What Happened
The US Department of Justice (“DOJ”) made several recent announcements expanding on its expectations for corporate compliance programs and unveiling new guidance on executive compensation structures, consequence management and business communications and ephemeral messaging.
DOJ also announced a new enforcement push focused on the intersection of corporate crime and national security.
Analysis
Updated Guidance on the Evaluation of Corporate Compliance Programs
DOJ Deputy Attorney General Lisa Monaco and Assistant Attorney General Kenneth Polite recently announced a number of significant policy changes affecting corporate criminal enforcement by DOJ during presentations at the ABA’s Institute on White Collar Crime in early March. These announcements expand on Monaco’s September 15, 2022 Memo on Further Revisions to Corporate Criminal Enforcement Policies Following Discussions with Corporate Crime Advisory Group, which laid the foundation for more detailed guidance on corporate compliance programs.
Among the more notable changes are:
- the rollout of a three-year Pilot Program Regarding Compensation Incentives and Clawbacks (the “Pilot Program”), which will require corporations who enter into criminal resolutions with DOJ’s Criminal Division to include “compensation-related criteria” in their corporate compliance programs and offer fine reductions to companies that seek to clawback compensation from culpable individuals in appropriate cases;
- guidance to prosecutors to assess a company’s “consequence management” procedures to identify, investigate, discipline and remediate violations of law, regulation or policy; and
- guidance on how DOJ will consider a company’s compliance program, policies and procedures relating to employees’ use of personal devices, communications platforms and ephemeral messaging applications.
Companies and regulated entities will need to reevaluate existing compliance programs to ensure their compliance programs are accounting for this new guidance.
Executive Compensation and Clawbacks
In his speech on March 3, Polite announced two key changes to DOJ policies pertaining to the evaluation of corporate compensation systems for all companies. Effective immediately, prosecutors assessing a corporation’s compliance program under DOJ’s updated guidance document, Evaluation of Corporate Compliance Programs (the “ECCP”), are directed to consider the design and implementation of a company’s compensation schemes to determine whether compensation is configured to incentivize compliance. The revised ECCP provides that prosecutors may consider, for example, “whether a company has incentivized compliance by designing compensation systems that defer or escrow certain compensation tied to conduct consistent with company values and policies” and whether a company maintains and enforces “provisions for recoupment or reduction of compensation due to compliance violations or misconduct.”
In addition to the ECCP changes, DOJ is rolling out a three-year Pilot Program, effective March 15, 2023. Pursuant to the Pilot Program, DOJ’s Criminal Division will:
- require companies entering into criminal resolutions to “implement compliance-related criteria in their compensation and bonus system and to report to the Division about such implementation during the term of such resolutions,” and
- “consider possible fine reductions where companies seek to recoup compensation from culpable employees and others who both a) had supervisory authority over the employee(s) or business area engaged in the misconduct and b) knew of, or were willfully blind to, the misconduct.”
Prosecutors are directed to integrate compliance-related criteria tied to compensation and bonuses into all corporate resolutions during the Pilot Program. Such criteria could include a prohibition on bonuses for employees who do not satisfy compliance performance requirements, disciplinary measures for employees who violate applicable law (and potentially their supervisors as well) and incentives for employees who demonstrate full commitment to compliance processes.
Likewise, the Pilot Program provides that an additional fine reduction may be warranted where a company:
- fully cooperates and timely remediates (as defined in the ECCP),
- demonstrates it has implemented a program to recoup compensation from employees who engaged in wrongdoing in connection with the conduct under investigation (or others in supervisory capacities), and
- has, in the DOJ’s estimation, demonstrated good faith in initiating a process to recoup such compensation before the time of resolution.
In these circumstances, DOJ will reduce “the fine in the amount of 100% of any such compensation that is recouped during the period of the resolution.”
Consequence Management
Relatedly, the ECCP provides guidance for prosecutors to consider whether a company has effective “consequence management” procedures in place that allow it to identify, investigate, discipline and remediate violations of law or misconduct. Prosecutors may consider whether a company has publicized disciplinary actions internally (as a deterrent effect) and whether it is tracking data related to disciplinary actions, compliance-related allegations and compliance investigations. Prosecutors are also directed to consider whether a company has effective human resources processes in place to ensure consistent application of compliance-related investigation procedures and disciplinary actions.
Guidance on Use of Personal Devices, Communications Platforms and Messaging Applications
DOJ also revised the ECCP to include new guidance on how it will consider corporate practices on the use of personal devices, messaging applications (including ephemeral messaging) and communications platforms in the workplace.
