Compliance Risk Assessment Fall 2016 Class 7 Stephen Paine Jay Holtmeier, Guest Lecturer
Compliance Risk by Area:
Anti-Corruption and Insider Trading
Recap of Class 1
Pfizer Case Study and Compliance Risks
Legal and Regulatory Incentives/Conflicts of Interest
Political Failure of Controls
Reputational Recidivism
Point of Sale/Distribution
Definitions
Compliance Risk is the risk of failing to comply with applicable legal or regulatory requirements resulting in a material loss (financial or reputational) or legal/regulatory sanction
A Compliance Risk Assessment is a framework to enable the evaluation and analysis of the overall Compliance risk (both inherent risks and control effectiveness) associated with a particular business area
Recap of Class 2
The Five Elements of an Effective Compliance Program
Tone at the Top
Enron Chronology: July 1985 Enron established through merger and by November 2006 entire senior management team has either been indicted or convicted with Enron and Arthur Andersen no longer operating
Corporate Culture and Communication
Codes of Conduct set the values for employees to follow and those values are based on Compliance Risk.
3. Compliance Risk Assessment
4. Testing and Monitoring
5. Chief Compliance Officer
Case Study: HSBC
Financing drug cartels
Permitting sanctioned regimes to process dollar payments
Claw back of compensation (including Compliance Officers)
Criminal charges for “failure to maintain an effective AML program”
Recap of Class 3
Compliance Tools/Controls
Advisory Function
Coverage of Front Office and Technology, Finance and Operations
Conflicts of Interest -- A Deep Dive
Conflicts of interest are inherent in the financial services business
Historical success of the industry has been managing these conflicts by eliminating or disclosing them
Top to bottom review of business operations to address conflicts of interest of every kind
Risk Assessments
Follow-Up
Policies and Procedures
Education and Training
Compliance Surveillance and Business Unit Review and Testing
‹#›
Recap of Class 4
A Compliance Risk Assessment is a framework to enable the evaluation and analysis of the overall Compliance risk (both inherent risks and control effectiveness) associated with a particular business area
1. Identifying Business Area(s) and Metrics
2. Mapping Applicable Rules
3. Identifying Key Compliance Risks and Themes
4. Defining a Controls Inventory
5. Rating Control Effectiveness
6. Determining Residual Risks
7. Scoring, Rating and Reporting
It’s All About the Questionnaire . . .
Compliance Risk Assessment Steps
Identify Business Area and Metrics
Map Applicable Rules
Identify Key Compliance Risks & Themes
Define Controls Inventory
Rate Controls Effectiveness
Determine Residual Risk
Score, Rate and Report
Phase 2 of the Course
Assignments
Listen carefully in class as assignments will be based on material from the sector presented.
Sector Risk
Listen and assimilate the material/lecture through the lens of the types of risks each of the areas present, as well as the corresponding controls – the 3/4 central boxes of the CRA Diagram
Be a proactive listener and ask questions or provide comments
Make notes of questions that you have or comments to discuss later
Compliance Risk Assessment Steps
Identify Business Area and Metrics
Map Applicable Rules
Identify Key Compliance Risks & Themes
Define Controls Inventory
Rate Controls Effectiveness
Determine Residual Risk
Score, Rate and Report
Recap of Class 5
Financial Services Regulation
Banking Services
Deposit Taking
Lending
Fund Transfers, checking
Securities and Investments
Buying and selling stocks, bonds
Participating in Capital Markets transactions
Investment Advisory Activities
Investment Company Activities
Federal Reserve, OCC, SEC, FINRA and CFTC, plus Exchanges
FINRA Regulatory Regime
Supervision
Self-Reporting
Case Study: Prospectus Delivery
‹#›
Recap of Class 6
Anti-Money Laundering and Financial Crime Risk and Controls
Anti-Money Laundering
Rule Mapping: Bank Secrecy Act, USA PATRIOT Act, EU Directives Proceeds of Crime Act
Elements: Proceeds of crime used in banking system
Inherent Risks of Clients – Client Lifecycle (Onboarding, Processing Transactions, Refreshing Information)
Geographical Location
Type of Client
Products and Services
Client Identification serves as the primary control: KYC -- Client Due Diligence and Enhanced Due Diligence
Sanctions
Rule Mapping: OFAC, United Nations and EU Directives
Elements: Penalties imposed by one country on one or more other countries/individuals
Client Screening as a control
Anti-Bribery and Corruption (ABC)
To be covered in Class 7
Suspicious Transaction Reporting
Filing a report with the appropriate regulatory authority when suspicious activity is identified
Strictly prohibited to disclose the filing of the report to parties involved
‹#›
Compliance Risk by Area: Focus on Anti-Corruption
With Guest Lecturer Jay Holtmeier
Jay Holtmeier is a partner in Wilmer Hale’s Litigation/Controversy Department, and a member of the Investigations and Criminal Litigation Practice Group. He co-leads the firm's Foreign Corrupt Practices Act and Anti-Corruption Group and is a member of the Dodd-Frank Whistleblower Working Group. He joined the firm in 2004.
