THE GLOBAL CORRUPTION PROBLEM: AN EXPERT SPEAKS
Jan 01, 0001
Jan 01, 0001
Corruption poses a serious threat to business interests worldwide. While bribery and other fraudulent acts continue to have significant impact on the global marketplace, measures to combat them, including the Foreign Corrupt Practices Act (FCPA) and the UK Bribery Act, have changed the landscape considerably and are causing corporations to reassess their controls and due diligence.
February 2014The Fraud Examiner
Corruption poses a serious threat to business interests worldwide. While bribery and other fraudulent acts continue to have significant impact on the global marketplace, measures to combat them, including the Foreign Corrupt Practices Act (FCPA) and the UK Bribery Act, have changed the landscape considerably and are causing corporations to reassess their controls and due diligence.
To cast a blind eye to corruption today is to risk being held liable under those regulations or local laws for criminal acts committed within a company’s scope of business. Translating this new awareness into solid action, however, may be a slow process.
As reported in Compliance Week, a survey by professional services firm AlixPartners found that despite a relatively high level of concern about corruption among international companies, less than half of respondents said they conduct regular due diligence checks on their third-party partners. Along these lines, almost two-thirds of them cited staffing constraints as one of the biggest obstacles to their anti-corruption efforts. The firm surveyed "more than 250 general counsels, compliance officers, and other senior executives at companies with annual revenues of $150 million or more and based in North America, Europe, the Middle East, and Asia.”
The Fraud Examiner discussed corruption and bribery with ACFE faculty member Eric Feldman, CFE, CIG. Feldman is Managing Director, Corporate Ethics and Compliance Programs for Affiliated Monitors.
The biggest obstacle to companies’ anti-corruption efforts, according to the AlixPartners survey, is staffing constraints (65 percent). Do you think this is a product of a difficult economic climate, or a ready excuse for companies whose owners or upper management are focused on the bottom line and cost-cutting?
I was really struck by the survey results because – while I don’t want to underplay the importance of having adequate resources – I think that using staffing constraints as an excuse shows a lack of understanding of what an effective anti-corruption program really is. It doesn’t cost a lot of money or a lot of resources to educate the appropriate people in your workforce about the rules and what is required.
The real issue with compliance is creating an ethical culture within your company that does not permit unethical business practices. That starts by integrating the core values of your company, and goes to every level of the company. Those things don’t take resources, they take emphasis and commitment.
Tone at the top is the minimum standard. You have to be sure it is effectively integrated at every management level throughout the organization. It’s a matter of dictating, “we are not going to go there … we are not going to base our business on giving illegal gratuities to foreign officials” (for example). There should be an effective system of rewards for positive behavior and discipline for negative behavior.
Are companies that don’t budget for due diligence being “penny wise and pound foolish,” in your opinion? What would you tell the executives or directors at a company that is doing business overseas but does not invest in controls?
Third-party due diligence is the most important and critical area, as it is the area that ultimately puts the company most at risk. It’s important to ensure that (third parties’) ethical values are consistent with your company’s ethical values. That doesn’t take a lot of money, either. As I said, it takes emphasis and commitment.
A company that doesn’t do proper due diligence is absolutely liable for what might happen down the road (or even what may have happened in the past). The days of “I didn’t know, that was their business” are over.
Companies are responsible for the actions of their third-party partners, and the question will be: Did you do everything that you reasonably could have done to keep the (criminal) activity from occurring? If you didn’t perform due diligence, you are not going to be in a defensible position. These issues come up often in mergers and acquisitions.
One such recent example where this was done right was with Morgan Stanley. They acquired another firm, and during their due diligence process, they found out the company may have been engaged in corrupt activities. Morgan Stanley disclosed this information (to the U.S. Department of Justice) and created an immediate remediation plan. Therefore the DOJ did not prosecute.
When clients come to you for due diligence services, are they more often being proactive, or are they dealing with a problem that has already presented itself in one way or another?
Typically, when I get involved, we’re often being brought into a crisis situation where a company has been notified that they are a target of an investigation. They have to quickly demonstrate remedial action. More recently, though, we have seen a trend of companies being more proactive, perhaps looking at what’s happening in their industry or area, and thinking they might need to have someone look at their due diligence steps. And that’s a good thing.