DOJ will evaluate a corporation’s policies governing electronic devices and data against the backdrop of the company’s risk profile and specific business needs, all the while assessing the company’s ability to access and preserve electronic data and communications. In conducting this evaluation, prosecutors are directed to consider three factors:
- Communication Channels.DOJ will consider what electronic communications channels the company and its employees use or can use to conduct business. It will consider whether the company’s policies and practice vary by jurisdiction or business unit, and will look at the mechanisms the company has put in place to manage and preserve information within those electronic communication channels.
- Policy Environment.DOJ will look at the policies the company has in place to allow it to secure, monitor or access business-related communications. If the company has a “bring your own device” (BYOD) program, DOJ will consider whether the company maintains policies for preserving and accessing data and communications on those devices, as well as the policies or procedures in place to ensure that communications and other data is preserved from devices that are replaced.
- Risk Management.DOJ will consider whether the company’s approach to permitting and managing communication channels, including BYOD and messaging applications, is reasonable in the context of its business needs and risk profile, and, in particular, will assess whether the use of personal devices or messaging apps, including ephemeral messaging applications, has impaired the company’s compliance program and its ability to conduct internal investigations or respond to requests from prosecutors, civil enforcement or regulatory agencies.
As Polite made clear, DOJ will expect companies to maintain, communicate and enforce policies that ensure that “business-related electronic data and communications can be preserved and accessed,” regardless of the medium on which they are maintained. Where companies fail to produce communications, prosecutors will ask about where they are stored and the company’s ability to access them. Polite was pointed in noting that “a company’s answers—or lack of answers—may very well affect the offer it receives to resolve criminal liability. So when crisis hits, let this be top of mind.”
Focus on National Security-Related Compliance Enforcement
Finally, Deputy Attorney General Monaco announced in her speech that DOJ would be making significant resource investments in the DOJ’s National Security Division so that the division is better able to focus on the intersection of corporate crime and national security. Citing the importance of sanctions and export control enforcement in US national security, Monaco noted that corporations “are on the front lines of today’s geopolitical and national security challenges” and that “corporate criminal investigations carry profound national security implications.”
Monaco admonished business leaders to take sanctions seriously, noting that DOJ is presently handing “corporate investigations that involve sanctions evasion” across the globe, in industries as varied as transportation, financial technology, banking, defense and agriculture. According to Monaco, “sanctions are the new FCPA.”
To better equip DOJ in these efforts, Monaco announced a surge in resources to address the intersection between corporate crime and national security, including hiring 25 new prosecutors to investigate sanctions evasions, export compliance and other economic crimes.
In addition, NSD will begin issuing joint advisories with the US Department of Commerce and the US Department of the Treasury to inform the private sector about enforcement trends and “convey [DOJ’s] expectations as to national security-related compliance.”
Summary
DOJ’s latest guidance provides tangible considerations for all companies to consider for their compliance programs. Details from the ECCP and Pilot Program provide companies and their compliance officers and employees the benefit of particular expectations and benchmarks from DOJ. It remains to be seen how the new guidance will pan out in practice, however.
For instance, while DOJ notes that the new revisions are intended to provide transparency around DOJ policy, prosecutors will retain significant discretion over, among other things, fine reduction recommendations and subjective assessments of “good faith” efforts to clawback compensation and overall effectiveness of compliance programs. This is particularly the case where prosecutors have broad discretion to require companies entering into criminal resolutions to implement the broadly worded “compliance-related criteria” in their compensation systems. It remains to be seen whether different prosecutors can cohesively implement such a policy with a measure of predictable consistency.
Additionally, the broad scope and coverage of DOJ’s guidance is significant. In contrast to specific rules that exist for public companies and regulated entities (such as broker-dealers and investment advisers) around recordkeeping obligations and executive compensation clawbacks, DOJ’s guidance applies to all companies. The practical result may mean that private entities currently not subject to existing obligations under the federal securities laws will likely need to consider the implementation of similar programs implemented.
Finally, many companies have likely not paid much attention to sanctions and national-security related issues when building out their compliance programs. To the extent that sanctions do in fact become “the new FCPA,” companies will need to bolster or implement policies and procedures that ensure the same degree of corporate compliance in the sanctions context as has become standard in the FCPA context.
The Hunton Andrews Kurth Blockchain Blog features opinions and legal analysis as we follow the development and use of distributed ledger technology known as the blockchain.