Mr. Holtmeier's breadth of experience as a litigator includes service as a federal prosecutor, a senior in-house attorney and a lawyer in private practice. Mr. Holtmeier represents institutions and individuals in complex government and internal investigations and matters of corporate governance and compliance. He has particular expertise in matters involving the Foreign Corrupt Practices Act (FCPA).
In FCPA matters, Mr. Holtmeier has represented clients in government and internal investigations involving conduct in Europe, Asia, the Middle East, Africa, Latin America and Australia. He regularly counsels clients facing difficult FCPA issues in a variety of business contexts, and he has assisted clients in numerous industries in developing and implementing FCPA compliance programs.
Assignment 5
Assignment 5 for October 19: Identify and rank the financial crime risk areas for two of the businesses in your financial services company. Explain how the controls of KYC, transaction monitoring and SAR reporting mitigate these risk areas. Be prepared to hand in this assignment at the beginning of class on October 19.
Identify 2 business areas. You can choose businesses at the division level or more specific business areas under the division level.
Then explain how the three controls mitigate Financial Crime Compliance risks in these two business areas.
2-3 pages
‹#›
Tone at the Top Update
October 12, 2016 Resignation of CEO
New CEO Appointed
October 18, 2016 News Story about prior fraud warning
Compliance Risk by Sector:
Insider Trading
What is Inside Information?
15
Relates to the securities of an issuer
Not publicly known
Has not been disseminated in a manner reasonably designed to provide broad, non-exclusionary distribution of the information to the public
Material
It has “market significance” (likely to affect the market price of any outstanding securities of the issuer)
A reasonable investor would consider the information important in deciding whether to purchase, hold or sell a security
Would be viewed by a reasonable investor as having significantly altered the total mix of information made available to holders of securities
Inside information is also known as material, non-public information (or “MNPI”).
What is Material?
16
There is no statutory definition of materiality – it is determined according to caselaw, with significant room for judgment.
Courts routinely reject bright-line mathematical tests for materiality
Both quantitative and qualitative factors can be relevant to materiality (5% rule of thumb)
Information may be material even if it relates to future, speculative, or contingent events. When events are contingent or speculative, the test for materiality depends upon a balancing of both the probability that the event will occur and the anticipated magnitude of the event in light of the totality of the company activity (the “probability/magnitude test”).
Examples of Material Information
17
A planned offering of securities
Mergers, acquisitions, purchases or sales of assets, refinancing, joint ventures
Calls of securities, repurchase plans, stock splits or changes in dividends
Earnings estimates, changes in previously released earnings or estimates
Changes in ratings of debt securities
Expansion or curtailment of operations
New products or discoveries or developments regarding customers or suppliers
Changes in control or in management
Writedowns of assets, additions to reserves
Defaults on securities, bankruptcy or receivership
What is Insider Trading?
