LAW HW
December 2014 Location: Peking University School of Transnational Law The Basics Rolling Out Your Corporate Compliance Program Carole Basri Adjunct Professor Fordham University Law School Visiting Professor Peking University Law School Cell: 917-822-2447 Email: [email protected] ©CBasri 2014
©Basri 2014
1
Carole Basri
BASIC REASON FOR AN “EFFECTIVE” CORPORATE COMPLIANCE PROGRAM
An effective corporate compliance program can:
Help insulate a company, and its officers and employees, from criminal and civil fines
Protect its board of directors from personal liability
Create a culture of “good citizen corporation” (5% good, 5% not, 90% follow)
2
Carole Basri
BASIC REASON FOR AN “EFFECTIVE” CORPORATE COMPLIANCE PROGRAM
A poorly constructed program can :
Serve a roadmap for prosecutors
Damage morale (employees view code of conduct as merely lip service by executives)
Encourage fraud and unethical conduct to continue
3
Carole Basri
Other Reasons To Implement an “Effective” Corporate Compliance Program
Federal Sentencing Guidelines, revised as of Nov. 1, 2004, requiring a “culture” of ethics and a Part C risk assessment or “best practice gaps” analysis to support the underlining structure of the corporate compliance program. (culture of ethics and best practice)
Justice Department guidance on the prosecutorial decisions in the Holder, Thompson, McNulty and, Filip Memorandum which states that in determining whether to charge a corporation for the criminal misconduct of its employees, prosecutors should consider, “the existence and adequacy of the corporation’s compliance program.”
4
Carole Basri
Other Reasons To Implement an “Effective” Corporate Compliance Program
NY Stock Exchange Rule 303A.10 requiring NYSE-listed companies to adopt codes of business conduct and ethics for directors, officers, and employees which codes are to be posted publicly. Further, waivers of the code for directors or executives must be promptly on a form 8-k.
NASDAQ Rule 4350 requires NASDAQ listed companies to adopt a code of conduct for directors, officers and employees which codes are to be posted publicly. Further, waivers of the code must be disclosed promptly on a Form 8-k within five days.
Large settlements with government against companies without “effective” compliance programs such as Siemens. ($1.6 Billion) check this (Look up JP Morgan and Bank of America)
5
Carole Basri
Other Reasons To Implement an “Effective” Corporate Compliance Program
Caremark Decision (Del.ch.1996), personal liability for directors for failure to oversee compliance program.
Avoidance of a Non Prosecution agreement (NPA) or Deferred Prosecution Agreement (DPA) with the government
The National Association of Fraud Examiners 2014 survey shows that the amount corruption in a corporation can be lowered by 51% with a hotline where reported violations are followed up by the company.
6
Carole Basri
History of Guidelines
U.S. Sentencing Guidelines Nov. 1, 1991 provided 7 steps for an “effective” compliance program.
U.S. Federal Sentencing Guidelines: Revised Nov. 1 2004
Provided for a “Culture of Ethics” (compliance and ethics are synonymous). (The right things to do versus doing the right thing)
And Includes Part C: Risk Assessment
7
Carole Basri
Part C plus Seven Elements Creates an “Effective” Corporate Compliance Program.
8
Carole Basri
Part C- Risk Assessment (Best Practice Gaps Analysis)
Anti-Money Laundering Act (AML)
Antitrust/ Competition
Conflicts of Interest
Conflict Minerals
Customs, Export Controls, and Sanctions
Cyber Security. Physical Security
Employment
Environmental
False and Deceptive Advertising
Foreign Corrupt Practices Act/ UK Bribery Act, OECD, and local bribery acts
Fraudulent Financial Reporting
Gifts and Gratuities
Government Contracting
Insider Trading
Intellectual Property
Lobbying, Political Contributions, and other political activities
New Business “Alliances”
Procurement of Goods/Services
Records Management
Privacy and Data Protection
Sexual Harassment
Social Networking
Subcontractors, Subsidiaries, and Consultants
Tax
Workplace Safety
US Patriot Act, Know-Your-Customer (KYC), OFAC, FACTA
Government Contracting
Insider Trading
Intellectual Property
Lobbying, Political Contributions, and other political activities
New Business “Alliances”
Procurement of Goods/Services
Records Management
Privacy and Data Protection
Sexual Harassment
Social Networking
Subcontractors, Subsidiaries, and Consultants
Tax
Workplace Safety
US Patriot Act, Know-Your-Customer (KYC), OFAC, FACTA
9
Carole Basri
Part C plus Seven Elements Creates an “Effective” Corporate Compliance Program.
