Compliance & Ethics PROFESSIONAL ®
corporatecompliance.org
a publication of the society of corporate compliance and ethics
Meet Gerry Zack Incoming CEO of SCCE & HCCA
see page 18
APRIL 2018
FEATURE
by Robin Singh, MS (Law), MBA, MS IT, CCEP-I, CFE, LPEC
What does it take to build an ethical culture? »» The journey of a compliance professional has undergone a sea change from working in the shadows to getting a seat at the table—the who’s who of the corporate world. »» Compliance departments have moved from monitoring policies, rules, and regulations to regulating individual ethics.
Robin Singh (robinsingh002@yahoo.com) is the Compliance & Fraud Control Lead at Abu Dhabi Health Services Company in Abu Dhabi, UAE. linkedin.com/in/whitecollarinvestigator @wcinvestigator
W
ith the growing web of the regulatory environment, attorneys and compliance officers alike face a lot of problems interpreting regulations. The buzzwords in today’s economy are “compliance programs,” because the words act as a euphuism for survival in the fight against regulatory compliance. There is an overreliance placed on the words “compliance programs” rather than the substance of them.
Singh
The pressure on the compliance department With the ever-growing regulatory and legal landscape, as well as other internal rules, policies, and procedures, it is difficult to manage or adhere to compliance. Furthermore, the effects of the recession are still looming over various economies, and there are many people who are simply looking for an entry into a profession to commence their daily earnings. Only a
limited handful of professions have grown in requirement, and if one removes the opportunities associated with information technology, then people are left with hardly any options. Compliance is a profession in demand, and it is in its nascent stage as it grows into a hardcore, technology-focused field. The impact of people not having the adequate background, engaging communication skills, training capabilities, a keen eye for detail, awareness of policies and local laws, and/or the ability to appropriately interpret regulations could be catastrophic for the organization that hires ill-equipped or inexperienced senior compliance officers. This can further lead to a false sense of security amongst the management and the board when: ·· A program is developed but is not tailored according to the local culture of the company; ·· Policies and risk assessments are carried out by employees who are not adequately trained or made aware of their responsibilities;
Compliance & Ethics Professional ® April 2018
»» Regulators have pierced the corporate veil to identify a living person responsible for any unethical act committed and ended up pointing fingers at chief compliance officers. »» Increasing uncertainty, developments in regulation, lack of budget, and work pressure have transformed some inexperienced compliance officers to “the dark side.” »» With the venerable force field over organizations to protect them from unethical conduct, there is no way around except to hire experienced compliance professionals.
+1 952.933.4977 or 888.277.4977 corporatecompliance.org 45
FEATURE
·· An induction/orientation program is held for new joiners without any substance to convey the organization’s values and conduct; ·· Investigations are carried out without any concrete evidence; ·· People are disciplined based on their hierarchal value in their chain; ·· Management reports are made on the number of investigations closed, only to later find out that half of them were closed because they were reported by anonymous whistleblowers; ·· The “weight” of the department is thrown around, only to find out that one senior compliance officer bullied the whistleblowers to reveal names; or ·· Monitoring/spot checks are carried out without any actual effect of compliance; and ·· The list goes on and on. U.S. Securities and Exchange Commission (SEC) Enforcement Director Andrew Ceresney, in 2014, mentioned the importance of
compliance officers and, in the same speech, mentioned that the SEC has brought and will continue to bring actions against personnel who have affirmatively participated in misconduct, who have misled regulators, or who had the clear responsibility to implement compliance programs or policies and wholly failed to carry out that responsibility.1 This goes to show the importance of compliance officers. One mistake in the hiring of a compliance officer could take the organization down like a house of cards.