Search
Recent Posts
Categories
Tags
- 2019 Leaders’ Declaration
- 2020 National Strategy for Combating Terrorist and Other Illicit Financing (the 2020 Strategy)
- Advancing Innovation to Assist Law Enforcement Act
- Airdrops
- AML compliance program
- AML/CFT
- anonymity-enhanced cryptocurrencies
- Anti-Money Laundering
- Anti-Money Laundering Act of 2020 (AMLA)
- Anti-Money Laundering Compliance
- Antifraud
- Aon and Marsh
- Arizona
- Arkansas
- Artificial Intelligence
- Artificial Intelligence (AI)
- Australia
- Australian Competition and Consumer Commission (ACCC)
- Australian Securities and Investments Commission (ASIC)
- Automated Clearing House (ACH)
- Bank of England
- Bank Secrecy Act
- Bank Secrecy Act (BSA)
- Bank Term Fund Program
- Bermuda
- Biden Administration
- BIS
- Bitcoin
- Bitcoin Cash
- Bitfinex
- BitLicense
- Blockchain
- Blockchain Incubators
- Blockchain Legislation
- Blockchain Regulatory Certainty Act
- Blockchain Technology Act
- Brazil
- Breach of Contract
- Broker-Dealer
- Broker-Dealers
- BSA
- BSA Enforcement
- BTFP
- Bureau of Economic Analysis
- California
- Canada
- Captive Insurance
- CCPA
- Celebrity Endorsers
- Central Bank
- Central Bank Digital Currency (CBDC)
- Centre for Information Policy Leadership (CIPL)
- CFTC
- Chapter 15
- China
- Christopher Giancarlo
- Civil Enforcement
- Class Actions
- Clearweb
- Colorado
- Commissioner
- Commodity Exchange Act
- Commodity Exchange Act (CEA)
- Commodity Futures Trading Commission
- Complaint Bulletin
- Compliance
- Compliance Note
- Congress
- Connecticut
- Consent
- Consumer Financial Protection Bureau (CFPB)
- Consumer Protection
- Convertible Virtual Currency
- Corporate Compliance
- Corporate Governance
- Corporate Transparency Act (CTA)
- Council of Institutional Investors
- Council of the European Union
- Countering the Financing of Terrorism (CFT)
- Cross-Border Data Transfer
- crypto arbitrage trading accounts
- Crypto Assets
- crypto bank
- crypto custody
- Crypto Hackers
- Crypto Mining
- Crypto-commodity
- Crypto-currency
- Cryptoassets
- Cryptocurrency
- Cryptopia Limited
- Cryptosweep
- CVCs
- cybercrime
- Cybersecurity
- Dalia Blass
- DAO Report
- Darknet
- darknet marketplaces
- Data Privacy
- Data Protection Authority
- Davos
- decentralized finance (DeFi)
- DeFi
- Del. Michael San Nicolas
- Delaware
- Department of Business and Industry
- Department of Justice
- Department of Treasury
- DFS
- Digital Asset
- Digital Asset Securities
- Digital Assets
- Digital Commodities Consumer Protection Act of 2022
- digital currency
- digital currency ATM operators
- digital currency exchangers
- digital currency flows
- Digital Financial Assets Law (the Act)
- Digital Token Act
- digital token sales
- Digital Tokens
- Distributed Ledger
- Documentary Stamp Tax (DST)
- Dodd-Frank
- DOJ
- Economic Sanctions
- EDPB
- Eleventh Circuit
- Endorsement Guides
- Enforcement Action
- ePrivacy
- Ether
- Ether Classic
- EU General Data Protection Regulation (GDPR)
- EU Regulation
- European Central Bank
- European Commission
- Exchange Act
- Exchange Traded Fund
- FDIC
- Federal Election Commission
- Federal Reserve
- Federal Reserve Board
- Federal Trade Commission
- FedNow
- fiat currency MSBs
- Fiat-Backed
- Fight Illicit Networks and Detect Trafficking Act
- Figure Lending LLC
- Final Guidance
- Financial Action Task Force (FATF)
- Financial Crimes Enforcement Network (FinCEN)
- Financial Privacy
- Financial Stability Board
- Financial Stability Oversight Council
- Financial Stability Report
- Financial Technology Protection Act
- FinCEN
- FINRA
- FinTech
- Florida
- Foreign Corrupt Practices Act (FCPA)
- Foreign Extortion Prevention Act (FEPA)
- Form BE-12
- fractional interests
- FTC
- Gemini Dollar
- Gemini Trust Company
- Global Consortium for Digital Currency Governance
- Group of Seven
- Group of Twenty (G20) Finance Ministers
- H.R. 5635
- Hard Fork
- Heath Tarbert
- Her Majesty’s Revenue & Customs (HMRC)
- HM Revenue & Customs (HMRC)
- home equity lines of credit (HELOCs)
- Homeland Security Assessment of Terrorists’ Use of Virtual Currencies Act
- House of Representatives
- House of Representatives’ Financial Services Committee
- Howey
- Howey test
- IEO
- iFinex Inc.