Standards, procedures, and controls to prevent and detect criminal conduct;
Board must be knowledgeable about and oversee program; top management must ensure effectiveness of program; specific individual(s) within high level personnel must have responsibility for program;
Reasonable efforts not to include within substantial authority personnel individuals who organization knew or should known have engaged in illegal activities or conduct inconsistent with effective program;
Communicate standards and procedures by training directors, employees and, as appropriate, agents, and by other means;
10
Part C plus Seven Elements Creates an “Effective” Corporate Compliance Program.
Auditing, monitoring, testing, and surveillance to detect criminal conduct; evaluate program periodically; have and publicize a system for reporting suspected violations and seeking guidance;
Promote and consistently enforce through appropriate incentives to perform in accordance with the program and appropriate discipline; and
After criminal conduct is detected, take reasonable steps to respond appropriately and prevent further similar criminal conduct, including necessary modifications to program.
Carole Basri
Seven Elements of An Effective Corporate Compliance Program are as follows:
Carole Basri
First Element
Written Policies, Procedures and Internal Controls for Risk Areas include the following:
Standards of Conduct
Internal Controls
Mission statement
Letter from CEO
Code of Conduct or Code of Ethics
Employee handbook
Corporate Compliance Program Guidelines
Alignment of Code of Conduct, Polices and Procedures, and Internal Controls
Carole Basri
Second Element
Board must oversee the compliance program. Top management should take a leadership role in fostering the compliance program.
Designate specific “High-Level Personnel” to oversee compliance such as a compliance officer.
A compliance officer is critical to the success of the compliance program.
A chief compliance officer should be appointed to coordinate the activities of individual compliance “officers” at subsidiaries.
Carole Basri
Second Element
The compliance officer should have the following:
Direct access to CEO and Board of Directors, and
Sufficient funding and staff
Carole Basri
Second Element
The compliance officer’s responsibilities include:
Overseeing and monitoring the implementation of the compliance program;
Reporting on a regular basis to the CEO and compliance committee the Board of Directors (if direct reporting) or to the General Counsel, CFO, or other officer of the corporation (indirect reporting);
Periodically revising the program in light of new developments;
Developing, coordinating and participating in a multifaceted educational and training program that focuses on the elements of the compliance program;
Assisting the financial management in coordinating internal compliance reviews and monitoring activities;
Independently investigate and act on matters related to compliance, including the flexibility to design and coordinate internal investigations; developing policies and programs that encourage managers and employees to report suspected fraud and other improprieties without fear of retaliation.
Carole Basri
Second Element
Reporting lines (Directed or Dotted Line) and Organizational Charts are critical tools
Carole Basri
Third Element
Reasonable efforts not to include in the compliance organization personnel of questionable integrity
Coordinating background checks on all employees with the Human Resources department involved in compliance administration and coordination
Background checks can only be performed at time of hire, promotion, or salary increase
Background checks can only check convictions, not arrest records (Beware of Ban the Box)
Only potential employers (not 3rd party providers can review social media)
Carole Basri
Fourth Element
Effective communication of Standards and Procedures
Training should include the following areas:
code of conduct;
employment issues;
conflict of interest issues;
anti-bribery issues;
using e-mail, voicemail, newsletters, memoranda, etc., to aid communications; and other topics as necessary.
Training should be at the time of hiring as well as regularly scheduled at least once or twice a year as necessary.
Types of training include internet, train the trainer, and in-person training.
Carole Basri
Fifth Element
Developing effective methods of monitoring, auditing, testing, reporting, testing, surveying, and publicizing the system.
Creating an anonymous hotline and protecting whistle blowers;
Setting up a regular auditing and monitoring schedule including on-site visits and spot checks;
setting up surveillance;
setting up testing; and
publicizing results of the compliance program.