False sense of pride and poor acumen...or just being overly smart Compliance officers are given good names as well as bad. They may be thought of as a flu shot, because the compliance function helps the company protect itself from regulatory problems. The bad names may include “Dr. Say No” or “the business interrupter.” However, it is not uncommon to see the U.S. Justice Department (DOJ) and regulators announce multimillion-dollar criminal or civil fines in settlements for anti-money
Compliance & Ethics Professional ® April 2018
Figure 1: Financial crime tops the agenda of regulators2
46 corporatecompliance.org +1 952.933.4977 or 888.277.4977
FEATURE
a comprehensive AML program, and certain red flags went undetected and/or inadequately investigated. FINRA fined the compliance officer $25,000 under Rule 3310. ·· Banamex: Citibank was fined close to $250 million for not implementing an effective AML program. Four people were penalized, including the CEO and CCO. The CCO had to pay $70,000 and was barred from working in the same domain. ·· Wells Fargo: The bank was fined for aiding and abetting securities fraud. The regulator held the CCO liable for not being able to foster a culture of ethics. The regulator’s main argument was that the problem was systemic. The CCO filed a lawsuit, and the judge ruled in favor of the plaintiff. The verdict had language that it is not good to single out people for the crimes of an organization. However, the CCO will always carry a blemish of this in her work history. ·· SFX Financial Advisory Management Enterprises: SFX failed to adopt reasonably designed policies and procedures to prevent the misappropriation of client assets. The regulator concluded pursuant to Sections 203(e), 203(f), and 203(k) that the investment advisers failed to implement the policies it did have. The recent trends and regulatory conditions, such as the individual accountability in the Yates Memo, coupled with the requirements of U.S. Federal Sentencing Guidelines, AML, CFT guidelines, and deferred prosecution agreements (DPA) are examples of requirements that are creating pressure for Compliance departments. Another question raised is, can “too many regulations” be used as an alibi for compliance
Compliance & Ethics Professional ® April 2018
laundering (AML) violations. Regulators have dramatically stepped up enforcement of AML and counter financing of terrorism (CFT) laws and regulations. Sometimes compliancerelated fines exceed many hundreds of millions of dollars, with a 2014 judgment reaching nearly $9 billion3 (see Figure 1). With these enforcements and financial technology, the SEC, and DOJ have started to target individuals. In most cases, though, they have targeted top-level executives. At times, the compliance officers have faced the brunt of the enforcement agencies, such as: ·· Brown Brothers Harriman: The bank had a money-laundering problem. FINRA identified it and fined the organization $8 million. Nonetheless, they had to hold an individual responsible, and in this case, it was the chief compliance officer (CCO), who was fined $25,000 and suspended from practicing in the field of Compliance. ·· MoneyGram: The Financial Crimes Enforcement Network (FinCEN) investigated and held the CCO responsible for a lapse under the Bank Secrecy Act (31 U.S.C. § 5311). The lapse was facilitated by a lack of controls, framework, and safeguards, with a penalty of $1 million. However, the CCO countersued FinCEN, and the case was finally settled at $250,000 and a ban for 3 years. ·· BlackRock: An investment manager in charge of an energy portfolio invested heavily in an energy company. Over time, the energy company became 10% of the portfolio of BlackRock. The SEC held BlackRock responsible for not disclosing a material conflict of interest under Rule 38a-1 of the Investment Company Act. The CCO was caught in the crossfire. However, he also filed a lawsuit and got off the hook with a fine of $60,000. ·· Raymond James: The firm was fined $17 million because it did not implement
+1 952.933.4977 or 888.277.4977 corporatecompliance.org 47
FEATURE
officers to be less meticulous in carrying out their duties? Some time back, I read a very nice article on the SCCE Compliance and Ethics Blog when a compliance officer was arrested by the FBI. Roy Snell made a wonderful argument that spending a day in the field of Compliance cannot make you an actual compliance officer or that a person from operations who has a compliance title cannot be construed to be an actual compliance officer.4 People without adequate training and certifications, at a minimum, should not be given the key responsibilities of a compliance officer. Perhaps it is better to hire such candidates as associates or trainees.
Compliance & Ethics Professional ® April 2018
Compliance applies to everyone An acquaintance of mine approached me seeking guidance, because the Compliance department of his company had initiated an investigation against him for some business development work he had carried out. My first response was, if you haven’t done anything wrong, you shouldn’t be worried about it. I asked him to refer to his company’s policy and procedures to prepare him for the course of the investigation. After he and his boss were interviewed—so was the client he had been soliciting to acquire a legitimate business with appropriate documentation, for example, Know Your Customer, etc.—he was issued a first-level warning letter. He was pretty upset. I asked him if any of the charges were proven, and he said none, and his boss was supportive as well. Then I urged him to speak with the Compliance department on the basis of the warning letter. This is where the best part comes in. When he called the compliance officer twice, the officer said, “How dare you call me twice,” and after a good tussle, the compliance officer told him not to appeal against the letter, because the Compliance department would go to any length to
48 corporatecompliance.org +1 952.933.4977 or 888.277.4977
maintain their reputation. My acquaintance decided to let it go, because this took place during the recession when jobs were scarce and the validity of the warning letter was only one year. This shows how important it is to have a working/implemented compliance program. This further shows that a compliance program is not only applicable to select departments of an organization, but also to the Compliance department itself. Overall, a compliance program is about setting the right culture and tone, and reducing unethical conduct. Compliance applies to each and every individual of an organization. Compliance and Ethics departments should naturally be held to a higher standard of ethical values, because they are entrusted with the responsibility on behalf of the organization. A fully developed and implemented compliance program is the only way of doing the right thing or of upholding the company’s values, especially when no one is watching. It reminds me of the movie, Training Day, where Denzel Washington’s character, a cop gone rogue, would go to any limit to prove his case. He finally got what he deserved from a fellow officer who was able to do partial good and partial justice to his profession.