Buying or selling a security
With intent to deceive
In breach of fiduciary duty or other relationship of trust
While in possession of MNPI about the security
What is Insider Trading?
Legal Conduct
Corporate insiders (officers, directors, and employees) buy and sell stock in their own companies during open trading windows
When corporate insiders trade in their own securities, they must report their trades to the SEC
Illegal Conduct
Buying or selling a security, in breach of a fiduciary duty or other relationship of trust and confidence, while in possession of material, nonpublic information about the security
19
Legislative History
No specific prohibition on Insider Trading – prohibitions from various statutes and caselaw.
Section 10(b) of the Securities Exchange Act of 1934 and Rule 10b-5 promulgated thereunder
Prohibits fraud in connection with a purchase or sale of securities
Rule 14e-3
Prohibits trading when you have MNPI about a tender offer, if you got that information directly or indirectly from someone involved in the tender offer
Section 16
Insider liability for short-swing profits (purchase/sale within 6 months)
Regulation FD
Prohibits selective disclosure by companies
20
Theories of Insider Trading
Classical
Corporate insider (e.g., board member, executive)
Owes fiduciary duty
Breaches fiduciary duty by trading on MNPI
Misappropriation
Corporate outsider (e.g., Lawyer)
Trusted with MNPI in confidence
Breaches a duty owed to the source of the information
Tipping
Trading on MNPI received as a tip from insider or misappropriator in exchange for a personal benefit
21
Why is insider trading prohibited?
Ensure a level playing field
Transparency and integrity of the financial markets
Inspire investor confidence that the financial markets are not “rigged”
Unfairness of insider trading gains for those with informational advantage
Keep the US financial markets among the most respected in the world
Illegal Insider Trading in the News
23
Insider Trading: Controls
What is the primary control for handling inside information?
Information Barriers
And how are information barriers managed?
The Control Room
Insider Trading
What is the Control Room?
26
What does the Control Room do?
The Control Room is a central function that monitors the Bank’s Information Barriers and the flow of inside information throughout the Bank
The functions of the Control Room related to Information Barriers include:
27
Development and maintenance of the Bank’s Information Barrier policies and procedures
Maintenance of the Bank’s Watch and Restricted Lists and approving Wall Crossings
Monitoring the integrity of the Bank’s Information Barriers (i.e., surveillance of Firm, Employee and Client trading activity)
Reviewing Equity and Fixed Income research for companies that may appear on the Watch List or Restricted List
Pre-clearance of private side employee personal account trades and certain Firm trades
Providing ongoing advice and training on matters related to inside information and information barriers
Private Side vs. Public Side
28
Above The Wall
Private Side
Investment Banking Department
Public Side
Equities and Fixed Income Sales and Trading
Capital Markets
Research
Private Banking
Asset Management
Shared Services functions with no access to Inside Information
Internal Audit
Asset Backed Origination
Structured Lending
Solutions Partners
Private Equity
Shared Services functions with access to Inside Information
Prime Services
Inside Information Barriers
Manage the flow of inside information to prevent its inadvertent spread and misuse
Restrict the sharing of inside information from employees on the “private side” of the Bank (e.g., those employees working in an investment banking or origination capacity) to employees on the “public side” of the Bank
Consist of:
Policies & Procedures
Physical Barriers
Electronic Barriers
Monitoring
Training
29
Control Room Notification Procedures
Information Barrier policies generally require all employees to proactively notify the Control Room of activities that have resulted in (or likely will result in) the receipt of Inside Information
Employees must also inform the Control Room when they learn of material developments associated with an existing assignment or situation
This includes Inside Information received outside the ordinary course of business, such as:
from a company or business that the employee or the Bank does not cover or intend to do business with
from a friend or other social or professional acquaintance
from being the unintended recipient of the information (for example, as a result of overhearing another conversation)
30
Watch List
The Watch List is a confidential list of issuers with respect to which the Firm possesses inside information that has not yet been publicly disclosed, or for which a transaction has not been publicly announced
Enables the Control Room to monitor sales, trading and research activities in a subject company’s securities, and to validate the integrity of the Firm’s information barriers
