law assignment
INT’L LAW IN PRACTICE: Part IV- Compliance>sanctions
Prof. Robert E. Lutz
Treusch Distinguished Professor of Int’l Legal Studies
Spring 2016
[April 21,2016]
General Comments about COMPLIANCE
[remarks drawn from the ALI’s “Principles of the Law—Compliance, Enforcement, and Risk Management for Corporations, Nonprofits, and Other Organizations” (Aug. 31, 2015)].
Nature of Compliance Function
“…is the set of rules, principles, controls, authorities, offices and practices designed to ensure that the organization conforms to external and internal norms.”
What are goals of compliance?
Provide input of the effective management of the organization
Deter misconduct by employees, agents, or others whose actions can be attributed to the organizations
Enforce code of ethics
Identify instances when violations of law have occurred
Establish and maintain a culture of ethics and compliance within the organization
Enhance the organization’s profits by reducing the cost of violations without limited legally permissible activities
What are Elements of Effective Compliance?
A compliance program
Support from the organization’s highest legal authority
Effective management
Adequate funding, staffing, and other resources
Incentives for compliant behavior
Procedures for independent validation
How does Risk-Assessment relate to the Compliance Function?
Compliance officers should undertake a compliance risk assessment that may include the following relevant factors:
Nature of org’s business
Industry’s history of violations
Organization’s history of violations
Compensation arrangements for executives
Whether org introduced a new product line or entered a new bus activity
Whether a change in applicable law
Whether or not internal controls are subject to manual override
Extent of org’s foreign activities
Org’s exposure to compliance violations by agents, vendors, customers, or supply-chain counterparties
Regulatory enforcement priorities
Probably impact of compliance violations on the org’s reputation
Compliance “red flags” of potential violations
Red flags can include:
Transactions with no apparent business purpose
Sudden material changes in performance that cannot be explained by known causes
Excessively complex structures
Frequent omission to complete required paperwork
Efforts to disguise the identity of customers or other counterparties
Gifts or favors to customers or business partners that appear excessive in light of the customs of the industry
Frequent self-dealing or other conflicted activities by employees and agents
Compliance under Legal Uncertainty
Compliance officer (CO) not responsible to resolve uncertainty in applicable rules or regulations
If CO seeks to resolve such uncertainty, he/she may seek guidance from the Chief Legal Officer or other qualified attorney,
OR, if appropriate, apply the “most reasonable interpretation.”
REGULATOR ROLE (the other perspective)
Shld structure its monitoring and supervision based on an evaluation of the risk of violations presented by an organization or activity
The Regulator should supervise an org’s compliance function and
The Regulator should provide guidance about the regulator’s expectations for the org’s compliance function
Regulator reqmts for effective compliance programs may be principles-based
An ineffective compliance function may be a ground for regulatory action
CREDIT for Effective Compliance Functions
Regulators should give appropriate credit to an org’s compliance function when charging violations, what violations, and penalties.
Credit should be given if:
Compliance function of org is effective, and
Org cooperates with regulator’s investigation
Amount of Credit should depend on:
Whether org discovered violation via its internal-control function
Whether org voluntarily disclosed violation
Whether Regulator “would” have discovered violation via other means
Whether org took affirmative steps to rectify the violation to ensure proced’s are implemented to prevent further violations
COMPLIANCE involves attention to following:
HUMAN RESOURCES--Hiring of Eees, retention of agents, and selecting of counterparties
INTERNAL REPORTING + WHISTLEBLOWING
ROLE OF THIRD-PARTY SERVICE PROVIDERS (attys, auditors, consultants, monitors)
INVESTIGATIONS (internal)
BEYOND THE ORGANIZATION (responsibility of Parent for Subsidiaries’ Compliance)
Parents are subject to compliance obligations of subsidiaries IF:
Provided by law
Parent undertakes such an obligation
Parent exercises control over the subsid’s mgt and benefits
Parent provides internal-control services for the subsid, the parent should perform those services competently and for the benefit of the subsidiary
SUPPLY-CHAIN DUE DILIGENCE
Org may find it advisable to compile an inventory of significant contractors and subcontractors and the services they perform or goods they supply [Vendor and Business-Partner Due Diligence (DD)]
Org may find it advisable to assess the compliance risk posed by violations committed by its significant contractors or subcontractors [Customer DD]
Org may seek to verify that significant contractors and subKors understand and agree to adhere to the org’s policies, procedures, and code of ethics
Codes and CSR
Org can embody its commitment to ethical behavior in a code of ethics (CoE)
CoE can make it clear that eees are expected to conduct themselves in ways that go beyond compliance with laws, regulations, professional stnds and the org’s compliance policies and procedures
CoE prohibits conduct that amounts to disrespect or unfairness to others.
CSR is a possibility and can affect org undertakings.
Int’l orgs pose special issues related to multiple legal regimes, culture, history, communication, etc., and complicates the assessment of risk.