- Illinois
- India
- Information Sheet 225
- Initial Chain Offering
- initial exchange offerings (IEOs)
- Insurance
- Intellectual Property
- International
- International Monetary Fund (IMF)
- Investor Protection
- IRS
- Jefferies Funding LLC
- Kenneth Blanco
- KYC/AML requirements
- Lael Brainard
- Large Platform Utility
- Legislation
- Legislature
- Liechtenstein Parliament
- liquidity
- Litecoin
- Litigation
- Louisiana
- Ltd.
- Malicious Cyber Activity
- Malicious Cyber Actor
- managed stablecoin
- Martin Act
- Maryland
- Metaverse
- model rule
- Monetary Policy
- Money Laundering
- Money Service Business
- money services businesses (MSBs)
- Mortgages
- Multi-Level Marketing Program (MLM)
- Mutual Fund
- Nakamoto
- narcotics
- NASAA
- Nebraska
- network maturity
- Nevada
- New Jersey
- New York
- New York Attorney General
- New York Department of Financial Services (DFS)
- New Zealand
- NFT (Non-Fungible Token)
- NFTs
- Non-fungible tokens
- North Dakota
- North Korea
- NY Department of Financial Services
- OFAC
- Office of Investor Education and Advocacy
- Office of the Comptroller of the Currency (OCC)
- Ohio
- Oklahoma
- Patent
- Paxos Standard
- Paxos Trust Company
- peer-to-peer exchangers
- Penalty
- Pennsylvania
- Personal Data
- Personal Information
- President’s Working Group (PWG)
- Privacy
- privacy coins
- Provenance.io
- Proxy Voting
- Public Blockchain
- rapid settlement
- real estate
- Regulation and Enforcement
- Rep. Sylvia Garcia
- Rescission
- Retail
- Ripple
- Ripple Labs
- Rule 233-1
- Russia
- Sanctions
- Sanctions Compliance Program (SHP)
- SAR lookback review
- SD8 coins
- SDN List
- SEC
- SEC crypto-securities
- SEC registration
- Securities
- Securities Act
- Securities Act of 1933
- Securities and Exchange Commission
- Securities and Exchange Commission (SEC)
- Securities Exchange Commission
- security tokens
- Self-disclosure
- Senate Committee on Banking Housing and Urban Affairs
- Shareholder
- Shareholders
- SIFI
- Signature Bank
- Silicon Valley Bank
- South Carolina
- South Dakota
- Spencer Dinwiddie
- stablecoins
- Stablecoins are Securities Act of 2019
- State-Sponsored Malicious Cyber Groups
- Suspicious Activity Report
- suspicious activity reporting (SARs)
- SVB
- SWIFT messaging system
- Swiss Financial Market Supervisory Authority (FINMA)
- Switzerland
- synthetic hegemonic currency
- Taxation
- Templum
- Tennessee
- Terrorist Financing
- Tether Limited
- Texas
- Texas Business Organizations Code (TBOC)
- Texas Senate Bill 1859
- Texas Senate Bill 1971
- The World Bank
- three-year safe harbor
- Token and TT Service Provider Act
- token developers
- token transfer limits
- tokenization
- tokenized assets
- Trademark
- Travel Rule
- Trump Administration
- TT Identifier
- TT System
- TVTG
- U.S. Virtual Currency Market and Regulatory Competitiveness Act of 2019
- UCC Article 12
- UK Tax Rules
- unhosted wallets
- Uniform Commercial Code
- United Kingdom (UK)
- United Specialty Insurance Company
- United States Bankruptcy Code
- United States Patent and Trademark Office
- US central bank digital currency (US CBDC)
- US Department of the Treasury
- US Department of the Treasury’s Office of Foreign Assets Control (OFAC)
- US dollar
- US Treasury
- USTR
- Utah
- Vermont
- Virginia
- Virtual Asset Service Providers
- Virtual currencies
- Virtual Currency
- Virtual Currency Consumer Protection Act of 2019
- Virtual Currency Exchange
- virtual currency license
- Virtual Currency Tax Fairness Act of 2020
- Virtual Markets Integrity Initiative
- Washington
- Weapons of Mass Destruction Proliferators Sanctions Regulations
- World Economic Forum
- Wyoming
- XRP
Authors
- Jimmy Bui
- Mayme Donohue
- Nicholas Drews
- Andrew Feiner
- Jason Feingertz
- Hannah Flint
- Kevin E. Gaunt
- Armin Ghiam
- Carleton Goss
- Gregory G. Hesse
- Scott H. Kimpel
- Marysia Laskowski
- Michael S. Levine
- Phyllis H. Marcus
- Lorelie S. Masters
- Patrick M. McDermott
- Uriel A. Mendieta
- Alex D. Pappas
- Daryl B. Robertson
- Natalia San Juan
- Caitlin A. Scipioni