Generally does not impact the sales, trading and research activities of the Firm, except in limited circumstances
The Watch List is not published and can only be accessed by the Control Room
31
Restricted List
The Restricted List generally reflects pending transactions in which the Firm is involved that have been publicly announced and in which we may have, or appear to have, inside information
The Restricted List also may be used for other regulatory purposes (e.g., to comply with the trading restrictions imposed by Reg. M or by the tender rules, Section 16, or if we own a large position or are an affiliate of the company)
The Restricted List limits certain marketing, research and trading activity that could constitute misuse of inside information or otherwise appear to be improper
The Restricted List is available to all employees via an internal web page as well as via direct feeds to trading systems and market data screens
32
Wall Crossings
Wall Crossing procedures must be followed when communicating inside information to public side (i.e. sales, trading and research) employees
All Wall Crossings require:
Prior approval by a designated senior executive;
Prior approval by an appropriate senior business line manager (a “Conduit”) of the person being brought over the wall; and
Consultation with a member of the Control Room
33
Insider Trading: Surveillance
Overview
Monitor Firm, client and employee trading activity in the firm’s divisions
Covers all products including equities, debt, derivatives and bank loans
Types of reports include:
Restricted List
Watch List
Over The Wall
Research Frontrunning
Restricted List Lookbacks
Watch List Lookbacks
External Deals
35
Scope of Control Room Monitoring
36
Product Coverage
Equities, equity-related securities and related derivatives
Fixed Income securities and related derivatives
Bank Loans and related derivatives
Investment Banking
Private Banking & Wealth Management
Business Divisions
Account Types
Restricted List
Watch List
Wall Crossings
Bank deal lookbacks
Non-Bank deal lookbacks
Watch List lookbacks
Research front-running
Firm (proprietary, client facilitation, hedge)
Institutional Clients
Private Banking Clients
Discretionary Portfolios
Asset Management Funds
Deal Types
Employee
Review Criteria – What The Control Room Looks For
Restricted List Reports
Whether the type of trading activity that occurred (e.g., firm vs. client activity, trading without approvals, etc.) represents a violation of the Restricted List
Over The Wall Reports
Trading activity by an employee (for the Bank, client or their own personal account) in a security for which he or she is currently over the wall
Watch List/Lookback Reports
Trading activity by employees on the private side of the Inside Information barrier (Above The Wall personnel, Capital Markets, etc.)
Trades by employees who are Conduits for or are part of the same group as wall crossed individuals
Trades by clients who have been wall crossed (e.g., through Market Sounding)
Activity that deviates from known trading strategies (e.g., larger than normal trade size, holding positions when they are normally liquidated at end of day)
Timely trades with significant profit potential
37
What Does the Control Room Want to Know About?
If an employee receives Inside Information
Trading activity while in possession of Inside Information (by employees, clients or the firm) or merely the appearance of (e.g., well timed trades)
Breaches of Information Barriers through the use of electronic communications or otherwise
Business changes that may invoke Information Barrier, Conflicts of Interest or Large Shareholding concerns (new businesses, reporting lines, physical location, booking systems, etc.)
Transactions that where the firm would own 3% or more of a public company’s equity securities (including through the use of derivatives)
Disclosure of personal accounts and pre-clearance of trades
Disclosure of outside business activities and directorships
38
Escalation Criteria – What We Do With Our Findings
Breaches by Employees (Restricted List, Information Barrier policies)
If following internal review an employee was found to have improperly directed trading or solicited/tipped a client in violation of CS policy, then standard misconduct, disciplinary and escalation procedures would apply
In cases of perceived or actual Insider Trading by an employee, Bank would contact the relevant regulator directly (in addition to filing a Suspicious Activity Report)
Potential Insider Trading by Clients
A fortuitous, well-timed trade alone would not lead to an SAR filing—it would require the presence of additional factors, such as:
Reason to believe the client had access to Inside Information (e.g., as part of a market sounding exercise, inadvertent email, etc.); or
A potential connection exists between the client and the parties involved in the deal (e.g., a principal of the client is on Board of a target company or affiliate); or
A pattern of the client trading ahead of other deals with a common link (e.g., same company, advisor, law firm, etc.)