Comprehensive policies are key Another incident that I encountered was when a person who worked in a public relations department accidentally released a statement with his name on it, instead of the CEO’s name, which should appear on the press release by default. The CEO was irate over the issue, and I understand this is a grave mistake; however, when the Compliance department came in, they could not equate this error to any policy or violation under their current laws, regulations, and rules. Finally, in order to get back to him, they had no choice
FEATURE
Conclusion We as compliance professionals take pride building a culture of compliance where the simplest definition of compliance says to comply with laws, regulations, policies and procedures, and other non-regulatory rules. Compliance should be the pinnacle of a company’s values and mission. Compliance officers need to be welltrained and should require further hand holding until they understand the company’s processes and the actual working culture. The above examples also show that it is not good to have a one- or two-person Compliance department, because it means no checks and balances for the monitoring authority, and it is subject to threats and manipulation. With part-time compliance officers, one-person departments, or a conflated party managing the department, people will see only as far as they want to see. The best example may be Peter Madoff, Bernie Madoff’s brother and CCO, who was sentenced to imprisonment because he chose to look past Bernie’s wrongdoing.5 Another
example is Charlie Shrem,6 a compliance officer for BitInstant, who was arrested and charged with failing to file suspicious activity reports in accordance with an antimoney laundering law for the transactions that he allegedly helped facilitate through BitInstant. And then there’s Oliver Schmidt,7 Volkswagen’s regulatory compliance officer, who was arrested on the charge of conspiracy to defraud the United States. And there’s William Michael Quigley,8 the former CCO of a registered broker-dealer in Woodbury, New York, who was charged with conspiracy to commit wire fraud and money laundering in connection with a fraudulent investment scheme. And the list goes on and on. As a compliance officer, one should be a gatekeeper and is supposed to guard against unethical conduct and fraud, instead of acting as an accomplice by doing only the minimum necessary. (Under English common law, an accomplice is a person who actively participates in the commission of a crime, even if they take no part in the actual criminal offense.) I can only begin to imagine what would happen if compliance officers started relishing schadenfreude (i.e., a feeling of enjoyment that comes from seeing or hearing about the troubles of other people). ✵ 1. U. S. Securities and Exchange Commission: Keynote address by Andrew Ceresney. May 20, 2014. http://bit.ly/2mS9nUy. 2. Radish Singh: “AML-CFT risk management framework evolutions” Deloitte, 2015. Available at http://bit.ly/2BGzbri. 3. U.S. Department of Justice, press release: “BNP Paribas Agrees to Plead Guilty and to Pay $8.9 Billion for Illegally Processing Financial Transactions for Countries Subject to U.S. Economic Sanctions” June 30, 2014. Available at http://bit.ly/1WlVVlr 4. Roy Snell: “The FBI Arrested a Compliance Professional???” SCCE Compliance & Ethics Blog; January 10, 2017. Available at http://bit. ly/2Dl4GJn. 5. FBI New York Field Office, press release: “Peter Madoff, Former Chief Compliance Officer…Sentenced to 10 Years in Prison” December 20, 2012. Available at http://bit.ly/2DNSEcn. 6. Kim Zetter: “Bitcoin Exchange CEO Charged With Laundering $1 Million Through Silk Road” Wired; January, 27, 2014. Available at http://bit.ly/2DKQnPb. 7. Adam Goldman, Hiroko Tabuchi, and Jack Ewing: “F.B.I. Arrests Volkswagen Executive on Conspiracy Charge in Emissions Scandal,” The New York Times; January 9, 2017. Available at http://nyti.ms/ 2DMqw9y 8. U.S. Attorney’s Office, Eastern District of New York, press release: “Former Chief Compliance Officer of Long Island Brokerage Firm Indicted on Fraud and Money Laundering Charges” May 28, 2015. Available at http://bit.ly/2mOGMyR.
Compliance & Ethics Professional ® April 2018
but to equate it to an equivalent issue in anti-money laundering. Now, what were they thinking? They have a public relations department, and they don’t have adequate policies to cover such an issue? This goes to show how important it is to have comprehensive, well-written (simple English) policies and guidelines when it comes to serious issues involving a company’s operations. The above issue is something that I see going poorly for the company, because they equated the offense to an issue that doesn’t apply, where the incident doesn’t fit the consequences that would be applied, and sooner rather than later, the employee will bring a court case against the company.
+1 952.933.4977 or 888.277.4977 corporatecompliance.org 49