Nearly 45% of the respondents say no amount of government control, whether more or less than what we got, could have prevented the severity of the economic crisis.

No to Uncle Sam as paymaster

Respondents are against the feds’ having a say in setting executive pay.

Are government limits on executive compensation justified?

No 88%

Should the government impose further limitations on pay?

No 97%

Should comp be left to the board?

Yes 76%


The only hope for "Achieving A Defensible Standard of Care" in your institution could be what Siemens and other wrongdoers have discovered. Spending hundreds of millions of dollars on "Compliance" might be a good thing when the time comes to differentiate yourself in the marketplace and negotiate with the government. Especially if you are a global enterprise doing business in countries that don't exactly have the best reputation with transparency and the rule of law. Here is what Chairman of the Supervisory Board of Siemens AG, Gerhard Cromme had to say on their efforts to date:

Wherever wrongdoing was proved beyond a doubt, we immediately took the necessary actions. Wherever there were systemic weaknesses, we identified them and corrected them. Where the necessary resources were lacking, we provided them. These demanding efforts have paid off: Today Siemens has a clear, transparent structure that no longer allows any gray areas with respect to responsibility. At the same time, these structures make Siemens more efficient, more cost-effective, and thus more competitive. The authorities took into consideration our unflinching desire to do whatever was necessary for a fresh start in determining the size of the penalties and the duration of the proceedings.


Operational Risk encompasses the actions taken by Siemens that includes the new centralized systems for payments, disbursements and other accounting functions that were previously in business units outside of Germany. This consolidation and integration of systems was not easy but represents that a discovery in the vulnerability of controls with a decentralized system warranted the investment in a new way of doing business.

Only time will tell whether any companies Board of Directors efforts to spend more resources on "The Art of Compliance" will make a difference to the regulators, investigators and litigators. One could probably bet that over time it will make a difference. But only if the "Tone at the Top" is commensurate with the actions being asked of the employees and stakeholders, doing the day-to-day tasks running the risk operations of the enterprise.

18 July 2009

FCPA: Modern Day "Smoking Gun"...

Corporate malfeasance is on the mind of most global executives today. Their enterprise is consistently fighting the economic challenges and at the same time defending it's reputation as new "Smoking Guns" are revealed. Perhaps these modern day discoveries of wrong doing should be renamed "Smoking Digital Evidence" because this is exactly what it is. Information uncovered through normal monitoring practices or as the result of a specific investigation produces "Red Flag" alerts based upon acceptable use policy or corporate rule sets.

These "Red Flags" uncovered in the context of programs devoted to processing digital evidence is now a standard Modus Operandi for corporate governance, legal and operations risk management. These new tactical business units are being developed in a rapid response to new regulatory and compliance mandates yet the greater pressure is coming from the wake-up calls senior executives have been receiving lately.

The Justice Department's probe of the credit default swaps market is reportedly focusing on Markit Group Holdings Ltd., the London-based supplier of prices in OTC derivatives, and its relationship to a group of major banks that own a stake in the company. The DOJ is scrutinizing the ownership of Markit by a group of banks that control a large amount of pricing in the $28 trillion credit derivatives market.

The banks have received a notice of investigation from the DOJ asking them for details on their trading activity, including how much they have at risk in the market and their monthly value of their credit default swaps, according to Bloomberg News. Banks that own the largest stakes in Markit, include: J.P. Morgan, Bank of America (through its acquisition of Merrill Lynch), Deutsche Bank, Royal Bank of Scotland which acquired ABN Amro, as well as Credit Suisse, Goldman Sachs, Morgan Stanley and UBS, according to Bloomberg News.

"The DOJ is looking to find any wrongdoing in that marketplace," commented Paul Zubulake, senior analyst at Aite Group in an interview with Wall Street & Technology. "Obviously that is going to open up a large can of worms," he said. "It will be costly for the dealers that have to battle the DOJ given the discovery issues, about all the information, emails and instant messages they will need to turn over."

Digital Forensics, Records Management and eDiscovery units at some of the largest financial institutions are working overtime. Finding any "Smoking Digital Evidence" will be the standard operating procedure on most international transactions whether it be in the financial services industry or even telecommunications:

Good news for compliance officers: You now have solid evidence that the benefit of implementing an effective compliance program far outweighs the cost, in the form of the massive Foreign Corrupt Practices Act settlements swallowed by Siemens AG and three of its foreign subsidiaries.

