About | HeinOnline Law Journal Library | HeinOnline Law Journal Library | HeinOnline



13 Int'l. In-House Counsel J. 1 (2020)

handle is hein.journals/iihcj13 and id is 1 raw text is: 

International In-house Counsel Journal
Vol.13, No. 50, Winter 2020, 1



        Critique   of the U.S.  Department of Justice Evaluation of
                      Corporate Compliance Programs


                                BRUCE   ORTWINE
  General Counsel, Americas; Adviser, Global Legal and Compliance; Senior Executive
              Vice President, Sumitomo Mitsui Trust Bank, Limited, USA


Introduction: On April 30, 2019, the U.S. Department of Justice, Criminal Division (the
DOJ)  published  updated guidance  (the DOJ  Guidance)  on the evaluation of a
company's  corporate compliance program (a CCP). The evaluation is to be considered
by DOJ  white-collar criminal prosecutors in the event that a criminal offense is committed
by an employee  or third-party agent or contractor of the company. The evaluation of the
CCP  is offered as guidelines both to a company to determine the extent to which its own
CCP  compares with the requirements of the DOJ Guidance, and to prosecutors to determine
whether to prosecute the company itself for the misconduct of its employee or third party
agent or contractor. While the DOJ  Guidance  provides transparency on the required
components  of an effective CCP, it fails to provide transparency on whether an effective
CCP  will spare a company from criminal prosecution.
Background:   In  recent years, legal and regulatory requirements have significantly
increased for companies operating in the U.S. and abroad. Federal and state criminal laws
have been aggressively enforced for numerous types of criminal misconduct, including for
crimes relating to bribery of foreign government officials and otherwise corrupt conduct,
and money  laundering. Moreover, a number of federal criminal laws have extraterritorial,
or global, jurisdiction, meaning that a company-whether U.S. or foreign having contacts
with the U.S.-may  be criminally prosecuted in the U.S. for criminal misconduct that takes
place outside the U.S.
Companies  are required to have CCP's that are both in effect and appropriately enforced.
The scope of a CCP should mirror the scope of the company's business activities, customer
base and geographic locations in which it conducts its activities. Certain types of business
activities (e.g., financial service activities), customers (e.g., cash-intensive businesses) and
geographic locations (e.g., countries known as drug havens or having corrupt governments)
are considered inherently high risk in nature. Companies need to develop comprehensive
CCP's  that include policies, procedures and controls that mitigate those risks, and need to
train and  otherwise communicate   to their employees  and  third parties about the
requirements of full compliance with all applicable laws and regulations.
The  Importance  of a Risk Assessment: The starting point of a CCP is a risk assessment,
which identifies the risks, assesses the likelihood of occurrence and severity if there is an
occurrence of misconduct, controls that are currently in place, assessment of the relative
effectiveness of those controls (e.g., do they prevent misconduct, deter misconduct or
merely inform as to the consequences of misconduct), determines the gaps that exist
between the nature of the risk and existing controls and how those gaps can be mitigated,
implements an action plan for remediation of the gaps within specified timeframes, and
then continuously monitors and otherwise tests for new risks, effectiveness of controls, etc.


ISSN 1754-0607 print/ISSN 1754-0607 online


International In-house Counsel Journal