What advice do you give large companies looking to expand overseas into markets like Africa, Russia and others? How careful do they need to be in setting up their business network?
The first thing is: know what the risks are in your particular area. For example, see the Transparency International Corruption Index. When taking the ACFE’s Fraud Risk Assessment, include those risk factors. Also, know what the rules are – you have to understand the FCPA. If you’re doing business in the UK, understand the UK Bribery Act. Then there are laws on the books in many of these countries that may not be widely enforced, but you’d better know what the rules are.
You also need to know who you’re doing business with. If your target is a public utility in Southeast Asia, for example, who owns that utility? Who is getting the revenue? This is important, because you might find out that a company or utility is 51 percent owned by the government (and subject to a specific set of anti-corruption rules). These are surprises you want to avoid.
Finally, you need to determine how you are going to mitigate the risks that do exist. Will it be through better controls? More oversight? More scrutiny? Or ... perhaps it isn’t worth it for us to do business in this country because the risk is too high. It’s important to go through that formal process.
According to the AlixPartners survey, only one in five respondents at European companies said their industries are exposed to significant corruption risk, compared with 40 percent of respondents from U.S. companies. How do you explain this "perception gap” between European business personnel and their counterparts in the U.S.?
There is definitely a cultural difference. European countries have had a history of doing business in a different way than in the U.S. Also, an increased level of enforcement is just gaining momentum in European countries. I think we are going to see a change in Europe, as most companies are not going to have an high acceptance for risk (due to the UK Bribery Act and other laws). Companies that run afoul of those laws can face dire consequences.
How is new regulation like the UK Bribery Act and other laws having an impact? Is there anything more on the near horizon in terms of new regulations?
First, there are some big differences between the UK Bribery Act and the FCPA. One of these differences is that the FCPA makes exceptions for what are called “facilitation payments.” That can get companies in some trouble because there can be a bit of a gray area between what is a “facilitation payment” and what is a bribe (the DOJ has an advisory function in which you can ask their opinion on whether an act is legal). The UK Bribery Act, however, makes no such exception. I advise companies to not even play the game with facilitation payments. Just don’t do it.
Also, the UK Bribery Act has a provision that requires companies to take active steps to prevent fraud and corruption. You have to have an anti-corruption program. Even if they can’t prove an underlying offense, companies have to be proactive – it’s required by law, which I like. I think that’s having an impact. People are attending the ACFE course that I present, Bribery and Corruption, to create strong anti-corruption programs at their companies. They include compliance, internal audit and internal investigation professionals, among others.
In your opinion, is the incidence and impact of bribery and corruption in business going to lessen or increase in the near future?
Enforcement is only going in one direction, and that’s up. It is a top priority. In the U.S., enforcement is going to go up, and actions will target more individuals as well as companies. The UK Bribery Act is hitting its stride, and we are going to see increased enforcement there, as well.
Most significantly, I think we are going to see more consistent enforcement in some of the countries that culturally have not been considered too tough. You’re going to see changes as the world economy becomes more intertwined. I already see it starting in China, Malaysia, some African countries and other locations.
What do fraud examiners need to understand, and help their clients understand, about corruption and the regulations aimed at curbing it?
The fraud examiner’s role within a corporate setting is really two-fold. One is to create an anti-fraud environment and sell to the leadership of the company on the return-on-investment of an anti-fraud program. There is a ton of data on the quantified impact that anti-fraud programs have on fraud losses, and the duration of fraud schemes, among other factors. Also, the fraud examiner often is a key player in conducting the company’s fraud risk assessment. Anti-corruption programs are becoming very important parts of both risk assessments and anti-fraud controls, all under the same umbrella.
This really makes the role of the CFE even more important. The sooner violations are detected, the sooner the company can meet its reporting obligations… and the better off it will be. Self-reporting and remediation are critical pieces. I don’t think that any government agency expects companies to never have problems or a bad actor. It’s about what they do and how they respond.
Eric Feldman, CFE, CIG, is an ACFE faculty member and Managing Director, Corporate Ethics and Compliance Programs for Affiliated Monitors. He also serves as President of Core Integrity Group. Send Eric an e-mail.