Siemens, a German conglomerate that is one of the largest engineering firms in the world, agreed in December to pay more than $1.6 billion to U.S. and German regulators for a massive bribery scheme that felled the highest executives at the company. Penalties paid to the Justice Department and Securities and Exchange Commission alone topped $800 million, by far the largest sanction ever imposed in an FCPA case.

In the following excerpt, Linda Chatman Thomsen speaks on the massive Siemens investigation: "Furthermore, the $1.6 billion total that Siemens will pay in these settlements is the largest amount that any company has ever paid to resolve corruption-related charges.

And that is fitting because the alleged conduct by Siemens was egregious and brazen. It was systematic, it involved thousands of payments, and it occurred over an extensive six-year period. Siemens created elaborate payment schemes to conceal these corrupt payments to foreign officials. The company’s inadequate internal controls allowed the conduct to flourish.

The details tell a very unsavory story: employees obtained large amounts of cash for Siemens’ cash desks; employees sometimes carried that cash in suitcases across international borders to pay bribes; payment authorizations were recorded on post-it notes that were later removed to avoid leaving any permanent record; there were slush funds and a cadre of consultants and intermediaries to facilitate paying the bribes.

Investigating this intricate scheme and righting Siemens’ wrongs has taken a remarkable and unprecedented level of coordination among many law enforcement agencies around the world."

The internal threat of employees, partners and so called in-country agents who help facilitate business deals is one square in the risk management matrix. The business transactions themselves are becoming part of the Venn Diagram that includes:

  • Business & Global Commerce
  • Personnel Security & Integrity
  • Rule of Law & Litigation
As global institutions continue their expansion across the continents where capital follows security and the rule of law, so too will the attacks on the corporate enterprise.

25 April 2009

Human Factors: Early-Warning System...

Predictive Intelligence And Analytics From 1SecureAudit Provides Transnational Organizations With A Preemptive Human Factors Early-Warning System

According to Managing Director and Chief Risk Officer of 1SecureAudit, Peter L. Higgins, the complexity of today's extended global enterprises requires a new governance lens to view hidden insider risks and to guide management executives to achieving a defensible standard of care.

"Our newest consulting practice accelerates the time line in identifying employee insider risks and potential threats associated with international client transactions," said Higgins. "Ms. Marcia Branco is launching our new client offering with more than a decade of experience identifying the complex connections between human behavior and corporate operational risk responsibility."

Advocating a "People First" approach, Ms. Branco, vice president, practice director of the Predictive Intelligence and Analytics practice, believes corporate personnel; partners and suppliers represent a tremendous asset and simultaneously a significant legal liability to a business. "People are the primary focal point to better understanding and resolving systemic risk problems within the walls of the enterprise and beyond to the extended supply-chain," said Branco.

The Association of Certified Fraud Examiners affirms "U.S. organizations lose an estimated seven percent of annual revenues to fraud," and insider negligence is the highest cause of data breaches, reports the Ponemon Institute & PGP Corporation. The complexity and quantity of insider threats is growing at the same time as businesses are facing shrinking budgets and mounting pressures to maintain and grow profits with fewer resources. "How successful has your company been at identifying and swiftly addressing issues, conflicts and preventing malfeasance? Whether originating internally from an employee or contractor or at your extended border of partners, suppliers and clients, predictive intelligence is essential?" asks Higgins.

1SecureAudit provides critical assessments, internal investigations, strategy execution and program development. These proactive governance and advisory services generate positive change to business culture, operations and bottom line.

"Our distinctive 'People First' approach examines your organization's human capital assets to gain unique insights on corporate culture, company issues and the workforce's attitude about management and business initiatives. We convert these human factor data into predictive intelligence to preemptively determine how to best shape current and new corporate strategies. Our clients are able to take advantage of short-lived opportunities, attract and retain employees, partners and customers, demonstrate a more defensible standard of care and promote a trustworthy corporate reputation," stated Branco. "Does your organization consistently adhere to and enforce corporate policies, ethical standards and procedures that value your employees and respond to shareholder advocates?"

Working with 1SecureAudit to integrate predictive intelligence in any business strategy and practices is a sound investment that directly contributes to corporate management's, Board of Directors', and shareholders' peace of mind. For more information, visit 1SecureAudit.com or e-mail RDU (at) 1SecureAudit.com.