Carole Basri
Sixth Element
Consistent enforcement through corrective actions and incentives
Written policy on disciplinary standards;
Create incentives system;
Dissemination of standards to new and existing employees; and
Performance evaluations for all employees including criteria on compliance values, ethics, integrity, and attendance at training sessions
Carole Basri
Seventh Element
Take reasonable steps to respond to detected criminal offenses
Detecting criminal violations;
Creating internal investigation protocols;
Conducting internal investigations (if appropriate);
Reporting criminal violations; and
Updating the Corporate Compliance Program
Carole Basri
Corporate Compliance Program Roll Out
Carole Basri
Phase I
Conducting a High Level Compliance Risk Assessment
During Phase I, you should:
Form a committee;
Request an inventory of documents;
Interview key officers and employees;
Prepare a report on Risk Assessment, including Best Practices and Gaps;
Prepare heat maps and dashboards;
Carole Basri
Phase I
The Committee should be composed of at least the following:
CEO or President
General Counsel
CFO
Internal Audit Director
Carole Basri
Phase I
The Committee should report to the Audit Committee of the Board of Directors or directly to the Board of Directors
Request an inventory of documents including written policy and procedures on key risk areas, employee handbooks, litigation logs, training manuals, corporate filings, existing codes of conduct, insurance policies, etc.
Interview key officers and employees of the company and all subsidiaries including the following:
President,
Business Development/Sales Marketing,
General Counsel/Outside Counsel,
Chief Financial Officer,
Human Resources Director,
Environmental Health and Safety, if any,
Compliance Officer, if any, and
Other key officers and employees, as necessary
Carole Basri
Phase I
Based on the interviews, prepare a report on Risk Assessment, including Best Practices and Areas of Deficiency (gaps) based on the following questions:
What are your key risk areas?
What are the standards and procedures that you now have in place in these risk areas?
What are the areas you have successfully limited risk and how?
What areas could you improve in the cost to limit risk and how?
What is happening in such key areas as antitrust, environmental, employment, intellectual property and insider trading?
Describe the company culture toward corporate compliance and limiting risk.
Carole Basri
Phase I
Present the report on Risk Assessment, including Best Practices and Gaps:
The report should provide a risk assessment for relevant areas of law.
The report should be presented to senior management and the Board of Directors.
The report should be presented to the officers of all subsidiaries who were interviewed.
The report should include Heat Maps and Dashboards.
Buy-in on the report should be encouraged.
Create a Workplan which includes a timetable and an action plan.
Carole Basri
Phase II
Develop an Overall Compliance Blue Print
During Phase II, you should:
Look at other Codes of Conduct;
Use the Committee and Focus Groups to develop a Code of Conduct;
Customize the Code of Conduct to the Company culture;
Customize the Code of Conduct so it is suitable for all employees;
Make sure the Code of Conduct is user friendly and attractively packaged;
Create a Mission Statement and letter from the CEO to accompany the Code of Conduct; and
Create Corporate Compliance Program Guidelines.
Carole Basri
Phase III
Evaluate and Develop Policies and Procedures in Substantive Areas
During Phase III, you should:
Inventory policies and procedures already in place (e.g., internal controls for antitrust/competition, sexual harassment policy, environmental policy, etc.);
Align, Code of Conduct, Policy and Procedures, Internal Controls and Employee Handbook; and
Develop Policies and Procedures where Gaps exist as indicated from the report on Best Practices and Gaps and borrow best practices, where necessary from other subsidiaries or outside the organization (see trade associations, industry practice groups, law firms, consultants, seminars, such as Practicing Law Institute (PLI) and the Association of Corporate Counsel
Carole Basri
Phase IV
Communication, Training and Implementation
During Phase IV, you should:
Introduce Code of Conduct and Program;
Ongoing Communications Plan;
Training Plan;
Training Materials/on the Intranet; and
Training Schedule.
Carole Basri
Phase V
Continual Refinement, Self-assessment, Monitoring and Reporting
During Phase V, you should have:
Management Controls;
Internal Auditing, Testing, and Surveillance System;
Internal Controls;
Incentive System;
Internal Investigation Protocols; and
Publicize Reporting Results
Carole Basri
Morgan Stanley Lesson Learned
In the Morgan Stanley 2012 Declination from Prosecution and “effective” corporate compliance program created a shield from prosecution resulting from the activities of a “Rogue” employee.
Carole Basri
Make Your Compliance Rollout Memorable
Mementos (tombstones, plastic cubes, post-it notes);
Screen savers;
Calendars;
Intranet sites; and
Formal announcements and invitations to compliance event.
Remember
This is a marketing campaign!
Your product is a Compliance Program!
Your audience is your employees!
Carole Basri
Carole Basri
Thank You
Carole Basri
President, Corporate Lawyering Group, LLC
www.corporatelawyeringgroup.com
Adjunct Professor, Fordham University Law School
Visiting Professor, School of Transnational Law, Peking University
917-822-2447 [email protected]
35