39
Insider Trading Controls: Personal Account Trading
Employee Personal Account Trading
1
Minimum holding periods apply and, where applicable, are subject to pre-clearance (generally good until end of trading day).
An Employee account:
Is an account that has brokerage capability in which an employee has an interest or the power to influence investment decisions
Includes employee’s spouse, partner and minor children
Trading is generally not permitted in securities of issuers on the Restricted List.
Bank securities may only be traded during approved windows and with pre-trade approval, where applicable.
Many regulators require banks to monitor the personal trades of their employees.
In most jurisdictions1, employees are required:
To declare their trading account details to Compliance
To receive pre-trade approval for certain transactions
41
Insider Trading: Other Related Risks
Discussions with the Buyside
Discussions between private-side bankers and buy-side clients (e.g., hedge funds) implicate insider trading risk
Private-side bankers have access to MNPI that cannot be shared with buy-side investors
Risk that buy-side investors are “fishing” for information about companies or specific transactions
Banks may limit these discussions, or require internal approvals and discussion guidelines (i.e., industry discussions only)
Expert Networks
The investigation of the Galleon/Raj Rajaratnam case highlighted the risk posed by “expert networks”
Expert networks connect investor clients with experts paid for information and insight in the expert’s area of expertise
Risk that expert networks will share MNPI with investors using their services
Banks/investors may limit use of expert networks by requiring certifications (e.g., no inside information) and qualifications (e.g., has not been an officer/director/access employee of a public company for a period of time)
Market Sounding
Market sounding refers to certain communications with prospective investors prior to the formal launch or announcement of a transaction or offering
Such communications are intended to gauge investor interest in a transaction
In some cases, market sounding may involve providing potential investors with MNPI
Confidentiality agreements and trading restrictions may be required
Safeguarding Confidential Information
Private side Bank employees will come into possession of the most sensitive information.
What practical steps should be taken to protect it?
Avoid discussing confidential information in public places
Avoid leaving sensitive information on voicemail or with administrative assistants
Working off premises, must ensure that you keep information secure
Ensure emails are sent to the correct address and with the correct attachment(s)
“Clean-Desk” Rule - In the workspace, avoid leaving confidential information exposed and ensure that when you leave your office or cubicle you have stored sensitive documents in a secure location.
Case Study: Merck Insider Trading
Do you think Merck includes insider trading in its annual compliance risk assessment?
Why or Why not?
Should every public company have controls for this?
What could Merck have done to implement controls to prevent this?
What about Bank of New York/Mellon?
‹#›
Assignment 4
Assignment was announced as not graded and will not be recorded as a grade
Your assignment was; however, scored to give you a better sense of your progress and my expectations.
Grade Distribution:
Excellent (E): 3
Good (G): 10
Satisfactory (S): 6
Poor (P): 3
‹#›
Assignment 6
Draft notes and questions for an interview with the Head of the Head of Mergers and Acqusitions in the Investment Banking Division of your financial services company(Morgan Stanley) for a Compliance Risk Assessment of Insider Trading.
Develop an interview for the Head of Mergers and Acquisitions relating to insider trading and Rule 10b-5
The Mergers and Acquistions Department advise companies on who are either(1) looking to acquire another company or(2) are the target of being acquired. These transactions present challenges as the mere fact that a company is about to be acquired can radically impact the stock price and trading of both companies.
Your interview should include a list of questions but also include notes about potential answers that could require require follow-up
I want to see how well you understand the concepts of insider trading and your ability to transpose the concepts presented in class into a Compliance Risk Assessment situation. You can include questions that relate to both risks and controls.
This is your first full questionnaire assignment and while there was a request to see an example of a questionnaire, giving an example now might compromise the learning component of this exercise.
‹#›